Live data from Hacker News

Silent Circle raises $30M, moves to Switzerland

telecompaper.com

21–30 of 46 posts

Re: Silent Circle raises $30M, moves to Switzerland

#21
post #15
post #11

Earlier quoted context omitted.

I think the point is that silent circle is secured by policy, not by technology. The validity of their security assertions only extend as far as you trust their word.

It's hard for anything but policy to protect against denial of service (legal attacks against the company). Even if you have technical security which prevents compromise of data, they can shut the business down. CALEA means you are actually prevented from building/operating some kinds of privacy tech within the US (PSTN voice without wiretaps for sure, and PSTN-interconnected VOIP is a gray area; a mobile-focused VPN…

I didn't know Tor, Bittorrent and Bitcoin use laws to protect themselves from DoS.

Re: Silent Circle raises $30M, moves to Switzerland

#23

I wonder how much longer Switzerland can cash in on their national brand for security and privacy. Their largest banks can't even keep their customers' accounts safe from foreign tax investigators. Why would I trust the integrity of my data there?

> Their largest banks can't even keep their customers' accounts safe from foreign tax investigators. Your knowledge is outdated. The US and (to a lesser extent) the EU forced the Swiss banks to hand over all relevant data. All. Moreover, they have to pay a stiff fine ( http://dealbook.nytimes.com/2014/05/19/credit-suisse-set-to-... ). Remember Switzerland is a small country and not member of the EU. They have no choi…

>Your knowledge is outdated.

In what way? I'm aware of the Credit Suisse conviction from this week. That case just reinforces my point that Swiss banks are unable to keep their customers' accounts safe from foreign tax officials.

Re: Silent Circle raises $30M, moves to Switzerland

#24
post #3

I wonder how much longer Switzerland can cash in on their national brand for security and privacy. Their largest banks can't even keep their customers' accounts safe from foreign tax investigators. Why would I trust the integrity of my data there?

I think you are confusing substantiated, well supported, warrants/subpoenas/etc and tax collaboration agreements, with arbitrary user requests, gag orders, mass surveillance, etc. The two are at opposite spectrums.

When implementing technology intended to provide user privacy, both fall under "attack on user privacy", and should be treated as such. Either the service has access to user data, in which case it can be arbitrarily compromised for reasons of varying "legitimacy", or the service does not have access to user data, in which case the legitimacy of the request is irrelevant.

Re: Silent Circle raises $30M, moves to Switzerland

#26
post #3

I wonder how much longer Switzerland can cash in on their national brand for security and privacy. Their largest banks can't even keep their customers' accounts safe from foreign tax investigators. Why would I trust the integrity of my data there?

I think you are confusing substantiated, well supported, warrants/subpoenas/etc and tax collaboration agreements, with arbitrary user requests, gag orders, mass surveillance, etc. The two are at opposite spectrums.

Who do you differentiate "substantiated, well supported" warrants from those that are not?

Do you accept all warrants from the US? All warrants from Russia? All warrants from Syria or Iran?

Re: Silent Circle raises $30M, moves to Switzerland

#27

Earlier quoted context omitted.

You realize the developer of PGP and the technical cofounder of Silent Circle are the same person, right? Bittorrent isn't really a great example either... How long do you think The Pirate Bay would last hosted in the US?

Pirate bay is not Bittorrent. Bittorrent, Tor and Bitcoin are all services. But they are not centralized in hands of one person who needs to live in CH. They are distributed among thousands of small nodes which makes the entire service truly reliable. Also: each user stores the keys to his destiny vs. giving them to a single trusted party.

Silent Circle's services are designed to be 'untrusted.' Keys never leave the client. Feel free to build the client yourself, the code's on GitHub (the android clients are currently a bit easier to build than the iOS versions... ).

Re: Silent Circle raises $30M, moves to Switzerland

#28
post #3

Earlier quoted context omitted.

I think you are confusing substantiated, well supported, warrants/subpoenas/etc and tax collaboration agreements, with arbitrary user requests, gag orders, mass surveillance, etc. The two are at opposite spectrums.

When implementing technology intended to provide user privacy, both fall under "attack on user privacy", and should be treated as such. Either the service has access to user data, in which case it can be arbitrarily compromised for reasons of varying "legitimacy", or the service does not have access to user data, in which case the legitimacy of the request is irrelevant.

Unless the courts ask you to modify your software to access the user data next time they login (iirc, this was the case with bit mail).

Re: Silent Circle raises $30M, moves to Switzerland

#29
post #15

Earlier quoted context omitted.

It's hard for anything but policy to protect against denial of service (legal attacks against the company). Even if you have technical security which prevents compromise of data, they can shut the business down. CALEA means you are actually prevented from building/operating some kinds of privacy tech within the US (PSTN voice without wiretaps for sure, and PSTN-interconnected VOIP is a gray area; a mobile-focused VPN…

I didn't know Tor, Bittorrent and Bitcoin use laws to protect themselves from DoS.

They do in that the organizations involved clearly dissociate themselves from running critical operational infrastructure, or getting involved with the potentially-illegal activities enabled by their tools.

If Tor Project ran a large number of Tor nodes directly, they'd be open to very simple legal attacks.

Re: Silent Circle raises $30M, moves to Switzerland

#30
post #3

I wonder how much longer Switzerland can cash in on their national brand for security and privacy. Their largest banks can't even keep their customers' accounts safe from foreign tax investigators. Why would I trust the integrity of my data there?

I think you are confusing substantiated, well supported, warrants/subpoenas/etc and tax collaboration agreements, with arbitrary user requests, gag orders, mass surveillance, etc. The two are at opposite spectrums.

Parallel construction
Post reply on HN