Assange: How cryptography is a key weapon in the fight against empire states
guardiannews.com
guardiannews.com
"Our government has kept us in a perpetual state of fear — kept us in a continuous stampede of patriotic fervor — with the cry of grave national emergency. Always there has been some terrible evil at home or some monstrous foreign power that was going to gobble us up if we did not blindly rally behind it by furnishing the exorbitant funds demanded. Yet, in retrospect, these disasters seem never to have happened, seem never to have been quite real." -General Douglas MacArthur July 30th 1957
Eisenhower warned us. http://www.youtube.com/watch?v=8y06NSBBRtY
Having a 2 party system (for decades or centuries at a time) only guarantees that there will be a lot of things both parties will agree on, and there's nothing the citizens can do about it (other than massive protests, which don't seem to be happening in America anymore, or if they do happen they get mocked by the media, and then by the brainwashed masses who watch said media).
I think approval voting would change things dramatically, but even using the voting systems of other countries (such as having 2 voting tours) would help a lot:
Charlie Stross recently wrote about this in the content of UK politics:
http://www.antipope.org/charlie/blog-static/2013/07/a-bad-dr...
First, I'd like to point out that by "democracy" he's referring to what we all understand by democracy right now - a democratic republic.
Now, I think the way most democratic republics work has failed. I think we need a lot more direct democracy elements implemented in the democratic republic system. He says there that even the democratic republics were formed so the transfer of power is done without bloodshed.
But what do you do when even in such a system, the people feel compelled to create massive protests, possibly even violent ones (most revolutions)? I think the answer is an even more democratic republic. And I think you can achieve that with more direct democracy elements, such as more citizen-made laws, referendums, citizen vetos of bills, and so on (some of these exist in some countries like Germany or Switzerland, but not a lot of them, and there need to be more to become "more democratic").
This way, when the citizens are really frustrated about something, they can just fight to change the laws themselves, instead of waiting for the corrupt government to do it, and instead of having to gather in the millions to protest the government in the streets.
Note: I'm not saying we should completely discard the democratic republic system, and do away with "representatives". That's what most people (mistakenly) think when they hear this type of suggestion.
What I'm saying is far from it. I just want the republics to become more democratic, and for more ways to exist to bypass the representatives in certain situations (explicitly defined in the law), when there is big frustration about something. But of course a balance must be kept, and the representatives should still handle 95%-99% of the policies.
As an added bonus, it solves the problem of rebublics like the US where a party could have 5% support and 0% representation.
MI5 (the internal security service) held very firmly to only gathering intelligence on political movements seeking to overthrow democracy rather than conforming to the wishes of the ruling party at the time. Successive left wing politicians on becoming Prime Minister feared there were large files on them or that the service wouldn't help. Instead they received briefings on the members of their party who were actually members of Militant Tendency, working for Russia or otherwise seeking to undermine democracy in the UK.
Compared to the FBI during the same period they were paragons of virtue. MI5 wasn't, and isn't perfect, but replacing a system of internal morality with outside laws and placement can easily corrupt.
It's not in the name of a perfect society... there is simply huge money in fear.
Effective steganography could hide the fact that you're using encryption at all, and could make traffic analysis[2] more difficult. Widespread use of effective steganography could make wholesale digital spying a lot more difficult.
The use of anonymous remailers[3] also needs to become much more popular; in particular, the mixminion[4] remailer, which was designed to address many weaknesses in earlier remailers.
Traditionally much more difficult, but as or even more important than the technological solutions mentioned above, is educating the general public about the need for and value of privacy enhancing technologies. Fortunately, the massive publicity around the recent spying scandals is doing a lot of the hard work for us in this area.
Finally, there's a great need for educating the general public on how to use these privacy enhancing technologies properly, and making them easier to use. There's still a lot to be done on this front, but the challenges are not insurmountable, and they are getting easier as the general public becomes more computer literate and more privacy- and security-conscious.
[1] - https://en.wikipedia.org/wiki/Steganography
[2] - https://en.wikipedia.org/wiki/Traffic_analysis
It makes you wonder what the actual point to all of this surveillance is. Regardless, I whole-heartedly agree with you that steganography should be prioritized much higher than crypto.
Since you can't explain it in those exact terms to the masses without causing an outrage, you have to tell them it's for their own safety and to protect them from brown skinned tunic-wearing AK47-waving freedom-hating lunatics.
Ten years ago, if something weird happened most of us would say, "Gee, I wish I'd brought a camera!".
Today, if something weird happens most of us would say, "Gee, I wish I'd had my phone out of my pocket when that happened!".
A couple of years from now, we'll just take for granted that we're recording everything around us all the time.
Humans love sharing stories, but we're obsessed with our own credibility. We could entertain others with a well spun tale far better than with a cellphone snap-shot, but we still strive to record that snap-shot so we won't need to tell the story and risk being doubted. In the process, we are eliminating the mutability of truth and perspective in human experience in favor of cold, hard bits that tell only the objective truth, and will do so perfectly for as long as they are stored.
While we worry about keeping the secrets we have, we're generating new secrets at an exponentially increasing rate. Secrets are necessarily losing their impact as a result. A nude photo was once a scandal. A hardcore pornographic movie, deliberately leaked, is now cheap promotion. Here in Canada, the mayor of a major city was allegedly caught doing crack on tape. People weren't sure whether to care or not, and it mostly came down to whether or not they already liked him. Society is changing to accommodate the reduction of personal privacy by becoming less responsive to scandal.
This is why the use of encryption has such difficulty overcoming sloth and why there is so little rage among the U.S. public about their loss of privacy. Compared to the indignities their pop-idols are subjected to, the snooping of the NSA seems benign. The government would have to start placing cameras in their bathrooms and bedrooms before they'd be properly outraged, and in a decade or two even that may be tolerable! However, even as some types of information lose their ability to wound, the type of information the government seeks will still serve as an instrument of control.
It's a bit of a conundrum. How do we make people care more about privacy when society is busy transforming itself to care less? I don't think the cypherpunk movement has a hope of combating this trend. Whatever it does for the good of society will have to be done in spite of society rather than with it's willing participation.
Also, yeah, humans like to share stuff, but not with enemies or whom they think is not worth sharing (like corrupted government, etc).
One interesting data point is a snapchat. It enables private picture sharing and it's pretty popular.
Another private messaging app talks about protecting the privacy and safety of your children, I can see the app becoming popular.
Maybe by building this kinds of networks we can offer more private channels. But not sure this can lead to anti government encryption because :
A. People are interested in protection from terrorism.
B. There are plenty of ways for government to subvert this kind of apps, especially since they are owned by commercial entities.
And maybe that's a good thing, in a world where terrorists will probably have increasing technological capabilities to cause damage.
I'm not sure that society is transforming itself. I feel like there are certain corporate actors that are extremely influential in this area and should either review their business ethics or prepare to be regulated out of their present mode of existence.
I don't think the cypherpunk movement has a hope of combating this trend.
Perhaps you are right, but defeatism and apathy is easy. Why shouldn't people who dislike the negative aspects of society's present direction challenge themselves? As the old Margaret Mead saying goes, "Never doubt that a small, group of thoughtful, committed citizens can change the world. Indeed, it is the only thing that ever has."
Whatever it does for the good of society will have to be done in spite of society rather than with it's willing participation.
Will is a funny one. If you take the oft-quoted computational sphere view on truths, cultimating in self-evidence, then it may be fair to say that such truths entering the stage of self-evidence are indeed accepted by society with it's willing participation.
We won the important battle getting the regulations largely out of the way. If we can't achieve pervasive always on encryption— and at least kill passive dragnet content collection dead— then can we achieve anything at all?
It always reminds me of a shocking fact in Dutch history: In the Netherlands, the Germans managed to exterminate a relatively large proportion of the Jews. The main reason was that before the war, the Dutch authorities had required citizens to register their religion so that church taxes could be distributed among the various religious organizations (https://en.wikipedia.org/wiki/Dutch_resistance)
And this looks so quaint now. We can only imagine what potentially damning information a totalitarian government can now find about every citizen retroactively.
Digital networks are increasingly an intermediate in every little communication and transaction between people. And with the internet of things, in everything we do, in the future maybe even inside our bodies (what's after Google Glass?).
We really need a way to prevent rampant data collection, otherwise the internet is a large threat to civilization. I didn't go into technology to facilitate some 1984-ish world government :(
If the government has a very big disk, then let's fill that very big disk with tons of crap.
NSA: "We're at 95% utilization of our storage. We better delete some old stuff so we have room for new data."
-- OR --
NSA: "Hey Congress, encryption usage has skyrocketed! We need more money to buy more storage to save all this encrypted data we're capturing!"
"If you lose control of your private keys, no previous conversation is compromised."
There's no obvious getting started guide, no plain English explanation stating that Pidgin must be installed first, nothing about configuring for first use, and nothing about starting a verified conversation.
Given that I don't see that as being feasible we should ask ourselves instead what can be done to avoid a homicidal state, even under the assumption that they have more computing power available than in your iPhone.
The design of the network has a role to play. Is it possible to design a network that doesn't expose where information is flowing, or better yet, doesn't even need to know where information is flowing (it can't leak what it doesn't know)? Such a network would presumably not require an address space.
Freenet does something like this, exchanging messages by a process akin to a dead drop and restricting each node's view of the network to its immediate neighbours. I'm thinking something like Freenet, but operating as a physical network rather than an overlay network. Does such a thing already exist?
I don't think that, in its current form, it is scalable by any means. I do think that it's a good start, however.
Post encrypted messages to Usenet; since anyone can receive them, there is no need for a destination address. Post the messages through anonymous remailers (mix-nets) if you want to avoid revealing that you sent them.
This problem was solved a long time ago.
Basically, there is a trend. Technology liberates "information" by improving access to it. But the same forces also work on aggregating information. Information is not just what the government is doing. It's also what you are doing.
When we talk about governments trying harder to maintain their secrets or record companies trying to maintain their copyrights, it seems like they are fighting a lost cause. You can't fight the trend. copyright is meaningless in a world of digital copies. Information gets out. It gets aggregated. Is that any different from these
Same force only this time we don't like the result.
So it's not governments who try harder to maintain their secrets, it's you (or us or whoever).
Just for the fun of it: take a recent pandora related artist-bashing thread, look for the "too late, digital wants to be free" comments and apply them to a scenario where we not talking about sound waves but phone metadata.
Nice ending, a call to action and all that. Quick quiz then - what do fellow HN'ers see as some of the greatest work still to come from a cypherpunk-like movement?
This is not yet a solved problem, because now I can do that only with someone who is able and is willing to install PGP or other tools - a very limited number of people. That would be quite an achievement.
It sure would be nice if some major internet service offered a PKI-like service.
PKI offered by a central party is not really any different to X.509 CA's today.
The same thing could be done with GPG, via identity validation (jumping through whichever hoops are required to link people's claimed 'real' world identities with their keys; probably checking documentation and then signing a key). However, that's probably best achieved via some decentralized method rather than trusting a centralized corporate intermediary as per X.509 CA's.
Convenient and standard way to cryptographically identify myself across different mediums.
Convenient variants of communication mediums such as chat rooms and forums that do not rely on or can be controlled by any one third-party server.
If you are a moderately advanced user, then you can start using such methods right now. While no method is "perfect", they do exist.
Because you're advanced, you do not need to wait for Apple, Google, Microsoft, etc. to introduce them to you in their products and services.
Until these methods become popular beyond only advanced users, there will be a tradeoff in "convenience".
"Engineering" by nature involves tradeoffs. I think (and again, this is only my opinion) you have to decide what is more important to you and better in the lng run for everyone using computers: a. "convenience" or b. what is by advanced users perceived as "the smarter way" (for lack of a better phrase).
The large monopolies mentioned have set their focus not on the advanced user but on the user who purportedly values "convenience" (a subjective definition) above all else. They make guesses about what things might become popular and they make assumptions about what their end users want. The future of computers is always uncertain. These companies will react to what users are doing.
If you want the companies that provide "convenience" to redirect their focus toward what you believe is "the smarter way" then I think you must lead by example. Start using the methods you prefer, even when it is less convenient than not using them.
But we should be careful to distinguish technologies aimed at home users versus those aimed at the enterprise. Unlike the consumers they serve, US corporations are allowed and encouraged to secure their communications and the storage of their information. What technologies might be useful to them in this regard?
I also believe that when any software or system reaches a sufficiently large userbase, large companies will be soon to follow - whether their interest is in adopting the software/system for their own internal use or for some other reason, e.g. developing and marketing it themselves, under their own brand perhaps, to consumers. Software user mindshare has inherent economic value[1], even if the software users are attracted to is developed and distributed "for free" and even if it begins life with a cryptic command line interface.
1. Just as Microsoft. They will always react to whatever becomes popular among software users. Always. Even when it costs them milions with little hope of ROI.
- usable distributed social network and search engine which would not store and sell my personal info to marketing companies
- strong encryption integrated in webbrowsers and e-mail clients and enabled and used by default.
- maybe more widespread link-level enryption (something like IPSec)
Its like saying in the 1950-s - if we ship enough weapons to the MLK supporters they will get their civil rights. Maybe, maybe not. What we will have for sure is more volatile and bloody situation.
Cryptography cannot be stable response to a surveillance/government overreach state. It just creates an arm race in which the government still has the power to beat you up to a pulp on whim. With a robot(wait 5 years).
It's the second amendment fallacy - enough technology in the hands of the people can stop the government.
By encrypting everything you just open the door for arbitrary enforcement on various laws.
There is some math proof that you can always encrypt more than someone can decrypt, thus if everyone used crypto no government would be able to decrypt everything.
More to the point, encryption isn't a "weapon" in this situation, it's the goal. If people are able to use encryption that can be trusted, the people have means to the basic right of privacy when they wish for it.
The majority of people who receive such notices hand over their decryption keys. Because the UK requires such notices only be made after consulting with specialists - it isn't like some random cop makes the requirement on their own. Those specialists can determine things like the likelihood of the "I forgot" defence working.
It should be fairly easy to come up with scenarios where claiming a forgotten password is unlikely. Especially if it is a case of the key being used regularly, for instance whole drive encryption, or one key for all email encryption. Then they're not claiming they forgot the key at some point - they're claiming they forgot it at the very moment the police came knocking. Because otherwise they'd have to claim they've been sitting on a bricked computer, or unusable email account. Which becomes even harder if you can show emails having been sent from that account up until a certain point in time.
Remember criminals tend not to be the smartest cookies running state of the art encryption with deniable characteristics etc.