Live data from Hacker News

A Saudi Arabia Telecom's Surveillance Pitch

thoughtcrime.org

51–60 of 115 posts

Re: A Saudi Arabia Telecom's Surveillance Pitch

#52
post #37
post #34

Earlier quoted context omitted.

Like Moxie says, money buys technology, and they will eventually find someone to rig up a workable solution for what they're trying to do. Governments are in a unique position here. They can always just move up the stack. Can't break the crypto? That's fine. They can just require the mobile phone companies to sell phones with spyware already included.

That problem is, I think, a showstopper for "anti-circumvention" tools like whatever- the- next- generation- of - Tor will be. Dictatorships have little to lose by backdooring or rootkitting devices; they'll laugh off any outrage stirred up by the discovery of these methods. But the economics flip around in Europe, Japan, the US, &c: governments there do have something to lose by surreptitiously backdooring huge numb…

That problem is, I think, a showstopper for "anti-circumvention" tools like whatever- the- next- generation- of - Tor will be. Dictatorships have little to lose by backdooring or rootkitting devices; they'll laugh off any outrage stirred up by the discovery of these methods.

Well until something like the DIY Cellphone gets more traction to deal with backdooring/rootkitting: https://webcache.googleusercontent.com/search?q=cache:http:/... (MIT Media Lab)

Re: A Saudi Arabia Telecom's Surveillance Pitch

#54
post #17
post #16

Earlier quoted context omitted.

> Nobody trusts CAs. Hundreds of millions of consumers use devices that implicitly trust CAs today. You're usually spot on, but in this case you're dead wrong. Most humans that use the internet use devices that trust CAs absolutely - which is exactly why they're being subverted for government interception.

This boils down to a semantic disagreement. You say people "trust" CAs because they don't know or care about them. I say that to "trust" a CA, you have to know what one is, and nobody who knows what a CA is trusts them anymore. The distinction between these two vantage points isn't particularly relevant to my point; at least, I don't think it is.

The difference is explicit and implicit trust. Even if you explicitly distrust CAs, almost everything on your system implicitly trusts them.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#55
post #24
post #2

This stuff happens more than anyone in infosec wants to admit; it's (ironically) what got me into professional software security to begin with, after being upset by what a commercial network monitoring tool would have allowed us to do to our customers at an ISP I helped run. It's especially funny to see a government sponsored telecom reaching out to Moxie Marlinspike. Also: this isn't like that time a random Microsof…

In this case I was mostly referring to the inclusion of certificate pinning (ex: https://github.com/moxie0/AndroidPinning ) in the mobile apps, which would theoretically prevent them from using a UAE or Saudi controlled CA to do the interception. In addition to iOS and Android, we also refused to compromise with low-end platforms like MediaTek, and made sure those clients were also all-TLS and that they employed cert…

If you really want the world to be a more secure place, can I please ask that you relicense the AndroidPinning code as BSD or something less viral than GPLv3?

I don't see Instagram, Facebook, etc. using that code to secure their apps, they won't license their Android clients as GPLv3 just to use the Android pinning library. While it is easy enough to re-create your code (though I have not looked at it), given that we're talking encryption libs, it's always nicest to have secure, vetted libs that just work.

(As a matter of fact, I'm sure you had to relicense it for Twitter to use it in their app.)

Re: A Saudi Arabia Telecom's Surveillance Pitch

#56
post #44

Earlier quoted context omitted.

It is possible to believe both things at the same time: that dictatorships will inevitably acquire exploits, backdoors, and monitoring tools, and that it's unconscionable for companies to sell these things to dictatorships. The story is perhaps clearer on exploit markets. The alternative to markets is publication, which burns the vulnerability by hastening its patch deployment. Dictatorships will inevitably acquire m…

> dictatorships will inevitably acquire exploits That's not what I mean. Even if you somehow stop them from acquiring exploits, they will remain in power because it's not derived from subtle technological advantages.

If the technological advantages do not help them stay in power, why do you think they would pursue them? And what 'advantage' would they be?

Re: A Saudi Arabia Telecom's Surveillance Pitch

#58
Dear Y Hackers, Please know that there are dumb, non-technical, readers that sit on the sidelines of this site and stare in awe of your courage and abilities. The fact that this article is atop the leaderboard speaks volumes about the community's character. Moxie Marlinspike you are a hero. You are a wonderful writer, and your adventurous spirit is incredibly inspirational. Thank you for sharing your stories. To me this site is a beacon of hope, a daily reminder that remarkably talented people are out there fighting for good.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#59
post #2

This stuff happens more than anyone in infosec wants to admit; it's (ironically) what got me into professional software security to begin with, after being upset by what a commercial network monitoring tool would have allowed us to do to our customers at an ISP I helped run. It's especially funny to see a government sponsored telecom reaching out to Moxie Marlinspike. Also: this isn't like that time a random Microsof…

> money buys technology I don't think it matters. He quickly noticed that the problem is cultural, that >> I’d much rather think about the question of exploit sales in terms of who we welcome to our conferences, who we choose to associate with, and who we choose to exclude, than in terms of legal regulations. I think the contextual shift we’ve seen over the past few years requires that we think critically about what’…

The problem here in Saudi is indifference. People take it as granted: "Of course its being intercepted" or "they know everything, don't even try." Its a decapitating indifference to the extent that people around me are mystified why I have a VPN connection 24/7 on my desktop and mobile phone; why do I even bother? Even many techies around me think I am naive to be taking all these precautions. Resistance is futile.

PS: Mobily is my carrier. Discomforting. Maybe resistance is futile after all. Sigh.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#60
post #24

Earlier quoted context omitted.

In this case I was mostly referring to the inclusion of certificate pinning (ex: https://github.com/moxie0/AndroidPinning ) in the mobile apps, which would theoretically prevent them from using a UAE or Saudi controlled CA to do the interception. In addition to iOS and Android, we also refused to compromise with low-end platforms like MediaTek, and made sure those clients were also all-TLS and that they employed cert…

If you really want the world to be a more secure place, can I please ask that you relicense the AndroidPinning code as BSD or something less viral than GPLv3? I don't see Instagram, Facebook, etc. using that code to secure their apps, they won't license their Android clients as GPLv3 just to use the Android pinning library. While it is easy enough to re-create your code (though I have not looked at it), given that we…

From the README:

>Please contact me if this license doesn't work for you.

I see no reason why Moxie should give Facebook and Instagram this valuable feature for free. When did open-source hackers become the unpaid laborers for silicon valley?

If they want it, they can either release the source code for their applications and liberate their users, or they can pay (hopefully) through the nose for it. Maybe that'll buy a few more months of TextSecure development, or whatever other cool things Moxie is doing now.

Post reply on HN