HNHacker News
TopNewBestAskShowJobs

krek

74 karma · joined June 11, 2013

submissionscomments
krek··on You can't control the internet. GCHQ needs to grow up and accept it
It's not about pedophiles or catching terrorists. It's about the state having power.
krek··on Shellshock DHCP Remote Code Execution – Proof of Concept
This is best plain English explanation I've seen yet (been looking for an hour). Thanks.
krek··on I'm 25 years old and I am lost
> people have more respect for those who present themselves well

If presenting yourself well means driving a luxury car, or having an expensive home, then no, I don't respect these people more than others. There are no such 'rules of society' except for materialistic people.

krek··on True Goodbye: ‘Using TrueCrypt Is Not Secure’
Yep. And reading the pdf for phase 1 of the audit, worth about $40k, the findings didn't seem very impressive. Specifically the readability portion where they give a critique of naming conventions in the code. I could see the developers figuring for that money they could've done a lot more good with it.
krek··on Earnest – A writing tool for first drafts
Wouldn't an offline desktop version of this be better?
krek··on NSA revelations could hurt collaboration with 'betrayed' hackers
The New Yorker's Mayer is paraphrasing an anonymous source, which she then counter-points in the very next sentence of the article with a quote from NSA historian Matthew Aid, who says: “The resistance to ThinThread was just standard bureaucratic politics. ThinThread was small, cost-effective, easy to understand, and protected the identity of Americans.” [1]

That's what Binney and Drake have said all along.

[1] http://www.newyorker.com/reporting/2011/05/23/110523fa_fact_...

krek··on NSA revelations could hurt collaboration with 'betrayed' hackers
> his own "ThinThread" system was designed to do exactly that, but with better technical controls over who could view the data.

That's plainly false. His system was specifically designed to throw-out private data, that is, never to store it. There is no data to view if it's not stored. See his 29C3 technical talk where he goes over it. [1]

>The notion that Binney is a staunch opponent of PRISM-style surveillance is revisionist.

This ignores nearly everything Binney has actually said when asked about why he came forward to blow the whistle on NSA's spying activities. Also, see above.

[1] https://www.youtube.com/watch?v=XDM3MqHln8U

krek··on NSA revelations could hurt collaboration with 'betrayed' hackers
> I couldn't imagine the comments that I've seen about blacklisting former government workers and publicly shaming service men and women coming from anyone who has carried this kind of responsibility.

I think the 'activists' that were derided are also working hard in the interest of the country. As for blacklisting and shaming former servicemen, see the aforementioned Bill Binney, and Thomas Drake, former NSA workers who dedicated decades of their lives to their country, and were blacklisted and prosecuted by their own government for daring to blow the whistle about violations of the constitution and Americans' privacy rights.

krek··on NSA revelations could hurt collaboration with 'betrayed' hackers
> Yes, I do have things to back it up.

Such as? Bill Binney, having actually been one of the top mathematicians at NSA for 30 years, carries more weight than you do, unless you want to share specifics that back up the regurgitation of the "10 year ahead" phrase.

krek··on NSA revelations could hurt collaboration with 'betrayed' hackers
> NSA, which has been ~10 years ahead of private industry for the last couple decades, before which time they were even further ahead.

Do you have anything to back this up other than the old rumor that NSA (specifically their crypto) was ahead of private industry by 10 years, something even Bill Binney said is probably not accurate any more. And mind you, this old "10 year ahead" phrase was always specific about crypto, nothing else.

> In fact, I think it's likely that they're significantly smarter than any of us. Bear that in mind when you design your NSA-proof email applications.

I wouldn't bet on it. NSA and many other government agencies are full of incompetent or barely adequate people. Just look at our intelligence failures regarding terrorism and in both wars the last 10 years. NSA has a huge budget with billions of dollars to throw at their problems, so they get stuff done, sure, but smarter than private industry? Nah.

krek··on A $45 Android tablet
You shouldn't get your news from corporate media. Corporate media don't like unions because they fight for living wages which cut profits from the few who benefit from them.
krek··on [dead]
Oh ya, Mitt, the epitome of a hard worker.
krek··on About the Reuters article
> b) a 30 year old person stuck in a Russian airport who has appointed himself the ultimate arbiter of what is leakworthy and what is not, what programs are legal and good and which are illegal and evil.

No, he's not the ultimate arbiter, that's what the US government tried to be, in secret, until Snowden stepped up. And others with access are free to step up as well.

krek··on Snowden maintains NSA has access to company servers, so someone's lying
> I managed to figure out what it meant with a little background in computer and networks knowledge and no background with IC work.

We still don't know what exactly is going on, or know if direct access really exists, so this is premature.

Secondly, your earlier example of using your web browser to collect directly has nothing to do with the actual slides, which talk about getting special access from the companies, and the document includes a timeline indicating when each company finally signed on to the Prism program.

He said "direct access" and the document says "collection directly from the servers of..".

> He knew what NSA jargon meant; he knew what the slide meant.

The NSA is a huge organization with a budget of tens of billions of dollars and employs tens of thousands of people. Snowden of course does not have complete understanding of everything, nor does Keith Alexander, nor does James Clapper, the DNI who blatantly lied to congress about collecting data on millions of Americans.

Placing any kind of blame on Snowden for directly paraphrasing a NSA document makes absolutely no sense.

Edit: 'paraphase' is far too kind. It's nearly the exact words, with the addition of 'access'. That NSA has special non-public access is something even the companies admit.

krek··on Snowden maintains NSA has access to company servers, so someone's lying
> The companies themselves are still the ones who end up providing the data to NSA though

Well that's certainly what the companies are saying. Whether they are telling truth (personally I think they are) or not is something else. Snowden is definitely not the one lying about this, since at worst his interpretation was very sensible, and at best it is the very interpretation intended by the author.

krek··on Snowden maintains NSA has access to company servers, so someone's lying
Your quote is accurate, "direct access" is not verbatim. Though "collection directly" and "direct access" seem semantically the same to me in the context of the slide. [1]

The relevant slide is talking about two types of mechanisms the NSA analyst should use. The "Upstream" and "PRISM". It's within the the Prism description that the words "collection directly from the servers of.." is used. So it's not referring to raw data collection through neutral access points, as that's what the "Upstream" is. It's explicitly saying the NSA has direct access to these companies.

[1] http://i.imgur.com/kIEtXjk.jpg

krek··on Snowden maintains NSA has access to company servers, so someone's lying
How is Snowden possibly lying? He's reading verbatim from the NSA documents which use the words "direct access". Also he isn't "maintaining" this, this is part of his original interview from over a month ago.
krek··on German minister: Stop using U.S. Web services to avoid NSA spying
How can we take full responsibility for the Evo Morales incident? Do Europeans bear no responsibility for allowing their governments to be US lapdogs? As a US citizen I have to bear the responsibility both for my country and your inability to elect a government with a backbone?
krek··on In 2009, Ed Snowden said leakers “should be shot.” Then he became one
Especially not surprising because working for CIA he expected to be monitored, and it's just self preservation to publicly espouse the "correct" ideologies.
krek··on Snowden touches down in Moscow ... tweeted by Wikileaks
It already has ended with a tragedy. Our privacy rights and 4th amendment protections have been thrown out the window. The making of Snowden into a Kardashian spectacle is to distract us from this fact.
krek··on The NSA can store communications of US citizens for up to 5 years, sans warrant
I interpret it to mean that if NSA's filter catches words related to communications security then it is flagged and possibly read by an analyst. It does say the Director of the NSA has to specifically request that the communication be kept, but someone has to read it first to determine its value. So it's read and stored without a warrant. Seems like a pretty clear violation of the 4th amendment to me.
krek··on NSA veterans speak out on whistle-blower [video]
Binney didn't design the system that's currently being used, and that's his whole point. He designed a cheap way to do what the current program does but that would protect people's privacy (in part by not storing all the data that it filters). His point is that the NSA spent billions on a dragnet system that violates privacy and isn't even able to catch terrorists as well as the privacy-respecting system he designed internally for dirt cheap.
krek··on Facebook Releases Data, Including All National Security Requests
The issue to me is if the so-called "upstream" actually stores all the raw SSL data, and how fast it's decrypted. This is apart from any corporate cooperation, except for the Mark Klein AT&T splitter variety. (Unless of course Google, Facebook, etc are handing over their private SSL keys.)
krek··on PRISM fears give private search engine DuckDuckGo its best week ever
What are the odds that Google, Yahoo, et al. handed over their private keys, I wonder.
krek··on PRISM fears give private search engine DuckDuckGo its best week ever
I can't remember which interview it was, if on Democracy Now, or his MIT lecture video, but Bill Binney stated that the NSA in fact does decrypt HTTPS.
krek··on The Guardian walks back claims of direct NSA access to servers of tech companies
Yes, if you mean his blogging. That's kind of the point.
krek··on The Solitary Leaker
The problem with Brooks's arguments is that they fail as soon as you apply them to other NSA whistle blowers like Bill Binney and Tom Drake. He paints Snowden as a young, incompetent, introverted outcast who "couldn't navigate the institution of high school." That mud just doesn't stick on the others who blew the whistle for the same moral reasons as Snowden, like 40-year NSA veteran Binney.

Was Daniel Ellsberg a youthful, rebellious societal outcast, unable to navigate the country's institutions? Just someone who was eager to confront authority?