We achieve this by making encryption easy, powerful and ubiquitous. That will take care of their dragnet espionage.
Ubiquitous encryption will be pointless if the encryption itself is subverted, like it was for 50 years with the 2 leading Swiss encryption vendors. I imagine the CIA/NSA would target the PRNG hardware as the crown-jewel, and the next-best targets would be "enclaves", then back-dooring the algorithms themselves (or implementations thereof).
Remember - their aim isn't to break encryption (which would be simple to spot) - it's to make it easier for them to break, while remaining hard for everyone else.
The cryptography community seems to already be aware of this risk. I've read about random number algorithms that mix the results of many randomness sources so that one compromised source cannot compromise the result.
> and the next-best targets would be "enclaves"
Yeah, we should watch out for this. Secure cryptoprocessors are a great thing but we need to be able to trust them. We already have hardware that runs free software but the chip itself can of course be compromised...
> then back-dooring the algorithms themselves
I trust that the worldwide cryptography community will never let that happen. From what I've read they no longer trust the NSA implicitly.
I wonder who puts in more expert man-hours into safeguarding/defeating crypto: the US alphabet soup agencies, or the rest of the of the "worldwide cryptography community". I'm fairly certain the government spends more dollars (doing things like factoring enough primes AOT to be able to decrypt ~20% of all https traffic in realtime[1]). Often things that community concludes to be "unlikely" or "difficult" are well within the governments ability - cue "SSL added and removed here ;-)"
I think the fact that the cryptography community didn't pick up on Crypto AG's subterfuge says a lot, IMO.
1. https://arstechnica.com/information-technology/2015/10/how-t...
You might like djb's article "Entropy Attacks!": https://blog.cr.yp.to/20140205-entropy.html
When people's needs aren't aligned all these personality variations in the population come to the fore.
Who cares if they should or should not exist? The point is that they are there in most countries already (nothing limited to the US) so worrying about the ideal situation of not having them around is not very helpful. Just like "we should not have nuclear weapons" is a very weak argument as there's no way you can put the genie back in the box.
Such organizations are simply necessary to run a nation. Global politics is a game, and everyone plays it. It involves gathering intelligence and acting on it. The work isn’t beyond reproach, and the nature of secrecy makes doing dirty things an unavoidable consequence... but ultimately you have to accept that reality is messy, the world isn’t very nice, and sometimes you don’t have a choice as a nation but to do some detestable act for some higher purpose... and rarely will it be possible for the whole story to be told publicly in order to be judged fairly.
Sure it would be nice if everybody stopped being so awful to each other, but you can’t pretend like that is already true if you don’t want to lose everything.
In plenty of circumstances intelligence agencies have done things that never should have been done, but that isn’t an argument to stop all together.
It's always important to force yourself to remember that essentially all detestable acts are done for detestable purposes, no matter how selfless the rhetoric tries to make them sound. There may have been a handful of exceptions in history, but they are so vastly outnumbered by the other kind that they can safely be ignored.
The narrative of doing something for the greater good should be treated as a lie until the burden of evidence is so high that you are forced to accept that it was indeed good. In particular, spy agencies have produced far more terrorism, coups, and disinformation for their own people, with the goal of supporting the monetary interests of their nation, all others be damned, than they have ever defended anything. The exceptions almost always happen when the goals of empire happen to be aligned with those of the people, like during WW2.
An obvious impossible standard, more than that you can’t really know if an action was right or wrong without an oracle to tell you what would have happened if different forces had been made.
Nations can’t just disappear, anarchy always transitions to tribalism to monarchy to ... etc.
Rewriting my entire home operating system to be the ideal may be a fool's quest, because one person will never be able to do as much work as the hundreds or thousands who developed the code he is replacing, but if you want to try it is entirely on you. I can putter away in my basement for years without bothering anyone.
Replacing or reforming a political system is fundamentally different because it requires the buy-in of a large portion - a super-majority ideally, but at least a powerful minority if you're willing to play violent or dirty - of the population to get started. And you can't just show up out of the blue with A Plan and expect people to all be on board - even if your plan is really quite good, human nature means almost no one will want to commit to someone else's plan. So you have to develop your plan in a group, making compromises that you may personally disagree with to get larger and larger groups of people on board, until, unless there really was a large number of dissatisfied people in your camp all along - which we all want to believe but is seldom the case - you end up politicking your way to a revolution that is barely different than the status quo.
Because we ourselves, our bodies, are an emergent system rather than a designed one?
Human biology seems to be even more chaotic than various political systems on Earth, but both have one great advantage under their belt: they survived unexpected crises in the past.
Designed machines tend to be nowhere near as robust.
If one day they have all disappeared, it just means they hid themselves from you, and fooled you completely.
As long as my devices can fend off the generic attacks, like script kiddies, port scanners, DNS hijacking at public wifi, I'm content.
That said, my defeatist attitude is at least partly because I'm a nobody. For high-value targets, they must have their own method of protection that doesn't rely simply on a promise to be neutral.
No they don't, if you know in the first place that your a "high value target"
Crazy, that such a seemingly simple idea was only realized as recently as 2015.
I think that's obvious, since the days of telnet/rsh.
It's a nice thing to say but it doesn't work, at least not as a oneliner without further explanation of how you think this could work.
Meaning, I would prefer the can of baked beans from a company that is open about where their beans come from and in what conditions. That would be possible today, and is already done to some extend but in early stages.
But getting your food from the local farmer, where you can actually visit the farm, it is much more easy to trust that it is good.
And regarding software, well - open source, preferably with a open community (or company) around it, where you can at least look through the actual dev logs and git submits to see if they sound solid and if you have the time and skills, jump into it to verify that they do as promised.
Then I can have trust. Otherwise the trust would have to be blind. And society has spoiled that for me, for various reasons.
Please don't try to shoehorn open source principles everywhere in life. It becomes a chore and a burden for a common citizen to verify the hazards of Baked Beans. Citizens offload this to a regulatory agency. You don't have the time to verify a fucking can of baked beans like a million other things in life.
If you buy a measuring tape, do you ask for a NIST certificate? Where does the chain of trust end? Somewhere at the measurement standards in the pyramid of trust. Your personal role in this chain ends at the brand name "STANLEY", because you trust them to make a measuring tape that measures within specified tolerance.
The whole movement around "I don't trust unless the information is freely available" is a pipe dream. It grinds the society to a halt.
I urge you to look around 99% things in life that you just blindly trust. We need better mechanisms for building trust than "Don't trust unless verified". It is applicable in high risk situations, but the society pays a huge price for such an inefficient way to live.
But I agree, it is not efficient to question everything. I do not want to question everything! But I do know enough, to question a lot of things.
Secrecy just allows bad things to stay hidden.
If the default would be openness, then people who do bad things would hesitate more, as it would be easier to detect those things, don't you think?
Whether it be government, food production or software.
Transparency builds trust overtime.
Yep. This is what I mean.
I come from east germany, a former post sowjet state. A state which was build on blind trust on the state and no way for the common person to verify anything (or even dare to question anything openly). And big surprise: lots of dark things happened regulary.
Now things are still far from perfect in my opinion, but much, much better. And I think they can still improve a lot with even more transparency, because there are still lots of dark things happening behind closed doors. We probably just disagree on the degree of those things.
The former Soviet states and other USSR satellites were not built on trust, they were built on force. You had to act like you trusted the state to avoid the repressive force of the state.
But people did not trust the state at all, much more so than in today's world. Everyone assumed their telephones were listened to. Everyone assumed that the walls had ears. The lies of the state were often obvious, and often discussed with very close friends and close family, and anything that wasn't an obvious lie was thus considered a likely lie anyway.
So, baked beans are probably OK in terms of SIGINT. Depending on how well food regulations are enforced in your area, I might or might not worry about the edibility of them, though. But on-line services are definitely suspect with respect to data handling. Doubly so, if they pop up where they shouldn't be in the first place - like e.g. IoT - as that's already evidence of a business model built on abusive relationship.
Hanlon's razor, "never attribute to malice that which is adequately explained by stupidity", does seem to apply to that particular one, though. But I'm no war historian or politician or something; while the security of these devices is stupidity to the point of criminal negligence, I find it hard to say for sure whether some of this might be on purpose.
Also, I wasn't thinking about security. I was thinking about intentional abuse of data, that starts with collecting and processing data that doesn't need to be done for a device to function.
--
[0] - Introduced in https://news.ycombinator.com/item?id=21691282, named after me in https://news.ycombinator.com/item?id=21691718 :).
The CIA, NSA, DHS, etc are all much, much smarter than me, and I would use IoT to compromise targets if it were my job. So there's that data point.
> baked beans are probably OK in terms of SIGINT. Depending on how well food regulations are enforced in your area
Unless you meant the IoT part, I'd love to see regulations, let alone enforcement, there.
For example, if you've seen Christopher Domas's talk/s on finding undocumented features of CPUs, any backdoors in a modern CPU will be buried deep in the vendor-specific features or require an extremely esoteric combination of register values and the like.
Yes, you can never 100% get rid of some trust, but it does not mean that you should give up and verify nothing. The more you (are able to) verify, the more secure you are.
We need a way to manufacture our own hardware. Just like we can already write our own software.
Currently manufacturing processors costs billions of dollars. Consequently, the power to create computers is centralized in very few hands. They are easy targets for government regulation and compromise.
What if we had technology that would let individual users fabricate their own hardware cheaply? That would give the power to create computers to everyone. We would then be able to create chips we could trust. Nobody would be able to interfere.
This "trust no one" is complete BS. A modern human society can not function without some trust.
We may write code but we didn't write the compiler which compiles the code. We didn't develop the runtimes, kernels, etc our software is dependent upon. The security, reliability and trustworthiness of the entire software world is dependent on trust.
You should read Ken Thompson's article on "Reflections on Trusting Trust"
> Currently manufacturing processors costs billions of dollars.
> What if we had technology that would let individual users fabricate their own hardware cheaply? That would give the power to create computers to everyone. We would then be able to create chips we could trust. Nobody would be able to interfere.
Absolutely. I believe that today's Capitalist/Corporate production (in contrast to Commons-based peer production or communism) undermines human ingenuity. Most of today's industrial production processes are wasteful. The corporate products it creates are non-modular and bloated, and waste energy and resources (especially since barely any e-waste is recycled or re-used).
If all tech was open source and there were no monopolizing and artificial scarcity -generating systems
If all tech was free/libre open source, and if there were no monopolizing and artificial scarcity -generating systems that put artificial limits on digital information systems that allow for a near-zero marginal cost of reproduction (I'm referring to the Intellectual Property systems and the (inter)national courts that enforce these property laws), and if all the latest research and developments were also shared open source - and only a system for authorship claims to help identify successful inventions/discoveries to note who contributed to the experiments that succeeded (to guarantee they those people can continue to be involved and supported to continue to do this work), existed, then the world would be able to radically skill up (growing, over time, what Karl Marx called, the 'General Intellect': "the general social knowledge or collective intelligence of a society at a given historical period") - then we'd be able to more thoroughly tackle so many of the problems we're facing today in new innovative ways. Stated inversely: today we cannot tackle many challenges effectively (collectively) because of artificial limits placed on knowledge and important discoveries/mechanisms.
I believe that the biggest obstacle to successfully averting a fatal climate crisis has to do with how we see, and work with, 'intellectual property' - which is basically privatized knowledge. Today's Global North elite/bourgeois Intellectual Property systems and agreements are facilitating the biggest theft that is happening to the working classes. It could be argued that it is the most violent turn of Capitalism to date, in that it deprives many children the right to ask questions, and forcefully prohibits human curiosity in general. Or at best it puts an exorbitant rentier price on ‘education' (e.g. in the form of an academic degree) and other learning materials. Intellectual Property systems have pushed the privatization and commodification of immaterial Commons to the furthest edges, exploiting and oppressing the working classes; especially alienating, dominating and disenfranchising the working class in the Global South. [1],[2],[3]
I believe the key strategy for proletarians, together with bourgeois class traitors, is to move towards a new Commons/natural-resource stewardship system.
I'll try to further describe what I hope for. Today, Corporations carefully track their total available material resources within a corporation through what's called an Enterprise Resource Planning (ERP) software system. The folks at Valueflo.ws and Holo-REA (REA = Resource Event Agent) are using the open-source distributed data-integrity engine called Holochain to allow groups of people to mutually-'self-sovereignly' peer produce; using what their team, together with Sensorica, have come to call a Network Resource Planning (NRP) system, or software.
This NRP configuration/system replaces ERP systems and instead creates and enables a fractal Open Value Network, meaning that humans are now able to more accurately (+ accountably and transparently) coordinate, map and plan how we'd like to share mother earth's precious resources/Commons.
Most importantly, I believe that by moving away from today's means-of-exchange money system, we lose the need to use artificial scarcity creating systems that privatize knowledge:
"Let's just replace the unit of account with distributed ledgers, let go of transactional mindsets requiring a medium of exchange, recognise our planet's resources as the store of value and be done with it" — @pospigos [4]
Workers of the world, unite!
[1] Vijay Prashad, https://www.thetricontinental.org/the-rate-of-exploitation-t...
[2] Jakob Rigi, https://www.triple-c.at/index.php/tripleC/article/view/487/6...
[3] Wendy Liu, https://tribunemag.co.uk/2019/01/abolish-silicon-valley
Will otherwise intelligent people want to fight tooth and nail if I mentioned any specific VPN provider being incapable having privacy assurances you can rely on? Of course so lets do it anyway
Protonmail
NordVPN
ExpressVPN
every one
It doesnt matter what you want to believe, the entire concept doesnt do what people think it does.
You would simply have no way of knowing if a VPN suddenly did start keeping logs.
I agree if your threat model requires that nobody eavesdrop/log your traffic, then a commercial VPN service probably isn't the right tool, and you should probably use tor instead. That said, it doesn't mean commercial VPNs are placebo/snakeoil. They still provide:
* anonymity from the websites you visit: your home internet connection's IP typically uniquely identifies you/your household (assuming no CGNAT). Meanwhile, a VPN server might be used by tens of hundreds of people, which greatly increases your anonymity set. It's further improved if you rotate VPN servers, because a VPN service might be used by millions of people.
* extra degree of separation: your ISP knows a lot of info about you (name, address, payment info, maybe even credit score), whereas a VPN service might only know your email and the ip you connect from. If your VPN service decides to go rogue and sell your browsing habits, they'll have a much harder time associating it with your real life identity.
anything that requires a government not knowing is outside of the use case
https://en.wikipedia.org/wiki/Swiss_neutrality
which has also contributed to diplomatic meetings often being held there, treaties often being negotiated there, and headquarters or offices of international and intergovernmental organizations often being based there.
Just in Geneva you have https://en.wikipedia.org/wiki/Geneva#International_organisat... and that doesn't include all the treaties, one-off diplomatic conferences and meetings, or confidential diplomatic interactions.
The Swiss neutrality policy would seem to imply that you would be safer overall meeting there or that you could trust the government not to have an alliance which would mean it was helping some other country undermine your activities in Switzerland. So this reporting on Crypto AG as well as this company can be seen as a criticism that the Swiss government failed to uphold its principles of neutrality, or perhaps (depending on the degree to which the government was involved or aware or not) that the companies were getting a benefit from the international perception of the famous Swiss neutrality while themselves having political dealings with particular governments.
I think Snowden also mentions in his autobiography that, because there is so much international activity and discussion in Switzerland, other countries' spy agencies also like to spy on Switzerland and goings-on there -- including him when he was working for the CIA. People who are trying to rely on Switzerland's neutrality might hope that Switzerland succeeds in deterring much of that spying activity, and at least doesn't participate in, condone, or encourage it.
Just first best Link: https://www.20min.ch/story/spionage-verdacht-gegen-die-berne...