HNHacker News
TopNewBestAskShowJobs

dane-pgp

8,830 karma · joined August 8, 2016

submissionscomments
dane-pgp··on Italian privacy regulator bans ChatGPT
> age verification for the users.

Do you need to verify your age to perform a Google search?

I think "age verification" is just another "think of the children" ploy to force all websites to check their users' government IDs (starting with sites run by people whose politics are different from those of the government that's enacting the ploy).

dane-pgp··on Italian privacy regulator bans ChatGPT
> children can not enter a library and get Adult books

Is that true? Can a 13 year old child in Italy not walk into their local town library and pick a novel off the shelf and start reading all sorts of violent and explicit narratives? Not to mention all the medical textbooks, and books containing images of artistic works depicting undressed humans.

dane-pgp··on Self-Service SBOMs
I'm glad you agree that knowing someone's name, age, and address doesn't prove their trustworthiness, because I don't want trust decisions to be dependent on threats of state-backed violence or mob vigilantism.

It is possible to build up trust in an identity based on how long that identity has been used, and the "transitivity of trust" principle. So you wouldn't trust someone because "John sounds like a trustworthy name", and instead you'd look at how long the author's key had been associated with the library, and whether their key had previously been endorsed on other people's projects (for example having their PRs reviewed and accepted).

Admittedly this introduces a new danger that the social graphs start to become very dangerous honeypots of metadata, especially if we start letting employers vouch for their employees, but the ultimate goal here should be to use something like Verifiable Credentials with zero knowledge proofs, which will allow very strong probabilistic arguments to be made about whether an author (and all the code reviewers) have suddenly gone rogue and decided to burn their hard-earned reputations.

dane-pgp··on Self-Service SBOMs
The first step in solving the trust problem is solving the identity problem. At the very least, once you've got cryptographic identities for entities involved in your supply chain, you can use a TOFU policy and check whenever an identity changes.

Simple operations like rotating a key shouldn't trigger any security warnings, as long as they new key is signed by the old one, and even adding new people to a team should happen seamlessly if (a majority of) the existing team members approve that new identity being added.

Of course it doesn't solve key compromise, or someone selling their keys to someone else, but with long-lived (even pseudonymous) identities, it becomes possible to reason about the trust level of packages just based on how long an identity has been used without being compromised.

No system is perfect, and there's still a long way to go, but the existing systems make the remaining problems more tractable, and already increase the cost for attackers, which should reduce attacks.

dane-pgp··on Elon Musk and others call for pause on AI citing ‘profound risks to society’
Isn't this just like the situation in 2014 where academics were arguing that 'gain-of-function' experiments were dangerous[0], but big government labs and pharma companies were too excited about the research and treatments they could produce?

[0] https://www.cidrap.umn.edu/avian-influenza-bird-flu/commenta...

dane-pgp··on We need better support for SSH host certificates
> Sure and they'll be quickly mistrusted. You can't really revoke DNNSEC trust of an ccTLD operator.

But you don't have to, because the blast radius is so much smaller, and the incentives are aligned better. The reason why CAs require such extreme punishment for misbehaviour is that one bad CA can break the trust for every site on the web.

If a country decided to invalidate the security of (predominantly) its own citizens' websites then that wouldn't harm anyone who used any of the other ccTLDs in the world (not to mention the hundreds of gTLDs).

Also, I think you are over-estimating the ease with which a CA can be "quickly mistrusted". What is the record for how quickly a CA has been taken out of browsers' certificate stores, measured from the time of their first misissuance?

And I would argue that revoking CA trust to Let's Encrypt / IdenTrust would be much more disruptive than revoking a single ccTLD operator, since that would mean breaking most sites on the web. So DNSSEC is actually better in terms of the "too big to fail" problem.

> This is bypassing a dangerous design, at best.

But that's my point; DNSSEC lets you bypass the danger of a rogue issuer, by swapping to an alternate domain in the worst case, whereas with CAs you have to hope that the rogue issuer doesn't decide to target you, and wait for the bureaucratic and software update processes to remove that CA from all your users' browsers.

There are definitely limitations to the DNSSEC system as currently deployed, just as there were with the web PKI system before browsers started to patch all the holes in that, but I don't know why my position on this technical question is so controversial. Nevertheless, I really appreciate you taking the time to offer intelligent counter-arguments in your comment, thank you.

dane-pgp··on We need better support for SSH host certificates
> DNSSEC, ... still does not work in most TLD and registers.

I'd be interested to know where you get your data from. By my count, there are 142 ccTLDs that support it and 106 that don't, out of 248 ccTLDs.[0]

That's already more than half, but if you include the gTLDs then the number of TLDs signed in the DNS root goes up to 92% according to the best data I can find.[1]

[0] https://www.statdns.com/cctlds/

[1] http://rick.eng.br/dnssecstat/

dane-pgp··on We need better support for SSH host certificates
Trusting the country that operates the ccTLD of your website is a much better situation than having to trust all the countries that have CAs operate in them.

A malicious CA in one country can issue a fraudulent certificate for a site in another country, whereas the people operating .ru can't affect the records for example.us so the blast radius is limited by design.

Moreover, no one is required to use a ccTLD, and there are hundreds of gTLDs to choose from, or you could even run one yourself if necessary.

dane-pgp··on We need better support for SSH host certificates
People used HTTPS before there were Certificate Transparency logs, so there's no reason why those couldn't be run for DNSSEC too.

https://datatracker.ietf.org/doc/html/draft-zhang-trans-ct-d...

https://www.huque.com/2014/07/30/dnssec-key-trans.html

https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-deleg...

dane-pgp··on Robots have been about to take all the jobs for 100 years
Do you think that the state shouldn't be allowed to kill unwanted Down syndrome babies after they are born because "that's eugenics"?

What about Down syndrome adults, who are reliant on state benefits?

In case it's not clear, I don't support the killing of disabled people at any age, but I understand that different people approach these questions from a different set of assumptions.

My point is that adding scare quotes around "that's eugenics" doesn't stop it from being an accurate description, so your question is not the gotcha you might think it is.

dane-pgp··on Domain Names as Handles in Bluesky
> If something else with the right properties comes along then we'll adopt it

Have you looked at DID-SIOP?[0] It's based on the "Self-Issued OpenID Provider" extension[1] to OpenID Connect, to make it easier for existing OIDC relying parties to support those identities.

[0] https://www.didsiop.org/

[1] https://openid.net/specs/openid-connect-self-issued-v2-1_0.h...

dane-pgp··on Revolutionary Stroke Treatment Will Save Millions of Lives
(Congrats on item ID number 35 million, by the way. It's kind of poetic that your comment has the string "000" in it.)
dane-pgp··on Germany opposes EU plans for client-side scanning
"Controlling the output of generative AI technology is simple. We will create context for its use. First we will censor any use related to social taboos. Then we will censor anything else that we desire. If anyone complains, we will accuse them of wanting to engage in or promote social taboos."

https://www.youtube.com/watch?v=-gGLvg0n-uY

dane-pgp··on Germany opposes EU plans for client-side scanning
> Are they going to outlaw electronics knowledge?

No, but they might ban "bespoke" devices.[0] Maybe you're smart and brave enough to build and maintain your own illegal device, but good luck trying to persuade other people to do the same so that you can communicate with them securely online. Also, the government might force ISPs to block access to devices that don't pass remote attestation checks.

[0] https://cyberlaw.stanford.edu/blog/2023/02/my-comment-uk-gov...

dane-pgp··on Germany opposes EU plans for client-side scanning
Except the EU is pushing for chat client interoperability[0], and side-loading[1], so everyone should be able to switch to open source apps that don't have this Kafkaesque "your guilt is decided by the AI" feature.

[0] https://matrix.org/blog/2022/03/25/interoperability-without-...

[1] https://goodereader.com/blog/tablet-slates/apple-will-allow-...

dane-pgp··on Germany opposes EU plans for client-side scanning
> the leading cause of death for children under 18 is car crashes.

Are you sure about that? In the US, firearm-related injuries became the leading cause of death among people aged 1 to 19.

https://www.nejm.org/doi/full/10.1056/nejmc2201761

dane-pgp··on Comment on the UK Gov Proposal to Ban “Bespoke” “Sophisticated” Encrypted Phones
The reason why DRM has failed in the past is that it only takes one person to crack the DRM on their own device, and then they have an unencumbered digital file which can be copied and distributed freely.

Applying DRM to kernels and applications rather than to media files is completely different. If someone wants to have an E2E encrypted conversation, not only do they have to have jailbroken their own device by extracting the secret keys from inside its processor (using an electron microscope, perhaps) but their conversation partner has to have done the same to their own device.

Even if a few brave and well-resourced journalists/lawyers/activists managed to do this among themselves, they would quickly be exposed by traffic analysis, allowing the government to simultaneously arrest all of them and use their devices as evidence.

dane-pgp··on Signal says it'll shut down in UK if Online Safety Bill approved
It was a good discussion, and I'm glad we've both had a chance to give our points of view clearly. :-)

Thanks for discussing respectfully, and for the work it sounds like you are doing to improve standards in academia.

dane-pgp··on Comment on the UK Gov Proposal to Ban “Bespoke” “Sophisticated” Encrypted Phones
> Even with attestation you could just daisy chain and use the attesting device as a proxy.

But you'd need the attested device to run the proxy server software, which would obviously not be allowed in the app store, and would be blocked by the gatekeeper daemon or the OS-level firewall. Well, proxy software would be allowed, but it would have to perform its own attestation checks on the devices it proxies for.

> Not to mentioned the billion of internet enabled devices that would never support it

The billion internet enabled devices would be allowed onto a special "safe" segment of the internet, which companies could apply to add their static IPs to. So your internet connected fridge could still phone home, but the manufacturer would take liability for any data that a rooted fridge managed to send out to the internet.

There might still be millions of old devices that don't support TPMs and don't have manufacturers willing to apply to have their IPs whitelisted, but the government will say that kicking these insecure unpatched devices off their internet would be a huge win for cybersecurity. Making people buy a whole load of new devices would probably also give a temporary boost to the economy too.

dane-pgp··on Signal says it'll shut down in UK if Online Safety Bill approved
> The absolute size of the risk is what's relevant.

But you weren't talking about the absolute size, you said "a very small problem compared to things like" (my emphasis). Please at least admit you were wrong about that.

In any case, as an absolute number, even one school shooting is too many, and if the US government can devote resources and legislation to reducing traffic accidents and drug overdoses harming children, then there's no reason why it can't do the same to reduce gun deaths, like every other civilized country does.

> Like everywhere in the United states, it's young Black men killing other young Black men

You may be surprised to learn[0] that "Black men and boys ages 15 to 34 ... were among 37% of gun homicides" in 2019, so most killings are not like what you describe at all.

[0] https://www.usatoday.com/story/news/health/2021/02/23/young-...

dane-pgp··on Signal says it'll shut down in UK if Online Safety Bill approved
Thanks for the link. That does seem to be a more thorough analysis than the one in Scientific American, although the latter was good at linking through to the actual studies, so you didn't have to trust the writer or editor of the article.

The RAND analysis doesn't appear to be as equivocal as you suggest though. It says that there are 3 types of laws which have the strongest level of scientific support for their success, but other laws have weaker support, which doesn't mean they aren't effective. Let me highlight two quotes:

"Importantly, however, where we conclude that evidence for a policy is weak, that does not mean that the policy is ineffective; the policy itself might well be quite effective."

"Still, even relatively small effects of gun policies are important to the people and communities affected."

So while it's possible that there are a lot of ineffective laws being proposed, that's far from being evidence that no laws are effective, and it might even be evidence that the problem lies with the Constitution itself (which is another type of law which could be changed).

I wonder, though, what it would take for me to convince you of anything, since you could just dismiss all scientific research as "coming from academia" and therefore tainted by political views that you don't like. Perhaps if the gun lobby commissioned their own researchers to produce a report, you would find that sufficiently neutral, but I won't go looking for such a report.

One area where we might agree, though, is in disapproving of immature ad hominem arguments, so perhaps we just need to make sure that we're both extending that disapproval to mature ad hominem arguments as well. ;-)

dane-pgp··on Comment on the UK Gov Proposal to Ban “Bespoke” “Sophisticated” Encrypted Phones
Presumably mobile networks will be required to only grant internet service to phones that were bought in the UK (or that have been registered with a foreign network for more than N months).

I'm not sure how easy it is for networks to filter by IMEI (and presumably there would have to be a database for recording which IMEIs were sold with UK-compliant OSes) but eventually there would be a system which covered all access to the internet, not just from phones.

This means broadband ISPs doing a Remote Attestation check before routing any other packets from your device. A proof of concept for this has been implemented for some online games already.[0]

[0] https://arstechnica.com/gaming/2021/09/riot-games-anti-cheat...

dane-pgp··on Comment on the UK Gov Proposal to Ban “Bespoke” “Sophisticated” Encrypted Phones
There are some good arguments in here, but I think it misses the broader picture.

Clearly someone at GCHQ has told the UK government that if they want to ban secure apps like Signal, they first need to get the apps taken out of the app stores, then they need to mandate that phone OSes don't allow side-loading, then finally they need to ban "bespoke" phones, i.e. ones that allow general purpose computing.

Not only Stallman[0], but Doctorow[1] was right too.

After implementing this, they'll do the same for desktops, using something like Apple's Gatekeeper software[2]. Linux distros will gain support for this using "Secure Boot" and something like systemd-censord, which Microsoft might get Lennart to implement for them.

[0] https://www.gnu.org/philosophy/right-to-read.en.html

[1] https://boingboing.net/2012/01/10/lockdown.html

[2] https://support.apple.com/en-gb/guide/security/sec5599b66df/...

dane-pgp··on Signal says it'll shut down in UK if Online Safety Bill approved
> Shootings ... are a very small problem compared to things like ... car crashes, and tiktok.

That's an interesting claim. Perhaps you didn't know that "Firearms now exceed motor vehicle crashes as the leading cause of injury-related death for people ages one to 24" according to [1].

I suppose that statistic might include gun suicides and gun accidents, which (under an extremely contrived definition) don't count as "shootings", but that still misses the point that sensible governments have successfully reduced car accident deaths by tightening regulations related to vehicle ownership and licensing, whereas America is notably bad at doing so for guns, and is paying the price for that failure with the blood of its children.

If you could provide a statistic for the number of annual US deaths due to TikTok, I'd be interested to compare that to shooting deaths too.

[1] https://www.scientificamerican.com/article/guns-now-kill-mor...

dane-pgp··on Signal says it'll shut down in UK if Online Safety Bill approved
> Gun laws don't work. The best available work on this suggests a modest decrease in murder rates at best.

Feel free to share a link to the best available work. Please also read this, though:

https://www.scientificamerican.com/article/the-science-is-cl...

dane-pgp··on Signal says it'll shut down in UK if Online Safety Bill approved
> Stop electing the people who follow them.

To be fair, most voters in the UK didn't vote for the current government.

https://en.wikipedia.org/wiki/2019_United_Kingdom_general_el...

dane-pgp··on Signal says it'll shut down in UK if Online Safety Bill approved
> hereditary peers were abolished in 1999.

Mostly abolished.

https://en.wikipedia.org/wiki/By-elections_to_the_House_of_L...

dane-pgp··on Signal says it'll shut down in UK if Online Safety Bill approved
> the last time we had a referendum in UK the people didn't vote for the option they were meant to

You mean "the people believed false promises and voted for something they inevitably regretted".

https://qz.com/brexit-polls-support-popularity-eu-uk-1849952...

dane-pgp··on Reddit co-founder’s quest for unseizable property
Did you miss where I said "in undisclosed locations in different jurisdictions"?

The other seven people would be known only by their public key, and you'd make contact with them through some onion-routed service. You'd never see their face, and all you'd know is that they were based in a different jurisdiction, where presumably the authorities that are after you don't have strong judicial connections.

If your threat model includes an adversary that is willing and able to kidnap and torture 5 innocent people from different countries around the world in order to get to you, then you're literally OBL or the leader of IS, in which case you have bigger problems than securing your passwords.

dane-pgp··on Reddit co-founder’s quest for unseizable property
> The best way to get someone's password isn't phishing, it's threatening to hit them in the head with a wrench.

But what if you need to combine that person's password with passwords that are in the heads of 5 out of 7 other people, who are all in undisclosed locations in different jurisdictions?

Perhaps a sufficiently resourced adversary could create a realtime deepfake of you, to attend the property transfer online digital ceremony, but the adversary who imprisoned you would also have to convince all of your friends that you had gone on holiday so that they didn't raise the alarm to warn those keyholders that you are under duress.

Page 1 of 34Next →