Live data from Hacker News

The Criminal N.S.A.

nytimes.com

91–100 of 116 posts

Re: The Criminal N.S.A.

#91
post #68

Earlier quoted context omitted.

Governments can still gather the metadata of encrypted emails. Both PGP and S/MIME do not encrypt the subject line, sender or recipient addresses. To use encrypted email and hide the subject line, you need to not use it (just say "Encrypted email") or something. This cannot be made automatic without impacting UX. The To: header fundamentally cannot be removed. The sender can be inferred from the account within the em…

> Governments can still gather the metadata of encrypted emails. True, but don't throw out the baby with the bathwater right away. I know metadata is at least as sensitive as the actual content, but you need to pick your battles. If we get people to widely use GPG to encrypt the content of their emails, that is already a huge win. Why? Because they're now using a public/private key infrastructure. And as you are prob…

> and I'm not entirely sure if those key-ID's are sufficiently unique and/or secure

They aren't: http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...

Re: The Criminal N.S.A.

#92

Earlier quoted context omitted.

We don't know for certain that several governments have archived stored copies of all cloud based email in existence, it's hazy as to what they do and do not have access to, what isn't hazy is that they have the right to demand the content of any given gmail account with effectively zero recourse available. The very fact that they actually do make these demands indicates on balance of probability, they don't actually…

I was hoping someone far more talented than me would write a browser plugin that would encrypt everything I type in a TEXTAREA with GPG, and then prompt me for a list of friends I'd like to have read that text. Everything, from Facebook to Gmail, would be encrypted that way. And I would be in control of the list of people that could read that text.

This is a solved problem, including the problem that you're haven't anticipated, which is the helpful "autosave" of drafts.

http://www.emacswiki.org/emacs/Edit_with_Emacs

I'm sure something similar exists for vi, sublime, etc., but emacs (of course) has great gpg support (http://www.emacswiki.org/emacs/EasyPG).

This moves the burden to your local machine, which, while not guaranteeing privacy, helps reduce the amount of data that you're just handing to the bastards.

Re: The Criminal N.S.A.

#93
post #81

Earlier quoted context omitted.

I was hoping someone far more talented than me would write a browser plugin that would encrypt everything I type in a TEXTAREA with GPG, and then prompt me for a list of friends I'd like to have read that text. Everything, from Facebook to Gmail, would be encrypted that way. And I would be in control of the list of people that could read that text.

Wouldn't you have to encrypt the text repeatedly, once for each recipient?

gpg handles this natively.

http://www.gnupg.org/gph/en/manual.html#AEN111

"multiparty encryption" is what you're looking for.

Re: The Criminal N.S.A.

#94
post #39

Earlier quoted context omitted.

How about we popularize encryption, and take the choice out of the hands of corporations and governments?

That would be helpful but ultimately will not address this as it needs to be made clear to governments that they are not welcome in our private lives except under cover of a specific investigation and public warrant. Encryption would be helpful but if the government compels your email provider to hand over your stored emails or just email headers they can still get a lot of information about you even if you always us…

Encryption would be helpful but if the government compels your email provider to hand over your stored emails or just email headers they can still get a lot of information about you

Exactly, this the line that the government has currently been using, that they only store "metadata" about communications and not the messages themselves, so encryption would no real difference.

Re: The Criminal N.S.A.

#95
post #39

Earlier quoted context omitted.

How about we popularize encryption, and take the choice out of the hands of corporations and governments?

That's why I did this; https://github.com/etherael/phoneme It's not perfect, but I think the first step to widespread crypto adoption is getting people accustomed to the workflow of fully encrypted email. Phoneme + mailvelope is not a huge jump from the current gmail experience and just that initial taste might be enough to get more people on the right track.

Is that supposed to be read as "phone me" or "phoneme"?

Re: The Criminal N.S.A.

#96
post #53
post #11

"Let’s turn to Prism: the streamlined, electronic seizure of communications from Internet companies." OK, good so far, PRISM does indeed streamline and automate the process... "... Prism is further proof that the agency is collecting vast amounts of e-mails and other messages — including communications to, from and between Americans." ??? PRISM was the one thing I stopped being worried about as soon as I figured out…

So from Wikipedia, Boundless Informant uses 504 separate DNR (electronic surveillance program records) and DNI (metadata) collection sources known as SIGADs. In a 30-day period, they collected 3 billion data elements from within the US from these SIGADS. And the PRISM document says it is the "the number one source of raw intelligence used for NSA analytic reports". Doesn't that mean that PRISM is the majority source…

If 2.999 billion elements never make it into those analytic reports then it may very well be possible that of the remainder that manual systems like PRISM end up being the majority source. As you note, there are hundreds of SIGADs, of which PRISM is just one.

> And why did Page, Zuckerberg and Apple say they never heard of PRISM?

Because PRISM is the name for the NSA end of that service and associated data tools. The company end of that service would be whatever they called the system they use for FISA warrant/NSL compliance.

Re: The Criminal N.S.A.

#97
post #91

Earlier quoted context omitted.

> Governments can still gather the metadata of encrypted emails. True, but don't throw out the baby with the bathwater right away. I know metadata is at least as sensitive as the actual content, but you need to pick your battles. If we get people to widely use GPG to encrypt the content of their emails, that is already a huge win. Why? Because they're now using a public/private key infrastructure. And as you are prob…

> and I'm not entirely sure if those key-ID's are sufficiently unique and/or secure They aren't: http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...

Short key IDs aren't. Just use longer ones. No format or protocol change is required.

Re: The Criminal N.S.A.

#98
post #86
post #67

Earlier quoted context omitted.

That isn't a sufficient solution. These spying programs are the beginnings of totalitarism. They have to be repealed.

Beginning? You guys do really think you are free lol? Just because you can choose one of gazillion same bubble gums is not freedom! Try to change important things (like your government) and you will see that you already live in tyranny. P.S. Intended to be brutal, think about it.

I don't entirely disagree with you. (I am not from the US, by the way). The developments in the US when it comes to justice, liberty and surveilance frighten me. From my point of view, the United States is fullfilling more and more of the requirements of a totalitarian regime.

I should probably be keeping my mouth shut regarding my opinions on US politics, since I'm visiting in a few months. Would be embarrassing to be confronted with this stuff at the border.

Re: The Criminal N.S.A.

#99
post #71

Earlier quoted context omitted.

Cool project, you seem talented... I'm just a bit confused here. If we basically know several governments already have copies of your historical gmails, and you're not securing the incoming channel (which we basically know has a beam splitter on it), what good does encrypting the historical files do?

We don't know for certain that several governments have archived stored copies of all cloud based email in existence, it's hazy as to what they do and do not have access to, what isn't hazy is that they have the right to demand the content of any given gmail account with effectively zero recourse available. The very fact that they actually do make these demands indicates on balance of probability, they don't actually…

While I agree with the sentiments, Google most likely does not delete the unencrypted mail, so even if the government hasn't stored the content of the mail they will just request copies of all your deleted mail too.

Certainly going forward it would be a good thing to do, but really (as you say) end to end encryption is required. It's a shame Hushmail was compromised [1], this is the type of thing if it was built into GMail would push encryption to the masses - I realise it's not in Google's interest or business model though.

With the smart phones being SUCH an integrated part of our lives now, this also makes it VERY difficult to keep your email with you on the go since the mailvelope plugin is only desktop based.

Shame. We have the tools, I hope we get better integration soon.

[1] http://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_p...

Re: The Criminal N.S.A.

#100
post #37

Here's the thing. If file-sharers have the right to anonymous speech , what does that say about everyone being spied upon by the NSA? http://torrentfreak.com/file-sharers-have-right-to-anonymous... I'm starting to think more and more that beyond this being a US Constitution issue, it's a human rights issue, and we should fight to ban all such spying internationally. Yes, I realize how hard that that may be to achieve…

UNIVERSAL DECLARATION OF HUMAN RIGHTS - Article 12. No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks. http://www.un.org/en/documents/udhr/index.shtml#a12

Unfortunately the Universal Declaration of Human Rights is only univeral in so far as it's universally ignored whenever that happens to be convenient.

I would be truly surprised if there is any country that does follow through on all human rights. The US especially probably breaks more human rights than any other first world country by a significant margin.

Post reply on HN