3 ms·
Doesn't this beg the question about larger issues, e.g. NSA man-in-the-middle attacks? I think rsync.net's warrant canary is top-notch and a leading example of
by mvanveen 13y ago
Doesn't this beg the question about larger issues, e.g. NSA man-in-the-middle attacks? I think rsync.net's warrant canary is top-notch and a leading example of a good privacy / transparency policy put into practice, but it's just one piece of a much larger set of strategies, no?
Anyone presenting a silver bullet, much less circumstances where trust of another entity is required, is somewhat dubious.
I think answers to said larger strategies are largely missing and the OP's question is probably speaking to these as of yet outstanding issues.
- rsync 13y agoWell, a deeper strategy would be to avoid a suspect technology (SSL, PKI in general) and rely on something both simpler and (we think) more secure: SSH. Unless your system is rooted, or the NSA is building backdoors into all operating systems, you have good assurance about the safety of your SSH connection. So, setting aside our firm for a moment, the general case would be a rational endpoint that you control (maybe us, maybe S3, whatever), a secure channel (SSH) and good encryption tools (duplicity, git-annex[1], hashbackup, truecrypt). So while I was being flip in my original response to the OP, I am now seriously proposing that this all already exists and can be procured from many different providers - a lot of whom can and should be considered "nsa friendly" or even outright hostile. [1] http://git-annex.branchable.com/encryption/ http://git-annex.branchable.com/encryption/
- hoodoof 13y agoIt's fairly easy isn't it to get access to the hard disk of a hosted machine?