Live data from Hacker News

Looking Back at the Snowden Revelations

blog.cryptographyengineering.com

191–200 of 244 posts

Re: Looking Back at the Snowden Revelations

#191

Earlier quoted context omitted.

Anyone absolutely can "Yell fire in a theater" in the US, this canard has an interesting history: https://en.wikipedia.org/wiki/Shouting_fire_in_a_crowded_the... You can also go on the radio and accuse your boss of whatever you like in the US as well. You might get sued by your boss in civil court, but the police will not come after you. You can also deny the Holocaust, that the earth is round, that people have lande…

The distinction between civil and criminal law isn't terribly relevant here. You can be found liable in civil court for all of the things listed in the first two paragraphs.

Sure it's relevant. In the context of Free Speech, we're talking about freedom from persecution by the state.

In the US, you can say whatever you like and you will not be prosecuted or jailed. That is simply not true in most other countries.

Re: Looking Back at the Snowden Revelations

#192
post #144

Earlier quoted context omitted.

"Freedom of speech is not freedom from consequences." It sounds like a quote from "Animal Farm", doesn't it? I am free to say anything I like, but if I say the wrong thing, I get punished for it. Also, "some are more equal than others".

I can insult the president, house, senate, justices, and all the others in government. And not only that, I can 'peacably assemble', and 'petition for a redress of grievances'. Those are all rights in the 1A alongside free speech. Compare that to: Poland, Netherlands, Spain, Switzerland, Thailand, and Saudi Arabia.4 are European and 2 not. Yet it is a criminal charge if you do. And in Saudi Arabia, it's a terrorist c…

Please dont do it. 1A is protecting you, but they still got guys with batons, tear gas and tazers. It is not about the letter within some law but rather how it is practised, by insulting someone strong enough, law might protect you but at the end you will still finish as a begger. And, me personally, I wouldnt dare to do it in states. Actually I would rather do it in Switzerland. Or maybe even Thailand.

Re: Looking Back at the Snowden Revelations

#193

As someone not from the US, the passages about how easy it was are clear reminders that just because only the NSA got caught, does not mean only the NSA was doing it. Even if they have by far the biggest budget...

We’ve seen other stories, Stuxnet in particular that implicate other countries like Israel. Anyone that thinks that the USA and Israel are spending money on cyber warfare but China and Russia are not is living in a fantasy world. Maybe some small countries like Andorra don’t have a cyber warfare division, but all the big countries do. Everyone is being spied on. Perhaps the only distinction worth making is whether yo…

and not to mention for small time people, there are nefarious people who want to spy on you so they can do identity theft or similar crime to you. So even if you are one of those "I have nothing to hide" people, you still need to hide your personal information due to cyber crime that could be used to exploit you. For some people, it is almost laughable the amount of information they put out openly on social media.

Re: Looking Back at the Snowden Revelations

#195

Earlier quoted context omitted.

You must not understand how cyber war works. The US has judges and legislation to enable the NSA. Russia, China, Iran, NK, and many other authoritarian states seek to use their power to attack America 24x7 and do so without any oversight.

A few countries actively try to hurt us, so let's spy on everyone, including our own citizens and allies!

[deleted]

Re: Looking Back at the Snowden Revelations

#196
post #66

Earlier quoted context omitted.

Yeah, we'll just go ahead and use x86 processors from AMD, another US company, which are surely not backdoored...

AFAIK, the equivalent of IME is not present in all AMD processors, only (maybe) those with integrated graphic chips ? But overall, yeah, Europe should just create their own chip industry, it's too critical to leave it to others...

https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo...

Re: Looking Back at the Snowden Revelations

#197

Naive question: This cryptography blog seems to, but... is WhatsApp really trusted as secure end-to-end encryption chat client? Colloquially, for one thing it's now owned by one of the biggest personal-data collection companies in the world, which would have little interest in owning a chat client it couldn't benefit from data-wise. For another, I read an article mentioning it was "known" that WhatsApp decrypted your…

It is highly unlikely that Facebook can read WhatsApp messages. The reason I say that is that Zuckerberg said the couldn't, repeatedly and explicitly, to Congress. If there was any chance that they could, he would have either not said anything (the context would have allowed for that) or he would have dissembled. As he did numerous other times on other subjects. As to benefiting from WhatsApp, I'm sure they benefited…

> It is highly unlikely that Facebook can read WhatsApp messages. The reason I say that is that Zuckerberg said the couldn't,

Not wittingly.

Re: Looking Back at the Snowden Revelations

#198

> ... — the agency spent $250 million per year on a program called the SIGINT Enabling Project. Its goal was, basically, to bypass our commercial encryption at any cost. Now that things have actually started going dark for these overfunded and completely unaccountable entities this is where the biggest danger lies. They have become so desperate for continued access to endless funding that they are actually turning ag…

Last year the Australian government even went so far as to pass a law allowing them to force companies to sabotage their own products/services in cases where a government agency wants to get access to someone's communications. https://www.engadget.com/2018/12/07/australia-access-assista...

For an extra scary thought: Atlassian are Australian. Jira tickets can be forced to be altered or deleted, and codebases hosted on bitbucket shouldn't be assumed as trusted. You'll never see a Jira ticket about a 0-day the Australian government doesn't want you to fix if they decide to utilize this law.

Re: Looking Back at the Snowden Revelations

#199
post #185

Earlier quoted context omitted.

“Security of organisations should be done in layers” and each layer makes breaking into your (whole) organisation harder, but comes with friction for your staff.

No, I think the new consensus is that all systems are vulnerable (obviously true if all systems have users with access, whom may be compromised) - so not layers: compartments (and need to know;need to access). I believe this is part of eg google/alphabet's new model: no hard wall, soft "inside" (egg model). Just stand alone secure sub-systems with ACL (access control lists) mediating access on a user-by-user, sub-sys…

Sure, I used (or the person I’m quoting used) the wrong term, thanks for the clarification. I did mean and he meant compartmentalising :-)

Re: Looking Back at the Snowden Revelations

#200
post #185

Earlier quoted context omitted.

“Security of organisations should be done in layers” and each layer makes breaking into your (whole) organisation harder, but comes with friction for your staff.

No, I think the new consensus is that all systems are vulnerable (obviously true if all systems have users with access, whom may be compromised) - so not layers: compartments (and need to know;need to access). I believe this is part of eg google/alphabet's new model: no hard wall, soft "inside" (egg model). Just stand alone secure sub-systems with ACL (access control lists) mediating access on a user-by-user, sub-sys…

Virtualization, privilege management, etc. are still another layer.
Post reply on HN