For me, this incident is an example where the U.S. democracy failed, pure and simple. Obama made campaign promises to not do surveillance. He was elected and then did it anyway. It's frankly impossible now to change this issue in a democratic fashion. From the outside it often looks as if American politicians are overly busy with a very expensive "game", rather than using the game for the greater good.
Why we can't go back to business as usual post-PRISM
61–70 of 186 posts
Re: Why we can't go back to business as usual post-PRISM
#62This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…
The difference now is two issues: (1) Previously, various official sources have denied this sort of thing was happening. As a specific example, Congress has asked and been told that universal surveillance of US citizens was not occurring, and the plain-text meaning of the law makes universal surveillance of US citizens illegal. (Now we are told that this is contradicted by a secret legal opinion.) (2) Frog boiling. Y…
(2) You do know that Friedrich Goltz, the creator of the "Boiling Frog" experiment had the brains of the frogs removed, only then these did not jump out of the heating water - I hope you're using the reference to this experiment intentionally that way
Re: Why we can't go back to business as usual post-PRISM
#63I'm a peaceful person, but this issue has been simmering in my head for years, and I find myself actually looking forward to some kind of meaningful conflict. I'm sick, sick, sick to death of the president issuing denials while they keep building more and more infrastructure against humanity. I think the article is right, that it'll get worse from here, and in a way, I'm glad.
Last time people were looking forward to a meaningful conflict, it plunged the whole world into 4 years of war, followed by another 7. Be careful what you wish for. We need a peaceful solution for this. Vote these people away. Replace them by better people. Educate those who think they have nothing to hide.
Re: Why we can't go back to business as usual post-PRISM
#64This whole thing is so bizarre to me. The NSA has been doing this sort of thing since at least the early 90s. Who knows, probably earlier. What exactly did people think the NSA was doing? The only difference is that, before digital cell service, it was more difficult to monitor phones conversations because the infrastructure simply didn't support it. Everyone's all riled up over a few PowerPoint slides (which may ver…
What I'm about to say is absolutely nuts, but it could be that this is something the NSA leaked intentionally and the media is running with it for reasons we are not aware of. Despite twitter and the like, the mainstream media is still largely in control of what occupies the "news" and therefore what the otherwise apathetic public is concerned about.
Do they want to reassure us of their best efforts in protecting us from terrorism?
I can't imagine a scenario existing where the tables might eventually turn & those who were once appalled & angry that the NSA was so into everything change their minds and become reassured that the gov't is actually on their game & has the means to get some outrageous terrorist threat we couldn't have imagined under control again because of their broad wiretapping capabilities.
Re: Why we can't go back to business as usual post-PRISM
#65Of course we can go back to business as usual post-PRISM, because PRISM turned out to be absolutely nothing. It's a mundane, boring data storage & analysis system for data obtained through FISA requests about specific individuals. It's not a data dump from major tech companies, it's not a warrant-less spy program, etc...
Re: Why we can't go back to business as usual post-PRISM
#66Earlier quoted context omitted.
Here's my view. I recently wrote an article on my blog ( http://ledgersmbdev.blogspot.com/2013/06/tangent-design-thou... ) which was on the front page of HN for a while. I want to summarize both my thoughts again and things that have occurred to me after writing it. All of our existing key interchange systems are amazingly brittle. With X509, there's no reason to assume the NSA couldn't order verisign to produce a ce…
Put a better interface on GPG to make managing web-of-trust not a nightmare. The infrastructure has existed for a long time, but using it is amazingly unfriendly. It gets more interesting when you consider a model like off-the-record encryption, where the goal isn't encryption and verification but deniability. OTR has the great property of ensuring that any time you manage to decrypt or intercept a message, you've al…
Foolproof software is operated by fools. Facebook has only proven that to an extent that you simply can't deny it anymore.
If fools use PGP/GPG, they will compromise you by putting the message in the subject and encrypting their disclaimer/footer.
OTR uses, iirc, AES and DH-kex, that are the same basic building blocks like RSA and AES or any other symmetric cipher you like to use for PGP/GPG/SSL. OTR adds deniability which is fancy for privacy but won't do for other scenarios (like business, money, profit), it works fine in one to one sessions, but group sessions are off the record.
We can conclude that OTR is fine for chat, sorry to hear google dropped the interoperability protocol in hangouts, take a wild guess why.
PGP/GPG can sent to group-messages (one message encryped for multiple recipients and may optional provide proof of the sender), does not imply any protocol like XMPP, and stores messags in a secure manner too. The drawback is, you have to take care of your private-key and your friens, partners, business-associates public-keys.
If somebody really inists that key management sucks with GPG/PGP let them do some key management and distribution only with a symmetric cipher.
Key-Managment with PGP/GPG is a light, soft breeze compared to that. Some people even used it as an excuse to party.
I understand why people have dropped privacy and anonmyity, it is no fun to follow procedure and there are so less benefits compared to every other social media app, it is so comfy to state you have nothing to hide and not care about the implications.
With PGP/GPG you won't have 600 friends, that means caring about 600 keys, that is basically one revoke a week if you are lucky and all you friends master crypto and revoking and getting their new key signed.
If you want to understand a bit crypto it may take a good tutor to teach you the very basic concepts and history of using crypto within 2 schooldays, 16h (and they'll hate you afterwards and they won't pay that).
Re: Why we can't go back to business as usual post-PRISM
#67Earlier quoted context omitted.
A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. So it was easy to imagine that only a few things were being intercepted: Communications be an amorphous "bad people". A distant problem for someone else. In the mean time digital communications devices, cloud services, socia…
A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. The fact that this is happening to _everyone_... Has this actually changed? Is there any evidence that a U.S. citizen's gmail account, or skype calls, or yahoo searches, or facebook information, has been obtained without a c…
Why are you ok with that?
Re: Why we can't go back to business as usual post-PRISM
#68https://mailman.stanford.edu/pipermail/liberationtech/2013-J...
Re: Why we can't go back to business as usual post-PRISM
#69Earlier quoted context omitted.
A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. So it was easy to imagine that only a few things were being intercepted: Communications be an amorphous "bad people". A distant problem for someone else. In the mean time digital communications devices, cloud services, socia…
A lot of people— sometimes the most technically competent ones— were busily telling them that wholesale surveillance was infeasible... greatly underestimating the available funding and ingenuity. The fact that this is happening to _everyone_... Has this actually changed? Is there any evidence that a U.S. citizen's gmail account, or skype calls, or yahoo searches, or facebook information, has been obtained without a c…
Re: Why we can't go back to business as usual post-PRISM
#70Earlier quoted context omitted.
> He was elected and then did it anyway. It's frankly impossible now to change this issue in a democratic fashion. And this is an intentional feature of the system. It's in the Constitution . That's what term lengths are for . The American people never understood how to hold enough power to keep the governmental branches in check. They're too busy feeling self-righteously indignant to actually keep ahold of any power…
While I have my quibbles with the American Constitution, I do understand that politicians in a representative democracy are not bound to the will of their voters. I still object in this instance because promises were broken, and in a significant, yet to be determined, portion of the population the spirit of the constitution was broken as well.
The fact that we ever even anticipate that a promises involving specific things ought to be made is a mistake in our civic education. It is a goddamned stupid expectation to have of elected officials. They give an oath. That oath defines their job.
Campaign promises should never be made, but no one significant can be elected without them. We ask them to lie and then are shocked when they do.
> and in a significant, yet to be determined, portion of the population the spirit of the constitution was broken as well.
But democracy, as an institution, is built to anticipate such failures. That's why there are impeachment procedures. That's why there are checks and balances. That's why there is civil disobedience. You can't call this a failure of democracy until those break down as well. (And, I concede, they probably will.)