Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

111–120 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#111

I'm uninformed. What is the significance of riseup.net?

I hadn't heard of it either until just now. I remember when Reddit removed their warrant canary. I barely even use it now. For most people I bet it didn't matter. I have a feeling with mission of Riseup, this will have a much larger impact on their userbase .. the ones who are aware of this.

I'll bet they placed bets on how quickly people would stop caring once it left the front page. That plus their usage of Moat display analytics tags on the homepage, and pushing for people's email addresses should be a clear telegraph of where they want to take the site.

I'm also curious about the security of things like RES.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#112

Earlier quoted context omitted.

Got any references to anyone speaking a foy-uh out loud? Ive only ever know it to be 4 letters, said discretely, and not as a word like SQL.

I would cringe when I would hear pronounced acronyms like "sequel" and "scuzzy" (SQL and SCSI) back in college; some acronyms simply aren't meant to be pronounced as words, especially if the pronounced word gave an uninformed listener the wrong impression. "Eww, why does my computer need to be scuzzy??"

I don't think, even in its heyday, I ever heard "SCSI" pronounced as anything but "scuzzy". Much more efficient and universally understood.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#113

Speaking for myself, this was brought to my attention in the context of a developing story about WikiLeaks being under duress or Julian Assange missing, who has not sent direct communication let alone signed communication for around a month now. EDIT - if curious, https://www.reddit.com/r/WhereIsAssange/

it's well known that his internet is cut off. I think if somebody was sending communications with his signing key while he is known to be unable to communicate, that would be the real problem.

He could probably just give a wave from the embassy balcony? He's been out there before, though perhaps his circumstances have changed.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#114

Earlier quoted context omitted.

Okay, that's telling, but the canary on its own seems to be valid still - it's from August 16, 2016, and they say it should be 'updated approximately once per quarter'

Well, after (I'm sure) many inquiries about the canary, their latest update says nothing specific, just: > we have no plans on pulling the plug https://riseup.net/en/about-us/policy/government-faq … https://twitter.com/riseupnet/status/800815181190217729

This reads like a vague suggestion that everything is fine, but in context (ie, no clear denial) it's a huge red flag being waved.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#115
post #38

Imagine if your office live-broadcasted nearly everything. From the corridors, reception area, to the opening of physical mail. The PR and generally more "public" email addresses could be transparent as well. This means when the NSL arrives, it will be seen by the world.

or the feed goes black

Or the CEO met in his doorstep by Men In Black, or whoever it is that delivers these things.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#116

Imagine if your office live-broadcasted nearly everything. From the corridors, reception area, to the opening of physical mail. The PR and generally more "public" email addresses could be transparent as well. This means when the NSL arrives, it will be seen by the world.

> Imagine if your office live-broadcasted nearly everything. The next step in the fight against ongoing, overbearing surveillance is... ongoing, overbearing surveillance?

Transparency, not surveillance.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#117

Imagine if your office live-broadcasted nearly everything. From the corridors, reception area, to the opening of physical mail. The PR and generally more "public" email addresses could be transparent as well. This means when the NSL arrives, it will be seen by the world.

I bet you a jam sandwich that an NSL is not actually a letter sent in the regular post.

They certainly are real letters, though you're right in that they might be hand delivered by an official process server. Either that, or just mailed with a return receipt and signature required.

Yahoo was able to publish the letters they received: https://s.yimg.com/ge/tyc/Redacted_Non-disclosure_Terminatio...

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#118

Earlier quoted context omitted.

I bet you a jam sandwich that an NSL is not actually a letter sent in the regular post.

They certainly are real letters, though you're right in that they might be hand delivered by an official process server. Either that, or just mailed with a return receipt and signature required. Yahoo was able to publish the letters they received: https://s.yimg.com/ge/tyc/Redacted_Non-disclosure_Terminatio...

Of course, it is ultimately a piece of paper...

But in every company I've worked for mail is signed for by whoever and, if it's addressed to an executive, delivered to a secretary who reads it and decides what to do it.

Given the requirement for secrecy, there is zero chance that an NSL will be treated in this way. And it won't be served by a random process server. Most likely it will be served by an NSA employee, in a discreet situation of their choosing.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#119
post #81

Earlier quoted context omitted.

What good is a warrant canary if it's also used for whimsy or commercial speech? If they don't take it seriously enough for people know what it means then their system isn't worth using to start with.

A Twitter feed is not a warrant canary. Edit: the exact link to the official warrant canary is specified in the top post, please don't answer if you haven't recognized that much: https://riseup.net/pl/about-us/canary The "If they're relying on double entendres then it might as well be" as a response to "A Twitter feed is not a warrant canary" really has no sense. https://en.wikipedia.org/wiki/Warrant_canary Also wort…

Think about it a while longer.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#120
post #57

Earlier quoted context omitted.

The parent statement is very misleading. Here are some significant differentiators between email providers: * Encryption in transmission emails sent and received, using SSL/TLS * Encryption in transmission of webmail sessions, using HTTPS * Authentication security: Do they use 2 factor or other tech? * Logging and retention of logs * Reading your mail to build marketing profiles and social graphs * Access by employee…

> Authentication security: Do they use 2 factor or other tech? Sorry for sniping this specific one, but 2FA is (more often than not), security theater. It gives the illusion of security like how TSA baggage check is a big dance of scanning, pat-downs, and key ceremonies. For context, consider Yahoo Mail, where emails are read by intelligence agencies before the user even gets them. Does my 2FA help here? Probably not…

> Sorry for sniping this specific one, but 2FA is (more often than not), security theater.

This is a completely wrong statement. It helps prevents compromise from non-system-level attackers. Telling a user that 2FA is "security theater" is doing far more harm than good.

Post reply on HN