9 ms·
NSA targets the privacy-conscious
- caster_cp 12y agoThe only way out of this, as I see it, is making privacy the default. But this require some cooperation and motivation from the big guys at silicon valley. Imagine if Chrome, Firefox, Safari, all of them had, just like the incognito mode, the private mode. Of course, as anonymity also depends on the behavior of the user online, other actions are needed to really ensure security and privacy. But making it the default will educate more people about the importance of privacy and, more importantly, make the point that privacy isn't only for criminals, terrorists and wrong-doers, but that "normal", law abiding citizens also should have the right to be private. And that is paramount for a democracy to work.
- deleted 12y ago[deleted]
- Zigurd 12y ago> But this require some cooperation and motivation from the big guys at silicon valley Unfortunately, this is key to making strong encryption commonplace. A social graph and real-time communication could be used to make key exchange easy and secure. Open client software is needed to make security verifiable. And the storage and email infrastructure and clients need to make using encryption the default. All the pieces of a "trust nobody" environment are there, and so are the pieces for making it an easy to use default. Hopefully, doing this will be required for American service and technology companies to regain trust.
- schoen 12y agoOne of the biggest difficulties for "easy and secure" key exchange is that so many people want to be able to access private communications on many different devices. How do you authorize a new device in an "easy and secure" way without simply outsourcing the problem to an intermediary who is then in a position to attack you by authorizing its own devices? This issue has quite concrete implications for the security and convenience of lots of existing security tools, from GPG to iMessage to Skype to Firefox. They've chosen different approaches but the underlying problem and associated tradeoffs apply to all of them. On the bright side, there are now a lot of people exploring the space of possibilities for dealing with these tradeoffs.
- bsder 12y ago"The perfect is the enemy of the good." Just authorize. If you have perfect-forward secrecy, as long as you aren't being man-in-the-middled right now, you're safe. It's better to have all people doing everything encrypted by default than not. The goal isn't for one individual to be safe against a targeted NSA attack. That's insane--if the NSA wants you, specifically you are screwed; it simply has far too many resources to bring to bear. The goal is to make it expensive for the big agencies to do pervasive surveillance. If everybody is encrypting all the time, random peon at Three Letter Agency has to get up from his chair and actually authorize a wiretap, get a warrant, etc. At that point, it's not going to happen unless you've actually done something very wrong.
- neurobro 12y agoFully agreed up until your last sentence: It's not going to happen unless they have reason to believe it will lead to evidence of someone doing something wrong, and that it will be wrong enough to justify the effort.
- higherpurpose 12y agoFunny enough, Chrome used to say that incognito mode doesn't protect you against spies. It still says it doesn't protect your data from governments.
- yry4345 12y agoI think the cooperation necessary would be for the "big guys" to not have a vested interest in selling out privacy, which has been the prevailing business model for a long time. And, since the big guys only listen to their bottom line, that means not using them until they support privacy. It may mean not using the Internet substantially at all. (It's more than a little ironic to be saying this on the preeminent "business hacker" (or "startup") community, which has a visible subset who sympathize with some of the NSA's programs, or at least have been able to rationalize them...) As you say, the tools have always been there, but no one uses them. That might be because it's a chicken-or-egg problem. At the same time, it might be because the people in the positions to develop and promote the tools, even if only for their own use, are being prevented by a one-track culture that encourages them to sell out their client's privacy in addition to discouraging them from working on projects like Tor. (Again, the HN forum is an example of that conflict - being a largely business-oriented forum; surveillance technology sells... Even DuckDuckGo, a favorite startup in this community, has filters to protect us.) Rather than peer-to-peer solutions like Gnutella, Gnunet, Tor, and even open wireless, people continue to make websites with JavaScript encryption, despite the proven MITM threat. I don't think JavaScript and CSS will get us out of this, but if this latest revelation doesn't wake people up in the tech community specifically, nothing will, since BoingBoing readership is a large number of them - which to me means that the tech and programmer categories are themselves a primary focus of the surveillance that some highly-respected tech pundits (and HN forum members) have defended and rationalized as only being used for terrorists and perverts. That definition now includes anyone with enough knowledge to build or use strong privacy tools. The definition now includes everyone on this forum.
- aluhut 12y ago"No one" uses it because it is too complicated for "every one".
- Sprint 12y agoThey can start with using HTTPS for everything and hosting things like analytics (Piwik rocks!), javascript libraries etc. themselves.
- terranstyler 12y agoWarning: The first sentence goes "If you read Boing Boing, the NSA considers you a target for deep surveillance". So, if you find this interesting, maybe you shouldn't read it.
- sroerick 12y agoOr maybe you should read what you want, and fight for your right to do so.
- notastartup 12y ago"I'm not a terrorist or a criminal so I am fine with forfeiting my rights to privacy and freedom so they can keep me safe from the imminent danger of terrorists" Heard that one before.
- krapp 12y agoYou're warning people about the possible consequences of reading BoingBoing on a site called Hacker News, Where actual hackers and technorati hang out and complain about the American government all the time.
- Sprint 12y agohttps://en.wikipedia.org/wiki/First_they_came_.. https://en.wikipedia.org/wiki/First_they_came_... First they came for the Socialists, and I did not speak out— Because I was not a Socialist. Then they came for the Trade Unionists, and I did not speak out— Because I was not a Trade Unionist. Then they came for the Jews, and I did not speak out— Because I was not a Jew. Then they came for me—and there was no one left to speak for me.
- terranstyler 12y agoOK, just to clarify - I wanted to point out that the site basically says "once you're reading this, you're getting tracked" paradox warning in a (IMO) funny way. I don't agree at all with these practices.
- cLeEOGPw 12y agoIf you are here, you can be damn sure you were already on their list long time ago.
- afarrell 12y agoWhen the NSA collects evidence on someone and uses that evidence to prosecute a criminal case, they can and should file a motion to suppress that evidence. The NSA data is collected under search issued by a FISA court. So, during a suppression hearing, defense counsel can challenge the validity of the warrant. If their challenge is denied, they can appeal. If their appeal fails, they can petition the Supreme Court. In all these courts, the proceedings are public record and the standard for a warrant can be debated by lawyers and the public alike. We have an open process for checking the work of the humans issuing FISA court warrants; Use it. Even if the warrant was valid, the NSA might have overstepped its bounds. This can also be challenged when the NSA defends the admissibility of its criminal evidence in a suppression hearing. An independent judiciary can decide if the executive branch has acted outside its bounds. No, an investigator isn't punished for the overbroad evidence collection, but they are embarrassed by having a criminal get off due to their sloppiness. We have an open process for checking the work of human investigators in this country; Use it. It isn't as if the government just takes that evidence and unilaterally decides to blow people up. We have due process in this country; Use it. /s
- mckoss 12y agoI believe it has been reported that the FBI lies about the sources used in investigations so that defendants never find out about the true sources that led to their prosecution. Your legal right to challenge sources of evidence is useless in the face of a corrupt government whose primary goal is to hide those sources from the public.
- avmich 12y agoBut you can always ask FBI to prove that their sources are legitimate. They say the sources are legitimate, but you say no, and it's their word versus your word, right? On an unrelated news, http://mayday.us http://mayday.us campaign still has two days left.
- bgentry 12y agoAnd meanwhile, years of your life will be wasted sitting in prison awaiting challenges, all while you're threatened with decades in prison for evidence that the government should never have had access to. Not to mention the legal fees if you can't get pro-bono coverage on your case. It's no wonder so many plea out to a lesser (but certain) sentence when given the choice.
- jewhaseloff 12y agoRaw milk distributors.
- sroerick 12y agoWait, what? Are you being facetious? This is so oddly specific.
- yry4345 12y agohttp://boingboing.net/2009/12/08/farm-family-put-unde.html http://boingboing.net/2009/12/08/farm-family-put-unde.html Edit: The title and link of this HN article have changed. The link changed from a BoingBoing article to the original German article, and the headline used to be a question ("Who is the NSA spying on..." or similar) that gave the GP comment more context.
- pekk 12y agoIt's a conservative meme that raw milk producers are being unfairly persecuted, in those circles it's supposed to be a paradigm case of the overly intrusive nanny state. In reality, there is hard epidemiological data showing that selling raw milk (edit: e.g. through the normal store channels) can lead to serious harm including deaths. So FDA bans it for interstate sales, but it's up to the state to decide how to regulate in-state sales. Just like any other food safety issue. NSA is extremely unlikely to be involved in enforcing regulations against raw milk in reality, but in the mind of the conservative conspiracy theorist it's all of one totalitarian piece.
- ajays 12y ago> In reality, there is hard epidemiological data showing that selling raw milk (edit: e.g. through the normal store channels) can lead to serious harm including deaths. I'd love to see the evidence, and see it compared to other food sources. I grew up in India. There all we got was raw milk from the cowherd; in fact, even today, my parents send the helper to get milk in a pail from the cowherd. It's always been raw milk, warm and fresh from the udder. And the first thing they do is to boil it. If I were to conjecture, it's that the "no raw milk" diktat forces farmers to go to big distribution companies with the requisite facilities for pasteurization.
- dang 12y agoChanged the url from http://boingboing.net/2014/07/03/if-you-read-boing-boing-the-n.html http://boingboing.net/2014/07/03/if-you-read-boing-boing-the..., which points to this. There were two versions of this story on the front page. This thread has the fuller discussion, the other the original source. In such cases we usually merge them by reassigning the url and burying the other thread.
- jobu 12y agoBecause anyone trying to keep anything private or secure must be hiding something bad... That's just wonderful. After 10 years of pervasive surveillance and not being able to catch a single terrorist I can't believe the NSA is trying to rationalize it as being a good thing. It's too bad the bill to defund the NSA didn't pass: http://defundthensa.com/ http://defundthensa.com/
- duaneb 12y ago> I can't believe the NSA is trying to rationalize it as being a good thing Is it really a surprise people in power wish to remain in power?
- Zelphyr 12y agoI wonder if the sentiment here is that the NSA used to be known for being a highly intelligent group of people trying to solve hard problems but now they seem like a bunch of D-level bureaucrats snooping through everything hoping they'll get lucky.
- sliverstorm 12y agoMaybe there's just both kinds of people working at the NSA...
- jobu 12y agoThat's it exactly. There are some brilliant people working at the NSA and our country would be better off if they were working improve the security of utilities, local governments, and critical businesses.
- watwut 12y agoAnd maybe they are a highly intelligent group of bureaucrats trying to solve hard problems so they can snoop through everything and get lucky. Highly intelligent person solving hard problems is not necessary "good guy" nor "ethical guy" nor "law abiding guy".
- bsder 12y ago
- pessimizer 12y agoOf course this happens, and it's an obvious technique. I'm sure that not having a facebook account adds to your score, using AdBlock adds to your score, mentioning the NSA online adds to your score, refusing cookies adds to your score, using Linux adds to your score, etc. That's how a police state works. (XKeyScore += 5) My mother was involved in civil rights, so she has a file. It's fine that I have a file too. Hopefully I'll be gone before they start going door to door. edit: http://www.linuxjournal.com/content/nsa-linux-journal-extremist-forum-and-its-readers-get-flagged-extra-surveillance http://www.linuxjournal.com/content/nsa-linux-journal-extrem...
- Holbein 12y agoYeah, and if you don't even have an internet connection, NSA is putting you on their most wanted list. Give me a break. Not doing something can't make you more suspicious.
- pessimizer 12y ago>Not doing something can't make you more suspicious. That's just stupid.
- Holbein 12y agoNo. That's common sense. If you don't do something on the internet, there is no data. No data = nothing suspicious.
- pessimizer 12y agoThere is no state of no data. You are known to exist, you are known for not participating in something that is common for your group. That, in combination with the thousands of other data points about you will determine whether you are of interest. That may determine whether your car gets searched during a traffic stop, or whether you're put on a no-fly list. This is not complicated to build, it is simple to build, and the only logical way of accomplishing what the government claims that they're attempting to accomplish.
- blauwbilgorgel 12y agoI'd like to focus on: Merely searching the web for the privacy-enhancing software tools outlined in the XKeyscore rules causes the NSA to mark and track the IP address of the person doing the search. Again the media makes it sound like there exists a dragnet on (Google) searches. But this time one of the authors is J. Appelbaum. So which is it? Terrorist Scores based on search engine searches sounds fantastically insane to me. But unencrypted it is possible to intercept. So perhaps it is something in between: All accessible searches are monitored, and search engines do not cooperate with this directly, unless they have to legally comply with the request?
- nostrademons 12y agoOne of the earlier Snowden disclosures was that the NSA had tapped private internal Google fiber lines carrying traffic between data centers. Same with Yahoo, Microsoft, other major Internet destinations. Google has since started encrypting all internal traffic, but for awhile pretty much anything was available to the NSA dragnet.
- alex_duf 12y agoI'm sure it still is. We just don't know how yet, but a giant corporation like google has probably other ways to be attacked. And if it is not possible on the technical level, the NSA will find the people to access the data they want.
- jqm 12y ago"It also records details about visits to a popular internet journal for Linux operating system users called "the Linux Journal - the Original Magazine of the Linux Community", and calls it an "extremist forum"." WTF? I guess I am on a list. Who knew being an extremist was so easy?
- reuven 12y agoI write for Linux Journal. Imagine how I feel! I had no idea that I was participating in subversive activities.
- cottonseed 12y agoProud?
- reuven 12y agoI'm certainly proud to be associated with LJ, and to be writing for them. I'm also willing to believe that hackers who want to use encryption and other privacy-oriented technologies use and read about open-source technologies. Although my guess is that this includes nearly all serious security researchers, experts, and implementers. That said, to claim that people who read LJ are extremists, or that the magazine is something of an "extremist forum," misses the mark in so many ways.
- kps 12y agoNo, it doesn't say that Linux Journal itself is an ‘extremist forum’. It says that TAILs is “advocated by extremists on extremist forums”, and includes Linux Journal as a source of information about TAILs, neither of which seem surprising.
- jqm 12y agoYes it says exactly that. Thus the quotes "" in my post. 4'th bullet point from the top in case you wish to check again.
- schoen 12y agoI think an even more significant thing in the XKeyScore code (in terms of the idea that "NSA targets the privacy-conscious") is the existence of a "documents/comsec/" hierarchy of fingerprints. I may have written some of the documentation that's targeted elsewhere within that hierarchy.
- Istof 12y agoand the top key-word on their watch list is de-fund
- deleted 12y ago[deleted]
- toddnessa 12y agoWhat I gleaned most from the article(s) is that it's becoming increasingly important for all of us in the tech community to take a stand ourselves along with TOR to promote online anonymity in our companies (& possibly even think about supporting the TOR Project itself in some way).
- antocv 12y agoDid you seriously think news.ycombinator.com doesnt increase your score and suspectibility of having your computing devices hacked into? And puts you on a very interesting NSA/CIA/Letter-Combo/For-Your-Safety list? Look at Ukraine. War just pops up. I wonder which list they will go by first.
- zby 12y agoThat is why you should join the Pirate Party! We are a targeted group - we must organize.
- junto 12y agoUnfortunately in Germany the Piratenpartei have a few too many undesirable links the NPD [1] (i.e. Neo-Nazis) for my liking. Until they clean house and stamp out the far right, they'll have a problem attracting new voters. http://www.sueddeutsche.de/bayern/piratenpartei-und-rechte-ueberlaeufer-klar-machen-zum-entern-1.1162369 http://www.sueddeutsche.de/bayern/piratenpartei-und-rechte-u...
- zby 12y agoThis is two years old article - as far as I know the German pirates now are rather leftist (actually too leftist for my liking - but as a whole the pirate movement is rather balanced between the two poles). Pirate Party as a new and mostly undefined movement attracted all kinds of freaks - but it can only work as a movement of those that understand how the Internet can be used in politics, both the dangers and the potential for good, and who value the freedom and openness that was associated with the early net.
- deleted 12y ago[deleted]
- Create 12y agoWe begin therefore where they are determined not to end, with the question whether any form of democratic self-government, anywhere, is consistent with the kind of massive, pervasive, surveillance into which the Unites States government has led not only us but the world. This should not actually be a complicated inquiry. http://www.theguardian.com/technology/2014/may/27/-sp-privacy-under-attack-nsa-files-revealed-new-threats-democracy http://www.theguardian.com/technology/2014/may/27/-sp-privac...
- noobhacker 12y agoI feel quite ambiguous about these discriminating techniques. For example, it is okay for us to give females / older people lower insurance rate because that's what the statistics says. Likewise, it's likely that people who search for privacy-enhancing software are more likely to engage in "subversive" activity. So it's hard for me to determine which kind of discrimination is justified and which not.
- TazeTSchnitzel 12y agoDid you mean ambivalent, not ambiguous?