6 ms·
Dilute PRISM – Use Open Source Alternatives
- jaytaylor 13y agoSeems like FUD - How is switching from Amazon to OpenStack going to help dilute PRISM? AMZN was not listed as a cooperating entity.
- arikfr 13y agoHow switching to Ubuntu will help me in this case? This makes no sense. PRISM probably monitors the network traffic that goes through the US. It makes no difference what OS you're using.
- gasull 13y agohttps://en.wikipedia.org/wiki/NSAKEY https://en.wikipedia.org/wiki/NSAKEY
- mpyne 13y agoWhich even Schneier has said is a conspiracy theory.
- davidong 13y agoI've been thinking about reducing trust in a post-PRISM world a bit today and while switching doesn't help here currently, open source projects are at least theoretically able to prove their trustworthiness by publishing audit tools. Say for example a distro publishes build scripts which download, verify, patch, compile and package some software using a specific toolchain, anyone could audit this via a simple hash check. Apple and Microsoft could never prove themselves this way because they need to keep their source code a secret.
- jiggy2011 13y agoDoes switching to Ubuntu really help you that much? Unless there are secret NSA backdoors in Windows/OS X. Hell even under Ubuntu they could just backdoor my nvidia drivers. I would really struggle to recommend using Tor as a "daily driver" for web browsing as well. Unless we want to go back to the 56k web. Most of the others (bitcoin,social networks) rely on network effects anyway.
- gasull 13y agoI'd recommend VPNs that route out of the US.
- neology 13y agoUS is not the culprit here. Any government can pass a law that allows them to scan data in their country.
- jiggy2011 13y agoDepends how much you trust your VPS provider. I don't think it would be illegal for the NSA to just hand over a bundle of cash to $randomRussianVPSProvider in exchange for access to their logs. Hell, for all we know half of these companies could be the NSA.
- kunai 13y agoThere aren't backdoors in OS X and Windows that are specifically designed by or for the NSA, but since we can't see about half of the source (at least in OS X) then they can exploit any backdoor that may be present without our knowledge. Ubuntu fares a bit better, but with the proprietary blobs, you never know.
- jiggy2011 13y agoI'd be curious how much work has been done to reverse engineer OS X / Windows. I can't believe that nobody has done it. And how successful these would be at finding potential backdoors?
- gasull 13y agoI would add Bitmessage to the list: https://bitmessage.org https://bitmessage.org
- qubitsam 13y agoBefore recommending Ubuntu (when the issue is, to an extent, one of privacy), let's remember this: http://arstechnica.com/information-technology/2012/12/richard-stallman-calls-ubuntu-spyware-because-it-tracks-searches/ http://arstechnica.com/information-technology/2012/12/richar... The discussion around it here: https://news.ycombinator.com/item?id=4888851 https://news.ycombinator.com/item?id=4888851 Also, a better alternative to Skype would be Jitsi: https://jitsi.org/Main/Features https://jitsi.org/Main/Features
- danso 13y agoOne thing to consider: if you use an alternative to the major services...doesn't that make it easier to find you? You've effectively joined a much smaller haystack. I guess how much of a risk this depends on where you see the vector of attack. If you think the NSA has one decade forward on decryption ability, then what does it matter if Facebook/etc hands over the data or if you've trusted another encryption scheme? But consider this scenario: the NSA knows that one member of a group may be a person of interest, with the rest being innocent (for example, a leaker within an organization). What draws more attention: the person who is sending all of their traffic through GMail, etc...or the person who, for some reason, is using an obscure service at particular hours of the day? Even the use of Tor might be a flag. And if your counter-argument is, "Well, so what? They won't be able to break the encryption on [so-and-so-independent service]?". Well, they don't have to. They just have to find someone who is exhibiting a reasonable amount of suspicious behavior and then observe them in other ways or get their associates/family members to flip...Investigations don't succeed or fail based on the unlocking of a key file...it's the work done around the secret that can reveal the secret. edit: An analogy - You wish to have an affair without your spouse noticing. Since affairs in relationships are not an unheard of occurrence, your spouse isn't going to actively suspect you of it, but he wouldn't ignore signs of an affair either. Having the affair in your own home isn't practical, and you choose not to do it at the Ramada that's just blocks away from your home/workplace because, well, there's so many people there, and there's the possibility that a mutual acquaintance will see you and then tell on you. So instead, you and your affairee agree to meet each other at a small bed and breakfast that is 1 hour away from your city and so small that no one you know probably even knows about it, and no one at the B&B will care who you are or know who your spouse is. So are you safe? Well, only until your spouse finds it weird that on occasional days after work, you're driving in a direction that there doesn't seem to be any reason for you to go, and these occasions end up with you being gone for several hours. And in one such occasion, you were noticed carrying what seemed like a bag for a bottle of wine. By going the obscure route, you've deflected one kind of exposure and opened yourself up to a whole new kind of suspicion.
- mtgx 13y agoThat's why we need to push for popular services like Skype, Hangouts, Gmail and others to implement these technologies to make them mainstream so most people use them.
- outside2344 13y agoI don't understand how this dilutes anything. Open source services are just as vulnerable to getting a national security letter as anything else.
- moreentropy 13y agoThe problem can't just be solved by simply pointing people to (random?) open source software. We still need servers as rendezvous points, and we can't expect everybody to run their own services. Properly setting up a mail server is hard. So, everybody who can should run XMPP and/or SIP servers and hand out accounts to their friends. Both telephony/messaging protocols have inherent capabilities for federating with other people's servers similar to what email does. And with OTR and ZRTP we have real end-to-end encryption without relying on (broken) SSL certificates. The technology is ready, now it's time to make it usable. Let's help people to move their lives back out of the cloud.
- vitriolix 13y agovery good points. check out guardianproject.info ... their whole mission is exactly this.
- SudoNick 13y ago> We still need servers as rendezvous points, and we can't expect everybody to run their own services. Properly setting up a mail server is hard. What could be done about this? Running a server on someone else's platform makes you more vulnerable and ISP port blocking can be an impediment to running a server at home. So I start thinking about relatively inexpensive dedicated microservers with integrated solid state storage. Power consumption optimized single board solutions that could just be shoved into a rack and that someone could build hosting plans around. I don't know if anyone has tried to do that. How far could we go in terms of protecting the microserver from the hosting provider and anyone that may try to pressure them for client data? Maybe provide a bare bones executive that allows them to get it up on the network and from there the client can connect and instruct it to install (from the hosting provider's repository or some other repository) pre-built images that are hardened and optimized for the services they want to run and which would include easy to use provisioning tools to help with post install config? Maybe it could run with fully encrypted storage and the executive could provide the hosting provider with an interface to backup that strongly encrypted storage? Thereby allowing for backups which could be restored by the hosting provider (in the case of a hardware failure for example) but without them having access to the OS and data stored on it?
- HunOL 13y agoUbuntu phone, oh really? Where i can buy tomorrow ubuntu phone? Ubuntu? Why this distro, not openSUSE or Debian? Nothing wrong that by default ubuntu uses Amazon ads?
- sp332 13y agoUbuntu is actually working on a phone OS, and the rest aren't. http://www.ubuntu.com/phone http://www.ubuntu.com/phone
- HunOL 13y agoWorking or planning to work? There no devices yet.
- sp332 13y agoAh, here's the link I was looking for: https://wiki.ubuntu.com/Touch/Install https://wiki.ubuntu.com/Touch/Install You can install it right now, it supports 4 current devices.
- HunOL 13y agoAre we talking about geeks or rest? Most geeks to some extent follow aforementioned advices. Ordinary man can't buy device with ubuntu phone. Moreover, ubuntu phone is not yet ready.
- qznc 13y agoIs there a good WhatsApp alternative? I mean a messenger which is Open Source; secure; available on Android, iOS, Linux, Windows, OS X. At best, even the little features like group chat. http://www.kontalk.net/ http://www.kontalk.net/ seems on the way, but not immature so far.
- mehrzad 13y agoThe only safe way to social network without eavesdropping is through encrypted private messages. A public post on Diaspora is still public.
- lettergram 13y agoYou can run, but you can't hide... Especially because they can access most of the internet hubs.
- joefarish 13y agoOpenStack isn't an alternative to AWS on it's own. You still need someone to host it for you.......