Tools For Treason
techcrunch.com
techcrunch.com
I was tempted to compare this type of end-to-end security to the second amendment (the right to bear arms), which was a right given to the people (in part) to ensure they could overthrow a corrupt government should one form - I don't think we're to that point and overreaching by the government has contracted back to reasonable levels before.
But thinking about this issue from a constitutional level, we have indeed (as the article states) given away our fourth amendment rights, and I don't see how developing the systems described in the article could be construed as treason - I'm simply making myself personally responsible for enforcing my fourth amendment rights.
My steps:
- Replace Google Apps for domains with my own servers.
- Stop using drop-box
- Establish private communications channels for IM (and perhaps something like Twitter.
Then I'll only use public infrastructure for data/messages I want to be public. Unfortunately, the list above represents a lot of work and is exactly the reason we seeded control of our data to outside corporations. We gave them our data as a means to simplify our lives or to gain greater "connectivity". It won't be so easy to go back.
one of the comments goes to great lengths explaining that
those controlling the data collection are duly elected.
And how powerless are they? The unelected Clapper did anything, while the elected Wyden could do nothing. The technologist Snowden did everything. Democracy didn't bell the cat of the government bureaucracy. Technology did. Technology is more powerful than both democracy and bureaucracy, as it is not subject to dilution and co-optation.How many web sites do you visit with ads compared to the ones you don't, again? I mean, the whole "eternal September" concept is predicated on certain technologies being diluted/coopted.
That's an interesting statement, and I think one I represents a a troubling undercurrent of thought in the tech community. "We refuse to submit to the democratic process and will override the democratic consensus through technology."
Corrupt power structures may have finally optimized for dominating a democratically organized society and we should be at least philosophizing about a favorable post-democracy world. I.e., what's more "democratic" than democracy?
In a more primitive time, would it be "scary" to suggest that through technological advancements like agriculture, writing, and calendars we could achieve a better, more just society?
Rayiner's point wasn't that technology intrinsically subverts the social contract; only that some technologists seem to want it to.
Specifically, you seem to hold a notion of a social contract: a concept that I reject. Subverting a "contract" which has been forced upon me and to which I never agreed sounds like a noble endeavor to me, but I'm sure you'd be repulsed by the idea.
Given our starkly different motivations, I believe the best outcome either of us could hope for in a debate is that we both remain reasoned and civil, as there's probably little chance of winning the other to our side.
Democracy sucks. But you know what sucks more? Everything else.
What I suggest in the article is little more than civil disobedience, in a way. It's refusing to supply an apparatus we never approved with information we never released. Since they can and will take it from us without our knowledge or consent, we have to make it impossible for that to happen before we can have a reasonable parley, you know?
Obviously we're not quite at the Gandhi or King level of disobedience (it would be rather hubristic to suggest it), but it's a similar principle in action, perhaps a bit more preemptively.
I think this may have been the point of the article's title (aside from being attention grabbing). The 4th amendment gives Americans the right against unreasonable searches without a warrant, and some similar legal protections exist in many other countries. But the technology the author is discussing generally has a design goal of preventing all searches, under any circumstances. In other words, to technologically ensure a right you never possessed in the legal sense. It provides protection for people and in situations not even the most rights respecting government would be likely to legally protect.
This doesn't make the technology bad, but it's a very interesting thing to think about, which is what I suspect was one of the points of the article. For better or worse, technological protection has the potential to go well beyond legal protections.
Either the data or system is secure, or it isn't. Technologically, if there is a way for a judge to authorize reading a single X; then it is a hole that eventually will allow to read all X without the warrant by others as well.
As an example, if a cellphone network software allows for FBI wiretaps, then that can be used also by illegal wiretapping (http://en.wikipedia.org/wiki/Greek_wiretapping_case_2004%E2%... - the criminals weren't even identified). And if a system is secure (for any reasonable definition of the word secure), then noone can break that security, no matter what warrants they have.
There is no middle way. If I'm allowed to protect my communications from random illegal snoopers (say, corporate espionage); then that protection will be just as effective against legal snoopers.
2) There are freely available steganography/hidden volume tools that make it impossible to verify IF there is something encrypted - for example, you might guess that a hidden volume exists, the accused may decrypt N hidden volumes, but noone would be able to check if there is another N+1'st volume for which a key was not provided.
Well, the alternative is that the government has access to everything, all the time, and we just have to trust that they're not going to misuse it.
Also, your wording implies that if a government agency does have a valid warrant, that this means they're somehow entitled to whatever information they seek (within the parameters of said warrant). This is patently absurd to me. If the government seizes an encrypted document with a valid warrant, more power to 'em. Have fun brute-forcing it. Doesn't mean I owe them the passphrase.
I wasn't suggesting entitlement so much as practicality. Up until recently, the distinction you're talking about didn't really exist. A warrant might not give police an "entitlement" to something in your house, but there wasn't really a lot you could do stop them from getting it. The best you could do is hide it which isn't very practical in a lot of situations.
But with an encrypted document, suddenly you have new protections. As you suggest, a warrant does the police no good because you also have the right (under the 5th amendment) not to tell them how to access it. Unlike a safe, forcing open an encrypted file might turn out to be impossible. Now you have a technical protection against searches that goes way beyond the legal one found in the 4th amendment.
Again, I'm not saying this is a bad thing, but I think it's an interesting way to look at it and at least one of the points I saw in the article. Technology is less a means to ensure 4th amendment rights and more a means to go beyond them...for both good and bad reasons.
Now I, as a (hopefully) rational human being, have a choice again.
I saw this too and thought how insanely naive it was. Also how nonsensical a response it is. The very point is that people feel betrayed by their government. By definition, then, those "duly elected people" are not representing the will of the people. That is, there is something broken about the system that must be fixed, but cannot be fixed by merely participating more in that broken system.
This dysfunction is also evidenced by the fact that much of this was done in secret by these elected officials and there is much effort to maintain that secrecy. A democracy cannot flourish in secret, as it relies upon an informed populace. But, if not for someone breaking laws created by "duly elected officials", we would not even know of these programs and hence the need to consider holding these officials accountable democratically.
In fact, that was the very point of the article: we have lost the reins and must now protect ourselves. And, the article itself was very thought provoking. Not so much for the technological solutions it suggested, but for the justification and context for their neccessity.
Here is the problem: the people don't feel betrayed. Just look at the turnout of the recent "Restore the 4th" in San Francisco--a pathetic ~400 people turned out. You claim that our elected representatives are not representing the "will of the people," but what you mean is that they are not representing the viewpoints of you and your friends. It's disingenuous.
And it's not because people are entirely apathetic. Just look at how many people Tea Party rallies attract. Tea Party rallies regularly get tens of thousands of people to turn out at events all over the country.
Maybe, just maybe, the people know and just don't think the slope is so slippery as you and your friends think it is?
Hint: The author specifically does feel betrayed. That's what the article is about.
It's also funny that you mentioned the Koch brothers-backed, corporate-sponsored, Fox News-pitched, astroturf Tea Party "movement", given the way that same media has covered this NSA issue like an episode of "Where In The World Is Carmen Sandiego" as they moved the focus to the Snowden chase vs. focusing on the actual NSA activity he uncovered. Such disinformation/redirection campaigns that fueled the woefully misled Tea Party folks are merely the flip side of the media campaign to mute responses here by shaping the narrative to one about a man vs. a nation. Ironically, this failure (or complicity) of the media is yet another threat to our democracy.
But, even with this concerted effort to placate the masses, there are many, many people who feel betrayed or who are concerned, irrespective of your scientific assessment of the pulse of America, which seems to be based solely on the turnout at a rally.
The freedom to own lethal weapons leads directly and inevitably to the massacre of innocent first graders.
Likewise, the freedom to be truly "secure in their persons, houses, papers, and effects" leads directly and inevitably to monstrous and evil acts.
Freedom is dangerous. Both the second amendment and the fourth cause us to "arm our enemies".
Freedom is also analog, not digital. We can accept some limits on our freedom to reduce the risk.
Speak for yourself. I don't wish to limit my freedom for any reason.
I don't intend to spend this short time worrying if someone else would approve of my choices.
I am more than capable of making my own decisions without harming myself and others, to hell with anyone who believes I don't deserve to do so.
I certainly didn't elect them.
If you carry it out to the point of absurdity, even water can kill people if too much is ingested too fast.
That seems an awfully low threshold for "strong enough to kill".
I think that every person should have personal encryption router from whih to access the cloud services
I thought this was some technology I wasn't aware of until I realized it was just missing a 'c'. :P
For an encrypted router, here is my script for making a RaspberryPi into a PORTAL: https://github.com/grugq/PORTALofPi
And an older blog post on why encryption and tradecraft only get you so far: http://grugq.github.io/blog/2013/03/12/anonymity-is-hard/
Here is the Ruckus Society's manual on "security culture" which has some brief info on why you need physical control over your data storage devices. Includes also some pointers on how to establish strong(er) physical security for your data. http://ruckus.org/article.php?id=789
Obviously if I'm wrong let me know, but I just meant it as a general alternative to people having their own entirely isolated physical server, local or remote.
In fact services like Spideroak would seem to be a reasonable tradeoff between convenience and security. A service you run on your own server from open source code reviewed by experts could be more secure, but it's a lot more of a hassle to set up.