Live data from Hacker News

Edward Snowden: The Internet Is Broken

popsci.com

81–90 of 180 posts

Re: Edward Snowden: The Internet Is Broken

#81

"police and the government then have the authority to search through your entire life in your pocket just because you are pulled over for a broken taillight" This is the classic Snowden formula. Establish a false premise that has no faith in the government or constitutional rights, then continue to paint a picture of a dystopian future. This guy should be writing sci-fi novels... [edit: I predicted at least 5 down vo…

What is the false premise? Why do you think 'faith' is required in a logical argument? What future?

"police and the government then have the authority to search through your entire life in your pocket just because you are pulled over for a broken taillight: "

Is false.

Re: Edward Snowden: The Internet Is Broken

#82
post #56

The EFF warned long ago something was going on when AT&T was putting beam splitters on Internet backbones to feed the NSA. Then Snowden revealed how everything is tapped. Then, be sure all mainstream encryption is "NOBUS". Nothing is truly random. Someone somewhere has the master key: elliptic curve cryptography using magic numbers from NIST? "Secure boot" by Intel? OpenSSL? Microsoft software? All backdoored. Trust…

For as long as technologically minded folks insist on technological solutions to political problems, we will be stuck in this quagmire. The answer is a political solution to a political problem. Admittedly, that's a hard one for some folks. It requires talking to people and building relationships. It takes a long time and change can be frustratingly slow to present itself. But that's how it is. Trust no one With this…

There has never, in my life, been a time that the government and the people they work for/represent/are have ever been more adversarial. When you realize government has stopped working for you and are actively treating you like a criminal, you ask who they are working for. It's hard not to land on banks, corporations, and Bernie's "Billionaire Class" - whether that's true or not isn't part of my point.

So it's hard to "trust" in a single direction when the actions that cause distrust are so, so bald-faced. Every conspiracy-sounding theory surrounding surveillance has turned out to be true. And all that worry about being caught has had a net-zero effect. Maybe Let's Encrypt was at least partially a result, but that's about it. So why worry now? Turns out secret courts are just about guaranteed to green-light whatever the hell the NSA wants, so people finding out didn't really turn out as badly as they were worried about.

So "trust us" is about impossible anymore. I don't know if the relationship can be healed, to be honest. Obama was the ideal of our best shot, but that ship sailed like, day 2.

Re: Edward Snowden: The Internet Is Broken

#83
post #52

Earlier quoted context omitted.

There was a cultural change when Bell was broken up and UNIX became less laissez-faire, a paradigm shift. Software became valuable and not just bundled with hardware. Stallman saw it coming early enough that he had completed his GNU Free toolchain in time for Torvalds to use it. A developer community is less likely to arise when your modifications can be closed and you cannot fork. If your business runs in someone el…

I mostly agree with that. It's not what you said, though, which went further and is what I responded to. Stallman and FOSS fans like to go from those contributions to unsopported claims where no proprietary can have a single property of OSS. Yours implied only FOSS could've resisted a secret, US directive which was 100% untrue given existence of closed, non-US products. I preempted your likely counter by pointing out…

Fair point and well preempted. Proprietary software can offer some freedom but it does not ensure it will remain, nor does it offer the full 4 freedoms required.

What you say is not technically incorrect, but practically Google, Apple & Microsoft were all secretly in NSA's PRISM. A large corporate entity is subject to state pressure in a different way than a public good. A corporation must profit, new markets must be entered, their regimes placated at the expense of users. Ownership is a single point of failure.

A proper security audit is only possible if one can compile that source with ones own toolchain or get the binary from a source you trust. One must test and make modifications, otherwise the binary only purports to be from exactly that source.

So you must in the end trust the companies, and trust them to release patches promptly, not delay them at the behest of the NSA (as per Snowden).

PGP and SSH are both provably secure. Security is dynamic, FOSS is faster at releasing patches and not removing features while updating security.

If a patch removes an essential feature and security is bundled with it, this is problematic. If you cannot use distributed community modifications then you are often out of luck.

Companies change hands, policies change, you may be secure today but they sell your data tomorrow. Free software forks at disagreements so everyone is happy. Free software cannot be taken from you by law - it is public domain.

Re: Edward Snowden: The Internet Is Broken

#84
post #15

Excellect! It's the most cogent analysis that I've seen from him. Damn, what a fucking hero! A few comments, however ... > ... we had to go to the dark side to be able to confront the threat posed by bad guys. We had to adopt their methods for ourselves. He's using "we" there in reference to the government. But it can also be read with "we" as you and me, and "bad guys" as the government ;) But then, I claim a broad…

I guess all he needs is to grow his hair long and a beard and HNers would genuflect at his picture in their hallway. Funny how this guy, at age 29 three years ago, is an expert in all worldly things nowadays.

Re: Edward Snowden: The Internet Is Broken

#85

Earlier quoted context omitted.

I heard about those taps in 2008/2009 I think. Snowden hasn't really given us anything truly new. It's also bizarre how quickly everything he presented was/is accepted as fact immediately without question. I think it's way more likely Snowden was intentional. He's still working for the Federal government and the leaks are intentional so that the Federal Government could announce to the world that they are spying on a…

I hope you're being satirical. This is such a classic formulation of a conspiracy theory that I hope it's intentional. If so, bravo! If not, then like all conspiracy theories you need to account for everyone who would need to be in on the secret, how they're all keeping the secret, and why--what's in it for them.

Just to be clear, a big chunk of what Snowden's leak revealed actualized a bunch of conspiracy theories. Do you see the disturbing irony of dismissing another conspiracy theory so flippantly? I don't believe it's true, but if it turned out to be, I'd hardly be surprised.

Re: Edward Snowden: The Internet Is Broken

#86
post #71
post #28

Earlier quoted context omitted.

Foresight has been essential in this. Without Stallman's foresight of the need for public domain open source software, there would only be proprietary software, all subject to PRISM. Without the foresight of potential Government's to come the US founding fathers would not have written in such protections as still exist today. Before Snowden there were many that suspected but now everyone knows. >Um. Who thought this?…

I kid you not. Stallman looked crazy in my eyes before Snowden. Even my "paranoid" perspective on all these things pre-snowden where never close to true Stallman "crazy" (or so I thought before..) Now I want to use Emacs. I want to use everything FSF if possible. I'm no where close. There is a lot for me to do to get there. But I'm hoping I will because soon that may be our only hope. > NSA's James Clapper lied to Ro…

Yes, Free software is not only your security but an investment in everyones security, rich or poor for generations to come.

Re: Edward Snowden: The Internet Is Broken

#87
post #15

Excellect! It's the most cogent analysis that I've seen from him. Damn, what a fucking hero! A few comments, however ... > ... we had to go to the dark side to be able to confront the threat posed by bad guys. We had to adopt their methods for ourselves. He's using "we" there in reference to the government. But it can also be read with "we" as you and me, and "bad guys" as the government ;) But then, I claim a broad…

> ve has lots of vis personas

Are those typos?

You touched on the cyperpunk fantasy: using multiple online identities, all kept carefully separate from each other and from your real identity. (There's an excellent short story called True Names that explores this idea.)

For the majority of ordinary, nontechnical people, there are lots of simpler solutions.

* Use cash. In Berlin, many ordinary people have an awareness of and distaste for government surveillance. People remember East Germany. One result is that lots of people will just pay for everything in cash. In most other western countries, the norm is to leave an electronic trail of every single shop you visit.

* Use Signal or WhatsApp. WhatsApp rolled out strong end to end encryption to a billion people--most of whom have no idea what a "key" is and only the faintest sense of what "encryption" means.

The lesson I take from those projects is that whenever we can ship transparent, easy to use encryption that our users dont have to worry about, its a massive win.

If your app allows users to talk to each other privately, consider adding E2E encryption. It's the future.

If your app has some kind of cloud backup, like a password manager or a photo app, make sure that it's encrypted with a key that you don't have access to.

E2E comes with product tradeoffs. You may have to charge your users money, because you cant target ads against data you cant access. You'll need to make an installed app rather than a webapp. But its worth it -- and I think someday, hopefully soon, users will demand it.

Re: Edward Snowden: The Internet Is Broken

#88
post #56

Earlier quoted context omitted.

For as long as technologically minded folks insist on technological solutions to political problems, we will be stuck in this quagmire. The answer is a political solution to a political problem. Admittedly, that's a hard one for some folks. It requires talking to people and building relationships. It takes a long time and change can be frustratingly slow to present itself. But that's how it is. Trust no one With this…

There has never, in my life, been a time that the government and the people they work for/represent/are have ever been more adversarial. When you realize government has stopped working for you and are actively treating you like a criminal, you ask who they are working for. It's hard not to land on banks, corporations, and Bernie's "Billionaire Class" - whether that's true or not isn't part of my point. So it's hard t…

Trust isn't a binary thing. I trust different people; different organisations, with different data, information and details about my life and other peoples lives.

Re: Edward Snowden: The Internet Is Broken

#89

Earlier quoted context omitted.

Just like VPNs, proxies and abuse tolerant networks. If you can't prevent the spam by other means than IP blocking then maybe you should make your website read-only.

Or just block the sources of abuse while everyone else enjoys and can act on the content. Or just block comments from anonymous nets so they can at least read. Comment sections that are Wild West hurt branding too much for it to be an option.

It seems like we know how to solve this. Put a CAPTCHA on account creation, then allow users to flag posts and auto-ban fresh accounts with high flag rates.

I'm honestly kind of surprised that there isn't more spam from attackers who compromise something close enough to a backbone provider that they can spoof arbitrary IP addresses and still see the return traffic.

Re: Edward Snowden: The Internet Is Broken

#90

The EFF warned long ago something was going on when AT&T was putting beam splitters on Internet backbones to feed the NSA. Then Snowden revealed how everything is tapped. Then, be sure all mainstream encryption is "NOBUS". Nothing is truly random. Someone somewhere has the master key: elliptic curve cryptography using magic numbers from NIST? "Secure boot" by Intel? OpenSSL? Microsoft software? All backdoored. Trust…

I wish there was some kind of map showing where each area (hardware, software/firmware, network, yada yada) is compromised and by which initiatives and companies. With solid info (avoid speculation). Just curious if would make any impact if the regular user see how their data and everything else is treated by the companies they think they "know" and "trust".
Post reply on HN