Live data from Hacker News

Why we can't go back to business as usual post-PRISM

mailman.stanford.edu

21–30 of 186 posts

Re: Why we can't go back to business as usual post-PRISM

#21

This may seem a bit off topic, but I do agree that we can't go back. So, I'm asking here. We are building out a software development framework "from scratch" and would like to make security a core aspect of the framework. Where would be a good place to start looking at encryption solutions? For example, would PGP be a good option?

Here's my view. I recently wrote an article on my blog ( http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou... ) which was on the front page of HN for a while. I want to summarize both my thoughts again and things that have occurred to me after writing it. All of our existing key interchange systems are amazingly brittle. With X509, there's no reason to assume the NSA couldn't order verisign to produce a ce…

I did a search in google for the HN post but couldn't find it. Could you give me the link to that HN post?

Re: Why we can't go back to business as usual post-PRISM

#22
post #17

I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

"Looking forward to conflict" comment auto-logged, reference #391Z328. Report to the proper authorities within 24 hours for interrogation. You've been auto-added to the no-fly list.

That's likely what will happen from here, because only a small percentage of American voters care about this issue.

Re: Why we can't go back to business as usual post-PRISM

#23
For me, this incident is an example where the U.S. democracy failed, pure and simple. Obama made campaign promises to not do surveillance. He was elected and then did it anyway. It's frankly impossible now to change this issue in a democratic fashion.

From the outside it often looks as if American politicians are overly busy with a very expensive "game", rather than using the game for the greater good.

Re: Why we can't go back to business as usual post-PRISM

#24

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

What's your question? How someone could possibly dare to care about something they did not care about before? How being pummeled 24/7 with reports about terrists and nucular mushroom clouds could possibly have lead to an atmosphere in which questioning the NSA was not an issue, what with starting wars all over the place and what not?

And what's with "being surprised" somehow being the only time where people to be allowed to discuss things? What's with that "argument" showing up all the time? If that's the only criticism you have, you have none, are you aware of that?

Re: Why we can't go back to business as usual post-PRISM

#25
I wonder if there will be a bigger outrage if companies like Salesforce and Oracle are involved. Non-US companies might be a tad alarmed if their ERP provider is cooperating with PRISM.

Since Microsoft is explicitly mentioned I wonder if the access includes their SMB-ERP stuff.

Re: Why we can't go back to business as usual post-PRISM

#26

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

What's your question? How someone could possibly dare to care about something they did not care about before? How being pummeled 24/7 with reports about terrists and nucular mushroom clouds could possibly have lead to an atmosphere in which questioning the NSA was not an issue, what with starting wars all over the place and what not? And what's with "being surprised" somehow being the only time where people to be all…

You're a cat.

Re: Why we can't go back to business as usual post-PRISM

#27

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

It's not because we have more information, it's that THEY have a lot more information. The amount of our lives that we divulge to or involve the internet has shot up exponentially, certainly since the 1990s but when you think about it, even since, say 2000-2005.

Re: Why we can't go back to business as usual post-PRISM

#28

This may seem a bit off topic, but I do agree that we can't go back. So, I'm asking here. We are building out a software development framework "from scratch" and would like to make security a core aspect of the framework. Where would be a good place to start looking at encryption solutions? For example, would PGP be a good option?

Here's my view. I recently wrote an article on my blog ( http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou... ) which was on the front page of HN for a while. I want to summarize both my thoughts again and things that have occurred to me after writing it. All of our existing key interchange systems are amazingly brittle. With X509, there's no reason to assume the NSA couldn't order verisign to produce a ce…

Put a better interface on GPG to make managing web-of-trust not a nightmare. The infrastructure has existed for a long time, but using it is amazingly unfriendly.

It gets more interesting when you consider a model like off-the-record encryption, where the goal isn't encryption and verification but deniability. OTR has the great property of ensuring that any time you manage to decrypt or intercept a message, you've also received all the information necessary to forge that message. Identifying keys are transient so you can never really prove any individual, sent any message since if you hold a copy of the message you could just as easily have faked the message.

Re: Why we can't go back to business as usual post-PRISM

#29
post #25

I wonder if there will be a bigger outrage if companies like Salesforce and Oracle are involved. Non-US companies might be a tad alarmed if their ERP provider is cooperating with PRISM. Since Microsoft is explicitly mentioned I wonder if the access includes their SMB-ERP stuff.

But those companies are both American, aren't they? Regardless, I feel like the ceiling for outrage and/or concern has reached its ceiling, at least among foreign governments who can at least do a semblance of something about it, since it's way more important which companies are used the most than the nations from which the companies in question originate, and the NSA has the data of all the most popular internet companies in the world.

Re: Why we can't go back to business as usual post-PRISM

#30

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

Threads like these might as well be generated by an algorithm.

>NSA news >Why is everybody so surprised!? comment

Like clockwork. Let me ask you, though. Do you really think that people only "suddenly" care (with the implication of ignorance or a contradiction on their part) or is it possible that there are nuanced differences between all of the things you casually reference as common knowledge and the current NSA news? I mean, there is speculation and there is confirmation. There are hunches and there are reputable sources. There is pointing somebody to the Room 641A Wikipedia page and there is telling somebody, "hey, look, this guy who was a part of the NSA is not only confirming this, but has sacrificed his career to give us even more information about it."

The public unconscious may have assumed that this was going on, clusters of people may have known, but you're underestimating how people compartmentalize this kind of knowledge. So when we have an event that brings a lot of this knowledge together and to the forefront and gives us something we can point to and talk about (even if it's only a story or a face at this point), I don't think we should pass up the opportunity to develop a louder voice about all of this rather than being cynical AGAIN just because we can't resist putting down public outcry.

Post reply on HN