Slashdot Mirror


Snowden Seeks To Develop Anti-Surveillance Technologies

An anonymous reader writes Speaking via a Google Hangout at the Hackers on Planet Earth Conference, Edward Snowden says he plans to work on technology to preserve personal data privacy and called on programmers and the tech industry to join his efforts. "You in this room, right now have both the means and the capability to improve the future by encoding our rights into programs and protocols by which we rely every day," he said. "That is what a lot of my future work is going to be involved in."

129 comments

  1. Kinda Like Mega by Anonymous Coward · · Score: 1

    Can't wait for an app that would allow anyone to be completely anonymous, even from the almighty Goog'lord.

    1. Re:Kinda Like Mega by Anonymous Coward · · Score: 0

      or Facebook, Twitter, [insert all social websites here]

    2. Re:Kinda Like Mega by PopeRatzo · · Score: 0

      Can't wait for an app that would allow anyone to be completely anonymous, even from the almighty Goog'lord.

      The NSA's probably got them in stock.

      --
      You are welcome on my lawn.
    3. Re:Kinda Like Mega by SuricouRaven · · Score: 1

      Retroshare can give you encrypted IM, mail and forums shared only with your retroshare contacts. It's a big of a headache on dynamic IPs though - it expects all nodes to be mostly-stationary. An observer could work out who your contacts are, but that's all they are getting - metadata only, no content. Also does file transfer and share-browsing.

    4. Re:Kinda Like Mega by Anonymous Coward · · Score: 0

      I wouldn't be surprised at all :(

    5. Re:Kinda Like Mega by Anonymous Coward · · Score: 0

      I developed a file sharing app for Unix (Linux, BSD, Solaris, etc.) and OSX back in the mid-2000s that permitted people to connect to "safe" IP lists (we called them "server lists") and then the final version of my p2p client also made every client a server, too. I bolted on encrypted (twofish) IM and file sharing. Years later I heard that several persecuted groups were using it to securely communicate inside despotic regimes.

    6. Re:Kinda Like Mega by AHuxley · · Score: 2

      Thats all the need. If the contact is the press and the sender works/worked for a gov they are both targeted.
      The "An observer could work out who your contacts are" gets even better if you try and meet in person. A member of the press turns their phone off and walks in a direction. Any other person in the area who turns their phone off and then on later like the member of the press is tracked.
      IP, the internet, mobile phones its all great for tracking back the moment a person in gov tries reach out.
      Thats what a good section of the talk was about. Discovering that journalist to whistleblower association, then turning press and byline journalist into criminals for accepting the material and daring to publish. Then its all secret laws, secret courts for the gov worker and soon the press too.
      More Vietnam, Iraq like entanglements as gov staff do not speak out. As they sit back and let more wars to start. That total oath only to authority.
      You can encrypt all you like, the metadata of an unbreakable code to the press will be tracked back. So unattributable internet access was mentioned as a good skill to consider teaching via people with the skills to work on such tasks.

      --
      Domestic spying is now "Benign Information Gathering"
    7. Re:Kinda Like Mega by SuricouRaven · · Score: 1

      Requiring the government to use fiddly correlation analysis to get a partial idea of your activities is still a lot better than the current situation, where they need issue one sternly-worded letter in order to retrieve everything including content and history.

    8. Re:Kinda Like Mega by AHuxley · · Score: 1

      Thats what the talks mentioned too, a set of small steps. Encryption but the wisdom to understand the networks as they are now.

      --
      Domestic spying is now "Benign Information Gathering"
    9. Re:Kinda Like Mega by mspohr · · Score: 3, Informative

      An app won't give you much anonymity. You need to start from the ground up with an OS that leaves no trace on the hardware and has good encryption and anonymity tools built in.
      Here's a good start: TAILS
      https://tails.boum.org/
       

      --
      I don't read your sig. Why are you reading mine?
    10. Re:Kinda Like Mega by Opportunist · · Score: 1

      Considering who owns Mega, I wouldn't trust it further than I can throw that blob.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    11. Re:Kinda Like Mega by Anonymous Coward · · Score: 1

      I've tried RS, Event tried to introduce it to the company but failed for a couple of reasons:

      1. The key exchange thing was a bit of a pain for others (don't see a way around that though). It wasn't seamless.
      2. No smart-phone support. People are not just PC bound.

      They ended up using HipChat.

      The thing is, RS is designed for the security conscious who are prepared to put up with a bit of stuffing around because there's nothing better out there. When people consider security 'a nice to have' with ease of use being the top priority... well RS is an also ran.

  2. soviet era crypto by Penn · · Score: 1, Insightful

    And I'm sure Russia will have absolutely no influence over what Snowden is working so hard to bring us too!

    1. Re:soviet era crypto by NotInHere · · Score: 5, Insightful

      As long as it's not the latest curve, privacy preserving crypto can be written by NSA itself, and still be secure for you. SELinux was written by NSA, and I don't have a problem using it. Your security model shouldn't rely on the party your software came from. It should rely on the software itself, idependent reviews, and, if you can't afford your own review, the many-eyes-principle (which has chilling effects).
      The russians could only say "this is too secure, design something that can be broken more easily".

    2. Re:soviet era crypto by balaband · · Score: 2

      Mod parent up.

      It is not who makes it, it is how it is made.

    3. Re:soviet era crypto by Anonymous Coward · · Score: 2

      Why (and this is the point,) would you trust the NSA any more than the Russian government? Neither wants you to be able to hide what you're doing from them. If these last few years have taught us anything, it's that your government, (wherever you live,) and possibly other governments, should be regarded as the same as any other group of people who could potentially do you harm by knowing things you might want to keep to yourself, whether or not you've committed any legitimate transgression or 'crime' as they call it. Crime is of course subjective because what's a crime in one place may or may not be in another. Case in point, possession, manufacture, consumption, transportation, or offering for sale the product generally known as "booze". Illegal in some places.

      If there are any other lessons here, it's that governments, indeed, other people in general can listen-in on your communications, PERIOD. Using any form of communication that can be intercepted virtually guarantees it will be intercepted by someone, or at least that you should figure it will be. If you find yourself in a room full of loud, random-noise generating equipment, (or just are next to a large waterfall,) and whisper something directly into the ear of another human being, cupping your hands so your lips movements, (etc.) can't be seen, MAYBE no one other than the person to whom you whisper can hear you. Maybe.

      If, OTOH, you're using a device that modulates your voice onto an electrical carrier wave, and broadcasts that via emissions of photons across half the universe, or conveys it using a half-dozen different companies' equipment to someone hundreds or thousands even, of miles away via wire and/or fiber... yeah, someone can listen in, and you should assume that someone will. You should further assume anything you say on the phone (or over the radio) can and will be used against you in a court of law, will be shown to your mother/father/wife/husband/boss/coworkers/the-general-public, and will be misinterpreted to make you seem complicit in whatever they decide it would be funny to frame you for, etc. etc. etc.

      The reason most people get away with using these technologies is that there simply isn't enough crap to pin on people to put every single person into jail, and then no one left to make the cops' doughnuts after everyone else is locked up. That's why we're not all in jail. Yet.

      But wait. They're working as fast as they can on robots who can do your job, and on technology that will enable them to read your minds. I can't wait, (though I think it will suck to live in this world, once this becomes reality,) if only to be able to say, "HA! I told you so!" to read of the first person put into prison for what he THOUGHT. No action, mind you, no "attempted" anything, just for having thought it; you know, he'll be wearing "Google Mind," or using the "iThink Headband," and won't realize they built backdoors into both, and the local police can read thoughts, and he'll have a fleeting fantasy about beating someone to death, pushing his mother off a cliff, or running someone over with his truck, or whatever... and they'll arrest and jail him, convict him and send him to the penitentiary just FOR THAT.

      You know the day is coming. They already jail you for what you say, in some places, what you wear, or don't, they'll do THAT even in " 'Murica " ... yeah, as soon as someone figured out how to make money off putting people in jail... well, it's just like any other time someone figures out you can make money doing a thing, people will do it.

      So forget crypto as a privacy device, unless you're prepared to make it yourself, test in yourself, and be responsible for it yourself. The only unbreakable crypto is the (TRULY F'ING RANDOM) one-time pad, and only if it's used correctly. Everything else is like the locks on your house or car, only keeps people out who don't REALLY want in. The reason the government relented on the whole "crypto is a weapon and you can't export it," is once they were c

    4. Re:soviet era crypto by Anonymous Coward · · Score: 1

      Mod parent up.

      It is not who makes it, it is how it is made.

      Assumptions breed ignorance. And even you were likely surprised over the capabilities and activities revealed by the very person we're discussing here. One would have thought you would have learned when random number generators were found to be not-so-random, and encrypted microcode updates validating themselves against compromised key servers came along.

      But hey, if you truly feel that it doesn't matter who makes it, then feel free to ignore those export control laws and purchase your electronics where they are cheap. I'm sure it'll be worth it, kind of like "free" smartphone apps that never collect any information on you.

      Do yourself a favor. Don't wait for the next Snowden document dump to come along. Wake up.

    5. Re:soviet era crypto by ArcadeMan · · Score: 1

      It is not who makes it, it is how it is made.

      I love that show!

    6. Re:soviet era crypto by ArcadeMan · · Score: 2

      Kind of like "free" smartphone apps that never collect any information on you.

      They don't? That's good to know, I'll go install a few dozen free apps right now!

    7. Re:soviet era crypto by balaband · · Score: 0

      I am not sure I follow your point.

      You are arguing that it does matter who makes the software, yet take examples of the unchecked software to be examples of supporting your case. Even if you get down to hardware level, you are back to square 1 - unchecked code.

      As for the build process, that only depends how thick is your tin-foil hat. I don't see any reason why Soviets are going to be any worse in producing your hardware then 'muricans or Chinese.

    8. Re:soviet era crypto by SuricouRaven · · Score: 1

      I'm waiting for them to do an episode on laws and sausages.

    9. Re:soviet era crypto by AmiMoJo · · Score: 1

      The russians could only say "this is too secure, design something that can be broken more easily".

      Like the NSA did with TrueCrypt?

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    10. Re: soviet era crypto by Anonymous Coward · · Score: 0

      Men already are sent to prison forever for fancying young girls. Thought crime has exists in the feminist states of America for some time

    11. Re:soviet era crypto by AHuxley · · Score: 1

      1+ for 'So forget crypto as a privacy device, unless you're prepared to make it yourself, test in yourself, and be responsible for it yourself. The only unbreakable crypto is the (TRULY F'ING RANDOM) one-time pad, and only if it's used correctly."
      Thats really the only way, one time pad used once, number stations. The key to all the free quality crypto was that all the press where been watched anyway so you get to encode all you want. The moment you send, attempt contact, its just tracked back. No need for a gov to waste time on the decrypt, just watch for encryption been used and all the press. Then get the hardware, software and the plain text before its encoded.

      --
      Domestic spying is now "Benign Information Gathering"
    12. Re:soviet era crypto by Anonymous Coward · · Score: 0

      Exactly. Except that for TrueCrypt there is a certain likelihood that there is a version available that isn't compromised.
      The thing is that even if it is created with an intentional backdoor, if the theory behind its operation is sound one can take whatever comes out of this and fix the backdoor. It is only if the entire concept is flawed that it becomes useless.

    13. Re:soviet era crypto by Anonymous Coward · · Score: 0

      Through the paywall it'll have a feature that can make a planeload of people disappear.

      Soukill and the Snowden lovers are having a re-think? Or they sticking to their BUKs?

    14. Re:soviet era crypto by Opportunist · · Score: 1

      The strange thing is that I trust the Russkies more by now than I trust the US...

      If someone told me that 30 years ago...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    15. Re:soviet era crypto by Anonymous Coward · · Score: 0

      [citation needed]

  3. they will always be MITM by Anonymous Coward · · Score: 0

    NSA will always be MITM. it's going to be challenging :)

    1. Re:they will always be MITM by ArcadeMan · · Score: 1

      NSA is Malcolm in the Middle?

    2. Re:they will always be MITM by present_arms · · Score: 1

      No, Malcolm was more intelligent

      --
      http://chimpbox.us
    3. Re:they will always be MITM by Opportunist · · Score: 1

      That's what strong encryption is for.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  4. Biggest problem in IT security: ID-10-T errors by Stolpskott · · Score: 4, Insightful

    Securing the technology is one thing - that in itself will be a huge job, because depending on how far you want to take it, you can end up needing to sandbox each application and harden each layer of the communication stack.
    You might need a complete new protocol ecosystem based on only systems which are open source (not just because I like open source, but so that everything can be audited and peer-reviewed at the code level), built with compilers which themselves are not only trusted but also auditable as matching their published source code, and using communication protocols which are themselves open source and audited.

    Put all of that together, and you still have the biggest security/privacy threat to deal with - the ID-10-T (aka the user sitting at the computer). Until users of a computer system are educated - not necessarily to the extent that they can themselves audit source code, but at least to the point where they can recognize compromised behaviour of a computer system - then they will always be the weak link in a security/privacy model for IT systems. Getting away from the Windows/local admin culture would be a huge step, but until the most idiotic and incompetent user of a given computer system is either isolated from the ability to do anything or educated to prevent them doing dumb stuff, the computer they use must be considered compromised and all users of that computer must be considered at risk.

    1. Re:Biggest problem in IT security: ID-10-T errors by AHuxley · · Score: 4, Interesting

      Small steps. Move away from the brands that helped ie the PRISM list of willing brands and tame staff building junk systems.
      Understand how "open source" telco layers over tame telco software and hardware can save any data on entry.
      ie once your targeted all is privacy lost no matter the fancy open source app. The security services will be in every hop of any network into and out of your computer/device until they get full plain text.
      Encryption seems to be the key until your use of it shows up at an endpoint under constant surveillance. Then the individual targeting starts on the new person.
      The most easy step is to make encryption more gui, web 2.0 friendly. Then a lot more people will be flooding the net with random heavy code 24/7.
      Use once hardware would be interesting. It would stop any longterm profile, any unique hardware numbers been sent. If you then work on really good crypto to hide voice, pic, file sent, text you could kind of have a one session. Snowden hinted a bit about association (you to the press), mixed routing, the need for unattributable internet access in the 1h+ talk.
      A lot of steps to fix an internet that is now really like Tempora https://en.wikipedia.org/wiki/... and what that can do to your message and a person in the press been watched.
      The other aspect was education. A civic duty to teach, educate the wider public and press. The classic Sysadmins of the world, unite! also mentioned.

      --
      Domestic spying is now "Benign Information Gathering"
    2. Re: Biggest problem in IT security: ID-10-T errors by Anonymous Coward · · Score: 1, Insightful

      Bull shit... OpenSSL is open source and look at all the crap they found this quarter alone...

    3. Re:Biggest problem in IT security: ID-10-T errors by Razed+By+TV · · Score: 1

      I would say the bigger problem right now is that people don't care enough, period. Your average person is going to want to use whatever is cheaper, or whatever they have now, and isn't aware enough to demand something better and isn't going to want to pay for it. Existing products and services don't have a lot of incentive to improve because the customers don't care enough. As long as competition keeps the playing field level, as long as noone tightens up their security, nobody has to spend money on something that doesn't directly generate revenue.

      Consumers aren't going to drive companies to improve. It's going to take competitors trying to one up each other, to offer better service at the same price, to make people want to use their product. Until then, it doesn't matter that the consumers are infecting their computers and giving scammers their login information; the NSA is just going to be using their dirty backdoor tricks to get what they want (plus whatever exploits they copy from the scammers).

      Once you have the scammers and the NSA back on a level playing field, then you can get back to status quo where the user is the biggest unseen threat.

    4. Re: Biggest problem in IT security: ID-10-T errors by Anonymous Coward · · Score: 5, Insightful

      Bull shit... OpenSSL is open source and look at all the crap they found this quarter alone...

      They found all that *because* OpenSSL is open source. How much have they found in closed source versions of SSL libraries?

    5. Re:Biggest problem in IT security: ID-10-T errors by AmiMoJo · · Score: 4, Insightful

      It doesn't have to be perfect, it just has to increase the cost of mass surveillance to a level where it is no longer feasible. Surveillance is too cheap because much of the data is just there for collection, unprotected.

      For example, the UK government just pass emergency data retention laws that require all ISPs to continue logging the domain names of every web site every subscriber visits. If more people started using VPNs regularly that capability would become far less useful, and while I'm sure they could attack the VPN providers or crypto or even the individual target's computers the cost would be much higher than simply requiring the ISP to run a large database. They would be forced to stop bulk collection and only target people of genuine interest, which is the reasonable.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    6. Re:Biggest problem in IT security: ID-10-T errors by SuricouRaven · · Score: 2

      For a start, just convince every site to use SSL. It's possible to MITM SSL, but not on a large scale without detection. All the ISPs would be able to log is DNS lookups and IP addresses, which is still bad but not nearly as bad as being able to see individual pages accessed. Then you can start looking into possible ways to make DNS harder to monitor somehow.

    7. Re:Biggest problem in IT security: ID-10-T errors by fustakrakich · · Score: 1

      ...it just has to increase the cost of mass surveillance to a level where it is no longer feasible.

      It doesn't work that way. It becomes a call for a bigger budget and higher taxes to pay for it.

      --
      “He’s not deformed, he’s just drunk!”
    8. Re: Biggest problem in IT security: ID-10-T errors by Anonymous Coward · · Score: 0

      The problem was discovered after systems had already been exploited. So apparently the many "eyes" theory of software security failed to identify a potential problem and do something about it until the proverbial horse was already out of the barn. It's never been about the number of "eyes" on the source code it is about how many of them are actually capable of even understanding base OS level constructs and how they work across various platforms and environments. And there has been no evidence proving the number of security and general application bugs in Open Source applications are less than what you would find in closed source applications.

    9. Re:Biggest problem in IT security: ID-10-T errors by Anonymous Coward · · Score: 0

      With all the normal things a person has to worry about on a daily basis the thought of making sure the NSA could possibly, or just maybe, or potentially examine your electronic back trail is pretty low on the list. Unless of course you are plotting the overview the country and have been using g-mail accounts to synchronize attack plans. The fact everyone misses is the fact that the governments of the world are just as vulnerable to having their secrets exposed by the same methods they might employ. It used to be a lot harder to break into a physical location and rifle through the filing cabinets and Xeroxing all the secret government documents outlining how they plan to take over the world. Comparing government secrecy today against government secrecy 60 years ago will show that today's government is the most transparent that it has been since it's founding. The biggest fuss to day is people confusing personal Anonymity with personal Privacy. The government has always collected and stored personal information since long before the internet age. Tax Returns and Drivers Licenses provide all the information a government would need to track you down if they were interested in finding you. Add in marriage licenses, property registrations, phone bills, SSN, and other similar types of personal information and your an open book should the government get interested in you personally. But today we have people who would rather preach hysterics about their rights being violated on an hourly basis and they are being tracked, monitored, or watch 24/7 by the government secret police. They tend to ignore that there has been no evidence that the government has been persecuting or disappearing people all because they got caught in a government surveillance scheme. These geniuses throw around words like Stazi, KGB, and NAZI's but fail to mention that people frequently were disappeared or out right killed and these services never tried to hide their actions because they would have lost their intimidation and fear factor they relied on to keep people in line. There are no corresponding services operating in the US today by a long shot.

      Oh, and Snowden's technical skills consisted of using his admin passwords and the stolen passwords of co-workers to "hack" the information. He should have limited himself to releasing only domestic related data and left the foreign intelligence programs alone. It's right he should be pardoned or have just a slight wrist slap for the domestic related releases but the foreign data releases makes him guilty of violating the espionage act and deserves what ever punishment he gets.

  5. Hero by Anonymous Coward · · Score: 0, Redundant

    Hero

  6. This could totally work out by SpzToid · · Score: 2

    Edward Snowden certainly has name recognition in the security space, which in branding terms equals big money. He's got his share of wild and crazy times overseas doing various hijinx not always on the up and up, sorta just like other security specialists of an earlier generation. Sure, in terms of branding alone Snowden could easily become the next McAfee, and he's still very young!

    And isn't as if they weren't both wanted on international warrants either; and street cred. does sell sneakers.

    --
    You can't be ahead of the curve, if you're stuck in a loop.
    1. Re:This could totally work out by Anonymous Coward · · Score: 0

      Credibility with whom? I'll grant you he has name recognition in general, but security? I'm not disputing what you're saying because you probably describe some of his biggest fans here, but personally I don't see how someone grabbing and dumping classified info gives him any credibility on anything (other than, perhaps, grabbing and dumping secrets).

      But, to your larger point, apparently Bob Villa has a hard time knowing which end of a hammer to hold, but he became America's best-known general contractor. I recall reading after that woman barricaded herself in her home against a home invader, then ended up shooting him a number of times, after her (mostly Fox News) media exposure, she became a consultant and expert for setting up neighborhood watch programs. Branding can certainly give one expertise.

  7. Re:Don't you want to be a traitor too? by some+old+guy · · Score: 4, Funny

    Don't be a police state fan boy, and learn to spell "cretin", cretin.

    --
    Scruting the inscrutable for over 50 years.
  8. Re:Don't you want to be a traitor too? by ChristW · · Score: 5, Insightful

    If making people realise that their basic rights are being trampled makes me a traitor, then I'd want to be a traitor any day...

    --
    09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
  9. Re:Don't you want to be a traitor too? by Anonymous Coward · · Score: 1

    Ain't you worried that there is someone with an erect penis monitoring your private communications inside an NSA control room?

  10. So Slashdot... by Anonymous Coward · · Score: 5, Insightful

    "You in this room, right now have both the means and the capability to improve the future by encoding our rights into programs and protocols by which we rely every day,"

    Looking at you Slashdot.

    When are we going to have access to this site with https? You can stop pushing down out throats your fucking annoying beta and do something useful for everybody instead.

    1. Re: So Slashdot... by Anonymous Coward · · Score: 1

      You mean https that's built on OpenSSL?

    2. Re: So Slashdot... by Anonymous Coward · · Score: 0

      SSL. Not OpenSSL.

    3. Re: So Slashdot... by Anonymous Coward · · Score: 1

      A protocol isn't built on an implementation. Use a version of OpenSSL that doesn't have known bugs or use another SSL implementation if you want to.
      Claiming that HTTPS is unsafe just because one implementation has bugs is like saying that C is slow because someone wrote a bad compiler once.

    4. Re: So Slashdot... by Anonymous Coward · · Score: 0

      You mean https that's built on OpenSSL?

      Of all the components that have received the MOST scrutiny from the entire community recently, I'd probably trust a patched OpenSSL implementation over a lot of other options.

    5. Re:So Slashdot... by ArcadeMan · · Score: 1

      Do something useful? Do you have any idea what it would do to Dice's profits?

    6. Re:So Slashdot... by Anonymous Coward · · Score: 0

      Yes. It's all about money. Filthty lots of money.

    7. Re:So Slashdot... by AmiMoJo · · Score: 1

      At this point I'm thinking that the NSA or GCHQ asked them not to implement HTTPS. What other reason could there be for not taking the simple, low cost, minimal action required to enable it? Soylent News, which runs on the same code base, supports it.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    8. Re:So Slashdot... by Anonymous Coward · · Score: 1

      And IPv6 access while you are at it.

    9. Re:So Slashdot... by Anonymous Coward · · Score: 0

      That's a laughable idea. TPTB don't care about your hot grits posts.

    10. Re: So Slashdot... by Anonymous Coward · · Score: 1

      Use a version of OpenSSL that doesn't have known bugs

      Bwa ha ha ha ha ha ha ha!
      Yeah, the guys who are making LibreSSL probably wish you could be doing that. If they weren't compelled to make a decent SSL implementation, they could probably focus more on things like the anti-botnet research of the Hail Mary cloud. But, since OpenSSL is known to not patch bugs, they've decided that this other work is necessary.
      Please don't refer to an OpenSSL version that doesn't have known bugs. Just because one super-critical bug has been identified and addressed does not mean that all other known security problems have been fixed.

    11. Re:So Slashdot... by Anonymous Coward · · Score: 0

      And you can't post on soylent news without first logging in.

    12. Re:So Slashdot... by Opportunist · · Score: 1

      I'm fine with http. I'm just stating my opinion. If that is grounds to lock me up, you can as well lock me up for then I'm in a prison already.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  11. Technology is only a small part of the problem by DoofusOfDeath · · Score: 4, Informative

    As long as the citizenry tolerates and sometimes even roots for the government's violation of civil rights, everything including the technology is just details.

    The existence of a decent open-source router can't do much against a U.S. National Security Letter.

    1. Re:Technology is only a small part of the problem by Anonymous Coward · · Score: 0

      The existence of an I2P router can. The letter has to be addressed somewhere.

    2. Re:Technology is only a small part of the problem by SuricouRaven · · Score: 1

      End-to-end encrypted communications can.

    3. Re:Technology is only a small part of the problem by Anonymous Coward · · Score: 0

      There is no such thing as "tolerating" coercive authority. You either obey, or you are dealt with through coercion (and ultimately deadly force, if you attempt to protect yourself).

    4. Re:Technology is only a small part of the problem by Anonymous Coward · · Score: 0

      That is why we have warrant canaries. Set one up.

    5. Re:Technology is only a small part of the problem by Sloppy · · Score: 1

      It's a small part, but it's a part. I think Snowden has done his fair share of trying to inform laymen and stir up giving-a-fuck. If he wants to switch to working on tech, he could accomplish nothing and still come out far ahead of the rest of us. ;-)

      The existence of a decent open-source router can't do much against a U.S. National Security Letter.

      While we certain should care enough to force our government to stop being our adversary, there will always nevertheless be adversaries. You have to work on the tech, too. Even if you totally fixed the US government, Americans would still have to worry about other governments (and non-government parties, such as common criminals, nosey snoops, etc), where you have no vote at all. You will never, ever have a total social/civic solution which relies on, say, 4th Amendment enforcement to keep your privacy. I'm not saying your chances are slim; I'm saying they're literally 0%.

      Furthermore, getting our tech more acceptable to layment acually would correct some of the problems inherent with NSLs, improving the situation even in a we-still-don't-give-a-fuck society. If you do things right, then the person they send the NSL to, is the surveillance target. The reason NSLs (coercion with silence) works is that people unnecessarily put too much trust into the wrong places.

      For example, Bob sends plaintext love letters to Alice, so anyone who delivers or stores the love letters, can be coerced into giving up the contents. OTOH if they did email right, then if someone wanted to read the email Bob sent to Alice, they'd have to visit Bob or Alice. That squashes the most egregious part of NSLs, where the victim doesn't even get to know they're under attack.

      That's true whether we're talking about email, or even if Bob and Alice get secure routers and VPN to each other. One of them gets the NSL ordering them to install malware on their router.

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  12. Is this irony? by Anonymous Coward · · Score: 0

    Speaking out about anti-surveillance on a Google platform, who makes money collecting information on people?

  13. New SSL root certificate authority by johnjaydk · · Score: 2, Interesting

    A nice step ahead would be the establishment of a new set of root certificates and an accompanying authority that signs other peoples certificates. All located in a country that doesn't play ball with NSA and other thugs.

    This would do a lot to dampen the routine man-in-the-middle we see these days.

    --
    TCAP-Abort
    1. Re: New SSL root certificate authority by Anonymous Coward · · Score: 1

      We have already have them. We need Google and mozilla to stop being little bitches and bending over for the CA's and security services and implent DANE already in their browsers. I don't buy for a fucking minute that they don't implement it because it's not common enough yet...

    2. Re:New SSL root certificate authority by Sloppy · · Score: 2

      A nice step ahead would be the establishment of a new set of root certificates...

      The lesson of CA failure is that there shouldn't be root authorities. Users (or the people who set things up for them, in the case of novices) should be deciding whom they trust and how much, and certificates should be signed by many different parties, in the hopes that some of them are trusted by the person who uses it.

      If you want to catch up to ~1990 tech, then you need to remove the "A" in "CA."

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    3. Re:New SSL root certificate authority by johnjaydk · · Score: 1

      If you want to catch up to ~1990 tech, then you need to remove the "A" in "CA."

      Thanks for the insult. It hardly stung. I expect you to start the project shortly. I'll gladly donate to it on kickstarter.

      --
      TCAP-Abort
    4. Re:New SSL root certificate authority by IamTheRealMike · · Score: 1

      There are already plenty of CA's in countries that are not under US jurisdiction. However, so far the CA's that issued bad certs were all outside the USA, and appear to have only done so because they got hacked and not because they were e.g. forced to by court order.

      Unless you have a magical solution to hacking I don't think your new root CA would solve much.

      Additionally, citation needed for "routine man in the middle". SSL MITM has been studied by academics at scale. They did not find evidence of much. Governments don't need to MITM SSL for as long as users browse non-SSLd sites like Slashdot and browser exploits exist.

    5. Re:New SSL root certificate authority by Sloppy · · Score: 1

      Thanks for the insult. It hardly stung.

      Unless you worked at Netscape in the mid-1990s, no insult was intended.

      All I meant is that by the very early 1990s, we (and by "we" I mean people smarter than me; I was clueless at the time) had a pretty good idea that CAs wouldn't work well outside of real power hierarchies (e.g. corporate intranets). But then a few years later the web browser people came along and adopted X.509's crap, blowing off the more recent PKI improvements, in spite of the fact that it looked like it wouldn't work well for situations like the WWW.

      Unsurprisingly, it didn't work well. Organizing certificate trust differently than how real people handle trust, 1) allows bad CAs to do real damage, and 2) undermines peoples' confidence in the system.

      A very nice way of saying this, is that in hindsight, the predicted problems are turning out to be more important than we thought most people would care about. ;-) It's almost as though now (no fair! you changed the requirements!!) people want SSL to be secure.

      Keeping the same organization but with new faceless unaccountable trust-em-completely-or-not-at-all root CAs won't fix the problem. Having "root CAs" is the problem, and PRZ solved it, over 20 years ago.

      I expect you to start the project shortly.

      It's a little late to start, but I do happen to still be running an awful lot of applications (web browser being the most important one) which aren't using it yet.

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  14. Secure technology by PopeRatzo · · Score: 3, Funny

    I'm going back to my 1942 Corona typewriter with the "t" slightly raised.

    --
    You are welcome on my lawn.
    1. Re:Secure technology by ArcadeMan · · Score: 3, Funny

      And why do you think the "t" is slightly raised, hum? Spyware, that's why.

  15. Maybe he can help hide BUK launches by swb · · Score: 0, Flamebait

    Even if you grant Snowden every consideration, how can he have any credibility as long as he's in Russia?

    1. Re:Maybe he can help hide BUK launches by ArcadeMan · · Score: 1

      Because in Soviet Russia, something something Dark Side.

    2. Re:Maybe he can help hide BUK launches by Anonymous Coward · · Score: 0

      He's exactly where the US government wanted him to be...nice and safe. If his passport wasn't canceled, he would've ended up in a place where a discrete bribe would quietly eliminate him from the face of this earth (Breaking Bad barrel-of-acid-style). Everyone would just assume he covers his tracks very well...

  16. Who will be auditing Snowden's code? by cold+fjord · · Score: 0

    So, who will be auditing Snowden's code? I wouldn't even consider using anything he wrote without independent third party audits .... lots of audits of the code, design, algorithms, everything. And no binaries that he builds.

    Imagine the evasive power of the dual or triple functionality achieved by some of the Obfuscated C content entries combined with the subtle designs of Russian government cryptographers. No threat there, no sir.

    --
    much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
    1. Re:Who will be auditing Snowden's code? by luis_a_espinal · · Score: 1

      So, who will be auditing Snowden's code? I wouldn't even consider using anything he wrote without independent third party audits .... lots of audits of the code, design, algorithms, everything. And no binaries that he builds.

      Imagine the evasive power of the dual or triple functionality achieved by some of the Obfuscated C content entries combined with the subtle designs of Russian government cryptographers. No threat there, no sir.

      Can he actually write code? And I mean code at the level of sophistication required for the type of functionality he is calling for? What he is calling for is way beyond the realm of sysadmin-related programming.

    2. Re:Who will be auditing Snowden's code? by SuricouRaven · · Score: 1

      Probably not, but he at least know it and instead calls upon those of greater ability in that area to rally to his cause.

    3. Re:Who will be auditing Snowden's code? by fustakrakich · · Score: 1

      See? Now I know you're full of it.. When have you ever seen anything subtle from the Russians?

      --
      “He’s not deformed, he’s just drunk!”
    4. Re: Who will be auditing Snowden's code? by Anonymous Coward · · Score: 0

      No, he can't. He is so stupid that he admitted that he once voted for a Republican. That proves there is no hope that he can think logically. Their kind is so anti-science.

  17. Re:Don't you want to be a traitor too? by Dins · · Score: 1

    I didn't post this, but I think most of the replies/mods missed this dripping sarcasm...

  18. Re:Don't you want to be a traitor too? by Dins · · Score: 1

    (My post above was in reference to the OP, not the post I replied to.)

  19. Re:Don't you want to be a traitor too? by dotancohen · · Score: 1

    I hate to admit it, but I just happen to have an erect penis reading your public communications on Slashdot.

    To be fair, it was erect before I opened the page. I think the SEO consultant sitting next to me is ovulating.

    --
    It is dangerous to be right when the government is wrong.
  20. It is about getting out. by Max_W · · Score: 1

    Privacy is about getting out. Put on light t-shirt, thin-sole running shoes, light shorts and go with your partner to a park, a stadium, etc.

    Or go to a beach for a swim.

    Have a meaningful private conversation while running, walking or swimming. Speak in a calm quiet voice, not louder than necessary.

    So getting out is good not only for health, but for privacy too. Besides, it is much safer to run together or to walk together.

    1. Re:It is about getting out. by messymerry · · Score: 1

      The parks are full of bugs...

      --
      Dear Microlimp: I give you 2 valid product keys for win7 and you reject both of them. Piss off you wankers!!!
    2. Re:It is about getting out. by Max_W · · Score: 1

      It is really funny :o)

  21. Re:Don't you want to be a traitor too? by ArcadeMan · · Score: 1

    Alright, but which day do you think it's going to be?

    Signed,
    your friends at the NSA.

  22. Re:Don't you want to be a traitor too? by ArcadeMan · · Score: 1

    cretin
    krtn / noun
    1. informal, offensive
    a stupid person (used as a general term of abuse).
    2. MEDICINE, dated
    a person who is deformed and mentally handicapped because of congenital thyroid deficiency.

    Well, if he is a cretin, you shouldn't criticize him. It's not nice to criticize the mentally handicapped.

  23. Re:Don't you want to be a traitor too? by cold+fjord · · Score: 0

    ... I'd want to be a traitor any day...

    Lets pick a specific day: April 1, 1940

    On that day Bletchley Park was reading the "email" of the German government, having broken the Enigma code - a fragile achievement that could fairly easily be foiled, perhaps permanently .... if the Germans knew about it. As a result of breaking that code, and keeping it secret that it had broken the code, the rights of the German government and people were trampled. The trampling of the rights of the German government and people in that fashion meant that Britain would not be starved into submission by submarine warfare, and ultimately the Allies would win the war. That meant that the trampling of the rights, including the right to live, of the people of Western and Eastern Europe by the then Nazi German government would come to an end.

    Beyond that, the ability of the UK and US to read Enigma type machine encrypted messages carried over into the Cold War (which at various points nearly flared into a shooting war, including nuclear war) and played a role in helping the West obtain the intelligence necessary to defeat Soviet Communism which killed far more people than the Nazis did.

    So, would-be traitor, is that still a good day for treason for you, knowing that Britain would likely have been starved into submission in WW2, the Nazis might have held on, and Soviet Communism might have lived on indefinitely? Many millions more would have been killed, several genocides would likely have been completed, we might still be faced by both Nazi and Soviet regimes, but nobody would be trampling on the rights of the German people by reading their encrypted mail. But I take it you're OK with that since it is "any day," right?

    Just curious.

    Isn't there an April 1st coming next year? And the year after that? What battles might be lost then?

    --
    much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
  24. Stop Snowden first ... by CaptainDork · · Score: 1

    Hell, he walked in and got the stash and fled the country. Manning had already done a similar heist before this.

    So, we've got minions with access to sensitive data and can't stop them. The government needs to audit itself ... again.

    It does no good to wrap this stuff up in a cloaking device if space cadets can glomp and run.

    --
    It little behooves the best of us to comment on the rest of us.
    1. Re:Stop Snowden first ... by slimshady76 · · Score: 1

      Unless you are trying to be sarcastic, I'd say you are one the remaining ones who still collect their checks from the government and didn't flee... yet...

  25. Irony or blowback? by kevlar_rat · · Score: 0
    TOR, of course, was created by the US gov't to protect users against dictatorships and now is mostly used to protect against the US gov't. See also the webertarian manifesto:

    The webertarian project aims to create software that makes tyranny mathematically infeasible.

  26. "Develop" or "Instigate the development of"? by bsDaemon · · Score: 2

    Nothing I have read about Snowden indicates that he is actually some sort of uber-hacker or capable of the type of software engineering that this proposal would entail. Is his plan just to use his name to fundraise (In bit coin, I guess. I doubt many people are stupid/brave enough to attach their name to a donation towards anything to do with this guy) and attract talent, or is he honestly going to try and release code himself, which will probably be of poor-to-average quality and expect the world to adopt it?

    I mean, let's be honest: Either way, whether he's going to just try and brand the stack or contribute, we have technologies that are perfectly good (that is, however, not to say perfect) already -- its just they aren't particularly widely deployed. How many organizations are running IPSec internally, other than just for site-to-site VPN tunnels? How many organizations are deploying DNSSec outside of governments and the military? How many organizations are using PGP or similar asymmetric encryption between employees? Making it easier might help, but chances are that the vast, vast majority of individuals aren't going to jump on any of these technologies in any great numbers unless they are mandated to (like at work, where they don't have a choice), but it isn't as if the government is going to make it a requirement that you try and "spy proof" your computer and communications.

    1. Re:"Develop" or "Instigate the development of"? by m00sh · · Score: 2

      Nothing I have read about Snowden indicates that he is actually some sort of uber-hacker or capable of the type of software engineering that this proposal would entail. Is his plan just to use his name to fundraise (In bit coin, I guess. I doubt many people are stupid/brave enough to attach their name to a donation towards anything to do with this guy) and attract talent, or is he honestly going to try and release code himself, which will probably be of poor-to-average quality and expect the world to adopt it?

      All that counts is that Snowden has the balls and integrity that is so lacking in the "uber-hacker" department. You can't threaten Snowden, you can't bribe him. An uber-hacker, you can buy him out or scare him.

      Anyways, you don't uber-hackers to develop security software. The encryption algorithms are university research level stuff and as long as you understand the basics of it, you're fine. The rest is just writing code around it that a decent programmer should be able to handle well.

    2. Re:"Develop" or "Instigate the development of"? by Anonymous Coward · · Score: 0

      Exactly this. If all that was needed was uber-hacking skills, this would be a non-issue.

      What is needed is the spark to light the fire to give those uber-hackers a challenge or goal that is worty of their talents.
      After all, there exists no better bragging rights than those whose work can deny the will of entire governments.

      " I wrote a program that stole online banking credentials "

      " I wrote a program that drove the US Government crazy because they couldn't easily spy on everyone anymore "

      Which would you rather be remembered for ?

    3. Re:"Develop" or "Instigate the development of"? by SuricouRaven · · Score: 1

      Or an equally good brag: "I wrote a program that's illegal in China."

      All I've written are two programs illegal in the US - but that's because one infringes on a software patent, and the other is a circumvention device under the DMCA. It's also a trivial program consisting of about five lines of C, but that doesn't really matter.

    4. Re: "Develop" or "Instigate the development of"? by Anonymous Coward · · Score: 0

      Considering he admitted to once voting for a Republican, he is a moron. I bet he can only barely read like the rest of their kind.

    5. Re:"Develop" or "Instigate the development of"? by IamTheRealMike · · Score: 1

      Nothing I have read about Snowden indicates that he is actually some sort of uber-hacker

      Except the stuff about how a 29 year old completely pwnd the NSA, probably the most technically sophisticated part of the US Government there is?

      Sheesh. Your standards are high. What would it take, exactly?

      Additionally, just because you have read nothing about his programming skills doesn't mean he has none. He once mentioned finding XSS holes in some CIA app so apparently he is good enough to do that.

    6. Re: "Develop" or "Instigate the development of"? by Anonymous Coward · · Score: 0

      I met a couple that could read well. Just because they're a Republican, doesn't prove that they can't read. It only makes it more likely than not.

  27. Re:Don't you want to be a traitor too? by AHuxley · · Score: 1

    How many more wars?
    As for 'if the Germans knew about it." is the classic understanding of ww2 crypto. Germany trusted the machine, upgraded it a bit and had all its spies turned.
    Lets take Normandy. Army Group B has some idea, Pz Lehr Division was moved, Germany had a spy near the British ambassador to Turkey, the Royal Navy had lost aspects to its low level codes, British railroads codes had been lost by late 1943, the German airforce saw changes in US and UK practice traffic, US Transport Command lost its codes, US M-209 and M-138 strip traffic was not totally secure, the A-3 A-3 speech scrambler was not so great, the Polish government in exile had code issues, a few German spies still existed in Sweden and Portugal, SIS-SOE agents where under watch in France
    ie Germans moved units to Normandy.
    As for "Enigma type machine encrypted messages" post ww2, the Soviet Union had a good understanding of the UK via humans. The Soviet Union was also moving to much tighter one time pad use as it fully understood its code reuse was a huge fault. But they had so much intel to send, they had few options but to risk it.
    If govs cant get to one main code, they go for the weak ones, they go for people, they go for the weak codes that get used all day in sloppy ways.
    For all the Enigma faith, Germany seemed to understand something was not perfect and worked hard to try and stay ahead.
    New rotors, wheel permutations, random indicators, protections to counter cribbing, CY procedure, Uhr device, the UKW-D reflector but it all failed as cryptologic security was so split up. But people keep the old WW2 stories about Germany, Russia, Finland, Australia, Japan code work as just been all safe or all broken.
    Post ww2 is filled with new advances and attempts by the UK and US. All very interesting, great in the new history books as more papers are released.
    So for that Enigma vision we all give up our rights via an oath to authority for generations?
    The talks did cover the authority and rights, press aspect in the last 30 mins.

    --
    Domestic spying is now "Benign Information Gathering"
  28. Russia and China will appreciate his work by Anonymous Coward · · Score: 0

    So now, he is busy helping Russia? Hmmm.

    1. Re:Russia and China will appreciate his work by Anonymous Coward · · Score: 0

      He already helped Russia and China far more than he realizes. What he gave to them will make their own spying apparatus far more effective than it was.

  29. Been @ it for YEARS (& more speed too)... apk by Anonymous Coward · · Score: 0

    Vs. DNS request logs in hostsfile hardcodes (faster than remote dns, shores up Kaminsky flaw w/ less moving parts complexity room 4 breakdown + electric power use (vs. local DNS)):

    APK Hosts File Engine 9.0++ 32/64-bit:

    http://start64.com/index.php?o...

    (Details of benefits in link)

    Summary:

    ---

    A.) Hosts do more than:

    1.) AdBlock ("souled-out" 2 Google/Crippled by default)
    2.) Ghostery (Advertiser owned) - "Fox guards henhouse"
    3.) Request Policy -> http://yro.slashdot.org/commen...

    B.) Hosts add reliability vs. downed/redirected dns (& overcome redirects on sites, /. beta as an example).

    C.) Hosts secure vs. malicious domains too -> http://tech.slashdot.org/comme... w/ less added "moving parts" complexity/room 4 breakdown,

    D.) Hosts files yield more:

    1.) Speed (adblock & hardcodes fav sites - faster than remote dns)
    2.) Security (vs. malicious domains serving malcontent + block spam/phish & trackers)
    3.) Reliability (vs. downed or Kaminsky redirect vulnerable dns, 99% = unpatched vs. it & worst @ isp level + weak vs Fastflux + dynamic dns botnets)
    4.) Anonymity (vs. dns request logs + dnsbl's).

    ---

    * Hosts do more w/ less (1 file) @ faster levels (ring 0) vs redundant inefficient addons (slowing slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ os, & 1st net resolver queried w\ 45++ yrs.of optimization).

    * Addons = more complex + slow browsers in message passing (use a few concurrently & see) & are nullified by native browser methods - It's how Clarityray is destroying Adblock.

    * Addons slowup slower usermode browsers layering on more - & bloat RAM consumption too + hugely excessive cpu use (4++gb extra in FireFox https://blog.mozilla.org/nneth...)

    Work w/ a native kernelmode part - hosts files (An integrated part of the ip stack)

    APK

    P.S.=> "The premise is quite simple: Take something designed by nature & reprogram it to make it work for the body rather than against it..." - Dr. Alice Krippen: "I am legend"

    ...apk

  30. ZeroKnowledge by MouseR · · Score: 1

    So now I guess ZeroKnowledge was 16 years too early. I remember laughing at it.

    I still don't care wether NSA or other idiots read my mail for I have nothing to hide. But the prospect of ill-advised policy enforcer's ability to use otherwise benign data as scapegoating is irritating.

  31. Link to Snowden hangout video by NotInHere · · Score: 1
  32. Vote Snowden / Binney 2016! by Bob9113 · · Score: 1

    Here's my latest Snowden / Binney 2016 bumper sticker art, suitable for printing at 2.75" x 5" cropped size plus a .125" bleed, 300 DPI, on vinyl:
    PNG
    Vector (LibreOffice Draw)

    This is my original artwork, CC BY-NC-SA, so print a pile and spread them around if you like. I use psprint.com, and I recommend searching "vinyl bumper stickers" on DuckDuckGo, where psprint is usually running a coupon in the search results. I haven't received the color proofs for this version yet, but these are corrected from a previous batch and should be pretty good.

    Disclaimer: I have no affiliation with DuckDuckGo or PSPrint, and Snowden/Binney is (perhaps unfortunately) neither a real nor a realistic campaign. This is just for giggles.

  33. Re:Secrets by Anonymous Coward · · Score: 0

    Sad, but not surprising, that you got modded down for your appropriately on-topic post. Speak not against the Snowden, for it is fraught with peril and fanbois down-modding.

  34. ....In Russia by gelfling · · Score: 1

    Oh please, Eddy, shut the fuck up.

  35. Read-Only Computing? by Anonymous Coward · · Score: 0

    One of the angles of privacy violation is by accessing data on the local machine. Is there any particular OS distro that could operate truly read-only, writing only to RAM for the current session?

    Could it work in metadata-free secure writes to a storage device if you wanted to store an acquired file?

  36. Re:Don't you want to be a traitor too? by Anonymous Coward · · Score: 2

    You seem to be comparing two searches:
    1) Done on ALL civilians, including people who were suspected of nothing
    2) Specifically targeting official transmissions with probable cause to expect genocide

    I don't know about the other would-be traitors, but the problem I have isn't with intercepting any communications of any kind; it's with searching innocent people. I'm perfectly OK with the NSA hacking actual terrorists.

  37. Re:Don't you want to be a traitor too? by Opportunist · · Score: 1

    Would July 14th be ok?

    The breeze around your neck that you feel shouldn't worry you...

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  38. Oh the irony... by Anonymous Coward · · Score: 0

    Meanwhile you can bet his ass is being surveilled magnitudes more by his gracious hosts than by anything when he was a U.S. citizen.

  39. snowden my favorite traitor by Anonymous Coward · · Score: 0

    gotta just love his hypocrisy

  40. Not going to happen. by ops2048 · · Score: 1

    I applaud and vigorously support Mr. Snowden's suggestion that our rights MUST (my emphasis) be encoded into the programs and PROTOCOLS on which we rely every day. I seriously and sincerely doubt however that anyone, let alone the entrenched interests who construct and maintain the Internet, will in any way be moved to action.

    As instance I cite the farce that is known as email. Architectural and design decision were made which did not consider the mass adoption of email by billions. Nor were the possibilities of incompetent, untrusted and malevolent actors considered. As a small illustrative example. Why, aside from the godlike feeling of absolute power conferred, do these servers allow sysadmins (or anybody who has hacked their account) to view or search the CONTENT of emails. The mail server programs implementing these flawed protocols were and continue to be kludges requiring near genius levels of competence to correctly configure and maintain.

    These flaws were and are directly responsible for the tsunami of email spam and malware which began all of twenty years ago. The response was NOT to realize that the protocols were flawed and that serious refactoring was required. Instead castles of sand were built on top of quicksand. Heuristic Bayesian spam filters I'm looking at you here. This non response has directly enabled hundreds (if not perhaps thousands) of millions of dollars worth of damage and computer fraud yet still the protocols and programs were and still are not redesigned !!!

    One could go on and on with similar critiques of virtually every piece of tcp/ip's fundamental infrastructure. IPV6 is not a counter example as some twenty years later it formats approximately four percent of internet traffic. These, not merely, and in addition to, the presence or absence of cryptography, I believe, are the privacy busting facts to which Mr Snowden alludes and refers.

    If such serious monetary damage cannot impel substantive action this poster asserts that it is difficulty to imagine Mr Snowden's totally laudable revelations and prescriptions having any effect whatsoever.

  41. The hackers on planet Earth? by linearZ · · Score: 1

    I'm guessing, with the crowd he was speaking to this kind of project would be open source.

    I've taken the time to watch some of the Chaos Computer Club videos on cryptography, which I think is loosely connected with this HOPE crowd. They seem like a very sharp bunch. I would certainly take my chances on anything they've hammered on.

    --
    Revolution is the opium of the intellectuals.
  42. Snowden, what a pathetic joke by Anonymous Coward · · Score: 0

    Did they get you to trade your heroes for ghosts?

  43. Re: Don't you want to be a traitor too? by Anonymous Coward · · Score: 0

    Let's pick another day: 9 November 1989.

    If the total surveillance state that you desire had been functional back then, the Berlin Wall would never have fallen, and Communism would still be ruling the USSR. You owe the fall of Communism to the failure of the surveillance state.

  44. Startpage Re:So Slashdot... by Anonymous Coward · · Score: 0

    "When are we going to have access to this site with https? You can stop pushing down out throats your fucking annoying beta and do something useful for everybody instead."

    You can use Startpage's free HTTPS proxy to access sites like Slashdot.

  45. Re: Don't you want to be a traitor too? by Anonymous Coward · · Score: 0

    If the surveillance state had been possible back in 1776 there would be no United States.

  46. What does he want to look at? by Anonymous Coward · · Score: 0

    One would have to question exactly what kind of material he proposes trading. Would we want kiddie fiddlers transferring data?
    Really who has mass surveillance harmed?
    http://www.dailymail.co.uk/news/article-2671467/Almost-300-pedophiles-including-teaching-assistant-retired-sheriffs-deputy-arrested-month-long-To-Catch-Predator-style-sting-operation.html