5 ms·
Not exactly... it's kind of like asking whether peeping into someone else's home at night is only illegal for the little people. For you and me, it's stalking.
by devindotcom 12y ago
Not exactly... it's kind of like asking whether peeping into someone else's home at night is only illegal for the little people. For you and me, it's stalking. For a police force that has presented probable cause, evidence, etc to a judge and been awarded a search warrant or wiretap, it's normal investigative technique.
- jnbiche 12y ago>Not exactly... it's kind of like asking whether peeping into someone else's home at night is only illegal for the little people. Well, if that's the analogy you want to use, then this is like police peeping in on the homes of thousands of people who have nothing to do with any crime, all in an effort to find a handful of criminals. There are many people who are OK with that state of affairs. I'm not.
- peterkelly 12y agoThe problem I have with this technique specifically is that it takes advantage of software vulnerabilities that arguably should be reported to the vendor and fixed. If we accept that it's just fine for government agencies (and remember, it might not be a government in your own country) to find exploits, not report them in order to protect people who use that software, and keep those to themselves for their own benefit, then I have a problem with that. It leaves people at risk of being infiltrated not just by (some government agency) but by criminals e.g. looking for their credit card information. Put another way, let's suppose you find a vulnerability in Chrome. Do you: 1) Report it to Google, wait until a patch is available, and then discuss it publicly (aka responsible disclosure) 2) Keep it for yourself, or sell to a government agency (possibly that of a country not friendly to your own) to take advantage of The thing I really have a major beef with is that so many people think that option 2 is just fine. Software should be secure - everyone in the industry has a responsibility to protect users, not leave them vulnerable.
- mike_hearn 12y agoI would agree, but then consider what happens after that - the FBI and similar in other countries have no other options left, and the path of least resistance for them is now to go to politicians and ask for Tor itself to be banned. Though I hate to say it, a system that (accidentally) allows police forces to deanonymise select individuals whilst other actors cannot do so, and even the police cannot do so in bulk all the time, is not a terrible tradeoff. Snowden has made similar remarks, I believe. Of course the supply of zero-days is presumably not infinite. As pointed out, if Tor had more manpower they'd maybe switch to Chrome which is much harder to exploit. So this situation whilst it may not seem ideal is perhaps the frying pan, and as endpoint security improves we may find ourselves in the fire. I recently proposed on tor-dev that individual relays be able to stop acting as introduction points for specific hidden services, with exactly this scenario in mind. They ignored me of course. They seem to feel invincible.
- hollerith 12y agoGreat comment. Can you give a brief explanation about why Chrome would be harder to exploit than Firefox is when used with Tor?