5 ms·
This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. It's almost as if the fact that I'll never be able to r
by arglebarnacle 9y ago
This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. It's almost as if the fact that I'll never be able to resist a targeted attack means that I shouldn't attempt to have any privacy at all, but surely that's not right.
Encrypted messaging apps and services like ProtonMail have never been primarily to help people with Snowden's threat model. They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense.
- dsacco 9y ago> They're for people like you and me to reclaim a semblance of privacy, and they work even with "Uncle Sam" as the threat model in a limited, dragnet surveillance sense. They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data. It's unclear to me why, if you take as premise a government capable of forcing one of the most valuable organizations in the world to hand over its data, you believe a company several orders of magnitude smaller is safe because it's "end to end encrypted" and has servers in Switzerland. Put another way, I find the concept of a government willing to force Google to give up data but unwilling to use operational vulnerabilities to achieve the same thing to be contrived - how is this not just an arbitrary line in the sand? Furthermore, the heuristic itself is a red herring, in my opinion. It is far more likely that Protonmail has a critical security vulnerability inherent to its software than Gmail does. And even if we assume that the government doesn't want to spend economic resources on actively compromising you as an individual, why would the government not spend resources on a system to compromise you passively as part of an en masse campaign? In other words, are you using a custom built computer with parts designed by a boutique firm from another country immune to the wiles of government backdoors? How do you decide where you want to stop down the rabbit hole, and are you really doing so empirically?
- njarboe 9y ago"Put another way, I find the concept of a government willing to force Google to give up data but unwilling to use operational vulnerabilities to achieve the same thing to be contrived - how is this not just an arbitrary line in the sand?" In the US we have a constitution the prohibits searches of our papers without a warrant signed by a judge. It might be out of fashion is some circles, but the rule of law and not just rule of power is quite popular and I would say a superior system of governance. Many Chinese who are acquiring assets outside of China feel the same way.
- rainbowmverse 9y agoThose laws are implemented by humans who don't always follow them, or only follow them for certain groups of people.
- HenryBemis 9y ago"willing to force Google to give up data" first they issued a gag order, and then they came for the gold "use operational vulnerabilities" am I the only one who strongly believes that Micro$oft is in bed with every 3-leter-agency in haning out backdoors/vulns for the last 20 years?
- bigiain 9y agoWith the current legal uncertainty around whether your fingerprint or retina scan locking your device has the same legal protection as a passcode - do you _really_ think every Three Letter Agency isn't operating under flimsy legal advice that "papers" does not include anything stored digitally? "The rule of law" is _very_ open to interpretation... (And it's not like parallel construction isn't a well known tool used to hide questionably legal (or outright illegal) law enforcement activity from whatever limited oversight they have anyway... A "Superior system of governance"? My opinion differs somewhat there...)
- GroSacASacs 9y agoEmail is one backdoor less to care about, step by step you can regain total privacy with project like these
- bigiain 9y ago"They don't work, because the US government's modus operandi is compromising machines or forcing users to provide access to their encrypted data." I'm not so sure - at least as recently as 2013, Lavabit showed that even top level US govt targets had some realistic reliance on properly encrypted 3rd party email providers... The "dragnet" is the thing that's potentially useful - if it's difficult enough for them, they can't do warrantless "full take" surveillance - even for non US citizens, then choose to individually target you later based on a complete historical record being open to keyword/"selector" based searches. (And for the appropriately paranoid - even Levison's comments back then suggested the thing he was prepared to fight and maybe go to jail for was handing over the SSL key that'd have exposes _all_ users. Reading it the right way suggests he may have sold Snowden out on his own - and I can't exactly say I wouldn't have done so myself in his position - but he was principled enough to not hand over the keys to the entire userbases's security. I sincerely hope _I_ never have the protection of privacy of a user like Snowden being my responsibility while the full pressure of the US government bears down on me. I strongly suspect my strongly-held personal principles would not stand up to that...)
- kllrnohj 9y ago> This comment seems to conflate resistance to mass surveillance with resistance to targeted surveillance. ProtonMail doesn't meaningfully address the mass surveillance aspect, though. Most emails still hit its servers in plain-text form. Encrypting once it hits their server doesn't help the mass surveillance aspect, it only helps the targeted surveillance when a warrant comes in. And if you're willing/able to get everyone that emails you to switch to PGP to get real end-to-end encryption then protonmail is worth even less, since none of their benefits matter anymore (google is obviously not able to decrypt your PGP emails, either).
- bigiain 9y agoAnd sadly - if someone emails a PGP encrypted mail to a protommail address using a key the recipient knows but protonmail doesn't - it doesn't work. Protonmail gives an "unable to decrypt" error, and doesn't hand over the encrypted body... For me - I think they're useful protecting against dragnet "full take" surveillance (especially since I'm a non-US citizen, so am considered "fair game" for warrantless surveillance), but I don't for a moment think they'll protect me from any sort of state actor level interest targeting me specifically (I'm still gonna get Mossad`ed upon...) (In more paranoid moments, I suspect that the first "dragnet" protection quite probably makes the second "targeted interest in _me_" more likely...)