Live data from Hacker News

The Criminal N.S.A.

nytimes.com

71–80 of 116 posts

Re: The Criminal N.S.A.

#71
post #39

Earlier quoted context omitted.

How about we popularize encryption, and take the choice out of the hands of corporations and governments?

That's why I did this; https://github.com/etherael/phoneme It's not perfect, but I think the first step to widespread crypto adoption is getting people accustomed to the workflow of fully encrypted email. Phoneme + mailvelope is not a huge jump from the current gmail experience and just that initial taste might be enough to get more people on the right track.

Cool project, you seem talented... I'm just a bit confused here.

If we basically know several governments already have copies of your historical gmails, and you're not securing the incoming channel (which we basically know has a beam splitter on it), what good does encrypting the historical files do?

Re: The Criminal N.S.A.

#72
This post makes a similar argument to my blog post[1] from earlier this week - that PRISM is simply criminal - although my analysis focused on why this made Snowden immune to charges as a whistleblower.

I agree that it's time to take the US government to task over this. How does that happen? A civil suit, a private prosecution?

[1] http://joe-jordan.co.uk/blog/2013/06/tinker-tailor-whistlebl... (hacker news comments: https://news.ycombinator.com/item?id=5945185 )

Re: The Criminal N.S.A.

#73

Earlier quoted context omitted.

Thou doth jest. Most western countries are lap-dogs to the US, and almost certainly exchange spying data with the US so that they don't breach their own privacy laws. This will have little impact with US allies.

Even if the intelligence governmental agencies exchange that in the US (and many certainly do), that doesn't mean they can't impose rules on businesses (expanding the privacy laws you mention) and other state entities to avoid using US tech services. Sure it'd be hypocritical, but when did that stop anyone?

Especially because there's been past concerns about US intelligence passing sensitive data to US companies to help them win contracts.

There's bound to be a lot of high level execs at European companies whispering in their governments ears at the moment about how this is putting them at a substantial disadvantage, whether or not they believe it to be true.

Re: The Criminal N.S.A.

#74
post #71

Earlier quoted context omitted.

That's why I did this; https://github.com/etherael/phoneme It's not perfect, but I think the first step to widespread crypto adoption is getting people accustomed to the workflow of fully encrypted email. Phoneme + mailvelope is not a huge jump from the current gmail experience and just that initial taste might be enough to get more people on the right track.

Cool project, you seem talented... I'm just a bit confused here. If we basically know several governments already have copies of your historical gmails, and you're not securing the incoming channel (which we basically know has a beam splitter on it), what good does encrypting the historical files do?

We don't know for certain that several governments have archived stored copies of all cloud based email in existence, it's hazy as to what they do and do not have access to, what isn't hazy is that they have the right to demand the content of any given gmail account with effectively zero recourse available.

The very fact that they actually do make these demands indicates on balance of probability, they don't actually just have an archived permanent copy of the content of every gmail account in existence. Why ask for what you already have?

Of course, that's an assumption and it may be incorrect. However on the downside if it is incorrect, you're back in the exact same position you started in and you've lost nothing anyway. And as previously stated, it might get people in the habit of understanding how PGP works if mailvelope and products like it see wider adoption.

In a network of correspondents where everyone is running something similar to mailvelope + phoneme, it becomes an obvious thing to do to simply implement proper end to end PGP, so I also hope it might be a solution to the chicken and egg problem which has plagued PGP deployment for so long.

It can never hurt to fight, even if you might lose, especially when if you don't fight, you'll definitely lose.

Re: The Criminal N.S.A.

#75
post #19

Earlier quoted context omitted.

As if that was the only headline or angle the NY Times displayed on the front page about that story as that story evolved. C'mon man.

Do you think that's an appropriate headline for the breaking front-page story about the scandal for an ostensibly objective news organization?

You'd be surprised how many people follow politics as if it were sports. The politic tactics surrounding the story are an angle that their readers are interested in, and they have real consequences as well. I think you'd have to consider all their coverage of the story as a whole to analyze their slant (which is Democratic, of course.)

Re: The Criminal N.S.A.

#76
post #11

"Let’s turn to Prism: the streamlined, electronic seizure of communications from Internet companies." OK, good so far, PRISM does indeed streamline and automate the process... "... Prism is further proof that the agency is collecting vast amounts of e-mails and other messages — including communications to, from and between Americans." ??? PRISM was the one thing I stopped being worried about as soon as I figured out…

HN's own PRISM apologist. You haven't figured out what PRISM is, you don't have a clue. But when, otherwise very conservative (by this I mean "less likely to fly off the handle") individuals start getting up in arms, you should realize this is probably a big deal. But then, you probably do realize it.

Re: The Criminal N.S.A.

#77
post #68
post #47

Earlier quoted context omitted.

I agree with this but why not take it a step further? We're hackers, working on tools/applications that facilitate the transfer of information - why don't we implement encryption from the get-go? There wouldn't be a need to 'popularize' something exists by default. GnuPG/PGP are fairly trivial to implement; here's some apps that are ripe for production: - Messaging application that exchanges public keys on first cont…

Governments can still gather the metadata of encrypted emails. Both PGP and S/MIME do not encrypt the subject line, sender or recipient addresses. To use encrypted email and hide the subject line, you need to not use it (just say "Encrypted email") or something. This cannot be made automatic without impacting UX. The To: header fundamentally cannot be removed. The sender can be inferred from the account within the em…

Cypherpunks have already created a solution, http://mixmaster.sourceforge.net/ and similar remailers, but similar technology needs to be incorporated into easIEST to use tools.

Re: The Criminal N.S.A.

#78
post #71

Earlier quoted context omitted.

Cool project, you seem talented... I'm just a bit confused here. If we basically know several governments already have copies of your historical gmails, and you're not securing the incoming channel (which we basically know has a beam splitter on it), what good does encrypting the historical files do?

We don't know for certain that several governments have archived stored copies of all cloud based email in existence, it's hazy as to what they do and do not have access to, what isn't hazy is that they have the right to demand the content of any given gmail account with effectively zero recourse available. The very fact that they actually do make these demands indicates on balance of probability, they don't actually…

I was hoping someone far more talented than me would write a browser plugin that would encrypt everything I type in a TEXTAREA with GPG, and then prompt me for a list of friends I'd like to have read that text.

Everything, from Facebook to Gmail, would be encrypted that way. And I would be in control of the list of people that could read that text.

Re: The Criminal N.S.A.

#79

Earlier quoted context omitted.

How are you construing an unconstitutional surveillance program as a political question? I don't see how any of the Court Cases listed on the wikipedia article are relevant. These all seem to relate to truly political things, like which branch has what authority, or how districts are apportioned. The article only cites 5 areas the courts have clear precedent on - wars, treaties, gerrymandering, impeachment, as well a…

I'm not all that sure it is unconstitutional, for one thing - aren't you begging the question here? And on a more general level, shouldn't you be considering precedent on justiciability, rather than basing your whole argument on your personal opinion of the waht the constitution means? I might note in asssing that I favor a constitutional amendment that would create an explicit right to privacy; I'm not in favor of a…

>I'm not all that sure it is unconstitutional

And you know who the perfect people to decide that would be? Judges. In a court of law. Since that's one of their main job functions.

Re: The Criminal N.S.A.

#80
post #42
post #39

Earlier quoted context omitted.

How about we popularize encryption, and take the choice out of the hands of corporations and governments?

How do we do that when people don't care about privacy?

> How do we do that when people don't care about privacy?

the same way governments / politicians / mass media do it: you make them care.

it's a sad fact of humanity that most people will care about whatever they are told to care about, or rather, whatever their peers are perceived to care about.

right now there is a window of opportunity for privacy to stand in the public eye's spotlight, fighting a (very real) fight against the encroaching forces of totalitarianism.

you ask what to do. how about anything you see an opportunity to. educate your friends about privacy, about what is going on, about what the dangers of surveillance are[0], or perhaps educate yourself about using GPG, get the hang of it together with a few other techie friends, so that you can explain it to more people (because it's really not that complex, if someone walks you through it), if you have a brilliant idea write some code, etc. and also, delete Facebook?

[0] http://www.reddit.com/r/changemyview/comments/1fv4r6/i_belie...

Post reply on HN