Live data from Hacker News

Encrypt your Google chats and make the NSA sad

github.com

21–30 of 195 posts

Re: Encrypt your Google chats and make the NSA sad

#21

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

He says "plant bugs in machines" , so that would seem to imply malware of some variety.

Re: Encrypt your Google chats and make the NSA sad

#22
post #6

Still waiting for Google to implement OTR and ZRTP in Hangouts by default... especially now after all this.

Probably not gonna happened, but it would solve so many problems with public key crypto. Key distribution? No problem, tie your public key to your gmail account. Need to communicate with someone? Just send them your public key. Goole would verify that key X belongs to mail Y, another problem solved. Mix it together with some javascript library (source code available by design) and you have almost perfect and simple to use public key crypto for masses. Oh well time to wake up….

Re: Encrypt your Google chats and make the NSA sad

#23
Why doesn't Google up the security in its own apps? The government may "force" them to provide access, but can it "force" them to remove safeguards like encrypting email/chats/etc? Even if they just gave us the option to check a box, and it wasn't on by default. The problem I'm seeing with all these solutions is that they're very specific to two users, they both need to have everything set up. Well, great, the NSA will see one less conversation when they peek through your stuff. I'd like to have ALL my messages encrypted.

Re: Encrypt your Google chats and make the NSA sad

#24
post #17

I've been using encryption with Adium for a long time, but the problem I have is switching between clients (laptop and mobile) results in me seeing gibberish on the mobile side. I have yet to find a mobile client that supports encryption.

For android, but:

https://guardianproject.info/apps/gibber/

Re: Encrypt your Google chats and make the NSA sad

#25

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

I took that to mean that they have exploits they can run once they which will let them take over your machine and install keyloggers etc. to report back any further activity. It wouldn't take much for them to purchase or develop a suite of vulnerabilities for all the major operating systems/browsers which they keep current, and once they have that any encryption is pointless as they can see what you see/type/hear. He mentioned it right after talking about seeing your machine on the network and mentioned hardware bugs separately.

Re: Encrypt your Google chats and make the NSA sad

#27

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

Perhaps he thinks that revealing technical details would actually hurt national security? (And I could easily see that.)

His goal wasn't to tear down the NSA, but to reveal what they've been up to domestically.

Re: Encrypt your Google chats and make the NSA sad

#28

This would definitely be the level of security that falls under this statement from Snowden: Q: Is it possible to put security in place to protect against state surveillance? A: "You are not even aware of what is possible. The extent of their capabilities is horrifying. We can plant bugs in machines. Once you go on the network, I can identify your machine. You will never be safe whatever protections you put in place.…

"We can plant bugs in machines" doesn't mean that they can do it remotely. That would actually be a serious serious backdoor and would put all kinds of businesses in mortal danger - banking, credit card, online shopping, etc.

Imagine what one rogue NSA employee can do with that kind of backdoor access.

So ENCRYPT EVERYTHING, and don't believe this propaganda. If your hardware has a backdoor, you're fucked no matter what, but businesses are fucked much much more.

Re: Encrypt your Google chats and make the NSA sad

#30

Earlier quoted context omitted.

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

He says "plant bugs in machines" , so that would seem to imply malware of some variety.

The FBI already plants or at least attempts to plant malware on targets (recently: http://www.slate.com/blogs/future_tense/2013/04/25/texas_jud... and regularly: http://www.wired.com/threatlevel/2009/04/fbi-spyware-pro/ )

Also, judges can now order people to decrypt whatever ( http://www.wired.com/threatlevel/2013/05/decryption-order/ )

Post reply on HN