Edward Snowden: ‘They’re setting fire to the future of the Internet’
washingtonpost.com
washingtonpost.com
Edward Snowden is the gift that keeps on giving. I feel like "seven proxies" is the proof of concept for a practice that should be more common. From now on, every statement about technology, especially the intersection of technology with important issues like civil rights, should be watermarked with at least one meme or obviously absurd statement. If a reporter regurgitates the meme as fact, readers are warned about the reporter's lack of general knowledge about the subject and will be primed to read the rest of the article with a more critical eye.
[1] http://knowyourmeme.com/memes/good-luck-im-behind-7-proxies
(Actually, a good test for whether someone has A-lister perception is to see if they can see past their own prejudices.)
Because, in your words, someone should know on the face of it, that "seven proxies" is implausible? Please explain how I should know that. Would it be worse or better if it were 6 or 8? Please answer from first principles concerning network technology. (The fact that you are not accounting for the fact that there are multiple interpretations to the term "proxy" makes my eyebrows raise.)
Real-world MITM attacks involving certificate misissuance have already been caught by these means (mostly by Google, which is putting the most effort into it).
Furthermore, this wouldn't really stop a bad actor from getting a cert signed by a third CA which your browser trusts and MITMing it to you, unless you're cert pinning, which practically nobody is because it comes with a tremendous list of user experience issues.
Anyone who thought that the internet wasn't going to have state actors and control, also must think that the internet would never be important.
The people don't rule in the first world. The businesses do. So, "Democracy" is the wrong word. "Plutocracy" and "Oligarchy" are more accurate.
Even if the UK, France, Germany, etc. can somehow assume that NSA will stop (which is laughable, but let's assume it), they still will have to deal with a resurgent Russia, Iran, and China.
Whatever methods can protect them from China can protect them from NSA, and vice versa. If anything they've been trying for a long time to put up "cyber borders" but policymakers have blown it off as unnecessary when it's just a matter of cyber crime.
Now that Snowden has opened up peoples eyes to the possibilities (quite forcefully, I might add), there is now political cover to build those cyber walls, only under the guise of "blocking the NSA" instead of blocking Chinese hackers.
You're right that this has been obvious too. There are no commons that are not regulated by the nations, and militarized when and if they become a threat. Antarctica is only left alone because it's unimportant. The Arctic is a growing strategic concern, and space itself is only a step away from being militarized.
If the U.S. cannot gain strategic value from cyberspace they will certainly not leave it open as a strategic weakness dragging along a "PLEASE HACK ME" sign, and a similar calculus applies to all of the democracies. Whether it's borders, or a national Internet kill switch, or both or more I don't know, but it won't be the same as it was before.
Antarctica is protected by international treaty but nations are populating it with "research" missions so they have a presence when that treaty is renegotiated. The continent has massive untapped natural resources.
All of which really supports your larger point.
We still can't even get our coders to stop using C for security-critical code, and you could effectively throw C++ in that complaint bin too. We can't get people to implement crypto appropriately. The list goes on and on. And with cybersecurity you only have to get one thing wrong, especially on an open Internet, while the attacker gets effectively unlimited time and numbers of attempts (although they don't even need that so far, as long as 0-days can be bought off the shelf).
And all the stuff we can't do in the civilian sector, it's even harder to do right in government and military (and apparently critical industry). There's a whole host of things we can do to be better, but half the reason walls will go up is because they are so much better at dealing with novel threats than the idea of "just design and implement everything perfectly, geez".
But either way, Germany's complaint wasn't just cyberattacks. There was also data privacy, and that complaint is centered entirely around the fact that they can't control whether a German's data gets routed to France, UK, etc. even in the course of entirely .de <-> .de Internet traffic.
But the roots are already here, it's not simply a prediction. After the 2007 Russian cyberattack on Estonia, Estonia was able to adapt and recover very effectively... but they still now have a national cyberborder in place, and are just waiting to hit the button (a useful button to have right now, given the crises in the Crimea).
Ironically things like open source will only make this trend easier I think. It's not hard to imagine governments setting up things like ownCloud with a federated model, with replication channels open to friendly nations' instances of ownCloud and closed otherwise.
Hacker News has nothing to dispute here?
That means something is very, very wrong.
Many people here work at companies that are on the PRISM list, or work for core infrastructure gear makers, or telecom network operators.
Some people here work in the "security" industry, which relies on an appearance of security that can be cracked "to catch the bad guys." These people know their tools and services are also used to put dissidents in prison.
The only way forward is to make everyone secure to the highest standards, routinely, for all communications and data storage.
And many, many more work at companies that would very much like to be acquired by a company on the PRISM list.
While the video and audio feed – routed from Russia *through seven
proxy servers* – was choppy, Snowden’s message was clear.
Seems legit. (Anyone else got that reference?)We can go to sleep safe. With an eye always open.
Drink ejecting through nose.
Jesus, this whole story has made the geek world go retarded.
http://www.theguardian.com/society/2014/mar/04/un-warning-ca...
[1] https://www.incb.org/incb/en/about.html [2] http://www.ihra.net/files/2012/04/05/INCB_Briefing.pdf
A commission of ECOSOC is also responsible for the scheduling of drugs under the same treaty that set up the INCB.
"Independent" agencies are not unusual in governmental contexts. The FCC, FDA, and FTC are all prominent US examples. "Independent" doesn't mean they're not part of the government, they're just outside the direct control of other parts of the government.
Every time, for example, the FDA bans an import of <whatever>, headlines spring up both inside and outside the US about "the US" banning <whatever>, generally followed within the article by explicit explanation that it's the result of an FDA action. It is not unfair nor even misleading, the FDA is part of the US government, and on the world stage, the US is answerable for its actions.
https://en.wikipedia.org/wiki/Single_Convention_on_Narcotic_... https://en.wikipedia.org/wiki/Berne_Convention https://en.wikipedia.org/wiki/WIPO_Copyright_Treaty https://en.wikipedia.org/wiki/WIPO_Performances_and_Phonogra...
(Some people have coined the term "policy laundering" to describe creating domestic policy by agreeing to a treaty demanding it, and then pointing to the treaty obligation as a reason that the domestic policy can't be changed -- maybe even within the country whose negotiators first proposed adding it to the treaty!)
I don't think there are many treaties that require states to engage in surveillance. There are civil rights treaties that can be interpreted to restrict it. The closest I can think of is that the Chicago Convention
https://en.wikipedia.org/wiki/Convention_on_International_Ci...
says that civil air carriers must comply with immigration rules, which might be one legal basis for collecting ever more information in identity documents, and for requiring carriers to verify them and share information about travelers with states. (I guess there are similar rules in treaties about ships, too?)
As far as copyright law, the last two examples, TPP and ACTA, were both essentially negotiated in secret, by large corporate interests. After negotiating a treaty (TRIPS, say) the bueacrats get to propagate the skullduggery.
Wasn't the DMCA an example of policy laundering - raising domestic policies "up to the level required by treat"?
I think one of the big worries with "Intellectual Property" treaties is that they end up (practically) mandating deep packet inspection, which is surveillance by another name.
Maybe he thinks other governments aren't anywhere near having the capability "to do the same", depending on what "the same" is. (Most states could tap cell phone calls off the air or make domestic carriers turn over lots of data, but not tap undersea cables, and probably not extensively compromise commercial telecommunications infrastructure in other countries.)
Maybe he thinks pretty much all governments have been trying to spy on everyone they can for some time now and none of them have so far perceived significant legal, political, economic, or moral deterrents in doing so.
Personally, I think your fingerprinting example is instructive because the practices of one state do have an influence on the practices of another -- though fingerprinting is something that the general public can see directly, unlike most electronic surveillance. After all,the fingerprinting is quite overt. I take Snowden's (and Eben Moglen's) point that states and spooks have talked together for a long time about their deeply shared understanding of spying, and never thought it was necessary to tell or ask the public.
I think that's it. Clearly enough to eject drink from nose to suggest that something that is essentially a secret activity will be stopped merely because the US doesn't do it anymore.
Will point out though that in reverse maybe not as true.
In other words it's quite possible that something that you perceive someone as doing that you hadn't thought of then becomes something that you contemplate.
Let's take an example.
Red light cameras. You see it done in one city and so you say "hey we can do red light cameras".
A bit later another city (say NYC) decides to remove red light cameras (assuming they have them I'm using NYC as "well known and large" for the purposes of this example). Doesn't mean other cities will stop (once the cat is out of the bag or the genie out of the bottle etc.)
All the same, I do think it's possible for someone to take a lead in allowing their citizens privacy. And even if that isn't possible, surely there's virtue in a democratic discussion about the reasons we all have to be surveilled.
http://www.theatlantic.com/magazine/archive/2007/11/just-ask...
There's also the issue that the US government and other members of the five eyes appear to be egging each other on to ever more elaborate ways round local restrictions.
That may have been what tptacek was guffawing at. If so, it's hard to argue with him.
It is the absolute height of arrogance to assume that other nations will follow the West's lead because we're "right" or "morally superior" or any other bullshit people want to make up.
The implication is that if NSA can engage in mass surveillance, that other nations might think that's acceptable. But the implication is already proven false; NSA wasn't even the first, and the list of countries that do engage in technical surveillance is not just Russia and China.
In the end a nation will or will not use network surveillance because it does or does not help them meet their policy and strategic goals.
After all look at the Russian response to very strongly-held "norms" about the sovereignty of borders in Ukraine. Whatever rhetoric you wish to use to defend their actions, the fact is that they're stepping on one of the few clearly-drawn lines in international law. What's more, the reason that they're doing so isn't because there isn't a "norm" against this behavior, it's because they judged there will be no appreciable penalty for their action. Putin isn't "going rogue" and he's definitely not stupid.
In case you're wondering, that is where the world will be led; power politics instead of wishy-washy Western values, because power politics is what works.
I think his point, and it's an important and valid one in my opinion, is that those Americans who feel unconcerned about the violation of the rest of the world's rights can expect to see this apparatus turned against them, both by other enemy governments, and by allies in the 5-eyes spying for the NSA on demand and for their own purposes (like GCHQ attacking Google communications).
I don't think he's implying that other countries don't spy and might start (presumably this is what you think is risible), he's pointing out that thinking this mass surveillance is acceptable for others while it is unacceptable for Americans is simply naive and untenable in the world we live in. Either we are all subject to mass surveillance by various unknown state actors, or we can all push back against it for everyone, and restore the original purpose of our intel agencies - to protect the people in the countries they work for from attacks (both on life and information), a purpose which they have subverted and betrayed by becoming the agents of attack themselves, undermining crypto standards etc.
Privacy rights, like human rights, should not depend on the country you come from or where you happen to be, and I agree with his position that targeted surveillance is acceptable in some circumstances, but mass surveillance is not, whoever is doing it; it's just too dangerous.
But apparently rhetoric and posture are of great importance in geopolitics and I'm an idiot (because I'm pretty sure most of the rhetoric and posturing that happens in a geopolitical context is aimed domestically).
If only we actually obeyed it.