Live data from Hacker News

South African authorities admit to mass surveillance

iafrikan.com

41–50 of 145 posts

Re: South African authorities admit to mass surveillance

#41

Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?

Who now sends traffic over these links and doesn't encrypt them? Remember that the intelligence agencies don't only want today's data, they want yesterday's data. You get yesterday's data by storing it today. Then you can decrypt it at your leisure, or when computers become powerful enough to break through. I know a lot of people on HN earn a living making sure internet traffic is encrypted. But honestly, I really be…

> I really believe there are multiple TLA's that can decrypt whatever they want in real time

How? They've cracked modern public key crypto?

Re: South African authorities admit to mass surveillance

#42
post #4

I’m no big fan of recent Google, but huge thank you to them for driving a push towards https by default

Thanks to Let's Encrypt too for making it easier and cheap to SSL your site. I now see "http://" and think "that looks dirty, what's their excuse?".

Re: South African authorities admit to mass surveillance

#43

Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?

Who now sends traffic over these links and doesn't encrypt them? Remember that the intelligence agencies don't only want today's data, they want yesterday's data. You get yesterday's data by storing it today. Then you can decrypt it at your leisure, or when computers become powerful enough to break through. I know a lot of people on HN earn a living making sure internet traffic is encrypted. But honestly, I really be…

How do you think they're decrypting in real time? Do you think there are backdoors in the crypto/protocols? Severe accidental flaws? How many times a speedup are you imagining?

State of the non-TLA art is that modern https is completely impractical to break, even with enormous server farms working for years, let alone in real time.

Re: South African authorities admit to mass surveillance

#44
post #25

Earlier quoted context omitted.

There were plenty of small samples in the various Snowden powerpoint slides of stuff NSA incepted from the pipes. It seems a ton of mobile apps are sending information with identifiers over HTTP (the ID is a key part for them legally to pick it up and store it in a DB, forever). I notified one developer that was sending real-time GPS data + an email address highlighted in one of the PPT slide's (just a screenshot of…

>> Linux users currently have the lowest when using Chrome with 86%. I'm curious why the is. They probably browse quite a few old sites for documentation and tooling that are just not updated for HTTPS. A forum I post on to this day is still served over plain ole HTTP and they have no interest in changing.

Not always true, if you message them directly and ask them nicely they'll switch to https. I've even messaged a few to switch from TLS 1.0 to 1.2 as it will be soon obsolete. About 80% of those I asked switched so I am calling it a success, especially compared to companies, I barely get a positive/any response there.

Re: South African authorities admit to mass surveillance

#45

Earlier quoted context omitted.

It surprises me as a South African because I didn't know our government had the technical capability or capacity to store and process so much data, let alone splice undersea cables without detection.

if they don't have the expertise, someone else with the expertise interested in access to the data will help them.

Hasn't China been doing this all over Africa and South America?

Re: South African authorities admit to mass surveillance

#46
post #4

I’m no big fan of recent Google, but huge thank you to them for driving a push towards https by default

Thanks to Let's Encrypt too for making it easier and cheap to SSL your site. I now see " http://" and think "that looks dirty, what's their excuse?".

HTTPS has downsides too, let's not kid ourselves.

Re: South African authorities admit to mass surveillance

#47

Earlier quoted context omitted.

Thanks to Let's Encrypt too for making it easier and cheap to SSL your site. I now see " http://" and think "that looks dirty, what's their excuse?".

HTTPS has downsides too, let's not kid ourselves.

What is the downside of using https over http?

Re: South African authorities admit to mass surveillance

#48
If traffic is encrypted E2E or OE it should not be a problem that someone eavesdrop on traffic.

Here is one to make public key crypto practical using AI+Human derived mnemonics:

Btw, Jack Dorsey’s Twitter account was hacked recently, which is another interesting story.

https://docs.google.com/presentation/d/1f2k6fsIkDmIS1WyJAT0l...

Re: South African authorities admit to mass surveillance

#49
post #25

Earlier quoted context omitted.

There were plenty of small samples in the various Snowden powerpoint slides of stuff NSA incepted from the pipes. It seems a ton of mobile apps are sending information with identifiers over HTTP (the ID is a key part for them legally to pick it up and store it in a DB, forever). I notified one developer that was sending real-time GPS data + an email address highlighted in one of the PPT slide's (just a screenshot of…

>> Linux users currently have the lowest when using Chrome with 86%. I'm curious why the is. They probably browse quite a few old sites for documentation and tooling that are just not updated for HTTPS. A forum I post on to this day is still served over plain ole HTTP and they have no interest in changing.

Isn’t it more likely to be low grade android devices in poor countries with outdated government, banking, and education portals?

I doubt kernel hackers make up a large enough demographic to skew the metrics...

Post reply on HN