Live data from Hacker News

Edward Snowden: The Internet Is Broken

popsci.com

91–100 of 180 posts

Re: Edward Snowden: The Internet Is Broken

#91
post #80

He's still not getting it or fully recommending it any more than most have. The funny thing is that I recently read a 150 page interview with one of founders of INFOSEC, Dr Schell, that showed his employer was the same way: ignored "COMPUSEC" as useless in favor of "COMSEC" solutions to all security problems. Schell, Karger, and Anderson's tiger teams smashed every mainframe and crypto using system put in front of th…

I agree that software bugs are a bigger concern than encrypting everything. I think the problem is that not many people are starting companies around "high assurance." How do you get people to turn their PL research into startups?

Galois Inc is a perfect example of one that continually makes money on high-assurance R&D some of which they open-source. Others spin it off into useful commercial tools. INRIA has done that with Astree Analyzer for C. Other times they can just make the tools practical and available for a community that will then build on them alongside their students. INRIA w/ Ocaml and Coq come to mind again.

So, that's one route.

Re: Edward Snowden: The Internet Is Broken

#92
post #72

Earlier quoted context omitted.

The U.S. government invented INFOSEC and funded most tech (security or otherwise) that you depend on. So what. It's the specific tech or actions that matter rather than who funds them. At worst, you increase scrutiny or consider subversion issues. Of course, high assurance is specifically designed to counter that. So, people worried about subversion should be using this stuff more than anyone. Btw, here's two things…

Cryptol is a nice tool, but it can't eliminate most important crypto bugs (for example, the sorts of bugs found in OpenSSL). It's useful for proving things about bit-mixy crypto code like AES, SHA, etc, but that code rarely has bugs (due to known-answer tests).

Well, it actually shouldn't introduce most of the bugs you find in OpenSSL. Plus, you don't use it alone. It works like this:

1. Cryptographers come up with the algorithms and protocols with their mathematical proofs applied to their properties.

2. Someone uses tools like CRYPTOL for algorithms or AnBx for protocols to generate the code.

http://www.dsi.unive.it/~modesti/anbx/

3. The code is run through visual inspections, static analysis tools like ASTREE or SPARK, tests, covert channel analysis, and so on. Modified if problems are found.

4. An optimizing version of a certified compiler like CompCert produces the object code.

5. It's distributed with public key cryptography and/or Merkle Signatures if people don't trust that. There's modern versions with efficient or unlimited signing.

6. Optionally, a subversion-resistant process builds the fist compiler and checkers in stages.

Re: Edward Snowden: The Internet Is Broken

#93

Earlier quoted context omitted.

Or just block the sources of abuse while everyone else enjoys and can act on the content. Or just block comments from anonymous nets so they can at least read. Comment sections that are Wild West hurt branding too much for it to be an option.

It seems like we know how to solve this. Put a CAPTCHA on account creation, then allow users to flag posts and auto-ban fresh accounts with high flag rates. I'm honestly kind of surprised that there isn't more spam from attackers who compromise something close enough to a backbone provider that they can spoof arbitrary IP addresses and still see the return traffic.

Those are possibilities. As is Disqus-style moderation. Nonetheless, it's a lot of extra work with nothing to show for it and possibly dangerous to site experience. That's the problem Tor poses.

Re: Edward Snowden: The Internet Is Broken

#94

Earlier quoted context omitted.

Just possibly old versions of truecrypt. This author's conclusions seem quite sound to me. They collapsed it in a way to comply with a gag order while silently sounding an alarm. https://forum.truecrypt.ch/t/my-analysis-of-what-really-happ... Anyone operating in this space is eventually going to get the same option as Lavabit's founder: compromise or collapse.

If you're super paranoid you shouldn't trust any version of truecrypt. Read the fascinating story of Paul Le Roux... https://mastermind.atavist.com/ He created E4M (which truecrypt was based on) and is rumored to have been one of the creators of truecrypt. Apparently he's also been a US government asset for a while.

So what? Snowden even said that Truecrypt was one of the only tools that currently the NSA could not defeat. I'd rather trust him on that than your opinion on the matter.

Re: Edward Snowden: The Internet Is Broken

#95
post #50

Earlier quoted context omitted.

Definitely. They could, targets were using it, they were known to tap backhaul microwaves/satellites, their own guideance in high-assurance side was using link encryptors between sites, its in their commercial recommendations (NIPSOM Industrial Security Manual), and so on. Everything in the world to make you think somebody was tapping your line and that they might. So, some groups that were wise went ahead and deploy…

Google's datacenter-to-datacenter links probably weren't going over the public internet, so they didn't feel the need to protect against man-in-the-middle attacks on physical lines that they owned. If you connected two computers to each other with a cross-over cable, would you feel the need to encrypt all communications between them, just in case?

> If you connected two computers to each other with a cross-over cable, would you feel the need to encrypt all communications between them, just in case?

If I cared about privacy and I couldn't control physical access to the cable? Yes, of course.

Re: Edward Snowden: The Internet Is Broken

#96
post #87
post #15

Excellect! It's the most cogent analysis that I've seen from him. Damn, what a fucking hero! A few comments, however ... > ... we had to go to the dark side to be able to confront the threat posed by bad guys. We had to adopt their methods for ourselves. He's using "we" there in reference to the government. But it can also be read with "we" as you and me, and "bad guys" as the government ;) But then, I claim a broad…

> ve has lots of vis personas Are those typos? You touched on the cyperpunk fantasy: using multiple online identities, all kept carefully separate from each other and from your real identity. (There's an excellent short story called True Names that explores this idea.) For the majority of ordinary, nontechnical people, there are lots of simpler solutions. * Use cash. In Berlin, many ordinary people have an awareness…

You can't E2E with a web app?

Re: Edward Snowden: The Internet Is Broken

#97

Earlier quoted context omitted.

Questioning the narrative is fine. I for one think he's a combo of whistleblower and traitir, hero and coward depending on what leaks and actions we're talking about. Yet, to think NSA or US did it intdntionally is beyond all reason. Snowden set back so many goal posts for US intelligence, LEO's, and industry that it's impossible thaf it was intentional by USG.

One thing is for sure. The CIA could have killed him, could kill him now, if he truly posed a threat to national security. The fact that they don't indicates they don't feel he is a threat. I'm confident that whatever goal posts you claim Snowden set back, I can explain as ultimatley serving US interests. That's the barometer. Has he hurt US Interests? Seems US interests are doing fine to me. Would things be better i…

They can't kill him now. Assassination would risk public backlash way beyond anything he could say.

Re: Edward Snowden: The Internet Is Broken

#98
post #87
post #15

Excellect! It's the most cogent analysis that I've seen from him. Damn, what a fucking hero! A few comments, however ... > ... we had to go to the dark side to be able to confront the threat posed by bad guys. We had to adopt their methods for ourselves. He's using "we" there in reference to the government. But it can also be read with "we" as you and me, and "bad guys" as the government ;) But then, I claim a broad…

> ve has lots of vis personas Are those typos? You touched on the cyperpunk fantasy: using multiple online identities, all kept carefully separate from each other and from your real identity. (There's an excellent short story called True Names that explores this idea.) For the majority of ordinary, nontechnical people, there are lots of simpler solutions. * Use cash. In Berlin, many ordinary people have an awareness…

No, they're gender-neutral pronouns:

ve = she/he

ver = him/her

vis = hers/his

I encountered them in Greg Egan's Diaspora.

And yes, True Names :) An inspiration.

With a decent host machine, one can run numerous Whonix instances, each with one or more personas. They can be long-term or throwaway.

I do nothing at all private on smartphones. Signal and WhatsApp are cool and all, but radios are untrustable black boxes. Even if the data is secured at rest.

Edit: In Egan's Diaspora, one of the protagonists is a software-generated entity, which literally has no gender. In my case, I'm referring to invented personas, which have whatever gender I fancy.

Re: Edward Snowden: The Internet Is Broken

#99
post #56

Earlier quoted context omitted.

For as long as technologically minded folks insist on technological solutions to political problems, we will be stuck in this quagmire. The answer is a political solution to a political problem. Admittedly, that's a hard one for some folks. It requires talking to people and building relationships. It takes a long time and change can be frustratingly slow to present itself. But that's how it is. Trust no one With this…

There has never, in my life, been a time that the government and the people they work for/represent/are have ever been more adversarial. When you realize government has stopped working for you and are actively treating you like a criminal, you ask who they are working for. It's hard not to land on banks, corporations, and Bernie's "Billionaire Class" - whether that's true or not isn't part of my point. So it's hard t…

I didn't say "trust government", I said "trust people". Do you trust your neighbours? Do you attend meetings or organizations with like-minded people? The surveillance state is most powerful when everybody sits at home afraid to go out. If you get out in public and organize with people and talk about these issues, you'll find strength and courage in your neighbours.

The #1 goal of the Neoliberal elite class is to crush the will of people like you. If you've already given up then you might as well be dead to them; they don't even need to spy on you at that point! If, on the other hand, you're out in public and organizing in large numbers then what can they do? You can force them to engage with the issues on your terms.

Re: Edward Snowden: The Internet Is Broken

#100
post #98
post #87

Earlier quoted context omitted.

> ve has lots of vis personas Are those typos? You touched on the cyperpunk fantasy: using multiple online identities, all kept carefully separate from each other and from your real identity. (There's an excellent short story called True Names that explores this idea.) For the majority of ordinary, nontechnical people, there are lots of simpler solutions. * Use cash. In Berlin, many ordinary people have an awareness…

No, they're gender-neutral pronouns: ve = she/he ver = him/her vis = hers/his I encountered them in Greg Egan's Diaspora . And yes, True Names :) An inspiration. With a decent host machine, one can run numerous Whonix instances, each with one or more personas. They can be long-term or throwaway. I do nothing at all private on smartphones. Signal and WhatsApp are cool and all, but radios are untrustable black boxes. E…

sigh more of that sjw crap. Hope it doesn't infest this place like it has a significant portion of the net. It's utterly detestable.
Post reply on HN