From encryption to darknets: As governments snoop, activists fight back
arstechnica.com
arstechnica.com
Ahem... their airwaves and networks? Perhaps part of the problem here is that the governments believe that they own these communications channels. But the airwaves and networks are like the seas and the atmosphere: some of it happens to fall within a government's borders, but it's impossible to "own" them.
This is the reason it infuriates me when telecoms start talking about the "free market". There's nothing free about it, they are using public thoroughfare and public airwaves to make money, essentially a state sponsored monopoly. Their job is to operate in the public's interest.
Our current conception of property rights does not recognize any ownership of these resources. This is very similar to resources such as the atmosphere; and rivers, lakes, and oceans. All these things are subject to "tragedy of the commons" issues, as well as market failures due to externalized costs.
You're right that there's nothing free about the market in communications spectrum. Because there is no recognized ownership, we must rely, as you note, on the stewardship by our governmental agencies.
The problem with this, of course, is the inherent inefficiencies of centralized control, as well as the errors created as a result of public choice economics.
The Coase Theorem [1] demonstrates that if we were to recognize an ownership interest in these resources, then we could expect that those problems could be worked out by an actual market, where today there is none in operation.
I've also never accepted the Coase Theorem because it too ignored the practical problem of "whomever builds the tallest tower wins". You simply can't build wireless network (or wired that have any practical use) without government control. Or, if you do, the market will work out a natural monopoly over time because of the need for standardization. It's the same reason it's so hard to break into the social network market, one platform is better and the larger it is, the better it gets. Imagine that extrapolated to something as economically essential as the telecomm system. We enable free markets by providing basic infrastructure (roads, telecom, etc.).
But that's getting off the topic of the discussion. The spectrum, in practice, is the property of the government and, by extension, the people. Wired networks are more complicated, but shared ownership is implied by right-of-way agreements, or at least the obligation to operate them in the public interest is implied. As long as that's true, governments are obligated to protect the public's interest in a free and open form of communication over those networks.
Does that mean it's certain that an actual market will sort things out, or simply that in one specific model (which is a gross simplification of how the real world works), it's theoretically possible that these problems will be solved?
http://news.ycombinator.com/item?id=1690871
The article touches on this towards the end.
Those of us behind the "relative safety of a western computer keyboard" may have more of an obligation to act than those under more strenuous restrictions. At least in our case we likely won't be hanged from a crane, as you say. Or at least our governments will have the good courtesy to have us shipped off to a friendly tinpot dictatorship first so we can be spared the humiliation of having such a thing done at home.
I don't think marketing really comes into it, all the circumvention tool vendors are quite direct and honest with the current state of their efforts and the extent upon which they can be relied. Also, they're not commercial efforts, and the creators stand to make no real direct economic gains from their adoption.
I wouldn't criticize someone using circumvention tools in Iran. I might criticize an American who tried to make a name for themselves by building half-assed tools for Iranian dissidents. That was my point.
I think the chances such a theoretical user who will engage in subversion at any rate no matter the risk level is much more likely to be less capable of creating a circumvention tool than say the tor team.
While he certainly has a point that badly done circumvention tools give a false feeling of safety, I don't think completely giving up is a solution either.
No matter what, activists in such countries are already daring their lives (through off-line activities). It is important to get some information out there, through regimes' firewalls, and the only way might be through such tools.
And only circumvention tools (such as TOR) that are public, open source, and actively being used can be subject to scrutiny (otherwise it'd be a completely academic exercise), which improves the security of the tools over the long run.
Edit: Also, with the recent push for internet censorship even in western countries it's starting to be pretty clear we need the tools here too.
That's fallacious because our need for circumvention tools is irrelevant. You are talking about moral imperatives and I'm talking about engineering.
The fact of the matter is, there is no way to build an assuredly secure messaging system; every attempt to build cryptographically secured messaging has failed, often multiple times. It isn't unlikely that every fielded cryptographic system is broken right now, and we're just waiting to find out how.
In the real world, resources matter. Nothing is perfect, so really we're talking about a contest between two parties. Will the circumvention tool authors figure out the flaws (that expose their messages, that allow attackers to use technical flaws in their tools to mislead users into compromising themselves, that allow attackers to easily pinpoint circumventing traffic, &c), or inadvertently fix them by laying more countermeasures into their code? Or will governments find those flaws first, and use them to turn the tools against their users.
The governments we're talking --- Iran, Syria, China --- have zero scruples, unlimited funds, and (if you're under the delusion that dictatorships have a hard time finding technical talent or that money doesn't simply buy it like anything else) demonstrated access to research and development skill in this specific area.
It doesn't matter that we need these tools. I'm betting on the hostile governments. If you think the dictatorships will win, you need to keep in mind that the worst case isn't "false sense of security". The worst case is, "run this tool and a government computer somewhere silently puts your name on a list".
Yes, that was very clear. I wish I could be amoral like you.
The worst case is, "run this tool and a government computer somewhere silently puts your name on a list"
Not always a problem. If enough people use the tool (which will be automatically the case as more ends up in the firewall), it's impossible to distinguish the people that use it for serious purposes (like anti-govt activism) or less serious purposes (like trolling anonymously or watching porn...).
Even circumvention tool authors --- I'm guessing I know more of them than you? --- will tell you that's not an uncommon pathology.
And I don't have any illusion that just geeks can "save the world", but they can at least provide support in some areas, such as allowing journalists to communicate with activists.
So you think the world would be a better place without any circumvention tools?
Well they'd say that wouldn't they. Old school tradecraft: Using an 'output-feedback mode stream cipher' (Pontifex) and a cheap phone gives you a secure and anonymous, 1 to many messaging system. It was designed specifically for covert 'dead-drops' communication. There are a few caveats, but it's lo-tech & bruce reckons it works ~ http://www.schneier.com/solitaire.html
I could see using Pontifex to encrypt text messages, but how do dead-drops fit into this? Communicating the location of the drops? Dead-dropping the phone with encrypted messages on it?
If you don't want anyone to know you are sending a message to another person you encrypt a message & leave it at a specific place with a marker. I assume you get this. But if you give a call with an an encrypted message on any phone you potentially give the game away. With a cheap $20 phone used minimally or once, sending a hand encrypted message using Solitaire you get anonymity and security.
1. Where does the one-to-many part come in?
2. Is there any reason other than plausible deniability to use a cheap cellphone vs. anything else (piece of paper, memory card, etc)?
AFAIK full-disk encryption offers the best protection against offline attacks. How much good would it do in a mobile phone that is almost always turned on?
But it also makes a data wipe easier to do securely, and gives you an additional last minute option when you see trouble coming (just turn your phone off).