Live data from Hacker News

Forced Exposure

groklaw.net

141–150 of 430 posts

Re: Forced Exposure

#141
post #134
post #128

Earlier quoted context omitted.

> Email does not fit that medium. Why not? Email can be implemented in a global p2p file database. Every "email" simply adds another file. Privacy can be ensured with encryption (as long as the encryption is not broken, at least). See existing Freenet message boards for an example. It may not be Internet RFC821/822 (and subsequent standards) Email, but it is email. What part of this will not fit the Freenet model?

How would you send the new file to your recipient?

The same way that message boards do this already on Freenet.

See https://freenetproject.org/understand.html.

Something like:

Publish a site using a USK (perhaps one per recipient), containing all encrypted messages sent recently. Update the site with an additional message when you need to send one. The recipient checks it for updates periodically.

I'm not sure if my understanding is inaccurate, but since Frost already achieves something like this, I don't see that it's automatically impossible such as what you seem to be inferring.

In fact, now that I look, there's: https://freenetproject.org/freemail.html

I'm dubious about the safety of using non-Freenet clients, but surely this demonstrates that it's possible to build a messaging system built over Freenet?

Re: Forced Exposure

#142

I guess I don't get it. Didn't we "know" about things like Carnivore in the 90s? Isn't it rather expected that unencrypted communications are going to be gathered? You don't even need a nation-state to do so. Anyone with physical access can place taps, and parsing and saving port 25 traffic ain't exactly Manhattan Project level work. I agree it's upsetting and citizens should be demanding oversight. But to assume you…

Do you believe that physical mail enjoys no reasonable expectation of privacy either?

Re: Forced Exposure

#143
post #6

Want to keep your rights and freedom? It's time to act, now. History is full of great things going all the way down. Don't wait for the Superman.

> It's time to act, now Suggested courses of action? Tried and didn't work: * voting * not voting * protesting online / offline * writing about these issues, raising awareness What options do we have left? Violence? Hopefully there's more.

What country are you in? Because as far as I can see, there has not been much offline protesting (participation-wise).

And online protests are mostly useless. 10.000 people in the streets raise more attention than 10.000.000 facebook likes.

Re: Forced Exposure

#144
post #83
post #80

Earlier quoted context omitted.

You need a CA for TLS-secured comms between MTAs. Many MTAs are set up to do opportunistic encryption out of the box, but they won't be validating the certs they get, so there's no guarantees about who's got the private key. Of course there's no need to rely on a central CA - it's not hard to run your own, and you can make it reasonably secure - say, a small ARM Linux board with passphrase-protected private keys on a…

> You don't necessarily need a $5000 HSM solution to issue your own SSL certificates at this level. Well sure, I can issue them myself in a few minutes, the issue is that arbitrary mail servers won't be able to authenticate me. Which means we're means we're back to MITM attacks—better than plain text if the observer can't manipulate the data stream—but I wouldn't bet on it. Work with the assumption that the NSA is Ma…

How is that different to the web of trust between friends that the parent referred to?

Re: Forced Exposure

#145
post #105
post #85

Earlier quoted context omitted.

That 'something unhealthy' is called privilege, and most people assume that it will protect them from government atrocities. Little do they know that privilege is given at the behest of the oppressor, and can be revoked instantaneously. I suspect that US tech companies who are complicit in dragnet surveillance - and PRISM specifically - are already understanding this.

> I suspect that US tech companies who are complicit in dragnet surveillance - and PRISM specifically - are already understanding this. Absolutely. Just as 2013 is the year where "ordinary people" have begun to understand that "the cloud" is a scam. (And that is doesn't make that much of a difference if they store their data with Google, Apple, or directly with the NSA. If the blueprints of PRISM can't be kept from l…

There's no evidence the blueprints of PRISM were leaked, just training slides for analysts. There's also no evidence that actual surveillance data was leaked.

This particular slippery slope argument seems weaker because one would expect the government to place tighter controls on the data or the blueprints.

Re: Forced Exposure

#146

Earlier quoted context omitted.

She makes the observation that any encrypted email is held on to for ~5 years--this may be why she didn't want to bother with the GPG bollocks.

The thing is, GPG is not bollocks. Barring a major unforeseen discovery, RSA cryptography will easily stand up to five years' retention. If you're worried, use a long keylength. I've been using 4096-bit keys for over a year now and there's no noticeable performance hit for regular comms on my computer. On my phone, 4096 is noticeably slower than 2048, but it still works fine (probably about a 5-10 sec operation to de…

The longest key in the world won't protect you from a FISA warrent.

Re: Forced Exposure

#147
post #29

Earlier quoted context omitted.

> While I understand his personal reasons pj = Pamela Jones But yeah, it's devastating -- especially when it comes just one day after a editor of the Guardian states that they can no longer report on certain topics from London. It seems like we need entirely new communication protocols.

> It seems like we need entirely new communication protocols How about new government - one that isn't broken and tramples on all of our civil liberties? The first step is to dismantle the military industrial complex

> The first step is to dismantle the military industrial complex

Yeah that'll happen

Re: Forced Exposure

#148
post #20

While I understand her (1) personal reasons for shutting down Groklaw, this is an extraordinarily bad decision for privacy and democracy. In the last few weeks quite a few providers of private communications and/or freedom (for some definition of freedom) have shut down. Lavabot, Freedom Hosting, etc. If the US could shut down The Guardian they would. This leaves fewer and fewer secure channels for private communicat…

> If the US could shut down The Guardian they would.

That's stupid. Of course they wouldn't. They would require them to stop reporting on the security state. But that is vastly different from shuttering them all together.

The Guardian certainly performs a public service in a variety of other domains (from which the government can and does benefit). The security state just doesn't want the press banging around in their domain.

Let's not let the hyperbole get away from us here.

Re: Forced Exposure

#149
post #68
post #20

While I understand her (1) personal reasons for shutting down Groklaw, this is an extraordinarily bad decision for privacy and democracy. In the last few weeks quite a few providers of private communications and/or freedom (for some definition of freedom) have shut down. Lavabot, Freedom Hosting, etc. If the US could shut down The Guardian they would. This leaves fewer and fewer secure channels for private communicat…

Obama continues to push hard to steal what little privacy rights US citizens have remaining. He is openly hostile about it, and lies about it constantly. Am I exaggerating here? The scary thing is I'm not. He's not done. It's going to get worse.

We -- all citizens of Western countries -- should seriously stop voting altogether. And I mean full stop. When the next election comes, nobody votes. That'll destabilize things right quick.

Re: Forced Exposure

#150

Earlier quoted context omitted.

Its a subject I keep an eye on, e.g. freenet and off-the-record messaging. I think these systems cannot work :( If you can make a system that is immune to traffic analysis - http://williamedwardscoder.tumblr.com/post/54088903127/onion... is my own blog but I'm about to shoot it down - then you basically have an open router and the spam abuse that implies. Any reasonably anonymous system will collapse under the weight…

Its not as though we don't have a spam problem already… Freshly pulled-out-of-the-air suggestion – anonymous but requiring micro-payments. Say, 500 or 1000 satoshi (around a tenth of a cent) per message delivered – not as a means of generating revenue, but as a way to destroy email's current "if I only get one sale per 100,000 emails I send, that just means I need to send 10,000,000 emails a day to get my desired 100…

>Freshly pulled-out-of-the-air suggestion

That's not fresh. I think it may have even been entertained by Congress for a while.

Post reply on HN