Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

131–137 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#131
post #130

Earlier quoted context omitted.

Maybe one day I'll release an archive of pre-2011 emails and IRC logs. Yes I'm Tunisian, I only know of a couple active people around here, but there is a ton of readers.

Wow, so you operated mail and IRC servers for use by dissidents pre-2011? I would definitely attend a talk about that! A blog post would be amazing too. I see, that's great to hear. I don't live in Tunisia, so I'm not familiar with the Tunisian tech scene. Judging by your Twitter feed, it seems to be really active, which is awesome!

Nothing that impressive, I was just a bystander, I had a bot that logged IRC conversations on certain rooms and I subscribed to a number of mailing lists.

I just need to find the time to filter that data and publish something.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#132
post #98
post #62

Earlier quoted context omitted.

I'd imagine that since lavabit NSLs make that harder if not illegal.

its not within legal purview to force someone to continue doing something, is it?

Even if you shut down immediately (more on that in a moment), you can't wipe your storage and The State can still look through that

And if it is an ongoing investigation, shutting down immediately may be very difficult. Unless you can make a compelling case that you were already doing so for whatever reason, it is a very clear textbook case of obstruction of justice/interfering with an ongoing investigation.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#133
post #102

Earlier quoted context omitted.

Not really my area of expertise, but it strikes me as completely clear. The canary hasn't been updated and the tweet implicitly acknowledges that they are aware of the concerns that people have about the overdue update. I can only think of two reasons to do this. 1. get some publicity or 2. for whatever reason they are unable to update the canary and are unable to say why. Personally, I doubt it's reason 1.

But why say they have no plans to shut down and link directly to the part of their FAQ where they say they will shut down if they are under government surveillance? Why not just tweet something like "We have heard your concerns" or something similar

The purpose of the hyperbole, I'd assume, is to make one ask the same questions you're asking. In the philosophical sense: if we have to ask, we already have our answer.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#134
Looks like issue will be resolved soon:

https://twitter.com/riseupnet/status/765414528951529472

    .@flanvel Thanks for noticing. A refreshed canary statement will be up shortly.
----------------------------------

Disregard, I forgot to check date.

----------------------------------

That tweet is from august

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#135
post #47
post #3

And from riseup.net @riseupnet listen to the hummingbird, whose wings you cannot see, listen to the hummingbird, don't listen to me. #LeonardCohen https://twitter.com/riseupnet/status/797142735283257345

That was probably just commemorating Leonard Cohen's death, and the certificate fingerprints were probably just removed because they switched to Let's Encrypt for those domains. But you never know.

or it means "the canary is dead for a reason; don't trust us"

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#136
post #39

I am highly skeptical of any claim that an email provider is more private than other providers. E-mail is fundamentally not secure and not private, unless you enhance it with PGP, which requires you to, of course, have something you want private. Most people don't encrypt because they're not scared enough. It usually takes some time before their wordlview is repeatedly shattered enough that encryption is the only cho…

I would add that Riseup don't claim to be the best on security or privacy.

> Riseup provides online communication tools for people and groups working on liberatory social change. We are a project to create democratic alternatives and practice self-determination by controlling our own secure means of communications.

This is what they claim on their homepage[1]. Tools built by people who believe in a certain philosophy for people working on "liberatory social change".

They try to operate and control their tools. They don't claim that they are "the-most-secure-email-provider".

They claim to work on what they call "Network Security"[2] (traffic encrypting and providing services outside of the tracking bubble), and define other fields of security ("Human Security", "Device Security", "Message Security"), that the user can improve himself by education. They provide means of education for this.

This is an alternative. Gmail is maybe more "secure", or maybe not, but don't claim these kind of social changes. Gmail is "free" and commercial. Riseup is not free and volunteer-run.

[1] https://riseup.net/

[2] https://riseup.net/en/security/#security-overview

edits: typos

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#137
post #97
post #84

If you're doing any kind of radical political work --- left or right --- and are worried about the attention you're going to attract, don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption. These are fundamentally unsafe services, and the idea that they can be provided safely just by paying attention to network secu…

While you are not lying, and mailing lists should be avoided if you want to share secrets, most of the times you need a mailing lists not to do that, but to simplify communications. At least in the global south, most of radical activists groups have strong "no-internet policies" for any type of secret, and no cellphones ones for their work. They have learned with their own history what they can or can't do, learned h…

Also, sometimes, some activists can deliberately use a mailing list as a public expression channel because it is important that these things can be eared by everybody.

I see it as sticking posters in the street. There is no reasons to use Facebook or Google Groups for most of the Riseup (public) Lists users, not because they want something secret and hidden, but because they don't want to play with some companies rules and appreciate to be a part of a network run by volunteers more than to use profitable fake-free services.

Because it makes sense, not because it is more or less secure.

Post reply on HN