Let's say you frequent lots of subreddits that might be considered outside societal norms. Right now that data is ONLY available internally at Reddit.
If the NSA hoovered up this data, suddenly they might learn a lot about you that they didn't know before (although there's probably a fair argument that people probably leave enough other clues scattered across other data sources they likely have access to that make this redundant).
Maybe you aren't looking at things that would set off their alerts for today's hot media topics. But what about the future? What if we end up with a President with a radical discriminatory agenda (a scarily likely possibility at this point unfortunately)? What if suddenly things that may have been frowned upon before by the general public are suddenly made illegal by Executive order or some other horrible twisting of our laws? This provides the government with a great way to narrow down the list and identify targets that have become "inconvenient" for them.
Think it can't happen or that this is an off-the-wall conspiracy theory? Germany and Russia would like to have a chat with you.
Sure, the mainstream users probably won't have any noticeable impact on their lives. For now at least. But this can still have a chilling effect on free speech today, without the nightmare scenario I outlined above occurring.
Case in point from a couple days ago: https://news.ycombinator.com/item?id=11374839
Or anybody monitoring their traffic. coughNSAcough
I would be shocked if NSA didn't get a secret court order to get AWS access.
I found:
"Identifying Website Users by TLS Traffic Analysis: New Attacks and Effective Countermeasures"
https://hal.inria.fr/hal-00732449/
Does anyone know of other, recent research in this area? It's been a long time since I last looked at opaque data captures of TLS/SSL traffic.
I also found: https://tools.ietf.org/html/draft-ietf-tls-chacha20-poly1305... which states in part:
"It should be noted that AEADs, such as ChaCha20-Poly1305, are not intended to hide the lengths of plaintexts. When this document speaks of side-channel attacks, it is not considering traffic analysis, but rather timing and cache side-channels. Traffic analysis, while a valid concern, is outside the scope of the AEAD and is being addressed elsewhere in future versions of TLS."
On a skim of https://tools.ietf.org/html/draft-ietf-tls-tls13-11 I couldn't find anything new wrt. recommendations on padding with the goal of thwarting traffic analysis?
Anyone have any pointers on this?
So would J Edgar Hoover.
It's not much but it's something.
But if you are still a carrot fetishist in the future, they can use the knowledge that you used to be a carrot fetishist to set up a sting operation. A little parallel reconstruction, they seize your phone and laptop, and next thing you know you're in prison in the future, thanks to the data they hoovered up today and will be in their database forever.
Which, in my mind, is preferable to the alternative.
I probably should have been more explicit about two of my big problems/uncertainties with warrant canaries in my initial comment. The biggest issue is that they only really seem to matter in circumstances where I assumed the service provided was a secure and private communication platform. My personal threat model does not treat the reddit platform as a secure and private communication platform and Reddit Inc. is just slightly less of an adversary than Eve's Agency. (sidenote: You are Threat Model Shostack correct?)
My other issue is that the canaries seem to be backward looking and do not do much for my future outlook. It seems that the knowledge that an NSL was served just tells me about the past, but very little about the future. Should I assume that since an NSL was served once that I should expect that they will continue to be served repeatedly and regularly going forward? I am having trouble expressing the latter adequately and clearly, hopefully it is teased out below.
For the sake of argument I am assuming/ignoring that Eve does not do global surveillance and cannot easily associate requests from my IP to reddit with submissions/comment timestamps, vote changes, etc.
> If the NSA hoovered up this data, suddenly they might learn a lot
> about you that they didn't know before
In C0, I am screwed, Eve's organization knows I frequent /r/BDSM, /r/guns, /r/earthliberationfront, etc. Am I to assume that further NSLs will be served in the future and therefore I stop visiting my favorite subreddits? If I was concerned about the privacy of my actions what was I doing using a public insecure communication platform?In C1, I continue to visit /r/BDSM, /r/guns, /r/earthliberationfront, etc and the record of my sensitive activities on reddit is even larger if they are served an NSL in the future.
> suddenly things that may have been frowned upon before by
> the general public are suddenly made illegal by Executive order
> or some other horrible twisting of our laws? This provides the
> government with a great way to narrow down the list and identify
> targets that have become "inconvenient" for them.
In C0 I have a greater reason to believe that I am on the "inconvenient list". In C1 I am still doing all the things its just I have less certainty if I am on the list. > Think it can't happen or that this is an off-the-wall conspiracy
> theory? Germany and Russia would like to have a chat with you.
I don't think this sounds crazy. I just do not understand what the difference is between C0 and C1. As far as I am concerned the only difference between C0 and C1 is that I know my activities may have been reviewed by Eve in C0. > Case in point from a couple days ago:
> https://news.ycombinator.com/item?id=11374839
As far as that study is concerned the difference between C0 and C1 is that in C0 I am more aware or "subtly reminded" of the existence of mass surveilance and therefore self-censor. There are fewer subtler reminders of mass surveillance in C1 therefore I self-censor less in C1 than in C0. That makes canaries seem bad?Edit: spelling
You're right that an early-warning system hasn't been developed. We have no way of knowing what the NSA will decide to analyse after the fact. Indeed, we do not know if an asteroid will hit the earth tomorrow. At one level, there is a limit to our ability to predict the future.
So it's up to the individual. We self-censor, or don't. The chilling effect of the knowledge of surveillance is well documented. Are you making a point that thinking you're being spied upon is more damaging than any fallout of the actual spying?
1) While it isn't a perfect mapping, this is similar to a "I have nothing to hide" argument. The value of anything security or intelligence will vary with the situation. The same counter-arguments apply; you probably don't want to get to the point where you cannot learn about a NSL.
2) In general, information that allows you to make informed, up-to-date decisions is valuable. The sudden disappearance of a warrant canary gives you data about the current state of the world. The canary gives you information about the actions of the growing surveillance state. This information might be used to make preparations or as a political tool. You can decide for yourself if you would take different actions with this information, but even if it doesn't change anything for you, at least you had the opportunity to make that choice.
3) Warrant canaries also serve as an indicator of the politics of the canary publisher. Someone who publishes a canary is sending a message that they care about keeping everyone informed.
I think you missed the point. The real question is, "So a canary died on a service I use, now what?" Well I have that question too. The damage is done. Should I toss my phone in the nearest trash can, burn off my fingerprints, cut and bleach my hair in the at the nearest connivence store bathroom, and shed a single tear as I will never return home to my family again as I am now hitchhiking to Mexico or what? Because, honestly, I don't know what to do besides that. If you're the target of an NSL, then you need to worry.
> 3) Warrant canaries also serve as an indicator of the politics of the canary publisher. Someone who publishes a canary is sending a message that they care about keeping everyone informed.
Yeah, but the set of those that don't publish canaries doesn't indicate the opposite. Organization X might not publish a canary, because the canary is already dead.
I'm pretty sure I didn't.
> "So a canary died on a service I use, now what?"
Yes, that's what I was addressing.
> Should I [stereotypically run like a fugitive]
Probably not, but I don't much about your specific situation.
> I don't know what to do
THAT was my point; you don't know know, because you cannot predict the future. The social or political situation might change in a way that makes NSL searches much more threatening. You might be in a situation where knowing that your activities have been discovered by an a NSL does suggest some type of action.
It's easy to consider the set of possible futures that you can enumerate. That set is rarely complete.
> If you're the target of an NSL, then you need to worry.
And that's the "nothing to hide" argument.
> Yeah, but the set of those that don't publish canaries doesn't indicate the opposite.
Obviously. The canary is still useful information.
Actually, I think you do the same as when an actual canary dies in the mine - you get out. If we look back at what we know about Lavabit, basically a compromised Reddit (or any other web service) might be doing who-knows-what with targeted javascript and what-not. Of course, "Evil Reddit" could already be doing that as a private entity -- but I think it does shift the degree of trust a lot, from a) "probably mining personal data for financial gain through advertising etc", to b) "certainly mining all data at the behest of a mad anti-terror juggernaut that's been out of control for decades".
I might choose not to use the service a) for a lot of things, but I certainly wouldn't want to use service b) for anything.
Now, if I was the NSA/CIA I'd of course try to fund social media and messaging startups through shell corporations, and I'd be surprised if they don't do that. In that respect we go down the "you can't defend against a nation state actor" line of reasoning. But if warrant canaries became enough of a problem, something that could lead to a real exodus of users for something like Reddit -- that might give these corporations enough incentive and reason to challenge the practice in the legal system (The government is forcing us out of business).
Another aspect of the canary, is that while people might not now stop using reddit (or logging in to a reddit persona that's associated with animal cruelty, native American rights activism or other terrorist activities) - it still serves as interesting indicator on continued government overreach, and encroachment on civil liberties and free speech.
As evidence that more and more "town squares" and cafes are fitted with microphones and cameras "for security reasons" surface, the fight against illegal surveillance (can) gain(s) momentum.
So maybe what you should do is not just step away from reddit, but take to the streets.
I'd be really interested in hearing more about this.
Instead, we live in a world where we know that many of them either are not being forced to secretly cooperate; or in one where canaries don't work, and they're being forced to lie about it.
And of course, there are ways of implementing internal surveillance without the cooperation of providers: by trespassing on their infrastructure, by analysing and recording traffic at their border, etc.
1. we were not asked to provide private post
2. we were not asked to provide metadata like IP addresses
3. we were not asked to backdoor our website
4. we were not asked to shadowban users
5. maybe even one canary per user, to know exactly who is affected
That said, while your behavior regarding reddit might not change, it could inform your political behavior. Since organizations can't say they've received NSLs, it's really hard to survey and see how common it is. I'm glad reddit's case here is gaining interest, and hopefully other companies will take part in this program and also get attention when it happens. It would be good to know just how prevalent this practice is.