Help make mass surveillance of entire populations uneconomical
prism-break.org
prism-break.org
If you actually want to do something like communicate with a journalist while hiding your own endpoint from exposure you have to go to fairly ridiculous lengths, such as acquiring a laptop used only for that purpose and which has no associated identifying information, use random open Wifi networks to log onto, and have a decent understanding of the concepts of public-key, asymmetric and symmetric cryptography.
Note that there is simply no way for two known parties on the internet to hide the fact that they are communicating with one another from government-corporate managers of the Internet - although it's possible to keep the content hidded, to some extent, unless your passwords get compromised, which seems fairly easy to accomplish for such actors via keylogger malware installed through backdoor attacks using secret zero-day exploits and so on.
The only real solution is the passage of data privacy laws that provide criminal penalities and which allow class-action lawsuits against corporations and governments that engage in warrantless mass surveillance or the retention and aggregation of customer's personal data in searchable databases.
https://en.wikipedia.org/wiki/Turbulence_(NSA)
This is of course what an outfit like the STASI or Gestapo would do, isn't it? If you're actually trying to hide from surveillance, the best tactic is to hide in plain sight, maintaining a cover story consisting of bland normal online presence that doesn't draw extra attention.
Of course living in an authoritarian panopticon and having to hide in this manner is an undesirable situation, and the solution is not technological, but rather political in nature. One basic issue is transparency, i.e. the public should be able to see what the intelligence agencies and corporations are up to with their surveillance programs. This is why Snowden's exposure of PRISM, XKEYSCORE, TRAFFICTHIEF, etc. was in the public interest, i.e. legitimate whistleblowing.
Instead, social/cultural solutions might be the key. If only a few people use these mass surveillance avoiding tools, then yes, they become targets. But if almost everyone uses them and they become ubiquitous, the landscape changes some.
I don't think political solutions are impossible, but if they are then our government is incapable of executing the public will. I think the key to generate this type of change is to tell a very compelling and broad story about why the current situation is unacceptable. Discussing {history lesson} or {personal security risk} doesn't seem to be a strong enough narrative. A very strong narrative can turn public opinion and force action by lawmakers. Over the last 100 years there has been a number of examples of popular opinion becoming so massive that the political system has to do something they clearly did not want to do.
* The draft is now reserved for emergency use only. Previously it was used for Korea and Vietnam, which were more about global power projections than direct threats to the US.
* The role of the US Military is moving away from World Police and limiting itself to more directly protect American interests. Troop deployments are highly scrutinized by the public and impact Presidential approval ratings.
* Cannabis went from the poster child for war-on-drugs to essentially unenforced federally and openly cultivated/traded/consumed in large regions of the country. Rules on Magic Mushrooms, MDMA, and Ketamine are beginning to loosen to.
* The end of COVID lockdowns and mask mandates in the US was largely determined by grassroots actions instead of top-down decisions.
I don't think it really even tries to.
To get past those "using these tools makes you suspicious" phase, you have to convince everyone to both care and to use the tools.
Once they care that much, the political solution is also much more feasible.
The methods of the STASI were extremely crude and different to what is available today. They relied on human informants and collected lots of paper.
Sure some genius might think their model has got me nailed but even when I had a Twitter a decade ago and asked for my data Twitter had my age, gender (details I had in my profile btw) and number of kids I have wrong.
The problem with tech companies is they’re run by people and people are pudding brains who believe in magic. The problem with AI, as Chomsky said, is people will believe it. It’s true because they’ve been believing these other terribly inept systems they built, whether technological or social.
The political solution requires a political consensus, and that's unreliable.
Defending your liberty with tools you own requires a social consensus, and that's unreliable.
Both are subject to change over time, thus both need to be worked on and managed.
I feel like I should be putting on my tinfoil hat saying all of that, but the reality is that these systems are less and less throttled by the availability of human brains to process the data the automated surveillance systems collect. We made a mistake in thinking that labor costs could ever be an effective guard rail for these tools.
The important thing to keep in mind - and one that I find most nontechnical people don't realize - is that over time mass surveillance and targeted surveillance trend to being the same thing.
Centuries, or even decades, ago mass surveillance was a dictators dream but merely a fantasy. There was no way to do it, not enough people or time, so it was impossible. You could only do targeted surveillance against selected groups or people.
With current technology these are starting to merge. You can actually spy on everyone all the time and store it for later perusal whenever you need to perform a dragnet search in the future.
We're not there 100% quite yet but every year more activities are online and more bandwidth and storage capacity makes it more and more viable to monitor everything and everyone all the time.
The legal and cultural framework to deal with this does not exist. Laws and mindsets are still focused only on targeted surveillance and cover things like search warrants.
Not entirely true. I could post a message on a popular forum like HN, where the message contains a hidden message.
I used to collect thousands of memes and just blast them to my mother indiscriminately. Then I wondered whether silly-looking memes could be carrying secret messages, or just nasty hidden stuff. I decided to stop helping traffick in that stuff.
Has anyone read/seen Mother Night? That's a real good example of how secret communication can hide in plain sight.
Are there any confirmed examples from non-fiction?
The Least Significant Bit method is used frequently for the legitimate use of watermarking image, video and audio IP. It is a simple technique that embeds the watermark data into the rightmost bit of a binary number (LSB) of some pixels of the cover image.
It is also very common for malware to hide it's configuration data or payload within image files. (ZeusVM, Zberp, NetTraveler, Shamoon, Zero.T)
> The criminal complaint alleges that on or about July 5, Zheng, an engineer employed by General Electric, used an elaborate and sophisticated means to remove electronic files containing GE’s trade secrets involving its turbine technologies. Specifically, Zheng is alleged to have used steganography to hide data files belonging to GE into an innocuous looking digital picture of a sunset, and then to have e-mailed the digital picture, which contained the stolen GE data files, to Zheng’s e-mail account.
In the UK atleast such as this BBC page[0]. As do the Guardian, Bloomberg and many more Im sure.
I appreciate that it is an involved process as you say but it doesn't seem excessive especially if you can use your smartphone now that tor browser is on android and iOS.
They already had law enforcement integration and judicial precedent dismantling the 4th Amendment.
...Now that you have me thinking about it...sigh... Yeah. I think I see where you are coming from. Funny how you can take an Act name, and map the actual outcome to the exact opposite of what the name would imply in layman's terms.
AFAIK governments empower specific agencies and groups with qualified immunity. How would such laws be enforced if an agency has immunity?
Powerful people can lie, cheat, and steal and face zero repercussions. They hold institutional power so groups like the police will protect them regardless of laws being broken. It's not illegal for a corporation to either literally or metaphorically kill someone, because there is no body that will hold them accountable, but it is illegal to assassinate a CEO and systems will pull all stops to hold the assassin accountable.
Its the real reason why Western style democracy ends up being a busybox for people who like rules. The people who can grant endless exceptions have addresses and beds where they rest their heads but people without power cannot decide on an exception to the rules, regardless how dangerous and damaging that person is.
>Huge stink and nationwide conversation ensues.
>High ranking member of political party 2 does the same damn thing.
>Crickets.
You can even reverse the order of the events or parties. It happens a lot. Such laws, unfortunately, simply become political tools.
Nation states may have a lot of budget, but they still have a budget. Mass survelience needs to have low per user cost to succeed. It is entirely reasonable to assume small changes if widely adopted could make mass surveilence ecconomically unfeasible.
Even your own example — a whistleblower talking to a journalist — illustrates that the fear is not of people who abide by laws, but people and organizations that don't care about the laws.
I'm not saying that there shouldn't be laws. But like almost everything involving human beings, the solution is not an if-then binary choice.
You have laws, but you also have mitigations.
Your view point sounds like we should give up on any form of legislation the rich and powerful would not like.
Without such laws, every business would store as much data as they could indefinitely, because $$.
All of this is besides the point that was made; your fatalistic view point suggests we should make no attempt at effective governance because there are powers that oppose us. There are countries which are more democratic than others, and the population of such countries tend to have a better quality of life and more rights.
When has the government ever wanted less surveillance power or less control over the internet.
But yeah, it may not be realistic to think that we can stop the expansion of surveillance powers for TPTB and erosion of rights for the average citizen, given the consistency and persistence of the proponents of such crap. When I look at trends of the past 20 years, it seems like wherever the law has fallen short of placing everyone under a microscope, private industry has conveniently stepped in to become the 1984-telescreen service providers instead of the government.
See! Government involved in your life!
Nice job building a firewall between society and government control.
At the end of the day it’s all people. The semantic bubbles do nothing to change its all just people looking to externalize effort to live simpler themselves.
Because of the setup of the electoral college, 2 senator per state where RI has the same number of Senators as California and gerrymandering, it is very much about the will of the minority.
That’s not to mention all of the things that get done by unelected officials and judges with lifetime tenure.
One with lines like:
"The Congress shall make no law..."
"The People shall..."
"...shall not be infringed."
"All powers not mentioned here are reserved for the States, or ultimately, the People."
We're beyond the point where good faith can be assumed, and we're down to brass tacks. Our judiciary has shown they are more than willing to creatively reinterpret precedent as they see fit. Our Executive is acting more and more like a dictator with an entire corpus of executive based lawmaking at his disposal (Administrative Law). The Legislature has abdicated responsibility for reigning in excesses in the interest of the little people rather than established incorporated interests and high value donors.
And the People are left with a choice. Amongst all this dysfunction, what should they do?
Even the GDPR with its huge impact and global implications does not apply to law enforcement agencies. So I wonder who would make such a law?
So much ink is spilled talking about cookies, ads tracking, etc. But really what's the worst a corporation is going to do? Try to sell you something?
Meanwhile, we continue to allow our governments to regulate and legislate ever more intrusive invasions of our privacy. And they can put us in jail, or worse.
This also gets blurry as governments take increasing control of companies, to the point that some are just about arms of the government, surveilling us in ways that the government can't (yet) do on their own - and being forced to pass that data to the government under penalty of law themselves.
We should be pushing to close these warrantless search loopholes, but in the meanwhile the only pragmatic way for an individual to maintain privacy is to prevent any and all third parties from collecting the data to begin with. After it has been collected, you have no control and no reasonable expectations of how it will be used.
[1]https://www.eff.org/deeplinks/2022/06/how-federal-government...
[2]https://www.nbcnews.com/tech/security/can-government-look-yo...
[3]https://arstechnica.com/tech-policy/2020/07/cbp-does-end-run...
This is what I have been doing. What can you add to this?
On phone disable Bluetooth, disable precise location, disable location and infrequently turn that on for something like photo geotag, use carrier phone number for nothing and use phone numbers from googlevoice or others. Put cars in LLCs or Trusts with address at POBox or UPS. Never use home address for mail unless it is from family. Put utilities in name of LLC or Trust.
Yes, the larger issue is that the government has just outsourced a lot of the work to corporations to get around the Constitution. If there were any integrity left in the US government, there would be a reckoning about this. We worry about regulatory capture, but the bigger problem is deep state/military-industrial complex capture.
Companies are building surveillance infrastructure that is:
* way ahead of governments in terms of technical capability (NSA and top-level intelligence agencies are outliers, but your average government IT departments are too incompetent to be of any threat)
* widely accepted and not regarded as malicious - not even the NSA can get people to voluntarily include some malicious Javascript on the vast majority of public-facing webpages, yet Google Analytics managed exactly that
* profitable and self-sustaining - the government doesn't have to spend money on building and maintaining it, nor needs to justify its budget/spending
Those companies however are still at the mercy of governments, either via violence/coercion (in the US, they have to obey a national security letter by law, or armed goons will show up) or mutually-beneficial relationship (a lot of companies either outright sell this surveillance data to the highest bidder, or don't outright sell it but will be happy to let the government in on it in exchange for a good relationship and favors in the future).
Actually, several distinctions. What do you mean 'our OWN governments'? This is a world where hostile foreign governments can wreak absolute havoc… including by popularizing arguments literally the same as the one you're making, for the purpose of undermining that government and fomenting revolution for their own selfish, imperialist purposes.
I can think of two great powers (okay, one formerly great) actively doing this within my lifetime, and the formerly great one was doing it as hard as it possibly could, within the last ten years, and is still doing it.
I don't trust your argument at all. You're leaving out significant things, conveniently.
Your government mass surveil's foreign citizens. But they can't mass surveil citizens legally.
This elicited a chuckle, though probably not for the reasons you intended.
Cooperate with domestic and remote governments, work with the deep state, influence elections and work with candidate teams, and so on. There are also companies with more reach and resources than entire countries.
Plus, corporations have been known to downright spy, threaten, beat up, and murder people when multi-billion interests are threatened (e.g. by local populations wanting clean water or better working conditions).
Corporations lobby governments to provide security, in part because some corporations want to sell security products and governments (at multiple different scales) are the biggest customers for that. Those who do not themselves sell security sometimes demand security not so much for the safety of customers and staff as for the customers that they would like to have. Security is big business. Before dismissing this as some marginal phenomenon, you might want to reflect on the proportion of the economy that revolves around security. Though a few years old now, this article raises a number of surprising questions that I've yet to see effectively answered: https://www.brown.edu/Departments/Economics/Faculty/Glenn_Lo...
Network effects cause society to coalesce around the same large corporations for social media, online shopping, payment processing, etc to the point that it can be hard to function in society without their services. Once their services are used by virtually everyone, their governance becomes governmental in its impact. On a weekly basis we see programs like the app stores, ad markets, search algorithms, and payment processors enforcing opaque policies that close businesses and end livelihoods, all based on an automated interpretation of the data we share with them.
Governments have grown to rely on corporations to spy on their own citizens, so being worried about corporate surveillance is being worried about government surveillance.
However, between the two (for the vast majority of people), corporations pose a more realistic threat than governments do.
As an aside, I think a lot of people want this gap to close, but for entirely unrelated reasons more related to political and economic goals, with the loss of privacy and individual autonomy being an unconsidered consequence of this.
I think a more rational alternative is to consider that everything except your unexpressed thoughts and emotions is already logged. At some point, this will become true (if it ain't already), so....then you at least will be ahead of that curve.
So if everything you do is monitored, how do you achieve privacy in such a world? That is the question, I think.
In fact, it's similar to how a corporation or nation needs to think about protecting their own secrets. They have to assume compromise (of people, systems, etc)...how do you confuse and compartmentalize what you want to protect?
Even at the hardware level we have real examples of exfiltration.
> Per our request, NitroKey has fixed one of the main issues in nitrokey.com/news/2023/smar…. XTRA downloads are done by xtra-daemon in the OS, not firmware. It also does use HTTPS by default, but the OS can override the default URLs via gps.conf and some OSes do override to HTTP URLs ... NitroKey is correct that xtra-daemon has support for sending information on the device including device model, serial number, etc. They're also correct that the user is never asked about it. It's less of an issue than SUPL which sends nearby cell towers, phone number and IMSI.
Not if we take the lore around mass survey into account (Snowden etc)
I suspect Snowden does them a service by making us all feel like we're under a big, scary, watchful eye.
In actuality, they probably do collect unholy amounts of data, perhaps even illegally... But they probably don't know how to process it effectively and if they do, they probably struggle to turn those insights into action.
It's easy for them to collect Facebook friends and Google searches, not Signal messages and DuckDuckGo queries made in an incognito window. It's easy because they can demand tech companies "hand it over" without actually hiring and assigning the skilled and creative people they'd need to figure out how to overcome the modest obstacles privacy-conscious people erect.
If you're a decision maker in one of these orgs, you'll be recognized and praised for cheaply trawling for privacy illiterate pedophiles and easy-to-identify, state-affiliated Twitter bots.
OTOH, you might not get promoted for spending hundreds of millions of dollars breaking into end-to-end encrypted convos only to find out that 99.95% of the data is benign and the .05% that's substantively suspicious requires a warrant and an FBI surveillance team to gather enough evidence to actually go to trial.
tl;dr: cheap measures to protect your privacy probably go much further than you'd think, because while they can be overcome individually, they're not worth overcoming at scale.
If privacy is important, assume compromise and work around it, sounds like the more secure strategy.
It's entirely unclear that it's difficult for them to collect duckduckgo searches (Why assume they wouldn't collect the info from duckduckgo?). Specific signal messages might be harder, but even signal collects and stores sensitive info (like a list of your contacts) forever in the cloud and in ways that could be easy for the government to get their hands on. Cell phones are basically designed to leak your info like a sieve and allow google/apple to do whatever they want (or are ordered to do) at any time without notice to users anyway, so anything done on them is probably capable of being observed and/or recorded.
You're right that most of the time it's probably not worth the effort to go after everyone for everything, but as long as they're collecting and keeping the data they can always decide to spend a little more effort if you become a problem for them.
I agree, people should take whatever steps you can to protect themselves whenever you can, since it can only help, but man, "Take care to never become inconvenient to those in power and hope they are incompetent when they finally come for you" is sure no comfort.
2. When you act as if you are being monitored and judged for your words/actions, you begin to self govern them to be more acceptable to the presumed omnipresent agent. Sometimes the fear of being surveilled is as powerful as actual surveillance.
Your computer is running several operating systems under ring 0 that Linux has no idea about, same goes with many components and peripherals. Those operating systems have direct memory access.
How would you hide in plain sight? That is the question.
Bruce Lee said: be water. But maybe you need to: Be Hamlet
No, I was thinking more, be a dissembler.
I might put a physical paper notebook in a reporters pocket then meet with them and buy them a coffee or tea. Or I might give them a USB drive with a self-decrypting file and instructions for how to use it securely.
Or if I am feeling silly I might borrow a few hundred digital billboards and just broadcast the data to everyone and let the public sort it out. FoghornBlowing?
In terms of dimensionality, I actually do not think it would physically be possible for the NSA to warehouse all the raw data they could Hoover (haha get it) up, so that might be a bit comforting. And certainly whatever data they do Hoover up will mostly never be directly seen by a human due to physical constraints on eyeball time available to spy vs produce content. That yields one answer to your question which is to just not attract enough attention they decide to turn on full logging and comb through your life
Proposals that suggests users get better at managing their own security are doomed. Most people don't understand the absolute insecurity of their door locks, let alone the state of their digital devices.
One possible answer is noise. There should be "digital noise generators" that create fake digital fingerprints for you everywhere. The goal isn't to make the landscape more pristine, it's to make it so "dirty" that it has no value to anyone anymore.
Even browsing the plain text Hacker News forum requires a web browser, so complex that only few companies in the world can produce it. And runs on super complex OS.
I wish we had something like "basic computing / commnication device" specification. Simple, limited and transparent, that everyone can produce. With small software, That would allow to exchange messages and browse information online. Not all data formats, but a limited set of formats, good enough for basic communications.
Better a frozen spec, not a moving target. (Or a very careful evolution, with very rare release of new versions)
Good publishers, web sites, etc, could test their systems against the "basic comp / comm device".
This not take anything out of your point, but HN can be browsed with simpler browsers like lynx, w3m, Ladybird or NetSurf, which are all written by a small set of people.
(they do rely on quite complex operating systems though)
If so, maybe it's better to think of two devices: trusted device, and fancy device.
The trusted device is a simple, low power and cheap device, maybe without even a camera. Just touchscreen, wi-fi and mobile internet. Fully open drivers, and hardware spec. Running bare bones Linux / Android, Firefox. Easy to root and reinstall the full software stack. There can be an open specification for at, as a "basic comp / comm device": 1 GB memory, CPU of certain performance, etc.
The fancy device is a cutting edge proprietary flagman device. Great power, but risk of tracking.
Every user can have both types of devices.
I assume you have to pierce some veil of reality, make a purchase, buy a ticket, etc. before it becomes a crime.
My point is if we can make surveillance costly by filling the airwaves with false positives that are just a group of bots plotting a terrorist act? I assume that is legal to do.
Edit - ok, so it definitely seems like this is not clever at all and almost certainly a crime. Don't do this!
https://leginfo.legislature.ca.gov/faces/codes_displaySectio...
So this means police informants in connection to the police are also committing a crime? Far too often people with recorded criminal activities are baited into getting another person caught for a more severe crime like terrorism, in exchange of being let go.
It says "falsely and maliciously".
So, if what say is true, it's not a crime.
If what they say is false but they believe it to be true, it's not done "maliciously", so it's not a crime.
If what they say is false and they know it, yeah, it is a crime.
But if the police and court believes them, or if it's the police itself that pressured them to point their fingers to some person they wanted to get, then it doesn't matter whether it's a crime or not, as it wont be prosecuted, and the police not only doesn't care, but explicitly wants the false testimony.
Not in most countries, no.
The problem with conspiratory talk is that while one person may fully not intend on action, it could inspire and/or manipulate others into committing acts. The blame is shared on all for conspiring and creating that environment where acts can emerge.
If they can get them, they will. The law is more of a technicallity for such cases.
So 80% of reddit and twitter is illegal conspiracy plotting/planning?
For example, if you and your friends agree to rob a bank and decide you'll need gloves, ski masks, and some kind of weapon, buying 6 pairs of rubber gloves at the store the next day would qualify as a material act. You don't need to acquire all the expected tools or go anywhere near the bank you discussed robbing.
So, no actual act is necessary.
That said, flooding the systems with false positives is definitely possible, but it would be used as a cover for actual terrorist attacks.
Well, that's true for any crime tho, so doesn't answer the parent's question.
> Canonical’s Ubuntu is not recommended by PRISM Break because it contains Amazon ads and data leaks by default
https://www.eff.org/deeplinks/2012/10/privacy-ubuntu-1210-am...
I clicked the link and it was from Ubuntu 12.04. This is something more than 10 years ago and has been unmaintained for years. It becomes hard to take this seriously when they make it seem like it is an ongoing issue (or do not link to a newer article if it is).
Authy was my escape from Google Auth.
I avoid Authy for a different reason: after upgrading phones, my backup password (which is 100% correct, trust me) is not unlocking my archive. I switched over to iCloud Keychain and will never look back.
I can't see the this making any kind of dent on the average person with these kinds of recommendations.
On https://prism-break.org/en/all/#email, they state "For more email providers, take a look at Privacy-Conscious Email Services. Please decide for yourself whether if you trust them with your data. For more discussion about safe email providers, please see issue #461.".
They even state that Thunderbird is a "Extensible, cross-platform email client.". The implied idea being to use Thunderbird to access a "Privacy-Conscious Email Service".
I use Gmail as an email client more than than I use it as an email provider because it has an External Accounts function. I apply Google's "App Script" system to my email to do things that you could do in Outlook's full-fat client or maybe in Thunderbird with some extensions.
This would go along with the rather crude emotional appeal.
That said, it hardly seems an efficient way to exploit people… though there are useful points. If you can get somebody credulous to use something that's compromised, and you're acting like a baleen whale and accumulating whole populations of credulous government-suspicious folks whom you've steered towards some mechanism where YOU can surveil them, that's got to have some usefulness.
People absolutely don't take into account the effectiveness of loosely manipulating entire populations in selective ways. You never need to select an individual and 'make' them take any action at all. You only have to cultivate the conditions for the outcome you want. Facebook might have discovered this first, but the idea sure caught on quick.
There doesn't appear to be any clear explanation or rationale. There is however the every unhelpful libertarian mantra "... do your own research ...". Whenever I hear those words uttered I immediate question the legitimacy of the source.
Hiding your research (or lack of) and telling people to do their own is a manipulation. It's telling people to either take you at your word or invest a lot of time and energy into research which might yield a similar conclusion.
Research is meaningless unless it's documented and shared so others can evaluate it.
Yep. And even worse, since those people are also telling you what conclusion they want you to reach, they're encouraging people to engage in the illusion of research (starting with a conclusion and looking for confirming data points) rather than real research.
Whilst the motivation of this project is commendable it's not going to reach the volume of folks needed to make a difference.
> If you use a custom domain...
I'd suggest trying to talk the average American into doing that. You'd have to be quite out of touch with everyday people to think this is a battle you can win.
Well, unfortunately, you can't encrypt your location and pretty much every mobile phone is sending detailed GPS, accelerometer, barometer, WiFi, and other sensor data back to the mothership multiple times an hour.
[1] The technical details of how this data are anonymized, nor how it is analyzed and used to "improve products" are not public.
[2] The implications of each click-through agreement are, as usual, non-obvious.
[3] The name of this mechanism keeps changing and it is harder and harder to find and disable.
They also still link to https://prxbx.com/email/ from https://prism-break.org/en/all/#email, which doesn't consider https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
How many Signal users are there, and why aren't there enough of us to drive the political agenda? One big problem with most privacy tools is they don't name their threat actor (it's your own governments), and using the tools doesn't translate to a vote for anyone who will do something about the problem. On top of it all, installing these tools acts as a reliable political metric for popular intelligence community approval.
I don't have many RSS sources (11) and some have news just every other month. That way I don't have to open a separate program and when something comes up, I see it right when I read my emails.
Did you know that you can use RSS to get notified when someone writes a reply to your HN comment? I love it: https://hnrss.github.io/#reply-feeds
https://en.m.wikipedia.org/wiki/PRISM
If a company stores data about you, it is possible it could be subject to a FISA request. Data which is end-to-end encrypted would still be provided if it satisfies the criteria in the FISA court order. But it would be up to the NSA to try to break the encryption. Metadata might or might not be encrypted.
Essentially it's to give an intolerable SNR to this scraping where they have to discard their metrics as useless
We should be aiming for a solution that is private while also convenient as the centralized ones. Otherwise even if we (HN audience) switch, many others won't and only a niche set of users will be using the private technologies and services.
This is a problem. Even the HN audience seems to struggle greatly in choosing non-proprietary and privacy friendly solutions. While the amount of privacy advocates are certainly greater here than in many other places, the general sentiment I get from reading a lot of these threads is that "If you have nothing to fear, you have nothing to hide".
Why do you think that is? Certainly a community like this shouldn't be bothered by the slight obstacles you would be challenged with.
> Why do you think that is?
I think it's because a lot of people think that there's nothing that can be done to change the situation, and so they adopt that mental stance in order to be OK with it. Whether or not that stance is correct isn't important. It's an emotional "safe space".
I get it, but not very helpful. The premise of making it "uneconomical" for a nation-state to perform mass surveillance is a bit naive; at best we can make it more expensive for our own governments to perform, which is backwards in IMO. We should make it cheap, efficient and easy to get too much garbage data.
Can you please explain how you have organized your current setup?
So instead of the government being able to spy on you, you want the government and anyone else capable of monitoring the blockchain to spy on you? That seems worse on all fronts.
Then when you send a message it can be hidden. And it becomes too expensive to review.
It certainly a choice an individual can make. But it will have about as much societal impact as domestic recycling has on global warming. Especially since we're talking about internet communications technologies here... The alternative to using Discord for most people these days is not corresponding with the people they need to correspond with.
Also btw we should put 2021 in the title because it hasnt been updated since.
It does mention Syncthing.
From the site:
> File Storage & Sync
> Prefer
> EteSync
> Encrypted calendar, contacts and tasks sync.
> Syncthing
> Direct file sync between devices.
A more modern alternative is https://www.privacytools.io/ but I haven't checked it in a while and can't vouch for the current contents.
The previous maintainers created and moved to: https://www.privacyguides.org/en/
read.fahads.net
Feel free to register. Though you won't get an activation mail, I would be happy to activate your accounts manually. Though you shouldn't probably use it for anything too serious, since I'm not an expert sysadmin.
I've thought about doing this to have a pen name with a pseudo anonymous identity but I also have burner emails to avoid spam.
I'm sure naming is related and glad to see the initiative.
"It is impossible to download and examine iOS's source code, which means that it is impossible to prove that iOS is not spyware. Any program which does not make its source code available is potential spyware."
Which I agree with. I'm not going to trust and put as much personal data as a smartphone usually contains into a proprietary black box.
> "Apple iOS devices are affected by PRISM. Even using the software tools we recommend here, your privacy may be compromised by iOS itself. The operating system of any device can unfortunately lever out any privacy protection that a program tries to offer you."
...made me conclude that these people are idiots. You don't need to activate iCloud on an iPhone and you can use standard stuff like IMAP and WebDAV to sync contacts and calendars etc. There's also a huge list of telemetry controls you can shut off in the OS.
Not to mention they have the best physical and OS security of any mobile device.
Suggesting that a small homebrew Android ROM, maintained by anonymous individuals, which hasn't seen any security updates in almost a year, is comparable in terms of end-user privacy is ludicrous.
Some of the recommendations are pretty suspect, too: how is using Thunderbird for email supposed to "opt you out of PRISM and XKeyscore"?
If the reference is keeping all your messages, and potentially your PGP keys, in "cloud" storage at a PRISM provider it's not particularly hard to understand some ways in which using Thunderbird instead is supposed to help. It's a fair point it's not a particularly satisfying mitigation though.
No, but that makes sense. The framing would have been much more apt back then than it is now, with the Snowden stuff being fresh.
> If the reference is keeping all your messages, and potentially your PGP keys, in "cloud" storage at a PRISM provider it's not particularly hard to understand some ways in which using Thunderbird instead is supposed to help. It's a fair point it's not a particularly satisfying mitigation though.
The reference is just "instead of Gmail, use Thunderbird" (e.g. https://prism-break.org/en/subcategories/macos-email/). They don't mention PGP in that section at all, though there's a later one about "Email Addons, which does, which is easy to miss (e.g. skipping b/c you don't already use addons).
Their (broken HTML) recommendation to run your own email email server is also suspect, because it's a bad tradeoff. Unless you want a second, unpaid job as email server administrator (with a pager!), you're "protecting" yourself against a rare hypothetical threat (government surveillance) by making yourself vulnerable to a much more common one (run of the mill hackers).
Realistically, they probably should have just said something along the lines of "email surveillance is practically unavoidable," so don't use it for anything you don't want monitored. PGP failed because it's too hard to use, so no one uses it, and any reasonable use of email will mainly involve exchanging messages with some "monitored provider's" servers.
The mail client may help improve privacy if you configure it to erase data in the server as it is downloaded to the client (POP), instead of letting it stay in the server for a indefinite amount of time (IMAP). If people are going to break into your provider, a empty mailbox would limit compromise.
Just do not provide clean data. Search for random shit occassionally so that the entire profiling gets poisoned with fake data points.
Oppressors will still buy or make software for those purposes, but we don't have to hand them the tools they use to oppress us.
The purpose of an ethical source license is not to be a fool-proof fix for all unethical behavior. The purpose is to send a message that human rights violations are not okay, and to make it harder for unethical corporations/users to defend their actions.
If the reason someone doesn't want to use ethical software is "someone might find my actions unethical", either they're morons or they're unethical. Ethics aren't t-shirt slogans. Human rights don't constantly change with the wind. Either you are abusing people or you aren't. If you are abusing people, then you can, you know, stop doing that. Or go find different software.
Finally, licenses are contracts which are legally enforceable. If someone breaks the license, that carries the force of law. You can absolutely stop someone from using the software if they break its terms, even internationally.
The cost has almost always been ~0 for gov officials performing unnecessary surveillance.
I trace this low cost back to news orgs. Most editors & journalists opt out of honoring their extra constitutional protections because they don't serve as an adversary to the powerful. Instead they favor publishing sportsball or celebs or parroting gov/corp/leo pr without any analysis, etc.
We don't know how officials will behave if they have to pay a persistent, meaningful cost for surveilling us. We've never tried it.
To try that, step one would be making people aware of what's even happening. As you say, news orgs are failing us all.
Assange and Snowden took Step One toward that end... And were made an international example of. The institutions and news orgs who ought to have been their main support failed, and even turned on them in most cases.
https://www.nitrokey.com/news/2023/smartphones-popular-qualc...
https://freebeacon.com/latest-news/google-gave-fbi-location-...
Granted, the website is dedicated to mass surveillance in the IT. But then think, generally speaking, is the mass surveillance on some reasonable level really so bad? It's helping identifying Russian soldiers who are committing war crimes and atrocities in Ukraine. It helps preserve the free and democratic society rather than creates a road to dystopia. Of course, I'm speaking of some reasonable levels, not of something like real-time client device scanning. It doesn't make any sense and it would simply not work.
In a world where individuals or very small groups of people are increasingly gaining the power to do potentially catastrophic damage using increasingly powerful technology, what are the actual alternatives? Trust?
How can society functionin going forwards without at least some oversight ?
Don't get me wrong, I don't want society to go this way, but I'm starting to see fewer and fewer options presented to Governments. I can see both sides of the story.
I wouldn't pretend I know the right answer, but I think we have to admit the world has changed quite a bit recently.
What happens when the state intelligence apparatus has the ability to perfectly surveil the population? Look no further than what the Stasi accomplished - it becomes trivially easy to discredit political opposition, journalists, business leaders, or any other person or group standing in the way of the powerful.
People split hairs about this kind of oversight, or that kind of oversight, but when the powerful are overseeing their own surveillance apparatus - using secret courts, secret warrants, and all manner of other methods for hiding the true scope of the surveillance - I do not believe it can be contained.
It is basically only ok if you can guarantee it’s users always use it in good faith which is virtually impossible.
“It is better, so the Fourth Amendment teaches, that the guilty sometimes go free than the citizens be subject to easy arrest.” William Douglas, Associate Justice of the Supreme Court. The argument to give up your rights is always initially used to target the worst of the worst. Its always terrorists, spies, child murderers, etc. Of course we shouldn't be slowed down by due process when it is for this child murderer. Yet it is then used against those least likely to be able to defend themselves for easy wins. Russian spies first, then its minor crimes committed by immigrants.
So, for the first five minutes.