Live data from Hacker News

SecureDrop Protocol

securedrop.org

11–16 of 16 posts

Re: SecureDrop Protocol

#11
They say don't roll your own encryption protocol (if something similar or same already exists and it's maintained), but these guys just can't resist.

Using a secure decentralized messenger to share a download (or upload) location on a Hidden S3 Service or one of those decentralized S3 services can't possibly be worse than this.

To commenter in https://news.ycombinator.com/item?id=40289777: BitMessage doesn't solve anything, it uses broadcast and Bitcoin peer nodes that first get the message know where it came from. And BitMessage is not an illegal content hazard of any kind (what a ridiculous statement!).

Re: SecureDrop Protocol

#13
post #7

Earlier quoted context omitted.

They can just use Tor and HTTP upload. This protocol is more theoretical than practical. No protocol helps when you have to testify in court.

What makes you say this?

In Australia you can be sentenced for up to 5 years for refusing to testify (in a secret hearing you can't tell anyone about). 2 years for refusing to give encryption keys. In general one should not rely on a protocol to protect you if someone comes at you with a wrench.

Re: SecureDrop Protocol

#14

Earlier quoted context omitted.

What makes you say this?

In Australia you can be sentenced for up to 5 years for refusing to testify (in a secret hearing you can't tell anyone about). 2 years for refusing to give encryption keys. In general one should not rely on a protocol to protect you if someone comes at you with a wrench.

> if someone comes at you with a wrench

relevant xkcd: https://xkcd.com/538/

Post reply on HN