Live data from Hacker News

Looking Back at the Snowden Revelations

blog.cryptographyengineering.com

101–110 of 244 posts

Re: Looking Back at the Snowden Revelations

#101
There are two problems - surveillance itself and the lack of democratic oversight and control.

Most people would agree that the state should be able to deprive people of their liberty ( prison ), but that stringent controls should be in place, with that process being public and involve peers ( though that is being slowly undermined in the west ).

What are the controls around surveillance? What processes stop abuse? Who is accountable? Where is the transparency?

You could argue that you can't be public about intent to spy, but there is a lot more that could be done.

https://www.theguardian.com/news/defence-and-security-blog/2...

Re: Looking Back at the Snowden Revelations

#102

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

I wouldn't say I don't care. I would say I permanently trust government less, as I do feel mostly powerless to make them less nosey. If I have an opportunity to vote against mass surveillance, I will do that for sure.

Re: Looking Back at the Snowden Revelations

#103
post #37

Earlier quoted context omitted.

Actually, nothing changed Some Laws was created. Some revelations was made. But even manipulations with elections did not kill any company

Let's Encrypt brought TLS to the masses, browsers are bringing focus to sites still not using transport encryption, https is a signal for Google ranking. Don't be so defeatist.

That had nothing to do with Snowden and everything to do with Firesheep. I remember people panicking when Firesheep came out, and that lead to the whole "we should all be using TLS" thing.

Re: Looking Back at the Snowden Revelations

#104
post #71

Earlier quoted context omitted.

One of the most interesting revelations was the security agencies apparent spying on members of Congress. But it’s like nothing happened. No investigation, no nothing. If they can’t be bothered by that, it’s little surprise they’re not bothered by their spying on regular folk.

That should tell us who is really in charge.

Yes, the American people, who can't be bothered to care enough to do anything about it.

Re: Looking Back at the Snowden Revelations

#105

Earlier quoted context omitted.

The protocol they use is open and very reliable, and it can be verified relatively easily from the outside that this is the protocol they're using. If you enable backups in WhatsApp those backups aren't stored on Facebook's servers, but they are probably not encrypted very well, since you don't enter your own encryption key, and WhatsApp has to be able to decrypt those backups if you lose your device. So those probab…

Or in other words, quoting James Mickens: > My point is that security people need to get their priorities straight. The "threat model" section of a security paper resembles the script for a telenovela that was written by a paranoid schizophrenic: there are elaborate narratives and grand conspiracy theories, and there are heroes and villains with fantastic (yet oddly constrained) powers that necessitate a grinding bat…

And yet, Snowden is out of the reach of the US govt (for now).

Re: Looking Back at the Snowden Revelations

#106
post #37

Earlier quoted context omitted.

Actually, nothing changed Some Laws was created. Some revelations was made. But even manipulations with elections did not kill any company

Let's Encrypt brought TLS to the masses, browsers are bringing focus to sites still not using transport encryption, https is a signal for Google ranking. Don't be so defeatist.

I always assumed Let's Encrypt was an NSA front so that they can decrypt most of the https traffic.

Remember just after the Snowden revelations all the 3 letter agencies were very worried about https adoption rising, then their concerns suddenly disappeared.

However I have no idea how encryption works so maybe my hunch is stupid (I remember that the NSA impersonated a certificate authority for that purpose).

Re: Looking Back at the Snowden Revelations

#107
The article mentions MUSCULAR, but neglected the follow-up: shortly after the leaks, Google began encrypting all of its internal traffic over its own fiber links.[0]

First, it's worth pointing out that "encrypt everything in flight always" is not prohibitively expensive on modern hardware; also that your own internal network should not be viewed as an impenetrable bastion where you can let down your guard, just because you keep a close eye on the external routers.

[0] https://www.washingtonpost.com/business/technology/google-en...

Re: Looking Back at the Snowden Revelations

#108

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

>Now everyone knows it’s true, but still nobody seems to care…

That just about sums up every bad act.

Lots of people were aware of all the bank fraud and toxic loans leading to the 2008 real estate bubble, no one cared leading up to it, and no one cares now.

The Googles/Facebooks/amazons are collecting and doing unsavory things with your data, whether you ever used their services or not (shadow accounts), no one seems to care.

Governmental spying on citizens? Hell the Government had a program which included secret kill lists, flew military bombers into foreign countries to drop bombs and kill a citizen. Even when the US failed to kill the citizen and the family sued, their case was dismissed as the courts denied any right to know who was on the list, how they got on the list, and even denied acknowledging the list existed...yet no one cared.

Imagine a foreign country flying military missions in the US and dropping bombs on a foreigner in the US, based on the foreign governments secret kill lists. It's pure insanity.

Re: Looking Back at the Snowden Revelations

#109
post #74

Earlier quoted context omitted.

Given that it was built by a highly trusted cryptography team, plus the fact that the protocol can be reverse engineered to confirm encryption and decryption on device, and that over-the-wire traffic has no plaintext, the trust in this is indeed very high. WA has a lot to lose, and big enough target on it for a backdoor to have been found, if E2E is false.

Apparently anilgulecha is, like many, unaware that WhatsApp is no longer end-to-end encrypted. It technically trivial to tap the traffic between decrypting and re-encrypting stages, and the only plausible reason for the very expensive change was to enable such access.

Looking at WhatsApp's website [1], instead of saying "your messages are definitely end-to-end encrypted at all times" they say it's "available", as in this sentence:

> WhatsApp's end-to-end encryption is available when you and the people you message use our app.

Is that what you're referring to?

[1] https://www.whatsapp.com/security/

Re: Looking Back at the Snowden Revelations

#110
post #91

Earlier quoted context omitted.

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

Certain Richard M Stallman faced a similar problem when he talked about DRMed content a decade ago.

More like two decades ago.

https://www.gnu.org/philosophy/right-to-read.en.html

Post reply on HN