Live data from Hacker News

Snowden Meets the IETF

mnot.net

21–30 of 80 posts

Re: Snowden Meets the IETF

#21
post #8
post #5

Earlier quoted context omitted.

I refuse to believe we cannot have both.

Security must, by its very nature, prevent you from doing insecure things. This manifests as an obstacle to users, so they end up choosing the insecure route (writing down passwords etc etc). Decentralised systems tend to lose to centralised ones because there's no money locus for advertising, development or curation. It's not totally doomed; the popularity of Snapchat suggests there is demand for services that don't…

Writing down passwords is not insecure.

Better to have a written down strong password than an easy to remember password not written down.

Re: Snowden Meets the IETF

#22

Earlier quoted context omitted.

This is by law in the UK. A 2014 amendment to the 2003 Communications Act forces ISPs to do this. Blame the government, not the ISPs. edit because HN won't let me post a rebuttal to the reply below: Private corporations can be compelled and coerced by the government in other ways that aren't readily publicized. If you think these companies enjoy wasting resources on porn filter then you're crazy. Wikipedia: "Prime Mi…

1. Porn filtering is not law in the UK, that is a common misconception. It was merely encouraged by the government, but ISPs are not forced to offer it. The ISPs absolutely are the ones to blame. 2. DNS hijacking certainly is not mandated by law. Edit: Here is a post by Adrian Kennard, CEO of Andrews & Arnold ISP in the UK, regarding porn filters: http://www.revk.uk/2014/02/porn-filters-no-it-is-not-law.htm...

Confusingly, there are three filters. The "adult material" one is optional. The torrents sites one https://wiki.openrightsgroup.org/wiki/Website_blocking and the IWF child porn one are not.

Re: Snowden Meets the IETF

#23
post #5
post #4

Earlier quoted context omitted.

More security, more usability. Pick one. That is why we are in the mess we are in

I refuse to believe we cannot have both.

Total security is not having a computer, or having it off all the time. So in the limit, they must interfere. What you're saying is you refuse to believe we cannot have an acceptable compromise. That I think is reasonable.

Re: Snowden Meets the IETF

#24
post #8
post #5

Earlier quoted context omitted.

I refuse to believe we cannot have both.

Security must, by its very nature, prevent you from doing insecure things. This manifests as an obstacle to users, so they end up choosing the insecure route (writing down passwords etc etc). Decentralised systems tend to lose to centralised ones because there's no money locus for advertising, development or curation. It's not totally doomed; the popularity of Snapchat suggests there is demand for services that don't…

This conflates "security" in the sense of requirements and "security" in the sense of technology. Users already have security requirements; security technology ought to be enabling them.

For instance, encryption lets me back up files to cloud services that I don't trust. Without the technology of encryption, my security requirement would have me not backing up files at all. I wouldn't just decide "oh, whatever" and back up unencrypted files.

SSL lets me access my bank safely (enough) from a coffeeshop wifi connection. Without SSL, I'd walk into a physical bank or ATM. I wouldn't decide "probably nobody's trying to hack me" and connect to my bank in cleartext.

Bad technologies manifest as an obstacle to users, yes. But passwords are pretty much the epitome of bad technology in the security field. (It's a legitimately hard problem, so I'm not claiming that people should be doing other things, but we also shouldn't let ourselves think that passwords are good.)

SSL, for all that the implementation sucked and still sucks, enabled the e-commerce revolution of the mid-'90s.

Re: Snowden Meets the IETF

#25
post #22

Earlier quoted context omitted.

1. Porn filtering is not law in the UK, that is a common misconception. It was merely encouraged by the government, but ISPs are not forced to offer it. The ISPs absolutely are the ones to blame. 2. DNS hijacking certainly is not mandated by law. Edit: Here is a post by Adrian Kennard, CEO of Andrews & Arnold ISP in the UK, regarding porn filters: http://www.revk.uk/2014/02/porn-filters-no-it-is-not-law.htm...

Confusingly, there are three filters. The "adult material" one is optional. The torrents sites one https://wiki.openrightsgroup.org/wiki/Website_blocking and the IWF child porn one are not.

Yes, that's correct. They shouldn't be confused though, IWF has been there for much longer.

Re: Snowden Meets the IETF

#26
post #5
post #4

Earlier quoted context omitted.

More security, more usability. Pick one. That is why we are in the mess we are in

I refuse to believe we cannot have both.

Not sure if you've ever heard of Bruce Schneier, but he is regarded by many as the father of modern cryptography. He also happens to know a thing or two about security, and frequently testifies to the US government such as the Senate on cybersecurity related matters.

Here are a few of his thoughts on the matter:

https://www.schneier.com/blog/archives/2009/02/balancing_sec...

https://www.schneier.com/blog/archives/2009/08/security_vs_u...

https://www.schneier.com/blog/archives/2009/09/unauthenticat...

Schenier's own words: """ Designing systems for usability is hard, especially when security is involved. Almost by definition, making something secure makes it less usable. """

Feel free to disagree with one of the leading experts in the field, but I doubt you'll end up right.

Re: Snowden Meets the IETF

#27
post #3

The more I consider the ramifications of these news reports, the more I realize we need full decentralization and total encryption. We have the tech: Strong encryption, Tor-like relays, and the blockchain. What we need is a way to make services based on these technologies not just as easy to use but easier to use for the average Jane. If the internet as we know it is to survive, we have to crack this nut.

That's necessary, but not sufficient. We need both sane policies and technical measures to ensure that nothing less than those policies is possible. If we only have the technology, policy-makers can and will make life difficult both for the users and makers of these technologies; more draconian regimes will simply never allow those technologies to take root to begin with.

I think this needs to be expressed more often. Not only will draconian regimes now allow it, but it's also harder to protect such systems at the ends. I saw a presentation by cperciva at some point that talked about the "Three B's": Bribery, Burglary and Blackmail. So tech should be one of many tools to combat oppressive societal structure - some other ones being more social and legal tools.

Re: Snowden Meets the IETF

#28
post #24
post #8

Earlier quoted context omitted.

Security must, by its very nature, prevent you from doing insecure things. This manifests as an obstacle to users, so they end up choosing the insecure route (writing down passwords etc etc). Decentralised systems tend to lose to centralised ones because there's no money locus for advertising, development or curation. It's not totally doomed; the popularity of Snapchat suggests there is demand for services that don't…

This conflates "security" in the sense of requirements and "security" in the sense of technology. Users already have security requirements; security technology ought to be enabling them. For instance, encryption lets me back up files to cloud services that I don't trust. Without the technology of encryption, my security requirement would have me not backing up files at all. I wouldn't just decide "oh, whatever" and b…

>encryption lets me back up files to cloud services that I don't trust

Any recommendation on an accessible, audited, client for Windows users? Running some company's random binary, especially when you log in and they can identify you, implies a fair amount of trust. Tarsnap's the best one I know of and it's not really accessible for most users.

Re: Snowden Meets the IETF

#29

Earlier quoted context omitted.

This is by law in the UK. A 2014 amendment to the 2003 Communications Act forces ISPs to do this. Blame the government, not the ISPs. edit because HN won't let me post a rebuttal to the reply below: Private corporations can be compelled and coerced by the government in other ways that aren't readily publicized. If you think these companies enjoy wasting resources on porn filter then you're crazy. Wikipedia: "Prime Mi…

1. Porn filtering is not law in the UK, that is a common misconception. It was merely encouraged by the government, but ISPs are not forced to offer it. The ISPs absolutely are the ones to blame. 2. DNS hijacking certainly is not mandated by law. Edit: Here is a post by Adrian Kennard, CEO of Andrews & Arnold ISP in the UK, regarding porn filters: http://www.revk.uk/2014/02/porn-filters-no-it-is-not-law.htm...

> It was merely encouraged by the government,

Not unlike in Pulp Fiction, Jules "encouraging" Brett not to say "what" again.

> DNS hijacking certainly is not mandated by law.

As others have said already, unfortunately it is, just not for adult filtering.

Re: Snowden Meets the IETF

#30
post #29

Earlier quoted context omitted.

1. Porn filtering is not law in the UK, that is a common misconception. It was merely encouraged by the government, but ISPs are not forced to offer it. The ISPs absolutely are the ones to blame. 2. DNS hijacking certainly is not mandated by law. Edit: Here is a post by Adrian Kennard, CEO of Andrews & Arnold ISP in the UK, regarding porn filters: http://www.revk.uk/2014/02/porn-filters-no-it-is-not-law.htm...

> It was merely encouraged by the government, Not unlike in Pulp Fiction, Jules "encouraging" Brett not to say "what" again. > DNS hijacking certainly is not mandated by law. As others have said already, unfortunately it is, just not for adult filtering.

Or like the piracy alert system in the US, which the White House "only mediated" and the ISPs' "volunteered".
Post reply on HN