Live data from Hacker News

Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

news.ycombinator.com

81–90 of 137 posts

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#81
post #47

Earlier quoted context omitted.

That was probably just commemorating Leonard Cohen's death, and the certificate fingerprints were probably just removed because they switched to Let's Encrypt for those domains. But you never know.

What good is a warrant canary if it's also used for whimsy or commercial speech? If they don't take it seriously enough for people know what it means then their system isn't worth using to start with.

A Twitter feed is not a warrant canary.

Edit: the exact link to the official warrant canary is specified in the top post, please don't answer if you haven't recognized that much:

https://riseup.net/pl/about-us/canary

The "If they're relying on double entendres then it might as well be" as a response to "A Twitter feed is not a warrant canary" really has no sense.

https://en.wikipedia.org/wiki/Warrant_canary

Also worth reading:

https://www.schneier.com/blog/archives/2015/03/australia_out...

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#82
post #81

Earlier quoted context omitted.

What good is a warrant canary if it's also used for whimsy or commercial speech? If they don't take it seriously enough for people know what it means then their system isn't worth using to start with.

A Twitter feed is not a warrant canary. Edit: the exact link to the official warrant canary is specified in the top post, please don't answer if you haven't recognized that much: https://riseup.net/pl/about-us/canary The "If they're relying on double entendres then it might as well be" as a response to "A Twitter feed is not a warrant canary" really has no sense. https://en.wikipedia.org/wiki/Warrant_canary Also wort…

If they're relying on double entendres then it might as well be.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#83
post #8

"a FOIA".

Depends on how you're reading it in your head. If you read "Freedom of Information Act", then it's "a FOIA" but if you read "Eff Oo Aai Aay", it's "an FOIA" That's why you get "an X-Ray"

I've always read it "faw-ya".

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#84
If you're doing any kind of radical political work --- left or right --- and are worried about the attention you're going to attract, don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption. These are fundamentally unsafe services, and the idea that they can be provided safely just by paying attention to network security is terribly misleading.

In the universe of possible media in which to conduct discussions with a group of peers, there may be none less safe than SMTP email mailing lists. Keep secrets off mailing lists. Never use mailing lists for secrets. Assume your mailing lists are public. Nobody is going to deploy a mailing list security solution that will ever be adequate against state-level adversaries. Any site claiming to keep political activists secure that offers mailing lists should be viewed with suspicion, because "don't use mailing lists" is close to the only thing that messaging security people agree about.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#85

Earlier quoted context omitted.

Yes, I know there are a few people who have said "He is fine, trust us", but it would take all of 2 seconds for him to send a message himself, a picture, a video clip, stand by the window, or go on the balcony, and there has now been a very long, uncharacteristic time window where he has not done this. He has many means of communication, regularly has visitors, and has a very legitimate reason for doing it (to silenc…

To be honest, people that aren't going to be convinced that an in-depth video interview John Pilger asserts was made on October 30th or an abundance of statements from all parties about two days worth of formal interviews over the court case that's dogged him for a while aren't going to be convinced by a quick video of him saying "I aten't dead yet", or probably even a keysigned message. There are an abundance of pre…

Sorry, but c'mon, that entire subreddit would disappear overnight if Julian gave just one, basic proof of well being. The majority of the 12,000 (and fast growing) are not conspiracy people, they just have a very simple request for a PGP message, a picture, a video, a public appearance, anything.

Again, I encourage the debate of circumstantial evidence on Reddit instead of here, but Julian does not say anything to indicate recency (pre mid October) in the Pilger interview, otherwise that would have probably ended the subreddit. And it's ambiguous to what extend Julian was involved in the recent posing of questions to the Ecuadorian prosecutor by the Swedish prosecutor (just the 1, without Assange's lawyers). Again, Julian just needs to take a quick minute and say "I'm fine," and that community would disappear.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#86

Perhaps I'm doing this wrong but when I try to verify the gpg signature I get gpg: Signature made Tue Aug 16 01:01:19 2016 EDT using RSA key ID 139A768E gpg: Good signature from "Riseup Networks " [unknown] gpg: aka "Riseup Treasurer " [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 4E07 9126 8F7C…

Do you have a trust path between you and that key? If not, that message is normal, but you have no in-band way of knowing whether it's a valid signature from the right key or a valid signature from a fake key. However, if you have some trustworthy source that that's the right fingerprint, then you know it's a valid signature from the right key.

(This is why I hate PGP.)

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#87

I'm uninformed. What is the significance of riseup.net?

I hadn't heard of it either until just now. I remember when Reddit removed their warrant canary. I barely even use it now. For most people I bet it didn't matter. I have a feeling with mission of Riseup, this will have a much larger impact on their userbase .. the ones who are aware of this.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#88
post #84

If you're doing any kind of radical political work --- left or right --- and are worried about the attention you're going to attract, don't use things like RISEUP.NET. You shouldn't be running mailing lists at all. You shouldn't be using Jabber and asking all your peers to enable encryption. These are fundamentally unsafe services, and the idea that they can be provided safely just by paying attention to network secu…

I remember clearly a Tunisian opposition party was using a RISEUP mailing list around 2006 to spread its articles, political statements, etc... (When they were banned before the revolution of 2011).

Not all politicians can/know how to operate anything more complex than an email account.

Re: Tell HN: Riseup.net fails to update canary; fingerprints deleted without notice

#90
post #33

Earlier quoted context omitted.

I'm trying to spread the word. Please post a proof-of-life of yourself today somewhere on the internet. http://imgur.com/9Gn8tRr

Sorry, I don't understand this. It's incredibly bizarre to be posting selfies with messages on HN.

Granted. You're right that this is bizarre. I'm posting a proof-of-life of myself because Julian Assange is unable to, and I'm trying to get the word out. It's not just a selfie -- It's proof that I'm alive.

Basically I'm pretty much freaking out at the moment because it appears that Julian has been disappeared, and I'm doing whatever I can to try and spread awareness about this issue.

Previously, there were people on HN who were sympathetic to WikiLeaks and their cause, and this appears to be changing.

Post reply on HN