Live data from Hacker News

U.S. surveillance laws have proven ineffective at countering terrorism

theprivacyissue.com

81–90 of 135 posts

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#81
post #11

"Two reasons why people do stuff - one that sounds good and the real reason." - JP Morgan

https://quoteinvestigator.com/2014/03/26/two-reasons/

TBH after reading that it still sounds like JP Morgan or Roosevelt is a safe attribution choice there. The particular structure of the sentence combined with "commonly used by" or "made popular by", etc is sufficient IMO. Quote sourcing is always a bit vague.

Or maybe just saying "as the commonly used phrase goes" is better.

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#82
post #43

The threat of terror gives power to the State. Power seeks more power. The State does not erode freedoms in support of safety. The State erodes freedoms to achieve more power. Terror is the excuse. It is the State's greatest tool.

> Those who would give up essential liberty, to purchase a little temporary safety, deserve neither liberty nor safety. - Benjamin Franklin

That quote doesn't mean what many people assume it does.

Franklin was actually supporting the authority of government to act/govern in the interest of collective security. [1]

[1] https://www.npr.org/2015/03/02/390245038/ben-franklins-famou...

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#83
post #43

The threat of terror gives power to the State. Power seeks more power. The State does not erode freedoms in support of safety. The State erodes freedoms to achieve more power. Terror is the excuse. It is the State's greatest tool.

Are you saying the state is effective? That there is no terrorism to counter act. The title seems to suggest the state needs more power or different tatics because there is terrorism that is not beong effectively acted againts.

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#84

The only measure that needed to be done after 9/11, and it's surprising why this very effective measure wasn't implemented before - securing access to the pilot's cabin. Everything else is overreaction cause by power grabbing by "security agencies" and politicians trying to score. The whole security system of today's world (especially in flying) is one pointless thing after another, holding on the a fear of "what if"…

Doesn't help when it's a pilot who wants to crash the plane. Further, that makes it impossible for anyone to intervene in that case.

Screening of pilots for various issues, mental and performance wise, has increased substantially since 9/11 as well.

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#85

Earlier quoted context omitted.

> VPNs do help maintain one small level of privacy (namely from your ISP) So you've transferred the lack of privacy from one company (your ISP) to another (your VPN vendor). Heck - look what happened to Onavo - facebook bought them and reaped a treasure trove of private browsing habits.

Well your VPN has a commercial interest in keeping your browsing private.

That hasn't proved to be the case. Nor does it appear so anyways, they have a commercial interest to appear as though they are interested in keeping your browsing private.

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#86

Earlier quoted context omitted.

> Those who would give up essential liberty, to purchase a little temporary safety, deserve neither liberty nor safety. - Benjamin Franklin

There's an interesting NPR interview on the origin of that quote: https://www.npr.org/2015/03/02/390245038/ben-franklins-famou... tl;dr; Franklin was defending government spending on defense

Interesting read, thanks for that.

I'll update the tldr with two quotes

> It is a quotation that defends the authority of a legislature to govern in the interests of collective security. It means, in context, not quite the opposite of what it's almost always quoted as saying but much closer to the opposite than to the thing that people think it means.

> And maybe it doesn't matter so much what Franklin was actually trying to say because the quotation means so much to us in terms of the tension between government power and individual liberties. But I do think it is worth remembering what he was actually trying to say because the actual context is much more sensitive to the problems of real governance than the flip quotation's use is, often.

I think the second quote is important, because sayings change over time and the meaning they hold changes too. That is the progression of language.

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#87
Law enforcement, tasked with catching the baddies, always wants more ability to complete their task: more surveillance, more laws, and more firepower. That's as it should be.

The problem is the lack of heavy-weight counter-balance, always demanding more privacy, fewer laws, and less firepower. The best we've got is "the status quo" and a few non-profits (that thankfully are punching way above their weight class).

Without such a counterbalancing agency, each small gain by law enforcement rarely reverts, so rather than oscillating between a bit too much freedom and a bit too much policing we have an arrow moving us steadily toward a police state.

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#88

The only measure that needed to be done after 9/11, and it's surprising why this very effective measure wasn't implemented before - securing access to the pilot's cabin. Everything else is overreaction cause by power grabbing by "security agencies" and politicians trying to score. The whole security system of today's world (especially in flying) is one pointless thing after another, holding on the a fear of "what if"…

> securing access to the pilot's cabin

Well, no, actually it was impossible to get into the cabin from outside long before 9/11 (in fact, I think since the 70’s). The hijackers smuggled box-cutters on board and used the box cutters to kill stewardesses until the pilot agreed to open the door - after which they had full access to the plane.

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#89

Earlier quoted context omitted.

What is the mis-selling exactly? Doesn't seem to me that they're saying using their VPN will make you impenetrable to dedicated actors with nation-state resources. VPNs do help maintain one small level of privacy (namely from your ISP), and if you're using one it's a good bet you'll be interested in other privacy concerns too. There are a lot of VPNs with really bogus claims on their websites but I didn't notice anyt…

Between TLS and DNS over HTTPS, the number of things an ISP can reliably discern from your traffic is becoming vanishingly small. Once the TLS SNI plaintext hole is closed, it becomes smaller still. One can argue that IPs and ports matter, but if all the IPs you visit are in AWS (and their ilk) over 443 (including real time communication protocols), it becomes meaningless.

I apologize for a somewhat snippy comment, but the idea that VPNS don't really protect against bad ISPs comes up all the time, and it drives me bonkers.

> Between TLS and DNS over HTTPS, the number of things an ISP can reliably discern from your traffic is becoming vanishingly small.

A) While encryption is commonplace, not everything on the web is encrypted. The most recent stats I can find[0] say that about 3-10% of common web traffic is still not encrypted. If you're browsing more interesting parts of the web (ie, old forums and independent sites, and not just Facebook/CNN) your stats are probably worse.

B) Even if all of the websites you visit are fine, a nontrivial portion of native apps also don't use encrypted endpoints, because unlike on the web there were never native warnings or lock icons in a URL bar to force them to make the change.

C) Even if the server is using TLS, there are numerous attacks based around measuring packet delivery times and request sizes to figure out exactly which static pages of a domain you're visiting. This is why Linux package managers have widely dismissed HTTPS -- it provides no privacy for their specific use-case, because anyone can figure out what you're downloading just by counting how many bytes get sent to you.

D) So you just turn on DNS over HTTPS, right? Sounds good, except pretty much none of your native apps or dedicated devices like game consoles, e-readers, and smart-home appliances support it unless you're handling it on the network level. Even if you are doing DOH on your router, it's not uncommon for dedicated devices to bypass your DNS settings entirely. Even Google is guilty of this, for a long time you could not set a Chromecast to use a custom DNS server.

E) Even if you have DNS over HTTPS, you still need to worry about SNI, and encrypted SNI still has relatively low adoption on the web outside of industry-leaders like Cloudflare.

----

But let's assume that none of the above applies to you. You're connecting to a site that's using TLS 1.3 and supports encrypted SNI. You're using DNS over HTTPS. In that scenario, knowing the IP/port of the server you're connecting to can still be good enough to unmask the domain.

You do bring up this point, but then you kind of just skip over it.

> One can argue that IPs and ports matter, but if all the IPs you visit are in AWS (and their ilk)

But they're not. Yes, if every single site I visited had the same IP, I'd be fine leaking that information. But they don't all have the same IP. I visit plenty of sites that are being hosted on independent hardware, on Linode servers, and so on. Servers with unique, static IPs are not uncommon.

Not only is this bad advice in the sense that it just isn't true, it's also bad advice because it's tying security/privacy to centralization. We want people to host their own stuff online, we don't want everyone to be on AWS and Google Cloud. We want diversity of hosting.

----

Finally, although I understand you're only talking about ISPs above, it's also worth noting that the point of a VPN is not just to obscure your traffic from your ISP, it's also to obscure your IP address from the sites you visit. That's also an idea that gets regularly dismissed by a vocal subgroup on HN, who are apparently of the opinion that the entire TOR project is just a waste of time because IP addresses don't actually matter.

VPNs are not a perfect solution. They're arguably not a even a good solution. But the problem that they're trying to solve does exist. There are reasonable, strong arguments to make against VPNs: that they aren't magic, that they're deceptively marketed, that shifting trust can be problematic. "IP addresses aren't worth protecting", or "DNS is fine already", are not reasonable arguments.

[0]: https://transparencyreport.google.com/https/overview

Re: U.S. surveillance laws have proven ineffective at countering terrorism

#90

The only measure that needed to be done after 9/11, and it's surprising why this very effective measure wasn't implemented before - securing access to the pilot's cabin. Everything else is overreaction cause by power grabbing by "security agencies" and politicians trying to score. The whole security system of today's world (especially in flying) is one pointless thing after another, holding on the a fear of "what if"…

Doesn't help when it's a pilot who wants to crash the plane. Further, that makes it impossible for anyone to intervene in that case.

what are you saying here? you would argue that cabin should not be secure, so as to guard against a hypothetical attacker who completes professional pilot certification and gets a job as a copilot for the sake of (hopefully) overcoming the captain 1 versus 1 and brings down the plane?

because that seems ridiculous

Post reply on HN