Live data from Hacker News

Forced Exposure

groklaw.net

261–270 of 430 posts

Re: Forced Exposure

#261
post #6

Want to keep your rights and freedom? It's time to act, now. History is full of great things going all the way down. Don't wait for the Superman.

> It's time to act, now Suggested courses of action? Tried and didn't work: * voting * not voting * protesting online / offline * writing about these issues, raising awareness What options do we have left? Violence? Hopefully there's more.

Organize. It's the only course of action that has ever worked.

Voting/not voting/protesting/etc. are tactics that are only useful as part of a larger campaign, and as part of a large group committed to a particular goal.

Re: Forced Exposure

#262

Earlier quoted context omitted.

She makes the observation that any encrypted email is held on to for ~5 years--this may be why she didn't want to bother with the GPG bollocks.

The thing is, GPG is not bollocks. Barring a major unforeseen discovery, RSA cryptography will easily stand up to five years' retention. If you're worried, use a long keylength. I've been using 4096-bit keys for over a year now and there's no noticeable performance hit for regular comms on my computer. On my phone, 4096 is noticeably slower than 2048, but it still works fine (probably about a 5-10 sec operation to de…

More to the point though, is that forcing the NSA to work on a specific message is computational power that they can't use to oppress the populace at large.

I know PJ is quite private (and probably rightfully so after the private investigators that were sicced on here during the SCO trials), but I was still shocked to read about this. Imagine if the New York Times and Washington Post had shut down in the 1940s, 50s, 60s when phone wiretapping was completely legal for the government to do.

Not only did they not shut down, but they didn't even have encryption to use back then. The people are far better armed today to be able to protect their communications.

Re: Forced Exposure

#263

Earlier quoted context omitted.

Your final statement here is not true. The way in which you keep anonymity with an onion system is as follows: 1. Use a central originating server for onion packet sourcing 2. Make it public who all users are 3. Have onion packet creation contain "token of receipt" for all messages along the chain. 4. Rate limit message origination from users 5. Ban users who refuse to forward encrypted packets at a steady rate 6. On…

How do you rate limit users? Are not originator traffic and pass thru traffic indisquishable, so a receiving peer cannot tell the if a node is just well connected and has a lot of traffic on behalf of others, or is an abuser? And how to measure forward rates?

There are two types of nodes in the system, "servers" and "users". All servers communicate with each other so that they are all aware of all existing "servers" globally. There will likely be a limit on who is allowed and authorized to be a server. ( likely a list of their public keys published to the main site for the project )

All packets must be hashed and authorized ( signed ) by the server before they can be sent out. Any packet not authorized by a server will be rejected. In this way, servers will rate limit originating packets.

The traffic is distinguishable because the onion layer is identified at each level. If, after unwrapping your layer, you discover the underlying "level" is not 1 less than your own informed level, the ip origination will be flagged back to the server for spamming.

Current estimate for number of onion levels is 100. Actual destination should be somewhere in the middle 60 or so, to prevent government tracing of the packet because all hops.

At each hop, random delays will be implemented, as well as injection of extra data and/or disguising the entire packets as other forms of tcp communication. ( to prevent dropping of the packets through filtering )

The "servers" know that users are sending out origination packets at a specific rate and to whom, but nothing about the layers beyond the first. Additionally, the entire onion packet is never sent to any server, only a hash of it with specific other information. This way, "servers" can never be accused of harboring illegal data of any sort.

Forwarding rates are measured because each onion layer containing a "message of receipt" that is sent back to the server. The server receieves all of those from the originating user before approving the onion packet.

The only think attackers of the system could try to do is attempt to DDOS users of the system. This is prevented inherently by it being known at all types all users logged into the system ( this is public knowledge in the system ). Communication is only allowed from valid behaving users.

Re: Forced Exposure

#264

Earlier quoted context omitted.

> It's time to act, now Suggested courses of action? Tried and didn't work: * voting * not voting * protesting online / offline * writing about these issues, raising awareness What options do we have left? Violence? Hopefully there's more.

What a joke. Please educate yourself about the history of successful social movements like labor rights, civil rights, environmental protection, etc. The privacy movement has not even begun to begin what is necessary to change the law. For example: can you name the leading organization that works solely on privacy? There isn't one. The issue is only sort-of covered if you add up the partial work of a bunch of differe…

>Please educate yourself about the history of successful social movements like labor rights, civil rights, environmental protection, etc.

Given that the current context involves opposing government power, I'm not sure labour rights and environmental protection are relevant examples; both resulted in massive expansion of the effective scope government power.

Civil rights would perhaps be a slightly better example simply because what was being fought against were largely government creations (e.g., legally compulsory discrimination). And even then the civil rights movement had a visible violent side[1].

[1] http://www.reddit.com/r/Libertarian/comments/1ds5fa/a_march_...

Re: Forced Exposure

#265

It is really tragic that we have reached a point where something so wonderful as Groklaw cannot effectively function. Nearly 200 years ago, de Tocqueville asked why the American experiment in self-government succeeded while its French counterpart led to the guillotine, mob excesses, and ultimate tyranny and he gave a complex answer whose core was that private moral restraints in the populace served to check the unbou…

This deserves to be a separate post, not a comment

Re: Forced Exposure

#266
Frankly, I don't understand that.

E-mails are unsafe for private communication. What the recent revelations did is that they showed that e-mails really are unsafe.

If you are really afraid that you are under surveillance, switch to PGP. It's not hard.

Re: Forced Exposure

#267

Earlier quoted context omitted.

Anybody building such systems today should have a plan for when (not if) they receive a National Security Letter.

Fuck the NSA. Dear NSA: I can and will be designing a fully anonymous open source distributed messaging system that is entirely secure even if you tap every line in the world. At the very best, you will be able to accuse people just of running the software. If you don't like this, I'd advise you that your only option is to hire me and/or pay be enough money to become disinterested in finishing the creation of the sof…

Trying to blackmail the NSA ? please let us know how it goes, it could be an interesting story.

Re: Forced Exposure

#268

I guess I don't get it. Didn't we "know" about things like Carnivore in the 90s? Isn't it rather expected that unencrypted communications are going to be gathered? You don't even need a nation-state to do so. Anyone with physical access can place taps, and parsing and saving port 25 traffic ain't exactly Manhattan Project level work. I agree it's upsetting and citizens should be demanding oversight. But to assume you…

I know. We're all so gullible and dumb right? Tell me. You're speaking with a friend in a public square or park in your town. You're not speaking in code with your friend. Judging by what you just said I expect you assume your every conversation is being monitored. We have certain expectations of privacy and basic human decency. Just because it's possible to wiretap and hoover up all unencrypted communications I woul…

First, I don't see you really addressing my point, which is that this behaviour dates back a long time (Carnivore was public knowledge before Snowden even worked for the NSA), and it doesn't even take a very powerful entity to implement it. (Jeez, I regularly get customers sending me traces of their customers (metadata+voice contents) just for troubleshooting purposes.)

Advances in massively deployed array microphones aside, I don't find speaking in a park to be remotely similar to transmitting over a large public network. On the Internet, you are willing handing your data off to multiple third parties. You have little control over which third parties, or even which countries, your data flows through.

I'm not insulting anyone's intelligence. I'm simply questioning why anyone assumes they've got privacy other than "because it feels like it should". And, hey, that might be a good argument and something to get enshrined in law. (Although, I'd be surprised if the USG backs down at all, except perhaps to concede to some more oversight audits.)

Snowden's "hard evidence" is great because it gives bigger, solid ammunition to argue against mass surveillance. But it's not like anything has suddenly changed, nor should anyone's behaviour change (other than to use encryption when possible).

P.S. Your comment would be better without the sarcasm. I'm being honest and serious in my attempt at commenting here.

Re: Forced Exposure

#269

Earlier quoted context omitted.

What. A FISA warrant doesn't magically render RSA invalid. If all your comms are encrypted, they can get whatever warrants they want, and they still won't be able to read your information unless you surrender your passphrase and key.

obligatory XKCD: http://xkcd.com/538/

That's what happens with extraordinary rendition, not FISA warrants.

Re: Forced Exposure

#270

Earlier quoted context omitted.

I know. We're all so gullible and dumb right? Tell me. You're speaking with a friend in a public square or park in your town. You're not speaking in code with your friend. Judging by what you just said I expect you assume your every conversation is being monitored. We have certain expectations of privacy and basic human decency. Just because it's possible to wiretap and hoover up all unencrypted communications I woul…

>Tell me. You're speaking with a friend in a public square or park in your town. You're not speaking in code with your friend. Judging by what you just said I expect you assume your every conversation is being monitored. You should be aware of the possibility that someone may be eavesdropping in this situation, yes. >We have certain expectations of privacy and basic human decency. Our expectations of privacy are vali…

> Our expectations of privacy are valid in private contexts, like a home or business. Public contexts, like a busy shopping center or the internet, do not contain inherent guarantees of privacy. Even though one can normally assume that no one dangerous is listening in, it's a risk you always take when you engage in any conversation or behavior in a visible location.

Or even if you talk in your house with your door wide open. Does anyone else remember Star Trek VI?

But either way we also don't expect every conversation we make outside to be monitored as a matter of course. To the extent that NSA is doing this we are right to be very upset.

The flipside is that even before email there were few options for communications between third-parties that could not be intercepted at all (without a full warrant) by the U.S. government within the U.S. Probably USPS was it (though later telephones received that same protection). And there were about zero methods if you were talking international communications (maybe diplomatic pouch was safe, probably nothing else was). So in that regard modern comms are still an improvement.

But I do agree with you that things people need to have private, need to be encrypted, as there are more threats out there than just the NSA.

Post reply on HN