Julian Assange: Cryptographic Call to Arms
cryptome.org
cryptome.org
http://www.youtube.com/watch?v=TuET0kpHoyM
No wonder NSA and FBI want warrantless access to private companies by lobbying for new laws like CISPA, and trying to build backdoors in services like Facebook, Skype, Twitter etc. They want to know absolutely everything you do online, besides your public posts:
http://www.wired.com/threatlevel/2012/05/fbi-seeks-internet-...
I don't know if they are doing it out of malice/power grabbing/control, or purely as a way to make their jobs more "efficient". But their #1 priority should always, always, be respecting the Constitution, and not trying to skirt around it. And I think they've forgotten all about that long ago.
They don't even have any historical roots in western political systems. The country with the claim to that is Russia (http://en.wikipedia.org/wiki/Okhrana), where they were commonly used to quell internal unrest and combat opposition.
[0] http://en.wikipedia.org/wiki/Frumentarii [1] http://en.wikipedia.org/wiki/Francis_Walsingham#Entrapment_o...
Yes, I was surprised by his responses, I thought his initial remark was great, but people mean quite different things by those lofty abstractions.
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness.—That to secure these rights, Governments are instituted among Men, deriving their just powers from the consent of the governed, —That whenever any Form of Government becomes destructive of these ends, it is the Right of the People to alter or to abolish it, and to institute new Government, laying its foundation on such principles and organizing its powers in such form, as to them shall seem most likely to effect their Safety and Happiness."
I recommend reading the whole thing if you have five minutes. It's a very fine piece of writing, and there are a lot of interesting details that most Americans either willfully ignore or fail to notice:
- Safety is mentioned in the first paragraph as a reason for government to exist.
- Many of King George's offenses will sound very familiar to us as things our government does today: maintaining standing armies, levying taxes, etc.
- Many of those offenses also have the phrase "without our consent" in them, which tends to be missed by people who bring up that second point.
- One of the offenses listed is limiting immigration. Whoa buddy!
The ending is a quite powerful summary of the rights of the state and probably about a thousandth as well known:
"We… solemnly publish and declare, That these United Colonies are, and of Right ought to be Free and Independent States… and that as Free and Independent States, they have full Power to levy War, conclude Peace, contract Alliances, establish Commerce, and to do all other Acts and Things which Independent States may of right do."
It's worth noting that interventionism doesn't seem to be on that list, even though we wouldn't even make it 40 years into countryhood before that changed.
…
So I think the OP and Chris are both right. The court cannot be expected to "defend liberty" outside the legal framework; they're beholden to the Constitution and the rest of the law. There is the "black ice" problem of case law, and the citizenry are going to have a very poor command of that, and that's just a fact. But the OP is right that it is the citizen's job to defend their own liberty as best as possible. The problem with that perspective is that resisting the government carries a price and most government infractions are not significant enough to pay that price. If you take that philosophy to the extreme you wind up with a Ruby Ridge scenario where a lot of people die because they misunderstand the founding fathers' opinions of taxation.
I also think we should have some awareness of the level of crap King George visited on the colonies as described in the Declaration. He wasn't merely taxing them, he was essentially waging war on them from within and without. Even with all that there were still significant numbers of loyalists in the colonies. We like to imagine that Britain raised taxes and we joined together as one to secede the next day. The way it played out on the ground was much messier.
* Democracy. That one's obvious. Universal adult sufferage regardless of sex, race, creed, property ownership. We all know about "women getting the vote", but men without property used to not have the vote, catholics/prodestants/muslims/jews (delete as appropriate) used to not have the vote. Race based voting restrictions are similarly common. Some countries allow restricting voting based on criminal record (USA) other's done (most of europe), some countries prevent current criminals being elected (UK did this after some IRA terrorists were getting elected).
* Inherent rights. Who gives you your human rights? The Crown/State? So can they take them away? Does everyone have rights? Or just people/men of the right colour/creed/aristocracy? Does everyone have the same rights? No. We view that everyone has rights all the time that cannot be taken away.
* Rule of law. You/anyone should be able to know what the law is. The crown/state cannot just make up a vague law that only they can interpret. Laws cannot apply retroactively. The law should apply to everyone. It should be wrong if a certain law doesn't apply to the local lord, but it does apply to you.
* Fair trials. It's wrong that the crown/state alone gets to decide guilt/innocence, there should be an independent trial. You are allowed to argue your case. You are allowed appeal. The jury cannot be punished for how they decide your trial. You should be presumed innocent. You cannot be locked up unless you have been tried.
* Constitutionalism. There should be a document that overrides the crown/state and defined how the state works. It should list what powers the state/crown has. The King/state is not allowed to just do whatever it feels like. (Fun fact: Nazi Germany, the USSR and the USA have/had constitutions. The UK doesn't really. :P )
It's quite easy for a Supreme Court to rationalize the disposal of civil liberties. Look at air travel. The argument is that people are consenting to the invasive searches because they are choosing to fly; never mind that flying is basically the only reasonable way of getting across this giant country. They can say the same thing about the internet. "You are consenting to use the option of internet based communication. If you want privacy, speak in person."
The US consitution & bill of rights were fine with the slavery, racial segration, denying women the vote, denying men without property the right to vote, legal sexism, etc.
You're right that it's all about how it was interpreted.
It's part of the American mythos/story/narrative, that the USA constitution/bill of rights/founding fathers were some sort of genius people who were the first to come up with this brilliant and perfect text.
Presumably their #1 priority can be specified in a more rational way without random worshipping of some old document? Other countries, not blessed with the Constitution of the USA, also have intelligence and law enforcement agencies.
Other governments' law enforcement agencies follow the laws of their own countries (or don't). Are you saying they shouldn't do that?
Weird that nobody realizes that the constitution does say that the government not only has the right to violate any (other) law to violate the constitution, but actually has the duty to do so.
To protect the constitution (and it's application within it's jurisdiction), the president (ie. the government) has the right AND the duty to violate ANY American law except clause 1 and 2 of the constitution. To put it plainly : the ONLY thing the president cannot do to defend the constitution is to mess with elections. That's it. It also states that the president is the person making the assessment if an action is necessary (and thus, not the courts, though of course, the president can be removed from office for making a decision that either congress or the courts think was not reasonable. That does not change the fact that the president cannot be punished for implementing that action. The maximum penalty for any crime for the president is impeachment, unless this is specifically extended by congress).
This is because article 2 of the constitution overrides every other law in the US, except article 1, including all following articles and amendments.
If you think this sequence is by accident, you should talk to a lawyer about things like this. Sequence in laws, and the principle that earlier rules override later ones is extremely well established technique of law.
What everybody seems to think these laws state, that you have extensive rights without any qualifications whatsoever, is just plainly not true. If you are a danger to the application of the US constitution within US borders, the president is not bound to any standard, nor does he have to respect any form of human rights in his attempts to stop you from doing so.
If you think it is better in European states, think again. Specifically, read what the Dutch monarch is allowed to do (e.g. she can have someone killed - both her and the actual murderer go free, she can confiscate any amount of property - with no legal recourse for anyone, etc.). Similar things are true for other Euro countries.
Weird that nobody realizes that the constitution does say that the government not only has the right to violate any (other) law to violate the constitution, but actually has the duty to do so. To protect the constitution (and it's application within it's jurisdiction), the president (ie. the government) has the right AND the duty to violate ANY American law except clause 1 and 2 of the constitution. To put it plainly : the ONLY thing the president cannot do to defend the constitution is to mess with elections. That's it. It also states that the president is the person making the assessment if an action is necessary (and thus, not the courts, though of course, the president can be removed from office for making a decision that either congress or the courts think was not reasonable. That does not change the fact that the president cannot be punished for implementing that action. The maximum penalty for any crime for the president is impeachment, unless this is specifically extended by congress). This is because article 2 of the constitution overrides every other law in the US, except article 1, including all following articles and amendments. If you think this sequence is by accident, you should talk to a lawyer about things like this. Sequence in laws, and the principle that earlier rules override later ones is extremely well established technique of law. What everybody seems to think these laws state, that you have extensive rights without any qualifications whatsoever, is just plainly not true. If you are a danger to the application of the US constitution within US borders, the president is not bound to any standard, nor does he have to respect any form of human rights in his attempts to stop you from doing so. If you think it is better in European states, think again. Specifically, read what the Dutch monarch is allowed to do (e.g. she can have someone killed - both her and the actual murderer go free, she can confiscate any amount of property - with no legal recourse for anyone, etc.). Similar things are true for other Euro countries.
That's the irony of the whole American security apparatus. They are in place, nominally, in order to protect American citizens rights to live with the freedoms inherently granted to them by the Constitution.
The Constitution does not grant freedoms to citizens. Instead, it delegates specific powers from the citizens to the federal government.
If your email, or SMS, or voice call, or fax, or IM, or whatever else they care about and know how to parse, ever goes through any of their boxes, it's stored and associated with your entity forever, and may be used to glean unknown levels of insight about you, or used against you in criminal cases.
While Google will use that data to show you harmless text advertisement, the FBI might use it to backup a phony case against you, that can ultimately put an end to your freedom.
I'd say that's an incredible difference. Wouldn't you too?
I'd stay both sides are bad. We may see them as completely different things, but you have to agree, in both sides, what we see is just the tip of the iceberg.
But only one of these can lock you up in jail for whatever reason they want whether or not you're guilty. Besides, if you want to avoid having your data collected and possibly sold without you conscent just stop googleling your thoughts.
Now, the real question. How to avoid governments taking over our rights?
My guess is that it's nowhere near possible given the amount of network traffic coming into/out of the US and current hard drive storage technology. IMHO the extreme amount of volume and limitations of storage space should create a necessity to be at least somewhat targeted in scope.
Not sure why people don't use common sense a bit more often...
Speak for yourself then. I've already got 10TB of storage at home in a case the size of a shoebox. It's got my entire life in it (at least every file I've created since university), but most of it is storing my movie and music collection. So, realistically your entire life can fit in a 1TB drive once you exclude videos and transcode audio. 2-4TB if you're a person of interest.
Do know that 1 Backblaze 4U-server holds 135TB. They are building a datacenter in Utah with 100,000sqft[1] of rackspace. 20,000 racks per floor (I don't know if there are multiple stories) gives you 29.7 petabytes if they used a Backblaze solution.
So yes, if the US govt wanted to record everything you did everyday they are more than capable of doing it, now.
[1]http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/
Think of Google. The have downloaded and stored lots of the internet. How else can they search it?
So if we know at some level that it's possible, could the NSA do it?`
As if we lived in a halcyon utopia prior to that. I can't buy into Assange's Manichean view of government, given the pre-governmental state of society as war of all against all, qua Hobbes: "In such condition there is no place for industry, because the fruit thereof is uncertain, and consequently, not culture of the earth, no navigation, nor the use of commodities that may be imported by sea, no commodious building, no instruments of moving and removing such things as require much force, no knowledge of the face of the earth, no account of time, no arts, no letters, no society, and which is worst of all, continual fear and danger of violent death, and the life of man, solitary, poor, nasty, brutish, and short."
Back when Wikileaks first came to prominence, it exposed malfeasance by private actors as often as states, notwithstanding the desire of those private actors to keep their doings private or even encrypted; Trafigure being a prime example (http://en.wikipedia.org/wiki/Trafigura).
States can certainly be destructive of liberty, but the absence of a state (either literally or by legal limitation ) does not necessarily yield liberty; often it results in mere libertinism.
You attack a perspective, quoting on a tangent, without contributing anything meaningful except the notion that government can have value: but of course! Nobody denies this.
Assange and other politically engaged hackers like him seek improved systems of governance: greater protection of fundamental freedoms, greater availability of additional freedoms, greater truth and transparency.
Relax, nobody wants to topple your car and burn your house down.
edit: To say something is truth if it's true is too circular - as a definition it doesn't have matters that can be confirmed by others so isn't so helpful to convince them.
I already disagreed with the grandparent comment, but I need to criticize this too: those metrics are terrible, and we shouldn't be looking to the past for the good old days.
Free time: only if you don't consider all the free time lost by all the people who died as children (extremely high premodern child mortality).
Material and economic equality: being equally poor is not really a solution anyone would like.
History informs the present and future. My point in bringing up anthropology was that the OP's implicit suggestion that there is no alternative is demonstrably invalid.
> being equally poor
I would also heartily recommend the same book to you. It's quite an eye opener.
That's only relevant if all those children died due to some specific form of government being in effect.
No I didn't. How can you expect me to engage with the rest of your comment in any serious fashion when you just make up claims like this?
If you want to argue that states are necessary, fine. But call a spade a spade. Can you imagine a state that doesn't wield violence? That's what a state is.
The lack of clarity on this issue leads to a lot of bad conclusions. When we argue that the state should solve any particular problem, we are explicitly saying the problem needs to be solved by coercive force. Maybe that's necessary. But let's not have any illusions about how states work and how laws are enforced.
That's part of what a state is, but it's more than that. A state is a violent organization that has managed to convince the vast majority of society that its violent actions are acceptable. In any conceivable society (state or no state), you will have violence. The difference between "criminals" (druglords, thieves, rapists, etc.) and "government" is that the vast majority of society condemns the violence of the former but accepts (and often even praises) the violence by the latter.
Got that a bit backwards there. A state is a violent organization formed by society meant to enforce the rules of said society. We prefer the state to criminals generally because we have some say in how the state works or find its rules preferrable to the criminals.
You have zero say about anything criminals do.
There is a vast difference.
Again, proportions simply do not matter to the victim of violence. Like I said, if DEA agent busts down my door and shoots me, it is absolutely no consolation or justification that >50% of voters approve of drug prohibition. If you propose the question "is it okay for a robber to take 30% of my paycheck as long as 51% of my community is okay with it?" most people will say "of course not!," but if you propose the exact same question, but with "a robber" to "the government," most people will say "yes of course that's okay."
I'm not talking about a crime; I'm talking about government rule vs warlord rule. And the issue is which most people prefer, not which allows you a better chance to disobey.
> Again, proportions simply do not matter to the victim of violence. Like I said, if DEA agent busts down my door and shoots me, it is absolutely no consolation or justification that >50% of voters approve of drug prohibition.
It absolutely is consolation and justification for the majority of people who support that policy. You might not like it; but individual liberty is not unlimited and the will of society, right or wrong, beats the pants off any other form of government we've found.
> If you propose the question "is it okay for a robber to take 30% of my paycheck as long as 51% of my community is okay with it?" most people will say "of course not!," but if you propose the exact same question, but with "a robber" to "the government," most people will say "yes of course that's okay."
The robber is taking something without giving something back; the government is taking their share of your wages for services rendered to you as a citizen. Completely different situations.
Yes, but not for the victim of the policy. Slavery used to be approved by the vast majority of society.
> You might not like it; but individual liberty is not unlimited and the will of society, right or wrong, beats the pants off any other form of government we've found.
I don't like it, and I don't want to replace it with another form of government. My whole point in this thread has been that government actions are indistinguishable from actions which are widely accepted to be crimes, except that government has convinced society that its actions are acceptable.
> The robber is taking something without giving something back; the government is taking their share of your wages for services rendered to you as a citizen. Completely different situations.
Fine then, change my analogy to a robber that takes 30% of your paycheck, uses part of it to blow up some people in other countries, part of it to feed the poor, part of it to pay prison companies to contain nonviolent criminals, and part of it to build some roads.
Government is society, we are our government, it is not some entity that has tricked everyone. It does what it does because open your eyes and look around, people want it doing those things.
I did not say that at all. I am OK with states being systems through which coercive force flows, because I think channeling and supervising said force usually results of less of it flowing than otherwise would.
Can you imagine a state that doesn't wield violence? That's what a state is.
It's hardly the only distinguishing feature. States also build infrastructure, promulgate laws, provide forums for resolution of disputes and so forth. Your argument as made here is both narrow and immature.
The most commonly used definition is Max Weber's,[6][7][8][9][10] which describes the state as a compulsory political organization with a centralized government that maintains a monopoly of the legitimate use of force within a certain territory.
This feature is so critical to how the modern system treats territorial integrity that we sometimes refer to states which can't control violent groups within their own borders as "failed states."
See, the reason why the war in Afghanistan is controversial is precisely because it is not clear that a country has a casus belli against another country if there is a (remote) connection of offenders to that country. In fact, the pilots lived and planned most of the plot in Germany.
A better example of a failed state would be the results of the war on drugs in Mexico.
In short, the authority of these private organizations are opt-out, while the authority of the state is not.
It's circular logic to say that a state has a monopoly on only legitimate violence since it's the same state which defines which violence is legitimate and which is not. Can you think of any organizations that successfully exercise a monopoly on illegitimate violence? Successful states do not allow such activities to continue for long.
A state is, as others have already said, simply a political institution which exercises a monopoly on violence and determines how to apply it within its political domain.
Without property there is not commerce, there is not agriculture, no civil growth and development to speak of.
http://dbzer0.com/blog/private-property-vs-possession
It would be nice if a society could exist that wasn't reliant on violence and also not suck, but I'm not sure if it's really possible.
Oh and "this is mine" has meaning in the context of a relationship where one party will simply be upset if the object is taken and the other party cares enough about them not to take it for that reason, even though there is no threat of violence if they do. This is how many couples and families work.
There has been much thought on this line of philosophy, it's called the non-aggression principle (https://en.wikipedia.org/wiki/Non-aggression_principle)
This can be a useful perspective, but it's rarely actually used to any intellectual benefit: people generally bring it up only as an excuse to dismiss the concept of statehood as worth exploration, because we've internalized the notion of violence as bad. It's just libertarian fear-mongering, and it drives away discussion of real issues of violence from the public arena into the private backrooms of government where we don't have a say because we act like a lynch mob when it comes up.
For me, the way to refute Assange's point that states depend on violence and are therefore bad is not to say no they don't, or that that's not a useful perspective, but rather, "Look at the wondrous things we can build using our ability to marshal force effectively."
When I first heard about this violence-based perspective, it threw into question the notions of society and in particular human rights that I had from my high school education, because as you say, we have this internalized notion that violence is bad.
But now that I understand that rights really are just agreements between people that are brought into existence by violence, it actually makes me glad to have this violence around, and I don't see it as a universally bad thing. Nevertheless, I would prefer a society in which there is as little violence as possible, but I'm not by any means convinced that the answer there is "less state".
The vast majority of people in most democratic societies do not require the threat of arrest and imprisonment to follow the majority of laws. Assuredly there are minor disagreements about which the validity of certain laws, and many people cheat a little here and there. But when the majority of citizens believe that the majority of the law, and the state which imposes it, is unjust, you have an authoritarian government, and a revolution is inevitable.
It might also be worth noting that even if, based on budgetary spending, the US government is primarily an institution of the force and its display, most of that is happening outside of US soil. Most of it, in fact, is deployed in protecting sea lanes for the benefit of shipping and the people who rely on it: namely, everyone on Earth. I'm not American, and I don't like everything about America, but I'm damn grateful for the fact that the American government is funding the security of the machinery which keeps food and goods flowing around the world, since a lot of people where I live (Canada) would have difficulty surviving the Winter (and maybe even in Summer) without it.
To what extent global commerce and trade are just or unjust is another question, but I suggest it can be addressed on a case-by-case basis, and that the vast majority is far more beneficial than detrimental to everyone involved.
It is the definition of a state as started by Max Weber and sociologists in the tradition of political realism:
http://en.wikipedia.org/wiki/Monopoly_on_violence
Max Weber's definition is used by wide variety of political factions, and is not a construct of anarchists\libertarians. During the Iraq War when discussing the use of mercenaries, the current President Barack Obama was quoted as stating:
"the core of our military relations to our nation, and how accountability is structured, you are privatizing something which sets a nation state apart, which is a monopoly on violence." [1]
Any action that is legitimate for the state institution to enforce, but would not be legitimate or legal for a non-state institution to enforce, derives its legitimacy from this monopoly on violence. This definition is simply stating that unlike other social insitutions, the state is the only institution which has the power to commit legal incarceration, execution, and confiscation.
The fact that non-state organization cannot impose taxes upon individuals and threaten fines and incarceration for non-payment indicates that taxation is a forcible (violent) means of appropriating revenue. If it were not, the revenue would be referred to as a donation, purchase, charity, or trade.
The definition of a state as an institution which wields a geographic monopoly on violence is agnostic towards the "purpose" of the state. The definition concerns the means not the ends of the state. The goals of states are diverse and change over time, but their fundamental principles of operation do not.
"The vast majority of people in most democratic societies do not require the threat of arrest and imprisonment to follow the majority of laws."
Consider if this statement would remain true (and if so, for how long) if the threat of state violence were not present.
Further, Hobbes' state of nature has zero grounding in empirical fact. Which historical state of nature does it refer to?
Hobbes' state of nature is probably an ahistorical argument. That all men used to live under a state of nature is not necessary to Hobbes' argument. It is a thought experiment, showing the consequences of there not being a state, and allowing him to infer the rights of the people within the state. In terms of history, Hobbes would have had in mind cases contemporary to him when state authority collapsed and violent chaos took hold -- the English Civil War etc.
He is not arguing from history, and to dismiss his argument on that ground alone might risk disengaging from what Hobbes' was trying to get at.
What we really need is a champion to explain in relatable, plain English why encryption is essential even for mom and dad, and to explain it in a more mainstream venue. I think a big reason why people don't encrypt mail, etc., is because:
1) they don't know why it's important because nobody can explain it to them in relatable terms (like saying: when you send an email, Google keeps a copy forever, and the FBI can read it just by picking up a phone and asking nicely), and
2) if they do know the importance, the practicalities of encryption are explained impenetrably. A blur of acronyms, bad metaphors ("keys?" terrible choice of metaphor, considering how a pair is intertwined and their actual use), and no well-known authority you can trust to explain it all simply.
The problem isn't that people don't care. They would care if they knew the realities of how their communications are stored, processed, and exposed to their governments. The problem is that nobody can explain it to them in a way that's not ridiculously complex or laden with terms like "Platonic realm" and "transnational dystopia".
You are right, people care. But not about things that would make reducing government power likely nor encrypting things by default probable.
They care about getting to work in the morning and getting home at night. They care about dinner with the family and a couple hours mindless television. They care about being safe while they do these things, and they've fully bought into the government's mantra of "we will protect you", so, as long as that's happening, they don't care about anything else.
Go talk to just about anyone outside of sites like Reddit or HN about the TSA, and you will be told how good a job they are doing. When the government tells them it is time to randomly drop their pants for the cavity check, as long as they are told it is making them safe, they will willingly oblige.
As much as the government's power grab, the complete lack of concern for it scares the hell out of me.
The notion that reliance on the government for protection is a brainwashed delusion is one of those conversational signifiers that convince normal people that all this encryption stuff has nothing to do with them.
The problem is the government has been leaning on that to expand to things that are of questionable "protection".
Does millimeter-wave scanning protect you? The government sure expects you to believe it does.
What about seizure of property? That will surely protect you from drugs.
Why should we need a warrant for things like accessing somebody's email? Terrorists might be sending emails.
In some way, each of these things might increase our safety, but the cost of that protection is intolerable to me and many others. Unfortunately, most people don't seem to realize any price is being paid.
this hit the nail on the head, because the pain of the price isn't felt by the average person _at all_. It is only felt by people at society's margin, who may skirt the law at times.
Now, someone might argue that this is actually a good result, because this will prevent laws from being skirted at all! If, or when some form of revolution is required, that necessarily entails breaking the law (otherwise it wouldn't be a revolution). This means, by slowly seeping such privacy invasion laws into place, its like boiling a frog alive - the frog doesn't even know its being killed.
This is why you have to watch very carefully, any form of censorship, or measures that strip away any sort of right that a citizen is entitled to.
unfortunately, no one is going to care. i hope i will be dead by the time things turn sour (if indeed they do).
> It has an obligation to actually protect its citizens
Perhaps you can claim agents acting on behalf of the state have a metaphorical obligation to protect citizens. But they do not have a literal, legal, or contractual obligation to do so in the majority of circumstances:http://en.wikipedia.org/wiki/Warren_v._District_of_Columbia
So I think someone should explain to the people in a clear way that you don't need 100% security, but you need to understand when and where your information can get compromised, and what you can do about it. Eg:
- Private message on facebook - you are screwed
- Messenger - you are screwed
- Post on a blog - you are screwed, unless you posted anonymously and hidden your IP (which is not that easy, we know of many geeks who were caught even when they were using Thor, because they didn't fully understand the technology - hint: exit nodes)
- Email - you can encrypt it, and you are safe as long as both computers (sender's and receiver's) stay safe (assuming you store your private key there)
- Data on your computer - you are safe unless malware is installed, or someone gets physical access. You can use full disk encryption, but you will probably have to use Linux (personally, I use Ubuntu), so this is a far fetched goal for the regular Joe. There is also truecrypt for windows, but it's not full disk if I recall correctly.
- Etc.
I'll add a recent anecdote here: Just the other day a friend of mine replied to one of my emails, saying that gmail broke the encrypted email (meaning he couldn't read it, not that gmail decrytped it). In his reply, I received the broken email, and four emails from a private conversation he was having with other people. Something happened in gmail, something went wrong, and I got those emails. They came with headers and everything, he didn't copy/paste those (he wouldn't know how to do that). So there's another reason to encrypt emails: mails server can make mistakes apparently.
"The people" don't need detailed explanations about why one form of technology is "more secure" than another. Instead they need motivation to care about security from their government.
Security and "being able to sleep" is more about understanding, and less about installing things on your PC. If everyone suddenly started encrypting their emails, of course we would be safer. But nobody is going to bother doing that, if they don't really feel safe (because they don't understand how safe they are, or which risks they are taking).
TL;DR - To sum up, even if you get people to want privacy, there is quite more work to do after that. People have lives to live, and if the cost of privacy is becoming a security expert, in most cases they won't bother.
Either you use a 3rd party service to encrypt, its easy and also extremely dumb (since its not end to end encryption).
Either you use PGP or SMIME and guess what: it's too hard. Their design is fine. I especially like GnuPG (PGP), but the UI, even in CLI, is terrible, terrible!
Most people don't even understand that a GnuPG keychain generally contains 2 private keys, not one (one for signing, one for encryption!) or the concept of master signing key and subkeys.
These concepts are relatively simple, but their use is hard. Terribly hard.
Thus the solution should work over email, and with our current email clients. S/MIME/GnuPG/PGP do, but their implementation is far from friendly.
I think you are overly optimistic here. Let's put it this way: if people were told that they had to report one crime committed by their neighbors in order to watch the superbowl, what do you think would happen?
"They would care if they knew the realities of how their communications are stored, processed, and exposed to their governments"
I have a lot of friends who know this, some of whom know it in more depth than many HN readers. Guess what? They all stopped bothering to maintain a PGP key. They all carry cell phones, and they do not even take the time to try to disable location services. They are all users of at least one of (Facebook Twitter Google+ GMail LinkedIn). If the people who know these things do not care, what make you think that people do not know these things would care if they became knowledgeable?
Are you personally sure no backdoors exist in the physical hardware you use? In the operating system you use? In the compiler used to build your OS? In any of the applications on your system? Are you sure that there's not a hardware keylogger on your keyboard, and do you check every day before sitting down that there's not one? Are there any secret cameras pointed at your keyboard, or sensitive microphones hidden nearby that can distinguish what keys you hit?
And once you're sure of all that, are you just as sure everyone you communicate with is equally diligent?
And, while we're at it, have you come up with a solid patch to prevent the well-known rubber hose vulnerability that exists in all cryptographic systems?
That doesn't mean the crypto-anarchist project must fail. Encryption is invaluable: while the vast majority of other technological advances--sedentary agriculture, writing, maths, roads, sewage systems, paper, the telegraph, electricity, the light bulb, cars, "computers," satellites, Google--have all increased the legibility of the world to the State, encryption does the opposite. The panopticon isn't an existing, established system but instead an equilibrium point that the State has to constantly push us toward: anytime the economic cost of that push is increased, it gives us more opportunities for creating spaces of genuine human autonomy.
But once you recast crypto-anarchism in that more moderate and stronger form, encryption moves from "our one hope against total domination" and a "hope that with courage, insight and solidarity we could use to resist" to something more banal: one tool of many. Not even a particularly effective tool: governments don't care about a bunch of nerds throwing PGP parties, and all the encryption in the world hasn't prevented the State from throwing Assange into jail (a pleasant jail with some fine Ecuadorian decor, but a jail nonetheless) and obliterating his organization.
Being this paranoid he should be advocating "post-quantum cryptography", i.e. cryptographic methods that are secure even once somebody develops a quantum computer.
What if the world changes, and yesterday's orthodoxy is tomorrow's heresy? This used to happen in the old Soviet Union, all the time.
What if, unknown to you, you are friends with a guy who the government doesn't like? This very thing happened to Maher Arar - actually it was two hops away, his friend's brother signed his lease, and that's all that was needed for the US government to whisk him from JFK airport to be tortured in a Syrian dungeon. Maher Arar is a guy just like you and me - he works in wireless tech, and crossed from Canada to America all the time. See http://maherarar.net/ .
Why do I have to explain this to someone whose nick is georgeorwell?
A few people took on the risk of giving him a treasure trove of stolen documents (the VAST majority of which did had zero positive impact in being released), and he turned it into a soapbox.
An invalid security certificate, and even that only if you go out of your way to specify https. If the vast majority of users saw this, they'd go running; including myself. I can't in good conscious recommend crypto that doesn't have it's own security certificates under control.
I have as yet not seen any less shady open implementations of PGP out there.
Of course, because of the proprietary nature of windows, it is totally possible for them to have back doors which will break your encryption, but I'm fairly sure that there are ways to verify, even without source code; that Microsoft isn't pulling any funny business.[0]
[0]: Besides, I'd prefer a situation where politically unsavory backdoors have to be used to read your data, as opposed to it being plain text and free for all.
The thing we really need (and what I'd fund if I had a spare $Xmm or so) is a great crypto API and solution to the user key management problem for iOS and Android, hooked into apps. It's technically easier to do on Android. On iOS, you're kind of stuck due to the core apps (mail, messages, etc.) being first-party Apple). It basically would take Apple deciding they cared about this issue, then building it into the OS in a way which didn't actually require trusting Apple completely, to work very well. Android has some steps toward this with some NSA projects, and wouldn't even necessarily require a full forking.
Some way to do tokenization and thus fairly transparent encryption on the client (phone) inside apps like the Facebook App, Twitter, etc. would also be nice. That's both a technical challenge and a UI/UX problem.
Silent Circle (from Jon Callas, Phil Zimmerman, Vinnie Moscaritolo (the PGP team...) and some Navy SEALs and defense contractors I knew from Iraq) actually seems like a pretty viable choice for sms, email, and voice right now. It unfortunately doesn't integrate into the social networks and other services people use, though.
I also feel pretty safe in saying it's not an either or thing, we can have both; and should.
1) Want military-grade(ish) hardened coms
and also
2) Aren't willing to set it up themselves, but trust a service provider to do it for them
I read their docs a bit ago and don't really get it. I didn't really get Whisper Systems offering either as it appeared to have a broken trust model on a variety of levels.
If I cared about this kind of thing, and I really don't, I'd likely want to own all parts of the transport system and have the only available threat surface be the encryption algorithm as much as possible http://www.voip-info.org/wiki/view/Asterisk+encryption
Might it all be pointless without massive amounts of traffic padding based on this attack? I wouldn't know. http://link.springer.com/article/10.1007%2Fs10207-010-0111-4...
I also find Eric Hughes much easier to rally behind than Julian Assange, although John Gilmore is better still (although largely focuses on drug policy, now). Or John Perry Barlow or Mitch Kapor.
There are really no shortage of events like this in the Bay Area. I think "how to help mainstream developers build and operate services securely" would be the only thing I'm really into; end users are too varied and stressful for me. (there are usually a critical number of true tinfoil hat, "I've been marginalized by society and need someone who hack my girlfriend's email" types at open end-user crypto meetings...) At least based on the previous several attempts at this kind of thing (2600, Ian/Len's key signing parties, cypherpunks physical meetings, etc.)
In-fact if I look around the room, I'm the one talking about what William Binney has said & Echelon, so I'm probably the tin foil hat.
I agree about the focus. What's interesting is some of the bugs that I've found because I don't often see things from a UI perspective, and talking to end users has made me see some new bugs, also see problems that remain to be solved that I am currently working on.
I think the bay area is unique, there is nothing much of it's kind like this in Sydney.
I agree with Moxie Marlinspike on that, we were preparing for fascism but got social democracy[1]. Assange is still preparing for fascism.
You mean the guy who is in internal exile in Britain because as a journalist he revealed war crimes committed by Britain's partner the United States? He's the guy who is delusional about the form of government that surrounds him, huh? Glad it's as simple as that.
I definitely appreciate his engagement in disclosing many interesting documents about the micro-social diplomatic environment. But after all, what about the more interesting stuff? Leaked documents from the center of the turbo capitalist universe are still pending. (IIRC those were promised for around last christmas...)
Isn't this because he refuses to undergo questioning? As I understood it, the laws under which he is to be charged prohibit laying charges against him until they question him. So in this case, to say he has not been charged is devoid of meaning.
He offered to go in for questioning under the condition that it was agreed that there would be no extradition. Officials said no.
So he sought asylum in the embassy under the pretense that he would otherwise face torture and death at the hands of the United States. Ecuador agreed that this was a valid concern, so they let him stay.
Seems telling.
Honestly, to me it looks a lot like Assange's argument boils down to, "I've asked for special treatment, but they won't give it to me. Clearly, they are conspiring against me."
How it shows most prominently at the moment is file sharing. Setting the endless copyright debates aside, what happens is that governments and large companies want to interfere with the privacy of what citizens are doing with their own bits. They say copying is theft while citizens consider twiddling their own bits a private matter that's none of anyone else's business. The citizens don't understand that while it's de facto legal to form a sneakernet—the actual legal status probably varies from place to place but nobody has ever been sued for sneakernet filesharing because nobody else never knows about it—it's illegal to form a filesharing network over the internet.
I don't promote or demote filesharing per se: it's just the cutting edge where the future trends will show years before they land elsewhere and that's what it makes it so interesting. A marginal slice of file sharing has already moved to anonymous darknets but in a few years and after a few more bad copyright/freedom-of-speech incidents with bad publicity, there will eventually be a breakthrough and the whole filesharing activity will go underground en masse.
When the masses go for it, the capacity and availability of invisible darknets will raise in orders of magnitude. That means there will be other providers in the anonymous networks as well, websites and services. There already are some, from anonymous wikis, anonymous project pages to anonymous forums but currently those are playgrounds. That is not so in ten years: there will be a major "bazaar" going on underground. While everything is anonymous and untraceable, everything is also secure. An online bank could very well operate in the anonymous network because the traffic is already cryptographically signed, and users can enjoy strong authentication if they wish to or remain a pair of anonymous public/private keys.
At that point the traditional grasp of internet control is lost.
The institutions governing the internet and the copyright and whatnot are faced with a big dilemma: do they dare to ban and make illegal anything that's not specifically permitted on the internet and if so, how to go about it in actuality. Do they lobby for laws that only allow ISPs to let citizens connect to a http proxy that validates all traffic to be "approved"? Do they extend the charges for any use of the invisible internet that is deemed illegal, to cover all users of the invisible internet?
We're still in the shadowdancing mode but the stakes are going higher, and in at most ten years the problem of control versus anonymity will have come out in the public.
We better know what we want, at that point.
this is predicated on the assumption that providers are not strangled by their balls by the authorities (who is in turn strangled by the balls by lobbiests/companies/vested interests).
If you could run your own routes with private equipment (such as a mesh like wireless network?), instead of having to sign up to an isp, then i see this as more viable a future.
It's already possible to connect to a website over https (with a self-signed cert you've obtained through a second channel) and be pretty much certain no one is snooping. The target you're connecting to doesn't have to be obvious either.
Most governments care about business these days. Do you think any government would say "no crypto" when Coca Cola says they need to protect the secrecy of their formula, or when HBO says they need to prevent people from copying movies?
I thought most people here had heard of The Silk Road onion service: https://en.wikipedia.org/wiki/Silk_Road_%28marketplace%29
> An online bank could very well operate in the anonymous network because the traffic is already cryptographically signed, and users can enjoy strong authentication if they wish to or remain a pair of anonymous public/private keys.
Or you can use bitcoins to accomplish the same and you don't even need banks.
As William Gibson said, "The future is already here — it's just not very evenly distributed".
Bitcoin and the silk road are not the future, but prototypes of it. It will be interesting to see if they become more than that, but they are showing the way forward if society continues to go down the directions currently being perused.
The longer this fiction persists, the less chance a fundamentally decentralized crypto currency will take hold. Trusted 3rd parties will always be necessary, and that's not a de facto bad thing.
BTC can work without trusted 3rd parties, and transactions can be performed in a completely anonymous way. Not every transaction requires or even benefits from these qualities, however. For Joe User's grandma to use BTC, there are going to need to be trusted 3rd parties (e.g. banks) to manage the minutia of transacting. These 3rd parties will make things simple for grandma, and ensure that she doesn't get screwed.
The thing that worries me about this push towards encryption and anonymity is that it does afford nefarious elements a lot of safe harbor. I imagine it's fairly possible to identify individuals given a few message traces, even in an encrypted anonymous environment, and layfolks simply aren't going to have the skills to cover all their digital tracks - can even expert cypherpunks? Meanwhile, a few malevolent elements in unison could easily co-ordinate and harvest details, with enough cover to be hard to track down (and even harder to prosecute).
An alternative is a world of transparency and openness - with a huge loss of privacy, but also a loss of privacy for those who would push their own causes of power and control, and/or commit crimes.
I honestly don't know what the long-term best path would be - or if there is even a genuine dichotomy between anonymity/privacy at all. I value my privacy, but I also value the opportunity to identify the sources of problems and use the structures of society to deal with them.
The secret might be a terrorist plan, a plan to open a new business, a plan to rob a neighbouring village or a plan to arrange a surprise birthday party. You never know, but people like their privacy. Even before the internet and telephone people could talk to other people to arrange things to come, while in the outside it just looked like the folks are walking around the town.
A transparent government and officials would be nice but I think that would never happen either. There are always matters that must be processed with confidentiality in the first stages, or the system just wouldn't work. Consider the old-fashioned hard-boiled journalism: people will talk if they can remain anonymous and confidential, and by talking they can prevent something worse from happening.
Limiting the secrecy of government/public sector affairs to a certain, absolute period of time might work, though. Things should be public as soon as they're finished.
I think that equal anonymity and confidentiality is better than the current world where most people are not anonymous and the powers to be can snoop on the rest and yet retain their own confidentiality in their actions.
The world might certainly be a very dull place if nothing was private - no more surprise birthday parties as you mention, for example - but perhaps there would be equal and opposite benefits to shared knowledge/information?
The situation regarding whistle-blowing itself requires that there is something worth reporting, which wouldn't be the case if the knowledge was already available (unless, perhaps, the knowledge was available but simply not highlighted well enough for people to spot any malicious behaviour).
Totally agree with your final point - it's a very strange dichotomy that as average people are finding less and less privacy, those with privilege or power are the ones who are afforded it.
Robots distributing social power? I think it will be the exact opposite. Robots will be used to maintain social power, to prevent people from every gaining it. Your robot will be like an iPhone: you will be locked out of the software, forbidden to make modifications, forbidden to hack. Your robot will produce only as much as you need to survive; you will not receive enough to gain any more power than you already had. Your robot will also spy on you, so that if you start organizing a group of people to rebel against those with power, you will be thwarted by some means (perhaps your food will be drugged to reduce your cognitive abilities, or maybe for simplicity you will just stop receiving food). The people with power will never have to worry about being unseated, because they will have total control over the means of production. The only threat to the powerful at the point will be their own incompetence; only when they are not able to make the right decisions about managing society will society have a chance to rebel.
Here is a microcosm of what a world where robots run everything would be like:
I have yet to see any evidence that this is true; all I see are anecdotes from law enforcement agencies who are pushing for less crypto, and even those anecdotes only tenuously describe "nefarious" elements. You cannot encrypt a blood stain or a fingerprint, nor can you use an anonymity system to hide the fact that a known terrorist group is increasing the volume of data it sends and receives.
So what nefarious elements do you think are going to avoid prosecution by using crypto? A few years ago, there was a case of a group of child molesters using PGP and anonymous remailers (and possibly other privacy technologies) to communicate and exchange photos of themselves abusing children over Usenet. They were caught, arrested, and prosecuted following a well-coordinated investigation -- otherwise known as "good police work." Only a handful managed to avoid identification or prosecution, and it is worth noting that this was the case with investigations of criminal organizations long before good encryption was widely available. It should hardly be surprising that such a group was ultimately caught: they were sending each other photographic evidence of their own crimes.
It is also worth pointing out that anonymity systems are used by the police to catch criminals. In the case described above, the police used the very anonymity system that the child abusers were using, and were thus able to observe their messages while maintaining the secrecy of their investigation. Similar scenarios have played out with Tor. Criminals who use the Internet will eventually figure out which IP addresses belong to the police; it will be critical for the police to use anonymity systems to mask their IP addresses (this, in fact, is closely related to the reason the Navy created Tor in the first place). It is not so much that society's nefarious elements are more empowered now; it is more that the nature of the game has changed, that new tactics and strategies will be developed by both criminals and the police to utilize and cope with these systems.
I would argue that crypto and anonymity systems have benefited society more than they have harmed it. The same crypto and anonymity technologies used by the group I mentioned above have been used by political dissidents and activists to protect themselves from abusive governments; human rights activists have used such systems to protect the people they work with. Whistleblowers have used such systems in the past, and will have to do so in the future. For people who do not have an army at their command, these sorts of systems are necessary for their protection. If you were going to report Mafia activity to the police, would you rather use Tor/remailers/etc. or would you walk into the police station in person?
There is no such thing as a world of transparency and openness, because crime is part of human nature and because political ambition is part of human nature, and both of these behaviors exploit openness and transparency. I am all for an open government, but even I acknowledge that the government will need to keep some things secret -- military plans, investigations of dangerous criminal enterprises, the locations of witnesses to crimes, and many other things must be kept secret for society's benefit. Open and transparent government does not mean "secret free," it means "secrecy when it is absolutely necessary;" it is the responsibility of citizens to ensure that their representatives in the government are not declaring too many things to be secret, and it is the job of journalists to report to the citizens what is being kept secret from them. The sooner society realizes that, the better.
I also completely agree that pretty much every technological innovation throughout history - weapons, communication mediums, etc - are used by both 'police and thieves', or whichever actors fit in the white/black boxes in the given situation.
The problem in my mind is more general - it's that crypto and concealment are just an evolution of the status quo - the arms race continues, with more 'secrets whispered in the woods', yet average people are already losing their day-to-day privacy, in vast numbers, and crimes still occur of course.
Opening everything is clearly radical and/or impossible, and it's a long-term idea/concept rather than anything feasible in the near future. Despite my ramblings, I'm a realist, and I've worked on migrating many, many legacy systems, so I'm familiar with the challenges, but this is the only process I've reasoned about so far regarding disruption of the arms race itself, as opposed to just evolution of arms, so I'm hunting for counter-arguments and these are good ones.
Enabling dissidence is a very good point, and I think it highlights the problems with hierarchy/power itself and information disparity. If neither party was able to operate without the knowledge of the other, then dissidence could take place openly without fear of hidden/unknown retribution. Trusting that the system is really 'open' and that you can see all the communications is definitely a challenge though (unsolvable?)
Regarding your final point, I'd say that although crime is part of a darker aspect of human nature (which can be encouraged, manipulated or instilled), we have been controlling our own education and evolution for generations through society and religion and choice of partners - so why can't we see this as an optimization problem, and try to guide ourselves towards a less criminal and violent nature?
(PS: the final point is a bit rhetorical - I think we have been for a long time already - cannibalism isn't hugely popular for example)
One interesting thing I've noticed that the people behind the best filesharing networks tend to have tremendous success with their later projects.
Napster is the obvious one. After Napster went down, Shawn Fanning co-founded Rupture and Path, and Sean Parker went on to become the first president of Facebook, key investor in Spotify, and managing partner at the Founders Fund.
Kazaa is another great example. After their legal walloping, the founders and development team behind Kazaa regrouped to form Skype.
And then there's The Pirate Bay, which is still rolling merrily along, court rulings notwithstanding. Its team hasn't created any billion-dollar companies yet (we'll see what happens with Flattr), but they created a political party that's won elections in multiple countries, as well as the webhosting company PRQ, which was Wikileaks' home in its early days.
I don't think all of these later successes are a coincidence. Filesharing involves hard technical problems, hard logistical problems, and intense competition. If you were an investor, a blind strategy of giving money to the best pirates you can find seems like it might be surprisingly sound.
"won elections" is a bit of a stretch. In countries with multi-seat constituancies and proportional representation, there are often minority/niche candidates.
[1] http://en.wikipedia.org/wiki/Pirate_Party#National_Pirate_Pa...
Not invisible to governments and corporations, just to your fellow citizen.
The corporate-state "owns" the infrastructure. Get your TCP/pigeons (or whatever network you can throw together) working and we can meaningfully discuss "invisible darknets".
The other day I found this fellow's idea for a peer-to-peer social network service: http://code.google.com/p/peer-book/
"Your data is stored in a distributed fashion, across the network, so that even when you turn off your instance of PeerBook, your friends will still be able to view your Profile and send you messages.
"Of course, all of this data is encrypted and backed up several times, so that even if Alice's data is being stored on Eve's machine, Eve will only be able to read it if she is Alice's friend; and Eve will only ever be able to delete her local copy of Alice's data which has no effect on its overall availability to the rest of Alice's friends."
He's got the right idea. I haven't examined the project, and it doesn't seem active.
I'm downvoting parent and giving you the right link: https://freenetproject.org/
Try this one: http://distributedcity.github.com/
The previous incarnation of Distributed City was pretty cool. I haven't looked at their new code.
The battle is winning the minds of the average person, by showing them that an encrypted, unmonitored, uncensored internet is in their best interests and not something to fear.
Or in the worst case, show that an all powerful (and therefore eventually corrupt) government is the greater of two evils. The proper tool for this is probably cheap, scalable marketing stunts and compelling media that spells this out in layman's terms.
Not entirely false, but http://xkcd.com/538/
http://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis | http://en.wikipedia.org/wiki/Rubberhose_(file_system)
Wired in 2008: "Among other achievements, he [Assange] co-invented Rubberhose deniable encryption, which would let a dissident being tortured reveal one key to unlock a hard drive, while not giving away that there was a second or third password-locked folder of information."
http://www.wired.com/politics/onlinerights/news/2008/07/wiki...
The truth is that the only reasonable thing to do is to become politically active.
If you can't beat them, join them.
We need to build and use technologies that respect human rights and we need to fight to make sure that they remain legal. One without the other is nothing. There is no point fighting to keep something legal if you don't have the technology and infrastructure to use it.
But I wonder what shape any political activism could have. Maybe this cryptography movement should be seen as just that, a way to force a political debate and make any political activism relevant.
Unfortunately, that is how you know if someone has gone off the deep end.
I agree though that we should all be encrypting communication, but our government helped develop the methods of encryption, and some methods have been known to have backdoors: http://www-cs-faculty.stanford.edu/~eroberts/cs201/projects/...
Why it is highly recommended not to implement your own encryption method, we shouldn't be using something that could easily be decrypted by the wrong people either. We need to study methods that we use extremely well, and be aware that encryption susceptible to decryption via brute-force with significant resources are just as dangerous as backdoors.
I also advocate development of wireless mesh networking technology to handle larger adhoc networks. While those that wish to spy could still become a member of an adhoc network, it would significantly complicate things for them.
Why It Matters: [...] This blog isn’t terribly controversial. But if only the “controversial” stuff is private, then privacy is itself suspicious. Thus, privacy should be on by default.
https://www.tbray.org/ongoing/When/201x/2012/12/02/HTTPS
EDIT: Ironically, I accidentally linked to the non-HTTPS version. Fixed.
Let's say there were some massive breech of probable cause before billions of people used the internet every day. Maybe some king is issuing multitudinous search warrants to go and seize all postal mail correspondence within some large sector of the population. I'm thinking of something "old tymey" here.
Okay. Well, it seems to me, the 18th century version of Julian Assange would essentially argue that people need to start getting good at writing in and decoding cryptograms. What we really need is the 21st century version of James Otis.
I know, it's a very, very unfair analogy. But it explains my point. If this stuff that William Binney is talking about is really going on, wouldn't a legal or a socio-political (not sure if I'm even using that term correctly) response be more lasting and effective than having everybody start writing letters in the form of a NY Times crossword puzzle?
http://www.salon.com/2012/12/02/julian_assange_the_web_can_c...
You can only buy this book direct from the publisher. Amazon isn't carrying it.
1dc2e5b6f0d5036a182e85ab34da839d15eaf1ed cypherpunks.epub
5d546aaa83aebd43a2342f6dc737d271a34ff684 cypherpunks.mobi
ccaf1c45fc31633c9728dcd2cd4545b55a27be7c cypherpunks.pdf
That's why a free payment system (without state control) should be given the top priority.
The only defence against tyranny is the effort of a sufficient number of people, with the will and means to resist, choose to actively support freedom and dismantle tyranny. Specifically, people in power: politicians, judges, lawyers, and police. If the people who run the state, and exert force in its name, prefer tyranny, then tyranny is what we'll get. And that's exactly what happens when those who oppose tyranny abandon the state those who support it.
I've spent a lot of time on ResoMail, a an easy to use open source secure alternative mail, but during beta testing it didn't show user interest, people don't understand the dangers of trusting their data to corporation and didn't use it, so now the project is on hold, now I'm looking for new opportunities to develop it.
No, but most average citizens' crypto is still ridiculously vulnerable to the three Bs: Burglary, Blackmail, and Blunt force trauma.
...and if you have a group of people truly loyal to freedom, then you don't need much crypto anyway ...just spoken words, physical transfer written/printed papers or usb sticks (this is how bin laden supposedly communicated his speaches if I remember well, right?) or other media and a brotherly handshake...
Another likely difference is that truecrypt works.
Neither will stand up to scrutiny for the purposes of deniability. It's obscurity which is effective in the scenarios that the docs outline below.
Now, this short excerpt of Assange's argument strikes me as outlandish, and there's only a couple of skeptical posts to be found!
There are a bunch of problems that I can see with it, I'll just list a few off the top of my head.
1) It's a predictive argument, which is hard (prediction). The prediction is that society will become worse because of the internet.
2) Glorification of the past: a casual consideration of societies and governments of the past highlights that they are, all of them, horrible. You don't have to go back far in US history to get to an amazingly evil government (1970s CIA activities for example)
3) The increased transparency brought on by the internet is a good thing. ,I'm glad Petraeus got his ass busted, as the phony hero creation meme has been weakened that provides cover for US misdeeds in the war theaters. Governments have been literally getting away with murder since time immemorial. There is a better chance of stopping them if there is, in general, more public, unencrypted communication (this is precisely what brought Petraeus down)
4) There is no way the public at large is going to start encrypting their communication. That kind of secrecy is just not that useful to the average citizen. It is also too complicated to understand for busy non-hackers.
5) The benefits created by network effects will be significantly diminished by introducing private encryption. One of the main uses of the internet is the creation of large scale markets. Markets are by definition public, or at least open to a group. To get efficient markets you need a sizable group. To keep access to a market private gets harder the more participants it has. Fairly determined efforts to conduct secret, anonymous actions by hacker groups like Anonymous have proved to be easily broken by law enforcement. And these are hackers!
6) Efforts at resisting tyranny can be demonized, and crushed, more readily if conducted in secret. The fact that Wikileaks acted somewhat non-anonymously to release supposedly secret data to public is what made it effective. If Assange had tried to undermine the secret making apparatus of the power structure in secret, he would have been just another terrorist (and maybe dead)
I could go on, but my point is that I think what Assange is promoting here is pointless. I can't even conceive of how private keys could be distributed to a large network without being easily compromised. I would love to hear some of you smarter folk comment on this.
We might be there already.
2) Glorification of the past
I don't think so. More like a broken promise.
3) The increased transparency brought on by the internet is a good thing. ,I'm glad Petraeus got his ass busted
That's just disingenuous. The secrets that really matters about military operations are not public in any way, while you are happy because this guy gets caught cheating his wife. Meh.
4) There is no way the public at large is going to start encrypting their communication.
Oh, that's a predictive argument. Make something usable and we'll see.
5) The benefits created by network effects will be significantly diminished by introducing private encryption.
So that networks effects are more important that freedom, aren't they?
6) Efforts at resisting tyranny can be demonized, and crushed, more readily if conducted in secret.
Sorry, that's total nonsense.
It illustrates that the indiscriminate sharing of information on public networks gives increased transparency into the lives of people, including the rich and powerful. Even if they know how to cover their tracks, they can be exposed through the insecure practices of "civilians" with whom they interact.
Something that Assange doesn't quite address in the excerpt is that not only do people not care about about secure communications, they actually want their personal information on the "public" web. Most people do not have a group of people they would like to communicate with but in a highly secure manner. The exception would be for affairs.
Even people working for companies that have requirements for secrecy need low friction method of exchange of information with larger networks of individuals that they don't know well.
There are negative consequence to this (specifically the ease with which the govt can spy on its citizens, as Assange points out).
But the cost to individuals, and to society, is too high for whatever benefits a widely used "darknet" would have. The value of the internet is connecting large numbers of people who are engaged in the various life activities that people do. It is not compatible with secure networks. The porousness is a feature not a bug.
I mean really, what sort of activities would an average person find it useful to use a secure network for? Illicit, illegal, or insurgent. Not a real high demand for this.
FWIW, I think what Assange has done with Wikileaks is heroic. I just think his vision of a sort of private internet is impossible. It would have to be based on "insiders" and "outsiders," a sort of division in the population. Those sorts of division are only maintained through nasty applications of "real life" power as far as I can see.
I think that that's our fundamental point of disagreement. Demand doesn't follow needs at once because people still doesn't know what they need. But they will. Cases like Petraeus' will contribute to raise awareness.
Also sometimes people tend to use at home what they've learned to be useful at work. Increased security in companies could contribute to the success of an easy-to-use product.
More: piracy, people living under tyrannic regimes, cheaters, etc.
http://www.zdnet.com/blog/btl/wikileaks-insurance-file-decry...
Wikileaks has distributed AES encrypted files that it claims are full of government secrets. They have withheld the information needed to decrypt some of those files ( although some keys have leaked from wikileaks, oddly enough) as a deterrent to persecution by governments. There's just one minor problem... This is effectively publication with delay, and it forces governments to go after them hard rather than deterring them.
AES is based on computationally difficult to crack algorithms. If you assume there will be no advances in algorithms, no new types of computers, no weaknesses found in the implementation of AES, etc. then it will take a comfortingly long period of time for these files to be cracked. These assumptions are bad. Cracking algorithms are advancing rapidly. It is astronomically improbable, but not impossible that someone could come up with an efficient algorithm for factoring tomorrow that would render all factoring-based cryptography impotent overnight. The prospect of quantum computing on the horizon also places a time limit on how long these files can remain secure.
When you commit secrets to a current form of encryption based on computationally difficult problems and distribute the cypher text broadly, you have effectively published those secrets with an unknown delay.
This is why governments want Assange so badly. He's not keeping secrets to deter them, he's publishing them with a delay because he doesn't know what the heck he's doing when it comes to encryption. If he used a one-time-pad (Vernam cipher) and kept the key on his person he'd be in a far better position, but he's apparently too stupid to do this. How do you use a one-time pad?
Cipher = message XOR key (XOR = exclusive OR)
10110101... (secret message in binary)
11010111... (true random key)
--------
01100010... (ciphertext)
For this to work, Assange would have to distribute the ciphertext and keep the random key secret, perhaps on a USB key around his neck. This method of encryption has been mathematically proven to completely secure provided the key is truely random and not from a pseudo-random number generator. True random number generators can be bought for relatively cheap these days. If Assange had encrypted the files this way they would be safe from any cryptographic attack, safe from quantum computers, or anything else out there. For all time. The only thing that could unlock these files would have been his USB key. Obviously, this is not a convenient method for online transactions, since transmitting the secret gives eavesdroppers all they need to decode the ciphertext. However, for the use Assange has been putting AES to, one-time pads are perfect.
Why didn't Assange use a one-time pad? The only answer can be that, for all his bluster, he remains utterly ignorant of how encryption works. Thanks to his ignorance the governments of the world have a vested interest in taking him down. Even if someone else picks up where Assange left off, hopefully that someone will understand how encryption works.
And you are suggesting he use a OTP?
Assange is not the one that does not know anything about cryptography here.
And you say _he_ doesn't understand cryptography?
In order to crack AES though you need to either brute force it (which you will never do. Not that many bits, just forget about it.) Or you need a cryptanalytic attack that allows you to do it with reasonable computation and memory complexity. An attack that is currently unknown.
But surely such an attack could conceivably appear.. so what is the difference? The difference is that while RSA is a ticking clock (worse case scenario: slap on another ~256 bits to "factor-able" every 5 to 10 years), AES is only a ticking clock in the sense that we cannot rule out the possibility that one day it may start to tick.
If anyone in the world can crack AES, or will be able to crack AES anytime soon, it's the NSA, And it does not matter to Assange if they can crack it (unless the entire insurance file is a bluff).
AES was and is absolutely the correct choice for an insurance file. (I believe this is about when tptacek steps in, correctly calls me an idiot, and points out that another symmetric key cipher is a better choice.)
AES is broken on-the-fly now.
Even if information is encrypted. They now just store EVERYTHING indefinitely until they can crack it.
Makes you wonder if in the future, when they crack your encrypted content if your grandchildren will get a visit...
The nazi's did that kind of thing too...
The use of AES is clever. It will be crackable at some point in the future for sure - everyone knows this. I'd be willing to put 20 bucks on NSA already having cracked it anyway, even if that makes me one of those tinfoil hat types, but that would make no difference to Wikileaks - in fact it probably plays into Wikileaks' hands.
The fact that the insurance file probably -will- be cracked at some point in the future means that the information will ultimately be public. Perhaps this encourages more prompt action against Assange but it's a matter of weighing up this risk with the perhaps higher priority of eventually releasing the information - even if every mechanism of distributing the key in case of emergency fails, it will be cracked ONE day. I think this strategy is easily plausible enough.
One could claim that Assange's strategy is poor - certainly being under house arrest hasn't been empowering - but saying Assange is ignorant of encryption is ridiculous.
What use would a one-time-pad be with the only key around his neck when he got arrested? He needed a dead-mans-handle type arrangement.
There are lots of things that can be claimed about Assange, but claiming that he doesn't know encryption is not one of them.
OTP is theoretically unbreakable, but that would require a key that is as long as the ciphertext, at which point Mr Assange can just keep the data on the USB stick around his neck.
Nothing remains sensitive forever. It's likely everything in the "insurance file" would be public and mainly of interest to historians in 50-100 years, even without Assange. Most sensitive information in government ceases to be sensitive once everyone involved in the decision-making process is dead, and almost all of it is only operationally sensitive or for the lifetime of a piece of technology or particular source.
I mean, if we found out incontrovertible proof about the USS Maine or Gulf of Tonkin being engineered casus belli, who would really care?
Have you seen the video? It has no commentary. It has subtitles. It has title screens. No commentary. https://www.youtube.com/watch?v=5rXPrfnU3G0
And how does that video have an anti-US agenda? It's recorded by US soldiers, it's illuminating a particular act on a particular day.
I think the public has a right to know, history has a right to know what goes on in Iraq.
b) The argument about deferred encryption may be correct. However this is not related to the relations between Wikileaks and any government. (The argument may also be wrong. It could turn out that decrypting AES is still hard even in 100 years. In any case it is likely to be safe until the data is de-classified anyway.)
the 'key' in this case would be a multi-gb random document. how do you publish this quickly?
A 1.4 GB key... Yeahhhhhh, very practical.
edit: and btw I hope you're also confident on the quality of your RNG to output 1.4 GB of random bytes.
The problem isn't with storing that 1.4 GB, it's with distributing it quickly to very many people.
Something much smaller is just a copy-pastable string that'll find its way into Wikipedia edit summaries or onto t-shirts or whatever.
One could suggest that he could use something semi-random but well published information instead of random generated blob for a one-time pad. Earth rotational speed, stock market numbers, intensity of the sun radiation comes to mind. In that case, the password would be the exact dates to take data from, something that could be spread faster than gigs of data. The problem with this is, as soon people start to use it, people would start testing those data to decrypt with, and the key-size essentially becomes the size of time ranges of existing data.
A one-time pad as a consumer encryption has yet to be realized though, even though the programming effort needed to create a system like this is low. It's even easier to use such a system in todays world of 64 GB USB drives. (64 GB could be used as a key for almost a life-time of text correspondance.)
What the public would benefit from is a system that works as follows:
- Program has a create key mode. Lets you specify key size, or use the rest of the capacity (eg. a full thumb stick).
- Creates two of these files (one for each participant).
- Has a simple interface for encrypting/decrypting content based on the key file.
- Each message is prefixed with the offset of the file
- Party 1 starts at the beginning of the file. Party 2 at the end of the file. In order to avoid resending data using the same offset. When they get close to overlapping in the middle, they create a new key.
def otp(s: String, key: String): String = {
def base64decode(s: String): String = {
new String(new sun.misc.BASE64Decoder().decodeBuffer(s))
}
def xor(a: Char, b: Char): Char = (a ^ b).toChar
val s2 = base64decode(s)
val k2 = base64decode(key)
val sb = new StringBuilder()
for (i <- 0 to s2.length - 1) {
sb.append(xor(s2(i), k2(i)))
}
sb.toString
}
val ciphertext = "LQcGRC0HFR4ME0sjHhkOHBVSGB0ZGhIcWRUPQgsNFkYIHwdE"
val key1 = "YWJjZGVmZ2hpamtsbW5vcHFyc3R1dnd4eXphYmNkZWZnaGlq"
val key2 = "eW9jZF5vemoscCpOezlobno/OGlxfzJ7K3R8MXItfShnaGtq"
otp(ciphertext, key1)
otp(ciphertext, key2)
So releasing the ciphertext into the wild accomplishes nothing.