Live data from Hacker News

COMSEC: Beyond Encryption [pdf]

grugq.github.io

31–40 of 54 posts

Re: COMSEC: Beyond Encryption [pdf]

#31

FWIW this is the talk that got them (Ben Nagy and The Grugq) thrown out of Kiwicon ( http://kiwicon.org/ ) for being transphobic, sexist and otherwise disrespectful to women and trans people. See http://geekfeminism.wikia.com/wiki/Kiwicon_2014_expulsion IMO it was justified, but guess you had to be there.

"A transgender Mongolian in the desert"? Is this really so gravely offensive?

Re: COMSEC: Beyond Encryption [pdf]

#32
post #14
post #13

According to the Pond docs: > What a global, passive adversary (one who can observe all Internet traffic) can achieve: > A GPA can learn who is using Pond and where their home servers are located. It's probably a great piece of software, but how exactly does it fit into the theme of cover over concealment? At its current level of popularity, simply using Pond, without a proxy at least, paints a giant target on you in…

Pond works through Tor, and Pond servers are hidden services. I consider that using Tor makes me a target, so I go through at least three VPN services.

Would have been better that you hadn't mentioned using tor then hmm?

Re: COMSEC: Beyond Encryption [pdf]

#33
post #7

Earlier quoted context omitted.

The ad-lib appears to be included in the provided PDF.

Hmm, "ad-lib" -- given that slide, what did they plan to say? Anyway, it's interesting to me that the pics of mostly-naked men and ASCII Goatse hardly get mentioned, overshadowed by a verbal remark. Maybe the con has changed its policy in response, but did they preview the slide deck?

Apparently they got in trouble for the ASCII Goatse too.

Re: COMSEC: Beyond Encryption [pdf]

#34

FWIW this is the talk that got them (Ben Nagy and The Grugq) thrown out of Kiwicon ( http://kiwicon.org/ ) for being transphobic, sexist and otherwise disrespectful to women and trans people. See http://geekfeminism.wikia.com/wiki/Kiwicon_2014_expulsion IMO it was justified, but guess you had to be there.

>FWIW this is the talk that got them (Ben Nagy and The Grugq) thrown out of Kiwicon

See, fuck this. We are all fucked if style begins to trump substance in infosec, like it has in most everything else. Fucking marketing turds. The Grugq is dropping pearls before swine.

Re: COMSEC: Beyond Encryption [pdf]

#35
post #31

FWIW this is the talk that got them (Ben Nagy and The Grugq) thrown out of Kiwicon ( http://kiwicon.org/ ) for being transphobic, sexist and otherwise disrespectful to women and trans people. See http://geekfeminism.wikia.com/wiki/Kiwicon_2014_expulsion IMO it was justified, but guess you had to be there.

"A transgender Mongolian in the desert"? Is this really so gravely offensive?

It is if you're an overly sensitive SJW twat. Otherwise, no. It isn't insulting to desert-dwelling transgendered Mongolians, just a humorous ad lib pulled from the speaker's memory based on something they happened to have read recently.

Re: COMSEC: Beyond Encryption [pdf]

#36
post #31

FWIW this is the talk that got them (Ben Nagy and The Grugq) thrown out of Kiwicon ( http://kiwicon.org/ ) for being transphobic, sexist and otherwise disrespectful to women and trans people. See http://geekfeminism.wikia.com/wiki/Kiwicon_2014_expulsion IMO it was justified, but guess you had to be there.

"A transgender Mongolian in the desert"? Is this really so gravely offensive?

I asked a friend and she gave me this explanation:

"It's not compassionate to remind transgender people that they're a minority that often has trouble "passing" and face extreme violence bc of that...if you were a trans woman in the audience who'd been beat up for not being able to pass as cis, how would it make you feel to have that treated like a joke"

Seems reasonable. I retract my previous comment.

Re: COMSEC: Beyond Encryption [pdf]

#37
I'm genuinely surprised to see Linux being dismissed as laughably insecure. I'd like to learn more -- particularly given that the main criticism is that the defaults are so bad. Does anyone know which distribution/kernel is being referred to?

Up until now, I'd thought of distributions like TAILS as offering excellent defaults, while providing good compartmentalization. I remember reading that Laura Poitras, Glenn Greenwald and Bruce Schneier all made use of TAILS when reading leaked NSA documents.

Re: COMSEC: Beyond Encryption [pdf]

#38

I'm genuinely surprised to see Linux being dismissed as laughably insecure. I'd like to learn more -- particularly given that the main criticism is that the defaults are so bad. Does anyone know which distribution/kernel is being referred to? Up until now, I'd thought of distributions like TAILS as offering excellent defaults, while providing good compartmentalization. I remember reading that Laura Poitras, Glenn Gre…

Among other reasons, the outright refusal of the Linux kernel developers (and Linus himself) to consider implementing the grsecurity patches have rendered it somewhat of a joke to the blackhats I know.

Re: COMSEC: Beyond Encryption [pdf]

#39
post #30
post #19

Earlier quoted context omitted.

I don't get why he says "VPN connection to TOR => GOTOJAIL". How is it OK that your ISP sees you connecting to Tor, but dangerous if your VPN provider does? Or is this about some other issue?

Yes, hard to understand why he says that, maybe he meant TOR connection to VPN?

He says that Tor to VPN is OK, as long as you buy the VPN service anonymously. So I don't think that there's semantic confusion. Also, there is a clear downside to tunneling VPNs through Tor, in that it prevents circuit switching, which increases vulnerability to deanonymization.

Re: COMSEC: Beyond Encryption [pdf]

#40
post #14

Earlier quoted context omitted.

Pond works through Tor, and Pond servers are hidden services. I consider that using Tor makes me a target, so I go through at least three VPN services.

Would have been better that you hadn't mentioned using tor then hmm?

Maybe I'm lying ;)
Post reply on HN