How to Remain Secure Against the NSA
schneier.com
schneier.com
Given the NSA's extensive tapping of key fiber lines, we should assume they can actually observe the necessary traffic.
From the paper: "A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary." --- Tor: The Second Generation Onion Router [0]
[0]https://svn.torproject.org/svn/projects/design-paper/tor-des...
So to the NSA, Tor is probably a flag that you might have something to hide. They are probably more likely to look at it than normal traffic.
Put another way, hide in the network should mean hide in the majority of traffic, not some small subset that partially self selects for doing suspicious things.
From my days working at a defence contractor: you should NEVER take security advice from one person.
But then, if you look at it, probably nothing is 100% secure ... not even SSL perhaps, but we still use it. I think what he means to say is that the technologies we use to keep us secure may not be 100% foolproof, but still using a HTTPS connection instead of plain-HTTP is better. Of course, this depends on who your adversary is.
In this case, I agree with you -- he should have mentioned this.
Not that this is an easy problem, but it needs to be seriously addressed.
He also points to what part technology can play in shutting down mass surveillance: If you blind enough of the dragnet surveillance that high value targets can't be selected, the whole structure loses effectiveness.
Which is what I've been thinking about. E.g. maintain constant streams of apparently random data traveling hither and yon.
Problems:
Data caps, especially mobile ones. Could be mitigated by keeping the total bandwidth really low, and "constant" could be "1 packet per N seconds".
Without something like a mesh network topology (or perhaps something like TOR, which I haven't studied), you gain nothing, and there's a high value on compromising nodes in-between endpoints. And at least early on, simply being participant marks you. Contra-TOR, I'm just thinking about basic communications, e.g. email and IM, I'm willing to give up low latencies.
And my major point, this all boils down to a political problem: what would be the national security state's response to losing so much capability, justification for budgets, people, facilities, etc.? Nothing good unless we win the political battle, with a big loss resulting in it getting outlawed.
Note my analysis is in the context of an expectation of serious ... messiness when the "free ice cream" runs out, when one way or another the US Federal government can no longer run an effective annual trillion dollar deficit.
And I keep coming back to some of your earliest words on this, in reference to comments by RMS (https://news.ycombinator.com/item?id=5840210):
"Until the early 80's there was no widespread use of mobile telephony and internet. It's not crazy to think that the surveillance state has ruined the internet and that there is more value in avoiding it than in using it. Maybe it's over.
I can recall some TI managers looking at Stallman like he had two heads when he told them, over 25 years ago, that developers would make money with free and open software.
The car industry is facing a generation of buyer who find cars a burden. It's crazy to think that we can't screw this up."
In practical terms, how can the NSA classify your traffic as that of a US citizen and discard it if they can't read it?
The idea of 100% privacy on the web is just not feasible for most people, most of the time.