Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

121–130 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#121
post #98
post #62

Earlier quoted context omitted.

I'd imagine that since lavabit NSLs make that harder if not illegal.

its not within legal purview to force someone to continue doing something, is it?

But they could order them to give them access to administer their servers, with acts of sabotage being punishable. There's no reason you should assume that the people running RiseUp right now are the same people that ran it a week ago.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#122
post #102

Earlier quoted context omitted.

Not really my area of expertise, but it strikes me as completely clear. The canary hasn't been updated and the tweet implicitly acknowledges that they are aware of the concerns that people have about the overdue update. I can only think of two reasons to do this. 1. get some publicity or 2. for whatever reason they are unable to update the canary and are unable to say why. Personally, I doubt it's reason 1.

But why say they have no plans to shut down and link directly to the part of their FAQ where they say they will shut down if they are under government surveillance? Why not just tweet something like "We have heard your concerns" or something similar

You might not be able to shutdown if you have been forced to keep the service running.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#124

Earlier quoted context omitted.

Okay, that's telling, but the canary on its own seems to be valid still - it's from August 16, 2016, and they say it should be 'updated approximately once per quarter'

Well, after (I'm sure) many inquiries about the canary, their latest update says nothing specific, just: > we have no plans on pulling the plug https://riseup.net/en/about-us/policy/government-faq … https://twitter.com/riseupnet/status/800815181190217729

If I were a scary government type and took control of riseup.net, that is exactly the thing I would post to twitter if I couldn't compel them to update the canary.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#125

Earlier quoted context omitted.

They certainly are real letters, though you're right in that they might be hand delivered by an official process server. Either that, or just mailed with a return receipt and signature required. Yahoo was able to publish the letters they received: https://s.yimg.com/ge/tyc/Redacted_Non-disclosure_Terminatio...

Of course, it is ultimately a piece of paper... But in every company I've worked for mail is signed for by whoever and, if it's addressed to an executive, delivered to a secretary who reads it and decides what to do it. Given the requirement for secrecy, there is zero chance that an NSL will be treated in this way. And it won't be served by a random process server. Most likely it will be served by an NSA employee, in…

A NSL is a legal document that originates from the DOJ (via the FBI) that requires no judicial approval. Nevertheless it is a legal document. The NSA does not participate, authorize, approve, initiate, or distribute NSLs.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#126
post #90

Earlier quoted context omitted.

Sorry, I don't understand this. It's incredibly bizarre to be posting selfies with messages on HN.

Granted. You're right that this is bizarre. I'm posting a proof-of-life of myself because Julian Assange is unable to, and I'm trying to get the word out. It's not just a selfie -- It's proof that I'm alive. Basically I'm pretty much freaking out at the moment because it appears that Julian has been disappeared, and I'm doing whatever I can to try and spread awareness about this issue. Previously, there were people o…

It changed because of elections.

Truth often hurts when it's bad and is against people you support.

I hope Assange is doing well.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#127
post #84

If you're doing any kind of radical political work --- left or right --- and are worried about the attention you're going to attract, don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption. These are fundamentally unsafe services, and the idea that they can be provided safely just by paying attention to network secu…

We in the XMPP community work hard to make "Jabber" secure. Forward secrecy, federation and client scoring, carefully constructed extensions. But without end-to-end encryption like PGP or something, you're open to attack. There are some really neat specs that work on making this more transparent and better, but yes, you can't just blindly use someone else's service and go "it's secure."

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#128
post #106
post #88

Earlier quoted context omitted.

I remember clearly a Tunisian opposition party was using a RISEUP mailing list around 2006 to spread its articles, political statements, etc... (When they were banned before the revolution of 2011). Not all politicians can/know how to operate anything more complex than an email account.

That's an interesting piece of history. It kind of makes sense that accessibility can sometimes be worth the potential downsides. By the way, are you a fellow Tunisian? I'm kind of surprised because I've never run into a Tunisian on HN :p

Maybe one day I'll release an archive of pre-2011 emails and IRC logs.

Yes I'm Tunisian, I only know of a couple active people around here, but there is a ton of readers.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#130
post #106

Earlier quoted context omitted.

That's an interesting piece of history. It kind of makes sense that accessibility can sometimes be worth the potential downsides. By the way, are you a fellow Tunisian? I'm kind of surprised because I've never run into a Tunisian on HN :p

Maybe one day I'll release an archive of pre-2011 emails and IRC logs. Yes I'm Tunisian, I only know of a couple active people around here, but there is a ton of readers.

Wow, so you operated mail and IRC servers for use by dissidents pre-2011? I would definitely attend a talk about that! A blog post would be amazing too.

I see, that's great to hear. I don't live in Tunisia, so I'm not familiar with the Tunisian tech scene. Judging by your Twitter feed, it seems to be really active, which is awesome!

Post reply on HN