Live data from Hacker News

Today is The Day We Fight Back

thedaywefightback.org

201–210 of 267 posts

Re: Today is The Day We Fight Back

#201
post #185
post #143

Earlier quoted context omitted.

> When the NSA demands your data, you're not really entering a business partnership. True, but I saw the original comment as relating more to recruiting. The NSA works just as hard as any tech company to compete for skilled employees. If you're the kind of person they want to hire, you have lots of fantastic other choices. So choose something else. Unless you're planning to pull a Snowden (and have gonads of steel).…

>If you're the kind of person they want to hire, you have lots of fantastic other choices. So choose something else. I am the kind of person they'd want to hire and what has kept me from applying is the relative low pay and not being in my area. As an engineer, you'd get access to cool tech in an interesting domain. >And if you do decide to help code the surveillance state, the rest of us may take that into considera…

So are you saying that the actions that the NSA have taken are not against your conscience? If so, then I would hesitate to hire you because ethical and conscience-based decisions are key to having trust in employees.

Re: Today is The Day We Fight Back

#202
post #34

My little fight back are some instructions on how to provide your own internet services, including encryption. http://freedombone.uk.to/ It's not ideal, of course, but in the short term since there seems to be no political appetite for relinquishment or meaningful reform then technical mitigation strategies - if they can be sufficiently popularised - may help to reduce the harm resulting from mass surveillance. Ultim…

Some feedback:

* don't use md5 as a security feature! I suggest to replace the use of md5sum with sha256sum (not even sha1sum is really safe anymore). The only use of seeing md5 in security contexts is to indicate that the person recommending its use doesn't understand security, which may admittedly be a worthwhile feature in itself. Perhaps you're really saying "this is one of the weak links in our security chain, the source code we're getting here might be hijacked or have huge security holes, and I haven't checked the sources, so it doesn't matter much anyway whether you're using the same sources as me anyway"? Then perhaps point this out, like using sha256sum and at the same time mention "(although I haven't verified the source code against security issues or backdoor (yet?))".

* I'm not a cryptologist, but regarding "the security of encryption depends upon how random the pseudo-random number generation on your system.." I think that's the wrong use of the term "pseudo-random number", as /dev/random really is about randomness, not pseudo-random numbers at all. /dev/urandom does stretch the collected entropy using pseudo-random number generation, but I think even the phrase "how random the pseudo-random generation" is mathematical nonsense, as it's not random at all, just random-looking when not knowing the generator inputs. Perhaps say "The security of encryption depends upon the randomness of the random source used on your system"?

(* I think the NSA is able to track you anyway, regardless of whether you're using your own server on the same IP or not. Thus the suggestion "make you more vulnerable to traffic analysis" will probably only hold for companies trying to track you.)

Re: Today is The Day We Fight Back

#204
post #34

My little fight back are some instructions on how to provide your own internet services, including encryption. http://freedombone.uk.to/ It's not ideal, of course, but in the short term since there seems to be no political appetite for relinquishment or meaningful reform then technical mitigation strategies - if they can be sufficiently popularised - may help to reduce the harm resulting from mass surveillance. Ultim…

Some feedback: * don't use md5 as a security feature! I suggest to replace the use of md5sum with sha256sum (not even sha1sum is really safe anymore). The only use of seeing md5 in security contexts is to indicate that the person recommending its use doesn't understand security, which may admittedly be a worthwhile feature in itself. Perhaps you're really saying "this is one of the weak links in our security chain, t…

Good points. Thanks. I used md5sum mainly because it was given on the original sites from which software was downloaded, but if sha256sum is more unique then I'll use that instead.

Although there are some systems where I'm familiar with the code - such as Bitmessage - in most cases I havn't personally checked the code myself. Ideally Freedombone would be a pure blend (I think that's also the aim of FreedomBox), but for now it does involve downloading some non-packaged systems.

Re: Today is The Day We Fight Back

#205
post #53

Earlier quoted context omitted.

excellent! well, i guess i played my part in the fight against surveillance today. ;)

Your comments were being watched.

Everyone's comments were being watched, now he's been escalated to a contributor and added targeting! :p

Re: Today is The Day We Fight Back

#206

Earlier quoted context omitted.

politicians ignore campaign promises You should back or elect different candidates. Don't simply choose the candidate others have chosen for you, get involved earlier in the process to make sure the person you're voting for has a greater chance of voting for the issues you care deeply for.

That worked really poorly with the last "Hope & Change" candidate. If you suggest voting for an independent... That is sort of a pipedream in the current US election climate. Noble thought and effort to push for such a candidate, but they have little to no chance of actually being electable. And even if they do get elected... Whats to stop them from being totally corrupted, or just overtly ignored by the rest of the…

> Edit: The biggest issue (in my opinion) at this point is the two party system that is entrenched beyond belief.

Entrenched to hopelessness.

Money buys politicians so much power and there is no amount of regulation (which would have to be passed by those in power and getting the money, HA!) that could curtail it. Eventually you are going to step on someone's first amendment right to "say" (buy ads upon ads upon ads) what they want for/against another candidate.

I think the only way I can hope for actual change is for more people to get involved and not be so easily swayed by various types of media. But the majority is lazy..

Re: Today is The Day We Fight Back

#207
post #185

Earlier quoted context omitted.

>If you're the kind of person they want to hire, you have lots of fantastic other choices. So choose something else. I am the kind of person they'd want to hire and what has kept me from applying is the relative low pay and not being in my area. As an engineer, you'd get access to cool tech in an interesting domain. >And if you do decide to help code the surveillance state, the rest of us may take that into considera…

So are you saying that the actions that the NSA have taken are not against your conscience? If so, then I would hesitate to hire you because ethical and conscience-based decisions are key to having trust in employees.

>If so, then I would hesitate to hire you because ethical and conscience-based decisions are key to having trust in employees.

Because every employee working for the NSA is doing a-thing-that-you-don't-like(tm) and not something different or important. I wouldn't want to work for someone that simplifies complex issues anyway.

Re: Today is The Day We Fight Back

#208
You want to fight back? Turn off Google services, MSFT services, Facebook, Youtube, Yahoo, DDG, Reddit, Tumblr, etc. for a day, that'll raise awareness like never before. But all these companies don't really care, do they? A day's worth of profit is more important.

Re: Today is The Day We Fight Back

#209

Earlier quoted context omitted.

Yes, SOPA and PIPA were defeated with much fanfare and attention, while some different laws doing the same damn thing were passed just a month or two afterward. Victory?!

Victory in the battle, not the war. But the ability to win a battle is huge.

True ... I just hate when a won battle draws attention away from a hidden, lost battle over the same ground, because in a way you're worse off if you think you won when you really lost.

Re: Today is The Day We Fight Back

#210

You want to fight back? Turn off Google services, MSFT services, Facebook, Youtube, Yahoo, DDG, Reddit, Tumblr, etc. for a day, that'll raise awareness like never before. But all these companies don't really care, do they? A day's worth of profit is more important.

Of course they care. http://www.reformgovernmentsurveillance.com/
Post reply on HN