Sorry Richard. You were right. Thank you for your unwavering commitment to freedom.
Or what about any of these groups?
http://en.wikipedia.org/wiki/List_of_intelligence_agencies
Which one(s) do you want to be the very best at this? Do you think the US is? And why?
He's just rms at gnu dot org
In the case of Microsoft there is still no proof/evidence for a NSA backdoor in Microsoft Windows (and would that not show up in the leaked Win2000 source code?) And even the Snowden documents do not allege that (please correct me if I am wrong).
What the Guardian claimed was that Microsoft helped to give access to Outlook.com. The NSA is mostly interested in online services. And this is a far bigger issue, because there is no real alternative for that. Because even if you compile your own Linux distribution you still use Google Gmail (Ha!) or visit this hacker news forum, and you have to trust a third party with your data. And even if that trust is merited the NSA can just slurp up the datastream in the Internet provider datacenters.
> In one case, after the government learned that a foreign intelligence target had ordered new computer hardware, the American manufacturer agreed to insert a back door into the product before it was shipped, someone familiar with the request told The Times.
> At Microsoft, as The Guardian has reported, the N.S.A. worked with company officials to get pre-encryption access to Microsoft’s most popular services, including Outlook e-mail, Skype Internet phone calls and chats, and SkyDrive, the company’s cloud storage service.
Please read.
http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet...
The same reason people trust the Dollar as a reserve currency. Yeah, it sucks, but better than any of the alternatives.
Fortunately, there exist open-source/public-domain alternatives for security products. (Doesn't mean that contributors can't be coerced with the equivalent of a Nation Security Letter, though.)
How long until we find out that the "humanitarian aide" so heavily pushed WRT Syria, is an IMF debt loan requiring a central bank and fealty to the US dollar is the primary reason for the opportunity war being sought.
I was talking to a potential client 2 days ago, they provide SaaS to a number of clients, and up until now this has always included data storage.
One of the projects we discussed involved, for a specific customer, moving data storage off the current (US based) server and onto their customer's servers in their own country.
Anecdotal, but still I am really small fish on the far edge of the world, I cannot imagine the reaction where the bigger fish are swimming.
The difference between 'suspected that our confidential data may be compromised by a third party if you believe all the conspiracy theories' and 'know absolutely that our confidential data is being compromised by a third party as we speak' turns out to be pretty big, and worth a lot to international companies who value the commercial value of their private data.
And did the whole security industry really not know what was going on? That's hard to believe. In general, I feel like my trust in the ecosystem has just been nuked from orbit.
Clearly a lot needs to be done to fix this. What kind of non-violent protest works? What kind of civil disobedience works? What are the best organic ways of organising people without getting shut-down? Do we have technology that is still secure, even if CAs are broken or even if hardware is backdoored?
"The question is," said Alice, "whether you can make words mean so many different things."
"The question is," said Humpty Dumpty, "which is to be master—that's all."
If Schneier has inside information, it'd be nice to get a simple, straightforward, article describing what exactly is known about the NSA capabilities. Various people speculating doesn't provide a clear picture of anything.
But if there's solid evidence, why don't they publish it? If they really have broken into Google, then publish the details. I'm sure Google would like to know, too. If they've backdoored Windows, Office, VLC, whatever - same thing. Or are we talking more stuff like "we knew Debian couldn't generate keys properly"?
If it's just stating that the NSA possesses heavy offensive capabilities, well, yeah, you'd expect that. Actual evidence of an NSA-backdoored common software or hardware would be a major story. (Not saying it's not possible, just speculating gets us no where.) If Schneier and Greenwald want to be taken seriously, then step up and speak out. Generic "the NSA is powerful" isn't much help.
First, it has kept the NSA in the headlines for almost three months now (quite a feat when you consider our cultural attention span is usually measured in fractions of days).
Second, it has let officials make denials and give reassurances come back to haunt them and tarnish then credibility when further disclosures are made (consider that Senator Feinstein, chair of the Intelligence Committee supposedly providing Congressional oversight of these surveillance programs, who spent weeks claiming said oversight was quite robust, admitted to not knowing about the internal NSA audit finding thousands of privacy violations).
I'm pretty confident there will be more disclosures. But given the realities of the news cycle and the political process, they are much more effective if they happen gradually.
I don't know much about The Guardian, but The Times, for better or for worse, has always self censored based on its own perceptions of the trade offs. It considers itself a responsible part of the establishment -- the loyal opposition if you will. You aren't going to see a wikileaks-esque dump from them.
> Intelligence officials asked The Times and ProPublica not to publish this article, saying that it might prompt foreign targets to switch to new forms of encryption or communications that would be harder to collect or read. The news organizations removed some specific facts but decided to publish the article because of the value of a public debate about government actions that weaken the most powerful tools for protecting the privacy of Americans and others.
I love his attitude towards this, however. He's right, we need massive civil disobedience, we need whistleblowers, and we need everybody who can contribute, to help dismantle this surveillance state apparatus.
I just wish I knew more about cryptography now, so I'd be in a position to do more to help.
Maybe there should be some canon of crypto fundamentals, and everyone ought to buy a set, as protest / funding for research / "I'm Spartacus"!
Though at this point, I also wonder if he needs to publish a list of some kind of hash of the pages' images, so readers can verify the NSA hasn't been borking it at the printer.
That said, does someone have a brief rundown of the details from a technical perspective, so I don't have to read through several long news articles mostly filled with elementary explanations of basic concepts?
"Prefer symmetric cryptography over public-key cryptography."
I always thought asymmetric and public key was safer, so could someone clue me in on this?
"Even agency programs ostensibly intended to guard American communications are sometimes used to weaken protections. The N.S.A.’s Commercial Solutions Center, for instance, invites the makers of encryption technologies to present their products and services to the agency with the goal of improving American cybersecurity. But a top-secret N.S.A. document suggests that the agency’s hacking division uses that same program to develop and “leverage sensitive, cooperative relationships with specific industry partners” to insert vulnerabilities into Internet security products. "
- To eavesdrop on the communications of foreign entities.
- To protect our own government from foreign entities that are doing the same.
It is the latter directive that has provided SELinux and AES.
Magnet link of the alleged software used to break encryption methods: magnet:?xt=urn:btih:f8a942ccff260f7b9035bbf3b8af5c3013e21097&dn=Parabon+Leaks