Live data from Hacker News

CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

itsecurityguru.org

51–60 of 86 posts

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#51
post #29

Earlier quoted context omitted.

What's that got to do with it? (genuinely interested).

I think it's ironic that those who are in favour of personal liberties are often on the left of the political spectrum whereas, in this instance, it was the Tories who rolled back aspects of surveillance legislation that was introduced by Labour.

I think that the left/right distinction is silly myself. A typical red vs blue flag waving exercise rather than solving anything.

Both labour and conservatives seem to mix the tenets of the two freely based on whim rather than manifesto.

On one hand we have Big Society and smash socialism.

On the other hand we have Big Society and smash socialism.

Same turds, different coloured glitter.

All parties have sold out to their corporate sponsors and are as bent as anything.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#53

we had the choice to make - either architect the world's most secure encryption system on the planet, so secure that CertiVox cannot see your data, or spend £500,000 building a backdoor into the system So, just like Lavabit as 'moxie keeps pointing out[1][2], it wasn't actually secure. Still, I like the principled stand they took. [1] https://news.ycombinator.com/item?id=6672442 [2] http://www.thoughtcrime.org/blog/l…

There is no actually secure - that's the problem. The best you can do is secure against specific threat models. Up until recently, most people didn't necessarily view government intrusion as a particularly credible threat, so didn't spend the extra time/effort/money mitigating against it.

One of the best things to come out of all these revelations, in my opinion, is a revised view of what threats we should consider which were previously dismissed as paranoid ramblings.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#54
post #51

Earlier quoted context omitted.

I think it's ironic that those who are in favour of personal liberties are often on the left of the political spectrum whereas, in this instance, it was the Tories who rolled back aspects of surveillance legislation that was introduced by Labour.

I think that the left/right distinction is silly myself. A typical red vs blue flag waving exercise rather than solving anything. Both labour and conservatives seem to mix the tenets of the two freely based on whim rather than manifesto. On one hand we have Big Society and smash socialism. On the other hand we have Big Society and smash socialism. Same turds, different coloured glitter. All parties have sold out to t…

Whilst I don't agree 100%, I don't disagree strongly enough to make an argument of it. :-)

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#55
post #37
post #4

There are some details of the legislation in question here[1]. It allows the UK to monitor "in the interests of the economic well-being of the United Kingdom" which seems a little broad! It would be interesting to know if this warrant targeted all users or a specific subset? I wonder how they decide whether to issue a warrant or just break into the site in question. A warrant could imply that they are unable to attac…

A warrant might just mean that they're asking for the information legally, so that they can use it, rather than relying on their illegally gathered hacked information. A warrant might mean that they do not ever illegally hack sites, and that they only ever obey the law. RIPA is problematic law, and it's nice to see discussion of RIPA cases involving GCHQ. Not avoiding the problems of RIPA and GCHQ (I certainly think…

> A warrant might just mean that they're asking for the information legally, so that they can use it, rather than relying on their illegally gathered hacked information.

Note that the "warrant", in this case, required that CertiVox hand over the key(s) to the encrypted data. It's possible that the authorities (not necessarily GCHQ itself, as NTAC provides assistance to other law enforcement and intelligence agencies) had already intercepted or seized the data but were unable to read it because it was encrypted.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#56
post #53

we had the choice to make - either architect the world's most secure encryption system on the planet, so secure that CertiVox cannot see your data, or spend £500,000 building a backdoor into the system So, just like Lavabit as 'moxie keeps pointing out[1][2], it wasn't actually secure. Still, I like the principled stand they took. [1] https://news.ycombinator.com/item?id=6672442 [2] http://www.thoughtcrime.org/blog/l…

There is no actually secure - that's the problem. The best you can do is secure against specific threat models. Up until recently, most people didn't necessarily view government intrusion as a particularly credible threat, so didn't spend the extra time/effort/money mitigating against it. One of the best things to come out of all these revelations, in my opinion, is a revised view of what threats we should consider w…

Sure, but they don't seem any more (technically) secure than any other decent webmail provider.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#57
post #53

we had the choice to make - either architect the world's most secure encryption system on the planet, so secure that CertiVox cannot see your data, or spend £500,000 building a backdoor into the system So, just like Lavabit as 'moxie keeps pointing out[1][2], it wasn't actually secure. Still, I like the principled stand they took. [1] https://news.ycombinator.com/item?id=6672442 [2] http://www.thoughtcrime.org/blog/l…

There is no actually secure - that's the problem. The best you can do is secure against specific threat models. Up until recently, most people didn't necessarily view government intrusion as a particularly credible threat, so didn't spend the extra time/effort/money mitigating against it. One of the best things to come out of all these revelations, in my opinion, is a revised view of what threats we should consider w…

You're right that we may have been naive about trusting our governments.

What I don't understand is why anyone trusted businesses (such as CertiVox and Lavabit) to keep their emails secure?

If the businesses themselves couldn't decrypt these emails, there's nothing the government could usefully ask them for.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#58
post #29

Earlier quoted context omitted.

What's that got to do with it? (genuinely interested).

I think it's ironic that those who are in favour of personal liberties are often on the left of the political spectrum whereas, in this instance, it was the Tories who rolled back aspects of surveillance legislation that was introduced by Labour.

Mean while, they Tories have rolled back legal aid, which means the poor cant get decent lawyers any more.

Non Brits might be amused to know that this Tory government wanted to out source poor people's legal representation to a haulage company. Yeah, you read that right.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#59
post #3

Wow, shows a lot of integrity closing the product instead of still keeping it up in a compromised state to comply with the warrant. We've seen some other providers here in the US even changed functionality to retain keys used in web clients of secure email at the behest of government orders. This does mean that the UK is now on the list, along with the US, of places where no credible crypto startup is possible, thoug…

I think most people completely missed the part of Snowden leaks that directly said that GCHQ is not any better than NSA.

GCHQ are both better and worse than the NSA. I would argue that it seems they are if anything even less restrained than the NSA in over broad surveillance. However it is less clear whether GCHQ have actually broken the rules (and certainly not the constitution) which the NSA may have done.

My view is that everyone (in the world) should be pissed off at both the NSA and GCHQ and that Americans should be additionally angry that the NSA seems to have broken the limits placed on them in terms of domestic surveilance.

Re: CertiVox confirms it withdrew PrivateSky after GCHQ issued warrant

#60
post #36

Earlier quoted context omitted.

So if I put a gun to your head, and you give me money, you haven't been forced to, right? Are you PG? No? Then who are you to decide when a discussion ends round here?

> So if I put a gun to your head, and you give me money, you haven't been forced to, right? Wrong. I HAVE been forced. You have threatened me with death if I don't comply with your demand. GCHQ never demanded that CertiVox shut down their service. They (or, rather, the Home Secretary) demanded that they hand over the key(s) required to decrypt one (or more) of CertiVox's customer's data. If CertiVox took it upon them…

Theresa, is that you?!

[1] https://en.wikipedia.org/wiki/Theresa_May

Post reply on HN