HNHacker News
TopNewBestAskShowJobs

themeek

359 karma · joined April 2, 2015

submissionscomments
themeek··on New WikiLeaks Documents Reveal NSA Spied on French Companies
Espionage is standard practice in the world today. So are isolated assassinations, torture, coups, and state sponsorship of terrorism. The United States participated in all of the above.

Domestic citizens in America feel as though their government is 'clean' or 'noble'. This is a myth propelled by Public Affairs, PR and supported by the media (at worst, the media will say, the US made blunders and mistakes).

The United States is in the boxing ring with every other nation. It's a heavyweight.

What's happening right now is that the United States is 'short of breath'. It's overextended. Long term plans haven't worked out. The US is finding itself reacting to other nations rather than keeping them on their toes. It's dropped in its financial, economic, and technological development capabilities. It is having trouble facing challenges brought by new technology. It is losing the support of its closest allies.

It's a difficult time for America. Not everything is decided. It may yet remain a unipolar power.

But to do so it will need to get in and scrap.

The hawks want to scrap. They want to fight for continued supremacy. There are no doves that are serious contenders for president and I don't know if the system would allow a dove to be elected, even if the candidate had majority support from citizens.

In this turbulence, we have to think about what we can do as citizens. The clearest answer is to get quality information and to be informed. Taking the Snowden and Wikileaks documents as a list of things that the US does that are bad is not the best way to read them.

The best way to read these and other documents is to better understand dog-eat-dog realpolitiks of global power games.

No matter whether you want to support the United States in this moment or demand it change course one thing is certain: you must be as educated as possible about the tradeoffs, the current investments, the challenges and the nature of the Great Game. Read across different sources of information and focus not only on domestic news but good foreign policy sources. Talk with neighbors and friends about your and American ideals and how and whether to negotiate and achieve those goals in a world that is 96% non-American.

Wikileaks is a great place to start. The reason for this is not that they have 'the dirt'. It's because they have primary documents. When you read, prioritize information that isn't summarized or filtered.

Muckrack is another great source. Washington Thinktanks another.

themeek··on Apple removes Civil War game from App Store until it removes Confederate flag
Could use an explanation for downvotes. Seems on topic to me.
themeek··on Apple removes Civil War game from App Store until it removes Confederate flag
That doesn't matter for his argument, though.

Sure the Confederate flag used today was the battle flag and not the flag of the union. I don't think people flying the flag really care about that. Flags are symbols and the south attempt at secession did rally under their military effort and flag.

Today the flag means something very different than what it did.

That happens all the time with flags.

But again, none of that matters for OPs argument.

themeek··on Apple removes Civil War game from App Store until it removes Confederate flag
Apple is not and should not be a political actor.

More and more the United States has included corporate activities into the fold of law enforcement and legislation.

A host of institutions called FDRCs exist in a public-private limbo - representing the interests of the state but inside the private world.

NGOs - non-governmental organizations - are in fact very governmental. They are enumerated by the United States, many times funded nearly exclusively by them, and are often fronts for the CIA and other parts of the government.

The government will make causal reference to Civil Society in speeches. Civil Society is not you and I - Civil Society are organizations (many times funded again by those elements that flirt inside and outside of government boundary). For example George Soros funds huge numbers of Civil Society Organizations for US-aligned political purposes around the world.

The United States has discusses standards of corporate governance and responsibility under the expectation that its partnerships with international corporations overseas act as 'proxies' for US government inspired cultivation.

US corporations are allowed and encouraged to participate in the creation of legislature. Given the inevitable pass of TPA it's timely to mention US corporate input into the one of the largest and most important pieces of modern US foreign policy. Wall Street wrote a bill draft for the House to remove limitations on derivative trading (put in after the housing crisis) and the House passed their bill without altering it.

Private corporations draft and/or research most of our legislation. Washington think tanks are critical pieces in the legislative process.

Private corporations own the fourth estate of our government - there's a looong long history here to write about how this has been used for private profit.

The majority of NSA work (it was discovered) is outsourced to private corporations and much of our intelligence work is done by private intelligence corporations (Palantir, HB Gary Federal, Stratfor).

Our military uses Blackwater (now rebranded because of their human rights violations) a benefit being that if a private corporations commits war crimes - it isn't technically the US governments fault.

Issues like modern surveillance (revealed by Snowden) and propaganda are not performed by placing laws on corporations that they must follow, but by partnerships. Corporations are allowed to do things that government can not and vice versa. Both benefit when an exchange can be made.

But probably the easiest place to see the blur and partnership between the state and the corporate world is the Republic and Democratic parties and their Commission - which also runs the presidential debates. This institution (our political parties) themselves are, legally, in practice and by definition, a corporation.

I do not want Apple to be law enforcement or national security enforcement. I do not care if it is more efficient to have private citizens perform the function of public institutions.

Public institutions have limitations that private bodies do not.

This is on purpose. The limitations on governance were placed to ensure liberty.

themeek··on L0pht’s warnings about the Internet drew notice but little action
There's two fundamental systemic blockers to investment in information security.

The first is a problem is with incentives over time. (The same thing happened with global warming, with overfishing, with deforestation, with cyber privacy rights, etc.) The problem is that the immediate incentives do not align with the long term incentives. If the country that can cut down the most forest or burn the most oil is the one that wins, relative to the other, a global race for power projection - no country will want to perform in the short term what it must in the long term.

Alas, today the short term incentives in software and hardware development are mostly the same. The security community has long preached that built in security as a crucial and fundamental engineering design goal. Today, as it has been for decades before, software is not competitive if it has security built in. It raises the costs of development and it slows production and building security awareness into every developer would require years of additional professional experience or schooling: building in security is a competitive disadvantage.

The second problem is that everyone's threat model is different:

- Consumers want their computers to run quickly and do not want their information or identity stolen. They want to have convenient and reliable control over the privacy of their online interactions - from the public and from law enforcement.

- Industry does not want to spend more time and treasure creating fewer visible features. Their existential threat model is losing their business by being too slow at production. Corporations are also scared dumb of having a SONY-style or Target-style breach.

- Government wants to be able to peek into all communications of everyone including its citizens. It wants to be able to hack into other countries - both their industrial and their government sectors - and those of private foreign citizens. It does not want the same to be true in reverse.

It's also true that the types of systems used by the military are different than those used in industry which are further different than those used by consumers. Where do you allocate investment in security? Consumer internet browsers? Virtualization for enterprises? Network intrusion detection for corporate LANs? Access control for government systems? Which do you prioritize? (Granted, its true that some technologies are shared between these classes, such as web browsers)

What's happening right now is that the discussion about threat model is being negotiated (though not in those conscious terms). Governments make their case about national security - how they need backdoors - and how they would like computer security to work. Security professionals - many of them private citizens - have separate threat models and can't agree with government. Individual citizens want privacy - and can't agree with government or industry. Industry wants to get customer and competitor data but also doesn't want to leak their own.

To the degree that the threat models are compatible, some level of real investment can be made (today there do happen to be large scale efforts to mitigate cyber security risks - particularly threat intelligence sharing programs).

Yet fundamental contradictions in threat models will keep the direction of security in limbo and worse if some threat model 'wins' it will comes at he expense of the others. Government's goals, even in so labeled 'free' countries, are disaligned with their citizens on threat model. Government goals themselves are further internally contradictory, as they would like computer networks to be both secure and insecure (giving birth to phraseology such as "NOBUS").

Today not only are we not able to secure the internet and computer systems, we still don't really know what a secure internet would mean.

themeek··on DoJ's Gag Order on Reason Has Been Lifted
Thank you. :)
themeek··on DoJ's Gag Order on Reason Has Been Lifted
Can you speak more about your experiences at Reddit, as much as you can? Was bulk information ever requested and what types of issues did it seem like requests came in for? Is other private information just IP addresses or is it passwords and other records (posting history/times/subscriptions) too?
themeek··on ‘We Assume the Bad Thing Has Already Happened’
This is the future (but really just one small step) of defensive measures that need to be taken against computer network exploitation.

There is essentially no computer network that can not be breached by dedicated and patient (and especially funded) hackers. With increasing importance it is crucial to merely assume that your network has been compromised and work on continual investigation for evidence of full compromise. Assume breach methodology also calls for better credential management: most networks - once on the inside - are very 'flat' in the sense that it's only a couple hops from any user to a network superuser.

This is the reason, for example, why Google's internal corporate network is now internet accessible (corp.google.com). Google has taken the stance that they can not rely on a network perimeter to keep adversaries out and are proving it by not relying on that perimeter for security.

Assumed breach philosophy dictates that detection (e.g. by finding anomolous activity, and alerting on signatures) and response/recovery (e.g. isolation of machines, rolling credentials en masse, forensics to determine scope of compromise) are at least as important as prevention.

Another layer of protection is the cloud where scaled efforts can be made to provide security. Here patches, access controls, isolation, logging and audits can be performed more cheaply by the provider than it can be done as a sum over all individual corporations. Of course, the hypervisor and virtual networking themselves provide a strong security container.

Many of these cloud providers and large US industries (finance, energy) rest on top of segmented parts of the US's DISN (the Defense Information Systems Network) where the DoD can monitor the periphery for cyberattacks and alert companies.

This is one example of data sharing - another large investment being made by the US to secure its cyberspace. Corporations can buy services from Mandiant, Fireeye and a number of other private parties for real-time information about threat intelligence (exploit/behavioral signitures and hacking group MOs). While expensive, these subscriptions can pay for themselves if they prevent or mitigate costs associated with a large breach.

Data sharing is also done between companies on legal agreement. Large companies form networks on threat intelligence - sharing information about malware signatures, activity, source IPs and account names of malignant activity. This is a cheaper option, though the intelligence is less 'curated'.

Finally, the US provides threat intelligence to onboarded corporations using formats like STIX and TAXI. At the speed of computer networking detection capabilities for tooling and tactics of adversaries can be proliferated cross industry so that, even if a breach is successful, if it is detected the cost for attacking other corporations is raised - malware must be recompiled, etc.

Computer intrusion is a cat and mouse game and none of these things, even their sum together, will stop successful breaches. They are, however, cheap means that increase the cost and required sophistication of attackers. Attackers continue to grow in sophistication and today, still outpace all layered defenses.

themeek··on Why Facebook Failed Our Censorship Test
Right. His domain was similar to and confused with the Russian propaganda operation. His website was roped into the censorship network by mistake because of its similar name.

Or do you think stopfasttrack.ru was posting 'spam' about viagra?

themeek··on Why Facebook Failed Our Censorship Test
Military information support for national security purposes within the borders of the US is considered legal by the US government. It is called Civilian Affairs Information Support. The Army, it was discovered, was sending fake letters to news media organizations about experiences and events that did not happen. The Bush Administration, with the Renton Group and through the Iraqi National Council (CIA front) influenced American journalists (Gordon, Miller) to write stories it knew to be false (about WMDs in Iraq) and then pointed to the resulting publications as justification for war. Jessica Lynch's story was a fabrication and the CIA helped in the production of "Body of Lies" - this is similar to CIA involvement in the narrative development of the recent CBS production "Good Kill". Benghazi is a perfect recent example. The old terrorist boogyman line, too. Ken Dilanian was outed recently working with the CIA to 'craft' journalism about the use of Drones overseas. Speculatively: the fellowship of media executives put together by Lynton on the request of the State Department to help with anti-Russian and anti-ISIL messaging could find CAIS applications.

CAIS is a separate concept from psychological warfare that happens to weaponize American media that will also ultimately be consumed by Americans such as "The Interview" (revealed by the SONY hack leaks) or the use of front page New York Times article placement for Military Deception in the invasion of Fallujah. It is different because it specifically seeks to encourage the public to support military operations and wars: Americans are the audience.

It is also true that legally the US government is allowed to perform influence operations ("strategic communications") on Americans during states of emergency. There are reports of this being done during both Occupy and Ferguson (in Ferguson there was a media blackout zone placed over the city and the US government worked with airline companies to deny journalist travel to Ferguson to get coverage; its also true journalists were regularly and asymmetrically arrested and detained). It's true that both Occupy and Ferguson were declared states of emergency - and so it would be legal for the government to manage public perception in these cases. But we don't have smoking gun evidence to claim that there were concerted, explicit efforts.

American citizens should be aware of these things and discuss with their representatives what level of narrative support they would like their government to supply.

themeek··on Why Facebook Failed Our Censorship Test
Yup. Let's dive into this a bit.

The thing is that when you invoke 'they' you don't mean Facebook. Facebook as a corporation doesn't care about the general public seeing how prisons are run.

The government - and where it shares coffers with private prison moguls - cares.

The government and the private prison industry are able to project their goals through Facebook.

themeek··on Why Facebook Failed Our Censorship Test
The link you give is to data requests, not to content curation.

Twitter has historically played much harder ball with the State Department and DoD with regard to account takedowns and content censorship. Though neither, as far as I can tell, have many public statements or publish data about it.

themeek··on Why Facebook Failed Our Censorship Test
I think the EFF is being generous here. Facebook blocks posts to certain types of political material even if it is posted by an American citizen. They would round out and wax and wane about 'terrorist material' - content such as the ISIL newsletter (which overall is not 'gross', especially compared to some American cinema). But blocked content is broader than that.

Facebook is also part of a network of other American Social Media companies that have automated systems to block content posted that match certain patterns and known propaganda efforts by other nations.

Recently an anti-TPP website was blocked simultaneously across several communication providers (https://www.reddit.com/r/technology/comments/38pmg8/hey_redd...). This was a mistake as the website name closely matched the name of a Russian Anti-TPP propaganda campaign.

The mere existence of the ability to coordinate content blocking across service providers means that a censorship network exists - the question becomes whether it is 'abused'.

It's difficult to ascertain abuse, of course, given the Obama Administrations policy with regard to censorship and propaganda and its weakening of the Smith-Mundt Anti-Propaganda Act. The Administration believes that the US government is not responsible for having its influence operations online spill over to affect American people - it is merely prohibited from actively and specifically targeting Americans. That is, the new policy is that it's okay - even expected - for Americans to be 'collateral damage' in censorship and propaganda campaigns.

Thinkers like Cass Sunstein are traded high up in the US Government - Sunstein wrote a book on the 'Problem of Free Speech'. Broadly this influential Washington Legal Scholar believes that speech that is actively harmful or misinformed can and should be 'addressed' by the state - and he recommends ways in which that can happen.

The Snowden documents reveal that (so far as we know non-specific American targeting) the mass surveillance networks are intrinsically tied to influence operation capabilities - outside those capabilities at the GCHQ (which legally are not prevented from targeting Americans) - and who engage quite heavily in psychological influence campaigns.

I have personally, repeatedly witnessed Facebook selectively block posts of mine linking Wikileaks material, the Snowden documents (when they were first being published), and leaked drafts of the Trans Pacific Partnership and watched as others complained about having their posts trying to organize protests on May Day blocked similarly.

It's true also that Facebook has been associated with at least two studies on societal manipulation programs with researchers that are funded by the Department of Defense in the same area. Many people remember the "Emotion Manipulation Study" - fewer the vote influence study. These sorts of programs have been called for in the past 10 years of Defense Document planning and DARPA today, under their SMISC program, study similarly how to shape and track ideas in social media networks like Twitter.

I'm honestly glad that the EFF is finally giving this issue some attention.

themeek··on Fully Homomorphic Encryption Without Bootstrapping [pdf]
Admittedly much fewer (on the order of 'a few'). It's also hard to compare, as constants are hidden in big-O. Real performance comparisons between cryptosystems are comparisons of real-world engineering implementations: especially since side channel blinding, exception and case handling, etc need to be taken into effect.

The take away is that this would still be nowhere near as efficient as 'traditional', especially symmetric, encryption. What would be a breakthrough is that presumably the scheme would be orders of magnitude more efficient than current existing theoretical FHE schemes.

themeek··on Fully Homomorphic Encryption Without Bootstrapping [pdf]
The paper suggests that it would take on order 2^27 bit operations for encryption/decryption for securely parameterized instances of this scheme, small ciphertexts and keys, and a simple multiplication and addition formula. If true, this would be an incredible leap - a breakthrough in efficiency. And efficient FHE would be a game changer for the Internet and the world.

Evaluating the claim thus requires skepticism and care. The quality of the paper is suspect as are its proofs. But, as is the case with science, heuristics like this count for little.

They do seem to have selected a hard worst-case problem to base the system on. Obviously this means very little if secure keys and setting in this complexity space can not be found in practice - or if the details of the cryptosystem, for one of many many reasons, lead to its easy compromise.

Looking forward to a proper peer review of the scheme.

Edit: Looks like it's already broken!

https://news.ycombinator.com/item?id=9734512

themeek··on Bing Moving to Encrypt Search Traffic by Default
> Amazing that so much attention is given to the NSA here..

Well, the topic of default encryption is related to a mass global surveillance network supported by data collection capabilities built into the internet backbone - and HN is concerned about what these technical capabilities could mean for a runaway government or in the hands of adversarial entities/governments/groups. It's an incredibly important topic, so I'm glad there's some chat about it.

> To me a more interesting question is how will this impact keyword data that's pasted through the referring URL?

Doesn't Google have a redirect mechanism that allows referrer information to pass through when a 'blue link' is clicked?

themeek··on Bing Moving to Encrypt Search Traffic by Default
Sure, if you can say that hundreds of millions of people can simultaneously be specifically investigated.

> We know that all corporations that had their inter-datacenter networks compromised have encrypted traffic on those links, making that a non-issue.

Actually, we know that they targeted the interlinks where encryption was removed and added back - giving plaintext (if you are referring to Google). If you remember after the Snowden exposures related to this hacking there was an industry wide call to encrypt data in transit - this very thing implies it was not the case before.

> The data-gifting is a figment of your imagination. Nobody will go out of their way to make their own data accessible to a third party for free, and these Internet companies in particular wouldn't share it with anybody.

Please familiarize yourself with the associated stored communication and service provider laws and data sharing programs.

themeek··on Bing Moving to Encrypt Search Traffic by Default
Well, that's generous. You don't have to be specifically investigated by the FBI (just 'related') and the court orders used to make requests can be quite large and in practice are primarily automated. If you look at the sort of processing the NSA is talking about they are discussing large scale sentiment and social media analysis (of the sort that non-related folks must be included). On this line we know that anyone 'three hops away' was considered legally relevant to an investigation. It was shown in the Snowden documents that NSA hacked into backend databases of US corporations to collect data - which gave data access with no warrant. Finally, companies are encouraged to give data to the government as a gift. This gifting of data is not compulsed legally and is outside the scope of (weak) legislation by FREEDOM providing some small limitations on bulk collection requests.
themeek··on Singapore Rising: The Plot to Be the Next Big Tech Hub
Expect more "Singapore Rising", "Philippines Rising", "Taiwan Rising", "Thailand Rising", etc stories in future.

In a bid to contain China's rise into a world power and global superpower rival, the US is orchestrating a Trans-Pacific Partnership between China's neighbors which excludes it and a mutual defense network in the Asia-Pacific Arena (starting with Japan) similar to NATO - again one which excludes China.

Another part of this bid is that the US is heavily invested in getting Asian nations (especially India) to rise in tandem with China rather than as economic satellites.

Whether the US succeeds in containing China with these and other tactics it is inevitable that the Asia Pacific will 'rise' as these individual nations cross into modern, consumer-style economies. Soon, too, will the majority of world trade will be passing through these waters. Singapore is rising because there is a rising tide in the Asia Pacific. A rising tide lifts all ships.

themeek··on US Navy Soliciting Zero Days
So many different purposes. Sometimes control is necessary for everyone's benefit - government has a legitimate claim to power. Sometimes control is self-interested - it does one party more good than it can do the other. Sometimes control is about a brace for an uncertain future - the American Empire right now is being seriously challenged for its global primacy. Sometimes control is about self-benefit - it consolidates power specifically to disadvantage the other power. Etc. Etc.

Power consolidation right now is a mixed bag. Those who want power for their own purposes find a good partner with those who consolidate power for noble purposes find a good partner with those who brace for the future, etc.

You can only pick voices from the cacophony if you train your ear in one direction. They are all there and it takes every singer in the chorus to work.

themeek··on US Navy Soliciting Zero Days
The control is not always in the hue of totalitarianism or evil or malice.

Some control is necessary of any government.

Some control is perceived to be, but is not actually, necessary.

Some control is self-interested and self-concerned.

Some control is conspired by those who seek to wield it for their own benefit.

When it comes to the US government, there's a big mix of the above and its never enough to establish one grand motive behind everything.

This of course doesn't take away your point - it is about power. It's just that the angle on this power has to be negotiated circumstantially and available alternatives. (If there's an simple, cheap and effective way to solve a problem but a power consolidating method is chosen instead the mask has slipped).

themeek··on US Navy Soliciting Zero Days
By cyberwar he means that nation states were investing in state-of-the-art capabilities to use Computer Network Exploitation for the purposes of espionage and sabotage.

This has been happening since the 90s.

It is true that it has gotten consistently warmer on the internet. There is a term called "hybrid warfare" now that is being traded in the US defense sector.

Hybrid warfare means assymetric capabilities in tandem with ground forces: IO (intelligence operations) with kinetic operations.

IO itself is a broad category consisting of Military Deception (MILDEC), PSYOPS or Strategic Communication (propaganda operations), Electronic Warfare (to disrupt communication, coordination and execution), and Signals Collection for espionage (SIGINT).

The US now considers hybrid warfare the norm and deploys IO operations with every kinetic force. In Syria this meant hacking their air force and grounding their planes - in Ukraine it means winning the 'idea war' in neutral territories and providing morale and information support to civilians and the military alike.

Cyberwar continues to change, as does all war, with the advancement of technology, the capabilities of the parties, the state of the art, and the scale of conflicts. But we've had it now for a couple decades in one stage of evolution or another.

themeek··on Show HN: An experimental Web Browser
I think it would still be non-trivial as event bindings, DOM bindings and others things would not work out of the box. It's a super neat idea though.
themeek··on Encrypting Windows Hard Drives
> as you write and rewrite the same sector, you're doing so against the same set of "tweaks".

> but as a backdoor, it's a pretty crappy one, because it requires your computer not only to be on and "unlocked", but also for you to continuously update the targeted blocks.

The hypothetical backdoor in this example would be in boot/hibernate/wake/suspend/whatever code - i.e. not "on and 'unlocked'". That's the entire point of this backdoor. If the computer needs to access encrypted parts of the disk during boot - even if encryption is done by an e-drive rather than in software - code that causes repeated writes (or even a single write) to an important sector could be designed to subvert FDE.

But it doesn't really matter about this particular hypothetical. We both agree that there is plenty of room to backdoor Bitlocker without having to rely specifically on bitlocker code.

themeek··on Encrypting Windows Hard Drives
No, we're on the same page. I don't have an attack on XTS you are not aware of.

Code (again pretend in hibernate/wake behavior) that deliberately leaks information about important boot blocks on the disk could lead to a full compromise. The attack and back door, of course, would be fairly sophisticated in this instance.

You'll concede that the possibility exists, but that its hard to evaluate. What I'm trying to contribute is not that such a backdoor is currently used (I have no idea) - but that RDRAND/TPM/XTS-leak or other non-Bitlocker backdoor can be used to thwart Bitlocker if we imagine that it hasn't been directly backdoored.

themeek··on Encrypting Windows Hard Drives
Sure. XTS reuses the sector-block for an IV, and so on a per-block level encryption is deterministic. The flaw here would be a scenario where there are deliberate repeated modifications to blocks of the harddrive (somewhere like within hibernation/wake code). Something carefully designed could, in theory, lead to the compromise at a block level that would allow tweaking of some contents on the disk (say, contents of the registry, or of some boot switches, etc) that would in turn enable the machine to be booted and the disk to be decrypted.

It's also true that the TPM protector for bitlocker uses a pin with max ~20 bits of entropy to shield the bitlocker key from exfiltration. The TPM is supposed to lock out repeated requests to extract they key but given the heavy involvement of the NSA in designing the TPM spec and its similarity to the Clipper Chip in function (so too with Apple's "Secure Enclave"), and its difficulty to audit (as if mom and pop consumers really need protection from adversaries who are going to reverse TPM chips to get computer data), one can't help but to acknowledge that a backdoor could easily exist there.

All of this is hypothetical of course. I don't claim to know that this sort of attack is there or that it is placed deliberately. I'm merely trying to make the point that a backdoor need not be in the harddisk encryption code itself.

themeek··on Encrypting Windows Hard Drives
Bitlocker (well, "Device Encryption") does upload your harddisk keys to OneDrive by default, and OneDrive is onboarded to PRISM for government request.

So in the case that you end up provisioning a computer or device with Bitlocker, the key may very well end up in a database for query.

Outside of this it's not really so speculative to think that Bitlocker has backdoors for gov't access. It's unlikely that Microsoft Bitlocker survived the combined forces of state-of-the-art cryptanalysis, legal compulsion, and company infiltration (exposed by Snowden).

A backdoor for disk encryption need not directly attack the cryptography. It could be something as simple as a means to generate a bunch of predictable blocks on the harddrive - that's enough to break XTS. That is, even if there's no software backdoors or backdoors build into the TPM (Lenovo, for example, has 'key escrow' capabilities to extract Bitlocker keys out of TPMs) or crypto backdoors in HW PRNGs (e.g. Intel RDRAND), etc there are software bugs in other places that could reveal the contents of the hard disk.

So it's merely not a threat model you're ever going to find a solution for. In the very worst case, presuming there were some mystical level of harddisk encryption that was't trivial to backdoor or break by a sophisticated adversary - intelligence folks can use TEMPEST attacks, break into your computer when you turn it on, and/or get rubber hose access. An encrypted disk will not stop Mossad.

There is no disk encryption that will unilaterally prevent USG from accessing your files (you can only make it more expensive).

But as the USG is fond of repeating - you don't need your disk encryption to protect you from the government unless you have something to hide. You only need it to prevent attacks from criminals and for device theft.

themeek··on The CEO of a $1 billion 'unicorn' startup admits we're in a bubble
We are definitely in a bubble.

The question is whether, when and how bad it will burst.

Predicting market events like bursts is extremely hard, even for experts - so hard you can make a lot of money from it - remember that economists too said that the housing market was a bubble and wrote posts to mock how, for four years people kept repeating the claims.

If billion dollar valuations for buttons that text 'Yo' isn't a speculation bubble on the one area of US industrial growth, an area that gets a lot of cash influx to keep it going (much of it taxpayer), I don't know what we could call a bubble.

Not all bubbles burst. But how much confidence do you have that the market will remain the way it is today after another series of Snowden revelations, a housing crises (or water crisis) in the Valley, the release of financial information that makes people lose faith, a shocking event like Alibaba beating out Amazon or something, etc?

If you think something like that could seriously damage the industry then you have to admit that the demand for the good and services is highly elastic - or at least fragile.

Fragility of a market + overvaluation and overspeculation implies a bubble.

themeek··on Twitter’s CEO Dick Costolo Is Stepping Down
Currently DIA uses internet signals collection, social media analysis and human intelligence to identify foreign messaging and popular messages that are harmful to national security.

They will submit requests to have these taken down (as the State Department did to Youtube to take down Al-Alwaki's videos) - though currently Twitter is not very cooperative.

I do not know how Twitter would handle a problem like this itself.

themeek··on Twitter’s CEO Dick Costolo Is Stepping Down
My guess would be that it is because fake accounts are not merely fraud, but are often front organizations, either by lobbyists and political PACs or by corporation PR groups, or by nations states abroad and at home for their own covert 'PR'.

These fake accounts are quite difficult to detect.

The accounts that are easy to detect are avoided anyway, since users get to manage their own subscriptions. Some are even cherished for their novelty - horseebooks, etc.

Detecting these covert accounts means being a middle man for whichever party lays a claim about source - and this makes Twitter a middleman for other parties' curation.

← PreviousPage 2 of 7Next →