Live data from Hacker News

Prism Break

prism-break.org

71–80 of 205 posts

Re: Prism Break

#71
post #61
post #47

Earlier quoted context omitted.

In relation to OSX, Windows, Chrome, IE, etc, I thought it was more to do with the fact that Apple, Microsoft and Google have all willingly turned over data to the feds...

> Apple, Microsoft and Google have all willingly turned over data to the feds More like gave direct access to their backends . [1] [1] https://www.youtube.com/watch?v=StlFKE_UVI4

One person's paraphrase of a general system is not evidence.

Re: Prism Break

#72
post #62

Earlier quoted context omitted.

Google works for the NSA. Avoid.

If you think you can do as robust a job at securing your mail as Google does with Gmail, by all means. But I'd feel awfully dumb if I migrated from Gmail to some other web mail provider only to lose my mail to a 17 year old with a Perl script.

I'm paying hushmail. But I suppose it's no better, they still honour warrants, and I haven't actually used the encryption provided, other than notes to self. I left google, when they changed the privacy policy last year, all google services build one personal profile etc. This is a ramble, but hushmail works, thus far.

Re: Prism Break

#73
post #62

Earlier quoted context omitted.

Google works for the NSA. Avoid.

If you think you can do as robust a job at securing your mail as Google does with Gmail, by all means. But I'd feel awfully dumb if I migrated from Gmail to some other web mail provider only to lose my mail to a 17 year old with a Perl script.

I know I can select a webmail provider that is not beholden to the United States of America's government.

If you think Google is the only company that can secure webmail, I bet you are an employee.

Re: Prism Break

#74
Let's pretend I'm the NSA. I don't care right now about what your saying, I just care about who you associate with and where you are hanging out. If those raise my suspicions then I will also track the where/who connections and create a map of activity. Those dots might start to line up and create further interest.

If suspicions are founded as actual threats I will do anyone of the following and probably more.

FISA request

Look into your credit card records and bank transactions

Serve your host/ISP with a request and also get your SSL private keys

Listen in on your cell phone/home phone/sat phone

Use traditional listening devices (these are great btw..)

Find an exploit in something you use (I'm pretty sure I have some zero days lying around).

Listen in on your girlfriend/wife/husband/boyfriend/friends and family.

Create lots of tor exit nodes and track your patterns

Ask some actual spy's/moles for some intel

Use satellites and tracking devices, maybe even some drones

Torture

Wait for you to mess up..people are lazy.

I made this to point out some real tactics that are actually used and why the vast majority of PRISM related posts like these are a bit silly...aka..you're probably not a terrorist. The NSA tracked bin Laden's courier Abu Ahmed al-Kuwaiti's cell phone which eventually led them to Bin Laden. Does that sound like anything you're doing?

The NSA is not above the law and I generally support Snowden, William Binney, etc .. I just think people need to get grip on reality here. The only people tracking you are ad trackers.

ps. Don't fret too much about the NSA, Google Glass will have citizens spying on each other in no time flat.

Re: Prism Break

#75
post #46

It is important to mention that "self-hosted" by itself, does not make one Prism-Free. In most cases, if the hosting platform provider will be asked to provide access to the infrastructure, it is most likely that SSL private keys that stored on the virtual machine will be taken along with other data.

Sorry, this is a fallacy of false equivocation. Not all hosting platforms are the same, especially in terms of jurisdiction.

Switzerland and China do not respond to Secret Service or FBI orders.

Re: Prism Break

#76
While I understand and sympathise with the compulsion to resist surveillance in this practical, technological way, I think it might be the wrong reaction to the information. It's typical of techie people to seek technical solutions to social problems, and this is one such case.

It may well be possible to mitigate their ability to watch you by wearing enough tin-foil hats. Even if you succeed, all you've achieved is to protect one solitary person at the cost of considerable personal inconvenience. Worse, once you consider yourself "safe enough" from prying eyes, your incentive to actually act on what they're doing will be diminished.

I think that we should try not to be meek about this issue, passively hiding ourselves and then getting on with our lives saying "Fuck you, got mine". Why should the tech community flee the very Internet that it has played such a crucial role in building? Is the idea that our democracies could eventually fix this situation really beyond all hope?

If you live in the UK, write to your MP (http://www.writetothem.com/). Support PPUK (http://www.pirateparty.org.uk/) if you feel strongly enough, as they're seemingly the only political group treating this matter with the seriousness it deserves.

Re: Prism Break

#77
post #49

Earlier quoted context omitted.

>My default assumption is that anything I can't see the source code of and compile myself is compromised. Did you also write and compile the compiler that compiled your compiler?

He very well may have, since you compile gcc using gcc.

I think blhack was referring to Ken Thompson's ACM Turing Award acceptance speech "Reflections On Trusting Trust"?

http://c2.com/cgi/wiki?TheKenThompsonHack

"a hack (in every sense), the most subversive ever perpetrated, nothing less than the root password of all evil."

A very very good read :)

Re: Prism Break

#79
post #8

Several of these suggestions seem somewhat disingenuous - e.g. many of them to be about free software more than actual concerns about tracking, as reflected in the labels "Proprietary" and "Free alternatives". In particular: - None of the proprietary browsers will track you - well, beyond what's specified in the privacy policy. Two of the alternatives are Tor applications, but the other two are Firefox (which provide…

> None of the proprietary browsers will track you

> Windows won't track you

Pinky-promise?

Post reply on HN