Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

151–160 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#151
post #53
post #44

Earlier quoted context omitted.

Most of the times, "sollen" and "müssen" are interchangeable. However, there are fine nuances between the words. In that case, "müssen" is more direct and used as a command which has consequences when not followed while "sollen" is more of a prompt or demand that hasn't to be followed.

I think a better translation for 'sollen' would be 'shall'.

And "müssen" is "must".

Re: New German law would force ISPs to allow secret service to install trojans

#152
post #124
post #107

Earlier quoted context omitted.

DNS usually isn’t, and TLS still runs over TCP, which is vulnerable to this type of hijacking, so yes, it is indeed still relevant due to both resolution as well as transport layer. NSA would be very bad at their job indeed if they couldn’t issue valid TLS certificates for any domain to themselves.

>NSA would be very bad at their job indeed if they couldn’t issue valid TLS certificates for any domain to themselves. Is there any evidence of this? With certificate transparency being mandatory a few years ago, you'd think that the NSA would be caught at least once.

There are 270+ CAs out there. All the NSA has to do is compromise the CA cert keys of one of them and they can then generate their own valid certs, completely disconnected from CT. All CT tells you is somebody goofed, was tricked into issuing a cert, or an account was compromised and an attacker generated a cert. In other words, not-super-advanced attacks.

The NSA have plenty of tricks. They intercept devices being shipped around the country/world, they tap cables, they dig into airgapped networks, they compromise satellites, they compromise the internal networks of the world's biggest corporations. They've been doing this for decades. If we don't believe they can compromise one organization out of 270...

Re: New German law would force ISPs to allow secret service to install trojans

#153

To not even be sure whether a website you visit, or a file you download is actually what its creator says it is, is like picking up an orange but the government secretly replaces it with an apple that contains almost no vitamin C in it at all. You have the right to seek out and eat an orange for your immune system and survival, and no government should have the right to interfere with that, at any time. This law is a…

Absolutely true and brilliant comparison. +1

What. Its awful. Privacy doesnt need comparisons or analogies. We have the language to describe privacy in native terms. We dont need help of figurative speech mixing and muddying the waters.

Re: New German law would force ISPs to allow secret service to install trojans

#154

To not even be sure whether a website you visit, or a file you download is actually what its creator says it is, is like picking up an orange but the government secretly replaces it with an apple that contains almost no vitamin C in it at all. You have the right to seek out and eat an orange for your immune system and survival, and no government should have the right to interfere with that, at any time. This law is a…

> Whoever proposed it should be ashamed of themselves Name and shame: Interior Minister Horst Seehofer of the conservative-authoritarian CSU. He and his party friends are who want this. We have the chance to kick them out of office in 2021, it's time for the stranglehold of Conservative internet-printers (Internetausdrucker, a German word for tech illiterates) as Interior Ministers to end once and for all .

> ...internet-printers (Internetausdrucker, a German word for tech illiterates)

Let me guess, this word describes people who print out their emails?

Re: New German law would force ISPs to allow secret service to install trojans

#155
post #96

Germany hassome weired laws that prohibit the use of "hacker tools". How can there be a German company creating these tools?

The hacker tool paragraph is pretty toothless. I just checked one of those legal tech apps and see 12 judgements total that even mention it. There was quite a bit going on when it passed that effectively clarified that working on, and with, tools like that is legal when there's an assumption of dual use for legitimate purposes, e.g. security research (which is like... all of them). LE use would likely benefit from the same assumption.

Re: New German law would force ISPs to allow secret service to install trojans

#156
post #153

Earlier quoted context omitted.

Absolutely true and brilliant comparison. +1

What. Its awful. Privacy doesnt need comparisons or analogies. We have the language to describe privacy in native terms. We dont need help of figurative speech mixing and muddying the waters.

I love making analogies. I even compared apples to oranges and it worked!

Humour aside, analogies are really important and I have never understood the disparagement of comparing one group or situation to another. Analogising is a tool to help understand one other and promote diversity.

Re: New German law would force ISPs to allow secret service to install trojans

#157
post #143
post #73

Earlier quoted context omitted.

Snowden uncovered astonishing breaches of Trust in the US, has there been a major loss of Hosts here?

Nope, everyone happily shovels all of their data, as well as all of the data their customers provide them, into AWS, which is very cosy with the US military. You can be reasonably certain that anything in AWS is available to US military intelligence without judicial oversight.

Every American service and product needs to be treated as compromised, it really comes down to that.

Individual companies now need to earn back basic trust.

This doesn't mean you have to completely abandon your favourite service, just have to modify the way you utilize it.

For example, if you absolutely have to use Google Drive, be sure to encrypt your files with appropriate strength first and assume they are actively trying to decrypt and build a file on you.

Re: New German law would force ISPs to allow secret service to install trojans

#158
post #154

Earlier quoted context omitted.

> Whoever proposed it should be ashamed of themselves Name and shame: Interior Minister Horst Seehofer of the conservative-authoritarian CSU. He and his party friends are who want this. We have the chance to kick them out of office in 2021, it's time for the stranglehold of Conservative internet-printers (Internetausdrucker, a German word for tech illiterates) as Interior Ministers to end once and for all .

> ...internet-printers (Internetausdrucker, a German word for tech illiterates) Let me guess, this word describes people who print out their emails?

Not only mails. I had teachers printing out web pages before reading them because it felt more natural for them.

Re: New German law would force ISPs to allow secret service to install trojans

#159
post #153

Earlier quoted context omitted.

Absolutely true and brilliant comparison. +1

What. Its awful. Privacy doesnt need comparisons or analogies. We have the language to describe privacy in native terms. We dont need help of figurative speech mixing and muddying the waters.

I think this blog does what you expect

> Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say

https://write.privacytools.io/freddy/why-privacy-matters-eve...

Re: New German law would force ISPs to allow secret service to install trojans

#160
post #40
post #31

Earlier quoted context omitted.

They just have to hijack one existing CA that's within their jurisdiction and force it to issue MITM certs. Key pinning or certificate transparency may mitigate this. Or the MITM box could use some kind of HTTP downgrade attack and not worry about certificates at all.

That would "burn" the CA (it will be removed and/or blacklisted from every major browser and operating system once it's exposed, and exposing it gets much easier with the recent push towards certificate transparency), so it can only be done once per CA.

Just wait a few years. I'm sure we will get something to support this on the EU level. It'll be positioned as fighting for your freedom and every company that doesn't implement them is the worst.
Post reply on HN