Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
71–80 of 137 posts
Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#72The EFF is surprisingly absent from this coalition. The other organizations listed as participating are: The National Association of Criminal Defense Lawyers, Human Rights Watch, Amnesty International USA, Pen American Center, Global Fund for Women, The Nation Magazine, The Rutherford Institute, and Washington Office on Latin America. From: https://blog.wikimedia.org/2015/03/10/wikimedia-v-nsa/#cite_...
I wonder why they are not part of it? Maybe they are prepping to do something on their own. I'd like to see the NSA under fire from many opponents rather than just one.
As listed above, it's probably because they're already in the middle of their own[0] (assuming that they will appeal, which I'd imagine is almost certain assuming they can fund it).
The EFF has been fighting this battle long before the Snowden revelations, so it's certainly not for lack of interest that they're not a claimant in the Wikimedia case.
[0] https://www.eff.org/deeplinks/2015/02/jewel-v-nsa-making-sen...
Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#73The solution should be technical: You don't want to NSA to read your communications: encrypt them (eg: HTTPS everywhere, encryption built-in everywhere). And that's us, builders of technologies, that need to make that happen. Basically securing against the NSA is the same as securing against hackers, it should be treated as a security threat like any other.
Firstly - you compare securing against the NSA to securing against "hackers". This massively underestimates the reach and resources of the NSA (or any nation-state actor). You can, to a point, keep out all but the most determined and skilled individuals. You almost certainly cannot keep out the NSA if they really want to target you. Even a physical airgap may not be enough (see: stuxnet).
Your example mentioned HTTPS specifically - how does this help if they can force/compromise the host to give up their TLS keys and MiTM your connection?
Secondly - all this does is encrypt the contents of your communication - it doesn't hide who you are, it doesn't hide who you're talking to, and other metadata besides this (yes, I know metadata is at this point a painfully overused term - sadly I can't think of a good synonym right now). You significantly undervalue how important it is to hide this information from an adversary.
Right now, if a major nation state targets you specifically, you have almost no chance. You'd need perfect operational security to anonymise yourself, encryption that can't be broken by forcing a local entity to surrender the key, and to implement this every time without making a mistake. Some people have managed this, but not very many.
If you're just looking to avoid dragnet surveillance, you're in a bad place too. The information we have suggests that it's the metadata, not the content of the communications, that is stored - and very little of that is hidden by using HTTPS rather than HTTP.
None of that should suggest that HTTPS isn't worthwhile - it very much is. And there's little reason not use use HTTPS everywhere these days. But it won't on it's own protect you very much from the NSA - that's why court cases like this are being raised (though I doubt it'll achieve anything in practice).
Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#74Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#75The solution should be technical: You don't want to NSA to read your communications: encrypt them (eg: HTTPS everywhere, encryption built-in everywhere). And that's us, builders of technologies, that need to make that happen. Basically securing against the NSA is the same as securing against hackers, it should be treated as a security threat like any other.
Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#76The solution should be technical: You don't want to NSA to read your communications: encrypt them (eg: HTTPS everywhere, encryption built-in everywhere). And that's us, builders of technologies, that need to make that happen. Basically securing against the NSA is the same as securing against hackers, it should be treated as a security threat like any other.
HTTPS everywhere is a good start, but it it does a poor job of defending against the NSA. Certificate authorities are fundamentally broken and users don't have the background knowledge to understand certs or why they are necessary.
Even technical people don't understand this. The last time I saw a post about certificate authorities on hacker news, the top comment was about how most people don't want authentication, they just want encryption. You can't have encryption without authentication: unauthenticated encryption is fundamentally broken. But the user who posted the comment was ignorant of this, and enough other people were ignorant of this that they upvoted his comment to the top.
The solutions proposed also don't address the problem that popular centralized services are bound to be compromised. Even if you're sure you're connecting to Google or Facebook services over a secure connection, Google and Facebook are such high-value targets that they will be compromised by an entity with as much money as the NSA. The defense against this is also technical, but it requires a fundamental shift from centralized to decentralized technologies, and I don't think that's easy or at all ready.
> Basically securing against the NSA is the same as securing against hackers, it should be treated as a security threat like any other.
This drastically understates the attacking power of the NSA.
Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#77I have some sympathy for our fellow hackers who work as contractors or in big companies, many of them with security clearance. Database engineers, software developers, data experts - the five eyes intelligence agencies directly and indirectly fund many of you readers of HN. They might be becoming increasingly disillusioned with their chosen life and/or unable to change course. Perhaps the money is too good, perhaps t…
I have no problem voicing my beliefs publicly. I'm always more than willing to explain the policies of the NSA, and happy to denounce the actions of Edward Snowden. I don't think he was a traitor, by definition, but what he did was wrong. It isn't necessary to divulge confidential information, the situation is pretty clear. I don't see any point in re-litigating the whole thing on this particular thread though, it wo…
Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#78I hope that more organizations come forward with similar suits so that we can get back on the right path.
Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#79The solution should be technical: You don't want to NSA to read your communications: encrypt them (eg: HTTPS everywhere, encryption built-in everywhere). And that's us, builders of technologies, that need to make that happen. Basically securing against the NSA is the same as securing against hackers, it should be treated as a security threat like any other.
They're always going to have more resources until we rip up the roots they use-- government funding provided by a heavily-surveilled and terrified of blackmail political body.
Re: Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
#80Earlier quoted context omitted.
On NSA stories, the top HN comment is always "too bad. whatever. let the NSA do its thing." NO. This is not about you. This is not about your data. This is about our society's collective ability to think and act for itself. Blanket acceptance of surveillance is a dangerous attitude and shockingly common. Political efforts, technological efforts, societal changes are all required to keep democracy alive. And that's wh…
> This is not about you. This is not about your data Democracy means that your fellow citizens get a vote too. If you and those that agree with you can't craft a message that appeals to them and their day-to-day concerns, the grandparent comment will continue to be quite correct.
The citizens never asked for this intrusion and would likely have resisted if they had been, so it was executed in secret, and would have remained a complete secret if not for Snowden.
Nobody has even tried to "craft a message that appeals to the public" until AFTER the fact, when their overreach had been exposed.
A democracy generally works by citizens' issue A going to politicians B and being passed after debate to agency C which effects action D; in our situation currently the NSA has decided that it is in the best interest of itself to effect surveillance. It isn't democracy in action no matter how you attempt to spin it.