Live data from Hacker News

Jimmy Wales threatens to encrypt Wikipedia if UK passes snooping bill

arstechnica.com

21–30 of 40 posts

Re: Jimmy Wales threatens to encrypt Wikipedia if UK passes snooping bill

#21

Earlier quoted context omitted.

So what do you guys do to counter this? Do you use encrypted VPNs? Any specific ones you'd recommend?

check mullvad. you can pay with cash over mail, bitcoin or whatever. no logs, two external ip's for thousands of customers. google it

Looks interesting, but who is to say they don't keep logs?

A VPN on VPS provider, whom accepts similar payment options is an alternative option.

Re: Jimmy Wales threatens to encrypt Wikipedia if UK passes snooping bill

#22
post #8
post #5

They should do this anyways. It's well known to the technical elite that dragnet surveillance is going on— but it's not known to the general public. It's arguably immoral that the site doesn't switch to https by default and give the public the privacy they think they already have.

What makes you think that those with the resources to implement dragnet surveillance do not have access to properly signed certificates, which let them Man-In-The-Middle the connection without triggering a browser warning?

As you say, some of the parties engaging in the drags absolutely do have the capability. But not all and stopping them has value. More importantly:

A man in the middle attack is _highly_ detectable and will leave irrefutable evidence when detected. So it can only be used secretly if it's used very sparingly. And highly overt interception, if its even tolerated by the public, at least solves the problem of people having no idea (being in denial) they're being watched.

Moreover, because MITM can be defeated by de-trusting the rogue CA or via key pinning using it for "mere" surveillance would destroy a valuable and potent weapon, so they won't do it. It simply isn't suitable for dragnet use.

Its also practically much more costly to scale. (E.g. instead of passive optical taps and cheap packet sampling for targeting they must fully intercept all the traffic and decrypt/reencrypt before they even know if its "interesting") Simply making the watchers have to spend a lot more money per unit of traffic monitored is a win for civil rights because it should result in more conservative use of the capability. Without the crypto the surveillance is maximally cheap and undetectable... anything is an improvement even if it can still be compromised.

Re: Jimmy Wales threatens to encrypt Wikipedia if UK passes snooping bill

#25
post #8
post #5

They should do this anyways. It's well known to the technical elite that dragnet surveillance is going on— but it's not known to the general public. It's arguably immoral that the site doesn't switch to https by default and give the public the privacy they think they already have.

What makes you think that those with the resources to implement dragnet surveillance do not have access to properly signed certificates, which let them Man-In-The-Middle the connection without triggering a browser warning?

http://convergence.io

Re: Jimmy Wales threatens to encrypt Wikipedia if UK passes snooping bill

#26
post #20

This is one reason why enacting this kind of legislation is such a terrible idea for the very people advocating it. Right now most of the web is ridiculously open and unencrypted. If authorities get the appropriate warrants it's almost guaranteed they will be able to spy on almost anybody doing almost anything because the default mode is unencrypted and nobody really thinks about it. But that default mode is only the…

This is, of course, assuming, that the government is creating this law for the reason of solving crime and not for some special interests / lobbies.

Re: Jimmy Wales threatens to encrypt Wikipedia if UK passes snooping bill

#27
post #4

Maybe a little bit of a sensationalist title, websites switching to HTTPS only isn't that much of a threat, yes the bill is bad and yes he should be opposing it but Ars seem to frame it as though it's drastic or has a negative effect on anyone. While I disagree with the bill and the concept of monitoring peoples internet, I don't think they're doing it so they can find out what you're reading on Wikipedia or who you'…

> I don't think they're doing it so they can find out what you're reading on Wikipedia or who you're messaging on Facebook. What makes you think that sort of information isn't exactly what they're interested in? Even if they don't care about it right now, once it starts being collected, if any future government decides they do care about it, it'd be very easy for them to get their hands on it.

This is actually one of the more interesting things about how data is being collected these days... because we (or rather, our machines) now have the capacity to scavenge and parse so much more data than we could've dreamed of before, people, corporations, governments, etc. have already caught on to the idea that you don't actually need to know your angle before you execute. Gathering tons and tons of data may seem completely worthless or missing the point, but the reality is that "the point" no longer exists. It's all just floating data that, when the time comes, either passes through the filter or throws a flag.

Basically, the government may not care who you're messaging on facebook now, but if someone discovers a correlation to some other problem in the future they'll be damn pleased that they have that data.

Re: Jimmy Wales threatens to encrypt Wikipedia if UK passes snooping bill

#28
post #21

Earlier quoted context omitted.

check mullvad. you can pay with cash over mail, bitcoin or whatever. no logs, two external ip's for thousands of customers. google it

Looks interesting, but who is to say they don't keep logs? A VPN on VPS provider, whom accepts similar payment options is an alternative option.

Even if they did keep logs, there's only 2 external IPs.
Post reply on HN