Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

201–210 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#201
post #200

Earlier quoted context omitted.

This marketing message always confused me: my techie understanding was that Telegram is actually one of the least secure messaging choices. If you want security, my understanding is that your preferences should go Signal, Whatsapp, iMessage, Hangouts or whatever Google's flavor-of-the-month messaging app is these days, Telegram, and Facebook.

I was following you until Hangouts...

Google's security is still better than both Telegram's or Facebook's. It's not great, but that's why it's #4 on a list of 6. If you care significantly about privacy & security I would not use anything worse than iMessage, and even that's borderline.

(Your opinion of whether Google or Telegram is better will likely also depend upon whether you think malice or incompetence is a bigger threat. Google's business model relies upon it snooping on you, but they have really, really good security people ensuring that nobody else snoops on you. Meanwhile Telegram has less of incentive to actively violate your privacy, but they may let other parties violate your privacy by passively fucking up their engineering. They've done stuff like roll their own crypto algorithms, which is a terrible no-no for anyone that cares about security.)

Re: Encrypted web traffic now exceeds 90%

#202

Earlier quoted context omitted.

19 days before Snowden flew to Hong Kong, former FBI counter-terrorism agent Tim Clemente spilled the beans on CNN[0] (for context, informarion from a phonecall between one of the Boston Marathon bombers and his wife had been leaked to the media): >BURNETT: Tim, is there any way, obviously, there is a voice mail they can try to get the phone companies to give that up at this point. It's not a voice mail. It's just a…

>> I don't feel comfortable saying Snowden is still working for the US government, but I'm certainly suspicious of him. Well. My deep belief is that individuals that are truly dangerous to the system (here, any system that is powerful enough but one can view it globally as a continuously evolving technology-driven wanna-be-AI) get separated from power asap and then directly eliminated if needed. One should be very na…

> One should be very naive to think that the following makes any sense: "a young boy from government family says that the whole world is controlled by a few; he wants to stop it and so gets a platform to alarm about it via main media channels, supposedly controlled by the same few".

I'm very sympathetic to this view, obviously; at first glance it seems too good to be true.

Of course we're supposed to believe that the media isn't controlled by these same few, that Operation Mockingbird ended by the time CIA Director George H.W. Bush announced in 1976 that the CIA would stop paying journalists, and that Operation Mockingbird was actually limited to a couple of wiretaps rather than the fullscale infiltration of the press previously reported through non-official channels (though they did admit that they paid journalists, they claimed that this was not done as part of Operation Mockingbird). Obviously the CIA still has people in media agencies, but we're crazy for believing that; it supposedly isn't the case. But even with a CIA-infiltrated media, I could see the story getting out. The CIA can't be everywhere; it's possible that by going through more than one media institution (including a British one, as if that mattered) and also contacting a documentary film maker who had a previous run-in with the federal government (she claims to have been put on the highest theat-level list the DHS has after making a film critical of the occupation of Iraq) he was able to make sure that the government couldn't stop the information from coming out through some channel or another. Or they could have been worried that by blocking it in the press they would provoke him to release unredacted versions that would reveal even more (yes, he claimed to not have these by the time he entered China, but he could have given copies to another still unknown source -- or he could have been lying about not still having them in some format, perhaps steganographically hidden).

I could also actually see a whistleblower escaping capture/death by going to an area controlled by a foreign power and making the defection public immediately so that any suspicious death would be seen as an obvious assination without a fair trial. That seems plausible to me, whether or not it actually happened.

Re: Encrypted web traffic now exceeds 90%

#205
post #124

Earlier quoted context omitted.

Google Compute Engine didn't even exist at the time that slide was made, or at least was not publicly available. That slide was about government intercepting Google's traffic, not cloud customer traffic.

It was certainly smaller, but GCE was first publicly available in April/May 2013, Snowden leaked things in June 2013. I'm not quite sure when this slide was released but sometime after that. Google moved to fix the problem after the start of the leaks. Pretty quickly (good for them), but after.

I'm pretty sure RPC privacy boost was underway before the leaks. It was just launched more hurriedly after they came out.

Re: Encrypted web traffic now exceeds 90%

#206
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

If people really listened to Snowden they wouldn't be relying on CA authorities for certificates.

I feel like Namecoin and Ethereum Name Service are the most promising replacements for certificate authorities that I'm aware of. Are you aware of any better suggestions?

Re: Encrypted web traffic now exceeds 90%

#208

We do need HTTP because sometimes public WiFi networks need you to agree to terms before any requests stop being redirected. I recently found http://neverssl.com That being said those public WiFi’s shouldn’t be redirecting sites in the first place because for HTTPs sites browsers don’t even let you see the page.

http://http.rip

Re: Encrypted web traffic now exceeds 90%

#209

Earlier quoted context omitted.

>> I don't feel comfortable saying Snowden is still working for the US government, but I'm certainly suspicious of him. Well. My deep belief is that individuals that are truly dangerous to the system (here, any system that is powerful enough but one can view it globally as a continuously evolving technology-driven wanna-be-AI) get separated from power asap and then directly eliminated if needed. One should be very na…

> One should be very naive to think that the following makes any sense: "a young boy from government family says that the whole world is controlled by a few; he wants to stop it and so gets a platform to alarm about it via main media channels, supposedly controlled by the same few". I'm very sympathetic to this view, obviously; at first glance it seems too good to be true. Of course we're supposed to believe that the…

The point of that wall of text you wrote is that we pay taxes so that a rogue government agency can play all kinds of stupid fuck fuck games with us and other people all over the world and it is high time that it came to an end one way or another.
Post reply on HN