Live data from Hacker News

Pervasive Monitoring Is an Attack

tbray.org

11–20 of 29 posts

Re: Pervasive Monitoring Is an Attack

#11
post #10

> if your ap­pli­ca­tion doesn’t sup­port pri­va­cy, that’s prob­a­bly a bug in your ap­pli­ca­tion. Amateur radio is explicitly not for traffic that needs to remain private. It exists for limited purposes not including routine communication that can be served by other means (e.g. a phone or ordinary internet connection). It is chiefly for education and research/experimentation in radio. It is not for general persona…

I was confused by the ham radio line. How does ham radio have anything to do with internet protocols? Are they worried about TCP/IP over packet radio? Seems like a very fringe concern.

Internet protocols have been used by ham radio operators for decades. 44/8 was allocated to amateur packet radio in the 1970s. And as I alluded to in my comment, the same WiFi you probably used to post your comment is also frequently used under Part 97 (amateur radio) rules.

Re: Pervasive Monitoring Is an Attack

#12
post #10

> if your ap­pli­ca­tion doesn’t sup­port pri­va­cy, that’s prob­a­bly a bug in your ap­pli­ca­tion. Amateur radio is explicitly not for traffic that needs to remain private. It exists for limited purposes not including routine communication that can be served by other means (e.g. a phone or ordinary internet connection). It is chiefly for education and research/experimentation in radio. It is not for general persona…

I was confused by the ham radio line. How does ham radio have anything to do with internet protocols? Are they worried about TCP/IP over packet radio? Seems like a very fringe concern.

Yes, some hams have been saying "please don't encrypt all Internet protocols because then I wouldn't be able to enjoy my hobby of running those protocols over ham radio", which seems incredibly selfish.

Re: Pervasive Monitoring Is an Attack

#13
post #12
post #10

Earlier quoted context omitted.

I was confused by the ham radio line. How does ham radio have anything to do with internet protocols? Are they worried about TCP/IP over packet radio? Seems like a very fringe concern.

Yes, some hams have been saying "please don't encrypt all Internet protocols because then I wouldn't be able to enjoy my hobby of running those protocols over ham radio", which seems incredibly selfish.

It'll be easy enough to run vintage protocols (like unencrypted HTTP or IP) over amateur radio, and bridge them to secure protocols on the other end. Amateur radio links just won't be able to route end-to-end-encrypted traffic, and that doesn't seem like a severe limitation. From what I've seen, amateur radio links typically form the last hop in the chain between a base station and a remote endpoint, so just terminate the end-to-end connection at the base station and transmit unencrypted to the endpoint.

Re: Pervasive Monitoring Is an Attack

#14
post #3

This is a good formal step. The time it took from 'common knowledge' to a formal proposal makes me a little worried. If the IETF isn't really a "council of wise folks" then in the long term, doesn't their effectiveness get eroded?

Standards bodies are, by necessity, slower-moving than those developing the works they standardize, It's remarkable that they successfully agreed upon a statement like this at all, let alone this quickly. As stated in the article, they had to deal with blatantly broken objections that ought to have been easy to dismiss; I'd be curious how the actual standardization effort managed to achieve rough consensus amid those objections.

Re: Pervasive Monitoring Is an Attack

#15

> if your ap­pli­ca­tion doesn’t sup­port pri­va­cy, that’s prob­a­bly a bug in your ap­pli­ca­tion. Amateur radio is explicitly not for traffic that needs to remain private. It exists for limited purposes not including routine communication that can be served by other means (e.g. a phone or ordinary internet connection). It is chiefly for education and research/experimentation in radio. It is not for general persona…

IANAL. The ham radio community needs to raise this with the FCC. This section was originally constructed a long time ago (1993?). I'm guessing it's biased this way to stop 1940's era spys from operating.

Re: Pervasive Monitoring Is an Attack

#16
post #12
post #10

Earlier quoted context omitted.

I was confused by the ham radio line. How does ham radio have anything to do with internet protocols? Are they worried about TCP/IP over packet radio? Seems like a very fringe concern.

Yes, some hams have been saying "please don't encrypt all Internet protocols because then I wouldn't be able to enjoy my hobby of running those protocols over ham radio", which seems incredibly selfish.

If they've said "please don't encrypt", they're making a much broader request than is necessary to comply.

The only thing we really need is for a protocol to have some way for us to transmit a callsign in cleartext (otherwise there would have to be a break in data exchange every ~10 minutes for transmission of a callsign unencrypted). On WiFi this gets accomplished by setting the SSID to our callsign.

The actual data could be encrypted, but we would have to record (and arguably publish) any keys (including session keys) used in the process.

Re: Pervasive Monitoring Is an Attack

#17

TFA says "PM is an attack ... and this is a consensus of the IETF". On the other hand, IETF continues to employ NSA employees (like Kevin Igoe, a co-chair of Crypto Research Group under IETF[1] ). So: is it a consensus or not? Does Mr. Igoe consider PM an "attack", even though his own employer does it? I'm having trouble reconciling the two. [1] http://article.gmane.org/gmane.ietf.irtf.cfrg/2337

> I'm having trouble reconciling the two.

Why? It's extremely common for industry/standardization groups like the IETF to come to conclusions that are contrary to the position of one of its members, and it usually doesn't result in said member being expelled or falling on their sword.

Re: Pervasive Monitoring Is an Attack

#18

> if your ap­pli­ca­tion doesn’t sup­port pri­va­cy, that’s prob­a­bly a bug in your ap­pli­ca­tion. Amateur radio is explicitly not for traffic that needs to remain private. It exists for limited purposes not including routine communication that can be served by other means (e.g. a phone or ordinary internet connection). It is chiefly for education and research/experimentation in radio. It is not for general persona…

IANAL. The ham radio community needs to raise this with the FCC. This section was originally constructed a long time ago (1993?). I'm guessing it's biased this way to stop 1940's era spys from operating.

http://www.arrl.org/news/fcc-dismisses-encryption-petition

The amateur radio community is not universal in their dislike for this rule. I don't personally see any way in which the rule could be removed without altering the fundamental character of the amateur radio service.

You simply should not be making transmissions in the amateur radio service that require privacy. Permitting unrestricted encryption makes that basically impossible to enforce.

Re: Pervasive Monitoring Is an Attack

#19

TFA says "PM is an attack ... and this is a consensus of the IETF". On the other hand, IETF continues to employ NSA employees (like Kevin Igoe, a co-chair of Crypto Research Group under IETF[1] ). So: is it a consensus or not? Does Mr. Igoe consider PM an "attack", even though his own employer does it? I'm having trouble reconciling the two. [1] http://article.gmane.org/gmane.ietf.irtf.cfrg/2337

I thought he explained pretty clearly that this is not a unanimous opinion of the IETF, and that there are very vocal groups that oppose it. Firing the chair of a IETF crypto research group would have only given those groups more ammunition, and probably would have prevented this RFC from ever being published.

That said, the very fact that the RFC was published sends a very strong message to those contingents about the IETF's priorities, and I for one am very happy to hear it.

Re: Pervasive Monitoring Is an Attack

#20
post #9
post #6

Earlier quoted context omitted.

>>The time it took from 'common knowledge' to a formal proposal makes me a little worried. As anti-NSA, pro-snowden as I am (I proudly wear my Snowden t-shirts) ... I think it's important for formal steps to make sure they've filtered out the hype and not just react while the general public is on fire about the issue. Waiting about 6 months to a year after Snowden did his thing I think is fast enough. Gives folks eno…

I guess I kind of expect the IETF to be predictive, and not be pop-culture or mass-market/media driven. I guess ultimately though, that's the only way to go. We knew years before Snowden that something fishy was up, but it took the leaks to really make people care at a level that could facilitate change.

>I guess I kind of expect the IETF to be predictive, and not be pop-culture or mass-market/media driven.

But that's the GP's exact point: this wasn't a media-driven RFC -- if it had been driven by media, it would have been published last summer. As it stands now, the body has carefully deliberated on the facts and yet still published a very strongly-worded RFC.

This pro-Snowden programmer is pretty happy to see the IETF step forward and take on a leadership role here. Let's not forget that the IETF was founded by a consortium of US government agencies and only when private in the 1990s.

With this RFC, they are asserting their independence in a surprisingly direct manner (for a standards body).

Post reply on HN