Live data from Hacker News

It’s Time to Encrypt the Entire Internet

wired.com

61–70 of 99 posts

Re: It’s Time to Encrypt the Entire Internet

#61
post #26

Earlier quoted context omitted.

> It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). This is how the internet is designed, and you can already do this today. In my case, I host my own dns, email, and my own webpages, locally on my home connection. You just have to be willing to…

Why would you need your own DNS?

To avoid DNS censorship, my ISP filters pirate bay, plenty of other sites.

Re: It’s Time to Encrypt the Entire Internet

#62
post #10

It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). The current situation is akin to having to travel to some centralized letter-reading facility in order to read letter mail. Your grandma sends you a letter in the mail and you have to go to a cent…

I think it's time to stop cooking up technology solutions to political problems. It's a lazy hack and a distraction. The counter-parties that encryption will supposedly neutralize are commercial entities doing monitoring for advertising (or other purposes) and government surveillance. Commercial entities have all sorts of ways to collect said information (ie. by compelling you to opt-in in exchange for services). The…

I think it's time to stop cooking up technology solutions to political problems. It's a lazy hack and a distraction.

I very much agree with this philosophy in general, but when government and corporate interests are fighting their political battles with tech by designing software to exploit you, there is no option but to push back on multiple fronts.

Re: It’s Time to Encrypt the Entire Internet

#66
post #42
post #37

Earlier quoted context omitted.

> Maybe someone will come along and create a super easy to install and low maintenance server platform. There is a developer release available already: https://freedomboxfoundation.org/ All packages are included in Debian Sid.

My mom can't install that herself, and wouldn't be able to find information on how to do it by browsing the freedombox website. It's so obvious that the current freedombox website is targeted at computer geeks only and not general people. It is not 'super easy to install' if it's not granny-proved.

Your mom could plug in a ready-to-go Freedombox device that was installed with all that software already.

Re: It’s Time to Encrypt the Entire Internet

#68
post #64

Earlier quoted context omitted.

To avoid DNS censorship, my ISP filters pirate bay, plenty of other sites.

You could just use Google's 8.8.8.8 and 8.8.4.4 though.

Plenty of people don't want to send all of their DNS requests to Google.

Re: It’s Time to Encrypt the Entire Internet

#69
post #26

Earlier quoted context omitted.

> It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). This is how the internet is designed, and you can already do this today. In my case, I host my own dns, email, and my own webpages, locally on my home connection. You just have to be willing to…

Why would you need your own DNS?

In addition to the other replies, which are also good reasons, remember that dns poisoning is a real thing. While running unbound[1] to check DNSSEC signatures HAS discovered invalid results, and you can bypass some (but not all[2]) of those problems if you bypass the bad (ISP/whatever) resolver.

There really isn't much of a performance hit by recursively resolving DNS - it all gets cached anyway.

[1] http://unbound.net/ (other servers may also work for this purpose)

[2] It protects against a resolver that lies, but race conditions (e.g. NSA/QUANTUM) are not affected. Hopefully, DNSSEC itself protects against poisoned results, regardless of the method.

Re: It’s Time to Encrypt the Entire Internet

#70
post #5

So perhaps this should start with a reduction in the cost of valid, "don't throw a security warning" certificates down to zero. At the moment the SSL certificate industry is one big ripoff fest...

You mean like https://www.startssl.com/ ? Their standard certificates are accepted by all major browsers released since 2010 (see http://en.wikipedia.org/wiki/Startssl#Trustedness ) and are free for non-commercial use (I've heard claim of trouble with Windows Phone 7 devices but I've not had opportunity to check that myself). http://www.cacert.org/ is another option, but their CA cert is generally trusted by default…

You mean the one with a terrible user interface who charge 25$ to regenerate a cert?

PKI is a scam and a racket.

Post reply on HN