Live data from Hacker News

Edward Snowden: Permanent Record

amazon.com

391–400 of 459 posts

Re: Edward Snowden: Permanent Record

#391
post #160

Earlier quoted context omitted.

He is sitting his 50 week sentence in HM Prison Belmarsh in UK and has access to lawyers. Media is tracking his case. There is nothing to report. There are people who spew up conspiracy theories on the spot when they have not heard anything, from pure ignorance, yet they speak ill of mainstream media.

Hes also sitting in the medical ward due to multiple issues, including mental issues. I dont think the news wants to report on his declining health.

How did you learn that?

Re: Edward Snowden: Permanent Record

#392
post #246

Earlier quoted context omitted.

That's actually the opposite of good practice; good practice in security is to base your planning off of facts and research. Throwing away your whole setup after every gig works for Mission: Impossible, and I guess it makes people feel extra-super-ninja, in practice it just perpetuates the endless (and pointless) culture of I-know-something-you-don't. Opsec should be based on reality and threat modeling, not endless…

That really is the difference between "proven secure" vs "not proven insecure", which would you consider best practice? As far as fingerprinting WiFi devices goes: It is an rf device and all rf devices vary in behaviour due to component tolerances. This shows in such things as spurious emissions, power variations across its transmission spectrum, oscillator drift, etc, etc. These are fairly easy to detect remotely. O…

That paper states that the accuracy could be as high as 95%. Apple has sold over a billion iOS devices with WiFi radios in them. I'll let you Google the base-rate fallacy for yourself, and decide if that risk is worth it.

Edit: make that over 2 billion

Edit: also, "proven secure" is impossible.

Re: Edward Snowden: Permanent Record

#393

Earlier quoted context omitted.

I've already given a literal life-or-death example above, which didn't involve guns. Strategems in which individuals are denied the very fundamentals of life, food, shelter, work, engagement in civic, social, commercial, or cultural practices, access to courts, institutions, and the like, without overt threats of violence, are far more effective than guns. to fight and conquer in all your battles is not supreme excel…

Your life or death scenario is an edge case with its own special complexities which should not be lumped in with discussions of the vastly voluntary choices we can make. Healthcare is heavily regulated as we all know. This raises the barrier to entry to new competitors, and leads to a less dynamic market where the status quo can last a long long time. So you end up with only 1 or a very small number of medical device…

Your life or death scenario is an edge case with its own special complexities which should not be lumped in with discussions of the vastly voluntary choices we can make.

Karen's and my 2019 FOSDEM keynote (and accompanying podcasts) discuss her struggles with the medical device industry and how those struggles relate to the larger set of choices related to technology that we make. This isn't an issue that lends itself well to short-form discussion. The issues are quite complex:

https://archive.fosdem.org/2019/schedule/event/full_software...

https://archive.fosdem.org/2019/interviews/bradley-m-kuhn-ka...

http://faif.us/cast/2019/jan/13/0x60/

http://faif.us/cast/2019/feb/19/0x61/

http://faif.us/cast/2019/mar/12/0x62/

http://faif.us/cast/2019/mar/20/0x63/

Re: Edward Snowden: Permanent Record

#394

Earlier quoted context omitted.

Amazon page blurb aside, I don't understand why this question comes up so often. Even during the initial revelations, people who wanted to downplay the topic regularly pointed out that Snowden was "just a system administrator, not an intelligence agent" and attempted to debate whether he worked directly for the government or only for a contractor. It baffled me, because that doesn't even seem relevant to his claims.…

That's an excellent point. Using the "only a sys admin" example was pretty weak. I just chose it quickly as one example of his trustworthiness level from the report. A better example would be that Mr. Snowden claims he began collecting files after James Clapper's testimony, but in fact he began 8 months earlier (third point in the Executive Summary, page iii). My main takeaway form the report is that Mr. Snowden was…

> Mr. Snowden claims he began collecting files after James Clapper's testimony, but in fact he began 8 months earlier (third point in the Executive Summary, page iii).

I don't think I've ever heard a normal human refer to him as "Mr Snowden", and just for interest, what reason could you possibly have had to memorize this specifically cherrypicked reference?

Are you an Amazon FC Ambassador when you aren't attempting to defend your agency?

Re: Edward Snowden: Permanent Record

#395

Earlier quoted context omitted.

That's actually the opposite of good practice; good practice in security is to base your planning off of facts and research. Throwing away your whole setup after every gig works for Mission: Impossible, and I guess it makes people feel extra-super-ninja, in practice it just perpetuates the endless (and pointless) culture of I-know-something-you-don't. Opsec should be based on reality and threat modeling, not endless…

"That's actually the opposite of good practice" Good security practice is considering all devices as insecure until proven otherwise. Also, mitigating known unknowns where a general problem happens a lot. Devices snooping on you, misleading you, interdiction, hacks on firmwate, etc. Then, you mitigate it in situations where you're unsure of what's going on just in case. So, long as mitigation isn't too costly. I used…

> until proven otherwise

Well that's impossible (see also the halting problem) so that's pretty clearly not good security practice.

Nothing in that says anything about what your threat model is. What risk are you mitigating by doing this? This sounds like the type of "ignore the words and listen to the sound of my voice" security espoused by management and vendor sales people.

It sounds like you have a diverting past time, and I wish you the best with that, but this isn't what security is about. Security is about identifying and mitigating specific risks. This goes doubly for operational security. All else is security theater.

Re: Edward Snowden: Permanent Record

#396
post #366

Earlier quoted context omitted.

> They published numerous details that a traditional journalistic outlet would never make public include the names of informants. Valerie Plame would like to have a word with you. If we keep going down this road we'd end up with No True Scotsman. The reality is "traditional" journalists have done this - Assange is not an outlier in this regard. If we tolerate the "worst" of the traditional (which US society clearly d…

>Valerie Plame would like to have a word with you. I probably shouldn't have used the word "never", but the fact that the Valieria Plame reveal was such a big deal is basically the exception that proves the rule that it is highly unusual for a journalist to reveal this information. Assange is certainly an outlier in the number of people who he exposed and the reason for exposing them. He reportedly said on the issue…

> but the fact that the Valieria Plame reveal was such a big deal is basically the exception that proves the rule that it is highly unusual for a journalist to reveal this information.

It was a big deal because people wanted to score political points, not because of a breach in standards. The more relevant point is the standing the journalist still had in society - he did not lose his job for it, let alone be prosecuted for it.

The quote you provide is taken out of context - at least from the Wiki page it is not clear if he is referring to the names that were leaked, as opposed to the ones that they ultimately decided to redact. I suspect the latter because it says "initially refused".

> but I really can't imagine a well respected journalist showing such a complete lack of concern for human life.

When you add the "well respected journalist", we really are in No True Scotsman territory. If all you mean to say is "He is a lousy journalist," then we have no disagreements. Without that qualifier, have you thought about extreme views held by existing, famous journalists? How much of an outlier is Assange compared to other "extreme" but established journalists?

Re: Edward Snowden: Permanent Record

#397
post #240

I think the administration badly, badly mishandled Snowden and Assange, and allowed Russia to coopt them by isolating and threatening them. If they had treated them as whistleblowers and journalists (even if they had nefarious motivations), they could have kept them in "the west" instead of driving them into the arms of Russia. I don't believe that Assange was a Russian agent at the beginning but he was surely one by…

I think the administration screwed up massively in more ways than one. - They conducted illegal, and most likely ineffective surveillance. I mean, if they have as huge watchlists as it is claimed, they can't reasonably watch very closely. - A subcontractor named Snowden, managed to leak a lot of secret stuff. And while it is the most memorable instance, it is not the first serious leak. - They failed at damage contro…

They also completely failed to detect and stop russia’s election interference and if they can’t do that why do we even have an NSA?

Re: Edward Snowden: Permanent Record

#398
post #75

Earlier quoted context omitted.

I'm self published on Amazon and can speak to that, but I see that this is actually published by a publisher (Metropolitan Books) In that case, from what I have learned from speaking to a few NYT Best selling authors, he's getting peanuts per sale, though it's very likely he got an advance in the range of $50k. He won't actually get a cent from sales until his share goes above whatever his advance was.

> an advance in the range of $50k That... would not be very much for a book that can be expected to generate hundreds of thousands of sales.

I agree.

One of the NYT best selling authors I spoke to over beers told me at most he can hope to get in the range of $200k in his lifetime for his book that was top of the charts for a significant amount of time, and continues to be very, very famous in it's niche.

i.e. Writing for a publisher sucks.

Re: Edward Snowden: Permanent Record

#399

Earlier quoted context omitted.

I think system administrators would take exception to your claim they don't help build anything. Also, Congressional report prepared by whom? Can't take a report by the fox guarding the hen house seriously.

I was a system administrator with similar responsibilities for several years, and it was quite clear who the system architects were and who the maintainers were. It's a minor point, but speaks to Mr. Snowden's reportedly inflated self-importance. It's up to all of us to take this report, and news reports and autobiographies, as seriously as you think they deserve. This provides background information not commonly kno…

You have, at this point in time, only three comments on HN, all related to Snowden, and are obviously using a throwaway account. You are also advocating heavily that the report, prepared by intelligence agencies in the US government, should be given credence, while you have developed none yourself. Really hard not to imagine you as a disinformation account created by a three letter organization.

Re: Edward Snowden: Permanent Record

#400
post #183

Earlier quoted context omitted.

It seems good practice not to assume there are no other ways to id/fingerprint a device then by mac address..

That's actually the opposite of good practice; good practice in security is to base your planning off of facts and research. Throwing away your whole setup after every gig works for Mission: Impossible, and I guess it makes people feel extra-super-ninja, in practice it just perpetuates the endless (and pointless) culture of I-know-something-you-don't. Opsec should be based on reality and threat modeling, not endless…

It's less a culture of I-know-something-you-don't than a culture of someone-may-know-something-I-don't. I don't understand your implication of intellectual delusions of grandeur here; I see it as the opposite.
Post reply on HN