Live data from Hacker News

Dilute PRISM – Use Open Source Alternatives

truelogy.wordpress.com

11–20 of 49 posts

Re: Dilute PRISM – Use Open Source Alternatives

#11
One thing to consider: if you use an alternative to the major services...doesn't that make it easier to find you? You've effectively joined a much smaller haystack.

I guess how much of a risk this depends on where you see the vector of attack. If you think the NSA has one decade forward on decryption ability, then what does it matter if Facebook/etc hands over the data or if you've trusted another encryption scheme?

But consider this scenario: the NSA knows that one member of a group may be a person of interest, with the rest being innocent (for example, a leaker within an organization). What draws more attention: the person who is sending all of their traffic through GMail, etc...or the person who, for some reason, is using an obscure service at particular hours of the day? Even the use of Tor might be a flag.

And if your counter-argument is, "Well, so what? They won't be able to break the encryption on [so-and-so-independent service]?". Well, they don't have to. They just have to find someone who is exhibiting a reasonable amount of suspicious behavior and then observe them in other ways or get their associates/family members to flip...Investigations don't succeed or fail based on the unlocking of a key file...it's the work done around the secret that can reveal the secret.

edit: An analogy - You wish to have an affair without your spouse noticing. Since affairs in relationships are not an unheard of occurrence, your spouse isn't going to actively suspect you of it, but he wouldn't ignore signs of an affair either. Having the affair in your own home isn't practical, and you choose not to do it at the Ramada that's just blocks away from your home/workplace because, well, there's so many people there, and there's the possibility that a mutual acquaintance will see you and then tell on you.

So instead, you and your affairee agree to meet each other at a small bed and breakfast that is 1 hour away from your city and so small that no one you know probably even knows about it, and no one at the B&B will care who you are or know who your spouse is.

So are you safe? Well, only until your spouse finds it weird that on occasional days after work, you're driving in a direction that there doesn't seem to be any reason for you to go, and these occasions end up with you being gone for several hours. And in one such occasion, you were noticed carrying what seemed like a bag for a bottle of wine.

By going the obscure route, you've deflected one kind of exposure and opened yourself up to a whole new kind of suspicion.

Re: Dilute PRISM – Use Open Source Alternatives

#13
The problem can't just be solved by simply pointing people to (random?) open source software.

We still need servers as rendezvous points, and we can't expect everybody to run their own services. Properly setting up a mail server is hard.

So, everybody who can should run XMPP and/or SIP servers and hand out accounts to their friends. Both telephony/messaging protocols have inherent capabilities for federating with other people's servers similar to what email does. And with OTR and ZRTP we have real end-to-end encryption without relying on (broken) SSL certificates.

The technology is ready, now it's time to make it usable. Let's help people to move their lives back out of the cloud.

Re: Dilute PRISM – Use Open Source Alternatives

#14
post #11

One thing to consider: if you use an alternative to the major services...doesn't that make it easier to find you? You've effectively joined a much smaller haystack. I guess how much of a risk this depends on where you see the vector of attack. If you think the NSA has one decade forward on decryption ability, then what does it matter if Facebook/etc hands over the data or if you've trusted another encryption scheme?…

That's why we need to push for popular services like Skype, Hangouts, Gmail and others to implement these technologies to make them mainstream so most people use them.

Re: Dilute PRISM – Use Open Source Alternatives

#16

Does switching to Ubuntu really help you that much? Unless there are secret NSA backdoors in Windows/OS X. Hell even under Ubuntu they could just backdoor my nvidia drivers. I would really struggle to recommend using Tor as a "daily driver" for web browsing as well. Unless we want to go back to the 56k web. Most of the others (bitcoin,social networks) rely on network effects anyway.

There aren't backdoors in OS X and Windows that are specifically designed by or for the NSA, but since we can't see about half of the source (at least in OS X) then they can exploit any backdoor that may be present without our knowledge.

Ubuntu fares a bit better, but with the proprietary blobs, you never know.

Re: Dilute PRISM – Use Open Source Alternatives

#17
post #15

Ubuntu phone, oh really? Where i can buy tomorrow ubuntu phone? Ubuntu? Why this distro, not openSUSE or Debian? Nothing wrong that by default ubuntu uses Amazon ads?

Ubuntu is actually working on a phone OS, and the rest aren't. http://www.ubuntu.com/phone

Re: Dilute PRISM – Use Open Source Alternatives

#18
post #14
post #11

One thing to consider: if you use an alternative to the major services...doesn't that make it easier to find you? You've effectively joined a much smaller haystack. I guess how much of a risk this depends on where you see the vector of attack. If you think the NSA has one decade forward on decryption ability, then what does it matter if Facebook/etc hands over the data or if you've trusted another encryption scheme?…

That's why we need to push for popular services like Skype, Hangouts, Gmail and others to implement these technologies to make them mainstream so most people use them.

Not sure what technologies you're referring to, but in regards to the OP, the OP is arguing that people use replacement services (Diaspora vs Facebook, for example) so that the NSA and such have a harder time finding you...But if you ascribe the kind of capabilities and motivations to the NSA that would make you this concerned (the collection/mirroring of all traffic, legal authority to request what they want, encryption well ahead of the state-of-the-art, and the information architecture to make broad-scale analysis possible)...then you're not really diluting anything and opening yourself up to other attack vectors.

Re: Dilute PRISM – Use Open Source Alternatives

#19
post #11

One thing to consider: if you use an alternative to the major services...doesn't that make it easier to find you? You've effectively joined a much smaller haystack. I guess how much of a risk this depends on where you see the vector of attack. If you think the NSA has one decade forward on decryption ability, then what does it matter if Facebook/etc hands over the data or if you've trusted another encryption scheme?…

> if you use an alternative to the major services...doesn't that make it easier to find you? You've effectively joined a much smaller haystack.

No. Because the 'haystack' you are (accidentally) referring to is a ginormous indexed/searchable database. All of their data goes to the same place, so it doesn't matter where it comes from.

Your argument through analogy is not applicable but let me clarify for you: They are not watching you. They are watching the Ramada and everyone who enters, exits, and everything they do while there. All of this information goes into organized storage until they need to dig it up.

They can't watch the bed and breakfast because the windows are blacked out (encryption). So you are safer there.

Security through obscurity is an awful policy to start with and only fails harder when applied to a situation like this.

Re: Dilute PRISM – Use Open Source Alternatives

#20
post #11

One thing to consider: if you use an alternative to the major services...doesn't that make it easier to find you? You've effectively joined a much smaller haystack. I guess how much of a risk this depends on where you see the vector of attack. If you think the NSA has one decade forward on decryption ability, then what does it matter if Facebook/etc hands over the data or if you've trusted another encryption scheme?…

So use alternative services for mundane things, all the time. Make it less of an anomaly that you're using less-trackable services, and make the haystack bigger for other leakers.

(I'm reminded of a talk about Tor where it was mentioned that Tor only works if the user-base is diverse; if only the FBI used Tor, the FBI would have anonymity from using Tor, etc.)

Post reply on HN