Live data from Hacker News

You have a moral obligation to use crypto

blog.easydns.org

41–50 of 92 posts

Re: You have a moral obligation to use crypto

#41
post #13

Earlier quoted context omitted.

As usual, misconfiguration causing scary warnings, useless to the end user, but the connection is still encrypted. I really wish we'd divorce the identity assurance part of PKI from the encryption part. I have no idea how it would be done, but.

Moxie introduced http://www.convergence.io/ a while ago now ( https://www.youtube.com/watch?v=8N4sb-SEpcg ), which could offer significant advantages over the PKI if it became widely adopted. Although it's not an end-all solution to identity, it's a step in the right direction (using web-of-trust ideas).

So convergence.io is only available over HTTP, yet it offers the plugin for download. It seems an ironically bad practice to install security software over an untrusted connection. Meanwhile, https://convergence.io yields a certificate for whispersystems.org and is in fact the https://whispersystems.org/ main page (nothing to do with convergence.io). There appears to be no secure way to obtain Moxie's plugin (it is not available from mozilla.org, though a fork is available, based on this repo: https://github.com/mk-fg/convergence). My understanding is that more recently, Moxie has been focusing on http://tack.io which offers improved security without overturning the CA model.

Re: You have a moral obligation to use crypto

#42
post #36

Earlier quoted context omitted.

The thing about moral obligations is you can't really "justify" them to someone who doesn't share your fundamental beliefs about morality itself.

Do you think most people are constructing their morality on top of some fundamental beliefs? (I tend to think we work backwards trying to come up with compact descriptions of what we are comfortable with...)

> Do you think most people are constructing their morality on top of some fundamental beliefs?

Yes, but not necessarily consciously, and certainly not necessarily consistently.

Re: You have a moral obligation to use crypto

#43
post #27

The title certainly makes an emotional appeal to me. However I could not find justification/explanation of any moral obligation in the text. I could understand a moral obligation to fight unjust surveillance, but that is not what was presented. Why am I morally obligated to increase the cost of surveillance? If society accepts the unjust surveillance the only consequences of increasing surveillance costs are economic…

It will become, if it is not already, a practical obligation. Why should anyone in the rest of the world trust American products that enable "justified" surveillance?

Re: You have a moral obligation to use crypto

#44
post #36
post #30

Earlier quoted context omitted.

Empty and unjustified statements about moral obligations.

The thing about moral obligations is you can't really "justify" them to someone who doesn't share your fundamental beliefs about morality itself.

I could have been clearer with what I meant by justification. By justify I meant demonstrate/explain, e.g.

* What are the moral values/principles that create the obligation?

* How does the use of crypto foster these principles?

Re: You have a moral obligation to use crypto

#45
post #23
post #20

The Internet services who are complaining should start coding, instead, or in addition to complaining. Secure key exchange, secure real time communication, secure storage, and secure email payload would blind the surveillance state. All surveillance states. Even if you think your own surveillance state is less than harmful, there are dozens of others which are patently evil or thoroughly corrupt. And yet, while we do…

Google has done more to securely encrypt Internet traffic than any other company in the world. Among other things, they are the pioneering standard-bearer for ECC forward secrecy and for certificate pinning, the two most important Internet encryption advances in the last 10 years.

Those things are very significant, much needed improvements, but would you agree that we need more user controlled, end to end crypto? I'm talking about things like ZRTP here. I'm not expecting solutions like that to come from Google because it has a vested interest in mining your data. Possibly even more so than NSA does.

Re: You have a moral obligation to use crypto

#46
post #36

Earlier quoted context omitted.

The thing about moral obligations is you can't really "justify" them to someone who doesn't share your fundamental beliefs about morality itself.

Do you think most people are constructing their morality on top of some fundamental beliefs? (I tend to think we work backwards trying to come up with compact descriptions of what we are comfortable with...)

Yes. I can not imagine any other conception of moral obligation. How would you come up with an obligation to do X or not do Y without an underlying belief structure?

Re: You have a moral obligation to use crypto

#47
post #22

OK. I'm prepared to agree with the headline in principle. However, here's the deal/problem: I am willing to encrypt outgoing mail only in cases where I can identify that the recipient are capable of decrypting it (with 0 friction at any stage). It's (still) more important to me that my e-mail is read by the recipient, than that it's not read by any other party.

Do email sites not already use HTTPS?

Transfer between servers is over SMTP, which is not encrypted by default and almost always subject to degradation attacks (the MITM can claim not to support STARTTLS). In any case, the user cannot verify or demand that STARTTLS be used and many hosts don't support it at all. Meanwhile, PGP does not require any trust of intermediate entities, but relatively few people you might want to email have PGP keys and even those with keys might not have them on the device from which they intend to read your email. S/MIME is in a similar position to PGP, with a CAs trust model instead of Web of Trust.

Re: You have a moral obligation to use crypto

#48
post #27

The title certainly makes an emotional appeal to me. However I could not find justification/explanation of any moral obligation in the text. I could understand a moral obligation to fight unjust surveillance, but that is not what was presented. Why am I morally obligated to increase the cost of surveillance? If society accepts the unjust surveillance the only consequences of increasing surveillance costs are economic…

It will become, if it is not already, a practical obligation. Why should anyone in the rest of the world trust American products that enable "justified" surveillance?

I am not really sure what any of your comment means and/or why you directed it to me? Is the practical obligation the same thing as financial incentive? And what does "enable 'justified' surveillance" mean? Existing in the world enables surveillance. I have no problem with just and legal surveillance, my problem is with unjust surveillance.

Re: You have a moral obligation to use crypto

#49
post #46

Earlier quoted context omitted.

Do you think most people are constructing their morality on top of some fundamental beliefs? (I tend to think we work backwards trying to come up with compact descriptions of what we are comfortable with...)

Yes. I can not imagine any other conception of moral obligation. How would you come up with an obligation to do X or not do Y without an underlying belief structure?

I was asking about the second half of the sentence.

(But to answer your question in terms of what I am getting at, you would work backwards from what you were comfortable with and then tell yourself that it was your underlying belief structure, whether that were meaningfully true or not)

Re: You have a moral obligation to use crypto

#50
post #13

Earlier quoted context omitted.

Moxie introduced http://www.convergence.io/ a while ago now ( https://www.youtube.com/watch?v=8N4sb-SEpcg ), which could offer significant advantages over the PKI if it became widely adopted. Although it's not an end-all solution to identity, it's a step in the right direction (using web-of-trust ideas).

So convergence.io is only available over HTTP, yet it offers the plugin for download. It seems an ironically bad practice to install security software over an untrusted connection. Meanwhile, https://convergence.io yields a certificate for whispersystems.org and is in fact the https://whispersystems.org/ main page (nothing to do with convergence.io). There appears to be no secure way to obtain Moxie's plugin (it is n…

I'm not sure what would be more ironic, this, or it delivering a "secure" download over the protocol it intends to replace for not providing sufficient security guarantees. The other irony is that a self-signed cert is basically as good as any CA issued cert with Convergence on, if only there were a secure way to bootstrap it. Perhaps a secure way to obtain it would be to email Moxie using GPG and ask him to send you a copy, but as you suggest, it appears to be unmaintained aside from the fork anyway, so it isn't much more than research material for now. I hadn't heard of Tack yet, but that also appears to have a lack of activity.
Post reply on HN