Live data from Hacker News

Forced Exposure

groklaw.net

51–60 of 430 posts

Re: Forced Exposure

#52
post #46

Lets not try to code our way out of this. We succumb to terror pushing away meaningless bits of code on Github as a crypto projects in response. Some projects flourish sure but the same forces that profit off the court-less killings of others are collating your data, your pet projects. Harvesting your stolen info out of botnets. Giving you a salary for technician work keeping infrastructure ticking. Enough enabling t…

Why is Dell on that list?

"Former intelligence contractor Edward Snowden began downloading documents describing the U.S. government's electronic spying programs while he was working for Dell Inc in April 2012, almost a year earlier than previously reported, according to U.S. officials and other sources familiar with the matter.

...

David Frink, a spokesman for Round Rock, Texas-based Dell, declined to comment on any aspect of Snowden's employment with the company, saying Dell's "customer" - presumably the NSA - had asked Dell not to talk publicly about him.[1]"

[1] http://www.reuters.com/article/2013/08/15/usa-security-snowd...

Re: Forced Exposure

#53
post #30
post #8

How feasible is Freenet for email? We can use PGP today, but the metadata is available to all. But what journalists who need to communicate more anonymously that that used pseudonymous PGP keys - one per story, rather one per person, and posted encrypted messages on Freenet?

It's just non-feasible. Freenet is a distributed file/web database, not realtime internet.

[deleted]

Re: Forced Exposure

#54
post #7

For me, personally, this is much more sad than Lavabit shutting down. Groklaw was an icon, it has huge significance. I do not know whether this - i.e. shutting down - is a good strategy in general. It raises some awareness, it might cause some change ... but what if change does not happens? What other means of protest will we have?

He's not shutting down to raise awareness, but because he feels unable to conduct the blog without feeling his communications with his readers are private.

she/her

Re: Forced Exposure

#55
post #7

For me, personally, this is much more sad than Lavabit shutting down. Groklaw was an icon, it has huge significance. I do not know whether this - i.e. shutting down - is a good strategy in general. It raises some awareness, it might cause some change ... but what if change does not happens? What other means of protest will we have?

My take away from this is she is doing it for her own sanity more than an act of protest. She isn't doing this with the thought that her closing down the site will help spur conversation or change minds but that she can't continue to live a happy, digital life and that the site can't function as intended with the current surveillance. She views privacy and intimacy as a crucial part of both retaining your own humanity and also a part of having a frank and honest discussion.

But I have to say, this is getting to me too... more than I would think something like this would.

Re: Forced Exposure

#56

Holy crap. Groklaw? I'd never for one second thought that the fall out from the NSA debacle would reach so far as to cause Groklaw to be shut down. PJ feels extremely genuine here, she is definitely not using this as an excuse. Wow. There is something very unhealthy in the air or in the water these days. Lots of people seem to be totally immune to the consequences of rampant surveillance and frankly bizarre powers ex…

Seconded. I hope you read HN PJ!

Thank you, PJ, for the invaluable and remarkable work you have done for the FOSS community and, as a consequence, wider society in general over the years. On a personal note, thank you also for helping me with some research for a paper I was writing a couple of years back even though you were a busy person.

Re: Forced Exposure

#57

Lets not try to code our way out of this. We succumb to terror pushing away meaningless bits of code on Github as a crypto projects in response. Some projects flourish sure but the same forces that profit off the court-less killings of others are collating your data, your pet projects. Harvesting your stolen info out of botnets. Giving you a salary for technician work keeping infrastructure ticking. Enough enabling t…

Hello, random new account advising us not to come up with electronic solutions to electronic government surveillance!

>Some projects flourish sure but the same forces that profit off the court-less killings of others are collating your data, your pet projects. Harvesting your stolen info out of botnets.

What in the fuck does this even mean? How is it relevant? The only problem with "fresh" crypto projects is that if you fuck it up, and you have bad crypto, it's as good as no crypto.

Most of us here don't work for those companies, nor do most people being spied on, so this advice sucks.

Legislation and regulation are the long-term methods of stopping this, but the short-term method of dealing with a technological problem is better technology.

Re: Forced Exposure

#58
post #32

Earlier quoted context omitted.

A part-solution. All tech geeks set up mail servers with encryption and volunteer to migrate their non-tech friends and family to new email homes. We also show how to configure encryption in their mail clients and start getting them to use native email clients rather than webmail. This will have two effects. It will send a message to Google/Microsoft/Yahoo!/insert big mail provider here/... that they have been lax in…

> All tech geeks set up mail servers with encryption and volunteer to migrate their non-tech friends and family to new email homes. I certainly wouldn't be comfortable with my peers having the opportunity to control my email and the myriad of accounts associated with it. I can't imagine they would be happy with me doing the same with their data. > We also show how to configure encryption in their mail clients Encrypt…

> Encryption is fairly useless without authentication, and we can safely assume that the NSA has control of Certificate Authorities.

You don't need CA's for e-mail encryption. You need keyrings and networks of trust (I exchange keys with my closest associates via offline means; I sign a certificate stating that I vouch for the authenticity of their certificates; my associates can then choose whether or not to trust the signatures I've signed, and whether to trust the signatures they've signed again).

Yes, there's room for infiltration, but it is vastly better than relying on central CA's for this type of usage, because it allows people you trust to contradict infiltrators.

Re: Forced Exposure

#59
post #7

For me, personally, this is much more sad than Lavabit shutting down. Groklaw was an icon, it has huge significance. I do not know whether this - i.e. shutting down - is a good strategy in general. It raises some awareness, it might cause some change ... but what if change does not happens? What other means of protest will we have?

He's not shutting down to raise awareness, but because he feels unable to conduct the blog without feeling his communications with his readers are private.

She. I remain surprised by how often this mistake is made, given her name is on every page and the whole thing a few years back where someone accused her of being a fiction made up by IBM.

Also, I wonder what the other contributors she had given post privileges to think of this (I thought she had stepped down/away from some of the cases groklaw was covering).

Re: Forced Exposure

#60

Earlier quoted context omitted.

Revolution is not what you think. It consists of the small actions of millions of people. The small actions are usually more revolutionary than the large. The NSA has just created a huge market for guaranteed secure communications infrastructures. The technology is there. It may need some extensions but it is there. Some ideas (again no time for a startup now and this is too important): 1. An email-like service based…

Encoding your own mail means that you are playing by rules of the game NSA has set up. The only way is to make your own game and make them play by YOUR rules. If you encode your communications there is a barrier that they will break down directly by making you disclose the keys while threatening with Tax audits, jail time etc. Or by breaking down encryption commications. They are the largest employer of IT/Security/C…

> Encoding your own mail means that you are playing by rules of the game NSA has set up.

well, actually, I was talking about encoding other people's email, for a fee. The goal is to change the game and change the rules. The NSA has created this market. Let's use this to reshape the game.

> If you encode your communications there is a barrier that they will break down directly by making you disclose the keys while threatening with Tax audits, jail time etc.

This is true, so the game is not just to get your own keys taken care of but everyone else's and locate the business in a country that will be better interested and able to stand up to NSA interests here.

> Or by breaking down encryption commications. They are the largest employer of IT/Security/Cryptographers on the face of the earth.

Again true, which is why the game has to change.

> So the only way to do this is to make them not play their game.

So the new game is to make sure as much traffic as possible is encrypted. All of the above take time. They could bug the end points, they could break down the encryption with massively parallel supercomputers. They could threaten individual users of the service.

So the game is to make sure that everyone encrypts everything every time (or at least that enough do to make individualized efforts prohibitive on a dragnet scale).

We know they don't like that game. They've been trying to get control over all encryption since the days of Clinton but they haven't yet.

> Frankly whole cancerous security apparatus has been fueled by privatized sector just like the one with privatized jail system.

Very true. BTW, read "The Servile State" by Hilaire Belloc if you want a really depressing read....

> Sad to say this but there only way I can see this being resolved is political/etc. Start websites cover the stories. Find methods of figuring out whether they are listening to you or not. For example set up fake drug deals so you can draw them on fact of monitoring your communications. Sue them every instance you find them breaking down your doors. Yeah I know it is not pleasant.

If someone wants to, great. I am not in the US at the moment so my options are more limited.

> Also make working for contractors of NSA and being employee of NSA being a very unpatriotic and scummy thing to do - akin to digging around underwear drawer of your next door granny neighbor.

How do we do that? How many of us know such contractors?

Post reply on HN