Live data from Hacker News

Groklaw legal site shuts over fears of NSA email snooping

theguardian.com

31–40 of 237 posts

Re: Groklaw legal site shuts over fears of NSA email snooping

#31

Now more than ever is when we need sites like this. This all plays right into the government's hands. They may as well keep it up because people are self-censoring and that makes their jobs easier.

If one person does it, it's self-censorship. If a group of people do it's a non-violent collective action protest.

These are in no way a "protest". Once a site shuts down, that's it, there is no message / discussion / fight, and it just blends into the background radiation a day later.

Continuing the site would benefit the "protest" infinitely more. And the operators probably know this on some level.

And that's the real story here -

These sites are shutting down because 1) it was unprofitable, 2) it was a time-sink, and 3) now there is an excuse to get out and move on with their lives and businesses.

*I'm not blaming them - and I'm not saying it's anything above the subconscious level. I'd probably do the same.

Re: Groklaw legal site shuts over fears of NSA email snooping

#32
post #11

Earlier quoted context omitted.

I agree, but I'd also like to add a more specific cause to this idea. Like you say, technical measures aren't a bad idea either, but only drag things on. My political view is this: both the right to communicate and the privacy of communications need to be treated as a fundamental human rights, just as freedom of speech is currently treated. Then there are subjective measures. Breaching these rights may be warranted i…

but in the us freedom of speech is not universally applied ie you employer can sack you for what you say for example "oh maybe we should organize a union" or maybe "the NHS model is a good idea" Any changes need to apply universally and not just to the government.

I don't think this matters. Since I'm advocating privacy of communications, you could arrange to use trusted third parties and encryption such that others would not know what you've been saying, or with whom you've been communicating. It's perfectly reasonable for an employer to monitor communications while on their premises, and it is generally illegal for them to wiretap your home without you knowing about it.

Re: Groklaw legal site shuts over fears of NSA email snooping

#35
post #16
post #12

Huh? I just don't follow. Groklaw is not a site that depends on anonymous tips. The last few stories posted on Groklaw were on Apple vs Samsung and did not appear to require privileged confidential information. How is it that other groups that do directly go against the government, such as the ACLU and the EFF, continue to do so without a paralyzingly fear that they can't keep their communications secret? The logical…

It doesn't depend on anonymous tips, but encourages them. PJ is basically saying she wants to prevent folks from sending her honest questions about things they have done or are involved from admitting guilt to law enforcement who can read everything.

Make sense, but I still think it's an overreaction. My original question still stands (is it irresponsible for the EFF/ACLU/etc to continue to operate with an online mailbox?), and I would also argue that PJ could mitigate this by simply removing any contact form or information from her site. Yes, people who know her email can still contact her anyway but obviously, that means they can already do that after the site is shut down. Groklaw could continue to operate as an outspoken advocate for legal freedom...perhaps Glenn Greenwald will find himself in a similar position, in which all communication to him is expected to be compromised, but I'd still think he'd continue to do his reporting and writing even if his sourcing was scarce.

Re: Groklaw legal site shuts over fears of NSA email snooping

#36
post #6

This is a tragedy. We need to reboot email. Encrypt everything, including metadata -- given current hardware, the client can easily bruteforce it from a list of known keys. Build some sort of easy key distribution tool (connecting via p2p, dns, whatever, just build a goddamn UI). Ask existing transports to relax their restrictions enough to let fully-encrypted mail through, and build some intelligent webmail interfac…

Won't work.

If you want a technological solution to the problem, use lavabit... I understand they offer a secure, encrypted (and reasonably convenient and usable) email service.

Re: Groklaw legal site shuts over fears of NSA email snooping

#37
post #6

This is a tragedy. We need to reboot email. Encrypt everything, including metadata -- given current hardware, the client can easily bruteforce it from a list of known keys. Build some sort of easy key distribution tool (connecting via p2p, dns, whatever, just build a goddamn UI). Ask existing transports to relax their restrictions enough to let fully-encrypted mail through, and build some intelligent webmail interfac…

The Direct Project is an email encryption scheme that hopes to replace the mail and fax currently used by American physicians to communicate patient health information. It is a requirement for Stage 2 (2014) Meaningful Use certified EHR software. So this is going to be adopted on a large scale in the next year or two.

It uses SMTP to transmit SMIME messages signed with X.509. Public keys for recipients are discovered either via DNS (as a CERT record) or via LDAP. Those discovered certificates are only trusted if the two parties have previously exchanged a trust anchor.

Direct itself does not define how trust relationships are initiated (which is a problem with scalability). So infrastructure is being formed around the protocol - such as HISPs and Trust Communities. HISPs intend to operate similar to how email providers operate - by providing web portals and edge protocols. Trust Communities are intended to create bundles of trust anchors for companies that have passed as certain level of accreditation.

There are currently two fully functional open source Reference Implementations in Java and C#.

http://directproject.org/

http://wiki.directproject.org/

http://wiki.directproject.org/Reference+Implementation+Workg...

Re: Groklaw legal site shuts over fears of NSA email snooping

#38
post #6

This is a tragedy. We need to reboot email. Encrypt everything, including metadata -- given current hardware, the client can easily bruteforce it from a list of known keys. Build some sort of easy key distribution tool (connecting via p2p, dns, whatever, just build a goddamn UI). Ask existing transports to relax their restrictions enough to let fully-encrypted mail through, and build some intelligent webmail interfac…

Any centralized service can be ordered to hand over encrypted material or to implement a backdoor, similar to Lavabit case. Bitmessage could be one possible type of solution. That way the only way to compromise the message (assuming it is as safe as bitcoin, not claiming bitmessage is) would be to compromise the sender or the receiver, both is much more secure than any email service. And they could not make any backdoors, because the code is opensource and changes would be visible. If they would make some of the clients with some kind of backdoor, others, without backdoor, could possibly not accept their messages, so the 51% attack would be vulnerability.

Re: Groklaw legal site shuts over fears of NSA email snooping

#40
post #28
post #9

Earlier quoted context omitted.

I disagree. This is a political fight. Technical means can drag the resistance longer, which is helpful, but the political system needs to be put in checks and balances against becoming a police state. There is no substitute of "taking roads and doing peaceful protests" as out of comfort zone they might be. We sometimes fall in love with our methods because that is what _we_ are good at, not what is necessarily the b…

The two fights don't conflict. In fact, they complement each other. When all email is getting stored in plaintext on NSA computers, it's going to be hard to get the government to give up all that juicy data. Reduce the value of the data they're getting, and it's easier to reach a point where the political heat just isn't worth it to them. At the same time, the political effort helps prevent new laws that make the tec…

I think it's not the value of data should be reduced, it's the cost of access to the data should be increased. If it would be too expensive to watch everyone, they would naturally stop doing that.
Post reply on HN