6 ms·
Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't
by sofaofthedamned 7y ago
Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them?
So, what value do the SA government have in intercepting these links now?
- mindslight 7y agoIt took well over a decade for this acceptance to go from "conspiracy theory" to common sense in the tech community, and patches of cognitive dissonance still remain. What makes you think that opsec has adjusted so quickly, especially with nowhere straightforward to go? Consider that metadata-spewing HTTPS still passes for security.
- somebodythere 7y ago* Many applications still aren't encrypted by default, like IRC. * If you have compromised a private key, you can get useful data from the cable intercept. * If you can collect ciphertext today, and decrypt it tomorrow (with, say, quantum computers), the cable intercept is very useful.
- esmi 7y agoIRC sure, but the big win is email.
- SXX 7y agoMajority of email traffic is by now for sure use s2s encrypted. Also considering how big major players are most of mail never leave Google / Microsoft / etc servers anyway and connections between them always only ever go over TLS.
- schoen 7y agoYou can get some statistics from Google at https://transparencyreport.google.com/safer-email/overview https://transparencyreport.google.com/safer-email/overview They're a lot better than I thought! (over 90% in each direction, although no data here about certificate verification and the presence or absence of backbone downgrade attacks) If you run your own mail service, check out my colleague's project at https://starttls-everywhere.org/ https://starttls-everywhere.org/
- esmi 7y agoI was just about to post the same link. Outside the US the numbers are a lot lower. Outbound to some countries is 0%. South Africa wasn’t in the report though.
- tialaramex 7y agoAlmost all of the SMTP over TLS will be opportunistically encrypted only and usually with pretty bad protocol / cipher choices. It probably means your email to your aunt isn't intercepted and shoved onto an enormous pile of decrypted email to be parsed for keywords. Probably. But that's about all. Against an adversary determined to intercept: - They can probably just strip STARTTLS, so that everything happens in plaintext - Even if they can't do that because of MTA-STS or similar, they can probably just present self-signed certs and it'll pass the mandatory checks - If they can't do /that/ either (no idea what proportion of email but it may well be in the minority) they can downgrade because unlike in HTTPS nobody is just saying "Old garbage bad, never do that or we'll scream" and so people keep doing it. SSLv3 may even work with a lot of mail servers. Still, what we have now with opportunistic SMTP encryption is equivalent to what you get with snail mail. The spooks CAN read anybody's mail, but it's a hassle so they mostly don't read yours.
- esotericn 7y agoIRC probably isn't the best example, I've been using TLS for a good while now. "By default" probably depends a lot on the client.
- jchw 7y agoModern IRC servers tend to support TLS on port 6697 and SASL for authentication. I’ve been connecting to IRC over SSL for probably a decade at least.
- maxheadroom 7y ago>Modern IRC servers tend to support TLS on port 6697 and SASL for authentication. The OC's point was by default, meaning/inferring clear-text is still the modus operandi for generally getting onto IRC services. >Many applications still aren't encrypted by default, like IRC. SSL and SASL aren't, precisely, user-friendly implementations with some clients (e.g.: IRSSI[0] - but if you're using IRSSI, you don't want a user-friendly GUI to begin with, so...). SASL has less to do with the actual encryption mechanism and more to do with the authentication mechanism (think NTLM)[1]. If IRC services dropped clear-text, today, that would go a lot further to standardising (e.g.: making default) encryption but, back to the OC's original point, it is not the default today. [0] - https://freenode.net/kb/answer/irssi https://freenode.net/kb/answer/irssi [1] - https://en.wikipedia.org/wiki/Simple_Authentication_and_Security_Layer#SASL_mechanisms https://en.wikipedia.org/wiki/Simple_Authentication_and_Secu...
- jchw 7y agoThis is mostly irrelevant; users using Web IRC gateways, services like IRCCloud or clients like HexChat[1] do not have to configure the server unless it isn’t already present in the list. If they do, they already will have to manually configure either TLS or plaintext. There is no “default.” I mention SASL because it is relevant to security posture, especially if the user wasn’t connecting via TLS. Although of course the server could allow PLAINTEXT in practice there’s no point in supporting that because IRC already had native plaintext server authentication. [1]: https://github.com/hexchat/hexchat/blob/3d1d9e1716d66abb6921d15ae22a25f320eeef13/src/common/servlist.c https://github.com/hexchat/hexchat/blob/3d1d9e1716d66abb6921...
- pfundstein 7y agoIn addition to what the other replies are saying, there's a lot to be gathered from metadata alone, even when the bulk of the data is encrypted. Knowing who is talking to who and at what time is difficult to mask and quite valuable information.
- ryacko 7y agoLayer 1 or even Layer 2 encryption would prevent interception of metadata outside of an endpoint.
- dmix 7y agoThere were plenty of small samples in the various Snowden powerpoint slides of stuff NSA incepted from the pipes. It seems a ton of mobile apps are sending information with identifiers over HTTP (the ID is a key part for them legally to pick it up and store it in a DB, forever). I notified one developer that was sending real-time GPS data + an email address highlighted in one of the PPT slide's (just a screenshot of a spreadsheet-like table) and never got a response from the developer. It was a small Canadian company with an app with a few million downloads, so I told Citizenlab about it (don't remember the name, had something to do with sports IIRC). This is a chart of TLS traffic sent via Chrome and across Google: https://transparencyreport.google.com/https/overview?hl=en https://transparencyreport.google.com/https/overview?hl=en 2014 = ~50% 2019 = 94% of traffic encrypted for Chrome users which is great. Linux users currently have the lowest when using Chrome with 86%. I'm curious why this is. Again mobile apps seem to be the biggest problem right now and there was no red HTTPS sign when they sent your sensitive information over cleartext: > Mobile devices account for the vast majority of unencrypted end user traffic that originates from a given set of surveyed Google services. Some older devices cannot support modern encryption, standards, or protocols. Maybe Google PlayStore should start punishing apps for not using HTTPS? Just like how Google is trying to make the internet faster by ranking performant/mobile friendly sites higher. The app testers should put fake identifying information in the various app forms + automatically measure the outbound HTTP traffic for cleartext versions of the IDs.
- icelancer 7y ago>> Linux users currently have the lowest when using Chrome with 86%. I'm curious why the is. They probably browse quite a few old sites for documentation and tooling that are just not updated for HTTPS. A forum I post on to this day is still served over plain ole HTTP and they have no interest in changing.
- lousken 7y agoNot always true, if you message them directly and ask them nicely they'll switch to https. I've even messaged a few to switch from TLS 1.0 to 1.2 as it will be soon obsolete. About 80% of those I asked switched so I am calling it a success, especially compared to companies, I barely get a positive/any response there.
- reaperducer 7y agoWho now sends traffic over these links and doesn't encrypt them? Remember that the intelligence agencies don't only want today's data, they want yesterday's data. You get yesterday's data by storing it today. Then you can decrypt it at your leisure, or when computers become powerful enough to break through. I know a lot of people on HN earn a living making sure internet traffic is encrypted. But honestly, I really believe there are multiple TLA's that can decrypt whatever they want in real time. Maybe not en masse, but certainly targeted streams.
- quickthrower2 7y ago> I really believe there are multiple TLA's that can decrypt whatever they want in real time How? They've cracked modern public key crypto?
- jefftk 7y agoHow do you think they're decrypting in real time? Do you think there are backdoors in the crypto/protocols? Severe accidental flaws? How many times a speedup are you imagining? State of the non-TLA art is that modern https is completely impractical to break, even with enormous server farms working for years, let alone in real time.
- reaperducer 7y agoHow do you think they're decrypting in real time? I have no idea how they're doing it. But I believe it can be done simply because the intelligence agencies have the best, largest, fastest, most advanced machines that money can buy. Machines that none of us have even heard of, that are years ahead of anything any of us will ever touch in our lifetimes.
- jefftk 7y agoBack of the envelope, to see scale: to brute force SHA-256 you need to try about 2^255 combinations, so you'd need to have 2^194x (1,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000x) the hashpower of the Bitcoin network (80 EH/s). If you told me you thought they had cracked a common algorithm so they could do it in only 2^60 time that would at least be plausible. But the idea that they have hardware to straight up brute force it, though, is just impossibly wrong.
- krustyburger 7y agoI think it’s naive to think that Google’s leadership was unaware of anything Edward Snowden revealed. They reacted to the information becoming public.