Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

41–50 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#42
post #39

I am highly skeptical of any claim that an email provider is more private than other providers. E-mail is fundamentally not secure and not private, unless you enhance it with PGP, which requires you to, of course, have something you want private. Most people don't encrypt because they're not scared enough. It usually takes some time before their wordlview is repeatedly shattered enough that encryption is the only cho…

> E-mail is fundamentally not secure and not private, unless you enhance it with PGP, which requires you to, of course, have something you want private.

That's not true. A friend and I use GPG just to use GPG. You don't have to want to keep something private, just like you don't need to be doing illegal things to want curtains on your house.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#43
post #33

Speaking for myself, this was brought to my attention in the context of a developing story about WikiLeaks being under duress or Julian Assange missing, who has not sent direct communication let alone signed communication for around a month now. EDIT - if curious, https://www.reddit.com/r/WhereIsAssange/

I'm trying to spread the word. Please post a proof-of-life of yourself today somewhere on the internet. http://imgur.com/9Gn8tRr

Sorry, I don't understand this. It's incredibly bizarre to be posting selfies with messages on HN.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#44
October 23:

"If you are doing certificate pinning with us, we are updating certs! so keep calm and check the new FPs here https://riseup.net/en/security/network-security/certificates …"

https://twitter.com/riseupnet/status/790245677234282496

Updated fingerprints (PGP signed Oct 22):

https://riseup.net/security/network-security/certificates/ri...

Edit:

See OP below restating that fingerprints for certain subdomains are what is missing. Should have read more closely ;)

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#45
post #29

Earlier quoted context omitted.

I certainly have no clue. I'm still getting email :) And they've had indirect FBI attention before: https://riseup.net/en/about-us/press/fbi-seizes-anonymous-re...

> I'm still getting email :) The failure mode of their warrant canary is not that you stop getting email, but that other people start getting your email too.

Sure. But you see, the prudent assumption is that adversaries always get all your email :)

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#46

October 23: "If you are doing certificate pinning with us, we are updating certs! so keep calm and check the new FPs here https://riseup.net/en/security/network-security/certificates …" https://twitter.com/riseupnet/status/790245677234282496 Updated fingerprints (PGP signed Oct 22): https://riseup.net/security/network-security/certificates/ri... Edit: See OP below restating that fingerprints for certain subdomains ar…

Yes I linked to the current certs in the post text. The issue is with the domains that were deleted in the commit (also linked) which no longer appear in these links.

Black, labs, and a few others have their own certificate that no longer can be verified with fingerprints, since Oct 22nd.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#47
post #3

And from riseup.net @riseupnet listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don't listen to me. #LeonardCohen https://twitter.com/riseupnet/status/797142735283257345

That was probably just commemorating Leonard Cohen's death, and the certificate fingerprints were probably just removed because they switched to Let's Encrypt for those domains. But you never know.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#48

Earlier quoted context omitted.

Got any references to anyone speaking a foy-uh out loud? Ive only ever know it to be 4 letters, said discretely, and not as a word like SQL.

I would cringe when I would hear pronounced acronyms like "sequel" and "scuzzy" (SQL and SCSI) back in college; some acronyms simply aren't meant to be pronounced as words, especially if the pronounced word gave an uninformed listener the wrong impression. "Eww, why does my computer need to be scuzzy??"

Though note that:

> It was initially called “Structured English Query Language” (SEQUEL) and pronounced “sequel”, though it later had to have its name shortened to “Structured Query Language” (SQL) due to trademark issues.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#49
post #39

I am highly skeptical of any claim that an email provider is more private than other providers. E-mail is fundamentally not secure and not private, unless you enhance it with PGP, which requires you to, of course, have something you want private. Most people don't encrypt because they're not scared enough. It usually takes some time before their wordlview is repeatedly shattered enough that encryption is the only cho…

The parent statement is very misleading. Here are some significant differentiators between email providers:

* Encryption in transmission emails sent and received, using SSL/TLS

* Encryption in transmission of webmail sessions, using HTTPS

* Authentication security: Do they use 2 factor or other tech?

* Logging and retention of logs

* Reading your mail to build marketing profiles and social graphs

* Access by employees to your data

* Retaining and sharing your personal data with other businesses

* Security of your account information; can they easily be persuaded to surrender it

* Security of the email provider's systems

* Responsiveness to 3rd party requests for your information, whether private parties in lawsuits or legal authorities with/without warrants

* Cooperation with government surveillance dragnets

Security always is a matter of degree. Email will never be perfectly secure but there are some big differences between providers.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#50

Speaking for myself, this was brought to my attention in the context of a developing story about WikiLeaks being under duress or Julian Assange missing, who has not sent direct communication let alone signed communication for around a month now. EDIT - if curious, https://www.reddit.com/r/WhereIsAssange/

Are you aware that the current top post (about blockchain) reads like a parody of a conspiracy theory?
Post reply on HN