6 ms·
Damn. I don't know if this started the whole movement or whatever you'd call it for this push towards privacy and the general public knowing about it, but it h
by aio2 2y ago
Damn.
I don't know if this started the whole movement or whatever you'd call it for this push towards privacy and the general public knowing about it, but it helped a lot. Before him releasing info about room 641A and whatever else, there really wasn't definitive evidence of any government spying and tampering, and either with the intention of starting this movement or simply letting people know, he was a big push in the right direction.
tldr: he's a w
- genewitch 2y agonot only was there not "definitive evidence"; if you said that the companies did that sort of thing you were called a conspiracy theorist whackaloon. oddly 85% of the general public suddenly was like "well of course they spy on email" after all this came out.
- philipkglass 2y agoI'm sure it depended on the audience, but I and others [0] guessed at broad electronic surveillance well before the 641A revelations. I was never called a conspiracy theorist for it either. In the 1990s if you had read Bamford's The Puzzle Palace [1] (published in 1982) and observed the government's legal fight against Zimmermann's PGP encryption software [2], you could make an educated guess close to the truth. If you phrased it as "I'm sure that the government is spying on everything," that went beyond the realm of what could be proved then, but airing suspicions about broad government snooping never elicited strong denials in my experience. [0] Like the people on the Cypherpunks mailing list [1] https://en.wikipedia.org/wiki/The_Puzzle_Palace https://en.wikipedia.org/wiki/The_Puzzle_Palace [2] https://en.wikipedia.org/wiki/Phil_Zimmermann#Arms_Export_Control_Act_investigation https://en.wikipedia.org/wiki/Phil_Zimmermann#Arms_Export_Co...
- genewitch 2y ago> [1] (published in 1982) and observed the government's legal fight against Zimmermann's PGP encryption software [2], you could make an educated guess close to the truth. what percentage of the US population do you reckon could "make an educated guess" about the technological capabilities of the US government in 2002? please remember this is a technology discussion forum, not a general public forum. > Zimmermann's PGP encryption software "PG what? Encryption? like the cryptkeeper? I like hans zimmer music"
- zmgsabst 2y agoPeople suspected there was funny business going on since the Patriot Act was passed in 2001. By 2003 gangs were aware government spied on phones at scale. NSA regularly came up in my high school tech class in 2004, in connection with War on Terror. By 2005, the program was confirmed. https://en.wikipedia.org/wiki/NSA_warrantless_surveillance_(2001%E2%80%932007) https://en.wikipedia.org/wiki/NSA_warrantless_surveillance_(... Lots of people knew that mass surveillance was likely with the advent of the internet, prior to 641A in 2006.
- somenameforme 2y agoLots of people know lots of things. The problem is those things aren't always true. And until there is a defacto public acknowledgement of something many people defer to the 'official position.' Here's a present time one for you - all US based cloud providers, including Apple, are providing full (and probably indirect) real time access to everything stored on those servers to various organizations including, but not limited to, the NSA. Lawsuits around this issue are motivated solely by an effort to do away with parallel construction [1] and enable the evidence obtained through such means to be able to be directly used. Lots of people know this, lots of people also think this is crazy talk. And prior to Snowden, and to a lesser degree Klein, the overwhelming majority fell into the latter camp regarding anything even remotely close to the scope and scale of what the NSA was doing. [1] - https://en.wikipedia.org/wiki/Parallel_construction https://en.wikipedia.org/wiki/Parallel_construction
- floweronthehill 2y agoHere's another official position relevant to current events but that is beginning to change. "Electronic voting machines are 100% safe and as safe as paper ballots if not more".
- genewitch 2y ago"My dad owned a 1965 softtop stingray, it was awesome!"
- lern_too_spel 2y agoThe really odd thing is that 85% of the general public will say "well of course they spy on email" even today, after Snowden's leaks showed that the Obama administration had shut that down.
- rl3 2y agoSetting aside the fact that the leaks you're referring to are over a decade old at this point, they also established that GCHQ buffered the entirety of the UK's internet traffic for 72 hours, bit for bit. If you think there's no collection on e-mail, rather than just legal shell games being played with terminology and various compartments, then I've got a bridge to sell you. In fact, the bridge is made of metadata and nothing else.
- lern_too_spel 2y agoSMTP connections are wrapped in TLS these days, so even if you were to collect email transfers bit for bit, you wouldn't be able to read them, not even metadata.
- potato3732842 2y agoIIRC there's been speculation that the NSA can/has brute forced TLS keys up through 4096 bit size. I read a paper once that crunched the numbers on energy cost and compute time and whatnot it comes out looking like a reasonable investment for them. Obviously they'd have to keep such an exercise on the DL if they did do it because increasing key size is pretty trivial.
- kbolino 2y agoA 4096-bit RSA key is still well beyond the means of even a very capable state actor. The standard nowadays is 2048-bit RSA keys, cracking of which is also (probably) still beyond anyone's capabilities. Maybe a multi-year effort directed at a specific target might manage to crack a single key, but I wouldn't bet on it. RSA cracking efforts would almost certainly focus on smaller keys that are still being used despite the warnings. However, even if they did crack a major infrastructure provider's RSA key, TLS nowadays uses ephemeral key exchange which provides forward secrecy. So it doesn't matter if an intelligence agency collected every packet, they could not decipher the contents after the fact. They would have to actively interdict every TLS handshake and perform a man-in-the-middle attack against both parties all the time. It is extremely doubtful that this is happening en masse. Such a process would require an immense amount of online computing power directly in the path of all Internet traffic. Much of the compute available to intelligence agencies (and accounted for in back-of-the-envelope calculations by outside parties) is effectively offline due to airgaps. It's not like they want people doing to them what they're doing to others, after all. It's much easier to send an NSL to Google to read your email than to try to intercept it over the wire. The latter capability would be reserved for high-value targets unreachable by the US legal system, not mass surveillance.
- nvarsj 2y agoIt's pretty depressing how society went from "that would never happen" to general apathy.
- deleted 2y ago[deleted]
- rcxdude 2y agoThat's not the general sentiment I recall. There was a general sense of 'the government's probably watching' (along with who knows who else: early internet protocols like email really aren't resistant to snooping by more or less anyone), just no public info on specifically how (and you might get some disapproving looks if you claimed any specific approach without evidence).
- abecedarius 2y agoIt depends. If you were a hacker who'd read Bamford and the news from whistleblowers like Klein, talking with other hackers, that general sense was common knowledge. But if the topic came up in conversation with, like, the guy you're subletting a room from in NYC, you could get a very skeptical look. (I wonder if these people remembered those conversations after Snowden.)
- potato3732842 2y agoThat's a really charitable way of framing the fact that a 15% minority screeching about "the government would never" and "but there's no proof" was able to control the narrative despite people generally having doubt or believing otherwise privately right up until the point that the proof was public record and so ironclad that even mainstream media had to report on it. (I assume the 85% number is made up, but for whatever the number is the point stands)
- DoingIsLearning 2y ago> started the whole movement or whatever you'd call it for this push towards privacy I don't really like this framing because it makes it sound like if you care for privacy you are some form of fringe advocate. We should always try to reframe: Would you be ok with government employees or law enforcement indiscriminately opening your letters? Ask any senior and the answer is a clear no. So why are we discussing this as if privacy is entirely optional as soon as you change medium from written letters to emails, sms, instant message?
- cj 2y agoI wonder what percent of Americans would trade their privacy to bring their monthly cell phone bill from $100/mo to $0/mo in exchange for sharing texts and emails with a telecom company. I suspect the percentage would be surprisingly high. Unfortunately normal people don’t really care that much about privacy (even if we all think everyone should).
- 1oooqooq 2y agoyou mean, exactly like most the public on this site did when moving from Gmail and abandoning their isp provided email?
- lotsofpulp 2y agoWhy would ISP provided email be any more private than Gmail? If anything, I expect ISP provided email to be more compromised.
- mulmen 2y agoBecause it’s a lot easier to compromise one email provider instead of a million. I’m surprised I have to explain the benefits of federated over centralized systems here.
- 1oooqooq 2y agoat&t main revenue channel wasn't selling you to advertisers before google showed them how profitable, and willingly everyone was.
- mulmen 2y agoThe Fourth Amendment seems like a more appropriate starting point. Most people call the “privacy movement” “the American revolution“.