Live data from Hacker News

Parallel Reconstruction of Lawful TLS Wiretapping

remyhax.xyz

51–60 of 81 posts

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#51

Earlier quoted context omitted.

One day that'll be illegal. End to end encryption? That obviously means you're a drug trafficking money laundering pedophile terrorist. Off to jail with you despite zero evidence. Maybe they'll declare your efforts to protect yourself as being in contempt of court and then jail you indefinitely until full decryption.

Sounds heartwrenching until you see a story like this: https://youtu.be/hKLIxxBrM-o To absolutely no sane person's surprise, the main audience of e.g. anti-censorship platforms is exactly people who typically feel or find themselves censored, which in a harmonious or at least well-functioning society will not be a particularly cheritable set of individuals. In one where that's not the case, the audience would change…

Well-funded criminal networks like the ones in the video you linked would have little issue if all e2ee chat apps disappeared tomorrow, they have enough money and operational incentives to pay someone to make custom encrypted chat apps (not to mention the myriad of open source ones available).

The only people actually hurt by banning e2ee are regular people.

> It's like trying to pretend people are shopping for regular items on .onion webshops rather than for contraband. I'm sure that crowd exists, but like, who are we trying to fool here exactly?

Based on public metrics, 3% of Tor traffic is .onion traffic and it is incredibly likely the vast majority of that is the Facebook .onion service (based on some stats posted by Facebook a few years ago).

So no, I think the burden of proof falls on you to show that the vast majority of .onion usage is illegal.

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#52
post #49

Yes this is to be expected. I've mentioned multiple times over the years that TLS CA issuance & validation's many security holes (>=14 at last count) could be solved by changing how certificates are issued. I've never had the kind of clout to get that message wide enough that anyone would take it serious. One of Web PKI's security holes is the fact that any CA can issue valid certs for any domain. The only official "…

> One of Web PKI's security holes is the fact that any CA can issue valid certs for any domain. The only official "mitigation" for that is voluntary and can be defeated. In case you were not aware, Moxie Marlinspike spoke about this at length back in the early 2010s[1]. His view was that the problem is that certificate authority trust is controlled by the wrong people (web hosts, not users -- or browsers, as a proxy…

You seem to be talking about registries (who manage tlds, so you have no choice for a particular tld). OP talked about registrars (who sell domains, and there's a wide choice). Though I'm not sure how that's supposed to work.

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#53
post #33

Earlier quoted context omitted.

> It is too fragile (multiple point of failure). If your DNS isn't working, you're not going to be making connections anyway. And if you can't keep DNSSEC running, you can't keep certs up to date either. DNSSEC is actually much simpler, with fewer failure points, once you set it up. > It is high volume (=it need be cacheable). It is. Unlike certificates. And the cache lifetimes are much shorter than typical certifica…

It is self-evidently not correct that companies that can't keep DNSSEC running can't keep certs running. Entire TLDs have fallen off the Internet because DNSSEC has broken. A certificate never took Slack down for half a day. It's just obviously not true.

It's amazing what practice and investment can do, even for a fragile system like X.509. Yet certs still break constantly. Like permanently killing people's "perpetual" Microsoft Word licenses in a story posted within hours of this one.

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#54
post #49

Yes this is to be expected. I've mentioned multiple times over the years that TLS CA issuance & validation's many security holes (>=14 at last count) could be solved by changing how certificates are issued. I've never had the kind of clout to get that message wide enough that anyone would take it serious. One of Web PKI's security holes is the fact that any CA can issue valid certs for any domain. The only official "…

> One of Web PKI's security holes is the fact that any CA can issue valid certs for any domain. The only official "mitigation" for that is voluntary and can be defeated. In case you were not aware, Moxie Marlinspike spoke about this at length back in the early 2010s[1]. His view was that the problem is that certificate authority trust is controlled by the wrong people (web hosts, not users -- or browsers, as a proxy…

> is not possible to revoke because once a web host uses a particular CA you are stuck trusting them forever

So, the fun thing about historical claims is that you can do Science (insert sound effect) by assuming they're right to make a prediction from that baseline and comparing what actually happened against that prediction.

Moxie gave that talk in August 2010, hence the "DEF CON 19" background. So almost 16 years ago. Over that time of course there have been numerous incidents that would give you good cause to distrust companies such as DigiNotar, StartCom and Symantec. Moxie's prediction tells us that we were "stuck trusting them forever" but er... nope, DigiNotar went bankrupt, StartCom exists only as some branding for the (now distrusted) Chinese company which bought it, and Symantec "pivoted" away from the CA business and now exists largely as branding as well.

> I am quite disappointed with the fact that clients are expressly forbidden from parsing CAA by RFC 8659.

This is a bad idea because it doesn't signal what you think it does. CAA is a signal about who may issue right now not a signal about who has issued in the past whether that's five seconds ago or five weeks ago. That's why it's a signal for the CAs and not for you.

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#55

Earlier quoted context omitted.

Sounds heartwrenching until you see a story like this: https://youtu.be/hKLIxxBrM-o To absolutely no sane person's surprise, the main audience of e.g. anti-censorship platforms is exactly people who typically feel or find themselves censored, which in a harmonious or at least well-functioning society will not be a particularly cheritable set of individuals. In one where that's not the case, the audience would change…

I skim-watched your link and it doesn’t seem to support your thesis. First, the secure end-to-end encryption was broken by international police and messages were read without making it illegal. Second they suggest reading hundreds of thousands of people’s messages to catch a dozen or so gang members - not supporting your claim that only crooks use it. Third, the video ends by the gang leader saying he was working for…

I have very serious concerns on the human vs LLM effort that went into this comment, but sure, let's go point by point then.

The first counterpoint I can't even decipher, it makes no grammatical sense. Are you saying that law-enforcement-intercepted encrypted messages are not necessarily illegal? ...why would they be? Sounds like a strawman.

The second is explicitly a strawman. I intentionally left space for legitimate use, because it's a trivial rhetorical target, so I just said that it primarily interests "illegitimate" use for now. While I do not have actually comprehensive data on the Sky userbase, the way these devices were distributed, the volume of criminal-use-connected messages uncovered, and the globally dispersed gang use presented in the video did suggest to me exactly what I said. I'm not sure why you think "just catching a dozen or so gang members" is a reasonable takeaway either, given that the video's focus was exactly just those people.

We can take issue with this, and downgrade this to just being evidence of significant (in the statistical terminology sense of the word) criminal use rather than primary criminal use. I just both fail to find that particularly compelling, and don't really feel like arguing on your behalf.

The third counterpoint I also struggle to decipher. It seems to also build on a strawman like the other two points. You accuse me of implying that "criticism of govt is all baseless conspiracy theories". I don't know how you managed to extract such a thing out of what I wrote, so I'm not sure how to respond. Governments around the world are routinely criticized, have plenty of perfectly valid things going against them, on which both the media and the general public report on plenty. It is - thankfully - only a select few places in the world where such speech is actually restricted. Now that was more a part of my point.

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#56
post #51

Earlier quoted context omitted.

Sounds heartwrenching until you see a story like this: https://youtu.be/hKLIxxBrM-o To absolutely no sane person's surprise, the main audience of e.g. anti-censorship platforms is exactly people who typically feel or find themselves censored, which in a harmonious or at least well-functioning society will not be a particularly cheritable set of individuals. In one where that's not the case, the audience would change…

Well-funded criminal networks like the ones in the video you linked would have little issue if all e2ee chat apps disappeared tomorrow, they have enough money and operational incentives to pay someone to make custom encrypted chat apps (not to mention the myriad of open source ones available). The only people actually hurt by banning e2ee are regular people. > It's like trying to pretend people are shopping for regul…

Despite that, for some reason, these well funded criminal networks keep buying into these weird phone deals instead. I genuinely don't understand why, but they do.

> So no, I think the burden of proof falls on you to show that the vast majority of .onion usage is illegal.

How does the burden of proof fall on me for a claim I (intentionally) did not make?

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#57
post #51

Earlier quoted context omitted.

Well-funded criminal networks like the ones in the video you linked would have little issue if all e2ee chat apps disappeared tomorrow, they have enough money and operational incentives to pay someone to make custom encrypted chat apps (not to mention the myriad of open source ones available). The only people actually hurt by banning e2ee are regular people. > It's like trying to pretend people are shopping for regul…

Despite that, for some reason, these well funded criminal networks keep buying into these weird phone deals instead. I genuinely don't understand why, but they do. > So no, I think the burden of proof falls on you to show that the vast majority of .onion usage is illegal. How does the burden of proof fall on me for a claim I (intentionally) did not make?

> Despite that, for some reason, these well funded criminal networks keep buying into these weird phone deals instead. I genuinely don't understand why, but they do.

Given how many of them have been CIA honeypots, they must have amazing marketing.

> How does the burden of proof fall on me for a claim I (intentionally) did not make?

Nice trick -- make a very clear implication and claim that you didn't make a positive claim.

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#58

Earlier quoted context omitted.

I skim-watched your link and it doesn’t seem to support your thesis. First, the secure end-to-end encryption was broken by international police and messages were read without making it illegal. Second they suggest reading hundreds of thousands of people’s messages to catch a dozen or so gang members - not supporting your claim that only crooks use it. Third, the video ends by the gang leader saying he was working for…

I have very serious concerns on the human vs LLM effort that went into this comment, but sure, let's go point by point then. The first counterpoint I can't even decipher, it makes no grammatical sense. Are you saying that law-enforcement-intercepted encrypted messages are not necessarily illegal? ...why would they be? Sounds like a strawman. The second is explicitly a strawman. I intentionally left space for legitima…

The first counterpoint is that you took the position E2E Encrypted messaging will be made illegal because of criminals. The video you linked to support this shows criminals being caught without banning E2E encrypted messaging. Therefore your link does not support the claim that catching criminals needs E2EE apps banning.

The second is not a strawman, you claimed that only criminals are attracted to E2EE messaging when the link you gave showed some 170 thousand users of that specific messaging app with no suggestion that most of them were criminals. "I just said that it primarily interests "illegitimate" use for now" yes you did say that, and that thing you said is not supported by your link.

The third is about your writing about how people who want privacy are performative victims who are falling into anti-government conspiracy theories, but your link shows a thing which was not a conspiracy theory and the government in question actually was accused of targetting their political enemies with gangs, and it would be reasonable to want privacy against such.

> "I don't know how you managed to extract such a thing out of what I wrote"

> "But I digress. I wouldn't wanna spread conspiracy theories after all, would I?"

maybe write less of this winky-face bs and just say what you mean.

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#59
post #57

Earlier quoted context omitted.

Despite that, for some reason, these well funded criminal networks keep buying into these weird phone deals instead. I genuinely don't understand why, but they do. > So no, I think the burden of proof falls on you to show that the vast majority of .onion usage is illegal. How does the burden of proof fall on me for a claim I (intentionally) did not make?

> Despite that, for some reason, these well funded criminal networks keep buying into these weird phone deals instead. I genuinely don't understand why, but they do. Given how many of them have been CIA honeypots, they must have amazing marketing. > How does the burden of proof fall on me for a claim I (intentionally) did not make? Nice trick -- make a very clear implication and claim that you didn't make a positive…

The implication (representing a belief, not a claim) was about the nature of item purchases on .onion webshops (that they're primarily contraband), not about the composition of .onion or Tor traffic. If anything, the attempt to pivot to that was a trick.

You may still fault me for mixing in beliefs into an argument, it is of poor form from me. Up to you. But then I don't think sentiments are just pure hard logic and evidence, so it'd have been potentially more dishonest from me to exclude it than to not.

Re: Parallel Reconstruction of Lawful TLS Wiretapping

#60

Yes this is to be expected. I've mentioned multiple times over the years that TLS CA issuance & validation's many security holes (>=14 at last count) could be solved by changing how certificates are issued. I've never had the kind of clout to get that message wide enough that anyone would take it serious. One of Web PKI's security holes is the fact that any CA can issue valid certs for any domain. The only official "…

If the wrong CA issued a certificate then wouldn’t that show up in the transparency logs? It seems like by monitoring them, you could see if a security bug is being exploited.
Post reply on HN