Earlier quoted context omitted.
Here's my view. I recently wrote an article on my blog ( http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou... ) which was on the front page of HN for a while. I want to summarize both my thoughts again and things that have occurred to me after writing it. All of our existing key interchange systems are amazingly brittle. With X509, there's no reason to assume the NSA couldn't order verisign to produce a ce…
I did a search in google for the HN post but couldn't find it. Could you give me the link to that HN post?
Why we can't go back to business as usual post-PRISM
31–40 of 186 posts
Re: Why we can't go back to business as usual post-PRISM
#32Earlier quoted context omitted.
Here's my view. I recently wrote an article on my blog ( http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou... ) which was on the front page of HN for a while. I want to summarize both my thoughts again and things that have occurred to me after writing it. All of our existing key interchange systems are amazingly brittle. With X509, there's no reason to assume the NSA couldn't order verisign to produce a ce…
Put a better interface on GPG to make managing web-of-trust not a nightmare. The infrastructure has existed for a long time, but using it is amazingly unfriendly. It gets more interesting when you consider a model like off-the-record encryption, where the goal isn't encryption and verification but deniability. OTR has the great property of ensuring that any time you manage to decrypt or intercept a message, you've al…
Re: Why we can't go back to business as usual post-PRISM
#33For me, this incident is an example where the U.S. democracy failed, pure and simple. Obama made campaign promises to not do surveillance. He was elected and then did it anyway. It's frankly impossible now to change this issue in a democratic fashion. From the outside it often looks as if American politicians are overly busy with a very expensive "game", rather than using the game for the greater good.
Re: Why we can't go back to business as usual post-PRISM
#34Earlier quoted context omitted.
Here's my view. I recently wrote an article on my blog ( http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou... ) which was on the front page of HN for a while. I want to summarize both my thoughts again and things that have occurred to me after writing it. All of our existing key interchange systems are amazingly brittle. With X509, there's no reason to assume the NSA couldn't order verisign to produce a ce…
Put a better interface on GPG to make managing web-of-trust not a nightmare. The infrastructure has existed for a long time, but using it is amazingly unfriendly. It gets more interesting when you consider a model like off-the-record encryption, where the goal isn't encryption and verification but deniability. OTR has the great property of ensuring that any time you manage to decrypt or intercept a message, you've al…
1. Ensuring that the key belongs to the person you think it does.
2. Graceful changing of keys.
In theory you could do something like what I am proposing with GPG too. You could sign a public key with the previous private key or two. In practice, getting the keys to where you want them is a bit more complex.
As a point I made clear in my blog entry, I am not a fan of X509, because the impedance mismatch of anything OSI and TCP/IP is significant. However, it does a decent job, when combined with LDAP (another monster IMHO) of spelling out the general solutions to problems PKI's suffer. It is therefore a useful reference point and probably the best foundation to build a decent proof of concept on.
Re: Why we can't go back to business as usual post-PRISM
#35This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…
A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. So it was easy to imagine that only a few things were being intercepted: Communications be an amorphous "bad people". A distant problem for someone else. In the mean time digital communications devices, cloud services, socia…
The fact that this is happening to _everyone_...
Has this actually changed? Is there any evidence that a U.S. citizen's gmail account, or skype calls, or yahoo searches, or facebook information, has been obtained without a court ordered warrant?
I'm not a U.S. citizen and have always assumed that anything I put on these companies' servers can be read by the U.S. government at will. But if you're a citizen of the land of the free and the home of the brave, I haven't seen anything come out that actually showed your cloud data is being accessed without probable cause being shown, the way it always has been.
Re: Why we can't go back to business as usual post-PRISM
#36Re: Why we can't go back to business as usual post-PRISM
#37This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…
(1) Previously, various official sources have denied this sort of thing was happening. As a specific example, Congress has asked and been told that universal surveillance of US citizens was not occurring, and the plain-text meaning of the law makes universal surveillance of US citizens illegal. (Now we are told that this is contradicted by a secret legal opinion.)
(2) Frog boiling. You can argue that at every point along the way the difference from the previous point is not big enough to cause an outcry. But there is a fallacy in this reasoning: at some point the aggregate IS enough to cause an outcry. Right now, there is an outcry among the media (partly exacerbated because these stories about leaks are contemporaneous with cases of prosecuting the media for leaks), perhaps it will spread to politicians and the citizenry.
Re: Why we can't go back to business as usual post-PRISM
#38Earlier quoted context omitted.
A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. So it was easy to imagine that only a few things were being intercepted: Communications be an amorphous "bad people". A distant problem for someone else. In the mean time digital communications devices, cloud services, socia…
The fact is there are almost no facts. The NSA is allegedly putting some stuff in a database. That's essentially the "facts." We don't know what, or how, or really understand the scope. We don't know if it's real time or archival. There are ZERO technical details. The only thing that concerns me is that the NSA is actually somewhat incompetent, as those three PowerPoint slides make it seem like the kind of security s…
William Binney, who was at the NSA for 30 years, and who designed big pieces of the infrastructure we're talking about, quit and blew the whistle. If I understand him correctly, every type of electronic communications people use -- email, phone, SMS, IM, fax -- are all stored forever.
There are a million interviews like this: http://youtu.be/TuET0kpHoyM
Edit: and, it seems that Snowden wanted the Washington Post and the Guardian to release all 41 slides, but neither paper had the courage to do it. I'd like to know what was on the other slides. If they had nothing of interest, why were they withheld?
Re: Why we can't go back to business as usual post-PRISM
#39I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.
We need a new conduit for effecting change.
Re: Why we can't go back to business as usual post-PRISM
#40I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.
"Infrastructure Against Humanity"... That is a really really nice term for it. Also very memorable, I shall be appropriating this term for future use.