Live data from Hacker News

Why we can't go back to business as usual post-PRISM

mailman.stanford.edu

121–130 of 186 posts

Re: Why we can't go back to business as usual post-PRISM

#121

Earlier quoted context omitted.

The scary thing is this: these people were already voted away. People voted for Obama when he promised the end of warrantless wiretapping, the closing down of Guantanamo, etc. Why should voters believe the next guy who promises these things? It feels hopeless.

what was the excuse for voting for him again in 2012? really I fail to understand people here, One day they bitch about invasion of privacy the next day they want the same people to have every bit of control over their health care. Well guess what, you cannot have it both ways. Granted he had help from a major government agency interfering with groups opposed to his reelection from gathering funds. So perhaps you did…

> One day they bitch about invasion of privacy the next day they want the same people to have every bit of control over their health care. Well guess what, you cannot have it both ways.

This is just as flawed as the arguments that giving the government access to your email is no big deal because you gave access to Google, and they're a massive organization too, right?

I have no problem with Medicare having access to the health records of every American. Single-payer healthcare is a great system. This is completely tangential to giving the NSA/FBI similar access to information.

Comparatively speaking, it might actually be more difficult for the NSA to get unwarranted access to government medical records, since we have extensive laws on the books protecting such data. Your argument is an absolute red herring.

Re: Why we can't go back to business as usual post-PRISM

#122

Earlier quoted context omitted.

"I'm not making excuses for Obama, but he's also up against the establishment." Obama's not 'up against' the establishment. He is the establishment. After everything he's done, how on earth are people still ascribing good intentions to this guy?

That's not what I was getting at. I was suggesting that pointing the finger of blame at one person, and placing the onus on them - and asking them to resign is a little shortsighted. Expecting the problem to just vanish is merely wishful thinking. Is he or is he not the establishment, that's probably another debate in itself. I'm over the pond here, so I can't quite grok the American reaction to the recent news over…

what's the general feeling over there? Mostly people fall into two categories: ignorant or apathetic.

Either people watch too much national news, and don't really hear this story, or if they do know about it they don't believe it's that big of a deal.

Here in the midwest, "I have nothing to hide" is a popular comment.

Re: Why we can't go back to business as usual post-PRISM

#123

Earlier quoted context omitted.

what was the excuse for voting for him again in 2012? really I fail to understand people here, One day they bitch about invasion of privacy the next day they want the same people to have every bit of control over their health care. Well guess what, you cannot have it both ways. Granted he had help from a major government agency interfering with groups opposed to his reelection from gathering funds. So perhaps you did…

> One day they bitch about invasion of privacy the next day they want the same people to have every bit of control over their health care. Well guess what, you cannot have it both ways. This is just as flawed as the arguments that giving the government access to your email is no big deal because you gave access to Google, and they're a massive organization too, right? I have no problem with Medicare having access to…

Not sure why you're getting the downvote. This is obviously true.

It's also important to consider not just the size of the organization, but the nature and extent of its powers. For instance, Google - no matter how big - cannot arrest you, try you, convict you, or imprison you. Your health insurer isn't going to send the Marines to attack another nation, no matter how many doctors they have in their network. I could go on, but the point should be clear: military and law enforcement have a unique - and uniquely dangerous - set of powers. Accordingly, they operate under structures for accountability unlike those that exist anywhere else. The extraordinary trust they're given in some areas is balanced by a distinctly high and formalized level of distrust in others (e.g. actions that are subject to prior judicial review and approval).

So contrary to what you insist, we can give some powers to some organizations, withhold the same power from others. And we can base those organization's ability exist and operate legally on the degree to which they respect and abide by these divisions, and the rule of law.

When it turns out that (a) they don't and (b) we can't respond to these violations, it's a signal that the most basic arrangement keeping our society viable is coming undone. That's a problem that needs to be solves. But thanks to the principle of divided power, it doesn't mean we have to give up intelligent arrangements for sending email or handling health care data in order to keep the police and military in line.

Re: Why we can't go back to business as usual post-PRISM

#124
post #12

This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…

A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. So it was easy to imagine that only a few things were being intercepted: Communications be an amorphous "bad people". A distant problem for someone else. In the mean time digital communications devices, cloud services, socia…

data is being correlated and stored

I'm thinking that the volume of data that they would have to store would be reflected in disk drive sales. In other words, it's probably large enough that it would have distorted the market price for hard drives.

Re: Why we can't go back to business as usual post-PRISM

#125
post #42
post #17

I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

Last time people were looking forward to a meaningful conflict, it plunged the whole world into 4 years of war, followed by another 7. Be careful what you wish for. We need a peaceful solution for this. Vote these people away. Replace them by better people. Educate those who think they have nothing to hide.

"We need a peaceful solution for this. Vote these people away. Replace them by better people. Educate those who think they have nothing to hide."

I hate to sound pessimistic, but it is incredibly naive to even think this is possible.

Re: Why we can't go back to business as usual post-PRISM

#126
post #42

Earlier quoted context omitted.

Last time people were looking forward to a meaningful conflict, it plunged the whole world into 4 years of war, followed by another 7. Be careful what you wish for. We need a peaceful solution for this. Vote these people away. Replace them by better people. Educate those who think they have nothing to hide.

"We need a peaceful solution for this. Vote these people away. Replace them by better people. Educate those who think they have nothing to hide." I hate to sound pessimistic, but it is incredibly naive to even think this is possible.

"I don't care because I have nothing to hide."

To which I reply:

Your voting record.

All the people you flirted (or more) with.

What you did in Vegas (every single visit).

The details of the activities you engage in when your parents/siblings/children/significant other aren't looking.

Your religious views.

Yes, the government knows a lot about all the above, thanks to the magic of big-data.

Re: Why we can't go back to business as usual post-PRISM

#127
post #87

Earlier quoted context omitted.

> I still object in this instance because promises were broken, The fact that we ever even anticipate that a promises involving specific things ought to be made is a mistake in our civic education. It is a goddamned stupid expectation to have of elected officials. They give an oath. That oath defines their job. Campaign promises should never be made, but no one significant can be elected without them. We ask them to…

Initial trust is always free. Candidates all compete for this initial implicitly transacted form of confidence. Then the electing public play the wait & see game. If the incumbent reneges on the promise, trust is understood to be broken, they vote someone else or soon enough become cynical of the entire system. This system is bullshit. Promises made without accountability is the problem. I think campaign promises sho…

> This system is bullshit.

Of course it is. It's bullshit because you have no responsibility in it. You've abdicated your democratic capabilities by saying, "Promise me the world, and I'll wait and watch to see if you give it to me."

You're just a face in the audience. Why would anyone give a shit about being accountable to you?

Re: Why we can't go back to business as usual post-PRISM

#128
post #66

Earlier quoted context omitted.

Putting a better UX or UI has been considered for PGP/GPG a very long time, and if you really reflect on that topic, you'll learn that a fancy interface or UX won't solve anything. Foolproof software is operated by fools. Facebook has only proven that to an extent that you simply can't deny it anymore. If fools use PGP/GPG, they will compromise you by putting the message in the subject and encrypting their disclaimer…

I agree with this, but would also point out that the problems I am addressing though can't be solved by a better user interface. In addition to the issues you describe you also have the question of key infrastructure. Key servers are not adequate as they are, and so IMO you need to have ways of verifying the key is legit, which are not included in the PGP model. That key infrastructure is something which needs to be…

Key infrastructure doesn't even emit security anymore. The P in PKI is for painful, and I really doubt that some CA, owned by big corporate entity (microsoft, oracle, ca) wouldn't manipulate the eternal append-only log-file for any given human factor and just re-roll it.

There is no benefit in auditing it permanently, like rewarding auditing with payment in bitcoin.

A given conglomerate CA would just revoke and reissue client/customer certificates for some reason and that eternal append log-file gets a short restart and everything is fine again, because of OOPPS compromise.

No CA ever, would host a eternal append-only log-file where you can simply point at and tell: I told you so.

It is simply beneficial for any CA to deploy compromising evidence, just in case, of OOPPS compromise. You sure know whom to blame.

It is not beneficial for a given CA (usa) to allow any other CA (china) to forever store their certificates and make you pay for it.

There is no benefit in eternal log-hoarding for PKI, and they make you pay it.

There is no benefit in it for customers even, because you cant even store that log, retrieve that log or even process it as an individual.

I am at a point where I would try web of trust with unicorns, raindows and flying cats before trying again and again with PKI by taking something from virtual currencies and attach it to PKI. Certificate Transparency is like Chrome, it is not build to let you or me delete, or remove CA-Certificates, we may dislike for any given reason, or just because we can.

I am at a point were I really conclude that taking away certificates or keys and delegate them, is the worst idea ever.

Certificate Transparency is baiscally the same wet-hot idea as in 1994 with PKI: PKI, nearly twenty years ago: In the perfect PKI world imagined by netscape, there would be no war, only love, because secrets would stay secrets forever and the NSA would still chew on their first intercepted message.

Reality check please.

CAs have proven not to be reliable trust providers. It is so easy to find the weakest CA and attack and compromise it. Certificate Transparency won't change that, its not even beneficial for CAs.

So lets try web of trust, it hasn't failed us yet, it just wasn't sexy enough. May we need that P in PKI pain to gain something after 20 years.

Imagine certificates trust-validated from your nerd friend, facebook group, google circle, 4chan, whom you trust, ymmv.

Everthing is better than certificates from the folks that hold your browser, operating system, data, e-mails or docments hostage and make you pay for some binary data blob and logging their failures.

Re: Why we can't go back to business as usual post-PRISM

#129
I know a couple of people that, for as long as I've known them, have been consumed by this idea of having to be able to defend yourself from an intrusive government. They, as one would expect, have gun safes full of guns of all types, piles of ammunition and other survivalist tools and equipment.

When the Newtown school massacre happened I actually called a friend in the Sheriff's department to ask if I should "drop a dime" on these guys. My argument was that, while they had never hurt anyone in their lives, perhaps they could one day blow a fuse and use their arsenal to kill innocent people.

This was a troubling call for me. I am not anti-gun at all. I don't happen to own any. Yet, I don't have any fundamental objections to law-abiding people owning them. The Newtown event rattled me as much as it probably did lots of people.

To my surprise my friend, the Sheriff, said not to worry. He went on to tell me that this sort of thing (stock-piling weapons and ammo) is very common. He said lots of cops do it. He went further and told me "we can find most of these people because they are being tracked one way or the other, whether they know it or not".

I didn't think much of that last statement until the latest government scandals started to surface, from the IRS targeting political groups (regardless of alignment, would you like it to happen to you in the future?) to this PRISM/surveillance mess. You now have to wonder where else the government is tracking us. Or, perhaps, the right question could very well be the opposite: Where are you safe?

All of a sudden these "nut-cases" who stockpile weapons and wake up every day thinking the government is out to get them actually have something to point to and say: "See, I told you so". I already got that call, BTW.

No, I am not going out to buy guns. Not interested. I have enough fun shooting them at the range. I don't feel I need to own any of them for any reason. But, you know, how can I now tell these guys they are insane for thinking the way they do?

Re: Why we can't go back to business as usual post-PRISM

#130
post #17

I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.

Unfortunately, despite all hopes, Americans persistently persist in not revolting against their government. I despair of the Revolution coming any time soon.

I honestly am far more fearful of what a revolution in the modern USA would look like.

The "Good Guys" have no assurances of being on the winning side. Who says we don't end up with a fascist dictatorship or, more realistically, a theocracy?

Post reply on HN