Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

71–80 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#71
post #65
post #61

Earlier quoted context omitted.

Maybe it's worth checking their feed before writing?

It could have been an attempt at plausible deniability.

Have you happened to see their other messages from the same day?

"Dear friends, please remember that internet is not always the answer..."

"by the way, that wasn't a trump related tweet..."

"listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don't listen to me. #LeonardCohen"

It all "has nothing to do with" canaries.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#72

Earlier quoted context omitted.

Yep that doesn't look too good. Iirc there was more reasonable discussion on r/bitcoin. They have used the blockchain in the past, I will say that. Without trying to turn this thread into a full "Where is Assange?" discussion, for me I just can't imagine why he has not sent communication since mid October, now long after the election, especially since the chorus is now strong enough that their Twitter has to say "eve…

Without trying to turn this into a full "Where is Assange?" discussion, unless the conspiracy against Assange involves compromising such disparate actors as Ecuadorean embassy staff and prosecutor, the Swedish prosecutor, his own legal team, Wikileaks staff posting press releases in his name, Pamela Anderson and John Pilger, all of whom have communicated with him since his supposed disappearance, it's probably safe t…

Yes, I know there are a few people who have said "He is fine, trust us", but it would take all of 2 seconds for him to send a message himself, a picture, a video clip, stand by the window, or go on the balcony, and there has now been a very long, uncharacteristic time window where he has not done this. He has many means of communication, regularly has visitors, and has a very legitimate reason for doing it (to silence all the people who are concerned, constantly Tweeting at them, calling to cease donations, etc.) - so the fact he hasn't is worthy of our suspicion.

EDIT - I really did mean "didn't want to start full discussion", because there apparently is a whole lot more circumstantial evidence, including regarding some of the people you mentioned (like some members of his legal team being barred entry), but seriously, I'm going to leave the fullness of that discussion for Reddit, and think anyone who is interested in it should take it up there.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#73
post #45

Earlier quoted context omitted.

> I'm still getting email :) The failure mode of their warrant canary is not that you stop getting email, but that other people start getting your email too.

Sure. But you see, the prudent assumption is that adversaries always get all your email :)

Your comment is a distraction, not a contribution. People came here to discuss whether a warrant canary had died, not to hear you trot out security 101 cliches.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#74

If you care enough to post canaries, shouldn't you also care enough to just close shop instead of subtly telling your users to stop using your services?

Or at least care enough to update them more than once a quarter... worse than useless, since those Unspeakable Agencies will have had their fill of information by then. And then the canary dies and people panic into moving their hosting to 'stay private'.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#75
Perhaps I'm doing this wrong but when I try to verify the gpg signature I get

gpg: Signature made Tue Aug 16 01:01:19 2016 EDT using RSA key ID 139A768E

gpg: Good signature from "Riseup Networks " [unknown]

gpg: aka "Riseup Treasurer " [unknown]

gpg: WARNING: This key is not certified with a trusted signature!

gpg: There is no indication that the signature belongs to the owner.

Primary key fingerprint: 4E07 9126 8F7C 67EA BE88 F1B0 3043 E2B7 139A 768E

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#76
post #47
post #3

And from riseup.net @riseupnet listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don't listen to me. #LeonardCohen https://twitter.com/riseupnet/status/797142735283257345

That was probably just commemorating Leonard Cohen's death, and the certificate fingerprints were probably just removed because they switched to Let's Encrypt for those domains. But you never know.

What good is a warrant canary if it's also used for whimsy or commercial speech? If they don't take it seriously enough for people know what it means then their system isn't worth using to start with.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#78
post #29

Earlier quoted context omitted.

Okay, that's telling, but the canary on its own seems to be valid still - it's from August 16, 2016, and they say it should be 'updated approximately once per quarter'

I certainly have no clue. I'm still getting email :) And they've had indirect FBI attention before: https://riseup.net/en/about-us/press/fbi-seizes-anonymous-re...

> I'm still getting email :)

While obviously this is not about preventing you from "getting email", you might not have received everything. You should consider the service compromised.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#79
post #57

Earlier quoted context omitted.

The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and received, using SSL/TLS * Encryption in transmission of webmail sessions, using HTTPS * Authentication security: Do they use 2 factor or other tech? * Logging and retention of logs * Reading your mail to build marketing profiles and social graphs * Access by employee…

> Authentication security: Do they use 2 factor or other tech? Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies. For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not…

It seems like you're just ignoring HackUser's argument that security is a degree.

Securing against low-level hackers and intrusions increases security, even if it doesn't stop the NSA. It also doesn't stop the CIA from physically spying on you.

Securing yourself against low-level hackers and intrusions is not security theater. For most people, these are the most frequent and direct threats.

I would also argue that over-securing yourself is security theater. It's the same as overselling insurance products to people whose risk profile doesn't match the product. If you're not making security decisions based on the profile of risks you encounter, then you're engaging in theater to make yourself feel better.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#80

Earlier quoted context omitted.

Without trying to turn this into a full "Where is Assange?" discussion, unless the conspiracy against Assange involves compromising such disparate actors as Ecuadorean embassy staff and prosecutor, the Swedish prosecutor, his own legal team, Wikileaks staff posting press releases in his name, Pamela Anderson and John Pilger, all of whom have communicated with him since his supposed disappearance, it's probably safe t…

Yes, I know there are a few people who have said "He is fine, trust us", but it would take all of 2 seconds for him to send a message himself, a picture, a video clip, stand by the window, or go on the balcony, and there has now been a very long, uncharacteristic time window where he has not done this. He has many means of communication, regularly has visitors, and has a very legitimate reason for doing it (to silenc…

To be honest, people that aren't going to be convinced that an in-depth video interview John Pilger asserts was made on October 30th or an abundance of statements from all parties about two days worth of formal interviews over the court case that's dogged him for a while aren't going to be convinced by a quick video of him saying "I aten't dead yet", or probably even a keysigned message.

There are an abundance of pretty straightforward hypotheses consistent with the known facts(e.g. "Assange isn't feeling fine because he's still angry and/or paranoid about his preferred internet connection being taken away", "Assange feels this story is good publicity, relative to other kinds of publicity he's getting at the moment") but of course these aren't the ones being discussed on "Where is Assange?" subreddits.

Post reply on HN