Live data from Hacker News

Prism Break

prism-break.org

171–180 of 205 posts

Re: Prism Break

#171
Surviving in the current situation, will require a radical change in attitude and education - you know, effort - not just switching out bits of software.

Re: Prism Break

#172
post #8

Several of these suggestions seem somewhat disingenuous - e.g. many of them to be about free software more than actual concerns about tracking, as reflected in the labels "Proprietary" and "Free alternatives". In particular: - None of the proprietary browsers will track you - well, beyond what's specified in the privacy policy. Two of the alternatives are Tor applications, but the other two are Firefox (which provide…

> - OS X and Windows won't track you.

How do you know? Too much trust in MS and Apple? Backdoors in such systems is a normal thing to expect.

Re: Prism Break

#173

Earlier quoted context omitted.

Unless they frequency-modulate the packets they send home to transmit additional data and you'd probably never figure it out looking at Wireshark output that they are sending more than meets the eye. This is a simple trick; there are probably many other I can't even think of.

I've never heard the term "frequency-modulate" applied to software, and Wikipedia only knows about the radio kind of modulation. Can you please explain what this is?

This is an interesting idea. I assume by "frequency modulation" of data, he means adjusting the timing of the transmissions to create an out-of-band channel that might be more difficult to notice when packet sniffing. As a crude example, if I uploaded War and Peace to you, not as a steady stream of traffic, but as bursts of dots and dashes, I could send "The Magic Words are Squeamish Ossifrage" in Morse code. (Although in the context of apps phoning phone, I'm not sure what the advantage is over simply encrypting the stream...)

Re: Prism Break

#174
I want to like this page but there are many problems...

* Who is the target demographic for this page? If it's lay-users, many of the suggestions are inappropriate: no-script, arch linux, "host-your-own cloud provider"... these are useless if you're not a programmer.

* Many of the suggestions don't do anything to improve your privacy. As tptacek noted, host-your-own may protect you from gmail handing your emails over en masse, but it doesn't protect you from yourself (you eliminate one attack surface but add many many new ones). Switching your email client... again, if the gov't can just ask your provider for all your mails, your client is irrelevant (excepting gpg which is a different question). It seems like many of these will create a false sense of security, which is even worse than no sense: "Yay I switched from outlook to icedove, take that NSA."

* There are way too many alternatives listed. What is the point of listing six different linux distributions? Pros are aware of the fact that there are many distros, newbs need a recommendation, not a dizzying list of alternatives with no guide to how to pick one. (I see mint is listed as newb choice; why are qubes, trisquel, etc. listed at all?). Ditto mail clients, browsers, and especially social networks. It seems little care was taken to ensure that the software on this list has any merit beyond being "free." Hey I made a free [barely functional, never updated] chat client, why isn't it on your list??

* The list reeks of politics over practicality. Seriously, IceDove? Trisquel? I'm a linux user at home, have used tbird, pidgin (& finch), adium, OTR, debian, ubuntu, mint, etc. etc. and I've never even heard of these tools. I suspect they are being listed because they are "FSF Endorsed" not because they are actually more useful. This is an AWESOME way to alienate new users: steer them toward ideologically pure but hard-to-use or nonfunctional software.

My suggestions: * pare down the list (only list 1 or 2 of the best alternatives, maybe with a "more options" link for IceDonkey or whatever);

* Indicate how much technical expertise is needed for different tools. NoScript is USELESS for lay-users, disconnect.me (if it's like ghostery) & adblock are set&forget, very low friction options for new users. Ditto arch linux &c.

* Don't include things just because it meets the requirements of being "free"!! You don't need every half-functional email client in the world because it's "free"- this makes the list worse, not better.

* Make clear what tools do and don't do!! Merely switching to pidgin to connect to your does nothing for you, your list suggests it does. Blocking google analytics does not stop the NSA or whomever from requesting information from your ISP about your browsing habits!!! This needs to be more clear on your list.

* Don't make outlandish, inaccurate, unrealistic claims! "Stop the American government from spying on you by encrypting your communications and ending your reliance on proprietary services." 90% of these tools have nothing to do with encryption and/or aren't any more secure by default. You can't "opt out of prism." You're not "stop[ping] the American government from spying on you" by hosting your own wordpress. This claim is horsefeathers and it needs to be removed.

Oh well... at this point I'm feeling that in its current state your list does more harm than good, overwhelming users with too many (shitty) choices, creating a false sense of security, and muddying the waters about online privacy like crazy. These tools require attendant tech education: you can't just dump Adium in someone's lap and say "now you're protected from spying."

Re: Prism Break

#175
post #76

While I understand and sympathise with the compulsion to resist surveillance in this practical, technological way, I think it might be the wrong reaction to the information. It's typical of techie people to seek technical solutions to social problems, and this is one such case. It may well be possible to mitigate their ability to watch you by wearing enough tin-foil hats. Even if you succeed, all you've achieved is t…

Cryptopunk's response to this is: write code, not law. Law writers and enforces are corruptible, while code is not.

> "code is not"

... what exactly have we uncovered with PRISM and the NSA bulk wiretapping, if not code having been corrupted from its original purposes in ways and extents unforeseen at the outset?

One has to write anonymizing p2p proxies because the old stack was corrupted. It's hardly different than the reason one would want new laws to address the way the old ones have been corrupted.

And our new p2p proxies? They're also (going to be) subject to corruption, by unforeseen things like Sybil attacks. Just as any new law is subject to possible future corruption.

Re: Prism Break

#176
post #161

Earlier quoted context omitted.

Is it a crime for a hungry man to steal bread? None of your proposed solutions would address his needs. America's government is so corrupt it is no longer democratic. Watch this video: https://www.youtube.com/watch?v=mw2z9lV3W1g

...yes, it is.

It isn't under Sharia law.

Re: Prism Break

#177

Earlier quoted context omitted.

I know I can select a webmail provider that is not beholden to the United States of America's government. If you think Google is the only company that can secure webmail, I bet you are an employee.

If you really bet that, it says more about you than me. But anyways: what does it matter if your webmail provider isn't beholden to the government, if a suitably motivated teenager can read your mail because of software vulnerabilities? Google Mail isn't likely to be more secure just because Google is inherently better at building software than anyone else. Rather, it's because they allocate more resources to the pro…

False equivocation. A script kiddie is not the same as a three letter agency funded by a first world government.

Re: Prism Break

#178

Earlier quoted context omitted.

Is it a crime for a hungry man to steal bread? None of your proposed solutions would address his needs. America's government is so corrupt it is no longer democratic. Watch this video: https://www.youtube.com/watch?v=mw2z9lV3W1g

> America's government is so corrupt it is no longer democratic. Unfortunately yes, absolutely. And you begin to see a direct cause-and-effect relationship between the level of corruption and the "quality" of the policy decisions that are made, example: The Iraq war. Another one: the "inertia" regarding climate change action (it's just corporate power effing it all up for us). It really has a grave effect on all huma…

You forget that we are as a whole a up-and-coming group and in 10 years, many of us will be in very powerful positions. The digital revolution did not enter mainstream before the 2000s: What we can and should do now, is talk to others, explain what is going on, share our ideas. Be the change and the world will follow.

Re: Prism Break

#179
post #76

While I understand and sympathise with the compulsion to resist surveillance in this practical, technological way, I think it might be the wrong reaction to the information. It's typical of techie people to seek technical solutions to social problems, and this is one such case. It may well be possible to mitigate their ability to watch you by wearing enough tin-foil hats. Even if you succeed, all you've achieved is t…

I think these things are not mutually exclusive. You raise good points that aren't addressed at Prism Break though.

Re: Prism Break

#180

Earlier quoted context omitted.

If you really bet that, it says more about you than me. But anyways: what does it matter if your webmail provider isn't beholden to the government, if a suitably motivated teenager can read your mail because of software vulnerabilities? Google Mail isn't likely to be more secure just because Google is inherently better at building software than anyone else. Rather, it's because they allocate more resources to the pro…

False equivocation. A script kiddie is not the same as a three letter agency funded by a first world government.

First, I don't think "equivocation" means what you think it means.

Second, the equivalence isn't false. The Venn diagram of sites that can be compromised by script kiddies is entirely contained by that of sites that can be compromised by NSA.

Post reply on HN