6 ms·
This is very correct. However, I would amend your solution: the solution is modern encryption and open source. These two in conjunction allow you to verify t
by survirtual 4y ago
This is very correct. However, I would amend your solution: the solution is modern encryption and open source. These two in conjunction allow you to verify trust.
ToS is like HR: they both exist to protect only the company.
- ecef9-8c0f-4374 4y agook. now the US government demands not to use modern encryption and open source. And we are back at square one.
- devmunchies 4y agoThat could go to the supreme court, maybe violates the 4th amendment? "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated" meaning, I got the right to secure my sh*t.
- survirtual 4y agoIf nothing else, it definitely violates the spirit of the second amendment. My digital self should be as secure and protected as my physical brain under the eyes of law.
- deleted 4y ago[deleted]
- synkarius 4y agoCitizens of other countries have no rights under the US constitution.
- rnk 4y agoIt's more complicated than that. They have many rights inside our border. Outside our border I'm not sure. Web search found https://libertarianinstitute.org/articles/constitutional-rights-noncitizens/ https://libertarianinstitute.org/articles/constitutional-rig...
- synkarius 4y agoThat's true about rights inside the US border, but in context, this thread was talking about non-US citizens in their home countries when said countries are being pressured by the US government. I could have been clearer there. I can see why you replied as such.
- anigbrowl 4y agoGreat, but this news item is about the government of the USA demanding rights over the personal data of people in other countries. Not being citizens, the US govt considers them lesser people with no Constitutional protection.
- devmunchies 4y agoI was responding to "now the US government demands not to use modern encryption".
- mtlmtlmtlmtl 4y agoBasically the same right is in the human rights convention, which has no caveats about citizenship and to which the US is a signatory.
- jolux 4y ago> I got the right to secure my sh*t I don't know if you've noticed, but the Supreme Court routinely flouts long-held interpretations of statute for nakedly ideological reasons. Rights don't mean anything if the government isn't willing to grant them, unfortunately. I would not bet on this court preserving a right to encryption as you describe it.
- jolux 4y ago> These two in conjunction allow you to verify trust. Not when it comes to server-based software.
- survirtual 4y agoYes, actually. - If you host your own servers you can still verify. - if you are using well-designed, human-centric software, untrusted servers (read: all servers you do not have control of / cannot audit) would not have any access to private data due to encryption, and clients can be verified to make sure decryption only occurs on the client side The trouble is, this kind of software is a poison pill to advertising. It will be a long time before it takes over.
- murderfs 4y agoYou say "human-centric", but you really mean "what I want". Many more humans would be upset at being unable to recover their data if they forget their password than would be pleased by this.
- survirtual 4y agoI said human-centric and I most certainly mean it. Humans cannot be trusted to do the right thing when it comes to mass scale, nameless faces. We need to be kept in check, and we have the mathematics to do it. Custodial services can always still exist for those among us that are incompetent.
- jolux 4y ago> would not have any access to private data due to encryption It's pretty difficult to fully scrub yourself of the metadata involved in making a connection to a server. For sure it can be minimized, like Signal does. But this has inherent UX tradeoffs that most people are not willing to make, like requiring you share your phone number to use the service, and not having server-based backup (yet, at least).
- 4y ago
- lisper 4y ago> These two in conjunction allow you to verify trust. No, they don't. They only allow you to verify that some entity that possessed some private key made some claim about some set of bits. It tells you absolutely nothing about whether any of those claims are actually true, including whether the possessor of the private key is who they claim to be.
- survirtual 4y agoI didn’t mention anything about signing? I said encryption. You can do encryption all kinds of ways. In this case, I am talking about encrypting your own data on a client and not allowing a server to see it. This would just require a secret key derived from a password ran through a password hashing algo. You only need asynchronous crypto when you involve another party, so it would play a role in a trustless architecture, but I am unsure what your point is. When I say “verify trust” of a system, I am referring to a product making a claim, such as “your data is private and we don’t sell it” — then backing up the claim by building the product in such a way such that it is impossible to sell it. Encryption + open source is just about all the way to proving that claim, and it can be verified that way.
- lisper 4y ago> I said encryption. No, you didn't. You said "modern encryption" which is generally understood to mean public-key encryption. But even so, your claim is still false because you can't trust your encryption software even if it is open source unless you build (and audit!) your entire tool chain yourself (and nowadays you have to roll your own silicon too if you really want to be sure).
- LarryMullins 4y agoLet's say hypothetically, Facebook buys Signal. They get all the code and signing keys, then use those to push a new update to the Signal app. This update decrypts your messages using the key on your device, then sends those decrypted messages to Facebook. What are you going to do about it? Call your senators, who are now in love with Facebook for giving the federal government access to these previously private communications?
- __MatrixMan__ 4y agoFork signal, put together a non-profit to run the nodes, start paying $1/mo or somesuch, and stop using the facebookified version.
- LarryMullins 4y agoThat's great if you stay on top of the news, see it coming and get your data out of the way before the compromised app is pushed to your phone. Maybe habitual HN users are safe, but I think most Signal users would be compromised like this.
- deleted 4y ago[deleted]
- void-star 4y agoWhat’s wrong with the existing signal? This is not a sarcastic question. I’m actually curious what the privacy concern over signal is and what is meant by “the facebookified version” and what the privacy concern therein is. The new “stories” functionality I’m guessing? I haven’t used it so I’m interested what observations there are there…
- __MatrixMan__ 4y agoIn the hypothetical above, it contains malware which is exfiltrating message content before encrypting it for send. As for the real world... nothing. I quite like signal.
- astrange 4y ago> ToS is like HR: they both exist to protect only the company. This is, of course, not true about HR and yet another thing people just say to sound cool. HR’s job is to hire people and run your payroll and benefits. If you have a health insurance question are you going to avoid them because they’re going to fire you as soon as you look at them? No. If you’re a first level manager molesting a distinguished engineer are you totally safe from HR because you’re “the company”? No.
- awesomegoat_com 4y agoWell, HR as any other power structure is to protect status quo. They will sack anyone if they see it necessary to protect the status quo. But more importantly, HR will create mindless policies to show you how powerful they are. As border force forcing your sneakers of.
- Aeolun 4y ago> to show you how powerful they are To show you how useful they are. It’s very much a matter of misaligned incentives I think. Of course HR has all day to execute their own policies, so they don’t see them as an overt burden.