Live data from Hacker News

The Criminal N.S.A.

nytimes.com

111–116 of 116 posts

Re: The Criminal N.S.A.

#111
post #46

Earlier quoted context omitted.

For call metadata, the pen register comparison might fly. If they are storing content, as is likely, it won't. The beginning of the article on standing does raise questions I hadn't thought about. How would you decide the penalty for something with the potential for abuse? Just because the NSA is storing the largest ever collection of personal info with potential for blackmail, election skullduggery, stalking, identi…

I'm thinking of the metadata, yes. I'm not convinced yet about the content allegations, and I suspect (but have not researched) that the point if illegality is when people start listening to them without a warrant rather than when they're merely stored.

That is certainly what the NSA seems to be claiming, and coincidentally it is the most convenient interpretation for them. But it seems highly bogus to me. Has the RIAA ever worried about whether downloaders actually listened to the contents of EnterSandman.rar?

More worrying, the NSA could abuse this by listening to whatever they liked, then getting information by other means, then lying about listening. And we certainly already know that the NSA is capable of lying and willing to do so.

Re: The Criminal N.S.A.

#112

Earlier quoted context omitted.

Please explain to me how a "constitutional amendment creating an explicit right to privacy" would do fuck all if the only body that assesses constitutionality won't allow us to complain when that right is breached.

You're allowed to complain, but they may not agree that your complaint has any merit. You don't seem like the sort of person who's into changing their mind though, so I don't really know what to tell you. You could try checking out some books on Constitutional law from the library to get a better understanding of how this works.

You did not address my point. "It won't happen because the court does not believe you have any rights that have been violated" is something that can be fixed by a constitutional amendment granting an explicit right to privacy, but seems to me a different claim than "it's just politics," and the court has supported a right to privacy in the past (though it's complicated). Obviously, the court may or may not consider us to have a right to privacy, may not consider the right to extend that far, &c, &c. Those still seem qualitatively different than what you'd lead with. What am I actually missing?

I fucking love changing my mind, but it takes actually convincing me, not simply argument from authority without even any credentials given. "Go read a bunch of books" is bad form (doubly so with no particular recommendations) - I have plenty on my reading list as it stands.

Re: The Criminal N.S.A.

#113
post #83

Earlier quoted context omitted.

> Governments can still gather the metadata of encrypted emails. True, but don't throw out the baby with the bathwater right away. I know metadata is at least as sensitive as the actual content, but you need to pick your battles. If we get people to widely use GPG to encrypt the content of their emails, that is already a huge win. Why? Because they're now using a public/private key infrastructure. And as you are prob…

> I know metadata is at least as sensitive as the actual content, but you need to pick your battles. If we get people to widely use GPG to encrypt the content of their emails, that is already a huge win. Why? Because they're now using a public/private key infrastructure. And as you are probably well aware, as soon as everyone involved has secure private keys, implementing all sorts of nifty crypto strategies to hide…

but you can make as many keypairs as you want or need. just like the circles in G+, except with privacy :)

Re: The Criminal N.S.A.

#114
post #88

Earlier quoted context omitted.

> Governments can still gather the metadata of encrypted emails. True, but don't throw out the baby with the bathwater right away. I know metadata is at least as sensitive as the actual content, but you need to pick your battles. If we get people to widely use GPG to encrypt the content of their emails, that is already a huge win. Why? Because they're now using a public/private key infrastructure. And as you are prob…

> If we get people to widely use GPG to encrypt the content of their emails, that is already a huge win. Sure. Completely agree. > (and I'm not entirely sure if those key-ID's are sufficiently unique and/or secure, but you can put more then just the ID in such a header to fix that) Note that a key ID is just the last characters of the fingerprint. If you want a more secure key ID, just use a longer piece of the finge…

> Note that a key ID is just the last characters of the fingerprint. If you want a more secure key ID, just use a longer piece of the fingerprint (which is a valid longer form of key ID that gpg will Just Work with).

cool, I was hoping it would work something like that :)

Re: The Criminal N.S.A.

#115
post #92

Earlier quoted context omitted.

I was hoping someone far more talented than me would write a browser plugin that would encrypt everything I type in a TEXTAREA with GPG, and then prompt me for a list of friends I'd like to have read that text. Everything, from Facebook to Gmail, would be encrypted that way. And I would be in control of the list of people that could read that text.

This is a solved problem, including the problem that you're haven't anticipated, which is the helpful "autosave" of drafts. http://www.emacswiki.org/emacs/Edit_with_Emacs I'm sure something similar exists for vi, sublime, etc., but emacs (of course) has great gpg support ( http://www.emacswiki.org/emacs/EasyPG ). This moves the burden to your local machine, which, while not guaranteeing privacy, helps reduce the amou…

Hardly solved. I want it to be so simple the average Facebook user will want to use it.

Emacs hardly fits that bill. Nor does popping up any other editor I think.

I would just like to use the native browser interface and right before doing a POST, have the browser do a pop up and ask me which of my friends I would like to share the text with.

Re: The Criminal N.S.A.

#116
post #92

Earlier quoted context omitted.

This is a solved problem, including the problem that you're haven't anticipated, which is the helpful "autosave" of drafts. http://www.emacswiki.org/emacs/Edit_with_Emacs I'm sure something similar exists for vi, sublime, etc., but emacs (of course) has great gpg support ( http://www.emacswiki.org/emacs/EasyPG ). This moves the burden to your local machine, which, while not guaranteeing privacy, helps reduce the amou…

Hardly solved. I want it to be so simple the average Facebook user will want to use it. Emacs hardly fits that bill. Nor does popping up any other editor I think. I would just like to use the native browser interface and right before doing a POST, have the browser do a pop up and ask me which of my friends I would like to share the text with.

Also, there is the decription part. The browser would need to auto-decrypt on the fly all the encrypted messages that are meant for your eyes only. Without asking for a password every time. And without having to open a new application. Rendering pages might prove difficult, as the page can only be rendered properly after decription.
Post reply on HN