1. WL disclosed information to US population. 2. WL is accused of being "Non-state Hostile Intelligence Service". 3. Hostile intelligence services work for enemies. 4. US population is the enemy.
73 karma · joined December 18, 2016
1. WL disclosed information to US population. 2. WL is accused of being "Non-state Hostile Intelligence Service". 3. Hostile intelligence services work for enemies. 4. US population is the enemy.
The "fake news" meme itself is the last desperate attempt to preserve the fake news monopoly which giant publishers enjoyed for so long. There is really nothing left when this one wears out.
Before "fake news" we had massive injections of noise to drown out information, but that didn't work quite well, not in the long run.
The current trend of turning giant social platforms to Disney-like dystopias is not working well either. People are flocking back to ... web sites!
So what can we expect after "fake news" ? Probably Disneyfication of DNS, and that's where it ends.
Because audiences will shift to the lowest commeon denominator - IP addressing, as they did in the beginning (Napster, Gnutella) and still do (Bittorent, Tor).
The narrative funded through GOOGL (and its affiliate EFF) and other big platforms is that this is evil doing of big content distribution monopolies.
What is missing in this picture is that this Directive gives affordable enforcement muscle to all content producers, including the smallest ones.
This Directive is the death knell for these platforms, which peddle content produced by 'nobodies' (their users) without any remuneration. There is nothing natural, just or given about it.
- it's impossible to effectively use horn and brakes in emergencies;
- one starts to rely on the horn clearing the way instead of slowing down, which is suicidally dumb;
- horn is used after-the-fact, which needlessly raises the temperature.
The only sensible use is to alert far-away pedestrians that are obviously going to do something stupid.
If we put aside creation of unemployment, putting limits on what human drivers will be able to do, and similar dystopian outlooks, what are the benefits for the masses?
People who cannot drive will be able to use cars as people who can. Is this good? Are interesting places on the planet going to have the same fate as Internet did, when it transformed from elite audiences in 90s to tragedy of commons today?
Like all pets, they are to be kept in the appropriate place, like horses that is. Not in the living room.
Who do you think can smoother monetize your data - your local ISP or Cloudflare? Or maybe Cloudflare solemnly promised never to do it?
If an effort is to be taken, the best thing is to run your own DNS resolver that will query root servers and follow the chains directly.
"Google Workers Astonished: Found Out They Work In Capitalist System, Not Nerd Commune"
This looks more like _Lord of the Flies_ setup than like for-profit company workforce that sells 8 hours of its time in return for paycheck, with some reasonable socializing at work.
This seems to be the trend, and is by no means limited to Facebook. Providing socializing benefits (food, playground, etc.) and requiring emotional committment at work is far more sinister than it appears.
While keeping employees emotionally arrested at 12-year-old stage may extract extra sweat, the overall downside for the society is abysmal.
The actual people are not much different than anywhere else in the US. But they quickly learn to provide lip service to the official ideology, especially when seeking employment or acceptance in social media-mediated groups (and there are very few that are not.)
The real problem with computer techies is that they tend to be more sycophantic to the prevailing power than other profesions.
The SV political and ideological climate is all about pidgeonholing you into 0.01-0.3% segment ('left-handed bisexual javascript expert'), then maintaining these segments and manipulating the fractured society into neoliberal directions.
It is obvious that there is nothing that can be named as a common interest in SV: there is no such discourse. The commonality is restricted to your 0.01-0.3% segment.
You are not middle class if:
- you will lose home, car if you are out of job for 6-10 months;
- you don't take 30 days vacation a year;
- you cannot afford health services without going to debt;
- you cannot send your kids to university;
- your diet is mostly junk food because you can't afford fresh stuff.
If some of the above is true, you are poor.
"Post a selfie of feeding the hungry"
"Leftover food spotted on the corner of 5th and Lincoln"
Then sell user data to law enforcement.
This approach worked well (for some parties) in many other areas, for example in education: now the teachers are the only ones left responsible for the structuraly failing education system.
Now, if these were 1930s, with hundreds of independent auto makers, perhaps the invisible hand of the market would fix this.
The art of managing relies on the capability to get work done by all kinds of engineers. The talent is rarely universally allocated. Some very 'bright' ones will never properly finish the work. Some 'slow' engineers may have remarkable attention to details.
And monoculture is the elephant in the room most pretend not to see. The current engineering ideology (it is ideology, not technology) of sycophancy towards big and rich companies, and popular software stacks, is sickening.
Tens of millions of concurrent unrelated clients, embarrassingly parallelizable, scales linearly with number of cores, as these share nothing.
Experience after designing and deploying systems that run 100,000 transactions/sec per box: don't bother with engineers that cannot achieve proficiency in Erlang. Elixir is a crutch, and not something you want to show up with in 400 meters hurdles race. You will look pathetic.
That is the best description of philosophy I ever heard.
Yes.
An easy-to read program executing generic Feistel-net block cipher with exchangable/modular S-boxes and trapdoor functions would be great. I'm looking into something like that.
I am skeptical about open source efforts being a match for (tens of) thousands well-paid professionals working for well-funded organizations, 5 days a week, year after year. It just doesn't make sense that point efforts of few can accomplish anything sustainable and effective against such adversary. Yes, open source people are brilliant, heroic, etc. It doesn't matter. These efforts need to be distributed from dozens to tens of thousands, and that will begin to be the match for the organizations we are dealing with.
To eliminate all issues and pushbacks about basic security of home-brew crypto (although I think that in the big picture it doesn't matter - you are either targeted or they don't have resources to figure out your particular ROT-17.5), it should always be used on the top of your favorite official crypto stack. So don't worry about being inferior to AES - use AES as well if you trust it.
Home-brew crypto works. In the latest Stone's film, the whistleblower takes out flash storage hidden in Rubik' cube. It needed to work only once, for him. If it is important, people will do it.
In the big picture, we may be dealing with the elitism of brain-work. It feels warm and fuzzy to be a member of an elite group helping billions. But as in other human enterprises, the real and sustainable success happens only when such brain-work gets widely distributed. While not the easiest thing in the world, crypto is not esoteric rocket science, and the notion that those few that had to resort to programming for living and fun are somehow more mentally capable than the rest 99.9999% is pure bs.
These threads illustrate some of these points:
https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
https://www.mailpile.is/blog/2016-12-13_Too_Cool_for_PGP.htm...
The task at hand is to elevate the perceived importance of privacy and the importance of self-defense/education to the point of writing some insecure (but unique) code. The latter is the novel point in this discussion.
Currently, the dogma is to explain the importance of privacy, and then point the newly aware audience to use one of the 2-3 options developed by 2-3 teams/companies. This will never work towards general privacy, because if all Internet users started using Signal, PGP, Snapchat etc. tomorrow, the day after tomorrow these products will be backdoored, and backdoored version pushed as an update, as these 2-3 teams have addresses and families, and engineers and CEOs in general do not respond well to anal probes, audits and accidents. This has happened so many times so far, that it boggles the mind how anyone with a shred of integrity can preach centralized pret-a-porter security solutions.
I do not know how to clearly demonstrate the importance of privacy today and the fact that you don't have centralized friends.
Showing smoker's lungs in formaline was easy.
To (ab)use another analogy, look at the history of the tobacco (ab)use. It was hard to get people not to indulge in it just because they will have problems 20 years from now, which is close to the surveillance damage. It took years and huge efforts to cut down the tobacco use.
Literacy started in the similar way, and it's not easy for everyone to learn to read and write (functional illiteracy rarely goes below 10% or so.)
I'll make a wild guess that 15-20% of the general population can learn in few months to tweak working code into working code. There goes surveillance.
Again, nothing prevents one to run this on the top of the 'proven' security stacks. CPU is cheap.
However, if this home-brewed crypto involves coding (and requires users to learn an appropriate language), then it's possible that the entropy harvested from brains of such novices will be orders of (decimal) magnitude over the simple text scrambling.
For example, take simple DES implementation and customize S boxes and/or key generation phase. Do not publish the program except to your peers. Yes, S boxes filled with your dog's vaccination report are likely more sensitive to differential cryptanalysis - but how much ciphertext would that take, not to mention the analyst's time?
We are not talking here about someone specifically targeted. Custom obscurity works great when practiced massively, as de-obscuring has to be done manually in each case.
The bigger issue is whether privacy and secrecy should be simple so that anyone can use it. We may be well past that - standardized security is obviously dead in the water. If security is important and affects one's life, then one should invest effort in it as the one invests efforts in hygiene, education, car maintenance etc.
The requirement that security must be simple so that even idiots can use it is a diversion, a fallacy that imposes inherently weak crypto on all. This is the biggest lie plaguing crypto since the first crypto war.