Live data from Hacker News

Prism Break

prism-break.org

31–40 of 205 posts

Re: Prism Break

#31
post #20

If you're going to continue using Google Mail, it's a dumb idea to deliberately switch away from Chrome. The connection between Gmail and Chrome is among the more carefully guarded TLS connections on the Internet.

How does Google create one of the most carefully guarded TLS connections? Should other sites model their implementation?

By controlling both sides of the connection, and by investing in people like Adam Langley. And yes, other sites should. Not "control both sides of the connection", which is unrealistic, but in modeling their server configurations on Google's so they can take maximal advantage of Chrome's TLS features.

Re: Prism Break

#32
post #8

Several of these suggestions seem somewhat disingenuous - e.g. many of them to be about free software more than actual concerns about tracking, as reflected in the labels "Proprietary" and "Free alternatives". In particular: - None of the proprietary browsers will track you - well, beyond what's specified in the privacy policy. Two of the alternatives are Tor applications, but the other two are Firefox (which provide…

> None of the proprietary browsers will track you

By default Chrome sends the text you type in the location bar to Google. I am not sure but they may also use visited urls to source the crawler.

Re: Prism Break

#33
post #13

I really do not understand the thought process behind this page: Why is chromium not listed as a free alternative to Chrome/IE/Safari? What components of DDG are partly proprietary and which are not? (not a criticism of DDG just this page) What is a "free search engine" anyway? Why are Firefox and Thunderbird listed alongside Iceweasel and Icedove? How do you list OpenNIC if they have not adopted an official privacy/…

There isn't much of a thought process. I opened an issue arguing for a more focused and defined modus operandi, but as it stands, the site is a community generated list.

Re: Prism Break

#34
post #8

Several of these suggestions seem somewhat disingenuous - e.g. many of them to be about free software more than actual concerns about tracking, as reflected in the labels "Proprietary" and "Free alternatives". In particular: - None of the proprietary browsers will track you - well, beyond what's specified in the privacy policy. Two of the alternatives are Tor applications, but the other two are Firefox (which provide…

> None of the proprietary browsers will track you By default Chrome sends the text you type in the location bar to Google. I am not sure but they may also use visited urls to source the crawler.

They do not use visited URLs. While Firefox separates its location and search bars, this seems to me more of a design choice than a privacy one. I could be wrong! - but then again, the much bigger privacy risk is using Google in the first place, and if you switch to a different search engine then Google stops receiving autocomplete too.

Re: Prism Break

#35
post #20

If you're going to continue using Google Mail, it's a dumb idea to deliberately switch away from Chrome. The connection between Gmail and Chrome is among the more carefully guarded TLS connections on the Internet.

How does Google create one of the most carefully guarded TLS connections? Should other sites model their implementation?

When Google.com's certificate was faked, it was discovered because Chrome restricts what CAs are allowed to sign Google's certificates, if I recall correctly.

Re: Prism Break

#36
post #11

Surprised Arch Linux [1] isn't listed. It's probably one of the most secure distros by limiting the installed packages to a bare minimum. Combine that with App Armour (or SELinux designed by the NSA) with a firewall and basic network monitoring to protect against rootkits. Plus always-on VPN, dm-crypted harddrive, noscript etc. NSA also released SEAndroid [2] which hardens Android significantly. It's included preinst…

I'm more surprised that Mint is being suggested at all in this. Considering how ridiculous this list is in the first place, the 'curator' should have noted that Mint, by default, installs search engines that are partnered with Mint[1]. Even more surprising is that BSD just got a cursory mention. You may as well switch to OpenBSD if you're going to switch to a majority of these alternatives. [1] http://www.linuxmint.c…

I've added a note about Mint's search engine policy, thanks.

Also, BSDs will get greater emphasis in future updates. I'm working on a way to promote more operating systems without the page getting even more overwhelming than it already is.

Re: Prism Break

#37
post #35

Earlier quoted context omitted.

How does Google create one of the most carefully guarded TLS connections? Should other sites model their implementation?

When Google.com's certificate was faked, it was discovered because Chrome restricts what CAs are allowed to sign Google's certificates, if I recall correctly.

Google does that for a number of other non-Google sites, too.

Re: Prism Break

#38
Interesting, I learned about the Autistici/Inventati collective only from this link, even though they seem to already be a large (>1k users) organization and in existence for a decade now. Useful info.

Re: Prism Break

#39
post #30
post #24

Earlier quoted context omitted.

You seem to be assuming that tracking only happens either through incompetence or government mandate? Companies also track users to make money . Just today there was the news that twitter is starting to track its users, for example (at least it is opt-out).

Tracking in client-side software that occurs to make money is typically described in privacy policies, and a browser adding additional tracking would likely cause an uproar. While Firefox may provide a better default regarding sync, there is a difference between saying "stop using Chrome" and "enable client-side encryption".

> Tracking in client-side software that occurs to make money is typically described in privacy policies, and a browser adding additional tracking would likely cause an uproar

Emphasis mine. Yes, you might trust them not to track you, or to trust that someone will find out if they do, and that you will hear about it if so. But far better would be to use an open source browser (either Firefox or Chromium).

Post reply on HN