Live data from Hacker News

You have a moral obligation to use crypto

blog.easydns.org

31–40 of 92 posts

Re: You have a moral obligation to use crypto

#31
post #16

Earlier quoted context omitted.

Can you add a CA to firefox manually yourself? It looks like you can.

Adding a single root to locally installed copies of a web browser is only really useful for 2 things: testing an SSL configuration for development, and deploying your own CA to all computers on an intranet to so you can MITM their traffic without throwing up warnings. For a bit of fun, compare the warnings about a self-signed certificate in Firefox with those triggered by attempting to download a self-signed certific…

A 3rd thing, which I've done, is for a private site to collaborate with a small group of people I know in real life. You give them a hardcopy of your CA cert and then they can verify the details when adding it to their browsers.

Re: You have a moral obligation to use crypto

#32
post #29
post #25

Earlier quoted context omitted.

That's nice. But putting our email, IM, and VoIP out of reach of snooping would actually change things. Actually, you can stop being obtuse here rather than farther down the thread.

You wrote "secure key exchange, secure real time communication, secure storage, and secure email payload would blind the surveillance state". Now I'm not sure we're working from the same definitions of those terms.

If you think Google, or any other consumer Internet service, has already secured those things, evidently not. What I have in mind is end-to-end encryption with no provisions for surveillance of cleartext, with or without a warrant. As I wrote earlier in this thread, even if you think our law enforcement can be trusted, there are plenty of jurisdictions where that is not the case at all.

Re: You have a moral obligation to use crypto

#33
post #32
post #29

Earlier quoted context omitted.

You wrote "secure key exchange, secure real time communication, secure storage, and secure email payload would blind the surveillance state". Now I'm not sure we're working from the same definitions of those terms.

If you think Google, or any other consumer Internet service, has already secured those things, evidently not. What I have in mind is end-to-end encryption with no provisions for surveillance of cleartext, with or without a warrant. As I wrote earlier in this thread, even if you think our law enforcement can be trusted, there are plenty of jurisdictions where that is not the case at all.

I think I understand. Any acknowledgement that Google has done more to secure Internet traffic for normal users than any other company would require you to concede something, and thus feel bad.

Re: You have a moral obligation to use crypto

#34
post #22

OK. I'm prepared to agree with the headline in principle. However, here's the deal/problem: I am willing to encrypt outgoing mail only in cases where I can identify that the recipient are capable of decrypting it (with 0 friction at any stage). It's (still) more important to me that my e-mail is read by the recipient, than that it's not read by any other party.

Do email sites not already use HTTPS?

Re: You have a moral obligation to use crypto

#35
post #33
post #32

Earlier quoted context omitted.

If you think Google, or any other consumer Internet service, has already secured those things, evidently not. What I have in mind is end-to-end encryption with no provisions for surveillance of cleartext, with or without a warrant. As I wrote earlier in this thread, even if you think our law enforcement can be trusted, there are plenty of jurisdictions where that is not the case at all.

I think I understand. Any acknowledgement that Google has done more to secure Internet traffic for normal users than any other company would require you to concede something, and thus feel bad.

"Normal users" don't need their stuff hidden from government surveillance? Nope, not going to concede that.

Stop being obtuse and address the point of the article: Unless encryption is routine, it isn't effective against dragnet surveillance.

Re: You have a moral obligation to use crypto

#36
post #30
post #28

Earlier quoted context omitted.

I would probably self-identify as a libertarian (although I would be eager to qualify that), and I am very tired of statements about moral obligations.

Empty and unjustified statements about moral obligations.

The thing about moral obligations is you can't really "justify" them to someone who doesn't share your fundamental beliefs about morality itself.

Re: You have a moral obligation to use crypto

#38
post #16

Earlier quoted context omitted.

Adding a single root to locally installed copies of a web browser is only really useful for 2 things: testing an SSL configuration for development, and deploying your own CA to all computers on an intranet to so you can MITM their traffic without throwing up warnings. For a bit of fun, compare the warnings about a self-signed certificate in Firefox with those triggered by attempting to download a self-signed certific…

A 3rd thing, which I've done, is for a private site to collaborate with a small group of people I know in real life. You give them a hardcopy of your CA cert and then they can verify the details when adding it to their browsers.

The real interesting thing about that use is that it makes it impossible for the NSA and the like to strong arm someone else for the keys.

With what we know about the current environment, being your own CA is actually the most secure approach.

Re: You have a moral obligation to use crypto

#39
post #36
post #30

Earlier quoted context omitted.

Empty and unjustified statements about moral obligations.

The thing about moral obligations is you can't really "justify" them to someone who doesn't share your fundamental beliefs about morality itself.

Do you think most people are constructing their morality on top of some fundamental beliefs?

(I tend to think we work backwards trying to come up with compact descriptions of what we are comfortable with...)

Re: You have a moral obligation to use crypto

#40
> But the idea that we are somehow "out of reach of the NSA" is definitely not one of them. Sure, we're not actively collaborating with them, as many US businesses are, but as we've said before: we just assume the pipes going into and out of our major network exchange points are being vacuumed en masse.

Maybe easydns isn't, but the Telcos are definitely collaborating. We've had intercept equipment directly under the control of CSIS installed in major datacenters since the early 2000s. (I really do mean CSIS, not CSEC.)

I've seen it myself and I have multiple sources with direct, first hand knowledge of it.

None of them are interested in coming forward though, and I have no proof to offer myself.

What would necessitate cooperation of easydns anyway? They can't possibly get transit or peer with anyone of significance in Canada that doesn't have the surveillance equipment installed, so I don't see why any of the spooks would bother contacting them.

Post reply on HN