26 ms·
The sins of the 90s: Questioning a puzzling claim about mass surveillance
- hobs 2y agoIn a nutshell I dont think we would have seen much change - corporations only engage in security insofar as much as they are required to - we've seen that even in this "metastatic SSL enabled growth" we've basically sold out security to the lowest common denominator, and core actors in the industry just use these security features as a fig leaf to pretend they give a single crap. Now, would CERTAIN industries exist without strong cryptography? Maybe not, but commerce doesn't really care about privacy in most cases, it cares about money changing hands.
- InDubioProRubio 2y agoI dont know, they sure make sure the paper-trail is shredded and shedded with the Azure Document Abo 365. When it comes to security from liability everything is top notch.
- Terr_ 2y agoRight: So what we need to do is make organizations liable for mishandling data. Imagine if you could sue a company for disclosing your unique email address to spammers and scammers. (They claim it's the fault of their unscrupulous business partner? Then they can sue for damages in turn, not my problem.) There are some practical issues to overcome with that vision... but I find it rather cathartic.
- red_admiral 2y agoCryptocurrency, if you accept it and its ecosystem as an industry, would certainly not exist. And as for privacy, a fairy dies every time some someone praises bitcoin for being anonymous.
- try_the_bass 2y ago> And as for privacy, a fairy dies every time some someone praises bitcoin for being anonymous. And yet countless thefts have happened and had the proceeds exfiltrated via Bitcoin, and the culprits never caught. If that's not effective/practical anonymity, I don't know what is?
- wmf 2y agoA decent number have been caught and plenty of others are known but can't be held responsible because they're state supported.
- try_the_bass 2y ago"A decent number" instead of "every" kind of supports my point, though. I'm not saying you get anonymity for free, but by taking the right steps and being very careful, it's actually pretty straightforward.
- WaitWaitWha 2y agoOne key part is that the crypto wars were around export, lest we forget "PGP Source Code and Internals". If there was no international business, any-strength crypto would have been and could have been used.
- convolvatron 2y agothere was a huge chilling effect on both product and protocol design. In the 90s I had to fill out a form and submit it to RSA in order to get a copy of their library. Which I eventually got after waiting 6 months, but I had to agree not to redistribute it in any way. Efforts to design foundational cryptographic protocols were completely hamstrung by the spectre of ITAR and the real possibility that designs would have to US only. Right around the time that the US gave up, the commercial community was taking off and they weren't at all interested in further standardization except was creating moats for their business - which is why we're still stuck in the 90s as far at the network layer goes.
- rangestransform 2y agoAFAIK the Zimmerman case was quietly dropped instead of ruled Tinfoil hat: it was dropped to prevent exporting code being 1A protected as case law
- somebodythere 2y agoSeems not tinfoil and rather plausibly a pragmatic decision by the prosecution.
- rangestransform 2y agoWould be a good day to have that enshrined in case law, maybe the US government would let me work on rocket GNC if code can’t be export controlled at all
- 1oooqooq 2y agowhen did local prosecution got a training in international politics and commerce interests?
- RamAMM 2y agoThe missed opportunity was to provide privacy protection before everyone stepped into the spotlight. The limitations on RSA key sizes etc (symmetric key lengths, 3DES limits) did not materially affect the outcomes as we can see today. What did happen is that regulation was passed to allow 13 year olds to participate online much to the detriment of our society. What did happen was that business including credit agencies leaked ludicrous amounts of PII with no real harm to the bottom lines of these entities. The GOP themselves leaked the name, SSN, sex, and religion of over a hundred million US voters again with no harm to the leaking entity. We didn't go wrong in limiting export encryption strength to the evil 7, and we didn't go wrong in loosening encryption export restrictions. We entirely missed the boat on what matters by failing to define and protect the privacy rights of individuals until nearly all that mattered was publicly available to bad actors through negligence. This is part of the human propensity to prioritize today over tomorrow.
- elric 2y ago> What did happen is that regulation was passed to allow 13 year olds to participate online much to the detriment of our society. That's a very hot take. Citation needed. I remember when the US forced COP(P?)A into being. I helped run a site aimed at kids back in those days. Suddenly we had to tell half of those kids to fuck off because of a weird and arbitrary age limit. Those kids were part of a great community, had a sense of belonging which they often didn't have in their meatspace lives, they had a safe space to explore ideas and engage with people from all over the world. But I'm sure that was all to the detriment of our society :eyeroll:. Ad peddling, stealing and selling personal information, that has been detrimental. Having kids engage with other kids on the interwebs? I doubt it.
- ryandrake 2y agoKids are not stupid, though. They know about the arbitrary age limit, and they know that if they are under that limit, their service is nerfed and/or not allowed. So, the end effect of COPPA is that everyone under 13 simply knows to use a fake birthdate online that shows them to be over the limit.
- Lammy 2y agoDownside of trading privacy for security: anything that makes a network connection creates metadata about you, and the metadata is the real danger for analyzing your social connections: https://kieranhealy.org/blog/archives/2013/06/09/using-metadata-to-find-paul-revere/ https://kieranhealy.org/blog/archives/2013/06/09/using-metad... The problem isn't about the big corporations themselves but about the fact that the network itself is always listening and the systems the big corporations build tend to incentivize making as many metadata-leaking connections as possible, either in the name of advertising to you or in the name of Keeping You Safe™: https://en.wikipedia.org/wiki/Five_Eyes https://en.wikipedia.org/wiki/Five_Eyes Transparent WWW caching is one example of a pro-privacy setup that used to be possible and is no longer feasible due to pervasive TLS. I used to have this kind of setup in the late 2000s when I had a restrictive Comcast data cap. I had a FreeBSD gateway machine and had PF tied in to Squid so every HTTP request got cached on my edge and didn't hit the WAN at all if I reloaded the page or sent the link to a roommate. It's still technically possible if one can trust their own CA on every machine on their network, but in the age of unlimited data who would bother? Other example: the Mac I'm typing this on phones home every app I open in the name of “““protecting””” me from malware. Everyone found this out the hard way in November 2020 and the only result was to encrypt the OCSP check in later versions. Later versions also exempt Apple-signed binaries from filters like Little Snitch so it's now even harder to block. Sending those requests at all effectively gives interested parties the ability to run a “Hey Siri, make a list of every American who has used Tor Browser” type of analysis if they wanted to: https://lapcatsoftware.com/articles/ocsp-privacy.html https://lapcatsoftware.com/articles/ocsp-privacy.html
- ForHackernews 2y agoI haven't seen the talk, but it sounds plausible to me: Technical people got strong crypto so they didn't worry about legislating for privacy. We still have this blind spot today: Google and Apple talk about security and privacy, but what they mean by those terms is making it so only they get your data.
- MattJ100 2y ago> Technical people got strong crypto so they didn't worry about legislating for privacy. The article debunks this, demonstrating that privacy was a primary concern (e.g. Cypherpunk's Manifesto) decades ago. Also that mass surveillance was already happening even further back. I think it's fair to say that security has made significantly more progress over the decades than privacy has, but I don't think there is evidence of a causal link. Rather, privacy rights are held back because of other separate factors.
- ForHackernews 2y ago> demonstrating that privacy was a primary concern (e.g. Cypherpunk's Manifesto) decades ago. Also that mass surveillance was already happening even further back. How does that debunk it? If they were so concerned, why didn't they do anything about it? One plausible answer: they were mollified by cryptography. Remember when it was revealed that the NSA was sniffing cleartext traffic between Google data centers[0]? In response, rather than campaigning for changes to legislation (requiring warrants for data collection, etc.), the big tech firms just started encrypting their internal traffic. If you're Google and your adversaries are nation state actors and other giant tech firms, that makes a lot of sense. But as far as user privacy goes, it's pointless: Google is the adversary. [0] https://theweek.com/articles/457590/why-google-isnt-happy-about-smileyface-postit-left-by-nsa https://theweek.com/articles/457590/why-google-isnt-happy-ab...
- warkdarrior 2y agoSure, that line of thinking makes sense, but I do not understand the alternative. Are you saying that if we (the users) got new legislation (e.g., requiring warrants), then big tech wouldn't do mass surveillance anymore?
- anovikov 2y agoHow could that be relevant for more than a few more years? The world does not end with the US. Regardless of the ban, strong crypto would have been developed elsewhere, as open source, and proliferated to the point of making continuation of the ban impossible: by ~2005 or earlier, it will be either US closing off from global Internet becoming a digital North Korea of a sort, or allowing strong crypto.
- wmf 2y agoPopular OSes and browsers have almost entirely come from the US. If people had a choice between IE with weak crypto or Opera with strong crypto they absolutely would have chosen IE.
- amatecha 2y agoOn that note, OpenBSD is from Canada and thus not subject to crypto export restrictions (not that I even know what such restrictions are present in the US today, if any) - https://en.wikipedia.org/wiki/OpenBSD https://en.wikipedia.org/wiki/OpenBSD
- ikmckenz 2y agoThis is a good article, and throughly debunks the proposed tradeoff between fighting corporate vs government surveillance. It seems to me that the people who concentrate primarily on corporate surveillance primarily want government solutions (privacy regulations, for example), and eventually get it in their heads that the NSA are their friends.
- g-b-r 2y agoAside from everything else, I don't understand what Whittaker's point was; she seemed to ultimately be advocating for something, but I can't understand what, exactly. It's probably in the talk's last sentences: > We want not only the right to deploy e2ee and privacy-preserving tech, but the power to make determinations about how, and for whom, our computational infrastructures work. This is the path to privacy, and to actual tech accountability. And we should accept nothing less. But who are "we" and "whom", and what "computational infrastructure" is she referring to?
- salawat 2y agoI can fill that in for you I think. The "We" and "Whom" are you, me, the arbitrary host/admin/user. If you look at the regulatory trends developing around tech at the moment there are a lot of pushes to slap obligations on the host essentially toe the societal line of their geopolity. You will spy on your users. You will report this and that. You will not allow this group or that group. This tightening acts in part to encourage centralization, which is regulable by the state, and discourage decentralization, which is at best, notionally doable. The power of technologically facilitated networking has, prior to the Internet, been in large part a luxury of the State or Entity granted legitimacy by the State. With everyone having the potential to take their networks dark enough where the State level actors legitimately revert to having to physically compromise the infrastructure instead of being able to just snoop the line, it's a threat to the edifice of power currently extant to under a bottom up inversion. No longer would the big boys in the current ivory tower be able to sit on high and know that there may be threats purely by sitting on SIGINT and data processing and storage alone. The primitive of true communications and signalling sovereignty would be in the hands of every individual. Which the establishment would like to cordially remind you includes those dirty terrorists, pedophiles, communists, <group you are mandated to treat as an outgroup>. So therefore, everyone must give up this power and conduct affairs is a monitorable way to make those other people stand out. Because you're all "good" people. And "good" people have nothing to fear. You can't deplatform persona non grata from infra they've already largely built for themselves, which is a terrifying prospect to the current power structure. It's all about control.
- 2y ago
- convivialdingo 2y agoI used to work with the guy who was named by DJB in the crypto export case which removed the restrictions. IIRC, the NSA guy used to be his student!
- singron 2y agoI think this article isn't considering wifi. Most early sites were pressured into using SSL because you could steal someone's session cookie on public wifi. Without cryptography, all wifi is public, and in dense areas, you would be able to steal so many cookies without having to actually get suspiciously close to anything. I'm guessing without crypto, we would only access financial systems using hard lines, and wifi wouldn't be nearly as popular. Mobile data probably wouldn't have taken off since it wouldn't have been useful for commerce.
- quietbritishjim 2y agoI thought WiFi was somewhat secure from other clients, even if your connection is unsecured at the TCP layer, so long as they're not impersonating the hotspot. You're certainly not secure from the hotspot itself, of course.
- Amezarak 2y agoBack in the day, we had a Firefox extension for stealing other people's cookies over WiFi. https://github.com/codebutler/firesheep https://github.com/codebutler/firesheep https://en.wikipedia.org/wiki/Firesheep https://en.wikipedia.org/wiki/Firesheep
- Rygian 2y agoUnencrypted WiFi would be equal to broadcasting your unsecured TCP traffic for everyone to eavesdrop in. Early domestic WiFi would use WEP ("Wired-Equivalent Privacy") which was very vulnerable: https://library.fiveable.me/key-terms/network-security-and-forensics/wep-vulnerabilities https://library.fiveable.me/key-terms/network-security-and-f...
- eurleif 2y agoOnly if the WiFi network is password-protected, which causes connections to be encrypted. Pretty much all WiFi is password-protected nowadays -- if a cafe wants to enable public access to their WiFi, they'll write the password on the wall -- but that only became the case after Firesheep and other sniffing tools drew attention to this issue around 2010. In the old days, there were plenty of networks with no password (and hence, no encryption) at all. The GP specified "without cryptography", in reference to a counterfactual world where we weren't allowed to encrypt things.
- m463 2y agoI think the social element is one of the roots of the problem. Basically, people don't understand privacy, and don't see what is going on, so they don't care about it. Additionally, most privacy intrusions are carefully combined with some reward or convenience, and that becomes the status quo. This leads to the people who stand up to this being ridiculed as tinfoil hat types, or ignored as nonconformist. everything after that is just a matter of time.
- A4ET8a8uTh0 2y agoYes. The weirdest example of this ( and most personally applicable ) is the DNA data shared with 23andme and the like. I did not subscribe to this. Neither did my kids ( or kids of the individual who did subscribe I might add ), but due to some shared geography and blood ties, whether I want to or not, I am now identifiable in that database. To your point, there is something in us that does not consider what information could do.
- 14 2y agoIf you have nothing to hide what are you worried about? Or if you are not planning to be a criminal what are you worried about? I am 100% not serious and do not believe either statement above. I sadly am in the same boat as you and had a blacksheep of a brother who did some sort of crime and as a condition had his DNA taken so I by default am in the system as well. I never could understand why people would willingly offer their DNA to companies that even if they are not selling that data sooner or later could have that data leak and the consequences could mean being able to afford life and medical insurance or not.
- A4ET8a8uTh0 2y ago<< I never could understand why people would willingly offer their DNA to companies I can play devil's advocate and come up with some level of rationalization along the lines of 'it will help humanity cure cancer' in a handwavy kinda way, but even then one is trading future potential against near 100% guarantee that things do change in regards to what you gave -- that is: even if company is promising today it will not do something with data, a day will come when that will no longer be the case. The blacksheep example is definitely interesting though and likely a good idea for a police drama episode ( if it wasn't used already ). Edit: And now that I think about it, if it would be made, it would show the the good certainly have nothing to fear indeed.
- tptacek 2y agoI think I agree with Bernstein that the talk is mostly incoherent about this "privacy" vs. "security" tradeoff. However, I do want to call out his "Amazon was doing good business before 1999 and the end of the crypto wars", and "companies allocate just a small fraction of their security spend to cryptography": * Prior to the end of export controls, Amazon was still doing SOTA cryptography * Export controls themselves boiled down to clicking a link affirming you were an American, and then getting the strong-cryptography version of whatever it was you wanted; there were no teeth to them (at least not in software products) * Prior to the widespread deployment of cryptography and, especially, of SSH, we had backbone-scale sniffing/harvesting attacks; at one point, someone managed to get solsniff.c running on some pinch point in Sprint and collected tens of thousands of logins. Lack of cryptographic protection was meaningful then in a way it isn't now because everything is encrypted.
- nebulous1 2y agoI don't think he was arguing that things weren't more secure after the export controls were dropped. I feel like that's why he was arguing to drop them at the time. He's just saying that all the signs point to Amazon/internet commerce becoming a behemoth either way. So we'd just end up in the same situation wrt what the talk sees as the current state of things, but with compromised cryptography.
- tptacek 2y agoHe was right about export controls. Nobody disagrees with him. I don't even think Meredith Whittaker does. But many times, I've come across a folk belief that strong cryptography was rare in North America before export controls were eliminated; it was not.
- cryptonector 2y ago> Meredith Whittaker, president of the Signal Foundation, gave an interesting talk at NDSS 2024 titled "AI, Encryption, and the Sins of the 90s". The lame claim that DJB is tearing to shreds in TFA is quite shocking coming from a senior manager at an institution that works on strong crypto. Really shocking. Is she just clueless?
- JetSpiegel 2y agoThe outfit that claims that federation is "too hard" for a millionaire foundation, shocking?
- cryptonector 2y agoWell yes, it isn't actually shocking, more like annoying -- really annoying.
- belorn 2y agoAccording to a talk by Eben Moglen (https://softwarefreedom.org/events/2012/Moglen-rePublica-Berlin/transcript.html https://softwarefreedom.org/events/2012/Moglen-rePublica-Ber...), the noted connection between strong encryption and mass surveillance was a policy change by the US government. Before 2001, the policy was to repress and delay strong encryption and keep out of the public sector in order to maintain the states ability to monitor communication. After 2001 the policy changed towards mass surveillance strategies, which methods we got some insight into by the many leaks that was released a decade late by people like Snowden. The connection is interesting, but the key word that I find important is the word policy. Mass surveillance is generally not a technology problem, it is a policy problem. If the government want to surveil every citizens movement they can put a camera on every street, regulate that every car has a gps and network connection that report their movements, have face recognition on every train and bus, and require government ID to buy a ticket that get sent to a government database. When the price of mass surveillance went down, the question of using it became a policy question.