Live data from Hacker News

Wikimedia Foundation v. NSA

blog.wikimedia.org

81–90 of 117 posts

Re: Wikimedia Foundation v. NSA

#81
post #27

Earlier quoted context omitted.

Yes, but only the addressing as far as I know.

The Stasi was able to read all mail of targets (and they had many) fifty years ago. Practically all mail crossing the border was read, which again was a lot. I'd assume addresses are scraped anyway, since they are digitized for routing already, and targeted mail being opened without leaving marks (an art existing for hundreds of years).

You could probably detect the message being opened if you wanted to. I think I have read somewhere about RFID to see if someone has opened a marketing mail, and I have also read about using eggs to seal the message to make it harder to open without destroying it entirely, as well as reusing the envelopes from junk mail to send your own messages. There is other stuff too possible such as trap messages I suppose. Also, the message may be hand written and is not necessarily typed, so hand written message would probably make OCR more difficult I should think.

Re: Wikimedia Foundation v. NSA

#82

Earlier quoted context omitted.

I have a hard time choosing what's the best thing to come out of the internet: WikiPedia or the Khan Academy. If you're so intent on smearing WikiPedia it would probably help you if you studied it for a bit before spouting off a bunch of nonsense in this thread. I get it: you don't like WikiPedia because they ask you for a donation. Note that you're under no obligation whatsoever to donate and that the content is you…

Wikipedia isn't camel-cased.

Some people just like to do that on purpose. See: systemd

Re: Wikimedia Foundation v. NSA

#83
post #63

Earlier quoted context omitted.

> Which 90% would you cut, and why? (Senior) Software Engineers : The site already exists. What could they possibly be engineering? Clearly all these positions can be axed and replaced by a few volunteers or an intern for the occasional maintenance patch. Even that is probably unnecessary - the site generally works fine for me. QA : See above Product : This isn't a product, it's a website. Obviously this entire secti…

SE/QA/Prod/Mobile - No piece of software can see such broad use by millions without constantly evolving to meet the ever-changing needs of users, the ever-changing blend of user agent / browser software, and the ever-changing and hostile environment of the internet itself. If you think you've ever seen a complex internet-based software project simply become perfect and then need no further changes for a decade or mor…

You are unable to recognize blatant satire.

Re: Wikimedia Foundation v. NSA

#84
post #77

Earlier quoted context omitted.

People don't just make fun of "cyber" because it sounds stupid, they also make fun of it because it is stupid. The media literally portrays the threat as Tron, when it's actually that critical systems have remotely exploitable vulnerabilities. The only real solution is to find the vulnerabilities before the bad guys do so we can close them before they're exploited. Hoarding vulnerabilities in secret is the exact oppo…

I used to think like that. But consider two things. The capabilities of the state actors are high. They cooperate with chipmakers and OS makers (or subvert or hack them). They compromise routers and hard drive firmware. Second, Kaplan's book documents multiple waves of cyber-fear in the US government; multiple US presidents starting with Reagan have tried and failed to secure our vulnerable systems. Simply put, corpo…

> The capabilities of the state actors are high.

Not just of state actors, we are not talking about aircraft carriers or nuclear missiles here, things that need a massive infrastructure behind them, we are talking about tools pretty much anybody with the right knowledge can apply once they get access.

That's the thing barely anybody wants to acknowledge with this situation because it's way more convenient to attribute everything to state actors, it's become the new get-out-of-jail card for shoddy security practices. "Nothing we could do to prevent that, adversary was a mighty state actor ¯\_(ツ)_/¯"

It's also convenient for pointing fingers at the usual suspects and start the war drums (Russia, China, NK) without admitting that attribution pretty much boils down to a guessing game with no guarantees.

In that regard the "who" is pretty much meaningless to the problem, it's all about the "how" and as Wannacry has shown the "how" quite often boils down to "Abused a vuln. that has been known, but hoarded in secret".

> They cooperate with chipmakers and OS makers (or subvert or hack them). They compromise routers and hard drive firmware. Second, Kaplan's book documents multiple waves of cyber-fear in the US government; multiple US presidents starting with Reagan have tried and failed to secure our vulnerable systems.

That's a bit contradictory, why would manufacturers be willing to let themselves get subverted to make less-secure products, but not to make more secure products? Especially considering how security is a big part of the business for quite a few of these companies, like CISCO's firewalls. For that very same reason, MS did act rather quickly and pushed out a fix when NSA informed them about EternalBlue.

> Remember how cannons made castles obsolete? We're in a similar era, where offense is outstripping defense.

That comparison doesn't really hold up. Cannons didn't work because of some obscure vulnerability in castle walls that only cannon makers knew about and which could have been fixed by wall-makers once they knew about it. Cannons simply overpowered walls.

One could argue that offense is outstripping defense due to the simple fact that "state actors" mostly focus on offense, while barely ever bothering with defense because that would also hamper their own offensive capabilities.

IT security always boils down to how much effort an attacker is willing to invest. If government agencies focus most of their efforts (backed by massive resources) on offense then the natural outcome will be that defense (mostly driven by private entities) always lacks behind, because we end up spending more time poking new holes than actually plugging them.

> Consider stuxnet. You have to assume Iran, which is smart enough to make nuclear weapons, took its best shot at securing that air-gapped network.

Their best shot was air-gapping the network, that's about it. To get trough that Stuxnet went wide and deep: https://www.scmagazineuk.com/chevron-confirms-that-it-was-hi...

> I think you have to accept that hoarding vulns is the international reality and difficult to change.

Sure I have to accept that, can't force anybody to do anything. That reasoning still reminds me way too much of the reasoning for selling weapons to questionable nation states, "If we don't do it somebody else is gonna do it", the kind of reasoning that doesn't get us anywhere and only makes the problem worse.

Re: Wikimedia Foundation v. NSA

#85

Earlier quoted context omitted.

It must be real tough to run a smear job here.

With HN being such an echo chamber, indeed it is.

yeah, I thought Reddit is echo chamber, but judging by comments here I am reconsidering my opinion and find people on Reddit more reasonable and open minded

Re: Wikimedia Foundation v. NSA

#86
post #11

Seems like it's trendy to hate the NSA. It gets conflated with an anti-authoritarian mindset. I wish smart people would gain some perspective - I got some by reading Bamford's books and a new one by Fred Kaplan - Dark Territories, about NSAs painful move to cyber. Some key points: * All the great powers have NSA equivalents. Meaning they play offence and defense in crypto, RF, and cyber. We (USA) can impose restricti…

>Seems like it's trendy to hate the NSA

Because they make us LESS SECURE.

They are an anti-security organization.

Re: Wikimedia Foundation v. NSA

#87
post #83

Earlier quoted context omitted.

SE/QA/Prod/Mobile - No piece of software can see such broad use by millions without constantly evolving to meet the ever-changing needs of users, the ever-changing blend of user agent / browser software, and the ever-changing and hostile environment of the internet itself. If you think you've ever seen a complex internet-based software project simply become perfect and then need no further changes for a decade or mor…

You are unable to recognize blatant satire.

You're not very good at blatant satire. Try something a little subtler.

Re: Wikimedia Foundation v. NSA

#88

Earlier quoted context omitted.

"In cyber, offense and defense become the same" More details pls. Because it sounds like bs. It is a difference to secure a network and maybe find out who a attacker is - and then attack back - than to just hack everyone you can and build as much hidden botnets as possible. Which would be "offense" "Gentlemen do not read each other's mail". It is indeed a noble statemt. And I'd like to see claims, how that led to US…

It's an obvious consequence of the action. They're not getting others' secrets. Their enemies are still getting theirs. So, their enemies will know their plans but not vice versa. Definitely not a smart way to wage war.

So you are saying the whole world is the enemy of the US, including their own population?

(I never said something against spying against enemys)

Re: Wikimedia Foundation v. NSA

#89
post #11

Seems like it's trendy to hate the NSA. It gets conflated with an anti-authoritarian mindset. I wish smart people would gain some perspective - I got some by reading Bamford's books and a new one by Fred Kaplan - Dark Territories, about NSAs painful move to cyber. Some key points: * All the great powers have NSA equivalents. Meaning they play offence and defense in crypto, RF, and cyber. We (USA) can impose restricti…

> I wish smart people would gain some perspective - I got some by reading Bamford's books and a new one by Fred Kaplan - Dark Territories, about NSAs painful move to cyber.

All smart people, or those that disagree with your findings from reading two books?

Re: Wikimedia Foundation v. NSA

#90

Earlier quoted context omitted.

It's not the role of a democratic and free government to use mass surveillance against its own citizens. It's something you do in a tyranny to weed out dissidents and quill rebellions before they happen. I'm sure you can put up a lot of good points as to why he NSAs of the world help, but the simple truth is, that we are not free when we live under a surveillance state.

And in what "democratic and free" state are there not bad actors who do need investigating? Hanson, Philby etc.

Safety is a common argument, but mass surveillance doesn't seem to be keeping us safe. https://goo.gl/images/ciNqLM
Post reply on HN