Edward Snowden at IETF 93
gist.github.com
gist.github.com
> If he felt his actions were consistent with civil disobedience, then he should do what those who have taken issue with their own government do: Challenge it, speak out, engage in a constructive act of protest, and -- importantly -- accept the consequences of his actions. He should come home to the United States, and be judged by a jury of his peers -- not hide behind the cover of an authoritarian regime. Right now, he's running away from the consequences of his actions.
Ridiculous. They literally don't know what "whistleblower" means.
"Go to prison because you deserve it in our clearly unjust system" ...the gall.
"In the land of the free and the home of the brave..." Haha. Ed Snowden is brave and we are freer as Americans knowing what the government is capable of when it comes to electronic surveillance.
Clapper and Alexander lying to congressional hearings too. There's no comparison.
> private corporations are collecting more data than ever
This has always been inevitable, if at some point the amount of data about ANYTHING decreases I'll surprised.
The 'freedom' that emerged from the snowden leaks was the ability to discuss and mitigate the implications of these facts without being dismissed as a crank.
And it is pretty clear that he is guilty of this law. Not much room for whistleblowers in a wartime law.
Is this "promise" legally binding? What about the next Attorney General? Or the next one?
Even if he isn't executed, he could be physically and psychologically tortured. I'm not sure if you know much about the US prison system, but this is a common and officially sanctioned practice. Many people would consider a lifetime of torture to be a worse punishment than execution.
I don't think there's any assurance or promise the US government could offer short of a full pardon that would be sufficient. The US, especially in areas of human rights and national security, is not a trustworthy entity.
It looks like he still strongly supports what Snowden did.
I also think Binney's case is a bit different - when you don't leak the actual documents the intelligence agencies can (and do) just lie. If not an outright lie it'll be a carefully stated misleading truth ('not in this program'). Snowden's leak is a bigger deal to the intelligence agencies because he has the actual documents and they don't know what he took which makes it hard to influence the story (since it's easier to be definitively caught).
Putting Binney in prison would have likely attracted more attention than not.
John Kerry and other people requesting Snowden to come to the US to stand trial are ignoring that what he did isn't a question of whether it was legal (it wasn't), but if it was right. You won't win a trial on principle when it's the law that's the problem.
That was a direct result of Snowden's actions. I don't see the argument that his exposing the US spying on other countries is "right", and deserves a pardon. If he had only leaked local surveillance, I'd have a weaker case.
>You won't win a trial on principle when it's the law that's the problem.
If the problem was that he disagreed with the law, in the US, the way to change laws you disagree with is through the political process. Not by breaking them then demanding a pardon.
That said, I suspect it's broad because it's hard to be selective internally without arousing suspicion and part of the leak was the scale of the operation itself - but that's not a great defense.
>If the problem was that he disagreed with the law, in the US, the way to change laws you disagree with is through the political process. Not by breaking them then demanding a pardon.
I think the core problem is actually deeper than this. When you have secret courts and secret interpretations of secret laws you don't have a process to change them. Part of leak was to bring this into the public view - given the incentives, politics and the existing laws surrounding the sharing of classified information I don't see another way this could have been done. Mass surveillance should minimally be a public decision - the secrecy surrounding it is dangerous.
Technically there's internal whistleblowing. Besides, the fact that there are secret courts wasn't secret, so you could campaign against having those courts be secret. If there's anything being done that actually violates the law, you'd have full whistleblower protection (if you go through official channels). If it's just your disagreement with the law, you can act against that (as the EFF had been doing for years before Snowden) without breaking it.
You can't change the laws through the political process when disclosure of the laws is illegal.
Further, Snowden is not demanding a pardon - we are demanding Snowden be pardoned.
Imagine a world in which Snowden resigned, then publically pushed for unclassifying all FISA court rulings, with the obvious implication (or he could even say explicitly) that he saw things there that shouldn't be secret.
He could even tell members of Congress with clearances and get them to announce it publicly in Congress, which effectively legally brings it into the public record (something like that happened with the Pentagon papers).
The text of the laws was public. But the NSA decided that those laws meant something radically different than what was written down.
Per my understanding, mostly that did not have involvement from the FISA court.
In any event, certainly much of what he published was unambiguously legal.
basically the government (caught red handed in violation of fundamental rights of the people) insists how civil disobedience must be done where is the main point of civil disobedience is ...? In particular interesting how they're trying to insist that civil disobedience can't be without martyrdom, and thus implicitly they try to scare people away from civil disobedience. Nice.
>Right now, he's running away from the consequences of his actions.
right now he is suffering from consequences of his actions - he sacrificed his good life in the US.
This is not to diminish the work of Dr. King but to say that the tactics he employed and decisions he made were made in a dramatically different context, where the way he could stay most involved and get the most done was to spend some time in jail. Snowden has stayed more involved from abroad than he would have been able to from where they'd have thrown him.
The rule of law should apply to everyone equally. I get that Ed Snowden is a likable guy and the documents he released may even have been a force of positive change in the world, but that doesn't necessarily absolve him of having to face trial. You can't go easy on him just because you agree with his politics.
Our whistleblowing laws are woefully inadequate, but I think it's generally a good thing that random government contractors aren't allowed to unilaterally declassify national security programs because they personally don't agree with them. It's easy to imagine examples where this would lead to a very bad situation.
He's charged with theft of gov't property, unauthorized communication of national defense information, and willful disclosure of classified intelligence. You can view the charging document here: http://apps.washingtonpost.com/g/documents/world/us-vs-edwar...
What is the more appropriate charge you think should have been levied instead?
Then start with the little incident that happened around 2008 that did far more damage to the average American. Also, hasn't Obama admitted to smoking pot? He is currently in a far greater position to damage the US and should be thoroughly punished for his crimes. What about Clinton and her emails? And if I started listing the skeletons in the closet of Congress we would be here for weeks.
Rule of law has ALWAYS been selectively applied.
Its pretty clear the rule of law doesn't apply to our intelligence services. How about you work on that first before going after the little guy?
http://www.telegraph.co.uk/news/worldnews/northamerica/usa/1...
http://www.ft.com/cms/s/0/bfa9ada4-81e6-11e4-b9d0-00144feabd...
http://www.usatoday.com/story/news/nation/2013/08/04/fbi-inf...
Get back to us when all that sees a court room, kay?
James Clapper lied under oath to Congress.
Hillary Clinton kept classified material on a personal server at her house.
These are all serious crimes with plenty of publicly available evidence that they were committed. The people who committed them are all inside the country and easy to find, so charging and arresting them wouldn't be difficult.
So where's the outrage from all the "rule of law" folks? Why aren't these well known fugitives ever mentioned alongside Snowden?
The way you phrased this made me curious, so I looked it up. I don't know if it was your intention, but the way you phrased it made it sound like they were preforming medical procedures, possibly heinous medical procedures. In fact, the experiments were collecting data[0]:
"...and crossed the line into human experimentation by collecting and analyzing data that were then used to refine harsh interrogation techniques, including sleep deprivation and waterboarding..."
Don't get me wrong, I don't agree with it, but I had visions of people having limbs attached to them, superhuman drugs injected into them, and death left and right, like some kind of V for Vendetta shit. This does not seem to be the case.
Until the system can show it's worthy of our trust by pursuing powerful people who flagrantly violate the law in the public view, there is no reasonable argument that Snowden should be subjected to its plainly unequal notion of justice.
Couldn't everyone accused of any crime use that excuse?
US media call him a coward for exposing how much effort their government puts into breaking citizens' privacy, and then GTFOing from the country? That's not a stand one can come to while having brain in the head. To have media so much aligned with government witch-hunting seems borderline Russian.
I'm too lazy to try and verify this myself. You seem to have information on how to verify this. Can you point me in at least a vague general direction so I can read up more on it?
> "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon probable cause, supported by oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
What was violated here? Break it down for me.
> if the internet and technology does become a danger to us in the future, it's our own fault because we decided not to participate and we let other groups and other influences to decide for us rather than being part of it [...]
Before that, he argues that more people should involve themselves more in the IETF and similar groups:
> [...] However, when you look at the IETF, they literally don't make a decision unless it's based on consensus. There are no requirements. There are no academic standards or qualifications that anybody has to meet before they can be involved in a working group. Literally, anyone can join, anyone can participate in the process, anyone can make themselves heard, anyone can influence the standards that we develop, put forth, and decide. [...] It's a more inclusive community than it ever has been before [...]
Not sure what his context for this is, but one could easily argue we're already here.
> So hi-tech is likely always going to be a domain where a few experts will have the knowledge to understand and control the system. Could it be that the use of hi-tech fundamentally undermines democratic society or kind of – how can we do something to educate users or...
It doesn't: there are multiple different programs for reporting perceived illegal activity. Snowden never availed himself of any of these, but instead committed espionage.
These programs had been used by multiple people before, with no results. They are for show, so that people like you can point to them to show that there's "oversight".
Whistleblowing of the type done by Snowden is a last resort when there is no other option. The options you speak of are not credible avenues for change.
> One of the things that has not been widely reported by journalists is that whistle-blower protection laws in the US do not protect contractors in the national security arena. There are so many holes in the laws, the protections they afford are so weak, and the processes for reporting they provide are so ineffective that they appear to be intended to discourage reporting of even the clearest wrongdoing. If I had revealed what I knew about these unconstitutional but classified programs to Congress, they could have charged me with a felony. One only need to look at the case of Thomas Drake to see how the government doesn't have a good history of handling legitimate reports of wrongdoing within the system.
> Despite this, and despite the fact that I could not legally go to the official channels that direct NSA employees have available to them, I still made tremendous efforts to report these programs to co-workers, supervisors, and anyone with the proper clearance who would listen. The reactions of those I told about the scale of the constitutional violations ranged from deeply concerned to appalled, but no one was willing to risk their jobs, families, and possibly even freedom to go through what Drake did.
[0] http://www.cnet.com/news/snowden-not-all-spying-bad-but-nsa-...
Every time I've been a contractor[1], I've been treated likewise.
[1]never been contracted out to a government agency of any level.
Government activity that is fascistic is usually going to be completely legal or made legal once revealed. We saw the government do this with the USA Freedom Act. Before that, they claimed to have authorization under the FISA and PATRIOT Acts. They do not want oversight, and the "abuses" are actually functioning exactly as intended. This is also why they endlessly lie to our faces about what is going on and don't get fired, even when they have been outed repeatedly.
Also, there's the documented fact [0][1] that whistleblowers at the NSA who go through the "proper channels" ultimately gets you fired, ostracized, raided, and prosecuted. So really, it's a non-starter to claim that they should have reported illegal activity.
[0]: https://en.wikipedia.org/wiki/Thomas_Andrews_Drake#Drake_act...
[1]: https://en.wikipedia.org/wiki/William_Binney_%28U.S._intelli...
"or threat to public interest"
It doesn't have to be illegal.
At what point does he cease being a whistle blower?
Still better than a full dump à la WkiLeaks, but the big question is whether the journalists have the OpSec skills to avoid leaking the documents to other governments.
It doesn't matter if it was directly or through an intermediary, everything that Snowden gave to journalists, Snowden leaked to the public.
Why not just leak documents related to that one issue? If he had, I would not hesitate in the least to call him a whistle blower, and in fact I think he'd be living as a free man right now if that were the case.
Second, we don't know the number of potential documents, nor how they may have been divided among those to whom they were disseminated.
Addressing the first point, it should take work and review, on an ongoing basis, to re-affirm the classification of that material. By default there should be a /reasonable/ and /short/ expiration time. If it costs too much to keep those secrets than that in and of it's self is a reason for not HAVING so many secrets to keep!
The cost, otherwise, is to our freedoms; to the very liberty for which our government is supposed to be protecting.
Perhaps you believe in your country right or wrong, but many don't nowadays, many feel little allegiance to national boundaries or national agencies which actively undermine our society.
What I find most interesting here is that this attempt by security agencies to collect it all actually means that their operation can be compromised by the smallest cogs in their machine whom they foolishly gave full access to. You can be absolutely sure that if Snowden walked out with this data, Chinese, Russian and other spies have the whole trove as well dating back years, because their security around private contractors was awful - GCHQ shared all this with the US without restraint, and of course all their data is now open to the world. So the ambition to collect it all and the entire collection of data (including data on western judges, politicans etc etc) is actually highly damaging to national security, even if you believe that flimsy excuse.
At some point if you're exposed to all this you might feel you have to take sides with humanity and take a stand, before these tools are used for widespread repression. At that point you start being a whistleblower, and your life will probably be destroyed by the powers that be (as his has been, or as Binney's was), because they now have that power.
http://www.nytimes.com/video/opinion/100000001733041/the-pro...
I think the biggest lesson from Snowden is not technical, but the simple argument that the power of state and citizen must be in balance for society to function, and we must constantly guard against the state aggrandising power, because that is in its nature.
Edward Snowden: So, I agree with you and I mean this is what's important about the IETF. Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. Nobody should trust me. Nobody should grant any sort of outsized weight to what I say.
When I talk about the NSA, I mentioned it in correlation with DANE and the DPRIVE initiative as well because the whole idea is that, yes, providing some mechanism for authentication of the responses between DNS queries is valuable. It's not an end to itself.
We still have to be able to say, "Well, all right, the certificate that you're getting from it, for a server is also reliable," and then we have to actually do more armour the requests themselves to make sure that they don’t become a new vector, they don't become manipulated.
Who knows like if eventually the DNS responses themselves that are provided through this become some sort of vulnerability because of the way they're parsed or whatever, but the whole idea is that we gotta start somewhere and then we've got to iterate from that point.
We've gotta begin building and when I think about things like DNSSEC, I don't think it's the golden age, we can solve all of the problems, but I do think that it's a start. It's better than the status quo. It's better than what we have today
And by getting the community thinking, by coming together and trying to develop some kind of solution, some kind of standard, we can start developing things that will allow us to build a bridge to the next generation of what we need to protect us against the next generation of coming attacks, and there's a lot of things that get in there. I mean cryptographic agility is one of the big hot things that we have to deal with as well.
I can barely follow this at all, but the part where he says DNSSEC is "better than the status quo" is pretty clear. The questioner responds, "so let's implement it".
Please be careful with what Snowden says. Whatever you think of his disclosures --- and most of my friends think they were brave and incredibly useful --- there is very little evidence that Snowden is qualified to advise anyone on cryptographic security, and some pretty significant evidence to the contrary.
I'm all for implementing the perfect protocol if it exists or there is a known credible path to get there. But to my knowledge noone has proposed such a thing (namecoin maybe?), certainly not in a form that my grandmother would be likely to use.
Do you have a suggestion for how you would like to see DNS evolve to fix these issues?
DNSSEC isn't an imperfect protocol; it's harmful, a net loss.
And here we have Snowden twice advocating for it.
And as Chrome experimented with DANE then removed support for it, I don't think you have to worry about that either.
But even if you did - so what? There are CAs in areas controlled by the American and British and French and Chinese governments already. I don't see how it makes anything different.
2. DNSSEC is harmful for reasons that go past DANE.
3. I am worried about DNSSEC; I think it's a more reasonable thing to be worried about w/r/t/ surveillance than 95% of what's been posted to The Intercept.
4. QUANTUM INSERT will work fine in an all-DNSSEC world.
5. You can revoke a CA. It has happened more than once. You can't revoke a TLD.
I'm happy to talk more about how I think DANE CAs are different and worse than the 20391 X509 CAs we have today, but I'm not sure you're asking me to go on at length about that.
Fair enough, my knowledge of DNSSEC is limited. I thought it provided confidentiality in addition to authentication, but I see I was mistaken.
I'm still not sure how you arrive at the conclusion that it is a net loss. Which attacks will DNSSEC enable that are not possible today? If you mean that it will give people a false sense of security, is that not the same as TLS today? Despite my hangups with the CA system I think we're better off with TLS than without it.
The NSA certainly has no problems with intercepting DNS requests today with their QUANTUM tools.
I am genuinely interested in hearing other ideas about how to provide confidentiality and authentication for DNS without central trust. Since you have clearly investigated these matters, I would like to ask again, are you aware of any promising projects or ideas in this regard? Because I would jump into the anti-DNSSEC camp in a heartbeat if one existed.
You make a strong argument that DNSSEC cannot deliver any real advantages. I did not see anything to support your earlier statement that it's worse than nothing, but given the general uselessness of the protocol, I certainly won't be deploying it.
* DNSCurve
* Certificate Transparency
* TACK
* HPKP headers
* HSTS headers
* TLS 1.2 minimum
* EdDSA TLS certificates (Ed25519 / Ed448-Goldilocks)
Implement all of the above, and you've obsoleted any argument that DNSSEC advocates can make.Most of the people who I've seen advocate for DNSSEC are graybeard traditionalists who want centralized control, not cryptographers or security experts.
A decentralized system like Namecoin, but more like Stellar (with EdDSA signatures please) than Bitcoin, would probably serve as an appropriate replacement for DNSSEC. But even that probably isn't necessary. Every sane end-to-end encryption protocol assumes DNS is insecure anyway.
Still no offline signatures.
How is it that centralized control is worse than the TLS's "everybody has full power to impersonate you" decentralization? You know that Certificate Transparency is still subject to MITM attacks, right? It just makes it obvious that you were victim of one after the fact (if there is an "after the fact").
> How is it that centralized control is worse than the TLS's "everybody has full power to impersonate you" decentralization? You know that Certificate Transparency is still subject to MITM attacks, right? It just makes it obvious that you were victim of one after the fact (if there is an "after the fact").
This is non sequitur. You're comparing a bad option where only a few can screw you over (DNSSEC) with a bad option where lots can screw you over (CAs).
I want a protocol where no one can screw you over, except yourself. And I want the government to be powerless to do anything about it without your consent. And if it function with high anonymity (e.g. with Tor Hidden Services on servers purchased with cryptocurrencies), all the better.
I think you're poisoning the well here. I haven't seen anyone suggest we should use Snowden as a technical advisor or anything of the sort.
https://www.mnot.net/blog/2015/07/20/snowden_meets_the_ietf
It’s important to point out that this was NOT an official
IETF event, and neither was it giving external advocacy
organisations a stage (as some have intimated); rather,
it was entirely an effort of individuals, working within
the rules for requesting a room at IETF meetings.What he brings to the table in discussions like this is basically having worked with people on surveillance projects. He knows how they operate and where they'd look for attack vectors. I think that's valuable when you have to think about designing any system with any kind of security requirements.
He literally stated himself that what he says shouldn't be accepted as gospel, and in a later question about MITM specifically confirmed that it's not his area of expertise. I don't think there's any risk of people suddenly jumping on the DNSSEC bandwagon just because of his lukewarm support.
Someone actively engaged in trying to prevent centralization of Internet trust, and decoupling it from the Five Eyes governments --- a worthy goal, I think --- should be adamantly against DNSSEC. But here's Snowden doing the opposite.
It's not because Snowden is disingenuous. I think he's a true-believer. It's because he doesn't understand DNSSEC.
Viewed another way, its a perfectly obvious and not at all weird response to a comment that quotes Snowden explicitly disclaiming that he is any particular, before providing a very vague general impression of things "like" a particular technology about which he was specifically questioned, without providing anything that looks like actual specific technical advice.
I interpreted this to mean encrypting each DNS packet.
Maybe I misread the statement?
DNSSEC of course does not protect the contents of the packet.
Instead, DNSSEC more or less is just another CA system (or an adjunct to the existing one), running over UDP.
Proposals like DANE, using TLSA records, or deploying SSHFP records on DNSSEC enabled domains, are a different kettle of fish.
Whether or not you believe in DANE really depends on whether you're willing to accept that the DNS infrastructure is already security critical. Truth be told, if I can hijack your DNS, I can get a certificate for your domain using simple domain validation... but that's true of your web server as well. There's no easy answer here.
I use my own cache, not shared with anyone. Do I really need to worry about snooping?
I also use CurveDNS with the authoritative server that serves my version of the root.zone.
Practicing my CurveDNS skills for that day when more authoritative servers are using curvedns. Not sure that day will ever come.
Edward Snowden: [...] Just because I say it, doesn't mean it's gospel. I can be wrong about an incredible amount of things. Nobody should trust me. Nobody should grant any sort of outsized weight to what I say.
I wouldn't expect him to leak anything or discuss government capabilities beyond what has already been leaked. That was never his stated intention. Involving journalists was deliberate on his part to remove himself from being final decision-maker about what to publish.
The internet belongs to the user, right?
The thing is, this is literally false. The infrastructure of the internet is paid for by governments and vendors. A user wouldn't be called a user if it belonged to them...
The internet is a great decentralization when compared to traditional media like television, but it's not nearly as big a difference as people make it seem. With how most people use it it's not far from just having more channels on your existing cable box.
> ...it's not nearly as big a difference as people make it seem. With how most people use it it's not far from just having more channels on your existing cable box.
You can't write emails on your TV, or do banking, or...well this is just a silly sentiment.
And yet they do: we may play in this sandbox, but we don't make decisions about the infrastructure, we don't make decisions about the law around it etc. This is congruent to the American political and legal system.
As you pointed out, it gets more confusing when you get international, but it's informative to look into how much control the US (and West in general) has over global internet infrastructure.
One of the problems Bitcoin solves is that you cannot have personas or unlinked identities in the traditional financial system. Governments, and therefore the banks they control, all view financial privacy or pseudonymity as only useful for criminals. That's a rather narrow viewpoint. Especially as the notion of "criminal" becomes more divergent between ordinary citizens and their rulers. There's some truth to it (anonymity does sometimes enable bad stuff), but it's excessively black and white.
Regardless, given that Snowden views payment methods and such as being very important, he even brought that up himself, I don't know how else he thinks it can be done, other than with Bitcoin. If you try and create a payment method that has privacy the banks won't give you the time of day. Being completely decentralised and independent is the only way to do money that exists outside of the status quo.
The long explanation:
It's complicated. US law tends to be specifically designed for one application in mind and then ends up being expanded as new applications rear their heads.
The IRS (tax collection entity for the US federal government) classified BitCoin as an investment a few years ago (as opposed to a currency). This suggests that other non-state created digital crypto-currencies are considered investments as well (IIRC Canada's mint was trying a digital currency, hence the "non-state created" phrase).
Money laundering statutes aren't new enough to know about [1] crypto-currencies, but they are effective with dealing with the conversion of money to products/services and back for the purpose of obscuring the original method of obtaining the currency. I don't know much about money laundering except what I see in movies+TV (specifically Breaking Bad).
I've heard that buying large value gift cards (plastic charge card versions of "gift certificates") are required to be reported to authorities by the retailers.
Recently a school sports coach was prosecuted for violating money laundering statute when he divided up one payment of $10,000+ into multiple smaller < $10,000 payments after his bank started to get suspicious about the nature of the transaction (which is required by US federal law of the bank). He violated the because he altered his payments "to avoid mandated financial institution reporting" of his transfers. Personally I think the mandatory threshold is stupid since people know what it is[2], but I feel no sympathy for the man in this case since the payments were suspected to be him paying off a student that he raped/molested. And yes, I realize that being accused of something is not the same thing as being guilty.
[1] http://www.fincen.gov/news_room/aml_history.html [2] although the US Patriot Act allows federal investigators to use _any_ change in financial habits to trigger an investigation, not just transactions above the $10k level
Bitcoin "solves the problem" to a much greater extent than any other actual system. It provides a base on which privacy can be improved over time. Tumbling is not required to upgrade privacy in Bitcoin, there are many other techniques that can help too.
I had the transcript done by a professional, and then went over it and corrected. That said, there are still some places where it may have errors, so if you find an odd statement, take it with a grain of salt and check the recording.
Corrections taken in comments, of course (don't think gist does pulls :(
http://www.cnbc.com/2014/06/05/snowden-a-traitor-andreessen....
1.) Public needed to know where there money was going 2.) Not enough to know we're being watched. We need tangible evidence of surveillance apparatus 3.) Leaks designed to bolster the web and privacy; look how many people suddenly care about security 4.) NSA got tired of working in a black box and wanted to flaunt its power 5.) Other reasons?
President Obama's administration has been arguably more hawkish against national security disclosures (when they don't benefit the administration) than Bush's was[1], and his administration has set up quite a few cases that involved tapping the communications of journalists.
I liked Candidate Obama quite a bit and am fairly disappointed in President Obama's policies. " The Obama administration, which promised during its transition to power that it would enhance “whistle-blower laws to protect federal workers,” has been more prone than any administration in history in trying to silence and prosecute federal workers."[2]
[1] http://www.politifact.com/punditfact/statements/2014/jan/10/...
[2] http://www.nytimes.com/2012/02/27/business/media/white-house...