Live data from Hacker News

Forced Exposure

groklaw.net

191–200 of 430 posts

Re: Forced Exposure

#191

Earlier quoted context omitted.

Even better, would be to have them report favourably or obtusely instead of shutting them down. I fail to see the hyperbole here... just a difference of method.

Shuttering a press outlet is a different thing in kind than what is happening right now. The US is not Zimbabwe or Burma or Jordan. It has its serious flaws and issues that need to be addressed, but we shouldn't mistake the kind of creature that we are dealing with. Making that mistake will lead one to seriously misunderstand what the interests and possible courses of action that western governments will pursue. Also…

Intimidation, confiscation/destruction of property without due process, invasive surveillance and retention under 'terrorist' laws for family of journalists is a difference of degree than what happens in Mexico.

I hold the liberal Western governments to higher standards though, and see the difference in degree as being eroded more easily than you suggest.

Re: Forced Exposure

#192

Earlier quoted context omitted.

She makes the observation that any encrypted email is held on to for ~5 years--this may be why she didn't want to bother with the GPG bollocks.

The thing is, GPG is not bollocks. Barring a major unforeseen discovery, RSA cryptography will easily stand up to five years' retention. If you're worried, use a long keylength. I've been using 4096-bit keys for over a year now and there's no noticeable performance hit for regular comms on my computer. On my phone, 4096 is noticeably slower than 2048, but it still works fine (probably about a 5-10 sec operation to de…

Yet you're using gmail and voluntarily surrendering at least part of your correspondence to Google's prying eyes.

Re: Forced Exposure

#193
post #6

Want to keep your rights and freedom? It's time to act, now. History is full of great things going all the way down. Don't wait for the Superman.

> It's time to act, now Suggested courses of action? Tried and didn't work: * voting * not voting * protesting online / offline * writing about these issues, raising awareness What options do we have left? Violence? Hopefully there's more.

What a joke. Please educate yourself about the history of successful social movements like labor rights, civil rights, environmental protection, etc.

The privacy movement has not even begun to begin what is necessary to change the law. For example: can you name the leading organization that works solely on privacy? There isn't one. The issue is only sort-of covered if you add up the partial work of a bunch of different orgs, like the EFF, ACLU, NRA, Emily's List, etc.

So: want to move the needle? Start an organization, raise many millions of dollars, collect thousands of contacts, and then run a big scary public and grassroots campaign. Give money to privacy-friendly politicians, and spend independent money to defeat opponents of privacy. Recruit privacy-friendly folks to run for local, state, or federal office. Take meetings with corporate, regulatory, and congressional staff to find folks who are sympathetic to the cause. Run privacy conferences. Pay people to write privacy blogs. Pick a nasty law and create a test case to get it into litigation. Etc, etc.

Now you might say "we shouldn't have to do that." And you're right. But: life isn't fair. Black people should not have had to risk lynchings in order to vote, but they did--and they did it. And they fought it.

Re: Forced Exposure

#194

Earlier quoted context omitted.

Not in the same way that you can use email though. It is unsafe to use GnuPG on a computer you do not own or trust like a computer at a public library or an Internet cafe. It is, however, possible to register an email address on such a computer and send unencrypted email on that same computer with some precautions and still be fairly sure that the contents will not be connected to you.

It's just as safe to use GnuPG on a public terminal as it is to use any other password-protected functionality on a public terminal. You run the risk that the terminal is recording your input and that your password may be compromised. In one case, this may compromise the security of your private key, and in the other case, it may compromise the security of your email account. One could argue that GnuPG is actually sa…

The main point I was trying to make is that, if you don't own a computer of your own and you are trying to leak something, an internet cafe or other public terminal that sees use by several people might be an effective way of hiding that you sent something. If you don't own a computer of your own you have no trusted place you can go to generate a PGP key, to set its passphrase securely, to encrypt email before you use the public terminal, to decrypt what you retrieved from the public terminal on your home machine (so your passphrase can't be keylogged or your key cannot be copied), and so forth. If you use a mass-market operating system (Windows, Mac OS X) you might have a computer that you own but cannot trust in any way. That's where opening a "throwaway" email address and sending something unencrypted is a viable use case. If you muck it up by trying to encrypt using PGP then possession of the key is persuasive (but not conclusive) evidence that you are the one that sent the email, and quickly becomes conclusive evidence if even the most basic automated surveillance techniques are used on that untrusted machine.

>One could argue that GnuPG is actually safer on a public terminal than generic online email access, because if you keep your keys on a USB stick, it's another critical piece of data that would have to get collected separately before the captured input data was of any use (this could be automated, but it'd be much harder than just running a keylogger, especially if one undertakes avoidance techniques).

One would be wrong. If an adversary is keeping a copy of every file that is opened on a USB stick (which would be trivial to add as an "update", "patch", or "option" to, say, an on-demand antivirus scanner) then it's game over.

>If one accesses an ordinary email service, the log would look like "gmail.com↲cookiecaper↲mypassword", which obviously contains all information necessary to access an account. As long as the private key is not automatically copied by the terminal, you can simply change your passphrase after each usage of a public terminal and it simply won't matter if someone stole your input or not.

If they have your key from the previous step then changing your passphrase does absolutely "jack" and "shit". Where are you going to change this passphrase anyway that's on a computer owned/trusted by you if you don't own a computer or don't want to tie that key back to your home machine and identity?

>The only issue is that in the real world, most terminals do not have GnuPG installed. We should be using taking this opportunity to try to change that, while public interest is on the topic.

Then you'll have backdoored copies of GnuPG installed on these machines that will offer you no security.

Re: Forced Exposure

#195
post #68

Earlier quoted context omitted.

Obama continues to push hard to steal what little privacy rights US citizens have remaining. He is openly hostile about it, and lies about it constantly. Am I exaggerating here? The scary thing is I'm not. He's not done. It's going to get worse.

We -- all citizens of Western countries -- should seriously stop voting altogether. And I mean full stop. When the next election comes, nobody votes. That'll destabilize things right quick.

most people in the US already don't vote, and look what that has accomplished ...

Re: Forced Exposure

#196

This doesn't make sense to me. There's a simple technical solution: stop using email for tips and setup a secure web form on the site. Can someone explain why this wouldn't solve the problem?

She'd be subject to NSLs and court orders and warrants. In fact it could even attract those things. She's cutting to the chase.

Re: Forced Exposure

#197

Earlier quoted context omitted.

Right, right, but for everyone that isn't a lean rockstar Node ninja programmer agile kanban expert--e.g., most of the population of the United States--it is far, far too easy to weigh going hungry against getting a "harmless" Facebook profile.

No programmer is going hungry in the US.

Was anyone here speaking exclusively about programmers?

Re: Forced Exposure

#198

Earlier quoted context omitted.

Shuttering a press outlet is a different thing in kind than what is happening right now. The US is not Zimbabwe or Burma or Jordan. It has its serious flaws and issues that need to be addressed, but we shouldn't mistake the kind of creature that we are dealing with. Making that mistake will lead one to seriously misunderstand what the interests and possible courses of action that western governments will pursue. Also…

Intimidation, confiscation/destruction of property without due process, invasive surveillance and retention under 'terrorist' laws for family of journalists is a difference of degree than what happens in Mexico. I hold the liberal Western governments to higher standards though, and see the difference in degree as being eroded more easily than you suggest.

You're still falsely equating. Even if it were a slippery slope along a line, it's still a line. Not all of the points are directly adjacent to each other.

Re: Forced Exposure

#199
post #116
post #35

Since we weren't allowed to say it when it was relevant, and the point was muddled and trampled on in pseudo-rational debates (“Can you find evidence that they’re abusing this new legislation?”, etc.), I'll go ahead and say it now: it's happening. There's still a big world outside the Internet, and yet ironically, we live in a world where some employers are so stupid that they won't hire someone without a Facebook, m…

> the best way to control a population is to analyze and manipulate the information they consume The comparison that some have made between the US Government and Stasi is more accurate than you think, with regards of Zersetzung : > By the 1970s, the Stasi had decided that methods of overt persecution which had been employed up to that time, such as arrest and torture, were too crude and obvious. It was realised that…

[deleted]

Re: Forced Exposure

#200
post #83

Earlier quoted context omitted.

> You don't necessarily need a $5000 HSM solution to issue your own SSL certificates at this level. Well sure, I can issue them myself in a few minutes, the issue is that arbitrary mail servers won't be able to authenticate me. Which means we're means we're back to MITM attacks—better than plain text if the observer can't manipulate the data stream—but I wouldn't bet on it. Work with the assumption that the NSA is Ma…

How is that different to the web of trust between friends that the parent referred to?

The WOT at least provides some authenticity, but only for people you already know. If I want to email you and aren't part of your WOT, then it's as good as plaintext.
Post reply on HN