Live data from Hacker News

What the CIA WikiLeaks Dump Tells Us: Encryption Works

nytimes.com

61–70 of 270 posts

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#61
post #37

Earlier quoted context omitted.

I think you are being too strict in your definition of 'secure'. 99.99% of devices run Android, iOS or Windows which are closed source and therefore not 'secure'. To me, security is not a binary property but rather a sliding scale. WhatsApp say they use end-to-end encryption and they have a strong financial incentive to be telling the truth. No hacker has demonstrated that WhatsApp are lying and the Wikileaks dump su…

https://source.android.com/ The source code for Android is open under the Apache 2.0 license. Of course, iOS and Windows are closed source.

Well my keyboard app is closed source, and I even imported the binary from the US to my country. Naturally I consider my phone compromised.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#62
post #51

Earlier quoted context omitted.

We can't do anything about the phone number requirement?

Actually magic link sent to your email would be MUCH better. Also central authority but Gmail >>> any telecom

> Also central authority but Gmail >>> any telecom

There's few of the big corps I trust as little as Google.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#63

This world we live in... the Associated Press permeates through nearly all of the US's media. They are the same reason you can find newscasts about some random throwaway story being repeated word-for-word verbatim. When you have dozens of news anchors across the country reading the exact same words from a teleprompter to push a story, something is very very wrong. I mean, it's nice that the NY Times specifies "By THE…

Wire services such as AP and Reuters have always been used heavily by papers (?!)

If anything they are used a little less now because there are more third party originating news services and syndication channel.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#64
post #37

Earlier quoted context omitted.

It seems that most people are completely in the dark when it comes to security, including myself, but there are some principles that should be unwavering that regularly get ignored again with every new iteration of "secure" software: * If there is a weak layer in the stack, from the physical layer to to UI, then the system is not secure. Even if your messaging app is secure, your messages are not secure if your OS is…

I think you are being too strict in your definition of 'secure'. 99.99% of devices run Android, iOS or Windows which are closed source and therefore not 'secure'. To me, security is not a binary property but rather a sliding scale. WhatsApp say they use end-to-end encryption and they have a strong financial incentive to be telling the truth. No hacker has demonstrated that WhatsApp are lying and the Wikileaks dump su…

That's the point. Android and iOS are not secure. Now the question is always, secure for what ? Against an average attacker, they are secure enough. Against the CIA, they are not. They can just threaten several people inside Google or Apple, get a back-door, and you can't check if they did.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#66
post #51

Earlier quoted context omitted.

Actually magic link sent to your email would be MUCH better. Also central authority but Gmail >>> any telecom

It also doesn't have to be a central authority, since "anyone" (meaning: anyone who can afford to operate a mailserver, which is actually a surprisingly-high number) can be such an authority for one's own mail.

I used to run my own but I can't find anyone to relay the mail anymore.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#67
I don't see any mention of quantum computers in here so I thought I'd mention:

the NSA themselves are concerned that quantum computing will be a great threat to encryption in the near future.

Keep in mind that the NSA and god knows who else are storing encrypted communications to break them later.

Quantum computing will defeat RSA, DH, ECC, asymmetric crypto, but it will only weaken symmetric crypto (eg. AES) by a factor of two.

So according to my Internet research: if your symmetric crypto is twice as secure (key size) as needs be, it is future proof.

Also (and please correct me if I'm wrong) I believe the triple encryption Serpent(Twofish(AES)) available in VeraCrypt (TrueCrypt fork) even protects against weaknesses which may be discovered in any of these cryptosystems: they would have to defeat all three.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#68
post #37

Earlier quoted context omitted.

It seems that most people are completely in the dark when it comes to security, including myself, but there are some principles that should be unwavering that regularly get ignored again with every new iteration of "secure" software: * If there is a weak layer in the stack, from the physical layer to to UI, then the system is not secure. Even if your messaging app is secure, your messages are not secure if your OS is…

I think you are being too strict in your definition of 'secure'. 99.99% of devices run Android, iOS or Windows which are closed source and therefore not 'secure'. To me, security is not a binary property but rather a sliding scale. WhatsApp say they use end-to-end encryption and they have a strong financial incentive to be telling the truth. No hacker has demonstrated that WhatsApp are lying and the Wikileaks dump su…

> WhatsApp say they use end-to-end encryption and they have a strong financial incentive to be telling the truth.

I'm not giving much to the various "whatsapp backdoor" allegations but I'm curious to why they'd have financial incentive to provide privacy.

Most of their userbase likely still doesn't care about security and they do belong to Facebook - so if anything, they'd have a financial incentive not to use effective crypto.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#69
If it didn't you wouldn't see Comey all over the place trying to promote his encryption backdoors.

Ironically enough, he's promoting them while saying "Americans don't have absolute privacy."

Yes, we know. That's why we're trying to use encryption more...But thanks for reminding us, James.

Re: What the CIA WikiLeaks Dump Tells Us: Encryption Works

#70
Does anyone here have an air-gapped computer setup?

I'm thinking of doing something with raspberry pi.

I'm stuck at the part where it communicates (for my purposes, small amounts of ascii) with a non airgapped computer without using USB or networking.

I'm thinking about giving both machines a little speaker and microphone and using high frequency pulses to transfer the text.

Why, you may be wondering?

1. Airgapped system is impervious to penetration

2. Can be used for literally unbreakable communications.

Post reply on HN