Snowden’s First Move Against the NSA Was a Party in Hawaii
wired.com
wired.com
I don't see why, given that educating the US public about security best practices perfectly aligns with their mission. Back in 2001 they even released the first version of SELinux:
http://www.nsa.gov/public_info/press_room/2001/se-linux.shtm...
It is only in the post 9/11 world that we somehow believe a CryptoParty is to the NSA what the tea party was to the british.
Steven Levy's book goes into pretty good detail about this: http://www.amazon.com/Crypto-Rebels-Government-Privacy-Digit...
At the time the NSA was not pleased about the release of DES and was also very concerned about PGP. There were attempts at laws requiring key escrow available to the NSA among other restrictions on foreign key size etc. It wasn't really until the late nineties that this stopped. For a time they would probably have liked to ban all citizen encryption all together, but it became obvious that this couldn't be enforced (and it's necessary for things like e-commerce).
A lot of early crypto based patents and research were retroactively classified - there was a big historical legal battle to get things where they are today.
No, the actual words are just "That was a huge risk for him to teach a crypto party while he was working for the NSA." It was a risk for him, the kind of like organizing "don't drink sugar water" event while working for Coca Cola which has effectively its own police, and that at the time the employee already downloaded the secrets from the Coca Cola's secure network and he even contacted some journalists to give them those.
Link with more info?
Snowden organized a "let's use Tor" event after he apparently already downloaded some secret documents and contacted a journalist. And the top commenter disputes the claim "That was a huge risk for him to teach a crypto party while he was working for the NSA" falsely claiming that the article "keeps saying in many words that the NSA would put Snowden on a boat to gitmo if they found out he hosted a CryptoParty." It doesn't. But I also claim that it was a potential risk for him as there was some chance that somebody in charge for security starts to investigate what he does or already did.
And if I understood other sources, at that time Snowden actually worked for a private company (Booz Allen Hamilton Inc.)
http://online.wsj.com/news/articles/SB1000142405270230462680...
which had the contracts with NSA. Still, apparently exactly working in that company gave him access to the secret documents he wanted to take.
I suspect how well it aligns depends on which part of the large and complex organisation that is the NSA any given individual works in.
If it is seen as subversive to a few of the many within the NSA I doubt they'd do a straw poll across the organisation as a whole to see how they address such an issue.
These systems come into conflict a lot because it has become nearly impossible to secure domestic systems without also securing foreign systems.
For a while, NSA appeared to favor securing domestic systems when the two came into conflict. Thus events like the withdrawal of SHA-0 and its strengthening and re-release as SHA-1.
Now, it appears to have swung back in the other direction, and pretty hard. They're keeping vulnerabilities secret and even deliberately introducing weaknesses in order to make their spying mission easier.
Educating the public about computer security aligns with one of their missions, and not the one they appear to really care about now.
“If I’d known it was someone from the NSA, I’d have gone and shot myself,” [Wolf] says.
(and, ultimately, those are still the big threats today; NSA is a more interesting threat, and one where policy has some chance of working, but the ambient criminal threat is more commonly encountered.)
I think NSA probably doesn't want their people giving even pro-NSA talks in public without a lot of screening and approval, though. At most they'd have reviewed/pulled his clearance and fired him, not Gitmo'd.
He is a hero and has brought out a (long due and) renewed interest in privacy and security. We'll all be the better for it in the coming years.
Indeed.
This sounds straight out of The Onion. "Controversial figure found to be working for the Chinese, the Russians, Al-Qaeda, the KKK and Nazi Germany at the same time"
Here is the article mentioning this claim: http://webcache.googleusercontent.com/search?q=cache:1cwq_2e...
[1] https://en.wikipedia.org/wiki/South_China_Morning_Post#Alleg...
I found this quite interesting. I wonder how many more of these events are happening around the world. They could teach how to use truecrypt, how to turn on two factor authentication for the popular services that use it and what it is, good password policies, and what https means for browsing the internet securely.
Edit: I found this: https://www.cryptoparty.in/
There's always this delicate thing of having a balance between being interesting to local hackers, vs. being understandable by laypeople. We veered towards the former, and it was great fun, but it would be very beneficial to try and be more welcoming towards the general crowd, too. It's not always easy when introducing complex technologies - I try to avoid using leaky metaphors, but sometimes that's not possible.
So if you're hosting one, make sure to announce it to various sites.
What a link bait title :(
Why isn't he railing against Russia's SORM-1, SORM-2, and SORM-3? My concern here is that his disclosures won't change business as usual and will provide political cover for nations with just as bad, if not worse, human rights violations because the US's critics can just point to Snowden and deflect the conversation, which is EXACTLY what's happening now.
http://www.theguardian.com/commentisfree/2014/apr/18/vladimi...
As for why he isn't railing against other policies I suspect he recognizes how lucky he is to not be in the position Bradley Manning is in even after leaking so much. Snowden has done enough good for one lifetime anyway.
However, perhaps Snowden's biggest achievement is to bring security to the forefront of everything and create a wave of new half-baked "security" products which want to ride the wave.
The notion of security is relative and the weakest link is always us. A small overlook or an error is all it takes...
That means truecrypt all the drives, https all the websites, pgp all the emails.
In short, If you have an option between a secure and nonsecure (but slightly more difficult) way of doing something, always pick the secure one.
The irony is so thick you could cut it with a knife.
Serious question, if we do round-up the NSA, who gets in trouble and who doesn't? Just the leaders? Are we also absolving Congress and POTUS? Please explain.
I'm all for voting out current office-holders, but in their defense: the NSA not only lied to Congress, but spied on Congress so they could see how well their lies were playing.