Live data from Hacker News

Snowden Meets the IETF

mnot.net

61–70 of 80 posts

Re: Snowden Meets the IETF

#61
post #34

Earlier quoted context omitted.

> there are better technical ways Sorry I'm a non-devops programmer ;) bad me. What are the better ways? HTTP 403 and friends? (Praying that you won't say "a .exe to fix the browser's access to porn")

Router-level blocklists/firewalling are the most common, but there are other ways. Think of how companies sanely implement their internal web access filters.

I've never seen a company that sanely implement their filters. How do they do that?

Unless you consider it sane to block anything that is not http.

But, well, the idea of filtering bad things from the internet is insane enough by itself.

Re: Snowden Meets the IETF

#63
post #2

It must have been an exciting surprise for attendees. I'm glad Snowden said DNS should be encrypted. From the tweet stream provided by @conflictmedia, that was tied for 1st for most re-tweeted, along with making the Internet for users, not spies. (It should be noted that DNSSEC is not encrypted.) Too bad his appearance wasn't recorded, but HUGE thanks to Niels ten Oever and Rich Salz for tweeting major points!

This is where I get to plug djbdns and DNSCURVE over DNSSEC. I think DJ has been ahead of the curve (no pun intended) on these things for quite some time. I am currently in the process of migrating from bind9 (and avoiding bind10 like the plague) to djbdns wherever possible. Quirks and lack of updates/extensions not withstanding, it's great so far. http://dnscurve.org/integration.html

I think that's a mistake. You are using abandoned software: djbdns 1.05 was released in 2001. It even has a published security flaw from 2009, for which the $1000 guarantee was paid by DJB, and yet there is still no official release to fix the issue (there is a patch available from other sources).

There is a fairly healthy ecosystem of BIND alternatives these days, but djbdns is not one of them.

Re: Snowden Meets the IETF

#64
post #3

The more I consider the ramifications of these news reports, the more I realize we need full decentralization and total encryption. We have the tech: Strong encryption, Tor-like relays, and the blockchain. What we need is a way to make services based on these technologies not just as easy to use but easier to use for the average Jane. If the internet as we know it is to survive, we have to crack this nut.

[deleted]

Re: Snowden Meets the IETF

#65
post #63

Earlier quoted context omitted.

This is where I get to plug djbdns and DNSCURVE over DNSSEC. I think DJ has been ahead of the curve (no pun intended) on these things for quite some time. I am currently in the process of migrating from bind9 (and avoiding bind10 like the plague) to djbdns wherever possible. Quirks and lack of updates/extensions not withstanding, it's great so far. http://dnscurve.org/integration.html

I think that's a mistake. You are using abandoned software: djbdns 1.05 was released in 2001. It even has a published security flaw from 2009, for which the $1000 guarantee was paid by DJB, and yet there is still no official release to fix the issue (there is a patch available from other sources). There is a fairly healthy ecosystem of BIND alternatives these days, but djbdns is not one of them.

This one? http://article.gmane.org/gmane.network.djbdns/13864 It is a little disappointing he didn't issue a new release with the patch included. Perhaps it can be rationalized that the original fork is abandoned, but distro-maintained forks are fine.

As someone who runs tinydns to serve a few personal domains, I'd be interested to hear of another simple, solid option, if it fixes any concrete problems a recent Ubuntu build of tinydns has.

Re: Snowden Meets the IETF

#66
Well, luckily for humanity this is exactly what I've been coding full time since December of 2014, dedicating my life to. I have been designing it for many years.

My vision is complete and planned, all the way until The World Brain! See: https://sherlock.ischool.berkeley.edu/wells/world_brain.html

The first layer, MORPHiS, is a global secure encrypted distributed datastore that deprecates bittorrent, email and the web so far and is slated for release at the end of this Month!

See http://reddit.com/r/morphis for details.

Sorry for reddit; it is because I keep getting shadow banned here for being pro Snowden, Etc. Do not worry, MORPHiS is designed to deprecate hacker news! Anyways, the website is morph.is but doesn't launch until the 31st of this month. Read the only article in the /r/morphs subreddit for lots of details on MORPHiS!

Peace all!

Re: Snowden Meets the IETF

#67

I find it interesting that people now consider Snowden the authority and source for all these things.

Agreed. He actually knows little about most of INFOSEC compared to other, serious practitioners. He seems to be a good IT guy, expert on NSA tools, and have anecdotes of what they had trouble hitting. Far as security engineering, I'd trust a source with a good track record of building and breaking stuff similar to what I'm assessing.

People are leaning on him way too much for way too many things. I'm not even saying my statements apply to the article here so much as in general for people interviewing or citing him. Anyone reading posts of high-security engineers pushing strong hardware and software security pre-Snowden would've survived almost everything in NSA's toolbox using such methods. Leads me to add that Snowden seems totally unfamiliar with that stuff and it's unsurprising given his job was SIGINT-related rather than strong INFOSEC.

My only failure was not focusing on clean slate chips and hardware design enough. My priority was software but prioritizing the kind of hardware I've promoted here & elsewhere would've got me further. Makes the software easier to secure. Just was too lazy to learn all the hardware engineering knowledge it takes to (a) do custom hardware and (b) do sub-micron, custom hardware. I'm making amends now, at least.

Re: Snowden Meets the IETF

#68
post #31

Earlier quoted context omitted.

|he is regarded by many as the father of modern cryptography No, he both isn't that and isn't regarded as that either.

Seriously. But the man is very well respected in the security industry, though.

No denying that, though sometimes I wonder why. For fun google for "bruce schenier $mammal" theres a good chance you'll find a blog post with him putting out an odd analogy.

Re: Snowden Meets the IETF

#69

Earlier quoted context omitted.

What we see in practice with all extant implementations of blockchains is increasing centralisation. Because computing hashes is the sort of computation whose efficiency per watt greatly increases with more and more specialised hardware. Thus the Bitcoin situation, where the promise of everyone being able to mine a few coins has become a small number of Chinese mining pools; altcoins do no better.

> altcoins do no better. Most altcoins are Proof of Stake, where mining via computing hashes doesn't take place. "Blockchains" isn't limited to Proof of Work, you can even get non-PoS/PoW blockchains such as Hyperledger.

Wait, most?

Do you mean most that aren't autogenerated ones that stop being mined a few months in, or do you mean to include those?

I'm a bit surprised about "most" but if you mean "most that do something" then I could believe that, but I am still surprised.

Re: Snowden Meets the IETF

#70

Earlier quoted context omitted.

Dropbox isn't audited. They have a poor track record for security (lying about internal access then trying to downplay). So even if you encrypt with truecrypt, you're running the Dropbox binary for uploading, and it can do anything - in short, you're trusting them. I've not found an open source tool that does block level backups with diff/compression support. Getting the client experience right is hard and not a whol…

Oh! You were looking for audited sync clients. Yeah, I've got nothing there. Edit: I would ask "How hard could it be to solve 90% of the problem?", but various BigCos have had spectacular failures in recent memory, so I guess the problem is pretty damn hard. I wonder how terrible using git as the backbone for one's sync software would be.

There's git-annex for that. I've not tried it myself.
Post reply on HN