Live data from Hacker News

Protecting Against Leakers

schneier.com

51–56 of 56 posts

Re: Protecting Against Leakers

#51
post #34

I'm not happy hearing the unqualified statement "we need secrecy" being banded around without any opposition.

How about replacing it with 'privacy'? We all need privacy and politicians are not an exception.

I would argue that politicians ARE an exception. They are the most public figures, and they do enjoy a unique status. They should have no professional privacy whatsoever; their personal privacy can be on par with celebrities etc.

Re: Protecting Against Leakers

#52
In a sense, Snowden was whistle-blowing on himself! whenever you have lower level employees given such tremenous power without auditing and checks, the system is open to abuse. He has shown that a conspiracy of one can engage in very significant and very bad actions. What if he did such things and told no one?

Re: Protecting Against Leakers

#53

Earlier quoted context omitted.

From Julian Assange's old blog: http://cryptome.org/0002/ja-conspiracies.pdf http://web.archive.org/web/20071020051936/http://iq.org/#The... ---- Sun 31 Dec 2006 : The non linear effects of leaks on unjust systems of governance You may want to read The Road to Hanoi or Conspiracy as Governance ; an obscure motivational document, almost useless in light of its decontextualization and perhaps even then. But if you read…

Hmm... a corollary might be that startups (insecure due to their very nature) have a huge edge with regards to standard institutions, precisely because they don't have to deal with security problems. So, as they grow bigger, they become more inefficient and customers more unhappy (see: Paypal). I hope there are ways to mitigate this.

It's not all bad for the powerful to have to work harder to use their power than might the meek.

Re: Protecting Against Leakers

#54
post #50
post #47

Earlier quoted context omitted.

I present a 4th scenario: These systems are on 'known good networks' staffed by people who have some of the most extensive vetting you can get. These are the folks who invented (or funded the development of) RBAC and the like. SELinux came out of NSA, for example. The tech exists, but it's a hastle to work with. If you've got fully-cleared, all-known-good actors, why bother? It's not like it's on the internet, or acc…

"Maybe they also put too much faith in the vetting process and external shell and less on protections within the chewy center." They put a lot of effort into screening staff, but they're also the most attractive target for well-funded adversaries (Russia, China, etc.). The only stuff I've ever seen come out of NSA and actually used by anyone in government that hasn't been crap has been hardware. SELinux, etc. are a s…

I can see why trust their people and their vetting process. They get to read your email and snoop through your browsing history before they hire you.

Re: Protecting Against Leakers

#55
> A public or private organization's best defense against whistle-blowers is to refrain from doing things it doesn't want to read about on the front page of the newspaper.

I feel like this hasn't been said enough in the debates surrounding the surveillance leaks.

Re: Protecting Against Leakers

#56
post #9

Earlier quoted context omitted.

It would be interesting to consider a world that is truly without secrets, even of obscurity. It's possible we might get there. I think the way companies and so forth do their work could end up being adjusted to cope.

'The dead past'. Isaac Asimov, 1956.

I just read that. Thanks for pointing it out. The parallels to the present day are striking and disturbing.
Post reply on HN