Live data from Hacker News

Edward Snowden: The Internet Is Broken

popsci.com

71–80 of 180 posts

Re: Edward Snowden: The Internet Is Broken

#71
post #28
post #16

> But at the same time, we technologists as a class knew academically that these capabilities could be abused, but nobody actually believed they would be abused. Because why would you do that? It seemed so antisocial as a basic concept. I guess so? Not me though. Snowden literally only proved what I had learned on my own. > But we were confronted with documented evidence in 2013 that even what most people would consi…

Foresight has been essential in this. Without Stallman's foresight of the need for public domain open source software, there would only be proprietary software, all subject to PRISM. Without the foresight of potential Government's to come the US founding fathers would not have written in such protections as still exist today. Before Snowden there were many that suspected but now everyone knows. >Um. Who thought this?…

I kid you not. Stallman looked crazy in my eyes before Snowden. Even my "paranoid" perspective on all these things pre-snowden where never close to true Stallman "crazy" (or so I thought before..)

Now I want to use Emacs. I want to use everything FSF if possible. I'm no where close. There is a lot for me to do to get there. But I'm hoping I will because soon that may be our only hope.

> NSA's James Clapper lied to Ron Wyden in Congress about mass surveillance.

And isn't that crazy? Try lying in front of congress and not go to jail. Such corruption. Completely institutionalized corruption of the processes and the power of congress to check the power of the NSA.

Re: Edward Snowden: The Internet Is Broken

#72

Earlier quoted context omitted.

I'm pretty sure Galois get a lot of contracts from the government.

The U.S. government invented INFOSEC and funded most tech (security or otherwise) that you depend on. So what. It's the specific tech or actions that matter rather than who funds them. At worst, you increase scrutiny or consider subversion issues. Of course, high assurance is specifically designed to counter that. So, people worried about subversion should be using this stuff more than anyone. Btw, here's two things…

Cryptol is a nice tool, but it can't eliminate most important crypto bugs (for example, the sorts of bugs found in OpenSSL). It's useful for proving things about bit-mixy crypto code like AES, SHA, etc, but that code rarely has bugs (due to known-answer tests).

Re: Edward Snowden: The Internet Is Broken

#73

Earlier quoted context omitted.

I'm pretty sure Galois get a lot of contracts from the government.

The U.S. government invented INFOSEC and funded most tech (security or otherwise) that you depend on. So what. It's the specific tech or actions that matter rather than who funds them. At worst, you increase scrutiny or consider subversion issues. Of course, high assurance is specifically designed to counter that. So, people worried about subversion should be using this stuff more than anyone. Btw, here's two things…

I myself have already previously starred Cryptol (I'm acquainted with a few ex-Galois people) but was unaware as to its wider adoption. Certainly I get reasonably frequent notifications on its issues list from Github.

Re: Edward Snowden: The Internet Is Broken

#74

Earlier quoted context omitted.

I heard about those taps in 2008/2009 I think. Snowden hasn't really given us anything truly new. It's also bizarre how quickly everything he presented was/is accepted as fact immediately without question. I think it's way more likely Snowden was intentional. He's still working for the Federal government and the leaks are intentional so that the Federal Government could announce to the world that they are spying on a…

Questioning the narrative is fine. I for one think he's a combo of whistleblower and traitir, hero and coward depending on what leaks and actions we're talking about. Yet, to think NSA or US did it intdntionally is beyond all reason. Snowden set back so many goal posts for US intelligence, LEO's, and industry that it's impossible thaf it was intentional by USG.

One thing is for sure. The CIA could have killed him, could kill him now, if he truly posed a threat to national security. The fact that they don't indicates they don't feel he is a threat. I'm confident that whatever goal posts you claim Snowden set back, I can explain as ultimatley serving US interests. That's the barometer. Has he hurt US Interests? Seems US interests are doing fine to me. Would things be better if he has revealed nothing? Probably not. His revelations are great distractions.

Re: Edward Snowden: The Internet Is Broken

#75

Earlier quoted context omitted.

We didn't know but it wasn't paranoid to assume it. The reason was the Echelon leaks and what was done about those. The answer: nothing.

It wasn't paranoid in crypto-knowledgable circles. It earned you a tinfoil hat outside of them. That's why Snowden was important.

This 100%. Snowden was so important because he brought this stuff mainstream. But, let's be completely clear that it was already mostly known in bits and pieces and many leaders in tech had already been sounding the alarms.

I am in no way downplaying Snowden or what he prompted everyone to do, but everyone knew it was happening. They just weren't motivated or felt no one else cared.

Its kind of like trying to get people to use PGP for normal communications: You understand why, and they might too, but they don't care enough. So it doesn't get done.

Re: Edward Snowden: The Internet Is Broken

#76

Earlier quoted context omitted.

Questioning the narrative is fine. I for one think he's a combo of whistleblower and traitir, hero and coward depending on what leaks and actions we're talking about. Yet, to think NSA or US did it intdntionally is beyond all reason. Snowden set back so many goal posts for US intelligence, LEO's, and industry that it's impossible thaf it was intentional by USG.

One thing is for sure. The CIA could have killed him, could kill him now, if he truly posed a threat to national security. The fact that they don't indicates they don't feel he is a threat. I'm confident that whatever goal posts you claim Snowden set back, I can explain as ultimatley serving US interests. That's the barometer. Has he hurt US Interests? Seems US interests are doing fine to me. Would things be better i…

No, they can't kill him now. They're not allowed to by one of only players on Earth they try not to push too hard: Putin, head of Superpower No 2. They weigh the risk against the fact that damage is already done and all they'd protect is further image problems. They're countering that seperately.

Re damage. Tens of billions to economy that military-industrial complex worked hard to get. Push-back against police state legislation. NSA ops and methods blown. Large uptake in products that reduce SIGINT. Businesses moving overseas. All with no benefits on the table for intelligence agencies.

Far as distractions, that's the media's job focing on mass shooters, North Korea, ISIS, etc instead of pending legislation and schemes by government.

Re: Edward Snowden: The Internet Is Broken

#77
post #75

Earlier quoted context omitted.

It wasn't paranoid in crypto-knowledgable circles. It earned you a tinfoil hat outside of them. That's why Snowden was important.

This 100%. Snowden was so important because he brought this stuff mainstream. But, let's be completely clear that it was already mostly known in bits and pieces and many leaders in tech had already been sounding the alarms. I am in no way downplaying Snowden or what he prompted everyone to do, but everyone knew it was happening. They just weren't motivated or felt no one else cared. Its kind of like trying to get peo…

"Its kind of like trying to get people to use PGP for normal communications: You understand why, and they might too, but they don't care enough. So it doesn't get done."

Good example. I've seen harder to use tools with little benefit adopted by enterprises because management forced it. The simplest version of encrypted email and storage often was ignored for just apathy.

Re: Edward Snowden: The Internet Is Broken

#78
post #67
post #19

Earlier quoted context omitted.

You knew GCHQ tapped Google's datacenter-to-datacenter links?

I had no idea. I'm not downplaying Snowden. The guy is 100% a hero in my eyes. But, to claim we in tech community were all like "I have no idea this was happening" is completely bogus.

It was also very easy to dismiss us as conspiracy theorists. And indeed we were. The Snowden revelations are useful as a way of saying "we predicted the state was engaging in mass surveillance and they denied it while they continued the program". That is immensely useful for the future.

Re: Edward Snowden: The Internet Is Broken

#79

Earlier quoted context omitted.

The U.S. government invented INFOSEC and funded most tech (security or otherwise) that you depend on. So what. It's the specific tech or actions that matter rather than who funds them. At worst, you increase scrutiny or consider subversion issues. Of course, high assurance is specifically designed to counter that. So, people worried about subversion should be using this stuff more than anyone. Btw, here's two things…

I myself have already previously starred Cryptol (I'm acquainted with a few ex-Galois people) but was unaware as to its wider adoption. Certainly I get reasonably frequent notifications on its issues list from Github.

Cool stuff. I think their Xen and Ivory work will probably have highest odds of benefiting people. All kinds of people doing stuff like Arduino and Raspberry Pi that it could be applied to. Either immediately or with a port.

Re: Edward Snowden: The Internet Is Broken

#80

He's still not getting it or fully recommending it any more than most have. The funny thing is that I recently read a 150 page interview with one of founders of INFOSEC, Dr Schell, that showed his employer was the same way: ignored "COMPUSEC" as useless in favor of "COMSEC" solutions to all security problems. Schell, Karger, and Anderson's tiger teams smashed every mainframe and crypto using system put in front of th…

I agree that software bugs are a bigger concern than encrypting everything. I think the problem is that not many people are starting companies around "high assurance." How do you get people to turn their PL research into startups?
Post reply on HN