And even if they get a key, they will show up in the CT Logs eventually and the attack becomes public.
Only if there's an Expect-CT header, which is trivial to strip.
Well, no, the CT Log will include any valid certificate presented so any widespread attack will have to outright block access to the CT Logs or you're gong to have a bad time.
Expect-CT only controls if the browser will warn the user if the cert is not in the logs, it does nothing about certs being entered into the CT Logs themselves.
If you want to win against a view, select a leader from your pocket, make him look plausible and make him take control of the whole view. At any point you desire, let that person discredit himself and take the whole view down.
Well if Edward Snowden weren't a CIA asset, how would you know? If there's no way for us to know if Edward Snowden is a CIA asset or not and he has every appearance of an independent actor, why should we care?
I think that it's not actually possible to know anything, and your only real options after recognising that are to reject the pursuit of truth entirely or fall back onto probabilistic models instead of binary beliefs. Not knowing whether or not Snowden is a CIA asset leads me to the question, "how likely is it that Snowden is a CIA asset?" As to why we should care, here's another question: "if Snowden were a CIA asset, how would that change my future behavior?" If it wouldn't change your future behavior, carry on not caring. If it would, then ask yourself "given that I may be wrong about Snowden being a CIA asset, which way would I rather err for an optimal risk/reward ratio?" Then you consider all three answers, and decide how to act in the future despite never actually coming to a conclusion about whether Snowden is a CIA asset. Maybe you think the risk of him being an asset is so low that you don't mind risking the chance that he isn't, or maybe you think it's reasonably likely that he could be an asset while not believing that your personal risk from being wrong is worth worrying about. Or, maybe you change your behavior.
We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…
Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.
>if they were, you wouldn't be able to access them from a new device after authorization with a password.
Telegram isn't great but if your password was used to derive the encryption key, that feature would be entirely feasible.
I like the explanation that simply explains "privacy": When you are going to the toilet, and everybody knows that your going and what you'll do there, but you still close the door (for the most of us, most of the time).
Sure, but people close the door out of modesty not really privacy. If there was a machine that provided a written transcript of what someone did in the bathroom with no video/audio I don’t think people would mind. Like when you’re in high-security areas and have to be monitored in the bathroom there might be a door between you and your guard but no real privacy. Or when people loudly object to strip-searches at the a…
I think it's a pretty good workable analogy actually. People don't mind if you know they go to the toilet as an abstract thing, but once you start keeping a notebook of who is going to the toilet and when it starts getting creepy and undesirable. And that's just for collecting metadata! imagine if someone would actually intercept your sewer and analysed the makeup of your turds, folks would be up in arms.
Accessing chats from a new device has no technical relation (or constraint) to the lack of end to end encryption. Wire encrypts all chats end to end, and still provides syncing conversations to multiple devices on multiple operating systems. It does limit the sync to the last 30 days, but that’s mostly because of cost reasons rather than technical reasons. Edit/correction: Neither Wire nor Signal sync conversations t…
If you can view your old conversation from a fresh installation on a new devices then this automatically implies that some 3rd party has access to your keys. I.e. your conversion cannot be considered truly private.
It can also imply syncing over an end to end encrypted (and verified, using QR codes at setup) channel between the devices being synchronised. I believe this is what signal does, for example.
I don't consider a cert trustworthy just because it's signed by a CA, unless that CA is mine or one run by someone I personally know and trust. I came to this position before Snowden, though.
In the CA model is anything 100% yours? A signed cert has to depend on someone you dont know.
> A signed cert has to depend on someone you dont know.
No, it doesn't. If it's signed by my own CA, then I clearly know who signed it. Likewise if it's signed by a CA run by someone else I actually know.
The point of the signing is to have someone I trust validate that the cert they signed is trustworthy even if I don't know the entity that made the cert they signed.
Sure, but people close the door out of modesty not really privacy. If there was a machine that provided a written transcript of what someone did in the bathroom with no video/audio I don’t think people would mind. Like when you’re in high-security areas and have to be monitored in the bathroom there might be a door between you and your guard but no real privacy. Or when people loudly object to strip-searches at the a…
I think it's a pretty good workable analogy actually. People don't mind if you know they go to the toilet as an abstract thing, but once you start keeping a notebook of who is going to the toilet and when it starts getting creepy and undesirable. And that's just for collecting metadata! imagine if someone would actually intercept your sewer and analysed the makeup of your turds, folks would be up in arms.
We need this information to correctly gauge the interest on different kinds of foods we should keep available to purchase in the cafeteria.
It's also helpful as we can notify you early if you have some undiagnosed medical issue. You could unknowingly spread your illness to your children without this early detection.
We're even able to reduce your monthly health insurance premium by providing this data to the insurance company!
This also enables us to find troubled Individuals before it's too late and address building drug issues before they're full addictions. We'll be able to get them the required attention they need to get back on their feet and be productive members of our society. (Maybe not here though)
I think it's a pretty good workable analogy actually. People don't mind if you know they go to the toilet as an abstract thing, but once you start keeping a notebook of who is going to the toilet and when it starts getting creepy and undesirable. And that's just for collecting metadata! imagine if someone would actually intercept your sewer and analysed the makeup of your turds, folks would be up in arms.
We need this information to correctly gauge the interest on different kinds of foods we should keep available to purchase in the cafeteria. It's also helpful as we can notify you early if you have some undiagnosed medical issue. You could unknowingly spread your illness to your children without this early detection. We're even able to reduce your monthly health insurance premium by providing this data to the insuranc…
Scary... but still very theoretical and thus people can't really relate to that I guess because
I think this has a lot more to do with Google punishing web results without https than it does with Snowden, couple that with Cloudflare and Let's Encrypt and you have an easy path.
Yeah, Google has done much for privacy and it's kind of ironic how people believe those who say it's malicious. The only crime Google ever did was to be successful.
I think you can separate their punishing https with their lack of privacy in their core products.
When netflix is half, torrent traffic included add in google/facebook/faangs and you arrive at 90% easily.
I thought torrent traffic was generally not encrypted.
Not to mention the world-class encryption used by torrents is RC4. It would be hard to pick a worse cipher (the encryption protocol was designed in 2006).