The Snowden Legacy, part one: What’s changed, really?
arstechnica.com
arstechnica.com
After working with the credit bureaus, I don't llike giving out enough info for anyone to mess up my personal life. For example, even the front of a drivers license without the license number is enough info for fraudulent creditors to wreck your credit.
If a schoolboy orders 3000 pizzas in your name that isn't your problem but the pizza place's problem. So why the /hell/ do we consider it different with big banks except for the general stupid human tendency to hold people in power to lesser standards?
Most people asking for your SSN or drivers license will already know your name and approximate location, therefore they'll have enough information to just look up your SSN and DL via various services like accurint.
You're trying to hide public information.
Why would people discount this?
It's not "real" to them.
Hopefully that thought sends shivers down the sounds of anyone who is trying to come up with a data anonymization scheme
Also, names are not unique, therefore hashes of names would also not be unique. And how would you verify the hashes belong to actual people?
so in other words, no effect, business as usual.
When you're a semi-anonymous commenter on the Internet, it's better to share your inputs than outputs.
Normal people know what "parallel construction," is and how elected governments will use these systems for political ends.
What I don't understand is why it's not a bigger public issue with all the controversy around the current U.S. president. The scenario where a radical takes power and has control of these systems was the precise nightmare scenario everyone was concerned about, and yet mass surveillance just isn't a part of the popular discourse in the culture war.
Is it because the other team wants to use it too, or is it because the current perceived radical tyrant isn't dangerous enough?
To me the current situation rings like an echo of that, people want strong leaders to fix their problems.
"History never repeats, but it rhymes" -- probably not Mark Twain
For one person, it's quite an achievement.
As for what has changed, Only in the movies would there be a neat resolution, and we go back to being safe.
We can never go back. But at least we know where we are. Fixing it is now our problem.
The people of the west can no longer look at China/Iran/Russia and say they're police states without looking at what they've allowed in their own countries. Once China's "Social Credit" system is in full force and in the governments eyes working well (undoubtedly crime/social tension will decrease, at the cost of freedom) will the west start copying these technologies just like their spy agencies did after 9/11?
Putting those online is not inherently a stupid or bad thing. Putting them online without a means to view them, without controls on who can view them, without ability to redress wrongs or corrections, without institutions that support it, yes that's crazy.
We are never going back to a world where only your neighbours knew what you were like, but we do not either have to go to a world where only the Stasi or ad-tech firms do too.
THE Chinese credit score is objective, there’s only one. It’s merely what the government thinks of you, with no room for disagreement, with the consequences of that assessment automatically enforced throughout all of China
As discussed, in true social credit, many people/citizens reporting their accounts of an individual's credit to the "centralized image" would be similar. Their government-held system is not.
What you seem to be describing is simply society, and the fact that speech in a free society can have social consequences.
i’m walking on the beach on thanksgiving and when i get back home i’ll feel just as free to speak my mind and respect my neighbors right to speak their mind without fear of the stasi knocking on my door tonight.
we have a free press whose only fault is our own (profit motive).
i could go on but you get the point.
Comparision does not have to mean the right-on teenager reflex of throwing out babies with bath water- Comparison means comparing against our ideals, as well as against the failings of others.
I am proud of the society my forefathers have created and try to do what I can to both preserve it, and enhance it.
And It is that enhancement that matters here - a new opportunity fell into the laps of our security services, who rightly took that as far as they could. They incorrectly kept it secret from us.
It is now up to us to decide how we balance the advantages and disadvantages of this new technology - something we are barely grappling with on Facebook, something billions of people are familiar with, as opposed to the more abstract Five Eyes world of surveillance.
We will get there. Things like GDPR are starting to grapple with the subject
I'm jealous of your optimism, but I'm in Australia and our politicians don't care about the freedom of our citizens. The exact opposite, in fact.
They have already brought in draconian metadata retention laws [1], despite the ministers involved not even being able to explain what metadata is [2], and are now trying to bring in a bill to literally install malware on our phones with no judicial oversight. This all happens unopposed in a bipartisan way, I suppose because no politician has the spine necessary to defend a position that, even though good for the vast majority of people, could be trivially misrepresented as being "soft on terror".
I'm as much in favor of stopping terrorism and most other crimes as anyone else, however I am far from convinced that blanket spying is an effective way to achieve those aims, and the negatives are so great. There has been no discussion on whether the loss of our freedoms is worth the actual damage. The people did not vote on these laws. Instead it is secret this and secret that, and everything is by default classified for "security reasons".
On a population scale the losses from terrorism have been minimal. Far too minimal to justify such massive changes to our fundamental way of life with no provided metrics in support, or any way provided to measure how effective those changes have been.
And what are we protecting if not freedom? Because a world where everywhere we go, and everything we do or discuss is recorded forever by Big Brother for later analysis is not freedom. There should be a right to privacy.
I guess that's why the people were not consulted. Better to ask forgiveness than permission. Although in this case they haven't even asked for forgiveness - they're not asking at all, and when discovered, doubling down!
Such surreptitious behavior does not inspire trust in people in charge of the greatest surveillance apparatus the world has ever known.
Frankly I do not trust our security services to safely handle all our personal data. There will be abuses of that information as well as false positives. Also data breaches and leaks. The government is not adept enough at data security to handle the multitude of hackers that will want to gain access to the worlds largest honeypot of blackmail information.
With the metadata retention laws of 2015, there has been an "authority creep" to now 81 entities who have requested that data, most of those agencies being unrelated to terror.
When the legislation was introduced, cutting down on the number of organisations that could access the data without a warrant was used as a selling point by the government, something which now seems laughable.
Centrelink is on that list of entities that have accessed that data, despite them having no authority under the Telecommunications (Interception and Access) Act 1979 to request metadata. [3]
The safest thing is not to collect all that dangerous data at all. There is enough data available with a warrant now (eg location data from phones) to investigate crimes. In the old days, actual police work was necessary. Every contact leaves a trace.
Anecdotal, and possibly I'm just uninformed about this, but it seems that almost every time there is a terrorist incident, the people responsible are already on some watchlist and known to the authorities.
[1] https://sydney.edu.au/news-opinion/news/2017/07/31/new-data-... [2] https://www.news.com.au/technology/online/social/george-bran... [3] https://www.computerworld.com.au/article/641100/digital-righ...
I agree with you. We do need to have election-level discussions on the trade-offs of surveillance and security. These go hand in hand with similar discussions on privacy, handling of private/personal/personally identifying data (I am tempted to get my genome sequenced for 200 bucks, but you know the company involved will have my genome. Forever. What can they do with it. If they go bankrupt what can the purchaser do with it?)
These are big questions, and we will only grok then answers in a generation - but we should most certainly not assume governments or corporations will do the right thing without regulation.
>>> The safest thing is not to collect all that dangerous data at all
But there is a benefit to collecting it as well - from genomics to terrorists mothers phone calls.
Snowden is an embarrassment for those who use human rights, freedom and democracy to further other interests. Hence the deafening silence. The entire ecosystem that supports dissenters with asylum, grand freedom narratives and wall to wall coverage about evil regimes and heroic protest closed shop for Snowden, Assange, Manning and others.
Imagine the hysteria of the 'free world' in unison against the totalitarian chinese if there was no Snowden and a chinese dissenter leaked something like this, and his or her subsequent global fame as a defender of freedom. Now look as Snowden stranded in Russia and Assange in the Ecuador embassy. That is the pathetic state of pretension.
And instead of demonizing others and filling pages upon pages scaremongering about totalitarian surveillance vs democracy, its surveillance that is being demoted to a lesser transgression, even something 'acceptable' if not 'necessary', and that's what Snowden changed.
That's a silly thing to imagine. China makes no secret of doing domestic mass surveillance (and censorship) far worse than anything in Snowden's leaks.
"Suddenly, everybody knows, and nothing's changed," security technologist and author Bruce Schneier told Ars. "It was never a campaign issue. We tried to make it one. We failed... the subsequent changes are very small."
tl;dw people care when dick pics are being surveilled
Here's the hard truth: the overwhelming majority of Americans don't care about being surveilled. They may say they do, but at the end of the day, the issue doesn't affect most of them directly (or even indirectly) and therefore goes to the bottom of the pile.
So... well played, government.
Then, Rome.
We’re also perfectly happy making money in the employment of those making the problem worse, e.g. Facebook. Silicon Valley has neither the political stamina nor moral high ground for solving this problem. In its absence, there isn’t a clear coalition leader.
"Yes you do. Do you have curtains on your windows? Do you wear clothes? If you don't care about privacy, open your curtains and walk down the street naked."
But the fact is that apathy is so high, that people don't give a damn when they're installing some app -- we're too focused on getting what we want (at that moment in time), and really not caring about sending up personal details to the cloud.
When I try to talk about apps (eg Messenger, WhatsApp) that requires access to the contact list -- everyone I've spoken to really don't care. They don't care that my details are sent to some company (FB) because they want to use WhatsApp.
When I try to talk about state level surveillance, I try to liken it to some sleazy guy taking photos up a woman's dress. It's wrong, no matter how you go about it. Just because I'm "in public" in no way suggests that I should be subjected to a "fully exposed" surveillance system. The same goes for the internet. Of course, this last part is non-legal rhetoric of mine, but I genuinely feel that if I think that I should have an expectation to privacy, regardless of my location, then the civil and polite thing to do is to respect that. State level surveillance all too easily disregards civility and politeness in the pursuit of their goals.
A simple example: recently there was the article about the DEA and ICE putting cameras in streetlights [0]. It is easy for the common person to understand how such a thing could be hacked and used to stalk someone. But the examples you use should target your audience and illustrate why they personally should be concerned. Because talking about turnkey tyranny is fairly abstract to most people.
[0] https://qz.com/1458475/the-dea-and-ice-are-hiding-surveillan...
2FA, E2E communications, TLS everywhere, tightening security on our phones and computers, Congress rolling back some of the NSA’s dragnet powers, allied countries switching to open source and re-evaluating intelligence sharing agreements, and a sharp rise in VPN use is nothing?
What popular by masses E2E encrypted comms are there?
It would be nice to see if things have changed behind the scenes. My hope is that more of them are just complying with court orders and refuse cooperating with mass surveillance. Mass surveillance without cooperation is very expensive and don't always work.
https://en.wikipedia.org/wiki/Joseph_Nacchio
https://en.wikipedia.org/wiki/Qwest#Refusal_of_NSA_surveilla...
Now, we know it.
Nah, it's stuff that reinforces what the government is doing or shows problems that wouldn't lead to rebellion. Pretty consistently. Especially the one or two episodes of Person of Interest I saw.
Section 3. Treason against the United States, shall consist only in levying war against them, or in adhering to their enemies, giving them aid and comfort. No person shall be convicted of treason unless on the testimony of two witnesses to the same overt act, or on confession in open court.
The Congress shall have power to declare the punishment of treason, but no attainder of treason shall work corruption of blood, or forfeiture except during the life of the person attainted.
Example: Some weeks ago the United States decided to sell out the fingerprints of 210 Million American citizens with the Netherlands, a tiny nation with aprox 20mil inhabitants and a insanely bad track record when it comes to infosec. This dot on the map is now enabled to unlock millions of phones, empty bank accounts, create compromat and so much more.. .
Edit: The only source I have is in dutch: https://www.trouw.nl/home/nederlandse-vingerafdrukken-worden...
Well, maybe not _that_ surprised, this is a very American-centric community.
Snowden's revelations had a direct effect on transatlantic ties, with the Court of Justice of the European Union holding that the EU-US Safe Harbor system violated the essence of the right to a private life. That's a big deal, and it's a very important piece of case law here now. I'm not sure if Schrems would have been able to make his case without those details being made public.
In the short term, it’s entirely possible - there’s probably some productivity metric (it’s not exactly a well-defined term) that was negatively impacted. Long term, honesty is the pillar atop which so much of what’s good in life is built (and that does include some measures of productivity: effective business decisions are those supported by fact and grounded in truth). There’s just no frame of reference in which an honest person can support sacrificing the truth in exchange for some temporary, perceived improvement in quality of life.
It’s a pointless endeavor, anyway: anything built on falsehood will, eventually, be exposed. Leaks happen. Though Snowden is exceptional, his story is hardly an exception to the rule.
I do feel less stressed now, because i was aware of what he made public. As for general public, I believe it added stress, and it is right thing, it might lead to some changes, and slow down surveillance apparatus.
"Do they think I'm spying on them, after Snowden reported that NSA men passed around private images of girls they found? Will I be named in the history books as a monster?"
It's always worth it. It's karma.
Let's Encrypt doesn't ever possess your private keys, doesn't know who connects to your site if you use OCSP stapling, and doesn't control what kind of cryptography you use when negotiating TLS sessions with your site visitors. Let's Encrypt also doesn't need any contact information from you when you obtain a certificate.
Let's Encrypt certificates aren't trusted by Chrome without a proof of inclusion in public Certificate Transparency logs, so all issued certificates have to be disclosed.
As I've said in a number of HN comments, the people working on Let's Encrypt generally still think that the CA system is too powerful, and are happy for your suggestions about how about it can made more transparent and less powerful.
Looking forward to it. I imagine, when SSL becomes mandatory by browsers, it can be used for censorship.
Can someone explain how that works? I thought SSL would make censorship less practical.
https://nakedsecurity.sophos.com/2013/01/08/the-turktrust-ss...
Anything that gets into your bundle establishes incredible power over you.
If SSL is required, then whoever controls those agencies controls what's seen online.
I already cannot easily add a root CA for .onion addresses and then make my own certs there, without browsers screaming bloody murder.
I already cannot bypass cert errors for certain types of cert fails.
Tor onion sites, which are end to end encrypted, are considered "insecure" because we plebes cannot buy a "proper" EV ssl cert, like Facebook did.
Enforcement of SSL is just another way of controlling the user in name of "stupidity". Sure, the dumb click-anything users win, but anyone tech-savy loses freedoms.
How would you want this to work? What would you want to do, and what would you want browsers to do in response?
https://letsencrypt.org/2015/10/29/phishing-and-malware.html
We need another Snowden to leak how corporations source, aggregate and store your data. A whistleblower from inside Google/Facebook/AdTech/CDNs.
Our relationship with shops has changed over the last 30 years thanks to CCTV (affordable webcams) and point of sale systems. We went from an era where we were not expected to be 'filmed as we shopped' to taking it for granted.
In the pre-CCTV days different strategies were needed for preventing slippage. Helpful shop assistants would ask suspicious customers if they 'needed any help'. Having stock locked away in glass fronted cabinets helped too, having all the goodies behind the counter or in hard to get to window displays helped too. There was a lot more going on than physical security though.
If your prices were actually reasonable and if everyone in town loved your store then you wouldn't get robbed. Being locally owned rather than part of a chain helped as theft from a big chain could be imagined to be only costing some notional insurance company (in a thief's mind wanting to justify stealing). Community also mattered in that nobody wants to steal from a shop they rely on, so getting barred from the local newsagents was not a desirable outcome. Nobody would steal a packet of sweets from a shopkeeper who they knew the name of and depended on for their daily newspaper/milk/fags/top-shelf magazines. Kids could be watched or only allowed in two at a time, adults could be trusted due to soft levers of trust.
Nowadays though you just wouldn't have a fortune in stock laid out ready for people to slip into their pockets, you would have CCTV, on every aisle, from both sides and from both directions. You would have some outsourced security contractor monitoring the CCTV and telling staff if they needed to apprehend anyone. There would be no 'he said vs shopkeeper said' discussion with the police, CCTV does the evidence providing bit.
The thing is that the CCTV works without anyone looking at the monitor screens. The 'smile you are on CCTV' signs are a huge part of it. They instil fear in the souls of the shoplifter. Coupled with this there is no need for patrons to actually know the staff or for them to know neighbours that could also be shopping. With increased mobility (people shop far and wide these days) the nature of shopping has changed.
The difference that the Snowden leaks have made is that we now know that the CCTV is 'everywhere', in our email and phone calls too. This ubiquitous spying works in a similar way to CCTV in retail - behaviour is controlled. We accept CCTV in retail in part because we want our pint of milk (or whatever it is) and there is no option to buy what we need from places that don't have CCTV. We are not going to buy a pasture and get a herd of cows going just to have that spot of milk in our tea. CCTV can't be objected to. Similarly in post-Snowden world we still have needs to communicate and we just have to accept the spying. That is what has changed, an acceptance of it.