Live data from Hacker News

Edward Snowden: The Internet Is Broken

popsci.com

171–180 of 180 posts

Re: Edward Snowden: The Internet Is Broken

#171
post #142

Earlier quoted context omitted.

>>You want a Donald Trump nominating one of his cronies at the head of the US intelligence services and starting to dig into untold amounts of already-recorded communications? Still a Donald Trump in USA is far better and very less dangerous as compared to the tyrants like Mao or Stalin or Castro, because USA has many good checks and balances in place. I do appreciate people's fears about state becoming tyrannical bu…

> Still a Donald Trump in USA is far better and very less dangerous as compared to the tyrants like Mao or Stalin or Castro, because USA has many good checks and balances in place. How do you think Hoover stayed in place that long? You can pull a great many things without needing to disappear people at four in the morning. > The important point to note here is that the intellectuals (Snowden and his supporters) who a…

>>How do you think Hoover stayed in place that long? You can pull a great many things without needing to disappear people at four in the morning.

Still Hoover or whoever in USA is no match for Mao or Stalin or Castro as far as their potential to inflict torture and control over their citizens is concerned. A president in US cannot be a president for his entire life, it's only 8 years max (that too if people wanted him/her to be).

While in Cuba we can see Castro remained in power until he couldn't move his body even so much and then also he put his crony (his brother) in power. That is dangerous and worrisome.

>>While Putin is certainly more willing to suppress political opponents, I doubt the Russian surveillance network is even remotely in the same league as the NSA.

The way Putin and his cronies suppressed homosexuals in Russia sends chills down the spines of free thinkers.

In short, with your neighbours and even family members spying on each other and reporting to Putin's people, you don't need sophisticated surveillance network in the first place.

In USA, the situation is far, far better than what the Snowdens and their supporters are trying to portray.

Re: Edward Snowden: The Internet Is Broken

#173
post #171

Earlier quoted context omitted.

> Still a Donald Trump in USA is far better and very less dangerous as compared to the tyrants like Mao or Stalin or Castro, because USA has many good checks and balances in place. How do you think Hoover stayed in place that long? You can pull a great many things without needing to disappear people at four in the morning. > The important point to note here is that the intellectuals (Snowden and his supporters) who a…

>>How do you think Hoover stayed in place that long? You can pull a great many things without needing to disappear people at four in the morning. Still Hoover or whoever in USA is no match for Mao or Stalin or Castro as far as their potential to inflict torture and control over their citizens is concerned. A president in US cannot be a president for his entire life, it's only 8 years max (that too if people wanted hi…

See [1] also

[1] https://en.wikipedia.org/wiki/LGBT_rights_in_Russia

Re: Edward Snowden: The Internet Is Broken

#174

Earlier quoted context omitted.

You need both. Technology alone cannot solve political problems. The technology can be banned. Technology can, however, raise the difficulty for sub-components of a government that are wanting to push the limits and do things outside the boundaries of the politically agreed upon systems. Encryption can't stop the NSA if it has widespread political support because the encryption can be banned. But right now intelligen…

Governments can ban anything they like but the ban doesn't mean much if they cannot feasibly enforce it. Such is the lesson of the War on Drugs: the government comes in and makes trouble for people from time to time, but otherwise they simply haven't got a clue, and for the most part people just live their lives as they please and ignore the laws they don't agree with. I'm glad there are people fighting the political…

Yes, but that's why strong encryption is such a strong force to stop them. They operate outside the political sphere at the moment. It's questionable how long that can last.

A war on encryption would be much easier to enforce than a war on drugs because there are such fewer sources, and there's not a big market for its use.

Re: Edward Snowden: The Internet Is Broken

#175

Earlier quoted context omitted.

You're falling victim to the same trap as what Snowden is talking about. Serial numbers on bills are routinely scanned and tracked. There's a discussion here: https://www.reddit.com/r/explainlikeimfive/comments/3ou4h4/e... It's not done at the point of sale. It's done when the money is returned to the banks themselves, and when they're dispensed at ATMs. Cash doesn't circulate for long and anti-money laundering laws…

Yes, and that's problematic for mailing cash anonymously. It's not so easy to accumulate large denominations, and may attract attention. When possible, I like to mail gold. It's easy to clean, too.

We need people operating mixes for cash and SIM cards.

Dump $50, get a random bunch of notes that add up to $50.

Dump a prepaid SIM, get a new prepaid SIM.

Re: Edward Snowden: The Internet Is Broken

#176

Earlier quoted context omitted.

The problem isn't unique to Tor. It's anything that allows a spammer to use the same IP address as innocent people, including things that aren't exactly legal, like compromised PCs and routers. Which means blocking Tor blocks the people who follow the law but not the people who break the law. And the problem is going to get worse as a result of IPv4 address exhaustion because some ISPs are going to have to start usin…

"The problem isn't unique to Tor. It's anything that allows a spammer to use the same IP address as innocent people, including things that aren't exactly legal, like compromised PCs and routers. " That's sort of true. It's technically true that any I.P. address might be the source of malice. Yet, Tor's I.P. addresses will steadily be the source of a ton of malice with no resolution of that problem. Quite different th…

> It's technically true that any I.P. address might be the source of malice. Yet, Tor's I.P. addresses will steadily be the source of a ton of malice with no resolution of that problem.

Which makes blocking Tor seem attractive until you still need some defense against the attacks from arbitrary other IP addresses, and once you have those defenses you can use them against malicious Tor traffic and no longer need to block its legitimate users.

> Good call. I saw this coming. There were already talks by Ross Anderson IIRC about how critical it was for forensics to get the port number and time-stamp since CG-NAT would make I.P.'s useless. Already is in some areas.

And even then it's assuming the carrier has port-level logs to compare against. If you have ten million customers who on average make one connection every ten seconds and a connection log entry is 50 bytes then you're writing 50MB/sec of log entries, i.e. >4TB/day. If they keep them at all it's not going to be for very long.

It seems like it would be a lot easier to move identities to some kind of proof of work based pseudonyms than to keep trying to force IP addresses to serve a role they were never designed for and the casting into of which causes no small amount of collateral damage.

> I'm more worried about the routing tables, though, if IPv6 got massive surge of traffic. Never looked to see if they fixed early concerns about how well Tier 1-3 HW would handle it vs IPv4.

Part of it is that IPv6 addresses are allocated in larger blocks, which means less address space fragmentation because nobody runs out and has to come back for another non-contiguous block, which means more addresses per routing table entry. And the rest of it is that memory is cheaper than it used to be.

Re: Edward Snowden: The Internet Is Broken

#177

Earlier quoted context omitted.

"The problem isn't unique to Tor. It's anything that allows a spammer to use the same IP address as innocent people, including things that aren't exactly legal, like compromised PCs and routers. " That's sort of true. It's technically true that any I.P. address might be the source of malice. Yet, Tor's I.P. addresses will steadily be the source of a ton of malice with no resolution of that problem. Quite different th…

> It's technically true that any I.P. address might be the source of malice. Yet, Tor's I.P. addresses will steadily be the source of a ton of malice with no resolution of that problem. Which makes blocking Tor seem attractive until you still need some defense against the attacks from arbitrary other IP addresses, and once you have those defenses you can use them against malicious Tor traffic and no longer need to bl…

"and once you have those defenses you can use them against malicious Tor traffic and no longer need to block its legitimate users."

What's your recommendation for a low-cost, low-effort method that solves the Tor and every other I.P. user problem? It has to provide a reduction just as good as blocking Tor with similar effort by admin.

Re: Edward Snowden: The Internet Is Broken

#178

"police and the government then have the authority to search through your entire life in your pocket just because you are pulled over for a broken taillight" This is the classic Snowden formula. Establish a false premise that has no faith in the government or constitutional rights, then continue to paint a picture of a dystopian future. This guy should be writing sci-fi novels... [edit: I predicted at least 5 down vo…

What is the false premise? Why do you think 'faith' is required in a logical argument? What future?

"Cops Need a Warrant Event Just To Look At The Screen"

http://motherboard.vice.com/read/court-cops-need-a-warrant-t...

Seriously.... don't fall prey to Snowden's scare tactics.

US law enforcement cannot physically take your smartphone without cause, much less even look at it.

Re: Edward Snowden: The Internet Is Broken

#179
post #83

Earlier quoted context omitted.

Fair point and well preempted. Proprietary software can offer some freedom but it does not ensure it will remain, nor does it offer the full 4 freedoms required. What you say is not technically incorrect, but practically Google, Apple & Microsoft were all secretly in NSA's PRISM. A large corporate entity is subject to state pressure in a different way than a public good. A corporation must profit, new markets must be…

"Ownership is a single point of failure." Ownership can be a single point of failure but someone owns copyright to GPL code, too. Trick is protections in licensing. A recent conversation found that the real issue, if you get down to it, is in distribution: free distribution and network effects is strongest benefit of FOSS over proprietary, shared-source model which may have every other benefit. "A proper security aud…

While you are technically not incorrect in your points, you also miss the entire point: if you can take it from me tomorrow I am not free. Paraphrasing Whedon "You can backdoor Google & surveil the net but you can't take my GNU PGP from me."

Your 'Network Effects and free distribution' are benefits of the efficiencies of freedom. But paltry when it comes to legal freedoms in the face of tyranny, the topic of this post-Snowden thread.

A Good Monarch or Wise & Benificent Dictator is a great form of government and historically golden ages & enlightenments record this. It is not the 'do no evil' CEOs, or good kings but those that might follow that Free Software offers legal protection against.

GPL is public domain 2.0, not a poor tragic commons starved by ever extending legal protectionisms or over grazing and undersharing.

Technically you are right, a company could stand up for our rights, but they didn't recently and they had to keep it secret. Discretionary, temporary freedom is illusory - it vanished when needed most. Like the constitution of a democracy the GPL seeks to enshrine natural rights in law. Like Democracy it must be actively defended and abuses policed. The GPL ensures freedom cannot be taken back easily, it is a legal hack that protects itself and the 4 freedoms with copyright.

Historically it revitalised the public domain in the software sphere and practically protected it against decades of well funded attacks and FUD - creating billions of dollars in value that didn't mainly go to rent-seeking intellectual landowners but developers and users.

Yes, your proprietary shared source model has given some freedoms & verifiability; Snowden shows how illusionly this was. The four freedoms: to Run, Compile, Modify & Share are all needed to ensure (not merely offer or promise) continued freedom.

FOSS & Shared source are one thing; Free GPL Software is quite another.

Is CVE french for FUD ? Because this is nonesense, security is an arms race. Under a panopticon even TOR is weak. Since Snowden millions have been spent & volunteered auditing, patching & shoring up our commerce & the individual against state level actors & fifth column code. Pre-Snowden no-one imagined the elliptic curves were a lie or our own governments funded & coerced weaknesses into ssh - freedom is playing catchup. Our own governments paid to make us all vulnerable to intrusion. Everyone technical was dumbfounded at the scale of the hidden betrayal of trust.

Security by obscurity & secrecy is weak. Published source alone is not free nor verifiably safe, the distributed binary's hash and compiled binaries hash may coincide but malicious code hash collisions are trivial for states to produce. Your scenario offers hypothetical freedom but Snowden's slides show backdoor concealement is actively pursued by states coercing companies, e.g. Lavabit CEO (and noone knows how many who merely complied and distributed the backdoored binaries rather than face jail.) Furthermore if the toolchain isn't free the Ken Thompson backdooring compiler hack applies.

GPL is owned by all. Coders retain their personal copyrights - that is its genius not a quibble. Again if you can't make a change you alone believe is necessary or receive it from & share it with with your community yous aren't free. GPL forks ensure every party has the same rights. Owners & Licensee's legal asymmetry can & has prevented this. Forking requires all 4 freedoms.

Yes GPL can license crap & democracies have elected theocracies & dictatorships. Magna Carta states If the Executive is not subject to the rule of law, it is nothing less than tyranny.

In final answer I quote Vonnegut & Churchill who both witnessed true horror: "So it goes. All is Foma.", & “Democracy is the worst form of government, except for all the others”

Re: Edward Snowden: The Internet Is Broken

#180

Earlier quoted context omitted.

> It's technically true that any I.P. address might be the source of malice. Yet, Tor's I.P. addresses will steadily be the source of a ton of malice with no resolution of that problem. Which makes blocking Tor seem attractive until you still need some defense against the attacks from arbitrary other IP addresses, and once you have those defenses you can use them against malicious Tor traffic and no longer need to bl…

"and once you have those defenses you can use them against malicious Tor traffic and no longer need to block its legitimate users." What's your recommendation for a low-cost, low-effort method that solves the Tor and every other I.P. user problem? It has to provide a reduction just as good as blocking Tor with similar effort by admin.

> What's your recommendation for a low-cost, low-effort method that solves the Tor and every other I.P. user problem?

The first step is realizing that you have a behavior problem, not an IP address problem. There is no silver bullet against an adaptive adversary, but this is the sort of thing that proof of stake or proof of work is well suited for. If the user wants to do more than read your website then they need to post some collateral. In the small time case this is just putting a CAPTCHA on account creation. If you're a bank or something then nobody gets in the door unless they have an account with you which has been verified against their government ID etc.

Then anybody who misbehaves forfeits their collateral, i.e. you close their account. Which for normal people never happens, but for malicious parties is designed to happen before the profit from their malice exceeds the value of the collateral. Spammers aren't going to be willing to solve CAPTCHAs all day just to post one message at a time which will be deleted in twenty minutes.

And then the administrative cost disappears because the spammers realize it isn't worth doing and you don't have to spend time deleting spam once they stop posting it.

> It has to provide a reduction just as good as blocking Tor with similar effort by admin.

To which a large point is that blocking Tor isn't particularly effective. People make a lot of noise about the fact that a Tor IP address is some large factor more likely than average to have malicious traffic, but it also represents a larger number of people than most IP addresses. If you look instead at the percentage of all malicious traffic that comes from Tor, it's a minority.

And even allowing Tor traffic and then trying to measure what percentage of all malicious traffic is from Tor is over-representing the effectiveness of blocking Tor by counting malicious traffic that comes from Tor if you allow it but would still come from somewhere else if you didn't.

Net result being that blocking Tor might get you something like a single digit reduction in malicious traffic. Now you need to do something about the other 90%. CAPTCHAs and pseudonym reputation systems and so on. But those things work about as well against traffic from Tor as traffic from anywhere else, which cuts a nice chunk out of the remaining single digit percentage improvement you had been getting by blocking Tor.

Net result is you end up blocking a lot of innocent people to get something like a 2% overall reduction in malicious traffic. And the better you get at solving the problem in other ways, the smaller the benefit of blacklisting IP addresses becomes.

Post reply on HN