Live data from Hacker News

You have a moral obligation to use crypto

blog.easydns.org

21–30 of 92 posts

Re: You have a moral obligation to use crypto

#21
post #2

Safari can't verify the identity of the website "blog.easydns.org". The certificate for this website is invalid. You might be connecting to a website that is pretending to be "blog.easydns.org", which could put your confidential information at risk. Would you like to connect to the website anyway?

As usual, misconfiguration causing scary warnings, useless to the end user, but the connection is still encrypted. I really wish we'd divorce the identity assurance part of PKI from the encryption part. I have no idea how it would be done, but.

[deleted]

Re: You have a moral obligation to use crypto

#22
OK. I'm prepared to agree with the headline in principle.

However, here's the deal/problem:

I am willing to encrypt outgoing mail only in cases where I can identify that the recipient are capable of decrypting it (with 0 friction at any stage).

It's (still) more important to me that my e-mail is read by the recipient, than that it's not read by any other party.

Re: You have a moral obligation to use crypto

#23
post #20

The Internet services who are complaining should start coding, instead, or in addition to complaining. Secure key exchange, secure real time communication, secure storage, and secure email payload would blind the surveillance state. All surveillance states. Even if you think your own surveillance state is less than harmful, there are dozens of others which are patently evil or thoroughly corrupt. And yet, while we do…

Google has done more to securely encrypt Internet traffic than any other company in the world. Among other things, they are the pioneering standard-bearer for ECC forward secrecy and for certificate pinning, the two most important Internet encryption advances in the last 10 years.

Re: You have a moral obligation to use crypto

#24
Reposting my comment on the blog:

I can't comment on which encryption schemes are still strong, but one advantage to using protection for general use is providing strength in numbers. Right now, using Tor or strong encryption is a bright beacon saying "this person has something to hide!" and the NSA et al hone in by default.

If, however, using Tor and strong encryption was the norm, it is easier for those who need it - whistle blowers, dissidents, etc - to hide underneath the regular noise.

edit: keep getting flagged for spam! Perhaps I have the wrong keywords?

Re: You have a moral obligation to use crypto

#25
post #23
post #20

The Internet services who are complaining should start coding, instead, or in addition to complaining. Secure key exchange, secure real time communication, secure storage, and secure email payload would blind the surveillance state. All surveillance states. Even if you think your own surveillance state is less than harmful, there are dozens of others which are patently evil or thoroughly corrupt. And yet, while we do…

Google has done more to securely encrypt Internet traffic than any other company in the world. Among other things, they are the pioneering standard-bearer for ECC forward secrecy and for certificate pinning, the two most important Internet encryption advances in the last 10 years.

That's nice. But putting our email, IM, and VoIP out of reach of snooping would actually change things.

Actually, you can stop being obtuse here rather than farther down the thread.

Re: You have a moral obligation to use crypto

#26

Earlier quoted context omitted.

As usual, misconfiguration causing scary warnings, useless to the end user, but the connection is still encrypted. I really wish we'd divorce the identity assurance part of PKI from the encryption part. I have no idea how it would be done, but.

HTTPS Encryption is virtually useless without the identify verification part. Anyone can run a valid HTTPS server with a self-generated public key. Anyone could then place a MITM, and without the identity bit, you're just as compromised. If we had dropped the identity bit, every ISP would be running a MITM proxy, because they want control. Already, plenty of businesses enable poor hygiene by including transparent squ…

I was familiar with the reasons why using self-signed SSL didn't buy you anything, but hadn't really put together how it would completely weaken the whole ecosystem until now. "Oh, that's just Verizon MITMing me like always..."

Re: You have a moral obligation to use crypto

#27
The title certainly makes an emotional appeal to me. However I could not find justification/explanation of any moral obligation in the text.

I could understand a moral obligation to fight unjust surveillance, but that is not what was presented. Why am I morally obligated to increase the cost of surveillance? If society accepts the unjust surveillance the only consequences of increasing surveillance costs are economic waste and most likely justifications for new encroachments on personal liberty.

Re: You have a moral obligation to use crypto

#28

Never going to get tired of self-identified libertarians making statements about moral obligations.

I would probably self-identify as a libertarian (although I would be eager to qualify that), and I am very tired of statements about moral obligations.

Re: You have a moral obligation to use crypto

#29
post #25
post #23

Earlier quoted context omitted.

Google has done more to securely encrypt Internet traffic than any other company in the world. Among other things, they are the pioneering standard-bearer for ECC forward secrecy and for certificate pinning, the two most important Internet encryption advances in the last 10 years.

That's nice. But putting our email, IM, and VoIP out of reach of snooping would actually change things. Actually, you can stop being obtuse here rather than farther down the thread.

You wrote "secure key exchange, secure real time communication, secure storage, and secure email payload would blind the surveillance state". Now I'm not sure we're working from the same definitions of those terms.

Re: You have a moral obligation to use crypto

#30
post #28

Never going to get tired of self-identified libertarians making statements about moral obligations.

I would probably self-identify as a libertarian (although I would be eager to qualify that), and I am very tired of statements about moral obligations.

Empty and unjustified statements about moral obligations.
Post reply on HN