Live data from Hacker News

SecureDrop

ssl.washingtonpost.com

11–20 of 99 posts

Re: SecureDrop

#11
post #10

Wow, Tor is still a thing? We have confirmation that security agencies have taken over exit nodes and injected spyware before to track targets. I'm surprised anyone uses it. It's like the security lottery.

Exit nodes are irrelevant for hidden services like WaPo's SecureDrop, the connection never leaves the Tor network.

Re: SecureDrop

#12

Sometime in the near future, I predict that the US will require some form of photo I.D before using an internet kiosk. As usual, the spin will be to protect the children.

South Korea has pretty much already implemented this with the majority of its major websites requiring their SSN equivalent to register.

http://en.wikipedia.org/wiki/Resident_registration_number

Re: SecureDrop

#13

Sometime in the near future, I predict that the US will require some form of photo I.D before using an internet kiosk. As usual, the spin will be to protect the children.

There's always McDonald's, except, you are probably on camera.

Re: SecureDrop

#16
Does anyone know what the codenames are like? If they are easy enough to remember, then they may be easy enough to brute-force?

I think this is a great concept, yet perhaps too little, too late (Journalists should know PGP and drop boxes like these should have been common already). I also worry a bit because of Washington Post's track record with leaks, of the top of my head:

- Washington Post was Snowden's first choice, but they put up enough demands for Snowden to move to The Guardian. [1]

- Washington Post, according to Assange, had access to the "Collateral Murder" video a whole year before WikiLeaks published their edited video. [2]

- Washington Post employs op-ed columnists that call for assassination of "criminally dangerous" leakers like Assange [3]

[1] http://nymag.com/daily/intelligencer/2013/06/nsa-leaker-shop... [2] http://www.abc.net.au/foreign/content/2010/s3040234.htm [3] http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

EDIT: More information on SecureDrop: https://pressfreedomfoundation.org/securedrop and source here: https://github.com/freedomofpress/securedrop

Re: SecureDrop

#17
post #10

Wow, Tor is still a thing? We have confirmation that security agencies have taken over exit nodes and injected spyware before to track targets. I'm surprised anyone uses it. It's like the security lottery.

The NSA leaks reveal that for the most part, Tor is still secure if you're using a sufficient number of intermediary nodes.

If anything, the real concern here is the implicit encouragement to use local library computers, which would be much easier for a government agency (or cybercriminal) to infect with malware and observe.

Re: SecureDrop

#18

Sometime in the near future, I predict that the US will require some form of photo I.D before using an internet kiosk. As usual, the spin will be to protect the children.

Fortunately, they can't do that for all the open/WEP/WPS wireless APs everywhere.

They've done a pretty good job of scaring people into securing their APs (which is also a legitimate thing in most cases); just publishing some stories about people having ISP service cut off due to freeloaders doing bad stuff would probably be enough; wouldn't even need to try to prosecute some.

Re: SecureDrop

#19

Does anyone know what the codenames are like? If they are easy enough to remember, then they may be easy enough to brute-force? I think this is a great concept, yet perhaps too little, too late (Journalists should know PGP and drop boxes like these should have been common already). I also worry a bit because of Washington Post's track record with leaks, of the top of my head: - Washington Post was Snowden's first cho…

Your codename seems to be a collection of random words, the number of which you get to specify.

Re: SecureDrop

#20
post #10

Wow, Tor is still a thing? We have confirmation that security agencies have taken over exit nodes and injected spyware before to track targets. I'm surprised anyone uses it. It's like the security lottery.

[deleted]
Post reply on HN