Earlier quoted context omitted.
That was probably just commemorating Leonard Cohen's death, and the certificate fingerprints were probably just removed because they switched to Let's Encrypt for those domains. But you never know.
OK, good point. This could just be drama.
Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
61–70 of 137 posts
Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#62If you care enough to post canaries, shouldn't you also care enough to just close shop instead of subtly telling your users to stop using your services?
Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#63Earlier quoted context omitted.
The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and received, using SSL/TLS * Encryption in transmission of webmail sessions, using HTTPS * Authentication security: Do they use 2 factor or other tech? * Logging and retention of logs * Reading your mail to build marketing profiles and social graphs * Access by employee…
> Authentication security: Do they use 2 factor or other tech? Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies. For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not…
To summarize, 2FA does not prevent email reading if the provider doesn't, however it does help prevent run of the mill takeovers, especially if you've reused a password somewhere.
Security is all about defense in depth, it's worth keeping in mind that 2FA is an important step there, but by no means the only one.
If you aren't encrypting+signing a message, you've already decided that security requirements of that particular message is minimal.
Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#64Speaking for myself, this was brought to my attention in the context of a developing story about WikiLeaks being under duress or Julian Assange missing, who has not sent direct communication let alone signed communication for around a month now. EDIT - if curious, https://www.reddit.com/r/WhereIsAssange/
Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#65Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#66Earlier quoted context omitted.
The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and received, using SSL/TLS * Encryption in transmission of webmail sessions, using HTTPS * Authentication security: Do they use 2 factor or other tech? * Logging and retention of logs * Reading your mail to build marketing profiles and social graphs * Access by employee…
> Authentication security: Do they use 2 factor or other tech? Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies. For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not…
MFA is used to prevent a third-party who has access to your credentials from being able to login as you and, in the case of U2F, to prevent a successful phishing attempt from compromising your account.
MFA offers no, and never has been billed as, protection against a subverted server or an attacker who can decrypt or tamper with traffic on the wire.
Security is a large, complicated problem. There will never be a single measure which protects against every threat.
Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#67Earlier quoted context omitted.
OK, good point. This could just be drama.
Maybe it's worth checking their feed before writing?
I don't particularly think Riseup is in that position, but unless someone actively says "don't worry about our lack of a canary, we took it down for $REASONS and all is well", negative evidence is all you can react to.
Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#68And from riseup.net @riseupnet listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don't listen to me. #LeonardCohen https://twitter.com/riseupnet/status/797142735283257345
Okay, that's telling, but the canary on its own seems to be valid still - it's from August 16, 2016, and they say it should be 'updated approximately once per quarter'
Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#69Earlier quoted context omitted.
Are you aware that the current top post (about blockchain) reads like a parody of a conspiracy theory?
Yep that doesn't look too good. Iirc there was more reasonable discussion on r/bitcoin. They have used the blockchain in the past, I will say that. Without trying to turn this thread into a full "Where is Assange?" discussion, for me I just can't imagine why he has not sent communication since mid October, now long after the election, especially since the chorus is now strong enough that their Twitter has to say "eve…
Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice
#70Speaking for myself, this was brought to my attention in the context of a developing story about WikiLeaks being under duress or Julian Assange missing, who has not sent direct communication let alone signed communication for around a month now. EDIT - if curious, https://www.reddit.com/r/WhereIsAssange/
it's well known that his internet is cut off. I think if somebody was sending communications with his signing key while he is known to be unable to communicate, that would be the real problem.
However, the election has been over for some time. Even if they could, I doubt the Ecuadorian Embassy would forbid him from sending a basic message, picture, clip to verify he is OK, especially since pressure has been on them for a while now about his well being.