Live data from Hacker News

Did Obama Just Destroy the U.S. Internet Industry?

linkedin.com

201–210 of 291 posts

Re: Did Obama Just Destroy the U.S. Internet Industry?

#201

Earlier quoted context omitted.

>We bought their cell phones To be fair, folks in the US bought a LOT of European cell phones first. :)

And to complete the circle (triangle?), nowadays we all but Korean/Taiwanese phones :-)

But not Chinese because lord knows they'll spy on us.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#202
post #185

Earlier quoted context omitted.

But the return on investment is likely to be far less. If it is harder, more resources have to be spent, then they will be more selective if just because it would be prohibitive to bug every system across the world, at least at present.

>But the return on investment is likely to be far less. I am not so sure about that. The internet... well, many of the wide-open holes have been closed... BGP hijacking isn't as trivial as it was in '08[1], mostly because filtering has been implemented in some places, but it's still something that could be done by someone of, say, my resources. It's trivial to anyone with real resources. And there are all sorts of ot…

Metadata cannot be protected as well as the actual content can. One of the keys of good security is to ask what has to be compromised for your data to be compromised, though. If you have SSL-protected connections, BCG hijacking alone isn't going to reveal your communications but BCG hijacking along with a fake certificate issued by a trusted CA under court order or merely voluntarily) would allow a MITM attack.

The thing is, if you have your own CA, and expect certs from both sides from the same CA, then it is very hard for an MITM attack of this sort to be orchestrated because you can say, "Something isn't right here." So that leaves attacks against the cyphers involved or against the endpoints.

One service we offer is an ability to use an SSL cert issued by the customer, as well as appropriate VPN options to connect to the system at all. Between these, in general I would expect that MITM approaches can be protected against in high security configurations. But that still leaves cyphers and endpoints.

So the first thing we need is a better PKI which can more robustly handle fraudulent certificates. This is something I have written about a bit. (see my blog, http://ledgersmbdev.blogspot.com for more.) But we also need a lot more.

BTW, we build everything on the basis of compartmentalized security with the idea that compromising customer data will require working through quite a bit of depth, particularly in relatively high security configurations. It wouldn't protect against a court order, but it should protect against a lot of other things.

Could the NSA hack us? I am sure they could. Could we make it difficult enough that they would be much better going through legal channels (maybe making deals with local law enforcement or the like)? That's what I am shooting for. It is probably the best one really can shoot for.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#203
post #126

Earlier quoted context omitted.

"Suppose you do business with an American company that has servers in Australia (for the record we are registered in the UK, not the US), and they get a FISA warrant? Of course they will send the info over" There's a way out. Those server offshore must be handled by subsidiary. Then the parent company in US does not have the data and they can not also command subsidiary to handle it over.

The big US companies have made it clear that they will give out data held by subsidiaries, even if this is illegal eg under European law.

That means the best option is not to use wholely owned subsidiaries and instead have a partnership with the parent owning a large plurality but non-controlling interest (say 10 partners from various countries, with the parent owning 49.9% of the subsidiary). You can set the agenda, more or less run things how you want, but anything you try to do as shareholder can be vetoed by the other 9 acting in unison.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#204
I doubt many people will leave American companies real soon there are just not many good alternatives at the moment but given a choice between an American company and say one in a more privacy oriented country that advertises its position properly people may think twice.

Nobody seems to mention that the intelligence agencies of the world deal with information and their not shy of selling it. Say for instance a revolution is brewing over Facebook in a country the US would like to keep as is how likely is it that the CIA would provide intelligence to that country to stop the revolution?

Facebook may be a tool for revolution but it can be a tool to stop revolution as well and the US government gets to decide which one will it be.

I'd rather they stay out of it and the only way to do that is to not use US services.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#205
post #137
post #104

One of the rather interesting side issues in this whole debate has been how casually the rights of foreigners are tossed aside as secondary to those of american citizens. There is intense debate about whether US citizens rights are being violated, but almost nobody questions whether there's any moral or ethical issue with completely unrestrained spying on everybody else. While I understand that this is largely becaus…

Absolutely. I remember how in 2001 when the US as the first country ever invoked article 5 of the NATO treaty, within hours all NATO members had followed through with support. And the minute of silence that was held all over Europe for the 9/11 victims. Then we joined them in two wars. We bought their cell phones, their operating systems and productivity suites, their internet adds, hosting and email services and mov…

>allies

No, we're vassals. The USA orders and we obey, whether it's supporting their military machine or handing over information, people, research, or economical advantages. It's a hegemony.

>the misdeeds that seems to have returned from the dark ages

You've been fed propaganda. The crimes have always been there. The USA has always supported tyranny, cruelty, and crimes against humanity if it served its best interests (like every other country, I might add.)

>we deserve the same protection as American citizens

If the government wants someone naked, chained, and tortured in some foreign place, it'll happen. No matter who it is. True? Maybe not (yet), but it's telling enough that it sounds plausible, no?

Re: Did Obama Just Destroy the U.S. Internet Industry?

#206
post #187

Earlier quoted context omitted.

No, I'll be putting some of my traffic through Cloudflare as we use several domain names, and each for a specific purpose.

also if they want to intercept a few of your high profile users, the fact you're using SSL really isn't going to stop them, when they can issue valid certs for your domain without asking you. short of SSL pinning being widely deployed: you're powerless to stop them, and while it's an admirable goal, it's ultimately disingenuous to suggest that you can safeguard your user's privacy.

I'm not suggesting that I can safeguard user privacy, but doing something is better than doing nothing, and certainly I can do what I am able to. Ultimately the user is far more likely to give up their privacy by posting identifiable information online, and through graph analysis revealing their associates too.

What I can do though is: Leave the core data in Europe, not store anything that I do not need to offer the service (and I don't need your real identity), educate users and encourage the use of Tor and VPNs, implement what measures I can do protect users (SSL).

Re: Did Obama Just Destroy the U.S. Internet Industry?

#207
post #173

Earlier quoted context omitted.

Foreigners don't want equal rights. Just equal protections from the government.

protection (from harm) is a right granted by the government.

Yes, but that you can identify one right that governments can/should afford non-citizens and citizens alike doesn't mean that's true of all rights. Venomsnake was trying to identify the kind of right that it should be true for.

As a British citizen I have a right to not be tortured by the government (under A.3 HRA1998), and a right to NHS healthcare. The former (a negative right) is one the government should afford to the whole world. The latter (a positive right) is not.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#208
post #185

Earlier quoted context omitted.

>But the return on investment is likely to be far less. I am not so sure about that. The internet... well, many of the wide-open holes have been closed... BGP hijacking isn't as trivial as it was in '08[1], mostly because filtering has been implemented in some places, but it's still something that could be done by someone of, say, my resources. It's trivial to anyone with real resources. And there are all sorts of ot…

Metadata cannot be protected as well as the actual content can. One of the keys of good security is to ask what has to be compromised for your data to be compromised, though. If you have SSL-protected connections, BCG hijacking alone isn't going to reveal your communications but BCG hijacking along with a fake certificate issued by a trusted CA under court order or merely voluntarily) would allow a MITM attack. The t…

>Could we make it difficult enough that they would be much better going through legal channels (maybe making deals with local law enforcement or the like)? That's what I am shooting for. It is probably the best one really can shoot for.

Yeah; my point was just that getting to that point (where it's easier for them to go through legal channels) is harder than it looks. It's certainly not the default state.

Re: Did Obama Just Destroy the U.S. Internet Industry?

#209
post #104

One of the rather interesting side issues in this whole debate has been how casually the rights of foreigners are tossed aside as secondary to those of american citizens. There is intense debate about whether US citizens rights are being violated, but almost nobody questions whether there's any moral or ethical issue with completely unrestrained spying on everybody else. While I understand that this is largely becaus…

This is something that already pissed me off when drone strikes were discussed. While not caring about foreigners is probably the most important reason, there is another one that actually makes sense, and which is why I give Americans a little bit of benefit of doubt: Given the strict protections of your constitution, it is much easier to fight the parts that concern citizens of the US. Edit: accidentally submitted a…

Drone strikes are also different. They represent currently a sort of danger to the world I don't think people really appreciate because they allow an elite to control more firepower with fewer henchmen than is possible otherwise. Air strikes are nothing new but in the past you had to contend with the fact that enough people might disobey orders to force a change of plans. With drones, the number of people you rely on is far less.

I remember a story that on 9/11 orders were issued to shoot down any aircraft left in the sky and that fighter pilots refused to carry out the order. How would things be different if it was 8 specially trained anti-terrorist folks commanding largely autonomous drones?

Post reply on HN