Live data from Hacker News

Encrypt your Google chats and make the NSA sad

github.com

121–130 of 195 posts

Re: Encrypt your Google chats and make the NSA sad

#121
post #83

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Further thinking along this line: most people in the world today are dependent on their phones and internet for information and communication. A lot of people suspected total listening capabilities and now we mostly know that's the case. But what if the NSA had total interference capabilities, as Snowden's quote implies? I suspect it does. I've been finding HN to be a hub for all the facets, ideas, and fallout from t…

When I told my grandparents (who now live in Russia/former Eastern Bloc) about what's happening in the US, they brought up this exact issue (with a less tech-oriented example).

My grandmother said that this was the most terrifying part of living in the Soviet Union. Since most of my grandparents were high up military (doctors, not soldiers), aerospace research, and medicine in the Soviet Union, they saw the reality of the USSR with a lot less propaganda. When they went back home or visited family in other parts of the country, they would immediately enter into a surreal world where the reality described by propaganda was starkly different from the reality they had experienced.

What's even more terrifying is that by nature of their isolation from international news sources and dependence on TV, most of America already lives in roughly this reality. The world as they see it is shaped by television.

Re: Encrypt your Google chats and make the NSA sad

#122
post #83

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Further thinking along this line: most people in the world today are dependent on their phones and internet for information and communication. A lot of people suspected total listening capabilities and now we mostly know that's the case. But what if the NSA had total interference capabilities, as Snowden's quote implies? I suspect it does. I've been finding HN to be a hub for all the facets, ideas, and fallout from t…

[deleted]

Re: Encrypt your Google chats and make the NSA sad

#124
post #97
post #47

Earlier quoted context omitted.

Intercept could also mean man-in-the-middle.

Which would be trivial if they had agreements with the various mostly US providers to quickly get man-in-the-middle signed keys from their CA's. Although this seems like it would be quick to spot since if you were watching certificate fingerprints change then you'd see the switchover and switchback.

Yeah, I know nothing about this area (so this is just speculation, ignore it as such if you wish), but it seems getting a firehose feed of all traffic would be easier and less exposure prone, than getting every ISP to allow a MITM and having absolutely no one in the computer security industry notice. Don't get me wrong, I would prefer a MITM, at least then you know they haven't broken crypto that is widely believed secure, the alternative is a bit scarier :)

Re: Encrypt your Google chats and make the NSA sad

#125
post #107

Earlier quoted context omitted.

this would make "intercepts" far more difficult Yup, Google is doubtless completely in cahoots with the NSA. ... Really? Is that what you are thinking? Apply some rational thinking here. It's simpler than that. Google advertises to you based on the contents of your email. It is not in Google's interests to prevent themselves from being able to read your email, and if they can read it so can the NSA.

I don't understand why everyone seems to think this is an issue. It's as though the only alternative to the status quo is local host browser-level crypto. The implementation I'm referring to doesn't preclude Gmail from reading emails it has of yours. It just means that only Gmail can read them, because only Gmail has your private key, a private key that's associated with two-factor authentication, and a private key y…

That would work fine, if all the NSA did was sniff traffic on the backbones.

Re: Encrypt your Google chats and make the NSA sad

#126
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#127
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#128
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#129
post #57

Google, Yahoo, and Microsoft could all make the vast majority of email vastly more secure by implementing PGP-by-default. Send: You enter an email address, a little key appears beside it if it's recognized as having an associated public key, and a warning appears that the email can't be encrypted if an additional email address is entered that doesn't have an associated key. Receive: email encrypted with your public k…

Where would the private keys be stored? How do you handle the use-case of a non-technical user losing their laptop?

Re: Encrypt your Google chats and make the NSA sad

#130
post #4

While this is a nice effort, why use Google Talk at all for chatting if you're going to do all this effort (per user configuration etc) if you could just use an XMPP client with OTR[1] support, or use an XMPP server you can trust? [1] https://en.wikipedia.org/wiki/Off-the-Record_Messaging

Because then you'd be talking to yourself as nobody uses XMPP with OTR.

I use it. So ... nobody+1 I guess?
Post reply on HN