Live data from Hacker News

Snowden Meets the IETF

mnot.net

11–20 of 80 posts

Re: Snowden Meets the IETF

#11
post #2

It must have been an exciting surprise for attendees. I'm glad Snowden said DNS should be encrypted. From the tweet stream provided by @conflictmedia, that was tied for 1st for most re-tweeted, along with making the Internet for users, not spies. (It should be noted that DNSSEC is not encrypted.) Too bad his appearance wasn't recorded, but HUGE thanks to Niels ten Oever and Rich Salz for tweeting major points!

> I'm glad Snowden said DNS should be encrypted. You know, it's funny because just last week, I chatted with a friend of mine in the UK giving me some pretty crazy rundown of DNS issues he was having. I found out that BT (UK's leading ISP) hijacks DNS for parental control purposes (read: pornblock). More info here: https://thecomputerperson.wordpress.com/2015/02/18/bts-netwo... It boggles my mind actual major ISPs ge…

This is by law in the UK. A 2014 amendment to the 2003 Communications Act forces ISPs to do this. Blame the government, not the ISPs.

edit because HN won't let me post a rebuttal to the reply below:

Private corporations can be compelled and coerced by the government in other ways that aren't readily publicized. If you think these companies enjoy wasting resources on porn filter then you're crazy. Wikipedia:

"Prime Minister David Cameron made it clear in July 2013 that his aim was to ensure that by the end of 2013 all ISPs would have a filtering system in place.[13] As a result three of the four major ISPs (TalkTalk, Sky and BT[14]) began applying default filtering to new customers in 2013[15] with the fourth major ISP, Virgin, doing so in February 2014.[16] Default filtering of existing customers was implemented by all four major ISPs during 2014 with the aim of ensuring that the system applied to 95% of all households by the end of the year.[17][18]"

This timing isn't a big coincidence. Elect a better PM (or indirectly elect considering this is the UK) if you don't want such shenanigans.

Re: Snowden Meets the IETF

#12
post #4
post #3

The more I consider the ramifications of these news reports, the more I realize we need full decentralization and total encryption. We have the tech: Strong encryption, Tor-like relays, and the blockchain. What we need is a way to make services based on these technologies not just as easy to use but easier to use for the average Jane. If the internet as we know it is to survive, we have to crack this nut.

More security, more usability. Pick one. That is why we are in the mess we are in

When Skype was secure, was it usable?

Re: Snowden Meets the IETF

#13

Earlier quoted context omitted.

> I'm glad Snowden said DNS should be encrypted. You know, it's funny because just last week, I chatted with a friend of mine in the UK giving me some pretty crazy rundown of DNS issues he was having. I found out that BT (UK's leading ISP) hijacks DNS for parental control purposes (read: pornblock). More info here: https://thecomputerperson.wordpress.com/2015/02/18/bts-netwo... It boggles my mind actual major ISPs ge…

This is by law in the UK. A 2014 amendment to the 2003 Communications Act forces ISPs to do this. Blame the government, not the ISPs. edit because HN won't let me post a rebuttal to the reply below: Private corporations can be compelled and coerced by the government in other ways that aren't readily publicized. If you think these companies enjoy wasting resources on porn filter then you're crazy. Wikipedia: "Prime Mi…

1. Porn filtering is not law in the UK, that is a common misconception. It was merely encouraged by the government, but ISPs are not forced to offer it. The ISPs absolutely are the ones to blame.

2. DNS hijacking certainly is not mandated by law.

Edit: Here is a post by Adrian Kennard, CEO of Andrews & Arnold ISP in the UK, regarding porn filters:

http://www.revk.uk/2014/02/porn-filters-no-it-is-not-law.htm...

Re: Snowden Meets the IETF

#14
post #5
post #4

Earlier quoted context omitted.

More security, more usability. Pick one. That is why we are in the mess we are in

I refuse to believe we cannot have both.

>I refuse to believe we cannot have both.

Define security. Not too long ago it was considered "rude" to have a not world-readable home directory on a unix server.

Today, "everyone" is worried about SIGINT by nation states. Meanwhile, there's little talk about things that can actually protect you from criminals like why is code written so shittily in general and why aren't we using a Rust-like solution for internet facing applications? Why is AV useless and unable to stop well-known malware like cryptocker variants? Why are my desktop/cloud files unencrypted by default? Why phishing scammers are constantly emailing me with realistic looking fake sites? Why doesn't Microsoft have a solution to the "download invoice.pdf.exe" problem?

Yes, Obama reading my "maymays" is bothersome, but that's not what my grandma needs. She needs a better way to get online and not get infected, her identity stolen, etc. So, who gets to define priorities here? You? I'd rather lean towards protecting Grandma's than geeks obsessed with the NSA's data collection program. Morally, I see the former as more important. That's my bias and its as valid as yours. If we can't agree then who can?

Re: Snowden Meets the IETF

#15
post #5

Earlier quoted context omitted.

I refuse to believe we cannot have both.

>I refuse to believe we cannot have both. Define security. Not too long ago it was considered "rude" to have a not world-readable home directory on a unix server. Today, "everyone" is worried about SIGINT by nation states. Meanwhile, there's little talk about things that can actually protect you from criminals like why is code written so shittily in general and why aren't we using a Rust-like solution for internet fa…

> Yes, Obama reading my "maymays" is bothersome, but that's not what my grandma needs.

Grandma needs a phone. A lot of those problems are implicitly disappearing as a majority of tech-illiterate users are moving to mobile platforms, which are far more locked down.

> So, who gets to define priorities here? You?

Those that work on it? Why isn't that obvious? Steps towards fixing either problems are good, so those that work on them get to work on whatever the hell they want, really.

Re: Snowden Meets the IETF

#16
post #8
post #5

Earlier quoted context omitted.

I refuse to believe we cannot have both.

Security must, by its very nature, prevent you from doing insecure things. This manifests as an obstacle to users, so they end up choosing the insecure route (writing down passwords etc etc). Decentralised systems tend to lose to centralised ones because there's no money locus for advertising, development or curation. It's not totally doomed; the popularity of Snapchat suggests there is demand for services that don't…

Blockchain-based decentralization looks somewhat easier to monetize.

Re: Snowden Meets the IETF

#17

Earlier quoted context omitted.

> I'm glad Snowden said DNS should be encrypted. You know, it's funny because just last week, I chatted with a friend of mine in the UK giving me some pretty crazy rundown of DNS issues he was having. I found out that BT (UK's leading ISP) hijacks DNS for parental control purposes (read: pornblock). More info here: https://thecomputerperson.wordpress.com/2015/02/18/bts-netwo... It boggles my mind actual major ISPs ge…

This is by law in the UK. A 2014 amendment to the 2003 Communications Act forces ISPs to do this. Blame the government, not the ISPs. edit because HN won't let me post a rebuttal to the reply below: Private corporations can be compelled and coerced by the government in other ways that aren't readily publicized. If you think these companies enjoy wasting resources on porn filter then you're crazy. Wikipedia: "Prime Mi…

Separate reply to your edit. [btw, you can click the timestamp in my comment if you are not presented with a reply link]

> If you think these companies enjoy wasting resources on porn filter then you're crazy

I don't know who's misleading you but BT offered parental controls, including adult content filtering, long before the 2013 governmental push. All they did was turn it on by default (it was off by default, before).

And none of this excuses hijacking DNS to offer parental controls. There are far better technical ways to achieve that.

And by the way, I don't live in the UK anymore and I don't like what you're implying with who I may or may not be voting for. I left when it got shit. Voted with my feet.

Re: Snowden Meets the IETF

#18
post #8
post #5

Earlier quoted context omitted.

I refuse to believe we cannot have both.

Security must, by its very nature, prevent you from doing insecure things. This manifests as an obstacle to users, so they end up choosing the insecure route (writing down passwords etc etc). Decentralised systems tend to lose to centralised ones because there's no money locus for advertising, development or curation. It's not totally doomed; the popularity of Snapchat suggests there is demand for services that don't…

> Security must, by its very nature, prevent you from doing insecure things.

Disagree. In practice security as a guarantee must do so (e.g. the OpenBSD opinion), but security as a gradient need not (e.g. the web opinion).

If Browser X defaults to the TLS version of a page regardless of what the user requested, but gracefully falls back to the unsecured page without action but with a yellow banner across the URL, does this not increase user security without preventing them from doing insecure things?

The objective is not perfect security but rather increased herd security.

If the minimum security threshold (specifically with respect to encryption) is raised, then we all benefit. Decentralized vs centralized and the feasibility of each are an argument for farther down the road (as long as we don't lock ourselves into one or the other). There's much lower-hanging fruit!

Re: Snowden Meets the IETF

#19
post #2

It must have been an exciting surprise for attendees. I'm glad Snowden said DNS should be encrypted. From the tweet stream provided by @conflictmedia, that was tied for 1st for most re-tweeted, along with making the Internet for users, not spies. (It should be noted that DNSSEC is not encrypted.) Too bad his appearance wasn't recorded, but HUGE thanks to Niels ten Oever and Rich Salz for tweeting major points!

> I'm glad Snowden said DNS should be encrypted.

And yet, when HBO screwed up their dnssec config and Comcast blocked the site, how did users react? By demanding Comcast stop verifying!

(Fully encrypted DNS can only fail in even more ways than dnssec.)

Re: Snowden Meets the IETF

#20
post #3

The more I consider the ramifications of these news reports, the more I realize we need full decentralization and total encryption. We have the tech: Strong encryption, Tor-like relays, and the blockchain. What we need is a way to make services based on these technologies not just as easy to use but easier to use for the average Jane. If the internet as we know it is to survive, we have to crack this nut.

That's necessary, but not sufficient. We need both sane policies and technical measures to ensure that nothing less than those policies is possible. If we only have the technology, policy-makers can and will make life difficult both for the users and makers of these technologies; more draconian regimes will simply never allow those technologies to take root to begin with.
Post reply on HN