Live data from Hacker News

Forced Exposure

groklaw.net

101–110 of 430 posts

Re: Forced Exposure

#101
post #50

Earlier quoted context omitted.

No, I mean protocols. While elsewhere in the comments, there is the sentiment that "you can't code yourself out of this", my hopes of voting myself out of it (or otherwise "fixing" a system, as if it was just accidentally "broken") are much lower. (But note that "protocols" may also have non-technological components.)

Its a subject I keep an eye on, e.g. freenet and off-the-record messaging. I think these systems cannot work :( If you can make a system that is immune to traffic analysis - http://williamedwardscoder.tumblr.com/post/54088903127/onion... is my own blog but I'm about to shoot it down - then you basically have an open router and the spam abuse that implies. Any reasonably anonymous system will collapse under the weight…

Its not as though we don't have a spam problem already…

Freshly pulled-out-of-the-air suggestion – anonymous but requiring micro-payments. Say, 500 or 1000 satoshi (around a tenth of a cent) per message delivered – not as a means of generating revenue, but as a way to destroy email's current "if I only get one sale per 100,000 emails I send, that just means I need to send 10,000,000 emails a day to get my desired 100sale/day" vulnerability - if that actually cost the spammer $10,000/day, it just wouldn't happen.

('course that required having hard currency to bitcoin exchanges easy enough for the general public to use, and scalable enough to service a significant proportion of internet-using people)

Re: Forced Exposure

#103
post #5

Lets not try to code our way out of this. We succumb to terror pushing away meaningless bits of code on Github as a crypto projects in response. Some projects flourish sure but the same forces that profit off the court-less killings of others are collating your data, your pet projects. Harvesting your stolen info out of botnets. Giving you a salary for technician work keeping infrastructure ticking. Enough enabling t…

That's nice to say. Get angry, be outraged. But what do we do , day-to-day, while things are still a mess? How do you organize a revolution under the noses of the people you're revolting against? The code still has a purpose, even if it's not the "right" solution, long-term.

"I don't have to tell you things are bad. Everybody knows things are bad."

I've taught more people about the Web Of Trust and how to use GPG in the last ~1.5 months than in the last ~1.5 decades.

"...and we sit watching our TV's while some local newscaster tells us that today we had fifteen homicides and sixty-three violent crimes, as if that's the way it's supposed to be."

Something about this current drama has made the whole concept of encryption and the realities of surveillance suddenly resonate with a LOT more people. It's not a majority yet, of course, but a change in perception this dramatic is a amazing.

"We sit in the house, and slowly the world we are living in is getting smaller, and all we say is, 'Please, at least leave us alone in our living rooms.'"

I have people emailing me encrypted email now, who just last year ignored the idea with the usual dismissal of it being "unnecessary" or "too complicated"[1].

"Well, I'm not going to leave you alone. I don't want you to protest. I don't want you riot. I don't want to write to your congressman because I wouldn't know what to tell your to write."

So now that people are finally noticing the reality they live in, and are finally getting mad, I see this as what educators call a "teachable moment" to try and suggest a few broader concepts tan the gpg lessons they are asking for.

"I'm as MAD AS HELL, and I'm NOT going to take this anymore!"

A few things I've been trying to teach recently, now that there are actually people listening:

* General education on the concept of data mining, and the power of a handful of JOIN clauses. The idea of grabbing all your phone calls is something most people already understand. Connecting a few random bits of entropy together to get a surprisingly reliable primary key is still not widely understood.

* Web Of Trust - Starting small and local is good, just like in elections. It would be amazing if somehow the Key Signing Party could be worked into some traditional social ritual.

* Stop supporting the feudal model of email, by tying your identity to an @company.com domain. Land is king IRL, and staking your claim on the internet is important for similar reasons. It would be nice if everybody could change their MX records and hosting service as easily as they change POTS long distance providers.

* Stop using webmail - many of the benefits of encryption are lost if you don't keep the keys in your physical possession, as demonstrated by lavabit and elsewhere.

This doesn't directly fix the problem[2], but it is stuff that can be done (and is being done) now, and these are certainly things that would help immediate problems faced when organizing a revolution. The NSA doesn't have the manpower or money to strong-arm their snooping routers into every last-mile endpoint. This kind of long-term cutting of the data the NSA can see is one of the better weapons we have against them.

"Then we'll figure out what to do about the depression and the inflation and the oil crisis. But first get up out of your chairs, open the window, stick your head out, and yell..."[3]

[1] You would think a Biology professor would understand an argument about how this isn't necessary about them, but about maintaining the "herd immunity" of the email ecosystem...

[2]: It might in the long run, once a lot more software support is written, and it finally becomes possible for regular people to extend their web of trust as far as, e.g. groklaw.

[3]: Incidentally, the lecture at the end of Network comes to mind every time the government panics about Snowden: "...and YOU have meddled with the primal forces of nature, and YOU...WIIL...ATONE!"

edit; formatting

Re: Forced Exposure

#104

Earlier quoted context omitted.

> Dell? A computer hardware device assembler? What on earth are you on about. You appear to think that the entire info-tech infrastructure, companies and "wage-slaves" alike are complicit in all this. "Former intelligence contractor Edward Snowden began downloading documents describing the U.S. government's electronic spying programs while he was working for Dell Inc in April 2012, almost a year earlier than previous…

That's a completely new one on me. I seem to stand corrected on the Dell issue (could someone expand on this?) -- but I still think you are casting your net a bit wide. I apologize for the heaping pile of denigration as you call it but maybe tone it down a bit and take the time to show (and link) in more detail why you are saying what you are saying, ok?

The time for toning it down has passed.

Re: Forced Exposure

#105
post #85

Holy crap. Groklaw? I'd never for one second thought that the fall out from the NSA debacle would reach so far as to cause Groklaw to be shut down. PJ feels extremely genuine here, she is definitely not using this as an excuse. Wow. There is something very unhealthy in the air or in the water these days. Lots of people seem to be totally immune to the consequences of rampant surveillance and frankly bizarre powers ex…

That 'something unhealthy' is called privilege, and most people assume that it will protect them from government atrocities. Little do they know that privilege is given at the behest of the oppressor, and can be revoked instantaneously. I suspect that US tech companies who are complicit in dragnet surveillance - and PRISM specifically - are already understanding this.

> I suspect that US tech companies who are complicit in dragnet surveillance - and PRISM specifically - are already understanding this.

Absolutely. Just as 2013 is the year where "ordinary people" have begun to understand that "the cloud" is a scam.

(And that is doesn't make that much of a difference if they store their data with Google, Apple, or directly with the NSA. If the blueprints of PRISM can't be kept from leaking, then subsets of the actual data will leak as well. Five or ten years from know, you'll have a huge grey market of -- medium to low quality, outdated, etc. -- surveillance data.)

Re: Forced Exposure

#107
...Can PJ not figure out GnuPG? Is she officially retiring from any and all digital correspondence contrary to her notice that "[her] email [addresses] still work"? She says she's getting off the internet to whatever extent possible, and then asks people to continue to send her mail. I also find it cute that people believe facilities based in other Western nations are outside of the NSA's reach.

I gotta say that stopping Groklaw, which is a public site anyway, because someone else might be reading it, doesn't seem to make a lot of sense, despite the emotional ploys in this article. She can write and save drafts locally in a (GASP) local word processor and encrypt anything she chooses to upload to remote storage. The government will then not be able to read unfinished Groklaw articles. Does this resolve the issue?

This whole article should've just been a public key and a PO box address with this note: "I will not acknowledge plaintext mail. If you are uncomfortable transmitting encrypted data over the wire, please send a USB disk to this box."

Re: Forced Exposure

#108
post #74

Groklaw has been a jewel in the crown of the free internet. We are all unbelievably impoverished by its passing. This is truly awful.

On the plus side, so far as it goes, I don't think we could make a better case for "chilling effects"...

Re: Forced Exposure

#109

OMG.. Groklaw shut down!? I'm in shock.

A part-solution. All tech geeks set up mail servers with encryption and volunteer to migrate their non-tech friends and family to new email homes. We also show how to configure encryption in their mail clients and start getting them to use native email clients rather than webmail. This will have two effects. It will send a message to Google/Microsoft/Yahoo!/insert big mail provider here/... that they have been lax in…

There is also https://mykolab.com that PJ now uses:

If you have to stay on the Internet, my research indicates that the short term safety from surveillance, to the degree that is even possible, is to use a service like Kolab for email, which is located in Switzerland, and hence is under different laws than the US, laws which attempt to afford more privacy to citizens. I have now gotten for myself an email there, p.jones at mykolab.com in case anyone wishes to contact me over something really important and feels squeamish about writing to an email address on a server in the US.

Re: Forced Exposure

#110
post #75
post #50

Earlier quoted context omitted.

No, I mean protocols. While elsewhere in the comments, there is the sentiment that "you can't code yourself out of this", my hopes of voting myself out of it (or otherwise "fixing" a system, as if it was just accidentally "broken") are much lower. (But note that "protocols" may also have non-technological components.)

> While elsewhere in the comments, there is the sentiment that "you can't code yourself out of this", my hopes of voting myself out of it (or otherwise "fixing" a system, as if it was just accidentally "broken") are much lower. So you intent of fixing just a small point of the whole mess (the surveillance thing) and not the overall mess (bad governments, something that affects 100% of our life and countries)? Not to…

"Everything can be outlawed, including mere use of unlocked general purpose computers as a non authorized professional in, say, 20 years time."

I think that genie is well out-of-the-bottle.

Did you see the article recently about installing linux on the microcontroller on a hard disk controller board? There's no end of "consumer electronics" that have "general purpose computers" inside them. Hell, I'm helping out some people deploying christmas lights with a half-gigahertz ARM Linux board with wifi as a controller. (hardware details here: http://dev.moorescloud.com/2013/07/06/holiday-hardware-is-op... if you're curious). They've shipped over a million RaspberryPi's in the last 16 months - they're mostly still going to be useable in 20 years time, and between now and then pretty much every toy,appliance,car,tv,phone,coffeemachine,whatever is going to contain something capable of running linux...

Post reply on HN