Live data from Hacker News

Prism Break

prism-break.org

51–60 of 205 posts

Re: Prism Break

#51
post #37
post #35

Earlier quoted context omitted.

When Google.com's certificate was faked, it was discovered because Chrome restricts what CAs are allowed to sign Google's certificates, if I recall correctly.

Google does that for a number of other non-Google sites, too.

Pretty sure its just google sites, because otherwise you might get false positives as other sites change servers/ips/certificates/etc

Re: Prism Break

#52
post #51
post #37

Earlier quoted context omitted.

Google does that for a number of other non-Google sites, too.

Pretty sure its just google sites, because otherwise you might get false positives as other sites change servers/ips/certificates/etc

Be less sure. Google provides certificate pinning as a service to other sites, who request it specifically.

Re: Prism Break

#53
Cyanogenmod should have a big asterisk beside it noting that it's system is signed with PUBLICLY AVAILABLE KEYS. Also they have just the same proprietary blobs (most of them) that other android devices have (radio firmware, camera drivers, etc) that have just been pulled out of shipping factory android images. The description (without these) is playing people false IMO

Re: Prism Break

#54
post #49
post #14

Earlier quoted context omitted.

> None of the proprietary browsers will track you. Can you elaborate a bit on this, how do you know they won't? My default assumption is that anything I can't see the source code of and compile myself is compromised.

>My default assumption is that anything I can't see the source code of and compile myself is compromised. Did you also write and compile the compiler that compiled your compiler?

He very well may have, since you compile gcc using gcc.

Re: Prism Break

#55
post #49

Earlier quoted context omitted.

>My default assumption is that anything I can't see the source code of and compile myself is compromised. Did you also write and compile the compiler that compiled your compiler?

He very well may have, since you compile gcc using gcc.

And where did the bin version of GCC he or she used to compile that version of GCC come from?

Eventually, somewhere down the chain, you have to have trusted a compiler that wasn't GCC and you probably don't have the source to.

Re: Prism Break

#56

New poster here, but someone needs to say this. Tor is amazing and great, but if you don't think the US/NSA don't know how to run their own Tor hops and cache the very same traffic that you think is on "anonymous" servers. . . then you have a more serious problem of understanding how this works. It's easy to run Tor servers. Even easier when you have an NSA budget. Also, ask yourself why wouldn't they be running thou…

Welcome! Don't worry, most of us know this, and those that don't are constantly being shouted at by everyone else.

Re: Prism Break

#57
Is there any indication that this isn't disinformation geared toward a false sense of security? Call your government representatives instead, it'll have a greater effect.

Re: Prism Break

#59
post #11

Surprised Arch Linux [1] isn't listed. It's probably one of the most secure distros by limiting the installed packages to a bare minimum. Combine that with App Armour (or SELinux designed by the NSA) with a firewall and basic network monitoring to protect against rootkits. Plus always-on VPN, dm-crypted harddrive, noscript etc. NSA also released SEAndroid [2] which hardens Android significantly. It's included preinst…

I'm more surprised that Mint is being suggested at all in this. Considering how ridiculous this list is in the first place, the 'curator' should have noted that Mint, by default, installs search engines that are partnered with Mint[1]. Even more surprising is that BSD just got a cursory mention. You may as well switch to OpenBSD if you're going to switch to a majority of these alternatives. [1] http://www.linuxmint.c…

You are being obtuse. There is an entire subsection on search engines and Mint can be configured to use them.

Re: Prism Break

#60
post #20

If you're going to continue using Google Mail, it's a dumb idea to deliberately switch away from Chrome. The connection between Gmail and Chrome is among the more carefully guarded TLS connections on the Internet.

Google works for the NSA. Avoid.
Post reply on HN