This is why I'm glad HTTP 2.0 intends to implement SPDY's always-on encryption. It probably won't be long until governments find a way around that, especially the US government, who can pretty easily gain access to companies like Google, Verisign, and even ICANN, but it would be a good first step in the right direction. Hopefully future steps like web crypto will help increase the security of people's conversations o…
Alway-on encryption is necessary but not sufficient. As long as Facebook or Google have the decrypted information, you are still subject to the transnational dystopia. The other day I found this fellow's idea for a peer-to-peer social network service: http://code.google.com/p/peer-book/ "Your data is stored in a distributed fashion, across the network, so that even when you turn off your instance of PeerBook, your fr…
Julian Assange: Cryptographic Call to Arms
201–210 of 281 posts
Re: Julian Assange: Cryptographic Call to Arms
#202Strong cryptography can resist an unlimited application of violence. No amount of coercive force will ever solve a math problem. Not entirely false, but http://xkcd.com/538/
http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis | http://en.wikipedia.org/wiki/Rubberhose_(file_system)
Wired in 2008: "Among other achievements, he [Assange] co-invented Rubberhose deniable encryption, which would let a dissident being tortured reveal one key to unlock a hard drive, while not giving away that there was a second or third password-locked folder of information."
http://www.wired.com/politics/onlinerights/news/2008/07/wiki...
Re: Julian Assange: Cryptographic Call to Arms
#203Strong cryptography can resist an unlimited application of violence. No amount of coercive force will ever solve a math problem. Not entirely false, but http://xkcd.com/538/
Long before Wikileaks, Assange worked on a project called "Rubberhose". (A hidden encrypted filesystem designed to offer protection against cryptanalysis by torture.) http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis | http://en.wikipedia.org/wiki/Rubberhose_(file_system) Wired in 2008: "Among other achievements, he [Assange] co-invented Rubberhose deniable encryption, which would let a dissident being tortured…
Re: Julian Assange: Cryptographic Call to Arms
#204Earlier quoted context omitted.
The FBI's actions aren't in any way different then Google. Who also crawl the Internet and download every post people make.
Sure they aren't, the difference lies on what they do with the data. While Google will use that data to show you harmless text advertisement, the FBI might use it to backup a phony case against you, that can ultimately put an end to your freedom. I'd say that's an incredible difference. Wouldn't you too?
I'd stay both sides are bad. We may see them as completely different things, but you have to agree, in both sides, what we see is just the tip of the iceberg.
Re: Julian Assange: Cryptographic Call to Arms
#205In maybe five to ten years, the internet will effectively split in two. There will be major, commercial service providers such as Facebook-type social media hubs, major news sites but there will also be an invisible internet that is everything internet used to be, and in addition to that encrypted, anonymous, and untraceable. How it shows most prominently at the moment is file sharing. Setting the endless copyright d…
> there will be a major "bazaar" going on underground I thought most people here had heard of The Silk Road onion service: https://en.wikipedia.org/wiki/Silk_Road_%28marketplace%29 > An online bank could very well operate in the anonymous network because the traffic is already cryptographically signed, and users can enjoy strong authentication if they wish to or remain a pair of anonymous public/private keys. Or you…
The longer this fiction persists, the less chance a fundamentally decentralized crypto currency will take hold. Trusted 3rd parties will always be necessary, and that's not a de facto bad thing.
Re: Julian Assange: Cryptographic Call to Arms
#206This xkcd strip was never more on-topic than now. http://xkcd.com/538/
Re: Julian Assange: Cryptographic Call to Arms
#207In maybe five to ten years, the internet will effectively split in two. There will be major, commercial service providers such as Facebook-type social media hubs, major news sites but there will also be an invisible internet that is everything internet used to be, and in addition to that encrypted, anonymous, and untraceable. How it shows most prominently at the moment is file sharing. Setting the endless copyright d…
I found your comment more insightful than the article.
Re: Julian Assange: Cryptographic Call to Arms
#208Earlier quoted context omitted.
> When the masses go for it, the capacity and availability of invisible darknets will raise in orders of magnitude. this is predicated on the assumption that providers are not strangled by their balls by the authorities (who is in turn strangled by the balls by lobbiests/companies/vested interests). If you could run your own routes with private equipment (such as a mesh like wireless network?), instead of having to s…
Will ISPs be forced to disallow all encrypted traffic? That would be disastrous. It's already possible to connect to a website over https (with a self-signed cert you've obtained through a second channel) and be pretty much certain no one is snooping. The target you're connecting to doesn't have to be obvious either.
Re: Julian Assange: Cryptographic Call to Arms
#209Earlier quoted context omitted.
> When the masses go for it, the capacity and availability of invisible darknets will raise in orders of magnitude. this is predicated on the assumption that providers are not strangled by their balls by the authorities (who is in turn strangled by the balls by lobbiests/companies/vested interests). If you could run your own routes with private equipment (such as a mesh like wireless network?), instead of having to s…
Will ISPs be forced to disallow all encrypted traffic? That would be disastrous. It's already possible to connect to a website over https (with a self-signed cert you've obtained through a second channel) and be pretty much certain no one is snooping. The target you're connecting to doesn't have to be obvious either.
Re: Julian Assange: Cryptographic Call to Arms
#210Why It Matters: [...] This blog isn’t terribly controversial. But if only the “controversial” stuff is private, then privacy is itself suspicious. Thus, privacy should be on by default.
https://www.tbray.org/ongoing/When/201x/2012/12/02/HTTPS
EDIT: Ironically, I accidentally linked to the non-HTTPS version. Fixed.