17 ms·
And this is why we all need to start encrypting everything. Every HTTP request, every email. There's strength in numbers and privacy in a crowd. They may have m
by msy 13y ago
And this is why we all need to start encrypting everything. Every HTTP request, every email. There's strength in numbers and privacy in a crowd. They may have massive resources but they're not limitless, we have the technology available to render tools like PRISM unfeasible for the foreseeable future, the choice is ours.
- danbruc 13y agoThe problem is that we are not enough - you have to get the other 95 % not really caring on the bandwagon...and this without causing the slightest bit of additional inconvenience.
- greyman 13y agoOr it is rather 99.995? ;-)
- danbruc 13y agoTrue. 316 million US citizens and 117 thousands of them signing the Snowden petition yields a first approximation of 99.96 %.
- eru 13y ago95% would be nice, but a few percent should be good enough, if there's enough traffic overall. (And even 100% would not be enough if there's almost no traffic, like in the beginning of the internet.) Absolute numbers matter more than shares, here.
- buro9 13y agoWe own websites... make them SSL. We affect the 95%.
- malloc2x 13y agoYou must assume that the NSA already has master keys for all domestic CA root certificates, and given how many were hacked recently, foreign ones too. In which case SSL traffic is effectively the same as plaintext to them. The solution could be a distributed CA system like http://convergence.io/ http://convergence.io/
- jeltz 13y agoPerfect forward security should prevent the master key from working.
- karlmdavis 13y agoIs this correct? Wouldn't they still need all of the leaf private keys to decrypt things? My understanding was that having a CA's private key just enables someone to issue new child keys for that CA. That vulnerability could be addressed with certificate pinning.
- malloc2x 13y agoTo decrypt after-the-handshake bytes I think you're right, they would need a leaf private key. However, they absolutely can mount a MITM with the CA root. EDIT: Further, if they can compel a master key then they can also compel a copy of all the private keys the CA generates.
- juhanima 13y agoNot quite sure what you mean, but for the record, as a general rule CAs do not generate keys. They just sign the public keys coming in as Certificate Signing Requests. Without ever seeing the accompanied private key.
- mhandley 13y agoOn the other hand, we do have the influence to get something like http://tcpcrypt.org http://tcpcrypt.org standardized and deployed in commodity operating systems if we really care enough. Then the 95% won't need to care.
- StavrosK 13y agoIt's really chilling when you realize this is your government you're talking about. It sounds like some dystopian future where normal citizens have to hide from their government's eye, but it's here and now.
- cypherpunks01 13y agoYep, scary. This is the cyberpunk future, after all.
- fnordfnordfnord 13y agoEncrypt your email. Help support jobs for mathnerdspooks. Seriously, the more people they have to hire to sort our garbage personal communications, the more likely future leaks will be about this invasive, wasteful, unnecessary threat to (life, the universe, everything).
- enraged_camel 13y ago>>Seriously, the more people they have to hire to sort our garbage personal communications... The more taxes we will all have to pay. :)
- davidcuddeback 13y agoAnd nothing motivates voters more than their wallets.
- fnordfnordfnord 13y agoYup, and that makes it harder to do in secret.
- mindcrime 13y agoI forget who first said this, but... "I used to wonder when the cyberpunk future was going to get here. Then I realized we're living in it"
- sixothree 13y agoThe Direct Project as part of the ARRA stage 2 meaningful use is worth looking at since encrypted emails will be widely adopted by medical professionals. Maybe this project will be useful for the rest of America. http://wiki.directproject.org/ http://wiki.directproject.org/
- mikegreen 13y agoThe challenge is if you encrypt every email, you're basically using your own email server and service. The gov't isn't decrypting your HTTPS gmail traffic - it is going to Google, saying "hey, give me msy's emails from 2007 to 2010. k?thnx buhbye!" So you essentially have to go off the usual grid to run your own email service... then you have to get all your contacts onboard with using it. I have a client that uses zixmail - webmail that is https and just sends notifications to your plain-old-text email, then you login and read and reply to your email over https. Ironically, it is a gov't agency that makes us use it.. I wonder if they snoop on their own encrypted, vendor-provided secure email?
- q3k 13y agoOr you can use GPG or some other form of point-to-point encryption.
- prg318 13y agoLavabit encrypts all of their stored email to the point that if you lose your password there is no way to recover your email. It might be worth checking out their service [1]. I've switched to lavabit from gmail and outside of a minor outage, I have had no complaints. [1] http://lavabit.com/ http://lavabit.com/
- fein 13y agoI loooove lavabit. Stumbled across it a year ago, and it's my primary account for all my freelance work. The only problem is that a lavabit email is generally viewed as an anonymous (burner) email, so half the services I want to register to just kick the email back as not being "legitimate" enough. For human to human emails it's great.
- prg318 13y agoIf you want to use something other than "@lavabit.com" for your e-mail address, you can. If you have a domain name, you can point your MX records for your domain at the lavabit servers to have your mail forwarded to your lavabit inbox. For example, you could get "John@Smith.com" and direct it to your lavabit inbox. After setting the MX records, you would just need to send an e-mail to lavabit support to have them set it up on their side.
- ianstallings 13y agoStart by using HTTPS-Everywhere plug in: https://www.eff.org/https-everywhere https://www.eff.org/https-everywhere
- sp332 13y agoI combine this with the HTTPS Finder https://addons.mozilla.org/en-us/firefox/addon/https-finder/ https://addons.mozilla.org/en-us/firefox/addon/https-finder/ which detects when a HTTPS version of a site exists and redirects you. It also writes a rule for HTTPS Everywhere so you don't visit the HTTP version again.
- kamjam 13y agoExcept it will make no difference when Google, Microsoft, Yahoo, Facebook etc just hand over your data anyway. Nice plugin though, installed.
- mhandley 13y agoAs a non-US citizen, they can keep all my communications forever anyway. It seems to me that my only redress is to encrypt as much as I can now so as to chaff that one time at some point in the future when I do have something to hide.
- phryk 13y agoYep, and I think they can even keep all the communications of everyone in the US you communicate with. Not encrypting to stay secure is just plain fucking stupid. If you don't encrypt they can read your shit anyways. Plus "reasonably believed to contain secret meaning" in all likelihood means "whatever the fuck we want". As someone else already noted: There's strength in numbers. Let's just encrypt everything and have those fuckers deal with humongous amounts of data, most of which will be completely useless. Shit, if you're inclined to do so let some piece of software run all day that just produces encrypted gibberish and sends it off to random recipients.
- fnordfnordfnord 13y agoNobody should believe that any encryption used today will be secure against attack from anyone after nnn days due to technological advance. Even if no weakness is ever found with which to attack the encryption, Moore's Law will eventually take care of it. edit: yeah, I was talking out my ass, get over it. I still think it's imprudent to assume that encrypted files may never be compromised in the future.
- pyre 13y agoThey are collection a ton of data. As time goes on, if a large portion of it is encrypted, then it may not be feasible to break it all, even with Moore's Law. They may just have to be selective with it. You can imagine that even in if the US becomes a new-age Nazi Germany / Stalin's Russia, it may still be prohibitively expensive to go spelunking through years old communications looking for people with possible subversive thoughts. Edit: It would probably just be easier at that point to ban encryption going forward.
- 13y ago
- theboywho 13y agoNSA logic: Don't encrypt your data or we'll keep it until we decrypt it. So, they will keep it until they can figure out its content ? Fine, so why make it easy on them by giving them plain content from minute 0 ? I don't see why would anyone able to encrypt his/her data not to. The problem is not about them keeping encrypted data but about them labeling you as a potential bad guy once you have encrypted data.
- antocv 13y agoIndeed that is the problem, we are now at the point where you are marked a target for trying to keep some privacy between you and your friends, when you try to keep a third-party, the government, at bay your citizenship rights are temporarily suspended. "Deine papiere bitte" on the streets is not that far away. Actually what we have today is worse, self-censorship and suspension of rights.
- fnordfnordfnord 13y ago>"Deine papiere bitte" on the streets is not that far away. Yup. It is practically here, license plate scanners, NSA metadata with location, constant surveillance. The only thing missing is automatic enforcement of the many petty crimes we commit each day (but you will be threatened with them if the gov't needs you to inform against someone, or simply wants you to plead guilty to some crime).
- 77887 13y ago>>The only thing missing is automatic enforcement of the many petty crimes we commit each day We already have this. Red light cameras.
- lifeformed 13y agoI wonder if you could tie up the NSA with honeypot spam? Just send tons of encrypted data from a bunch of different sources, 24/7. You could even hide your legitimate messages within it. Does a system like that exist? A constant stream of random bytes, some of it real information, most of it not. Only those intended to be the recipient know where to look.
- daturkel 13y agoIt's often possible to distinguish random data from encrypted data using something like a chi square test. However, if you just encrypted random bytes, then it would look just as encrypted as your real data (because it is). Alternatively, you could just encrypt spam emails (it'd be cute if a system like this encrypted and sent every spam email that you received).
- ronaldx 13y agoIdeally, encrypted data should be indistinguishable from random. I agree, this may not be true in practice. [Presumably, NSA is not collecting all sources of random data?]
- jessaustin 13y ago...system like this encrypted and sent every spam email that you received I wanted to like this proposal, but then I realized these encrypted spams have to be sent somewhere. Any ethical target would be too easy for "the bad guys" to filter. Oh well.
- nicholasjarnold 13y agoThis is almost exactly what I logged in to say. If we all use strong encryption to secure our private communications then we'll quickly exhaust all available decryption resources possessed by any government or entity looking to do massive-scale dragnet surveillance. We do have a choice here, and our collective decisions will be what shape our future and our future government. Without a concerted effort we're doomed to slip ever closer to a dystopian future of zero privacy and ever present suspicion of everyone.
- EFruit 13y agoWoah, we don't want to go there. If they can't get the data in transit, they'll go for the sources and destinations. Legally mandated keyloggers, anyone? An 'adversary' as markedly omnipresent as the NSA has had no problems [1][2][3] with intruding upon infrastructure, and I doubt your pesky little Win8 tablet or your pretty little Linux box would be able to withstand even a fraction of what the NSA could set up as a push-button intrusion system. A click of a button, and you're compromised. If you mess with the bull, you'll get the horns. [1] http://rt.com/news/snowden-nsa-china-hack-120/ http://rt.com/news/snowden-nsa-china-hack-120/ [2] http://venturebeat.com/2013/06/12/nsa-global-surveillance/ http://venturebeat.com/2013/06/12/nsa-global-surveillance/ [3] http://www.wired.com/threatlevel/2013/06/snowden-says-nsa-hacked-china/ http://www.wired.com/threatlevel/2013/06/snowden-says-nsa-ha...
- msy 13y agoI can't edit that now but actions speak louder than words - get your GPG key set up today: http://gpgtools.github.io/GPGTools_Homepage/keychain/ http://gpgtools.github.io/GPGTools_Homepage/keychain/ It takes 5 minutes, tops. If you've spent 5 minutes talking or worrying about this issue you owe it to yourself to do it. Set it up with your favorite email client and encourage your friends to do the same. My public key is here: http://sho.ch/alexgraul.publickey http://sho.ch/alexgraul.publickey and on the gpg keyserver, where's yours?
- leephillips 13y agoI've had my public key available on my website for years. Nobody uses it. The problem is social: people are not in the habit of using encryption and only the technically adept have any idea how. Even my correspondents who know how to use gpg don't bother.
- acabal 13y agoThat, and the fact that public/private key encryption is difficult to understand on a conceptual level, uses poor, inconsistent, or misleading terminology, and has a user-hostile interface with GPG or a buggy and error-prone interface with Enigmail. The problem is social in part because we've done such a poor job packaging and marketing the solution.
- unimpressive 13y agoThis, a thousand times this. I could write an entire post on the key metaphor alone. I don't think anyone has ever had their conceptual understanding improved by calling the codes you use to encrypt and decrypt things 'keys'. If we insist on calling them that, can we at least make sure to explain why it's called a key, instead of giving people the impression that it somehow works like an actual key?
- milfot 13y agomaybe the public key should be called a lock.. lock and key makes sense to me
- wahsd 13y agoAs long as there is no default way of doing that for the majority of activity of the lowly user it will not succeed. If, e.g., Mozilla and Ubuntu built it in to all their assets by default with the ability to disable it, then you might have a working plan to overload and drain away the resources put towards decrypting data. Does it dawn on anyone else that our government has and will continue to have turned on its own people. Let that sink in for a couple seconds. The the majority of the legislature instituted it and the executive has been executing it with impunity. It is already bad enough just based on principle as to what is being done to the rest of the world, but our own government has turned on its own people. Just like Europe didn't quite understand what it was getting into, let's say late ~1910 and again in ~1930, because what was to come was so beyond their experience and comprehension; we are making the same mistake and not quite comprehending the ramifications and consequences that will wash over us. No one wants to acknowledge it, but the enemy is within. Tyranny is spreading the way it does and will not be apparent until it is too late.
- Joeri 13y agoThe irony is that reforming the U.S. so that it turned insular and tore itself apart was the very goal of the terrorists who this system is supposed to defend against. The remedy is becoming the disease itself.
- rwl 13y ago> And this is why we all need to start encrypting everything. Every HTTP request, every email. There's strength in numbers and privacy in a crowd. And strength in numbers is not the only reason to do this. The more people expect that their Internet communications are private by default, the more outrageous it will seem to the general public that encrypted data is an exception to whatever rules there are against storing and targeting data from U.S. citizens. "Encrypt everything by default" is a good policy for changing social attitudes, not just a technological measure to defeat an unconstitutional practice.
- LoganCale 13y agoFurthermore, it's a counter to the absurd argument that our emails are not private because we share them with third party servers. By encrypting them, we are clearly asserting our intent for them to remain private.