Live data from Hacker News

Why we can't go back to business as usual post-PRISM

mailman.stanford.edu

41–50 of 186 posts

Re: Why we can't go back to business as usual post-PRISM

#41
post #12

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. So it was easy to imagine that only a few things were being intercepted: Communications be an amorphous "bad people". A distant problem for someone else. In the mean time digital communications devices, cloud services, socia…

Part of the problem is defining wholesale surveillance. I don't think we are to the point of having everything stored by the NSA (in terms of all content we produce, send, or exchange). I think it is quite likely that the NSA does in fact store their most interesting subset of broad data (cdrs etc) along with a narrower subset of content. If that isn't wholesale surveillance, then we aren't to that level yet.

But in the end what I have said for a while is that it doesn't matter. The NSA doesn't need to store your Facebook stuff on their servers because Facebook is doing it for them. The scary thing is that the interesting subset that the NSA has to pipe back is a small fraction of what they can go through if they ever decide to make you a target of an investigation, so in that sense we are under wholesale surveillance and the NSA is just controlling a very small piece.

Re: Why we can't go back to business as usual post-PRISM

#42
post #17

I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

Last time people were looking forward to a meaningful conflict, it plunged the whole world into 4 years of war, followed by another 7. Be careful what you wish for.

We need a peaceful solution for this. Vote these people away. Replace them by better people. Educate those who think they have nothing to hide.

Re: Why we can't go back to business as usual post-PRISM

#43
post #17

I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

"Infrastructure Against Humanity"... That is a really really nice term for it. Also very memorable, I shall be appropriating this term for future use.

IAH (Infra Against Humanity)

Nice, memorable, and accurate. Let's make it an official euphamism.

Re: Why we can't go back to business as usual post-PRISM

#44
post #25

I wonder if there will be a bigger outrage if companies like Salesforce and Oracle are involved. Non-US companies might be a tad alarmed if their ERP provider is cooperating with PRISM. Since Microsoft is explicitly mentioned I wonder if the access includes their SMB-ERP stuff.

From the reports I would be surprised if non-hosted ERP stuff was ever easily targeted. Hosted stuff is a bit of a different story.

ideally if you are paranoid, you should run things in-house and firewalled. If you are less so, I will point out I help run a British-registered hosting company for an open source ERP (the company can be found at http://www.efficito.com).

Everyone wants to talk about how the cloud will change ERP and while I am involved in a startup that is operating in this space, I have to say that it is extremely important for users to know that they give up a lot of control over security when they make that choice. We do our best but we cannot compare to a well-run internal installation.

Re: Why we can't go back to business as usual post-PRISM

#45
Of course we can go back to business as usual post-PRISM, because PRISM turned out to be absolutely nothing. It's a mundane, boring data storage & analysis system for data obtained through FISA requests about specific individuals. It's not a data dump from major tech companies, it's not a warrant-less spy program, etc...

Re: Why we can't go back to business as usual post-PRISM

#46
post #42
post #17

I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

Last time people were looking forward to a meaningful conflict, it plunged the whole world into 4 years of war, followed by another 7. Be careful what you wish for. We need a peaceful solution for this. Vote these people away. Replace them by better people. Educate those who think they have nothing to hide.

I didn't mean to make it sound as if I want violence. I hate violence. But they've been lying and building weird information weapons for years. We need something other than that to start happening soon.

Re: Why we can't go back to business as usual post-PRISM

#47
post #28

Earlier quoted context omitted.

Put a better interface on GPG to make managing web-of-trust not a nightmare. The infrastructure has existed for a long time, but using it is amazingly unfriendly. It gets more interesting when you consider a model like off-the-record encryption, where the goal isn't encryption and verification but deniability. OTR has the great property of ensuring that any time you manage to decrypt or intercept a message, you've al…

I wish there was a site to connect open-source projects who need better UIs with the designers over at Dribbble. On Dribbble you see a lot of UI concepts that never come to fruition. What if we could convince some of them to help build a better PGP UI? After all, real world applications look much better on a resume than concepts.

We've tried to write a streamlined UI for GPG keysigning parties in university. The CLI of gpg was absolutely hostile. Fatal errors would still have 0 as the exit code etc... :(

Re: Why we can't go back to business as usual post-PRISM

#48

For me, this incident is an example where the U.S. democracy failed, pure and simple. Obama made campaign promises to not do surveillance. He was elected and then did it anyway. It's frankly impossible now to change this issue in a democratic fashion. From the outside it often looks as if American politicians are overly busy with a very expensive "game", rather than using the game for the greater good.

It's because the American people voted for looks over substance. Obama has no morals and no spine, but he looks and sounds like a Hollywood star.

Obama is just the US population's reflection in the mirror.

Re: Why we can't go back to business as usual post-PRISM

#49
post #42
post #17

I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

Last time people were looking forward to a meaningful conflict, it plunged the whole world into 4 years of war, followed by another 7. Be careful what you wish for. We need a peaceful solution for this. Vote these people away. Replace them by better people. Educate those who think they have nothing to hide.

The scary thing is this: these people were already voted away. People voted for Obama when he promised the end of warrantless wiretapping, the closing down of Guantanamo, etc. Why should voters believe the next guy who promises these things? It feels hopeless.

Re: Why we can't go back to business as usual post-PRISM

#50

Earlier quoted context omitted.

Assuming you trust it (e.g. Google), Keyczar[1] is a good starting point. If you don't trust it and you can deal with the GPL, GPG[2] is probably a reasonable way to go, but key management is still a bitch. Of course, these are very high level answers, and neither may actually work for you project, since you don't really talk about what making "security a core aspect" actually means. Cryptography is insanely hard to…

Thanks. We'll check these out. We're creating a development environment based on a visual object language using a fully composable framework. The output of the development environment is blobs of "hooked up" objects. The user's programs are stored on host servers and, in real time, propagated to all people working on the project. Meta-data and data are also part of a program the user is creating. We would like to enc…

Also check out http://nacl.cr.yp.to

there is a more library friendly version called sodium[1]. I don't know how much review has been done of that so far yet though....

[1]: http://labs.umbrella.com/2013/03/06/announcing-sodium-a-new-...

Post reply on HN