Live data from Hacker News

Snowden Meets the IETF

mnot.net

51–60 of 80 posts

Re: Snowden Meets the IETF

#51

Earlier quoted context omitted.

Blockchain-based decentralization looks somewhat easier to monetize.

What we see in practice with all extant implementations of blockchains is increasing centralisation. Because computing hashes is the sort of computation whose efficiency per watt greatly increases with more and more specialised hardware. Thus the Bitcoin situation, where the promise of everyone being able to mine a few coins has become a small number of Chinese mining pools; altcoins do no better.

> altcoins do no better.

Most altcoins are Proof of Stake, where mining via computing hashes doesn't take place. "Blockchains" isn't limited to Proof of Work, you can even get non-PoS/PoW blockchains such as Hyperledger.

Re: Snowden Meets the IETF

#52

Earlier quoted context omitted.

>encryption lets me back up files to cloud services that I don't trust Any recommendation on an accessible, audited , client for Windows users? Running some company's random binary, especially when you log in and they can identify you, implies a fair amount of trust. Tarsnap's the best one I know of and it's not really accessible for most users.

Not sure what you mean by "accessible", so I'll go from easiest to least easy: Truecrypt has been audited, works on Windows, and appears to offer an encrypted file container that you can attach to a Windows drive letter. What you could do is create the container, let DropBox (or whatever) sync the file containing the container, then perform your file operations within the container. Depending on your needs, there's a…

Dropbox isn't audited. They have a poor track record for security (lying about internal access then trying to downplay). So even if you encrypt with truecrypt, you're running the Dropbox binary for uploading, and it can do anything - in short, you're trusting them.

I've not found an open source tool that does block level backups with diff/compression support. Getting the client experience right is hard and not a whole lot of fun, so I'm guessing there's little incentive for companies to open source that valuable part.

Thanks for the info on Erlang.

Re: Snowden Meets the IETF

#53
post #2

It must have been an exciting surprise for attendees. I'm glad Snowden said DNS should be encrypted. From the tweet stream provided by @conflictmedia, that was tied for 1st for most re-tweeted, along with making the Internet for users, not spies. (It should be noted that DNSSEC is not encrypted.) Too bad his appearance wasn't recorded, but HUGE thanks to Niels ten Oever and Rich Salz for tweeting major points!

If a future DNS improvement (hopefully, blockchain based) starts providing SSL keys to reduce the latency required for an SSL connection on HTTP/2 (skipping the "Connection: Upgrade") and on HTTP/1 (when being redirected from http to https), it would provide advantages and would also encourage encrypted DNS queries.

Re: Snowden Meets the IETF

#54

Earlier quoted context omitted.

Not sure what you mean by "accessible", so I'll go from easiest to least easy: Truecrypt has been audited, works on Windows, and appears to offer an encrypted file container that you can attach to a Windows drive letter. What you could do is create the container, let DropBox (or whatever) sync the file containing the container, then perform your file operations within the container. Depending on your needs, there's a…

Dropbox isn't audited. They have a poor track record for security (lying about internal access then trying to downplay). So even if you encrypt with truecrypt, you're running the Dropbox binary for uploading, and it can do anything - in short, you're trusting them. I've not found an open source tool that does block level backups with diff/compression support. Getting the client experience right is hard and not a whol…

I keep a list of cloud sync solutions I've looked at for a similar use case: https://github.com/pjc50/pjc50.github.io/blob/master/secure-...

I'm still not quite satisfied either.

Re: Snowden Meets the IETF

#55

Earlier quoted context omitted.

Not sure what you mean by "accessible", so I'll go from easiest to least easy: Truecrypt has been audited, works on Windows, and appears to offer an encrypted file container that you can attach to a Windows drive letter. What you could do is create the container, let DropBox (or whatever) sync the file containing the container, then perform your file operations within the container. Depending on your needs, there's a…

Dropbox isn't audited. They have a poor track record for security (lying about internal access then trying to downplay). So even if you encrypt with truecrypt, you're running the Dropbox binary for uploading, and it can do anything - in short, you're trusting them. I've not found an open source tool that does block level backups with diff/compression support. Getting the client experience right is hard and not a whol…

Oh! You were looking for audited sync clients.

Yeah, I've got nothing there.

Edit: I would ask "How hard could it be to solve 90% of the problem?", but various BigCos have had spectacular failures in recent memory, so I guess the problem is pretty damn hard.

I wonder how terrible using git as the backbone for one's sync software would be.

Re: Snowden Meets the IETF

#56
post #33

Earlier quoted context omitted.

> I'm glad Snowden said DNS should be encrypted. And yet, when HBO screwed up their dnssec config and Comcast blocked the site, how did users react? By demanding Comcast stop verifying! (Fully encrypted DNS can only fail in even more ways than dnssec.)

> (Fully encrypted DNS can only fail in even more ways than dnssec.) The main reasons DNSSEC fails frequently are: * pre-computed signatures, rather than online signing * a demented, overly complex protocol * signatures that expire rapidly Maybe tptacek can name some others. The only DNS encryption people are currently using (DNSCurve/DNSCrypt) does per-packet encryption, with a very simple protocol involving only a…

> and no signatures.

It's probably time to retire unauthenticated encryption as useless.

Now, if what you meant is that it uses AEAD, that amounts to the same thing as a signature. It has all the same failure modes, namely failure to authenticate.

DNSSEC is a clusterfuck, but if somebody can't put the right public key in the right place, I'm not convinced they'll be able to put the right public key in the right record with DNSCurve either. The exact same thing will happen, and then the solution will be "click here to disable dnscurve".

Re: Snowden Meets the IETF

#57
post #3

The more I consider the ramifications of these news reports, the more I realize we need full decentralization and total encryption. We have the tech: Strong encryption, Tor-like relays, and the blockchain. What we need is a way to make services based on these technologies not just as easy to use but easier to use for the average Jane. If the internet as we know it is to survive, we have to crack this nut.

I really hope http://maidsafe.net/ doesn't end up being forever perfected and never released.

Re: Snowden Meets the IETF

#58
post #31
post #26

Earlier quoted context omitted.

Not sure if you've ever heard of Bruce Schneier, but he is regarded by many as the father of modern cryptography. He also happens to know a thing or two about security, and frequently testifies to the US government such as the Senate on cybersecurity related matters. Here are a few of his thoughts on the matter: https://www.schneier.com/blog/archives/2009/02/balancing_sec... https://www.schneier.com/blog/archives/200…

|he is regarded by many as the father of modern cryptography No, he both isn't that and isn't regarded as that either.

Seriously. But the man is very well respected in the security industry, though.

Re: Snowden Meets the IETF

#60

Earlier quoted context omitted.

We don't have the tech for two important, related things: user-friendly, trust management tools as effective as in person; key management for various, complex scenarios. These two have so many issues that even technical people screw up. I've certainly seen a lot of good work on these. Yet, we're not there yet and getting there is worth a ton of effort by anyone who will try. We get that, then we might integrate it wi…

Seen keybase.io? I think that's one of the best stabs in this direction I've seen so far.

It looks better than manual GPG but not quite there yet for majority acceptance. Need a lot more work on visual alternatives to this sort of thing. Whatever is mass market will be easy for them to mentally visualize and connect dots. Implies the solution will likely be visual (eg GUI).
Post reply on HN