Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

61–70 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#61
post #56
post #47

Earlier quoted context omitted.

That was probably just commemorating Leonard Cohen's death, and the certificate fingerprints were probably just removed because they switched to Let's Encrypt for those domains. But you never know.

OK, good point. This could just be drama.

Maybe it's worth checking their feed before writing?

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#62

If you care enough to post canaries, shouldn't you also care enough to just close shop instead of subtly telling your users to stop using your services?

I'd imagine that since lavabit NSLs make that harder if not illegal.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#63
post #57

Earlier quoted context omitted.

The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and received, using SSL/TLS * Encryption in transmission of webmail sessions, using HTTPS * Authentication security: Do they use 2 factor or other tech? * Logging and retention of logs * Reading your mail to build marketing profiles and social graphs * Access by employee…

> Authentication security: Do they use 2 factor or other tech? Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies. For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not…

It doesn't help a system-level adversary, but it does help prevent trivial takeovers by malicious actors attempting to get access to your email as a vector to compromise other services.

To summarize, 2FA does not prevent email reading if the provider doesn't, however it does help prevent run of the mill takeovers, especially if you've reused a password somewhere.

Security is all about defense in depth, it's worth keeping in mind that 2FA is an important step there, but by no means the only one.

If you aren't encrypting+signing a message, you've already decided that security requirements of that particular message is minimal.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#64

Speaking for myself, this was brought to my attention in the context of a developing story about WikiLeaks being under duress or Julian Assange missing, who has not sent direct communication let alone signed communication for around a month now. EDIT - if curious, https://www.reddit.com/r/WhereIsAssange/

it's well known that his internet is cut off. I think if somebody was sending communications with his signing key while he is known to be unable to communicate, that would be the real problem.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#66
post #57

Earlier quoted context omitted.

The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and received, using SSL/TLS * Encryption in transmission of webmail sessions, using HTTPS * Authentication security: Do they use 2 factor or other tech? * Logging and retention of logs * Reading your mail to build marketing profiles and social graphs * Access by employee…

> Authentication security: Do they use 2 factor or other tech? Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies. For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not…

That's like arguing that an airbag is safety theater because it doesn't prevent drowning if you drive off of a bridge.

MFA is used to prevent a third-party who has access to your credentials from being able to login as you and, in the case of U2F, to prevent a successful phishing attempt from compromising your account.

MFA offers no, and never has been billed as, protection against a subverted server or an attacker who can decrypt or tamper with traffic on the wire.

Security is a large, complicated problem. There will never be a single measure which protects against every threat.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#67
post #61
post #56

Earlier quoted context omitted.

OK, good point. This could just be drama.

Maybe it's worth checking their feed before writing?

That's the problem with canaries, though. By definition, they exist for situations where the canary-owner can't offer positive evidence for compromised security.

I don't particularly think Riseup is in that position, but unless someone actively says "don't worry about our lack of a canary, we took it down for $REASONS and all is well", negative evidence is all you can react to.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#68
post #3

And from riseup.net @riseupnet listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don't listen to me. #LeonardCohen https://twitter.com/riseupnet/status/797142735283257345

Okay, that's telling, but the canary on its own seems to be valid still - it's from August 16, 2016, and they say it should be 'updated approximately once per quarter'

If "quarter" is defined as "3 months", we're officially just on the outside of a quarter since the last update — 3 months and 5 days, to be precise.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#69
post #50

Earlier quoted context omitted.

Are you aware that the current top post (about blockchain) reads like a parody of a conspiracy theory?

Yep that doesn't look too good. Iirc there was more reasonable discussion on r/bitcoin. They have used the blockchain in the past, I will say that. Without trying to turn this thread into a full "Where is Assange?" discussion, for me I just can't imagine why he has not sent communication since mid October, now long after the election, especially since the chorus is now strong enough that their Twitter has to say "eve…

Without trying to turn this into a full "Where is Assange?" discussion, unless the conspiracy against Assange involves compromising such disparate actors as Ecuadorean embassy staff and prosecutor, the Swedish prosecutor, his own legal team, Wikileaks staff posting press releases in his name, Pamela Anderson and John Pilger, all of whom have communicated with him since his supposed disappearance, it's probably safe to assume that he has other priorities than sending a signed "I'm fine" message, particularly since it's already been documented that his preferred method of internet access was cut.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#70

Speaking for myself, this was brought to my attention in the context of a developing story about WikiLeaks being under duress or Julian Assange missing, who has not sent direct communication let alone signed communication for around a month now. EDIT - if curious, https://www.reddit.com/r/WhereIsAssange/

it's well known that his internet is cut off. I think if somebody was sending communications with his signing key while he is known to be unable to communicate, that would be the real problem.

He usually sees a lot of visitors, and the organization has access to millions of dollars, so he certainly has various methods available to him to say "I'm fine." They can't physically "cut him off" the Internet, but they can demand that he pause the election-related PR he was doing. They asked him to not interfere in the election, specifically.

However, the election has been over for some time. Even if they could, I doubt the Ecuadorian Embassy would forbid him from sending a basic message, picture, clip to verify he is OK, especially since pressure has been on them for a while now about his well being.

Post reply on HN