Live data from Hacker News

Prism Break

prism-break.org

61–70 of 205 posts

Re: Prism Break

#61
post #47
post #8

Several of these suggestions seem somewhat disingenuous - e.g. many of them to be about free software more than actual concerns about tracking, as reflected in the labels "Proprietary" and "Free alternatives". In particular: - None of the proprietary browsers will track you - well, beyond what's specified in the privacy policy. Two of the alternatives are Tor applications, but the other two are Firefox (which provide…

In relation to OSX, Windows, Chrome, IE, etc, I thought it was more to do with the fact that Apple, Microsoft and Google have all willingly turned over data to the feds...

> Apple, Microsoft and Google have all willingly turned over data to the feds

More like gave direct access to their backends. [1]

[1] https://www.youtube.com/watch?v=StlFKE_UVI4

Re: Prism Break

#62
post #20

If you're going to continue using Google Mail, it's a dumb idea to deliberately switch away from Chrome. The connection between Gmail and Chrome is among the more carefully guarded TLS connections on the Internet.

Google works for the NSA. Avoid.

If you think you can do as robust a job at securing your mail as Google does with Gmail, by all means. But I'd feel awfully dumb if I migrated from Gmail to some other web mail provider only to lose my mail to a 17 year old with a Perl script.

Re: Prism Break

#63
post #20

If you're going to continue using Google Mail, it's a dumb idea to deliberately switch away from Chrome. The connection between Gmail and Chrome is among the more carefully guarded TLS connections on the Internet.

It's cute how many people think nobody can break free from gmail.

Also, what's the point of having a "carefully guarded TLS connections on the Internet", if at least one of the ends is completely compromised?

Re: Prism Break

#64
post #55

Earlier quoted context omitted.

He very well may have, since you compile gcc using gcc.

And where did the bin version of GCC he or she used to compile that version of GCC come from? Eventually, somewhere down the chain, you have to have trusted a compiler that wasn't GCC and you probably don't have the source to.

Diff the binaries :)

Re: Prism Break

#65
post #63
post #20

If you're going to continue using Google Mail, it's a dumb idea to deliberately switch away from Chrome. The connection between Gmail and Chrome is among the more carefully guarded TLS connections on the Internet.

It's cute how many people think nobody can break free from gmail. Also, what's the point of having a "carefully guarded TLS connections on the Internet", if at least one of the ends is completely compromised?

My comment didn't say "nobody can break free from gmail", but I'm happy to provide a coat rack on which to hang that argument.

Re: Prism Break

#66
Quite aside from protecting your data from the NSA, this site has a lot of software it's good to be aware of -- Jitsi, git-annex, Etherpad [1], and Piwik seem particularly interesting.

[1] I've seen Etherpad mentioned multiple times on HN, but I somehow never realized that it's self-hosted FOSS.

Re: Prism Break

#67
sharefest.me is another alternative to secured file sharing. The main advantage is browser only - sandbox security. And p2p - files don't touch the server. Although not yet as secured as the other, we're working to improve it. Would love any security feedback on github.com/peer5/sharefest/issues

Re: Prism Break

#68
post #53

Cyanogenmod should have a big asterisk beside it noting that it's system is signed with PUBLICLY AVAILABLE KEYS. Also they have just the same proprietary blobs (most of them) that other android devices have (radio firmware, camera drivers, etc) that have just been pulled out of shipping factory android images. The description (without these) is playing people false IMO

Ugh, really? So is there no smartphone OS that you can be at-least-sort-of certain doesn't have a backdoor (leaving aside unintentional exploits)? My understanding was that even FFOS was built on top of an Android kernel...

Re: Prism Break

#69
post #64
post #55

Earlier quoted context omitted.

And where did the bin version of GCC he or she used to compile that version of GCC come from? Eventually, somewhere down the chain, you have to have trusted a compiler that wasn't GCC and you probably don't have the source to.

Diff the binaries :)

If they really want to get you they could use a birthday attack?

Since we are talking about checking the compiler that compiles your compiler here.

Re: Prism Break

#70
post #64
post #55

Earlier quoted context omitted.

And where did the bin version of GCC he or she used to compile that version of GCC come from? Eventually, somewhere down the chain, you have to have trusted a compiler that wasn't GCC and you probably don't have the source to.

Diff the binaries :)

Which a diff tool you compiled your self, or looking at the hard drive with a magnifying glass?
Post reply on HN