Web-based cryptography is always snake oil
121–130 of 137 posts
Re: Web-based cryptography is always snake oil
#122Earlier quoted context omitted.
> Using e2e from a US-based entity means you are prone to spying from the US government, but at least you know you're reasonably secure against the IRGC, the Chinese intelligence service, the FSB, and so on. Framing this in terms of governmental espionage is nonsensical. Using e2e from a US-based entity makes you completely sure that the US government is spying on you, because they assert direct control over the soft…
I think the whole US vs. non-US thing is total crap and there's nothing you can reasonably do with it in any direction, but I always think it's important to point out that US signals intelligence can lawfully compromise foreign communications; that's literally their chartered purpose.
It's not. US companies can be subpoenaed in the US.
> I always think it's important to point out that US signals intelligence can lawfully compromise foreign communications; that's literally their chartered purpose.
Of course they can. But it's significantly easier to get a warrant to target a company under US jurisdiction.
Re: Web-based cryptography is always snake oil
#123Re: Web-based cryptography is always snake oil
#124Earlier quoted context omitted.
No, I'm very clear on what the question was asking, and it is not in fact "NSA" driving this process. This is 100% Daniel Bernstein drama. Bernstein is upset that the NIST contest selected MLKEM (Kyber). He's been running a yearslong crusade to impeach the standard, up to and including opposition to lattice cryptography writ large , despite himself signing on to a lattice entrant (SNTRUP) to the PQC competition. Over…
Your argument would be far more charitable if NIST had not already been caught pushing a broken standard at the behest of the NSA before. DJB might be combative and somewhat caustic, but the one thing he's never been, given enough time in the retrospect to show it, is wrong.
Re: Web-based cryptography is always snake oil
#125Earlier quoted context omitted.
I think the whole US vs. non-US thing is total crap and there's nothing you can reasonably do with it in any direction, but I always think it's important to point out that US signals intelligence can lawfully compromise foreign communications; that's literally their chartered purpose.
> I think the whole US vs. non-US thing is total crap It's not. US companies can be subpoenaed in the US. > I always think it's important to point out that US signals intelligence can lawfully compromise foreign communications; that's literally their chartered purpose. Of course they can. But it's significantly easier to get a warrant to target a company under US jurisdiction.
Re: Web-based cryptography is always snake oil
#126Earlier quoted context omitted.
> I think the whole US vs. non-US thing is total crap It's not. US companies can be subpoenaed in the US. > I always think it's important to point out that US signals intelligence can lawfully compromise foreign communications; that's literally their chartered purpose. Of course they can. But it's significantly easier to get a warrant to target a company under US jurisdiction.
Foreign companies don't have to be subpoenaed. NSA can simply break in and take whatever they want, lawfully. In light of that, the warrant point you're making doesn't make sense: they don't need a warrant to go after foreign assets.
You can't be serious …
The NSA can break in the same way the Mossad can assassinate you anywhere in the world. That doesn't mean it's a it's going to happen anytime soon unless you're an exceptionally high priority target. Authorities getting legal access to your personal informations from US companies on the other hand is routine practice. Equating the two is a crazy take.
By the way, you read the argument completely backwards in the first place: the original argument was that even if using an American company means the US law enforcement have full access to your data if they want to, your data is still pretty safe from anyone else there (unless, of course, if you are a high priority target again).
See the original sentence:
> Using e2e from a US-based entity means you are prone to spying from the US government, but at least you know you're reasonably secure against the IRGC, the Chinese intelligence service, the FSB, and so on.
Saying someone's argument is “total crap” without even having taken enough time to properly read the sentence you're criticizing is kinda lame IMHO.
Re: Web-based cryptography is always snake oil
#127Earlier quoted context omitted.
Foreign companies don't have to be subpoenaed. NSA can simply break in and take whatever they want, lawfully. In light of that, the warrant point you're making doesn't make sense: they don't need a warrant to go after foreign assets.
> NSA can simply break in You can't be serious … The NSA can break in the same way the Mossad can assassinate you anywhere in the world. That doesn't mean it's a it's going to happen anytime soon unless you're an exceptionally high priority target. Authorities getting legal access to your personal informations from US companies on the other hand is routine practice. Equating the two is a crazy take. By the way, you r…
Re: Web-based cryptography is always snake oil
#128Earlier quoted context omitted.
> NSA can simply break in You can't be serious … The NSA can break in the same way the Mossad can assassinate you anywhere in the world. That doesn't mean it's a it's going to happen anytime soon unless you're an exceptionally high priority target. Authorities getting legal access to your personal informations from US companies on the other hand is routine practice. Equating the two is a crazy take. By the way, you r…
I am 100% dead serious and I kind of don't understand the rebuttal you're trying to write here.
> I kind of don't understand the rebuttal you're trying to write here.
Fill free to make the effort to read it (again).
Re: Web-based cryptography is always snake oil
#129Earlier quoted context omitted.
I am 100% dead serious and I kind of don't understand the rebuttal you're trying to write here.
“Cryptography is useless because governments agencies will kidnap you and hit you with a wrench” isn't the hill I expected you to die on TBH. > I kind of don't understand the rebuttal you're trying to write here. Fill free to make the effort to read it (again).
Re: Web-based cryptography is always snake oil
#130Earlier quoted context omitted.
“Cryptography is useless because governments agencies will kidnap you and hit you with a wrench” isn't the hill I expected you to die on TBH. > I kind of don't understand the rebuttal you're trying to write here. Fill free to make the effort to read it (again).
I have no idea who you're responding to because nobody on this thread has made that argument.
All I got from your few words is that apparently you consider the NSA breaking into a random foreign app a reasonable threat model to design around. Abduction from the CIA being only marginally more unlikely, why bother with anything?
Or maybe I misunderstood your point but then again when you can't bother writing down two consecutive sentences how am I supposed to read your mind?