Pervasive Monitoring Is an Attack
tbray.org
Pervasive Monitoring Is an Attack
1–10 of 29 posts
Re: Pervasive Monitoring Is an Attack
#2So far, the disclosures have involved the NSA and GCHQ: intercepting hardware and modifying it; strong-arming companies into "coöperating"; pushing weaknesses known only to them into standards; and spending tens of billions to copy most of the Internet and have server farms sort it.
None of that seems amenable to this RFC.
Re: Pervasive Monitoring Is an Attack
#3The time it took from 'common knowledge' to a formal proposal makes me a little worried. If the IETF isn't really a "council of wise folks" then in the long term, doesn't their effectiveness get eroded?
Re: Pervasive Monitoring Is an Attack
#4" . . . the IETF is putting this stake in the ground in May of 2014." This isn't much of a stake in the ground, but its a start. So far, the disclosures have involved the NSA and GCHQ: intercepting hardware and modifying it; strong-arming companies into "coöperating"; pushing weaknesses known only to them into standards; and spending tens of billions to copy most of the Internet and have server farms sort it. None of…
Re: Pervasive Monitoring Is an Attack
#5Amateur radio is explicitly not for traffic that needs to remain private. It exists for limited purposes not including routine communication that can be served by other means (e.g. a phone or ordinary internet connection). It is chiefly for education and research/experimentation in radio. It is not for general personal communications or commercial use.
The applicable rule in the US[1] says:
"(a) No amateur station shall transmit: [...] messages encoded for the purpose of obscuring their meaning"
This serves to ensure the amateur radio service is not used in violation of its rules and purpose.
The rule has exceptions elsewhere in the rules. For example, remote control of satellites and model aircraft. And FCC rules as a whole pretty much go out the window when transmissions are for the purpose of protecting the immediate safety of life or property.
The rules are also susceptible of a particular interpretation: You can use encryption, provided the algorithm is documented, and you keep a record of the keys used. This has been used to block non-amateur access to WiFi access points operating within the ordinary WiFi band, but under Part 97 rules (e.g. non-FCC-approved equipment, or higher power than allowed for unlicensed users).
The rule also does not in any way prevent use of authentication and message integrity mechanisms, e.g. HMAC, because they are not intended to obscure the meaning of the message, merely authenticate it.
If you need private communication, there are other avenues available than the amateur radio service. And if you want greater freedom for unlicensed use of the airwaves than now exists, you'll have my support in principle (there are real problems with a free-for-all, but there are myriad ways FCC rules and spectrum allocation practices could be greatly improved in this regard). But this rule is not a bug, it is a deliberate feature of the amateur radio service.
[1] http://www.gpo.gov/fdsys/pkg/CFR-2013-title47-vol5/xml/CFR-2...
Re: Pervasive Monitoring Is an Attack
#6This is a good formal step. The time it took from 'common knowledge' to a formal proposal makes me a little worried. If the IETF isn't really a "council of wise folks" then in the long term, doesn't their effectiveness get eroded?
As anti-NSA, pro-snowden as I am(I proudly wear my Snowden t-shirts)... I think it's important for formal steps to make sure they've filtered out the hype and not just react while the general public is on fire about the issue. Waiting about 6 months to a year after Snowden did his thing I think is fast enough. Gives folks enough time to digest the info and for anyone else out there thinking about "leaking" more info that (dis)proves Snowden enough time to weigh consequences 'n such. This way when formal steps begin to happen nobody can complain that they didn't have enough time to respond/defend themselves, etc. USGov has been given plenty of time to quell concerns and haven't done a particularly good job so I feel that Snowden is mostly, if not completely, correct and I can confidently consider the USGov/NSA as the real villains in the world attempting to misdirect everyone else with allegations of boogieman terrorists & spying from Russia/China/Nigeria/whatever.
Not that I ever believed otherwise... just that this gives me more talking points in future debates with friends/family/random-online-comments.
Re: Pervasive Monitoring Is an Attack
#7Re: Pervasive Monitoring Is an Attack
#8So: is it a consensus or not? Does Mr. Igoe consider PM an "attack", even though his own employer does it?
I'm having trouble reconciling the two.
Re: Pervasive Monitoring Is an Attack
#9This is a good formal step. The time it took from 'common knowledge' to a formal proposal makes me a little worried. If the IETF isn't really a "council of wise folks" then in the long term, doesn't their effectiveness get eroded?
>>The time it took from 'common knowledge' to a formal proposal makes me a little worried. As anti-NSA, pro-snowden as I am (I proudly wear my Snowden t-shirts) ... I think it's important for formal steps to make sure they've filtered out the hype and not just react while the general public is on fire about the issue. Waiting about 6 months to a year after Snowden did his thing I think is fast enough. Gives folks eno…
I guess ultimately though, that's the only way to go. We knew years before Snowden that something fishy was up, but it took the leaks to really make people care at a level that could facilitate change.
Re: Pervasive Monitoring Is an Attack
#10> if your application doesn’t support privacy, that’s probably a bug in your application. Amateur radio is explicitly not for traffic that needs to remain private. It exists for limited purposes not including routine communication that can be served by other means (e.g. a phone or ordinary internet connection). It is chiefly for education and research/experimentation in radio. It is not for general persona…