Live data from Hacker News

Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

techcrunch.com

91–100 of 124 posts

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#91
Once again, I would like to recommend Tahoe-LAFS [0] (which anyone can install on their own on their servers or use the paid service from the creators of Tahoe-LAFS [1]). One can even store "shares" securely on Google Drive and Dropbox though it is a bit involved.

[0] http://tahoe-lafs.org/

[1] https://leastauthority.com/

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#92
I can't agree with his logic here :

"When you say, ‘I have nothing to hide,’ you’re saying, ‘I don’t care about this right.’"

How does he arrive at that conclusion? I have nothing to hide, but I still don't support the violation of these rights. Does he suggest that we instead support some other service or method under the illusion that we are immune from NSA spying?

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#93

Earlier quoted context omitted.

"The data is also collected and stored and processed by algorithms without any court oversight." This is false. PRISM doesn't get any data that wasn't specifically requested with a court order. It sounds like your understanding is still based on Greenwald's original reporting, which has since been shown to be inaccurate.

Director James Clapper of the NSA testified before congress that the NSA was not collecting any information on American Citizen. He was outright lying when he said that. [1] I would be interesting in how you know PRISM does not "collect" information for further "review" later? [1] http://www.washingtonpost.com/blogs/the-switch/wp/2014/01/27...

Minor nitpick, but I keep seeing people get this wrong: James Clapper is the Director of National Intelligence. He has previously served as the director of the National Geospatial Intelligence Agency and the Defense Intelligence Agency. He has never been the director of the NSA.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#94

"Even with that encryption, he said law enforcement officials can still ask for warrants that will give them complete access to a suspect’s phone, which will include the key to the encrypted data." What, pray tell, is the mechanism by which the key will be obtained? Snowden is bloviating here.

If a key is stored on your phone, it can be obtained the same way any other data is obtained. If the key is password protected, a key logger would yield the password. Edit: I forgot to check to whom I replied; "lern_to_spel" shows up on all of the Snowden threads.

The key is not stored in the clear, and the device password is entered before a keylogger can run. https://www.eff.org/deeplinks/2014/10/even-golden-key-can-be...

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#95
post #91

Once again, I would like to recommend Tahoe-LAFS [0] (which anyone can install on their own on their servers or use the paid service from the creators of Tahoe-LAFS [1]). One can even store "shares" securely on Google Drive and Dropbox though it is a bit involved. [0] http://tahoe-lafs.org/ [1] https://leastauthority.com/

More importantly, you can host the storage over i2p, or a hybrid of clearnet and darknet. There's even an implement ion of free net over i2p using tahoe-lafs.

I have assisted a few people in implementing this for their storage needs. No complaints, either.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#96
post #45

Earlier quoted context omitted.

> A social network Diaspora* > and a search engine DuckDuckGo

Are they not compromised or more likely easily compromised considering they don't even have the resources to secure and legally fight against government interferences?

Well, Diaspora* is open source and decentralized(somewhat anyway), so I think it would probably be difficult to compromise the majority of it. I'm not sure though. I suppose if a subtle error was submitted in a pull request(?)?

I suppose that any single pod could be compromised fairly easily, and some of the larger pods have a large number/portion of users, so just compromising some of the larger pods could be sufficient.

Also, iirc, Diaspora* has been said to have some security and privacy concerns,

But I thought it would be good to mention that there isn't really a single "Disapora*" which can be told to give up all the data for all users, because different users use different pods. (And I think a collection of pods can be somewhat isolated from the rest maybe? I'm not sure.)

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#97

I use DropBox and Google Drive a lot, but I have scripts to encrypt data into ZIP files for anything that needs to be protected. It really is not much of a hassle. I have a SpiderOak account, but don't use it as often. Speaking of protecting data: I am surprised at how many companies seem to keep their software in private repositories on github and bitbucket. That seems like a security hole, if software if the core o…

When I started using DropBox, I made an encrypted directory (using EncFS) for the stuff I cared about keeping private. This keeps the real-time sync element of DropBox, and avoids needing to reupload all of the encrypted files whenever one changes (although it does prevent incremental updates on individual files). As an added bonus, these files are now encrypted on my machine as well.

EncFS, as you may be aware, only encrypts the contents of the files. The metadata (filename, size, timestamps) is available in clear, and a lot could be inferred from metadata if you don't want to trust others who could access the raw bits.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#98
post #91

Once again, I would like to recommend Tahoe-LAFS [0] (which anyone can install on their own on their servers or use the paid service from the creators of Tahoe-LAFS [1]). One can even store "shares" securely on Google Drive and Dropbox though it is a bit involved. [0] http://tahoe-lafs.org/ [1] https://leastauthority.com/

Premise: I'm not interested in setting up a server and maintaining it, but I am interested in storing my data on services that can promise, or even better, guarantee, privacy and security.

I have looked at Tahoe-LAFS for a few years now, along with the paid service. In my observations over the last few years, the paid service is getting almost zero attention from the creators. Initially they had it at an enormous cost (like $1 per GB per month) compared to other competitors. In the recent times it has moved to other schemes that are still expensive for many people ($25 per month).

Their products, or rather services, are rarely updated and remain in the TBA (to be announced) status for far too long while other competitors (the "privacy conscious" ones like SpiderOak that cannot truly guarantee it like Tahoe-LAFS can as well as the "what's privacy?" services like Dropbox, Crashplan, Box, Google, Microsoft and Apple, to name just a few) are moving ahead much faster and bringing down prices.

I'm willing to pay a decent enough premium to help privacy guaranteeing services survive and thrive, but this kind of pricing and sluggishness in introducing services from leastauthority.com makes it seem like they don't really want many users to sign up.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#99
post #4

http://www.dbms2.com/2014/09/15/misconceptions-about-privacy... While I'm a huge Snowden fan, he's a bit wrong at times about encryption, in that it solves a smaller part of the problem than he sometimes suggests.

Dropbox was revealed as a participant of the PRISM program: anything you store there is searchable. The same is true of Facebook and Google and Yahoo, Apple, all cell phone carriers, all internet carriers and other cloud storage companies including Skydrive/Onedrive.

What's worse with Dropbox is that it deduplicates data across users. So it's really easy for someone who "needs to know" (like the NSA) as well as people who "would like to know" to "takedown" a single user for something and identify every other Dropbox user who has the same content.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#100
post #78

Earlier quoted context omitted.

Tech companies can't give up what they've never had, and tech companies choose whether or not they'll store user data centrally. Here's one for your list: http://syncthing.net/

>>tech companies choose whether or not they'll store user data centrally ...until the USgov/NSA chooses for them. Also, while it's all great the Syncthing tool is open source I see that they have precompiled binaries. Now I ask you, what percentage of people will compile themselves instead of downloading the readily available binary? Especially Windows users? In short, syncthing isn't immune to the USgov/NSA. We're t…

> ...until the USgov/NSA chooses for them.

Local binaries can be -- and are -- audited. The USgov can't simply push new code (and this is why web-style pushed upgrades are a bad thing).

> Me and the person I replied were talking about "services"(tech companies), not stand-alone tools.

Goalpost movement. Services that control both client and server, and all the data involved in it, CAN NOT solve this problem; this is why we have (and need more of) well-defined protocols with more than one client and server implementation thereof.

SaaS, with their plethora of proprietary protocols, are the antithesis of privacy rights and a vibrant open internet ecosystem.

Post reply on HN