Live data from Hacker News

The Criminal N.S.A.

nytimes.com

101–110 of 116 posts

Re: The Criminal N.S.A.

#101
post #69
post #12

Earlier quoted context omitted.

> If you want opinion as news, I refer you to Fox News or Buzzfeed or Upworthy. All "news" is someone's, or a group of someones, opinion. There's no such thing as objective journalism. > chicken little reddit-level bullshit It's only been a couple of weeks since people became aware that the largest spy agency in the world is spying on pretty much anything they can get a bead on. Perhaps cutting people some slack unti…

Nobody is claiming all news is objective. I also think that the constant claims about 'msm' 'ignoring' important stories is annoying, incorrect and in fact distracting from the proper discussion to be had. There is in fact a very distinct difference between opinion articles and 'proper' news articles. You see, journalism is not a claim to objective truth, but a procedure aimed at achieving a minimum level of validity…

> I also think that the constant claims about 'msm' 'ignoring' important stories is annoying, incorrect and in fact distracting from the proper discussion to be had.

You're welcome to your opinion.

Re: The Criminal N.S.A.

#102
post #99

Earlier quoted context omitted.

We don't know for certain that several governments have archived stored copies of all cloud based email in existence, it's hazy as to what they do and do not have access to, what isn't hazy is that they have the right to demand the content of any given gmail account with effectively zero recourse available. The very fact that they actually do make these demands indicates on balance of probability, they don't actually…

While I agree with the sentiments, Google most likely does not delete the unencrypted mail, so even if the government hasn't stored the content of the mail they will just request copies of all your deleted mail too. Certainly going forward it would be a good thing to do, but really (as you say) end to end encryption is required. It's a shame Hushmail was compromised [1], this is the type of thing if it was built into…

once again on the "most likely" front, it's possible, sure, but according to their own statements, they do actually delete it when you delete it;

http://www.smartplanet.com/blog/thinking-tech/does-8220delet...

http://productforums.google.com/forum/#!topic/gmail/QZh2Ce75...

Note response; Unfortunately, once you have permanently deleted a message from Trash or Spam using "Delete forever," it cannot be recovered. Google complies with data privacy legislation. As a result, our systems are configured in a way that it is infeasible to restore user-deleted data.

Sure, they could be lying, but they could also be telling the truth, and if we assume they are then there is an advantage in keeping a fully encrypted store rather than plaintext. Google has given us no reason to believe that they are directly untrustworthy unless they are actively compelled by law to act in user hostile fashion, and they do not seem to enjoy it.

Personally I'm far more concerned about the state as a hostile entity than Google.

> With the smart phones being SUCH an integrated part of our lives now, this also makes it VERY difficult to keep your email with you on the go since the mailvelope plugin is only desktop based.

I make reference to this on the project page, there's APG which is PGP for android, makes reading / writing / signing PGP possible on mobile http://www.thialfihar.org/projects/apg/.

> Shame. We have the tools, I hope we get better integration soon.

I hope the same, I kind of see this as pushing the issue, we'll see where it goes.

Re: The Criminal N.S.A.

#103

Earlier quoted context omitted.

That's why I did this; https://github.com/etherael/phoneme It's not perfect, but I think the first step to widespread crypto adoption is getting people accustomed to the workflow of fully encrypted email. Phoneme + mailvelope is not a huge jump from the current gmail experience and just that initial taste might be enough to get more people on the right track.

Is that supposed to be read as "phone me" or "phoneme"?

http://en.wikipedia.org/wiki/Phoneme

Re: The Criminal N.S.A.

#104
post #68

Earlier quoted context omitted.

Governments can still gather the metadata of encrypted emails. Both PGP and S/MIME do not encrypt the subject line, sender or recipient addresses. To use encrypted email and hide the subject line, you need to not use it (just say "Encrypted email") or something. This cannot be made automatic without impacting UX. The To: header fundamentally cannot be removed. The sender can be inferred from the account within the em…

> Governments can still gather the metadata of encrypted emails. True, but don't throw out the baby with the bathwater right away. I know metadata is at least as sensitive as the actual content, but you need to pick your battles. If we get people to widely use GPG to encrypt the content of their emails, that is already a huge win. Why? Because they're now using a public/private key infrastructure. And as you are prob…

> I know metadata is at least as sensitive as the actual content, but you need to pick your battles.

So, picking the metadata battle:

Its straightforward from the command line to email crypto-content to your desired addressee while emailing(spamming?) to a few more auto-generated others. These newly(if functional) spammed others would value your contact, as it provides them with a participating valid email account, so `spamee' can now also `shotgun' emails to more addressees further obfuscating his intended addressee(s). If this became popular, universal, The graph of all our email metadata (nodes?) becomes chaotic.

The timestamp metadata? Send to subset random sampled addressees over set random offset ranges.

The SUBJECT: header could be automated to filter through all this new junkmail.

What else, hmmmmnnn...

Re: The Criminal N.S.A.

#105

Earlier quoted context omitted.

We don't know for certain that several governments have archived stored copies of all cloud based email in existence, it's hazy as to what they do and do not have access to, what isn't hazy is that they have the right to demand the content of any given gmail account with effectively zero recourse available. The very fact that they actually do make these demands indicates on balance of probability, they don't actually…

I was hoping someone far more talented than me would write a browser plugin that would encrypt everything I type in a TEXTAREA with GPG, and then prompt me for a list of friends I'd like to have read that text. Everything, from Facebook to Gmail, would be encrypted that way. And I would be in control of the list of people that could read that text.

Just a small quibble, if you're typing in the textarea the website or any other extensions you have in your browser could spy on the plaintext as it is being typed. A secure browser extension would have to call an external program, let you type and encrypt your message in there, and then deposit the encrypted message back into the textarea.

Re: The Criminal N.S.A.

#106
post #99

Earlier quoted context omitted.

While I agree with the sentiments, Google most likely does not delete the unencrypted mail, so even if the government hasn't stored the content of the mail they will just request copies of all your deleted mail too. Certainly going forward it would be a good thing to do, but really (as you say) end to end encryption is required. It's a shame Hushmail was compromised [1], this is the type of thing if it was built into…

once again on the "most likely" front, it's possible, sure, but according to their own statements, they do actually delete it when you delete it; http://www.smartplanet.com/blog/thinking-tech/does-8220delet... http://productforums.google.com/forum/#!topic/gmail/QZh2Ce75... Note response; Unfortunately, once you have permanently deleted a message from Trash or Spam using "Delete forever," it cannot be recovered. Googl…

Ok, let's err on the side of Google for now (although, still not sure I can fully trust them, esp with all this news).

Still, great work and thanks for the additional info. Here's to hoping one day EVERYTHING will be encrypted by default!

Re: The Criminal N.S.A.

#107

Earlier quoted context omitted.

I'm not all that sure it is unconstitutional, for one thing - aren't you begging the question here? And on a more general level, shouldn't you be considering precedent on justiciability, rather than basing your whole argument on your personal opinion of the waht the constitution means? I might note in asssing that I favor a constitutional amendment that would create an explicit right to privacy; I'm not in favor of a…

>I'm not all that sure it is unconstitutional And you know who the perfect people to decide that would be? Judges. In a court of law. Since that's one of their main job functions.

As I have pointed out numerous times over the last few weeks, my belief is that they made that determination in 1979, in Smith v Maryland.

Re: The Criminal N.S.A.

#108

Earlier quoted context omitted.

I'm not all that sure it is unconstitutional, for one thing - aren't you begging the question here? And on a more general level, shouldn't you be considering precedent on justiciability, rather than basing your whole argument on your personal opinion of the waht the constitution means? I might note in asssing that I favor a constitutional amendment that would create an explicit right to privacy; I'm not in favor of a…

Please explain to me how a "constitutional amendment creating an explicit right to privacy" would do fuck all if the only body that assesses constitutionality won't allow us to complain when that right is breached.

You're allowed to complain, but they may not agree that your complaint has any merit. You don't seem like the sort of person who's into changing their mind though, so I don't really know what to tell you. You could try checking out some books on Constitutional law from the library to get a better understanding of how this works.

Re: The Criminal N.S.A.

#109
post #46

Earlier quoted context omitted.

Read Smith v. Maryland and get back to me. The issue of standing is more complex, and lies along a philosophical fault line about the role of the judiciary; I refer you to this law review article for an overview of those issues: http://scholarship.law.berkeley.edu/cgi/viewcontent.cgi?arti...

For call metadata, the pen register comparison might fly. If they are storing content, as is likely, it won't. The beginning of the article on standing does raise questions I hadn't thought about. How would you decide the penalty for something with the potential for abuse? Just because the NSA is storing the largest ever collection of personal info with potential for blackmail, election skullduggery, stalking, identi…

I'm thinking of the metadata, yes. I'm not convinced yet about the content allegations, and I suspect (but have not researched) that the point if illegality is when people start listening to them without a warrant rather than when they're merely stored.

Re: The Criminal N.S.A.

#110
post #59

The public is not acquiescing in surveillance. It is simply rare for the mainstream media to report on this critically (or at all -- note the lack of front-page coverage of this story in the New York Times), an appalling development given the extension of this surveillance apparatus to targeting journalists. With that in mind, it is worth noting that the two authors of this piece are NOT professional journalists, alt…

> note the lack of front-page coverage of this story in the New York Times NYT front page on June 20, 22, 24, 25, 26 -- five out of the past 7 days. Plus a front page mention on June 23. I know you don't mean your comment literally, but I think there's been a lot of coverage. There's some criticism that the stories of late tend to focus more on Snowden, but his part of the story is the only thing that's had material…

Thanks for the check. I was actually looking at the online version, and checking the prominent stories. I agree that the where-is-Snowden story is getting some coverage, but even there the selection and tone of the materials support the administration.

Does the lack of new information from the US government mean that there are no new "material developments" in the story? Considering the damaging revelations in these leaks (misleading congressional testimony? private contractors with access to dragnet surveillance systems?), it is not plausible to claim there is no investigative journalism to do. That it has taken two outsiders to write a piece sensibly critical of the administration and unconstitutionality of data-vacuuming is utterly damning.

Post reply on HN