Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

91–100 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#91
post #84

If you're doing any kind of radical political work --- left or right --- and are worried about the attention you're going to attract, don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption. These are fundamentally unsafe services, and the idea that they can be provided safely just by paying attention to network secu…

Don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption.

So what are the types of services one should use?

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#92

Earlier quoted context omitted.

To be honest, people that aren't going to be convinced that an in-depth video interview John Pilger asserts was made on October 30th or an abundance of statements from all parties about two days worth of formal interviews over the court case that's dogged him for a while aren't going to be convinced by a quick video of him saying "I aten't dead yet", or probably even a keysigned message. There are an abundance of pre…

Sorry, but c'mon, that entire subreddit would disappear overnight if Julian gave just one, basic proof of well being. The majority of the 12,000 (and fast growing) are not conspiracy people, they just have a very simple request for a PGP message, a picture, a video, a public appearance, anything. Again, I encourage the debate of circumstantial evidence on Reddit instead of here, but Julian does not say anything to in…

Exactly. Every day that goes by w/out a proof-of-life from Assange adds weight to the theory that he is in fact no longer alive.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#93

If you care enough to post canaries, shouldn't you also care enough to just close shop instead of subtly telling your users to stop using your services?

They just tweeted that they have no plans of doing so

https://twitter.com/riseupnet/status/800815181190217729

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#94
post #39

I am highly skeptical of any claim that an email provider is more private than other providers. E-mail is fundamentally not secure and not private, unless you enhance it with PGP, which requires you to, of course, have something you want private. Most people don't encrypt because they're not scared enough. It usually takes some time before their wordlview is repeatedly shattered enough that encryption is the only cho…

I was running my own e-mail server for a while before I finally got around to generating/publishing a PGP key. It's a pretty simple process, but also an incredibly complicated process for the uninitiated.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#95
post #90

Earlier quoted context omitted.

Sorry, I don't understand this. It's incredibly bizarre to be posting selfies with messages on HN.

Granted. You're right that this is bizarre. I'm posting a proof-of-life of myself because Julian Assange is unable to, and I'm trying to get the word out. It's not just a selfie -- It's proof that I'm alive. Basically I'm pretty much freaking out at the moment because it appears that Julian has been disappeared, and I'm doing whatever I can to try and spread awareness about this issue. Previously, there were people o…

It's more likely that the relatively logical and thoughtful HN community isn't sure if Julian has become somewhat unhinged, if you will.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#96
New tweet: https://twitter.com/riseupnet/status/800815181190217729

Confusing update IMHO. Could be read as reassurance. Could also be read as being threatened with incarceration and being forced to keep the site up. or a reminder to archive stuff immediately because of impending shutdown.

Not really sure what to make of it, other than they have obviously heard the concerns and /not/ updated the canary.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#97
post #84

If you're doing any kind of radical political work --- left or right --- and are worried about the attention you're going to attract, don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption. These are fundamentally unsafe services, and the idea that they can be provided safely just by paying attention to network secu…

While you are not lying, and mailing lists should be avoided if you want to share secrets, most of the times you need a mailing lists not to do that, but to simplify communications.

At least in the global south, most of radical activists groups have strong "no-internet policies" for any type of secret, and no cellphones ones for their work. They have learned with their own history what they can or can't do, learned how to deal with IRL infiltration, and even learned how to communicate without any kind of contact or even agreements between groups. To survive and act against dictatorships or invading armies is not easy, they had to be smart.

But still, because travelling is expensive and networking today is a need for some of those groups or collectives, they can communicate with each other talking about their resolutions or activities, which are not secret (as I already said, it's assumed there can be a IRL infiltrate) but they are also not public.

You can see SMTP and mailing lists as a huge security risk, and they are, it's just not very common to see people that assume the opposite around here.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#98
post #62

If you care enough to post canaries, shouldn't you also care enough to just close shop instead of subtly telling your users to stop using your services?

I'd imagine that since lavabit NSLs make that harder if not illegal.

its not within legal purview to force someone to continue doing something, is it?

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#99
post #84

If you're doing any kind of radical political work --- left or right --- and are worried about the attention you're going to attract, don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption. These are fundamentally unsafe services, and the idea that they can be provided safely just by paying attention to network secu…

Don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption. So what are the types of services one should use?

Instead of looking for anti-authoritarian services to hide from authoritarian government services you should probably blend in with the fish like Mao said:

> The guerrilla must move amongst the people as a fish swims in the sea.

It's better to create false identities that are seemingly legit and fully fleshed out, for example: with back stories, and utilize regular services as a normal person would. The key is disconnecting your own identity from the false one. Rather than trusting your security to a 3rd party service that makes a name for themselves on helping people trying to hide their identity, thereby attracting scrutiny.

That being said there are ways to use encryption services in a way to protect your communication but the bar for doing so is very high and most people will either make mistakes or get lazy. Fortunately services like Whatsapp and to a lesser extant Signal are so popular that you could easily blend in using them, while still having high-quality data encryption. Although they both use phone phone numbers for authentication and the device itself is always a weak-link which is why the identity part is so critical.

thegrugq posted an article a long time ago about how CIA agents in Lebanon [1] got caught because they used burner phones in a way that was unlike the way anyone else used cell phones, if I remember correctly: they were turned off the device most of the time except to make a few calls to other phones that were similarly not used often - not in the way normal people make calls. So anyone in control of the mobile operators would be able to ID potential evasive behaviour an zero-in on those devices/people for extra scrutiny.

That type of behavioural analysis that applies to real life can even more easily give you away in the digital world. Which is why it's important to not stand out from the crowd by using services like Riseup when your entire goal is privacy.

[1] http://grugq.github.io/blog/2013/03/12/anonymity-is-hard/

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#100

Imagine if your office live-broadcasted nearly everything. From the corridors, reception area, to the opening of physical mail. The PR and generally more "public" email addresses could be transparent as well. This means when the NSL arrives, it will be seen by the world.

I bet you a jam sandwich that an NSL is not actually a letter sent in the regular post.
Post reply on HN