8 ms·
This is infuriating, and the worst part is that a clear solution isn't in sight. Sure, we can fight this in the courts, and a few secret programs might get shu
by dkulchenko 13y ago
This is infuriating, and the worst part is that a clear solution isn't in sight.
Sure, we can fight this in the courts, and a few secret programs might get shut down, but operations will just continue under a different name. We can encrypt our data, move our services and data offshore, but that just paints a big target on our heads - doesn't actually address the fundamental issue. This is supposed to be a democracy, but I don't see any democratic way of addressing this.
What do we do?
- mpyne 13y agoIf the mere capability of surveillance is what upsets you, then I'd recommend yoga and encryption. Investigatory powers have been used in pretty much all nations for hundreds of years and so if your big plan is to remove the very ability for governments to do that, you're going to be in for a long and arduous slog. If instead your concern is with unchecked and expansive untargeted surveillance, we need to push hard for transparency and oversight, which is something that is politically viable and gets 99.9% of the benefit to the average person of surveillance not being possible at all.
- Karunamon 13y agoMake the bastards work for it. Enough people using strong encryption (both for data over the wire and data at rest) makes big-data collection (can't dedupe random noise) and processing/datamining prohibitively expensive if not impossible. Nobody is getting in trouble for moving their data and services offshore. Aside from that? I'd suggest finding a few friendly people in various countries and establish a constant /dev/urandom | ssh | > /dev/null stream when your internet connection is idle.
- davidw 13y agoI wonder if, more than crypto, false positives would make them work harder. They know who you are emailing too, and so likely are not going to target you in any case, since you are not part of an interesting network. But if you start talking about a movie, where they plan to detonate a dirty bomb in Times Square or something... Emacs automates this with M-x spook: morse War on Terrorism encryption Forte Blowpipe LLNL John Kerry Albright Kh-11 22nd SAS ANC Semtex SEAL Team 6 smuggle CIA Also, everyone here from the US has placed a phone call to their representatives to politely, succinctly, and clearly state their opposition to this stuff, right? Ultimately, a political solution is best. False positives make them waste their time, and there are a lot of them who probably really do care about catching genuinely bad people who want to do bad stuff. Just that they need less secrecy, more focus, and much more oversight.
- Karunamon 13y ago6 degrees, though. The network of connecting one person to any other person on the earth is usually quite small. Hmm.. here's a silly idea. A peer to peer network, let's go with a cool web-2.0-ey name like Chaffr, that assigns you a GUID and establishes a stream of truly random (or pseudorandom) data which is propagated out via a P2P system kinda the same way Tor nodes communicate with each other. This stream of noise is generated and runs 24x7. Might require a hardware dongle of some kind to keep the entropy pool full enough. This data is random for the most part, but if you have the GUID of another user, you can send them messages which will be encoded into the stream and received by the other person either immediately, at a set time, or at a random time inside a given window. Garbage, uncompressable, unusable data for the snoops (and the nature of the system as explained in the Snowden leaks will require them to store every useless byte), an anonymous, decentralized communication network for everyone else.
- sneak 13y agoThey can buy hard drives much faster than the 2000 people who would run such a thing can upload data. It's a nice thought, though.
- mpyne 13y agoYou would still have to encrypt that though, which reintroduces the problems of key management and authentication/trust. I'm sure that issue is resolvable though, although I would expect that most ISPs simply drop that type of traffic completely as it can only hurt their operations. So you'd also need to find ways to route around ISPs that don't choose to participate in this.
- pinchyfingers 13y agohaha, I just tried M-x spook, I didn't think it would actually work. Here was my output: national information infrastructure Ceridian INSCOM supercomputer AIEWS Afghanistan Blowpipe chameleon man sweep M-14 hackers Roswell lock picking codes spies second time: world domination cracking Operation Iraqi Freedom IRA Reno analyzer M-14 David John Oates electronic surveillance pipeline INS security Tony Blair national information infrastructure ASLET """ spook is an interactive compiled Lisp function. (spook) Adds that special touch of class to your outgoing mail. """ ; Variables (defgroup spook nil "Spook phrase utility for overloading the NSA line eater." :prefix "spook-" :group 'games) (defcustom spook-phrases-file (expand-file-name "spook.lines" data-directory) "Keep your favorite phrases here." :type 'file :group 'spook) (defcustom spook-phrase-default-count 15 "Default number of phrases to insert." :type 'integer :group 'spook) -- Looks like it'd be a good idea to update and expand the spook.lines file.
- guard-of-terra 13y agoThis is a brilliant suggestion actually. If I ever make a crypto messaging system I'll surely bake in a module that sends bogus messages to random nodes in the system. Then any sorts of metadata are useless to evil people.
- cbr 13y agoFiltering out the random noise wouldn't be very hard.
- guard-of-terra 13y agoHow are you going to figure out whether it's random encrypted noise or an unrandom encrypted message?
- varjag 13y agoWhite noise has distinct statistical properties that allow to mitigate it's effect on detection of meaningful signal. E.g. filtering white noise from audio stream is a very common operation. Sending packets to all contacts at random is a form of introducing white noise, vulnerable to signal processing techniques known and used from 1950s.
- Karunamon 13y agoI thought the point of encryption was that the end result is supposed to be indistinguishable from noise.
- varjag 13y agoWe're talking about metadata here (who talks to whom), not the content of messages.
- guard-of-terra 13y agoYour noise can be non-white. Your noise can favour some of your peers, some time of day, messages can be elaborately routed around in circles. You can even make clients download new message distribution patterns each day. Genetically enchanced patterns.
- sneak 13y agoThe only nonviolent solution I've found is to move away and stop paying taxes to the US war machine. Don't use or support services that pay US taxes, either. It's what I did. PS: It is very, very, very difficult, because most of the people you care about will not move with you.
- deftnerd 13y agoMy family and I have started this process already and expect to be in Central America within the year.
- rayiner 13y agoBecause the Central American governments so wonderfully respect human rights.
- unimpressive 13y agoI know you'd probably prefer people stay in the US, but would you like to make a recommendation for our viewers at home looking to get away?
- mpyne 13y agoI hear Human Rights Watch maintains a rank-order list. Probably Amnesty Internation does as well. But I'm about to leave to go home or otherwise I'd dig it up myself.
- rayiner 13y agoWhere are you going to go? People playing up third world countries don't know shit. The day-to-day corruption in nearly every such country is so bad that after awhile you'd rather have someone reading your e-mail but otherwise leaving you alone. And let me tell you from first hand experience--it is soul sucking to live in a country like that where you're constantly surrounded by people living on the edge of subsistence (or if you aren't you've segregated yourself into 1%-er bubbles, which is its own kind of bad). Look at the BRIC countries, which are supposedly on an upward trajectory. Russia, India, and China are out off the bat. Russia and China do not have functioning democracies, and while India does, it is corrupt from top to bottom. Someone commented about Brazil yesterday how debts are inherited in that country, not to mention it's got outrageous income inequality. Out of the big European countries, you've got the U.K. with cameras on every corner, and France where until recently it was a crime to insult the President. It has come out that Germany spies on people too, though apparently less than the U.S. to a degree (I guess just because of shorter retention periods). Australia tried to put up a nation-wide internet wall a few years ago, so that's out. Canada? Canada does it too: http://www.michaelgeist.ca/content/view/6870/125 http://www.michaelgeist.ca/content/view/6870/125. Libertarians like to put up Hong Kong as some shining example, but that's just proof that libertarians don't really value democracy (since Hong Kong doesn't even pretend to have democracy). Hong Kong apparently does less internet surveillance, except if you're a pro-democracy activist in which case all bets are off. That leaves the Scandinavian countries, I suppose, but I have a hard time seeing a lot of libertarian-minded people fleeing the U.S. for that collectivist utopia.
- rayiner 13y agoThe democratic solution is to get people to care about your issue. If the anti-abortionists can do it, so can privacy advocates. Also, we have no idea whether Lavabit's operator's real situation is (though I certainly fault the government for the ridiculous NSL scheme that prevents him from spilling the beans). Is he objecting to installing a PRISM-style scheme, or to legitimate wiretaps?
- caf 13y agoThis is why the "first amendment" issue might be the most important part of this - he might want to stand up and say "the Govenment wants to force me to backdoor my system, and I think Congress should change the law so this can't happen", but he's not allowed to do so. Restricting this kind of clearly political speech is not right, is not just and is not democratic.
- rayiner 13y agoThe first amendment issue is the most important part of this, and is in my opinion the strongest vector of attack in a potential litigation.
- enraged_camel 13y ago>>The democratic solution is to get people to care about your issue. If the anti-abortionists can do it, so can privacy advocates. Not quite the same thing. Abortion is an inherently sensitive topic that is susceptible to emotion. Saying something as simple as "they are killing helpless babies!" is enough to get a ton of people on the anti-abortion side. What's the equivalent of privacy? How do we make the 4th amendment an emotional issue? Because there lies our victory.
- rayiner 13y ago"Obama is going to take away your guns" (by spying on online gun transactions). "Obama is going to make it illegal to speak out against abortion" (by spying on anti-abortionists). "Obama is going to make religion illegal" (by spying on your church e-mails). "Obama is going to shut down the Tea Party" (by spying on their emails). "Obama is going to criminalize anti-Obama criticism" (by spying on Facebook). Raise money and run ads in red states associating Nancy Pelosi with the whole scheme. These sound out there (and are), but: 1) there is a grain of truth embedded in each one; 2) they speak viscerally to things people care about; 3) they will get an emotional reaction.
- acabal 13y agoAs developers perhaps the most effective thing we can do from a long-term perspective is baking strong cryptography in to all of the products we create, and opting for open source whenever possible. (After all, open source is the only way we can guarantee that the software we're using really doesn't snoop on us.) If crypto were easier to use and presented as a default, more regular people would wind up using it and we'd slowly start stymieing the NSA and similar organizations. Playing politics and calling your congressman isn't going to work in the long term, as you said. We might get one or two laws changed in the short term, but things can change back in the scale of decades and we could be even worse off. The only real solution is to make it mathematically impossible for agencies to read our communications now and in the future.
- SoftwareMaven 13y agoTo make crypto truly secure, the end user has to take on management of their key and that key can never reside on your servers. Users can barely manage their password; expecting them to manage something that, if they lose, takes all their data with them, is asking a lot. I tried to get a startup off the ground for 2 years that would secure gmail, and we went round and round on this. We wanted to not be able to read the user's mail, but the impact on usability was so large, users wouldn't touch it. How do we train users to manage keys? What would be really nice is true homomorphic encryption.
- toufka 13y agoGive us a try? It seems this is the default line and that the users never get to piss off the support people because they're never given the chance. Let us burn ourselves and then we can learn to use the stove. If we never understand the importance of that key we'll never get used to maintaining it properly. Quite clearly - is there any messaging service that allows users to end-to-end encrypt? That is not PGP? There is such a conspicuous void in the market here...
- LoganCale 13y agoAdium and Jabber both support OTR for IM, which is end-to-end encryption.
- crucialfelix 13y agoI have a theory that actually They don't care about surveillance, They don't care about a few measly terrorists or dissenters. It's all about the massive federal money to implement these surveillance systems. They are just doing their jobs because its profitable. It's the new Military Industrial Complex. War is profitable. So we have to disrupt and eradicate that as an incentive. Encryption and political solutions are just playing defense. Destroy the core problem : the profit incentive to violate our privacy and constitutional rights.
- oscargrouch 13y agoDont forget the political power all this information gives to whoever is in charge at the white house.. even if you guys do manage to elect a guy sensitive to privacy.. in the minute he see all the information provided to him about all his adversaries.. and all the other players around the world.. this guy will be converted instantly to the mass data surveilance state "cult"
- wissler 13y agoPeople aren't using the first amendment while they can -- and by that I mean that they 1) do not engage each other on politics nearly enough; 2) when they do, they are generally not very honest or rational. In short -- on average and with exceptions, we deserve what we are getting.
- rwallace 13y agoI'm going to throw in a suggestion that I haven't otherwise seen made in this discussion. Governments' justification for surveillance is that it's necessary for fighting terrorism. Okay, I can't say how useful it is for that purpose, I'm not privy to the relevant data; hopefully we can all agree fighting terrorism is a good thing as far as it goes, and it's clear governments believe surveillance is part of that. And if surveillance data was only going to be used against terrorists, that would be fine. The reason many of us are so wary of pervasive surveillance is that we reasonably fear it won't stop there. Would it be politically easier, would governments be more amenable, to attacking that problem instead? To say: fine, the NSA and its counterparts in other countries can have their surveillance, but only if the firewall between the NSA and other branches of government is strengthened to stop the data being used for any purpose except counterterrorism.