Live data from Hacker News

Looking Back at the Snowden Revelations

blog.cryptographyengineering.com

71–80 of 244 posts

Re: Looking Back at the Snowden Revelations

#71

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

One of the most interesting revelations was the security agencies apparent spying on members of Congress.

But it’s like nothing happened. No investigation, no nothing. If they can’t be bothered by that, it’s little surprise they’re not bothered by their spying on regular folk.

Re: Looking Back at the Snowden Revelations

#72
post #50

Earlier quoted context omitted.

> Before Snowden, if you spoke about these issues, you were dismissed as paranoid. I’ve been telling people for years, but nobody listened. Now everyone knows it’s true, but still nobody seems to care…

Description of my life. I was telling people for years what is going on, not from position of daydreaming, but what I would be able to pull off. I got back everything from tin foil hat to "I have nothing to hide". Snowden changed that and I am gratefull to him for exactly that... And for one more sentance, that is a work of pure genius: “Arguing that you don't care about the right to privacy because you have nothing…

> “Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say.”

I find this sentence interesting because it is very specific to the American public. I am European and personally I care a lot more about privacy than free speech, and America's obsession with free speech boggles my mind.

It might have to do with the last time we in Europe experimented with unadulterated free speech, and got Hitler and WW2 as a result. We might have dialed it back a bit after that. But what do I know ?

There seems to be some a profound divide between America and Europe on this front and I haven't quite put my finger on why yet.

Re: Looking Back at the Snowden Revelations

#73

Naive question: This cryptography blog seems to, but... is WhatsApp really trusted as secure end-to-end encryption chat client? Colloquially, for one thing it's now owned by one of the biggest personal-data collection companies in the world, which would have little interest in owning a chat client it couldn't benefit from data-wise. For another, I read an article mentioning it was "known" that WhatsApp decrypted your…

It is highly unlikely that Facebook can read WhatsApp messages. The reason I say that is that Zuckerberg said the couldn't, repeatedly and explicitly, to Congress. If there was any chance that they could, he would have either not said anything (the context would have allowed for that) or he would have dissembled. As he did numerous other times on other subjects. As to benefiting from WhatsApp, I'm sure they benefited…

Don't have the transcript - did he say that 'he' couldn't or that Facebook couldn't? Or that other agencies, facilitated by Facebook couldn't?

Re: Looking Back at the Snowden Revelations

#74

Naive question: This cryptography blog seems to, but... is WhatsApp really trusted as secure end-to-end encryption chat client? Colloquially, for one thing it's now owned by one of the biggest personal-data collection companies in the world, which would have little interest in owning a chat client it couldn't benefit from data-wise. For another, I read an article mentioning it was "known" that WhatsApp decrypted your…

Given that it was built by a highly trusted cryptography team, plus the fact that the protocol can be reverse engineered to confirm encryption and decryption on device, and that over-the-wire traffic has no plaintext, the trust in this is indeed very high. WA has a lot to lose, and big enough target on it for a backdoor to have been found, if E2E is false.

Apparently anilgulecha is, like many, unaware that WhatsApp is no longer end-to-end encrypted. It technically trivial to tap the traffic between decrypting and re-encrypting stages, and the only plausible reason for the very expensive change was to enable such access.

Re: Looking Back at the Snowden Revelations

#75
post #69

Earlier quoted context omitted.

It is highly unlikely that Facebook can read WhatsApp messages. The reason I say that is that Zuckerberg said the couldn't, repeatedly and explicitly, to Congress. If there was any chance that they could, he would have either not said anything (the context would have allowed for that) or he would have dissembled. As he did numerous other times on other subjects. As to benefiting from WhatsApp, I'm sure they benefited…

Does not suggest, in any way, that nobody else can read all WhatsApp traffic, only that explicitly-Facebook employees can't. It would be pre-2013 naive to imagine that, now that WhatsApp traffic is no longer end-to-end encrypted, no use is being made of the change.

> now that WhatsApp traffic is no longer end-to-end encrypted

I'm sorry, what?

Re: Looking Back at the Snowden Revelations

#76

Naive question: This cryptography blog seems to, but... is WhatsApp really trusted as secure end-to-end encryption chat client? Colloquially, for one thing it's now owned by one of the biggest personal-data collection companies in the world, which would have little interest in owning a chat client it couldn't benefit from data-wise. For another, I read an article mentioning it was "known" that WhatsApp decrypted your…

The protocol they use is open and very reliable, and it can be verified relatively easily from the outside that this is the protocol they're using.

If you enable backups in WhatsApp those backups aren't stored on Facebook's servers, but they are probably not encrypted very well, since you don't enter your own encryption key, and WhatsApp has to be able to decrypt those backups if you lose your device. So those probably aren't secure if you are directly targeted.

Also if you are directly targeted, it's not completely impossible that Facebook has a way to send you a custom "update" that simply sends all your messages to Facebook encrypted with their keys.

But in terms of mass surveillance, it seems fairly unlikely that Facebook can read WhatsApp messages, because something like that would not be hard to find for someone from the outside, especially since the protocol WhatsApp is supposed to use is completely known.

Facebook probably cares more about your meta-data (who has who in their address book) anyway than it cares about the content of your messages.

Re: Looking Back at the Snowden Revelations

#77

As someone not from the US, the passages about how easy it was are clear reminders that just because only the NSA got caught, does not mean only the NSA was doing it. Even if they have by far the biggest budget...

We’ve seen other stories, Stuxnet in particular that implicate other countries like Israel. Anyone that thinks that the USA and Israel are spending money on cyber warfare but China and Russia are not is living in a fantasy world. Maybe some small countries like Andorra don’t have a cyber warfare division, but all the big countries do. Everyone is being spied on. Perhaps the only distinction worth making is whether yo…

In fact, once the content and data are liberated, there is no reason to assume it is well-protected from criminal access. Personal facts that are not directly incriminating are often just as valuable for extortion. Those facts need not be about you, to affect you. They could be about a federal judge's brother.

As extortion is the central procedure of spycraft, people trained in its use by the government also have access to the "goods". Criminal intent is no bar to employment by Booz Allen, or by NSA or FBI proper, never mind Russian GRU or FSB or their Chinese counterparts.

Extortion works for anybody.

Re: Looking Back at the Snowden Revelations

#78

Naive question: This cryptography blog seems to, but... is WhatsApp really trusted as secure end-to-end encryption chat client? Colloquially, for one thing it's now owned by one of the biggest personal-data collection companies in the world, which would have little interest in owning a chat client it couldn't benefit from data-wise. For another, I read an article mentioning it was "known" that WhatsApp decrypted your…

The protocol they use is open and very reliable, and it can be verified relatively easily from the outside that this is the protocol they're using. If you enable backups in WhatsApp those backups aren't stored on Facebook's servers, but they are probably not encrypted very well, since you don't enter your own encryption key, and WhatsApp has to be able to decrypt those backups if you lose your device. So those probab…

Or in other words, quoting James Mickens:

> My point is that security people need to get their priorities straight. The "threat model" section of a security paper resembles the script for a telenovela that was written by a paranoid schizophrenic: there are elaborate narratives and grand conspiracy theories, and there are heroes and villains with fantastic (yet oddly constrained) powers that necessitate a grinding battle of emotional and technical attrition. In the real world, threat models are much simpler (see Figure 1). Basically, you're either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you'll probably be fine if you pick a good password and don't respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU'RE GONNA DIE AND THERE'S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they're going to use a drone to replace your cellphone with a piece of uranium that's shaped like a cellphone, and when you die of tumors filled with tumors, they're going to hold a press conference and say "It wasn't us" as they wear t-shirts that say "IT WAS DEFINITELY US," and then they're going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them. In summary, https:// and two dollars will get you a bus ticket to nowhere. Also, SANTA CLAUS ISN'T REAL. When it rains, it pours.

Re: Looking Back at the Snowden Revelations

#79
post #37

This is a good article. Everyone has forgotten how much has changed since Snowden.

Actually, nothing changed Some Laws was created. Some revelations was made. But even manipulations with elections did not kill any company

if anything, manipulations of elections are being used to backdoor encryption, ensuring that nothing will change

Re: Looking Back at the Snowden Revelations

#80

As someone not from the US, the passages about how easy it was are clear reminders that just because only the NSA got caught, does not mean only the NSA was doing it. Even if they have by far the biggest budget...

We’ve seen other stories, Stuxnet in particular that implicate other countries like Israel. Anyone that thinks that the USA and Israel are spending money on cyber warfare but China and Russia are not is living in a fantasy world. Maybe some small countries like Andorra don’t have a cyber warfare division, but all the big countries do. Everyone is being spied on. Perhaps the only distinction worth making is whether yo…

Wait, are there people who think china doesn't do this!?
Post reply on HN