Live data from Hacker News

Britain passed the “most extreme surveillance law ever passed in a democracy”

zdnet.com

241–250 of 302 posts

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#241
post #63

What is the easiest way to explain to the average citizen that the "Nothing to hide, nothing to fear" argument is not a good reason to let the Government keep tabs on your online activities? Most people don't give any thought to online privacy that it truly scares me.

I guess in the US you could take advantage of the current Trump Scare.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#242
post #182

Earlier quoted context omitted.

I've noticed that Britons, generally speaking, put a lot of trust in authority. They'll shrug it off or rationalize it when their government introduces another perverted law - the NHS works, so it can't be that bad, surely. Britain lacks a sizeable and vocal government-distrusting counterculture like they exist in Germany or the US. How you go about introducing that artificially, I don't know. The frog is being boile…

That is interesting. Living in Sweden, and having lived in the UK for 15 years, I feel the Brits trust their government much less than the Swedes do. In the UK there is strong resistance against a national ID card, as an example. Whereas in Sweden you can hardly live without one. I got the feeling that the Brits didn't trust their government with that info and control it implies. In Sweden we have the opposite: ID ca…

Resistance to the national ID card idea mostly came down to two things 1) cost to government, and 2) cost to citizens.

There's also the fact that ~87% of the population already hold a passport, and some of those that don't likely have a drivers license.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#243

Earlier quoted context omitted.

Quote from his documents about tls DECRYPTION (exactly decryption) would be much more convincing than "oh there is a ton".

Sure, there's been good journalist work compiling the state of the art here: http://www.spiegel.de/international/world/nsa-documents-atta... But also, being familiar with the cryptography you are attempting to have conversation about is a basic starter. For example, there were attacks listed in the prior comment following the "oh there's a ton" header. You seemed to have glazed past those, but they are familiar topic…

Thanks for the link. I've read all of the docs (presentations slides) related to ssl/tls and found only one weak point (Debian sessions). And none of them have information about decryption of collected traffic - collected encrypted traffic is useless, only possible (at this moment) way is to intercept multiple things in live mode and try to decode data.

It's sad, but I'm still saying "use encryption", because alternative is "don't use encryption" and it's obviously worse. So I'm much more responsible than those who are trying to propose second option.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#244
post #226

Earlier quoted context omitted.

If you run your own VPN will they not just log traffic from the endpoint (if in the UK) then tie it to you with billing records?

Depends where you're running your VPN. If you're running it on a server in the US they might not have access to that information.

Skip the US. Our surveillance agencies are in bed, and American VPN providers can be strong-armed with an NSL. Use a VPN incorporated and with exit points in a more neutral/second-world country.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#245

Earlier quoted context omitted.

Learn political organizing skills, which address these issues: How to build awareness, appeal to people, organize them, etc. As many veterans of past civil rights battles have said: Don't get mad, organize!

I've just started out freelancing, this is the kick in the pants I need to fill my downtime.

Fill your downtime with work to fill your pipeline.

Unless you plan on selling freelancing services related to anti-surveillance work (Security, building an audience in the area) really filling your time with anything but sales is going to hurt in a years time

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#247

Earlier quoted context omitted.

I wrote what I wanted to write, enough with sophisms.

I understand that you wrote what you wanted to write. Unfortunately what you wrote was FUD in the worst case and misinformed in the best. Anyway I think we both are at a point where we understand the other's point of view. Thank you for the conversation. I believe we both hope a lot of HN folks will stumble over it over the next few days. :)

And again you are trying to offend me even when i'm trying to stay calm in this conversation. And it's all just because I recommended to use encryption, lol. Fuck off and bye.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#248
post #64

Earlier quoted context omitted.

There is no single method of protecting privacy; VPNs are privacy against commercial-level actors. Tor has its own bounds, but people should use that, too. I generally think the internet is barely usable over TOR, but I don't need state-level privacy. My point being is that these are valid tools with valid uses, and people should understand and use them, NOT that VPNs are anything other than a way of encrypting and p…

>I generally think the internet is barely usable over TOR // I've only used tor browser (adding to the noise!), nothing beyond web. Could you go in to what makes the internet "barely usable" over TOR, do you mean speed or is there other things you're trying to accomplish that can't be done?

It's really just a speed thing—it's not worth the anonymity tradeoff for me.

Of course, maybe I should put my money where my mouth is and use it to improve it for people who DO find the tradeoff worth it.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#249

Earlier quoted context omitted.

Sure, there's been good journalist work compiling the state of the art here: http://www.spiegel.de/international/world/nsa-documents-atta... But also, being familiar with the cryptography you are attempting to have conversation about is a basic starter. For example, there were attacks listed in the prior comment following the "oh there's a ton" header. You seemed to have glazed past those, but they are familiar topic…

Thanks for the link. I've read all of the docs (presentations slides) related to ssl/tls and found only one weak point (Debian sessions). And none of them have information about decryption of collected traffic - collected encrypted traffic is useless, only possible (at this moment) way is to intercept multiple things in live mode and try to decode data. It's sad, but I'm still saying "use encryption", because alterna…

Sure thing!

Unfortunately I'm afraid that you missed a lot of the content! You had asked for specific documents, not news reporting that pieced the context together (for example following the code names of the various programs together to understand how the system works as a pipeline).

In doing so, I'm afraid you're deeply underestimating the capabilities of the NSA, which expert analysis of the documents in question along with the technologies, related programs and internal customer requests indicate something much more startling than Debian session issues.

To put a point on that: TLS is broken at scale for billions of internet browsing sessions across platforms.

Give the short amount of time you've looked at the documents, I understand the misinterpretation you've arrived at. At the same time it's really impressive that you bothered to try to read the documents at all and should be commended.

Please feel encouraged to continue reading.

A large number of documents are hosted on edwardsnowden dot com and search functionality is provided here: https://search.edwardsnowden.com/

Der Spiegel, The Guardian and The Intercept provided good analysis of the documents as they were being released and that can be found at the websites respectively.

> It's sad, but I'm still saying "use encryption", because alternative is "don't use encryption" and it's obviously worse. So I'm much more responsible than those who are trying to propose second option.

Yes. I agree with this. Just don't recommend this as 'enough' to people who have serious need to protect their communications. If someone is worried about their porn habits, sure. But recommending this for sensitive use (journalists, dissidents, organizers, politicians, administrators) can lead to very serious outcomes.

For these cases, it is important to have frank conversations about the limitations of freely available and widely distributed tools.

Re: Britain passed the “most extreme surveillance law ever passed in a democracy”

#250

Earlier quoted context omitted.

I understand that you wrote what you wanted to write. Unfortunately what you wrote was FUD in the worst case and misinformed in the best. Anyway I think we both are at a point where we understand the other's point of view. Thank you for the conversation. I believe we both hope a lot of HN folks will stumble over it over the next few days. :)

And again you are trying to offend me even when i'm trying to stay calm in this conversation. And it's all just because I recommended to use encryption, lol. Fuck off and bye.

Eugene.

We agree about the need to use encryption.

We disagree about it's limitations, and how to use it effectively.

Unfortunately this isn't a theoretical debate. Journalists, for example, around the world are being killed at increasing rates by governments, with this year reaching an all time high. State surveillance is an issue of tremendous importance for civil rights and personal freedoms. Our conversation and recommendations have to be sober and give candid, informed advice.

I think you absolutely have the right motivations: to encourage people to protect themselves from state coercion and violence.

Post reply on HN