Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

51–60 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#51
post #39

I am highly skeptical of any claim that an email provider is more private than other providers. E-mail is fundamentally not secure and not private, unless you enhance it with PGP, which requires you to, of course, have something you want private. Most people don't encrypt because they're not scared enough. It usually takes some time before their wordlview is repeatedly shattered enough that encryption is the only cho…

> E-mail is fundamentally not secure and not private, unless you enhance it with PGP, which requires you to, of course, have something you want private. That's not true. A friend and I use GPG just to use GPG. You don't have to want to keep something private, just like you don't need to be doing illegal things to want curtains on your house.

Thanks for clarifying. I have to remember this quote:

"If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged"

What I mean is that I can decide to not encrypt and have my emails under public scrutiny, but as I said, most people are not scared enough because it doesn't happen on their watch.

It doesn't matter what the content is, or how non-libelous - if it's encrypted with PGP, it's private.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#54

Earlier quoted context omitted.

Got any references to anyone speaking a foy-uh out loud? Ive only ever know it to be 4 letters, said discretely, and not as a word like SQL.

I've only heard "foya", and I find "sequel" for "SQL" to grate like nails on a chalkboard. YMMV!

I'm now imagining that's pronounced Yim-Vee!

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#55
post #50

Speaking for myself, this was brought to my attention in the context of a developing story about WikiLeaks being under duress or Julian Assange missing, who has not sent direct communication let alone signed communication for around a month now. EDIT - if curious, https://www.reddit.com/r/WhereIsAssange/

Are you aware that the current top post (about blockchain) reads like a parody of a conspiracy theory?

Yep that doesn't look too good. Iirc there was more reasonable discussion on r/bitcoin. They have used the blockchain in the past, I will say that.

Without trying to turn this thread into a full "Where is Assange?" discussion, for me I just can't imagine why he has not sent communication since mid October, now long after the election, especially since the chorus is now strong enough that their Twitter has to say "everyone relax." He usually sees a lot of visitors, and they have access to millions of dollars, so he certainly has various ways to connect to the Internet just to say "I'm fine."

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#56
post #47
post #3

And from riseup.net @riseupnet listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don't listen to me. #LeonardCohen https://twitter.com/riseupnet/status/797142735283257345

That was probably just commemorating Leonard Cohen's death, and the certificate fingerprints were probably just removed because they switched to Let's Encrypt for those domains. But you never know.

OK, good point.

This could just be drama.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#57
post #39

I am highly skeptical of any claim that an email provider is more private than other providers. E-mail is fundamentally not secure and not private, unless you enhance it with PGP, which requires you to, of course, have something you want private. Most people don't encrypt because they're not scared enough. It usually takes some time before their wordlview is repeatedly shattered enough that encryption is the only cho…

The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and received, using SSL/TLS * Encryption in transmission of webmail sessions, using HTTPS * Authentication security: Do they use 2 factor or other tech? * Logging and retention of logs * Reading your mail to build marketing profiles and social graphs * Access by employee…

> Authentication security: Do they use 2 factor or other tech?

Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies.

For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not.

I can understand that 2FA does have its uses, but frequently I'm seeing it being used like those 'Secured by Comodo SSL' with a picture of a shield to make a would-be shopper feel like the transaction is more secure. It can be theater.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#58

I'm uninformed. What is the significance of riseup.net?

I remember it being used a lot by radical leftist (mostly anarcho-*) groups when I was at university. But even then it was basically assumed that riseup was infiltrated or a honeypot run by the feds.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#59
post #3

And from riseup.net @riseupnet listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don't listen to me. #LeonardCohen https://twitter.com/riseupnet/status/797142735283257345

A beautiful quote. A nice picture. Also worth seeing the previous two messages there made on the same day while also thinking about the hummingbird.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#60
post #57

Earlier quoted context omitted.

The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and received, using SSL/TLS * Encryption in transmission of webmail sessions, using HTTPS * Authentication security: Do they use 2 factor or other tech? * Logging and retention of logs * Reading your mail to build marketing profiles and social graphs * Access by employee…

> Authentication security: Do they use 2 factor or other tech? Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies. For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not…

2FA is generally effective but not enough to guarantee security by itself.
Post reply on HN