This may seem a bit off topic, but I do agree that we can't go back. So, I'm asking here. We are building out a software development framework "from scratch" and would like to make security a core aspect of the framework. Where would be a good place to start looking at encryption solutions? For example, would PGP be a good option?
Here's my view. I recently wrote an article on my blog ( http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou... ) which was on the front page of HN for a while. I want to summarize both my thoughts again and things that have occurred to me after writing it. All of our existing key interchange systems are amazingly brittle. With X509, there's no reason to assume the NSA couldn't order verisign to produce a ce…
Why we can't go back to business as usual post-PRISM
21–30 of 186 posts
Re: Why we can't go back to business as usual post-PRISM
#22I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.
That's likely what will happen from here, because only a small percentage of American voters care about this issue.
Re: Why we can't go back to business as usual post-PRISM
#23From the outside it often looks as if American politicians are overly busy with a very expensive "game", rather than using the game for the greater good.
Re: Why we can't go back to business as usual post-PRISM
#24This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…
And what's with "being surprised" somehow being the only time where people to be allowed to discuss things? What's with that "argument" showing up all the time? If that's the only criticism you have, you have none, are you aware of that?
Re: Why we can't go back to business as usual post-PRISM
#25Since Microsoft is explicitly mentioned I wonder if the access includes their SMB-ERP stuff.
Re: Why we can't go back to business as usual post-PRISM
#26This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…
What's your question? How someone could possibly dare to care about something they did not care about before? How being pummeled 24/7 with reports about terrists and nucular mushroom clouds could possibly have lead to an atmosphere in which questioning the NSA was not an issue, what with starting wars all over the place and what not? And what's with "being surprised" somehow being the only time where people to be all…
Re: Why we can't go back to business as usual post-PRISM
#27This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…
Re: Why we can't go back to business as usual post-PRISM
#28This may seem a bit off topic, but I do agree that we can't go back. So, I'm asking here. We are building out a software development framework "from scratch" and would like to make security a core aspect of the framework. Where would be a good place to start looking at encryption solutions? For example, would PGP be a good option?
Here's my view. I recently wrote an article on my blog ( http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou... ) which was on the front page of HN for a while. I want to summarize both my thoughts again and things that have occurred to me after writing it. All of our existing key interchange systems are amazingly brittle. With X509, there's no reason to assume the NSA couldn't order verisign to produce a ce…
It gets more interesting when you consider a model like off-the-record encryption, where the goal isn't encryption and verification but deniability. OTR has the great property of ensuring that any time you manage to decrypt or intercept a message, you've also received all the information necessary to forge that message. Identifying keys are transient so you can never really prove any individual, sent any message since if you hold a copy of the message you could just as easily have faked the message.
Re: Why we can't go back to business as usual post-PRISM
#29I wonder if there will be a bigger outrage if companies like Salesforce and Oracle are involved. Non-US companies might be a tad alarmed if their ERP provider is cooperating with PRISM. Since Microsoft is explicitly mentioned I wonder if the access includes their SMB-ERP stuff.
Re: Why we can't go back to business as usual post-PRISM
#30This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…
>NSA news >Why is everybody so surprised!? comment
Like clockwork. Let me ask you, though. Do you really think that people only "suddenly" care (with the implication of ignorance or a contradiction on their part) or is it possible that there are nuanced differences between all of the things you casually reference as common knowledge and the current NSA news? I mean, there is speculation and there is confirmation. There are hunches and there are reputable sources. There is pointing somebody to the Room 641A Wikipedia page and there is telling somebody, "hey, look, this guy who was a part of the NSA is not only confirming this, but has sacrificed his career to give us even more information about it."
The public unconscious may have assumed that this was going on, clusters of people may have known, but you're underestimating how people compartmentalize this kind of knowledge. So when we have an event that brings a lot of this knowledge together and to the forefront and gives us something we can point to and talk about (even if it's only a story or a face at this point), I don't think we should pass up the opportunity to develop a louder voice about all of this rather than being cynical AGAIN just because we can't resist putting down public outcry.