Live data from Hacker News

Why we can't go back to business as usual post-PRISM

mailman.stanford.edu

11–20 of 186 posts

Re: Why we can't go back to business as usual post-PRISM

#12

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity.

So it was easy to imagine that only a few things were being intercepted: Communications be an amorphous "bad people". A distant problem for someone else.

In the mean time digital communications devices, cloud services, social media, etc. have become increasingly central to our lives— mediating more and more of our most private communications and storing our most trusted data. Most of it has built on an architectural house of cards which provides little systemic security beyond "hasn't screwed you yet".

The fact that this is happening to _everyone_, that the data is being correlated and stored— perhaps forever— that the argued legal basis of the program itself is cloaked in secrecy, that the public has been denied the ability to question something that potentially impacts the entire world, that the leaders of technology companies that we trust with our most personal data are either clueless or lying— as they make claims that appear to contradict the whitehouse.

And now it's becoming clear enough that its harder to say "well, maybe it isn't really happening" (even as you say "which may ver well be fake!)or "the black box rooms are for someone else" and so instead of ignoring it people are being forced to process the information. Some of them feel violated and upset. "Hasn't screwed you yet" is starting to look a little too weak once considered in the sunshine.

Re: Why we can't go back to business as usual post-PRISM

#13

This may seem a bit off topic, but I do agree that we can't go back. So, I'm asking here. We are building out a software development framework "from scratch" and would like to make security a core aspect of the framework. Where would be a good place to start looking at encryption solutions? For example, would PGP be a good option?

Assuming you trust it (e.g. Google), Keyczar[1] is a good starting point. If you don't trust it and you can deal with the GPL, GPG[2] is probably a reasonable way to go, but key management is still a bitch. Of course, these are very high level answers, and neither may actually work for you project, since you don't really talk about what making "security a core aspect" actually means. Cryptography is insanely hard to…

Thanks. We'll check these out.

We're creating a development environment based on a visual object language using a fully composable framework. The output of the development environment is blobs of "hooked up" objects. The user's programs are stored on host servers and, in real time, propagated to all people working on the project. Meta-data and data are also part of a program the user is creating.

We would like to encrypt the blobs of objects so behavior can not be injected into the program (logic can be injected anywhere - think something like Aspect oriented programming to an extreme). We would like to encrypt any data (program - blobs of objects, meta-data and private user data) that is being persisted and/or propagated.

Re: Why we can't go back to business as usual post-PRISM

#14

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

Already this is scrolling off the news. It's a safe bet that the vast majority of voters either don't care or don't feel they can change it. If they do try to change it, they put themselves at risk. The surveillance will continue and become more pervasive. As before, if you don't have anything to hide you have nothing to fear, until you do.

Re: Why we can't go back to business as usual post-PRISM

#15

This may seem a bit off topic, but I do agree that we can't go back. So, I'm asking here. We are building out a software development framework "from scratch" and would like to make security a core aspect of the framework. Where would be a good place to start looking at encryption solutions? For example, would PGP be a good option?

[deleted]

Re: Why we can't go back to business as usual post-PRISM

#17
I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

Re: Why we can't go back to business as usual post-PRISM

#18

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

How indeed, but people smoke and stuff their mouths full of unhealthy food even if they know it can kill them. Humans aren't always 100% rational beings. When they suddenly get cancer (ie actual proof) they wake up.

Also, this isn't just about the NSA but also about FBI, and that order certainly isn't fake.

Re: Why we can't go back to business as usual post-PRISM

#19
post #12

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. So it was easy to imagine that only a few things were being intercepted: Communications be an amorphous "bad people". A distant problem for someone else. In the mean time digital communications devices, cloud services, socia…

The fact is there are almost no facts. The NSA is allegedly putting some stuff in a database. That's essentially the "facts." We don't know what, or how, or really understand the scope. We don't know if it's real time or archival. There are ZERO technical details.

The only thing that concerns me is that the NSA is actually somewhat incompetent, as those three PowerPoint slides make it seem like the kind of security strategy developed by a 12 year old kid.

I would have assumed that the NSA wouldn't need to ask Facebook or Google to participate. I just assumed that they could get access to any encryption keys necessary through any number of ways, and syphon off the data wholesale at the ISP level. These aren't exactly "secure" organizations. Gmail accounts routinely get hacked by 15 year old Chinese kids trying to steal WoW passwords. I would hope the NSA could do much better.

Re: Why we can't go back to business as usual post-PRISM

#20
post #17

I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

"Infrastructure Against Humanity"... That is a really really nice term for it. Also very memorable, I shall be appropriating this term for future use.
Post reply on HN