Live data from Hacker News

Forced Exposure

groklaw.net

71–80 of 430 posts

Re: Forced Exposure

#71
post #50

Earlier quoted context omitted.

> we need entirely new communication protocols Whole new enforcement of privacy laws, you mean?

No, I mean protocols. While elsewhere in the comments, there is the sentiment that "you can't code yourself out of this", my hopes of voting myself out of it (or otherwise "fixing" a system, as if it was just accidentally "broken") are much lower. (But note that "protocols" may also have non-technological components.)

If your laws are being ignored by institutions in power, you have bigger problems, and you can't code your way out of each one fast enough.

Re: Forced Exposure

#72
post #35

Since we weren't allowed to say it when it was relevant, and the point was muddled and trampled on in pseudo-rational debates (“Can you find evidence that they’re abusing this new legislation?”, etc.), I'll go ahead and say it now: it's happening. There's still a big world outside the Internet, and yet ironically, we live in a world where some employers are so stupid that they won't hire someone without a Facebook, m…

> best way to control a population is to analyze and manipulate the information they consume

That brought back a quote from a past: "He who controls the past controls the future. He who controls the present controls the past."

I had to look it up to get the exact wording right. Was only half surprised that it comes from Orwell's 1984.

Re: Forced Exposure

#73
post #7

For me, personally, this is much more sad than Lavabit shutting down. Groklaw was an icon, it has huge significance. I do not know whether this - i.e. shutting down - is a good strategy in general. It raises some awareness, it might cause some change ... but what if change does not happens? What other means of protest will we have?

He's not shutting down to raise awareness, but because he feels unable to conduct the blog without feeling his communications with his readers are private.

[deleted]

Re: Forced Exposure

#74
Groklaw has been a jewel in the crown of the free internet. We are all unbelievably impoverished by its passing. This is truly awful.

Re: Forced Exposure

#75
post #50

Earlier quoted context omitted.

> we need entirely new communication protocols Whole new enforcement of privacy laws, you mean?

No, I mean protocols. While elsewhere in the comments, there is the sentiment that "you can't code yourself out of this", my hopes of voting myself out of it (or otherwise "fixing" a system, as if it was just accidentally "broken") are much lower. (But note that "protocols" may also have non-technological components.)

>While elsewhere in the comments, there is the sentiment that "you can't code yourself out of this", my hopes of voting myself out of it (or otherwise "fixing" a system, as if it was just accidentally "broken") are much lower.

So you intent of fixing just a small point of the whole mess (the surveillance thing) and not the overall mess (bad governments, something that affects 100% of our life and countries)?

Not to mention there is nothing to fix this way. Everything can be outlawed, including mere use of unlocked general purpose computers as a non authorized professional in, say, 20 years time.

Re: Forced Exposure

#76

Lets not try to code our way out of this. We succumb to terror pushing away meaningless bits of code on Github as a crypto projects in response. Some projects flourish sure but the same forces that profit off the court-less killings of others are collating your data, your pet projects. Harvesting your stolen info out of botnets. Giving you a salary for technician work keeping infrastructure ticking. Enough enabling t…

> Lets not try to code our way out of this. I disagree. Let's use all our skills and avenues, not just some of them. > We succumb to terror pushing away meaningless bits of code on Github as a crypto projects in response. That is a subjective opinion. Email itself is meaningless bits of code. You want us to stop using email altogether? What about the web? Why are you even posting on this forum so? > Some projects flo…

"Some projects flourish sure but the same forces that profit off the court-less killings of others are collating your data, your pet projects. Harvesting your stolen info out of botnets."

> That is alarmist hyperbole.

Those were two direct references, the first being SAIC with their military drone[1] and domestic 'domain awareness center[2]' operations. The second being Endgame Systems and their monetization of botnet data/malware[3].

> Let's keep the spotlight where it is needed -- on the secrest out-of-control governmental surveillance organs of various nation states.

On it with laser-like focus, sir.

[1] http://articles.latimes.com/2011/dec/29/world/la-fg-drones-c...

[2] http://oaklandwiki.org/Domain_Awareness_Center

[3] http://wiki.echelon2.org/wiki/Endgame_Systems

Re: Forced Exposure

#77
post #68
post #20

While I understand her (1) personal reasons for shutting down Groklaw, this is an extraordinarily bad decision for privacy and democracy. In the last few weeks quite a few providers of private communications and/or freedom (for some definition of freedom) have shut down. Lavabot, Freedom Hosting, etc. If the US could shut down The Guardian they would. This leaves fewer and fewer secure channels for private communicat…

Obama continues to push hard to steal what little privacy rights US citizens have remaining. He is openly hostile about it, and lies about it constantly. Am I exaggerating here? The scary thing is I'm not. He's not done. It's going to get worse.

What is even more scary is that we have been in freefall in this regard mostly since at least Nixon signed the Banking Secrecy Act.

This was followed by Carter signing FISA....

Regan followed, signing among other things legislation to allow the military to enforce drug laws domestically as an exemption to Posse Comitatus. This meant that the military was involved in surveillance at both Ruby Ridge and Waco, and also directly provided military equipment and in some cases personnel to these operations (in addition to Navy SEALs raiding crack houses in some cities).

Then came Clinton and things got worse again with the Anti-Terrorism and Effective Death Penalty Act and some other laws.

Then came GWB, no further comment required.

And now we have Obama.

Whoever we elect screws us. That's the truth.

Re: Forced Exposure

#78
post #35

Since we weren't allowed to say it when it was relevant, and the point was muddled and trampled on in pseudo-rational debates (“Can you find evidence that they’re abusing this new legislation?”, etc.), I'll go ahead and say it now: it's happening. There's still a big world outside the Internet, and yet ironically, we live in a world where some employers are so stupid that they won't hire someone without a Facebook, m…

  There's still a big world outside the Internet, and yet ironically, we live in a world where some employers are so stupid that they won't hire someone without a Facebook, making the abuse and surveillance of Internet more relevant than it needs to be.
You know what's my thought towards such employers? A big fat FUCK YOU! Those are companies, where I rather collect unemployment benefits than ever working one day for such an outfit.

The same sentiment is extended to any service, which requires me to have a Facebook (or any other social media) account.

Re: Forced Exposure

#79
post #7

For me, personally, this is much more sad than Lavabit shutting down. Groklaw was an icon, it has huge significance. I do not know whether this - i.e. shutting down - is a good strategy in general. It raises some awareness, it might cause some change ... but what if change does not happens? What other means of protest will we have?

Chilling.

Re: Forced Exposure

#80
post #58
post #32

Earlier quoted context omitted.

> All tech geeks set up mail servers with encryption and volunteer to migrate their non-tech friends and family to new email homes. I certainly wouldn't be comfortable with my peers having the opportunity to control my email and the myriad of accounts associated with it. I can't imagine they would be happy with me doing the same with their data. > We also show how to configure encryption in their mail clients Encrypt…

> Encryption is fairly useless without authentication, and we can safely assume that the NSA has control of Certificate Authorities. You don't need CA's for e-mail encryption. You need keyrings and networks of trust (I exchange keys with my closest associates via offline means; I sign a certificate stating that I vouch for the authenticity of their certificates; my associates can then choose whether or not to trust t…

You need a CA for TLS-secured comms between MTAs. Many MTAs are set up to do opportunistic encryption out of the box, but they won't be validating the certs they get, so there's no guarantees about who's got the private key.

Of course there's no need to rely on a central CA - it's not hard to run your own, and you can make it reasonably secure - say, a small ARM Linux board with passphrase-protected private keys on a removable SD card. Generating the keys in a secure way is perhaps a bigger problem - untrusted hardware RNGs, poor quality entropy after boot etc.

One can also keep a virtual machine CA on a hardware-encrypted USB device (IronKey, say, depending on your level of trust with Imation) - it's easy enough to bootstrap a tiny Linux distribuution from source with just OpenSSL and some utility scripts to issue & revoke certs.

You don't necessarily need a $5000 HSM solution to issue your own SSL certificates at this level.

Post reply on HN