Live data from Hacker News

Prism Break

prism-break.org

121–130 of 205 posts

Re: Prism Break

#121
post #83

I praise this effort. Whatever the criticism may be, it's a useful site and it educates people. Folks like them do a lot more than us ranting here in the comments :)

I am not sure what kind of education does it provide. If NSA has access to GMail, it does not matter what email client you use, open-source or proprietary. If your ISP logs all your activity, it does not really matter what browser do you use. And in general it is simpler and more revarding to target services providers instead of client apps for those services.

Re: Prism Break

#122

Earlier quoted context omitted.

I don't think the idea is to 'flee', but to lead by example and use secure technologies so they become better and more convenient and spread faster. If everyone used tools like this, it would be much more difficult for governments to trample on privacy rights. It seems like a worthy goal.

But let's also be realistic -- if this technology reached mass adoption, the predictable outcomes are either 1) The government outlaws it or 2) They figure out ways to work around the security

Mass adoption is a bulwark against legislation, not a promoter of it. Eg. alcohol is legal because it's popular, not because it's safer than drugs which are illegal.

Re: Prism Break

#123
post #14

Earlier quoted context omitted.

> None of the proprietary browsers will track you. Can you elaborate a bit on this, how do you know they won't? My default assumption is that anything I can't see the source code of and compile myself is compromised.

You can always run Wireshark to see if/when they phone home.

Unless they frequency-modulate the packets they send home to transmit additional data and you'd probably never figure it out looking at Wireshark output that they are sending more than meets the eye. This is a simple trick; there are probably many other I can't even think of.

Re: Prism Break

#125
post #23

Earlier quoted context omitted.

Sociologically: there is a surprisingly large contingent of people who believe that if a company makes a claim, it's the God's honest Truth. The OP may not necessarily fall into this camp. Technically: if the browsers were somehow phoning home, even if the data were highly fuzzed, I'm sure there would be guys like tpatcek who would manage to detail, if not the content of the tracking, at least the amount of data sent…

It is possible to send data along with other data so that it's reaaally hard to find. Also, they don't need to send data all the time, but rather activate this mode on request, say when a person using this browser is a suspect for some reason and govt needs to track his every move on the internet. This would make detecting of such a functionality virtually impossible, because it'd be turned off most of the time for m…

I wonder if anyone tried frequency-modulating the data stream they send home, i.e. encode the sensitive data as changes in frequency of sending packets. Now try to Wireshark that one.

Re: Prism Break

#126
post #76

While I understand and sympathise with the compulsion to resist surveillance in this practical, technological way, I think it might be the wrong reaction to the information. It's typical of techie people to seek technical solutions to social problems, and this is one such case. It may well be possible to mitigate their ability to watch you by wearing enough tin-foil hats. Even if you succeed, all you've achieved is t…

Cryptopunk's response to this is: write code, not law.

Law writers and enforces are corruptible, while code is not.

Re: Prism Break

#127
post #76

While I understand and sympathise with the compulsion to resist surveillance in this practical, technological way, I think it might be the wrong reaction to the information. It's typical of techie people to seek technical solutions to social problems, and this is one such case. It may well be possible to mitigate their ability to watch you by wearing enough tin-foil hats. Even if you succeed, all you've achieved is t…

> If you live in the UK, write to your MP (http://www.writetothem.com/)

Does anyone have a suggested template letter for this?

Re: Prism Break

#128

Earlier quoted context omitted.

You completely missed the point. The NSA is tracking everyone. They're building a database of everyone's activities. Nobody knows who the "terrorists" are going to be 20 years from now. The moment you become a suspect, they can bring up everything they've recorded you saying or doing and use it against you. The NSA is above the law and the rules they follow are set by a secret court appointed by a single man who has…

Also extremely likely - the NSA/GCHQ/Whoever siphon off all "metadata". At the next Boston bombing, or whatever, they analyse that metadata for the perpetrator. And the next one. And the next one. And build a profile of what a "terrorist's" communication patterns look like. And then they single out everyone matching that profile and stick watches on them, or bring them in. It's Minority Report without the psychics. G…

> It's Minority Report without the psychics. Google Now for Homeland Security.

Eagle Eye (yet) without an AI.

Re: Prism Break

#129
Tor should NOT be on here. It has little to do with "breaking" PRISM. PRISM is a voluntary program wherein a handful of endpoints have chosen to submit copies of their database to the NSA. Regardless of the mechanism or browser used to access Facebook, the reality is that all of that data gets uploaded to the NSA anyway, so who cares? People aren't interested in the real solution to PRISM, which is "Don't use services provided by PRISM participants".

Furthermore, Tor's outproxy network (i.e., accessing normal internet sites through Tor) is heavily compromised, rife with honeypots run by both non-governmental and governmental operatives, and nothing stops anyone from injecting more honeypots. New exit nodes are automatically registered and used by the network as soon as the client flips his/her bit. While ostensibly exit nodes are not supposed to be sniffing these packets, since it likely violates wiretapping laws in their jurisdiction (unless it's an NSA-owned exit node, of course), one would be very naive to presume such sniffing is not occurring. This means that any data that eventually hits the exit node should be considered, for all intents and purposes, public (correctly-implemented SSL may mitigate this risk where employed). This is fine if you're just trying to circumvent a firewall (remember, Tor was originally designed as a firewall-circumventer so that dissidents in China et al could convey their traffic to blocked sites; the goal was simply "get this public blog post out of China and to the rest of the world", not "hide all data from the NSA", hence the design of the exit node network) so you can use IRC, where your conversations are public anyway, but it's not fine for all kinds of browsing applications, so "try using Tor for everything" is actually horrendous advice.

The upshot of that is that like most other privacy software, you really need to understand the software well to a) actually obtain any meaningful privacy from its usage and b) not accidentally seriously harm yourself.

On top of all that, Tor traffic is easily distinguished and most likely automatically flags your NSA profile for additional attention.

Re: Prism Break

#130
post #76

While I understand and sympathise with the compulsion to resist surveillance in this practical, technological way, I think it might be the wrong reaction to the information. It's typical of techie people to seek technical solutions to social problems, and this is one such case. It may well be possible to mitigate their ability to watch you by wearing enough tin-foil hats. Even if you succeed, all you've achieved is t…

> I think that we should try not to be meek about this issue, passively hiding ourselves and then getting on with our lives saying "Fuck you, got mine". Why should the tech community flee the very Internet that it has played such a crucial role in building?

Who is "the tech community"? I'm in the tech community, and I'm pretty sure I didn't create The Internet, or Facebook, or the NSA. I think the goal here is to provide people with resources so they can the internet more safely, and to normalize safety measures in order to guard against their demonization or prohibition.

Edit: However I absolutely agree that it's important to fight on social and political fronts as well as technological ones.

Post reply on HN