Earlier quoted context omitted.
Just like VPNs, proxies and abuse tolerant networks. If you can't prevent the spam by other means than IP blocking then maybe you should make your website read-only.
Or just block the sources of abuse while everyone else enjoys and can act on the content. Or just block comments from anonymous nets so they can at least read. Comment sections that are Wild West hurt branding too much for it to be an option.
Edward Snowden: The Internet Is Broken
31–40 of 180 posts
Re: Edward Snowden: The Internet Is Broken
#32Like Schell and Karger said for 30 years, what we need is to start deploying high-assurance security practices, protocols, systems, methods... everything that's proven to get the job done in various ways. We need them deployed pervasively. More private protocols and encryption by default, too, but who gives a shit if it runs on systems so insecure it doesn't need backdoors?
Let's go back to 1960's moving toward the 70's and 80's on hardware stuff. Burroughs stuff was tagged so everything in memory was code or data, pointers protected, arrays bounds-checked, arguments checked on function calls, and OS tried to isolate apps from each other. Some LISP machines had GC's for memory management. System/38 had capability-security & built-in database. Solo had safe concurrency at OS level. One had read-only firmware you couldn't change without physically moving it with a nucleus that handle protected functions that OS's built on. Two implemented a secure, Ada runtime that enforced the language's safety properties. SAFE (crash-safe.org), Cambridge's CHERI, and Sandia's SSP/Score processors follow these traditions.
Now let's look at how Schell et al said to do assurance. Precise, math/flowcharts/whatever description of functional and security requirements to avoid ambiguities & resulting vulnerabilities. Similar for design with attention to simplicity. Implementation in safest language you can with simpler subset and style easy to analyze. Every module proven to match a requirement/spec so no subversion (well, a start on it...). Strict modularity, layering, and interface checks all over the place. Success and failure states modeled then shown to follow a precise, security policy. If you can't state it precisely, then you can't secure it because you don't know what security means for you. Code review, tests of each function, formal proofs if possible, static analysis if possible, covert channel analysis of info flows, configuration management that assumes malicious developers, source to object code verification, trusted distribution of HW/SW to customers, onsite verification/generation from source, and configuration guidance. All of this independently verified by at least one set of professionals that know what they're doing.
That was security in 1970's-1980's. Far from red tape some here claim, every method above was proven by researchers, field users, and pentesters to catch serious problems. The only dispute was what caught most and where to spend most money. Even those questions had decent answers. Well, plus specific design and modeling decisions but INFOSEC was in infancy & that was evolving. I'm talking assurance activities: getting it done right whatever it is. Fast forward today to find that all the problems Schell, Karger, etc predicted have happened and consistently in systems that don't use those methods whereas systems that do avoid many more problems.
So, here's the solution: raise assurance of our systems across the board using methods that go back to 1961. That's right, Burroughs engineers were doing a better job on security before that was even a thing just trying to improve reliability. This is 2016. We have better specs, better languages, better static analysis, easier formal tools, automated test generation, tons of sample code, fast dev machines... you name it. There's no excuse, outside willful ignorance or apathy, for security-focused developers (esp in FOSS) to not use everything at their disposal that's proven to work at reducing risk. Even less excuse for the stuff they make to still be less secure than tech from the friggin 60's and 70's.
Shout out to the exceptions that are trying to do it right. Groups like GenodeOS, Dresden, NICTA/OKL4, Carlisle's IRONSIDES DNS, Bernstein's stuff, Galois, JX OS, ETH, INRIA, Secure64, Sentinel HYDRA (minus bodacion crap lol), Combex, and even NativeClient since they knocked off OP browser. Enough stuff like this and NSA will be begging us to ban INFOSEC books and shit since their info will dry up haha.
Re: Edward Snowden: The Internet Is Broken
#33The EFF warned long ago something was going on when AT&T was putting beam splitters on Internet backbones to feed the NSA. Then Snowden revealed how everything is tapped. Then, be sure all mainstream encryption is "NOBUS". Nothing is truly random. Someone somewhere has the master key: elliptic curve cryptography using magic numbers from NIST? "Secure boot" by Intel? OpenSSL? Microsoft software? All backdoored. Trust…
I think it's way more likely Snowden was intentional. He's still working for the Federal government and the leaks are intentional so that the Federal Government could announce to the world that they are spying on all their own citizens...and nothing happen. No real revolution, and no real end to the surveillance.
I mean yea, we have better security practices, more people use encryption, more people are aware about security ... but overall the landscape hasn't changed except in one crucial aspect: people are talking less publicly. People are afraid that what they say is monitored. There has been a chilling effect.
The Snowden narrative needs to be questioned. Since when does an NSA contractor working from home in Hawaii get VPN access to all the government secretes? Like...people actually believe that?
Re: Edward Snowden: The Internet Is Broken
#34> But at the same time, we technologists as a class knew academically that these capabilities could be abused, but nobody actually believed they would be abused. Because why would you do that? It seemed so antisocial as a basic concept. I guess so? Not me though. Snowden literally only proved what I had learned on my own. > But we were confronted with documented evidence in 2013 that even what most people would consi…
This was censorship by business and security communities plus apathy by consumers. Plain and simple. The business communities didn't want to spend crap on INFOSEC. The ones that did faced two obstacles: (a) low volume meant real deal was ridiculously expensive with slower development; (b) mainstream INFOSEC conned companies with bandaids or fake security because they made more money that way. Constantly charging to fix problems they left in or upgrades people didn't need.
So, result was everything is shit security and stays that way. Neither proprietary nor FOSS learn from lessons 99% of the time. All due to what Schneier always called "perverse incentives" that keep bad stuff produced.
Re: Edward Snowden: The Internet Is Broken
#35He's still not getting it or fully recommending it any more than most have. The funny thing is that I recently read a 150 page interview with one of founders of INFOSEC, Dr Schell, that showed his employer was the same way: ignored "COMPUSEC" as useless in favor of "COMSEC" solutions to all security problems. Schell, Karger, and Anderson's tiger teams smashed every mainframe and crypto using system put in front of th…
Re: Edward Snowden: The Internet Is Broken
#36Earlier quoted context omitted.
Just possibly old versions of truecrypt. This author's conclusions seem quite sound to me. They collapsed it in a way to comply with a gag order while silently sounding an alarm. https://forum.truecrypt.ch/t/my-analysis-of-what-really-happ... Anyone operating in this space is eventually going to get the same option as Lavabit's founder: compromise or collapse.
If you're super paranoid you shouldn't trust any version of truecrypt. Read the fascinating story of Paul Le Roux... https://mastermind.atavist.com/ He created E4M (which truecrypt was based on) and is rumored to have been one of the creators of truecrypt. Apparently he's also been a US government asset for a while.
Re: Edward Snowden: The Internet Is Broken
#37He's still not getting it or fully recommending it any more than most have. The funny thing is that I recently read a 150 page interview with one of founders of INFOSEC, Dr Schell, that showed his employer was the same way: ignored "COMPUSEC" as useless in favor of "COMSEC" solutions to all security problems. Schell, Karger, and Anderson's tiger teams smashed every mainframe and crypto using system put in front of th…
I'm pretty sure Galois get a lot of contracts from the government.
Btw, here's two things Galois did with their contracts that mainstream security folks are mostly ignoring instead of building on or applying:
And a repo with the rest that uses the magical power of open source to counter people's fears and improve the world:
At least some of them have stars in the three digits. I'm impressed an open-source crowd giving it that much attention. Maybe cuz it's on GitHub. The rest might need to go on there, too, for better odds of adoption. Using Google and Save As... are apparently major obstacles of adoption these days. Idk as I'm still trying to figure it out.
Re: Edward Snowden: The Internet Is Broken
#38> But at the same time, we technologists as a class knew academically that these capabilities could be abused, but nobody actually believed they would be abused. Because why would you do that? It seemed so antisocial as a basic concept. I guess so? Not me though. Snowden literally only proved what I had learned on my own. > But we were confronted with documented evidence in 2013 that even what most people would consi…
Foresight has been essential in this. Without Stallman's foresight of the need for public domain open source software, there would only be proprietary software, all subject to PRISM. Without the foresight of potential Government's to come the US founding fathers would not have written in such protections as still exist today. Before Snowden there were many that suspected but now everyone knows. >Um. Who thought this?…
Or proprietary, shared-source software provided by nonprofits or companies in jurisdictions that aren't surveillance heavy. No, you don't need FOSS to avoid PRISM lol. It has its advantages in resisting totalitarianism for sure but you don't actually need them. More of author or organization's intent and licensing that really matters. Many models available.
Btw, the first, secure-ish mainframe OS (MCP of Tron fame) was sold in source form by Burroughs with fixes/updates allowed to be submitted. In 1963. High-assurance stuff under Orange Book similarly had to deliver source that was reviewed and provided a way to know you had same copy. Just to support my claim that there's proprietary models for it but most just wanted money instead. ;)
Re: Edward Snowden: The Internet Is Broken
#39Earlier quoted context omitted.
Or just block the sources of abuse while everyone else enjoys and can act on the content. Or just block comments from anonymous nets so they can at least read. Comment sections that are Wild West hurt branding too much for it to be an option.
Ah yes, we can't sacrifice the all-important branding!
1. Focus on benefiting anonymous people who either don't contribute shit back to the business or barely do. Freeloaders.
2. Focus on benefiting the founders, customers, and employees (in that order). If you loose some freeloaders, then so be it. If it's their design decision, then so be it time 10. They can always set up an unrestricted forum for people like them to discuss the article and deal with security headaches they bring in.
Wait, No 2 seems to work as most readers and the company are benefiting except for the few that choose not to.
Re: Edward Snowden: The Internet Is Broken
#40Earlier quoted context omitted.
http://archive.wired.com/science/discoveries/news/2006/05/70... This stuff has been going on, and widely discussed, for over a decade. But no one really cared or understood the full scope until Snowden's slapped everyone across the face with it.
Yeah I know about the AT&T splitters mentioned in the footnotes. But the Snowden leak was a lot bigger than that. Did 0xCMP know that the NSA was recording the full contents of every cell phone call in the Bahamas and keeping them around for at least 30 days?