Live data from Hacker News

Julian Assange: Cryptographic Call to Arms

cryptome.org

271–280 of 281 posts

Re: Julian Assange: Cryptographic Call to Arms

#271
post #257

Earlier quoted context omitted.

> It absolutely is consolation and justification for the majority of people who support that policy. Yes, but not for the victim of the policy. Slavery used to be approved by the vast majority of society. > You might not like it; but individual liberty is not unlimited and the will of society, right or wrong, beats the pants off any other form of government we've found. I don't like it, and I don't want to replace it…

> except that government has convinced society that its actions are acceptable. Government is society, we are our government, it is not some entity that has tricked everyone. It does what it does because open your eyes and look around, people want it doing those things.

But you're still just saying that violence is fine as long as >50% of society approves of it. And that's being gracious, since there's no reason to actually believe that >50% of society approves of the actions of the government.

Re: Julian Assange: Cryptographic Call to Arms

#272
post #271

Earlier quoted context omitted.

> except that government has convinced society that its actions are acceptable. Government is society, we are our government, it is not some entity that has tricked everyone. It does what it does because open your eyes and look around, people want it doing those things.

But you're still just saying that violence is fine as long as >50% of society approves of it. And that's being gracious, since there's no reason to actually believe that >50% of society approves of the actions of the government.

Violence is a natural and inevitable human trait, and is not necessarily wrong. There are times when it is OK, and is even the right thing to do. What better way to determine what those times are than democratically?

Re: Julian Assange: Cryptographic Call to Arms

#273

Earlier quoted context omitted.

It's a very hard problem IMO. Not just finding the words, but everything. For example, before learning linux to a degree where it wasn't a pain to use as a desktop, I thought it made no sense to waste time learning this or that security feature (like email encryption), because an expert would probably be able to fuck me anyway. Now that I have a better understanding, and I can mentally trace the information from end…

Can you please elaborate on Tor exit nodes vulnerability? As far as I know they can read your passwords if you're not using secure connection, but how can it compromise your identity? I'm assuming the new account was created for an anonymous blog post.

Exactly, if you are careful you are safe. But it takes just one mistake to get caught. For example, if you have javascript activated (without it most of the web is useless), you could get fingerprinted, and then make a match with facebook or gmail, or if you are already a suspect, just get raided and make the match there. I don't know exactly how these guys I mentioned got caught, they probably did something stupid like logging in to a website with a real account. If I remember correctly, the news article only said that the police started running an exit node and sniffing the data that went out.

Re: Julian Assange: Cryptographic Call to Arms

#274
post #13

I think this is very relevant here - interview with the NSA whistleblower, William Binney, on how NSA is storing every post people are making online, so they (and FBI) can use it later: http://www.youtube.com/watch?v=TuET0kpHoyM No wonder NSA and FBI want warrantless access to private companies by lobbying for new laws like CISPA, and trying to build backdoors in services like Facebook, Skype, Twitter etc. They want…

Forget about the Constitution. Rather, they should respect basic human rights and the principles of the Enlightenment. All this focus Americans put on their Constitution makes it easier for their government to become oppressive, because it encourages complacency. As though you could write the perfect set of laws, that you could define the perfect set of operating principles for your government, and in that way free y…

(in case anyone missed the reference, "the price of liberty is eternal vigilance" is attributed to Thomas Jefferson)

Re: Julian Assange: Cryptographic Call to Arms

#275
post #161

very platonic, but totally oblivious to "rubber hose cryptanalysis" ...unless you have a group of fanatically loyal people at the core of your "freedom protectors" group and the "engineers" that implement your cryptography systems part of this group, force and bribery will always win. ...and if you have a group of people truly loyal to freedom, then you don't need much crypto anyway ...just spoken words, physical tra…

You might be interested to learn that Assange had developed the Rubberhose file system. https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29 So I don't think he's oblivious to the concept.

do you how does it compare to similar features offered by TrueCrypt?

Re: Julian Assange: Cryptographic Call to Arms

#276
post #14

I think that more focus, at least in the short term; needs to be put on making crypto accessible to windows users. As an example, consider the following project website: https://www.gpg4win.org/ An invalid security certificate, and even that only if you go out of your way to specify https. If the vast majority of users saw this, they'd go running; including myself. I can't in good conscious recommend crypto that does…

I feel pretty safe predicting that most communications are moving to mobile, vs. desktops. Even if you have a desktop, most of your communications will happen on a mobile device. The thing we really need (and what I'd fund if I had a spare $Xmm or so) is a great crypto API and solution to the user key management problem for iOS and Android, hooked into apps. It's technically easier to do on Android. On iOS, you're ki…

Silent Circle appears to be for people who both

1) Want military-grade(ish) hardened coms

and also

2) Aren't willing to set it up themselves, but trust a service provider to do it for them

I read their docs a bit ago and don't really get it. I didn't really get Whisper Systems offering either as it appeared to have a broken trust model on a variety of levels.

If I cared about this kind of thing, and I really don't, I'd likely want to own all parts of the transport system and have the only available threat surface be the encryption algorithm as much as possible http://www.voip-info.org/wiki/view/Asterisk+encryption

Might it all be pointless without massive amounts of traffic padding based on this attack? I wouldn't know. http://link.springer.com/article/10.1007%2Fs10207-010-0111-4...

Re: Julian Assange: Cryptographic Call to Arms

#277
post #75

Earlier quoted context omitted.

How on earth can you bring up diaspora in this context? Some kind of cruel joke? I'm downvoting parent and giving you the right link: https://freenetproject.org/

Do Freenet now have any social features in it? Last time I looked (few years ago) it didn't have any significant.

It appears to be useful for admins getting convicted of CP trafficking for running a node. Does that count?

Try this one: http://distributedcity.github.com/

The previous incarnation of Distributed City was pretty cool. I haven't looked at their new code.

Re: Julian Assange: Cryptographic Call to Arms

#278
post #275

Earlier quoted context omitted.

You might be interested to learn that Assange had developed the Rubberhose file system. https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29 So I don't think he's oblivious to the concept.

do you how does it compare to similar features offered by TrueCrypt?

TrueCrypt's plausible deniability system is dependent on a passphrase instead of an auth key iirc.

Another likely difference is that truecrypt works.

Neither will stand up to scrutiny for the purposes of deniability. It's obscurity which is effective in the scenarios that the docs outline below.

http://www.truecrypt.org/docs/?s=plausible-deniability

Re: Julian Assange: Cryptographic Call to Arms

#279
post #158

Earlier quoted context omitted.

Just as a thought experiment, what do you think of an alternative reality in which even more of reality is transparent - including the operations of commercial, political, and other entities? Preferably collated and maintained by the community rather than centralized entities, crucially; somewhat akin to a shared wikipedia. The thing that worries me about this push towards encryption and anonymity is that it does aff…

"The thing that worries me about this push towards encryption and anonymity is that it does afford nefarious elements a lot of safe harbor" I have yet to see any evidence that this is true; all I see are anecdotes from law enforcement agencies who are pushing for less crypto, and even those anecdotes only tenuously describe "nefarious" elements. You cannot encrypt a blood stain or a fingerprint, nor can you use an an…

Thanks for the detailed response - first of all, I don't see all uses of crypto as problematic by any means - and I'm very glad that good police work and investigation can, and does, track down malicious behaviour even when enabled by the latest technology. Ultimately all these things are about human networks at the end of the day, and we're all fallible, and I generally trust that there's more sunlight than darkness.

I also completely agree that pretty much every technological innovation throughout history - weapons, communication mediums, etc - are used by both 'police and thieves', or whichever actors fit in the white/black boxes in the given situation.

The problem in my mind is more general - it's that crypto and concealment are just an evolution of the status quo - the arms race continues, with more 'secrets whispered in the woods', yet average people are already losing their day-to-day privacy, in vast numbers, and crimes still occur of course.

Opening everything is clearly radical and/or impossible, and it's a long-term idea/concept rather than anything feasible in the near future. Despite my ramblings, I'm a realist, and I've worked on migrating many, many legacy systems, so I'm familiar with the challenges, but this is the only process I've reasoned about so far regarding disruption of the arms race itself, as opposed to just evolution of arms, so I'm hunting for counter-arguments and these are good ones.

Enabling dissidence is a very good point, and I think it highlights the problems with hierarchy/power itself and information disparity. If neither party was able to operate without the knowledge of the other, then dissidence could take place openly without fear of hidden/unknown retribution. Trusting that the system is really 'open' and that you can see all the communications is definitely a challenge though (unsolvable?)

Regarding your final point, I'd say that although crime is part of a darker aspect of human nature (which can be encouraged, manipulated or instilled), we have been controlling our own education and evolution for generations through society and religion and choice of partners - so why can't we see this as an optimization problem, and try to guide ourselves towards a less criminal and violent nature?

(PS: the final point is a bit rhetorical - I think we have been for a long time already - cannibalism isn't hugely popular for example)

Re: Julian Assange: Cryptographic Call to Arms

#280
post #166
post #158

Earlier quoted context omitted.

Just as a thought experiment, what do you think of an alternative reality in which even more of reality is transparent - including the operations of commercial, political, and other entities? Preferably collated and maintained by the community rather than centralized entities, crucially; somewhat akin to a shared wikipedia. The thing that worries me about this push towards encryption and anonymity is that it does aff…

I don't think the transparent reality would work. For thousands of years people are known to gather in the back of the woods to hatch plans that must be kept secret before the execution. That's just how people want to deal with a part of the things in their lives. The secret might be a terrorist plan, a plan to open a new business, a plan to rob a neighbouring village or a plan to arrange a surprise birthday party. Y…

Thanks for the reply! Would I be mis-representing things to say that you feel that the need for privacy/hidden communication is predicated by the fact that it has beneficial purposes as well?

The world might certainly be a very dull place if nothing was private - no more surprise birthday parties as you mention, for example - but perhaps there would be equal and opposite benefits to shared knowledge/information?

The situation regarding whistle-blowing itself requires that there is something worth reporting, which wouldn't be the case if the knowledge was already available (unless, perhaps, the knowledge was available but simply not highlighted well enough for people to spot any malicious behaviour).

Totally agree with your final point - it's a very strange dichotomy that as average people are finding less and less privacy, those with privilege or power are the ones who are afforded it.

Post reply on HN