Live data from Hacker News

Looking Back at the Snowden Revelations

blog.cryptographyengineering.com

181–190 of 244 posts

Re: Looking Back at the Snowden Revelations

#181
post #71

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

One of the most interesting revelations was the security agencies apparent spying on members of Congress. But it’s like nothing happened. No investigation, no nothing. If they can’t be bothered by that, it’s little surprise they’re not bothered by their spying on regular folk.

Google "jane harman alberto gonzales". George W. Bush's Attorney General was apparently "twisting Rep. Jane Harman's arm" over some moderately bad things that FBI or somebody caught Harman saying to some AIPAC people being surveilled.

That was in 2009. I remember being kind of stunned that nobody seemed to care that the executive branch blackmailed an elected Rep. Log rolling and pork barrelling is fine, but blackmail seems like a bridge too far.

Re: Looking Back at the Snowden Revelations

#182

Earlier quoted context omitted.

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

>Now everyone knows it’s true, but still nobody seems to care… That just about sums up every bad act. Lots of people were aware of all the bank fraud and toxic loans leading to the 2008 real estate bubble, no one cared leading up to it, and no one cares now. The Googles/Facebooks/amazons are collecting and doing unsavory things with your data, whether you ever used their services or not (shadow accounts), no one seem…

For pure insanity Operation Northwood still takes the biscuit.

Do we really think that they are any better 50 years later because I don't.

Re: Looking Back at the Snowden Revelations

#183

Naive question: This cryptography blog seems to, but... is WhatsApp really trusted as secure end-to-end encryption chat client? Colloquially, for one thing it's now owned by one of the biggest personal-data collection companies in the world, which would have little interest in owning a chat client it couldn't benefit from data-wise. For another, I read an article mentioning it was "known" that WhatsApp decrypted your…

WhatsApp is great for casual users but not truly end to end because of its design imo. Silent rekeying is the default behavior. No perfect forward secrecy here either: old messages silently re-encrypted with the new key and re-transmitted. The Guardian and others reported on this some years back and of course you can witness the behavior yourself if you flip that setting in your client. If a buddy gets a new phone, it will now disclose that to you (but not wait to send old messages). Was that really my buddy's new phone or an attacker? Hopefully I can trust WhatsApp (but trusting the broker means it's no longer E2E).

Yes, like everyone says it's all about your threat model. If it really includes nation states, you should not use WhatsApp. Everyone else can use it for iMessage like functionality over-the-top.

Re: Looking Back at the Snowden Revelations

#184
post #66

Earlier quoted context omitted.

Yeah, we'll just go ahead and use x86 processors from AMD, another US company, which are surely not backdoored...

AFAIK, the equivalent of IME is not present in all AMD processors, only (maybe) those with integrated graphic chips ? But overall, yeah, Europe should just create their own chip industry, it's too critical to leave it to others...

Ironically enough we (the UK) actually had a massive input in the current chip landscape via ARM until the government allowed it to be sold to a foreign buyer.

You have to wonder if the French government would have allowed the sale (as an example).

Seems like the conservatives don't give a shit about strategic national companies as long as the cheques clear.

Re: Looking Back at the Snowden Revelations

#185

The article mentions MUSCULAR, but neglected the follow-up: shortly after the leaks, Google began encrypting all of its internal traffic over its own fiber links.[0] First, it's worth pointing out that "encrypt everything in flight always" is not prohibitively expensive on modern hardware; also that your own internal network should not be viewed as an impenetrable bastion where you can let down your guard, just becau…

“Security of organisations should be done in layers” and each layer makes breaking into your (whole) organisation harder, but comes with friction for your staff.

No, I think the new consensus is that all systems are vulnerable (obviously true if all systems have users with access, whom may be compromised) - so not layers: compartments (and need to know;need to access).

I believe this is part of eg google/alphabet's new model: no hard wall, soft "inside" (egg model). Just stand alone secure sub-systems with ACL (access control lists) mediating access on a user-by-user, sub-system by sub-system level. No real trust in "location" as proof of authorization (I assume truly, off-grid clean rooms are excepted) - because "everything" needs access to networked resources.

Ah, I guess they call it BeyondCorp:

https://cloud.google.com/beyondcorp/

Re: Looking Back at the Snowden Revelations

#186

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

Yeah, he's wrong that the most paranoid weren't assuming how bad it was. If anything, Enemy of the State had general public worried with Echelon revelations and technical details of Puzzle Palace making me certain they were doing mass surveillance and hacking. At least within a few years of 9/11 and Patriot Act. They'd do whatever they (a) could and (b) had to do for their mission.

Far as weakening, we were noting they did a lot of things that were public knowledge that indicated they prioritized shoddy products and surveillance over security. I had an essay listing most of them. I might dig it up and submit it Thursday if anyone is interested.

Re: Looking Back at the Snowden Revelations

#187

Earlier quoted context omitted.

Your legal name is: $name Your Address is: $address Your phone is: #ph You work at: $employer You did X abhorrent thing (fakes picture or video with deepfakes). It would be a shame if something happened to you. ------------------------------- That right there is indeed verbal violence, AND a call to arms to enact violence against you.

That right there is not an example of violence, despite any assertions to the contrary. There is a clear distinction between statements and actions.

And this is where my opinion lies.

Re: Looking Back at the Snowden Revelations

#188

Earlier quoted context omitted.

Anyone absolutely can "Yell fire in a theater" in the US, this canard has an interesting history: https://en.wikipedia.org/wiki/Shouting_fire_in_a_crowded_the... You can also go on the radio and accuse your boss of whatever you like in the US as well. You might get sued by your boss in civil court, but the police will not come after you. You can also deny the Holocaust, that the earth is round, that people have lande…

The distinction between civil and criminal law isn't terribly relevant here. You can be found liable in civil court for all of the things listed in the first two paragraphs.

Its entirely relevant. Your speech is subject to civil law, never criminal law, because speech is free. If it is somehow subject to criminal law its not really the speech that is, but some other act which the speech is facilitating.

Yelling fire in a theater isn't illegal, but deliberately doing something that will cause a panic is.

Re: Looking Back at the Snowden Revelations

#189

Earlier quoted context omitted.

And yet, Snowden is out of the reach of the US govt (for now).

Snowden is in a situation where it would be a PR nightmare for the US if they were to touch him. That's not the same as being out of reach.

Snowden is in a situation where it could be nuclear war between Russia and the US if they were to touch him on Russian soil.

Re: Looking Back at the Snowden Revelations

#190

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

> https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf The author dismisses CPU-level backdoors in favor of Intel ME backdoors mainly on the basis that, since CPUs can't save state, they can't protect themselves against replay-"attacks", and hence Intel would lose any sort of plausible deniability once an "activation sequence" was ever found in the wild. But I don't really see how ME is protected against repl…

I thought everything in it would be backdoored with each one looking like an intermittent failure, a timing error, something like MMU failing in long-lasting system due to silicon aging, "honest mistakes" all over networking-connected code in ME, something similar in its hardware, etc.

The one they'd use the most was deniable looking flaws in ME. They'd reserve their best ones for most important cases with lowest chances of detection. Maybe even with personal physically there activating it with a RF signal. Could integrate wireless in something called Centrino to make that easier. Take a pile of hard cash and lots of defense sales as a thank you.

Post reply on HN