6 ms·
>a book she’s publishing to accompany the exhibit includes her journal from the height of that surveillance, recording her first-person experience of becoming a
by GigabyteCoin 11y ago
>a book she’s publishing to accompany the exhibit includes her journal from the height of that surveillance, recording her first-person experience of becoming a spying subject, along with her inner monologue as she first corresponded with the secret NSA leaker she then knew only as “Citizenfour.”
That line really highlighted the fallacy that "mass surveillance is effective" for me.
They were actively spying on her concurrently while she was "the subject of a grand jury investigation" and still were unable to deduce that she was actively conspiring with Edward Snowden which would ultimately decimate their reputation worldwide.
- jlgaddis 11y agoPGP FTW!
- mirimir 11y agoYes, and Tor :)
- nickpsecurity 11y agoGood that you two were wise enough to mention the only two that slowed and stopped NSA in the leaks. Keep it up at every opportunity. ;)
- exo762 11y agoTechnical means are not enough. We need political change.
- sail 11y agoHistorically technology has been more successful in affecting political change.
- exo762 11y agoI believe that we have an example of such "success". In Stasi era total surveillance was too expensive. Today technology made it cheap, hence we do total surveillance. We could try to bet on technology-first approach. That means rewriting of all the stacks, create automated solutions that hack and/or patch systems (see DARPA Cyber Grand Challenge), hardening systems and protocols, etc. Now, this leaves us with dumb users that need to be retrained. And that can't be done. And there is other side of things. While we wait for thing that may not happen (dark internet), a) public money are being wasted b) surveillance is creating chilling effect TODAY c) wars with US involvement are raging, fuelling ranks of radicals in Arab world
- petra 11y ago>> We could try to bet on technology-first approach. Since we don't control all the stack(processors, maps ,cellular towers, etc ), and we'll probably won't be allowed to control all the stack , the technology-first approach is just wishful thinking.
- acdha 11y agoCan you cite an example? It's hard to come up with one where you can't find examples of use or abuse, with the direction depending on social factors.
- stinkytaco 11y agoI disagree. In the end, all encryption is breakable with a rubber hose. Nothing stops people in a position of great power from abusing that power except social and political pressures. The key is to create a social and political environment that stigmatizes these behaviors. Unfortunately, we're not there in the US yet. I believe it will come, in the same way that the search warrant became necessary for tapping someone's phone, say, but it will take time for society to catch up.
- justinjlynn 11y agoPGP, if used incorrectly, can actually be worse than if you had communicated in plain text (assuming you have some preshared phrases that make sense in context to use). PGP can reveal not only to whom your talking but without a doubt that it is you and only you and them and only them no matter what email addresses you use. PGP doesn't necessarily protect against replay attacks either and when sent via email, the email the headers and subject lines are, of course, unencrypted and unprotected. Accordingly never put sensitive information in mail headers and, by extension, the subject line. You can use a well-known strongset key for rendezvous but once contact is established always rotate PGP identities with every communication and discard target keys with the throw-keyid(s) option. PGP/GPG can keep you safe but it takes a significant amount of work to use correctly and one screw up can bring it all crashing down. If you need it to keep you alive you must practice, practice and practice some more. Develop your own tools and filters to catch mistakes and always consider the metadata trail you might be leaving. Metadata can convict. Remember, the United States Government targets people for execution based on metadata alone. Consider posting crypted/signed messages to Usenet instead of using email to obscure your communications. Sign and encrypt your messages on an offline system and distribute them online using a different and preferably public computer you don't own and only use once. Distribute and collect your correspondence via ToR if at all possible. Keep your keys offline on encrypted storage. Set up a duress key, always chain different keys (never thread messages with the same key) and always plan for failure, because if it can fail it will. Only then will PGP/GPG have a chance at helping you stay alive and free.
- deleted 11y ago[deleted]
- justinjlynn 11y agoAlso, burn keys after each message. Never reuse non-rendezvous keys and preferably set up new rendezvous keys for each group, groups or entities with which you collaborate and rotate rendezvous keys regularly. Finally, never respond on a regular schedule or too quickly. Delay is your friend. Delay adds noise and makes it harder to connect the metadata you're generating to your data trail thus revealing the connection and breaking one layer of your hopefully multilayered defence.
- exo762 11y ago>>a book she’s publishing to accompany the exhibit includes her journal from the height of that surveillance, recording her first-person experience of becoming a spying subject, along with her inner monologue as she first corresponded with the secret NSA leaker she then knew only as “Citizenfour.” > That line really highlighted the fallacy that "mass surveillance is effective" for me. Ohh it is so much worse than that. For me eye opening moment was CCC 2015 talk "What does Big Brother see, while he is watching?". The main takeaway. People engaged in surveillance are not "evil", "villainous", "dark", "shadowy" or "dangerous", or even "malicious". They are bunch of very sad, very pathetic wankers. Their job has less meaning than any other job I can think of. (Even TSA airport checks may be more meaningful) This is a powerful talk. And it frames global surveillance just as it should be framed. As a waste of money, people going through soul killing, democracy killing, privacy killing motions. Without any chance of getting closer to declared goal, using methodology that if anything, hurts their declared goals. Unless their real goal is control! But in such case they should be called out on that and de-funded.
- acqq 11y agoThanks for the recommendation. The link to the talk you mention: "What does Big Brother see, while he is watching? [32c3]" https://www.youtube.com/watch?v=Teu5qXJDFow https://www.youtube.com/watch?v=Teu5qXJDFow The site of the presenter: http://simonmenner.com/ http://simonmenner.com/
- anon4 11y agoSo you're saying the "pretend to upkeep security while in reality maintaining an iron grip on society for your friends in [REDACTED]" market is ripe for disruption? ...
- chippy 11y ago>People engaged in surveillance...They are bunch of very sad, very pathetic wankers However the reality is neither "evil" nor "pathetic" - they are us, the people reading this article, they are techies, hacker news readers, hackspace users, friends, geeks. They believe what they are doing is right, or they like being challenged by the mathematics, or they want to make a difference for their country, or they want to be at the leading edge of crypto. That's the reality - the people engaged in the technical side of surveillance are hacker news readers.
- nickpsecurity 11y agoThat's a great counterpoint to their methods. I'll add that to my list of stuff to use if I get to face off with a FBI or NSA director on TV. Long shot there but gotta be ready anyway. ;)