Live data from Hacker News

Laura Poitras on the Crypto Tools That Made Her Snowden Film Possible

wired.com

21–26 of 26 posts

Re: Laura Poitras on the Crypto Tools That Made Her Snowden Film Possible

#21
post #20

Earlier quoted context omitted.

Absence of evidence is not evidence of absence.

Greenwald and Snowden also used Cryptocat in Q1 2013. Now, there's no evidence to think that NSA decrypted all those messages... but in Q1 2013, Cryptocat was breakable; by NSA in June, and by anyone with a laptop from May all the way back to October 2011. These attacks are passive. If you've been hoovering up all the raw Internet traffic, you can go back through your archives and decrypt all the Cryptocat traffic fr…

This is a great argument in favor of wild speculation and fear mongering, but in no way does it follow from any rational line of thought.

Besides, "anyone with a laptop" hasn't been "hoovering up all the raw Internet traffic", and frankly the NSA hasn't been either.

Again, there's wild speculation, but there's no evidence. Again though, here you are preaching the fear and the wild speculation.

Re: Laura Poitras on the Crypto Tools That Made Her Snowden Film Possible

#22
post #20

Earlier quoted context omitted.

Greenwald and Snowden also used Cryptocat in Q1 2013. Now, there's no evidence to think that NSA decrypted all those messages... but in Q1 2013, Cryptocat was breakable; by NSA in June, and by anyone with a laptop from May all the way back to October 2011. These attacks are passive. If you've been hoovering up all the raw Internet traffic, you can go back through your archives and decrypt all the Cryptocat traffic fr…

This is a great argument in favor of wild speculation and fear mongering, but in no way does it follow from any rational line of thought. Besides, "anyone with a laptop" hasn't been "hoovering up all the raw Internet traffic", and frankly the NSA hasn't been either. Again, there's wild speculation, but there's no evidence. Again though, here you are preaching the fear and the wild speculation.

I'm not sure I follow. Let me connect the dots:

1. Stipulate that NSA is hoovering up all of Internet traffic, that being the motivating reason why people want encrypted messaging tools.

2. Cryptocat hosted egregious cryptographic errors for several years.

3. Those errors made it trivial for NSA, given a pcap file containing Cryptocat traffic such as would be generated by a Narus box, to decrypt and read Cryptocat messages.

4. Greenwald and Snowden used Cryptocat during this window of time.

5. Even if NSA didn't care about Cryptocat, Snowden, or Greenwald in June 2013, the vulnerabilities we're talking about allow them to retroactively decrypt those messages today, now that it's obvious that those messages were worth reading. We aren't talking about flaws that would let NSA MITM Cryptocat; we're talking about the worst possible vulnerability in a cryptosystem: retroactive arbitrary message decryption.

Which of these assertions to you dispute? We can go into lots more detail. I'm pretty familiar with Cryptocat's code[1], and I'd consider Steve Thomas a friend, in that he's been to my house a couple times and I gave a Black Hat presentation with him which in part involved Cryptocat.

[1]: 31580544b27c10736ebe1bdd05a56d96c486823d563d4493c317548976c3d8db --- I had to write my own CC client to get this, which is 2 hours of my life I'm never getting back :)

Re: Laura Poitras on the Crypto Tools That Made Her Snowden Film Possible

#23
post #22

Earlier quoted context omitted.

This is a great argument in favor of wild speculation and fear mongering, but in no way does it follow from any rational line of thought. Besides, "anyone with a laptop" hasn't been "hoovering up all the raw Internet traffic", and frankly the NSA hasn't been either. Again, there's wild speculation, but there's no evidence. Again though, here you are preaching the fear and the wild speculation.

I'm not sure I follow. Let me connect the dots: 1. Stipulate that NSA is hoovering up all of Internet traffic, that being the motivating reason why people want encrypted messaging tools. 2. Cryptocat hosted egregious cryptographic errors for several years. 3. Those errors made it trivial for NSA, given a pcap file containing Cryptocat traffic such as would be generated by a Narus box, to decrypt and read Cryptocat me…

That's all very interesting, and the only thing I dispute is (1), where I'd just say I don't think we have any direct evidence that the NSA is literally logging every packet sent anywhere within the US. Maybe some indirect evidence, but nothing that points to all the packets.

I think your source of confusion is related to the association you may have in your mind between me and Cryptocat, though in actuality there is literally none. In my previous comment I was referring to TrueCrypt, not Cryptocat.

As for your citation, what's that for?

Re: Laura Poitras on the Crypto Tools That Made Her Snowden Film Possible

#24
post #22

Earlier quoted context omitted.

I'm not sure I follow. Let me connect the dots: 1. Stipulate that NSA is hoovering up all of Internet traffic, that being the motivating reason why people want encrypted messaging tools. 2. Cryptocat hosted egregious cryptographic errors for several years. 3. Those errors made it trivial for NSA, given a pcap file containing Cryptocat traffic such as would be generated by a Narus box, to decrypt and read Cryptocat me…

That's all very interesting, and the only thing I dispute is (1), where I'd just say I don't think we have any direct evidence that the NSA is literally logging every packet sent anywhere within the US. Maybe some indirect evidence, but nothing that points to all the packets. I think your source of confusion is related to the association you may have in your mind between me and Cryptocat, though in actuality there is…

What's the point of an encryption tool that only works if your adversary can't see your raw packets? That's like a health insurance policy that only pays out if you never get sick.

Later: sorry, I missed the other question you had; here's an answer:

https://hn.algolia.com/?query=author:diminoten%20cryptocat&s...

Re: Laura Poitras on the Crypto Tools That Made Her Snowden Film Possible

#25
post #24

Earlier quoted context omitted.

That's all very interesting, and the only thing I dispute is (1), where I'd just say I don't think we have any direct evidence that the NSA is literally logging every packet sent anywhere within the US. Maybe some indirect evidence, but nothing that points to all the packets. I think your source of confusion is related to the association you may have in your mind between me and Cryptocat, though in actuality there is…

What's the point of an encryption tool that only works if your adversary can't see your raw packets? That's like a health insurance policy that only pays out if you never get sick. Later: sorry, I missed the other question you had; here's an answer: https://hn.algolia.com/?query=author:diminoten%20cryptocat&s...

I think you've mentioned CryptoCat more than I have in this conversation, and someone I know (and you surely adore) once said, "Fun message board trick: someone says something dumb about crypto? Search for their name and “cryptocat”."

If I gave you/anyone a TrueCrypt volume, could you/anyone crack it? No? Then stop trashing it. It's that simple.

Edit: I'd just like to say I'm glad you're developing a sense of humor regarding our conversations. I was worried you were a robot.

Re: Laura Poitras on the Crypto Tools That Made Her Snowden Film Possible

#26
post #6
post #4

Earlier quoted context omitted.

Thanks, it's mostly security nuts like me about security related topics. Hopping through my own Tor nodes could be a bit counter-productive, as it would make attribution of my circuit quite a bit easier. I use an extended hop relay with hand-selected nodes, which allows me to use five hops instead of the standard three, and hand-select fast relays that are in nations which are unlikely to share information readily. T…

Well, there are many uses. Impopular speech is in theory protected by free speech laws, but in practice you are only safe doing popular speech. Anyone that says something impopular should use COMSEC. It might not be needed today, but I'd use it to be safe tomorrow.

Free speech is an ideal I hold closely, and I would rather let myself be locked up, with all that entails, than acquiesce to governance that required I renounce it.

So if I no longer live in a country that feels as I do, which I very sincerely doubt, let come what may.

Post reply on HN