Live data from Hacker News

Looking Back at the Snowden Revelations

blog.cryptographyengineering.com

51–60 of 244 posts

Re: Looking Back at the Snowden Revelations

#51

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

There is nothing to suggest an ME backdoor. I’d call it unlikely.

Lol

Re: Looking Back at the Snowden Revelations

#52

Isn't the practice of the NSA just plainly treason? And why would it not be?

No, it isn't plainly treason. This is the definition of treason: Treason against the United States, shall consist only in levying War against them, or in adhering to their Enemies, giving them Aid and Comfort. No Person shall be convicted of Treason unless on the Testimony of two Witnesses to the same overt Act, or on Confession in open Court. Did the NSA levy war against the US? Did the NSA give aid & comfort to the…

>Did the NSA give aid & comfort to the enemies of the US?

The US suffered a cyberattack that was only possible due to NSA's subversion of Juniper Systems.

This could well and truly be considered 'giving aid / comfort to enemies of the USA' ..

Re: Looking Back at the Snowden Revelations

#53
post #37

Earlier quoted context omitted.

Actually, nothing changed Some Laws was created. Some revelations was made. But even manipulations with elections did not kill any company

Let's Encrypt brought TLS to the masses, browsers are bringing focus to sites still not using transport encryption, https is a signal for Google ranking. Don't be so defeatist.

More SSL traffic gets terminated at CF, AWS & Co. Build a data center next door, mail them the NSL and off you go. Much easier than running covert operations hooking into lots of CIX and providers world wide.

Re: Looking Back at the Snowden Revelations

#54
post #37

Earlier quoted context omitted.

Actually, nothing changed Some Laws was created. Some revelations was made. But even manipulations with elections did not kill any company

Let's Encrypt brought TLS to the masses, browsers are bringing focus to sites still not using transport encryption, https is a signal for Google ranking. Don't be so defeatist.

[deleted]

Re: Looking Back at the Snowden Revelations

#55
post #49

Earlier quoted context omitted.

Let's Encrypt brought TLS to the masses, browsers are bringing focus to sites still not using transport encryption, https is a signal for Google ranking. Don't be so defeatist.

That's non-targeted attacks. Nothing stops the targeted attacks. Sure, they might not be able to listen in on those https connections, but if they wanted to attack/listen to this Joe Smith over here, they are more than capable, and still do it.

World governments can also just generally have you arrested or killed without a ton of fuss if you are a big problem.

The problem with the NSA revelations wasn't that the NSA spies on people - that's their job.

It was about mass warrant-less surveillance of the american public, not individual targeted surveillance.

Re: Looking Back at the Snowden Revelations

#56
> ... — the agency spent $250 million per year on a program called the SIGINT Enabling Project. Its goal was, basically, to bypass our commercial encryption at any cost.

Now that things have actually started going dark for these overfunded and completely unaccountable entities this is where the biggest danger lies. They have become so desperate for continued access to endless funding that they are actually turning against the people they are sworn to serve. The most dangerous time will come when the governments of the world start the task of trimming down such entities to something proportionate to their worth. That process has not really even begun yet...

Re: Looking Back at the Snowden Revelations

#57
post #37

This is a good article. Everyone has forgotten how much has changed since Snowden.

Actually, nothing changed Some Laws was created. Some revelations was made. But even manipulations with elections did not kill any company

I meant more changes to people's behaviour and tools used and prevalence and awareness of encryption

Re: Looking Back at the Snowden Revelations

#58

As someone not from the US, the passages about how easy it was are clear reminders that just because only the NSA got caught, does not mean only the NSA was doing it. Even if they have by far the biggest budget...

Yeah, there's a severe danger here that only the stories that are worthy of media play are going to be discussed. Snowden has been proven to generate clicks, so we'll probably continue to see a lot of Snowden stories.

We're in a multi-party cyberwar. We have been for years. It involves both governments and NGOs. Most of the players are pushing as hard as they can, short of real warfare, to gain the advantage over the others.

That's a much tougher story to tell, since it doesn't have clear heroes and villains. Also it involves a lot of technical stuff Joe Layman doesn't want to process. Because of this, media outlets are always going to tell the simpler story. The overwhelming danger here is that nobody learns what is going on, which presumably is the point of having a media outlet in the first place.

Re: Looking Back at the Snowden Revelations

#59

As someone not from the US, the passages about how easy it was are clear reminders that just because only the NSA got caught, does not mean only the NSA was doing it. Even if they have by far the biggest budget...

We’ve seen other stories, Stuxnet in particular that implicate other countries like Israel. Anyone that thinks that the USA and Israel are spending money on cyber warfare but China and Russia are not is living in a fantasy world. Maybe some small countries like Andorra don’t have a cyber warfare division, but all the big countries do.

Everyone is being spied on. Perhaps the only distinction worth making is whether you’re being spied on by your own government in addition to foreign governments.

Re: Looking Back at the Snowden Revelations

#60
Naive question:

This cryptography blog seems to, but... is WhatsApp really trusted as secure end-to-end encryption chat client?

Colloquially, for one thing it's now owned by one of the biggest personal-data collection companies in the world, which would have little interest in owning a chat client it couldn't benefit from data-wise. For another, I read an article mentioning it was "known" that WhatsApp decrypted your message, stored it, then resubmitted it encrypted to the destination. (Inconveniently, I can't seem to find the article now.) If, say, your life relied on privacy, would you trust WhatsApp, and if not, why?

Post reply on HN