Live data from Hacker News

Julian Assange: Cryptographic Call to Arms

cryptome.org

11–20 of 281 posts

Re: Julian Assange: Cryptographic Call to Arms

#11

> The world is not sliding, but galloping into a new transnational dystopia. This development has not been properly recognized outside of national security circles. I agree with Moxie Marlinspike on that, we were preparing for fascism but got social democracy[1]. Assange is still preparing for fascism. [1] https://www.youtube.com/watch?v=eG0KrT6pBPk

"Assange is still preparing for fascism." You mean the guy who is in internal exile in Britain because as a journalist he revealed war crimes committed by Britain's partner the United States? He's the guy who is delusional about the form of government that surrounds him, huh? Glad it's as simple as that.

To add some more complexity: the reason he is in a dodgy situation in the first place are rape allegations. Looking at some "leaked" parts of his biography this doesn't sound too far-fetched to me.

I definitely appreciate his engagement in disclosing many interesting documents about the micro-social diplomatic environment. But after all, what about the more interesting stuff? Leaked documents from the center of the turbo capitalist universe are still pending. (IIRC those were promised for around last christmas...)

Re: Julian Assange: Cryptographic Call to Arms

#13
I think this is very relevant here - interview with the NSA whistleblower, William Binney, on how NSA is storing every post people are making online, so they (and FBI) can use it later:

http://www.youtube.com/watch?v=TuET0kpHoyM

No wonder NSA and FBI want warrantless access to private companies by lobbying for new laws like CISPA, and trying to build backdoors in services like Facebook, Skype, Twitter etc. They want to know absolutely everything you do online, besides your public posts:

http://www.wired.com/threatlevel/2012/05/fbi-seeks-internet-...

I don't know if they are doing it out of malice/power grabbing/control, or purely as a way to make their jobs more "efficient". But their #1 priority should always, always, be respecting the Constitution, and not trying to skirt around it. And I think they've forgotten all about that long ago.

Re: Julian Assange: Cryptographic Call to Arms

#14

I think that more focus, at least in the short term; needs to be put on making crypto accessible to windows users. As an example, consider the following project website: https://www.gpg4win.org/ An invalid security certificate, and even that only if you go out of your way to specify https. If the vast majority of users saw this, they'd go running; including myself. I can't in good conscious recommend crypto that does…

I feel pretty safe predicting that most communications are moving to mobile, vs. desktops. Even if you have a desktop, most of your communications will happen on a mobile device.

The thing we really need (and what I'd fund if I had a spare $Xmm or so) is a great crypto API and solution to the user key management problem for iOS and Android, hooked into apps. It's technically easier to do on Android. On iOS, you're kind of stuck due to the core apps (mail, messages, etc.) being first-party Apple). It basically would take Apple deciding they cared about this issue, then building it into the OS in a way which didn't actually require trusting Apple completely, to work very well. Android has some steps toward this with some NSA projects, and wouldn't even necessarily require a full forking.

Some way to do tokenization and thus fairly transparent encryption on the client (phone) inside apps like the Facebook App, Twitter, etc. would also be nice. That's both a technical challenge and a UI/UX problem.

Silent Circle (from Jon Callas, Phil Zimmerman, Vinnie Moscaritolo (the PGP team...) and some Navy SEALs and defense contractors I knew from Iraq) actually seems like a pretty viable choice for sms, email, and voice right now. It unfortunately doesn't integrate into the social networks and other services people use, though.

Re: Julian Assange: Cryptographic Call to Arms

#15
This kind of over-the-top writing confirms what I already thought, which is that despite whatever good he might do in terms of exposing corrupt governments in the world, Julian Assange is just desperate for attention.

Being this paranoid he should be advocating "post-quantum cryptography", i.e. cryptographic methods that are secure even once somebody develops a quantum computer.

https://en.wikipedia.org/wiki/Post-quantum_cryptography

Re: Julian Assange: Cryptographic Call to Arms

#16
post #14

I think that more focus, at least in the short term; needs to be put on making crypto accessible to windows users. As an example, consider the following project website: https://www.gpg4win.org/ An invalid security certificate, and even that only if you go out of your way to specify https. If the vast majority of users saw this, they'd go running; including myself. I can't in good conscious recommend crypto that does…

I feel pretty safe predicting that most communications are moving to mobile, vs. desktops. Even if you have a desktop, most of your communications will happen on a mobile device. The thing we really need (and what I'd fund if I had a spare $Xmm or so) is a great crypto API and solution to the user key management problem for iOS and Android, hooked into apps. It's technically easier to do on Android. On iOS, you're ki…

I feel pretty safe predicting that Desktop computing will be around for a while yet.

I also feel pretty safe in saying it's not an either or thing, we can have both; and should.

Re: Julian Assange: Cryptographic Call to Arms

#17
A sufficiently motivated government has a nearly infinite amount of tools available for breaking encryption. Ignoring the possibility that it might know proprietary weaknesses to various systems (a hypothesis that is unknowable), there's just so much you need to secure at each node in a computer system.

Are you personally sure no backdoors exist in the physical hardware you use? In the operating system you use? In the compiler used to build your OS? In any of the applications on your system? Are you sure that there's not a hardware keylogger on your keyboard, and do you check every day before sitting down that there's not one? Are there any secret cameras pointed at your keyboard, or sensitive microphones hidden nearby that can distinguish what keys you hit?

And once you're sure of all that, are you just as sure everyone you communicate with is equally diligent?

And, while we're at it, have you come up with a solid patch to prevent the well-known rubber hose vulnerability that exists in all cryptographic systems?

That doesn't mean the crypto-anarchist project must fail. Encryption is invaluable: while the vast majority of other technological advances--sedentary agriculture, writing, maths, roads, sewage systems, paper, the telegraph, electricity, the light bulb, cars, "computers," satellites, Google--have all increased the legibility of the world to the State, encryption does the opposite. The panopticon isn't an existing, established system but instead an equilibrium point that the State has to constantly push us toward: anytime the economic cost of that push is increased, it gives us more opportunities for creating spaces of genuine human autonomy.

But once you recast crypto-anarchism in that more moderate and stronger form, encryption moves from "our one hope against total domination" and a "hope that with courage, insight and solidarity we could use to resist" to something more banal: one tool of many. Not even a particularly effective tool: governments don't care about a bunch of nerds throwing PGP parties, and all the encryption in the world hasn't prevented the State from throwing Assange into jail (a pleasant jail with some fine Ecuadorian decor, but a jail nonetheless) and obliterating his organization.

Re: Julian Assange: Cryptographic Call to Arms

#18
I agree with the sentiment, but Assange's prose is a little dense. Maybe it's OK for his target audience, as I assume the layman won't be reading cryptome.org.

What we really need is a champion to explain in relatable, plain English why encryption is essential even for mom and dad, and to explain it in a more mainstream venue. I think a big reason why people don't encrypt mail, etc., is because:

1) they don't know why it's important because nobody can explain it to them in relatable terms (like saying: when you send an email, Google keeps a copy forever, and the FBI can read it just by picking up a phone and asking nicely), and

2) if they do know the importance, the practicalities of encryption are explained impenetrably. A blur of acronyms, bad metaphors ("keys?" terrible choice of metaphor, considering how a pair is intertwined and their actual use), and no well-known authority you can trust to explain it all simply.

The problem isn't that people don't care. They would care if they knew the realities of how their communications are stored, processed, and exposed to their governments. The problem is that nobody can explain it to them in a way that's not ridiculously complex or laden with terms like "Platonic realm" and "transnational dystopia".

Re: Julian Assange: Cryptographic Call to Arms

#19

This kind of over-the-top writing confirms what I already thought, which is that despite whatever good he might do in terms of exposing corrupt governments in the world, Julian Assange is just desperate for attention. Being this paranoid he should be advocating "post-quantum cryptography", i.e. cryptographic methods that are secure even once somebody develops a quantum computer. https://en.wikipedia.org/wiki/Post-qua…

Nice username you got there. So you're saying this all conspiracy theory stuff? I think we've gotten way passed the point where the fact that the government monitors everyone online is just a conspiracy theory.

Re: Julian Assange: Cryptographic Call to Arms

#20

First, recall that states are systems through which coercive force flows. Factions within a state may compete for support, leading to democratic surface phenomena, but the underpinnings of states are the systematic application, and avoidance, of violence. Land ownership, property, rents, dividends, taxation, court fines, censorship, copyrights and trademarks are all enforced by the threatened application of state vio…

Assange speaks truth. You cannot deny the fundamentals of the state are violence. The US speaks already of a capacity for instant global weapon strikes within the hour. You claim it is wrong to question the system, implicitly suggesting there is no alternative. But anthropology shows clearly that premodern societies had more free time, greater material and economic equality. (Try 'Debt: The First 5000 Years').

You attack a perspective, quoting on a tangent, without contributing anything meaningful except the notion that government can have value: but of course! Nobody denies this.

Assange and other politically engaged hackers like him seek improved systems of governance: greater protection of fundamental freedoms, greater availability of additional freedoms, greater truth and transparency.

Relax, nobody wants to topple your car and burn your house down.

Post reply on HN