Live data from Hacker News

Looking Back at the Snowden Revelations

blog.cryptographyengineering.com

91–100 of 244 posts

Re: Looking Back at the Snowden Revelations

#91

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

Certain Richard M Stallman faced a similar problem when he talked about DRMed content a decade ago.

Re: Looking Back at the Snowden Revelations

#92

Snowden's revelations proved once again that conspiracies are all false, because it is literally impossible for large numbers of people to keep their mouth shut. Exactly as we're told on forums, exactly as we're told on TV. This is how you know Epstein is also innocent and why it won't be investigated, because we know people cannot keep silent about committing crimes, therefore we know no crimes were committed.

> Snowden's revelations proved once again that conspiracies are all false, because it is literally impossible for large numbers of people to keep their mouth shut. That's both a good point and not so much. In the end, they didn't keep their mouths shut, Snowden spilled the beans and uncovered the large conspiracy. It's a good point with regard to "that would require a large conspiracy, and those don't work" not being…

Its also important to note Snowden wasn't the first NSA person to warn us about this, there were a handful in the 2000s before him.

Re: Looking Back at the Snowden Revelations

#93
post #91

Earlier quoted context omitted.

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

Certain Richard M Stallman faced a similar problem when he talked about DRMed content a decade ago.

Even a broken clock is correct twice a day

Re: Looking Back at the Snowden Revelations

#94

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

If I asked 10 people around me, who is Edward Snowden, maybe one would know. When the story broke, I never heard anyone in real life bring it up.

I know young wealthy people who don’t know who Elon Musk is. People’s attention is highly fragmented.

Re: Looking Back at the Snowden Revelations

#95

Earlier quoted context omitted.

> https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf The author dismisses CPU-level backdoors in favor of Intel ME backdoors mainly on the basis that, since CPUs can't save state, they can't protect themselves against replay-"attacks", and hence Intel would lose any sort of plausible deniability once an "activation sequence" was ever found in the wild. But I don't really see how ME is protected against repl…

You assume a device can not be tracked from creation to dsitribution. Why?

Of course one device can be tracked. But not every CPU can be tracked, I consider that quite infeasible indeed. If you already know the target, and know that target is looking to buy a new PC/laptop, you can feed it a specific CPU, sure. But you could just as well feed it some sort of modified BIOS that doesn't require any special hardware, and would be pretty much just as hard to detect for someone that isn't specifically looking for that kind of modification.

But that's usually not the interesting case. The interesting case is that you find a new target, and that target already has a PC/laptop, and you want to gain access to it without having to physically infiltrate. Now, you might be able to manipulate their network in some way, or send them an E-Mail, or get them to visit a website that contains an activation code. But having to backtrack which CPU that laptop contains seems impossible to me in the vast majority of cases. Even if you can somehow figure out where he bought it, most stores aren't even going to be able to tell you the serial number of the product they sold, and even if they can, now you have to match that serial number to a CPU, which is... impossible? How would you get that information? Retailers buy hundreds of thousands of CPUs, and they probably don't tell Intel which CPU they put into which device, or even who buys which individual CPU. If you send a CPU back on Amazon, they don't even check if it's the same goddamn model! (Hence the surprise of some people who bought a $550 CPU and got a $550 CPU box with a $50 CPU in it.) And if the CPU or laptop was bought used, now you're really out of luck. I really don't see how this is very useful, when instead of doing that you can just force Intel to give up plausible deniability and hack everything in sight. If you get caught (which is incredibly unlikely in the first place), you just say "we did it for America!" and that's it, nobody would care. I mean Intel would be kinda fucked, but the NSA wouldn't be.

Re: Looking Back at the Snowden Revelations

#96

Naive question: This cryptography blog seems to, but... is WhatsApp really trusted as secure end-to-end encryption chat client? Colloquially, for one thing it's now owned by one of the biggest personal-data collection companies in the world, which would have little interest in owning a chat client it couldn't benefit from data-wise. For another, I read an article mentioning it was "known" that WhatsApp decrypted your…

It is highly unlikely that Facebook can read WhatsApp messages. The reason I say that is that Zuckerberg said the couldn't, repeatedly and explicitly, to Congress. If there was any chance that they could, he would have either not said anything (the context would have allowed for that) or he would have dissembled. As he did numerous other times on other subjects. As to benefiting from WhatsApp, I'm sure they benefited…

If you can read your WhatsApp messages on your phone and you don't control the WhatsApp binary... then Facebook can backdoor WhatsApp to read the decrypted message.

Re: Looking Back at the Snowden Revelations

#98

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

Isn’t it a bit like global warming? If people feel the issue is so much bigger than them they will just resign and give up.

Unless you communicate why we need to do sth anyways and what small managable steps can be taken it is hard to tackle this alone, even if you are an informed person with the motivation and the breathing space to do so.

So unless the felt pain and the impeding doom doesn’t exceed the threshold of “oh shit this isn’t fine, what was I thinking!” people will just call the whole thing off as unmanagable and move ahead.

Re: Looking Back at the Snowden Revelations

#99
post #50

Earlier quoted context omitted.

Description of my life. I was telling people for years what is going on, not from position of daydreaming, but what I would be able to pull off. I got back everything from tin foil hat to "I have nothing to hide". Snowden changed that and I am gratefull to him for exactly that... And for one more sentance, that is a work of pure genius: “Arguing that you don't care about the right to privacy because you have nothing…

> “Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say.” I find this sentence interesting because it is very specific to the American public. I am European and personally I care a lot more about privacy than free speech, and America's obsession with free speech boggles my mind. It might hav…

You're afraid of free speech? Manipulation occurs no matter how open or free communication is. Discourse and skepticism are the only weapons we have against Manipulation, and those exist via free speech.

Re: Looking Back at the Snowden Revelations

#100
post #71

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

One of the most interesting revelations was the security agencies apparent spying on members of Congress. But it’s like nothing happened. No investigation, no nothing. If they can’t be bothered by that, it’s little surprise they’re not bothered by their spying on regular folk.

[deleted]
Post reply on HN