VPN will not protect your privacy, as VPN providers are monitored by state police and VPN protocols have been broken and backdoored by intelligence agencies (as disclosed in the Snowden Documents).
How do they do that? Do you understand how TLS works? They would have to MITM every session, and it would be immediately obvious as the key exchange wouldn't line up.
Unless you're implying they've found a way to solve the discrete logarithm problem?
Oh there's a ton of ways to do it, from stripping, downgrade attacks, backdoored constants, precomputed tables for low order groups, shadow ca certs, etc.
I recommend reading the Snowden Documents, which disclosed a number of successful at-scale attacks on the PKI infrastructure.
I find it surprising there's so much ignorance in the Hacker News community about the state of encryption, especially given the newsworthiness of the Snowden Disclosures.
I also find the prevalence of 'shoot the messenger' regarding HN folks getting angry at me for pointing out publicly known issues with the current practice of commercial and consumer encryption.
But also, being familiar with the cryptography you are attempting to have conversation about is a basic starter. For example, there were attacks listed in the prior comment following the "oh there's a ton" header. You seemed to have glazed past those, but they are familiar topics to those who habituate themselves with the technicalities of cryptography and its practice.
Thanks for the link. I've read all of the docs (presentations slides) related to ssl/tls and found only one weak point (Debian sessions). And none of them have information about decryption of collected traffic - collected encrypted traffic is useless, only possible (at this moment) way is to intercept multiple things in live mode and try to decode data.
It's sad, but I'm still saying "use encryption", because alternative is "don't use encryption" and it's obviously worse. So I'm much more responsible than those who are trying to propose second option.
Unfortunately I'm afraid that you missed a lot of the content! You had asked for specific documents, not news reporting that pieced the context together (for example following the code names of the various programs together to understand how the system works as a pipeline).
In doing so, I'm afraid you're deeply underestimating the capabilities of the NSA, which expert analysis of the documents in question along with the technologies, related programs and internal customer requests indicate something much more startling than Debian session issues.
To put a point on that: TLS is broken at scale for billions of internet browsing sessions across platforms.
Give the short amount of time you've looked at the documents, I understand the misinterpretation you've arrived at. At the same time it's really impressive that you bothered to try to read the documents at all and should be commended.
Please feel encouraged to continue reading.
A large number of documents are hosted on edwardsnowden dot com and search functionality is provided here: https://search.edwardsnowden.com/
Der Spiegel, The Guardian and The Intercept provided good analysis of the documents as they were being released and that can be found at the websites respectively.
> It's sad, but I'm still saying "use encryption", because alternative is "don't use encryption" and it's obviously worse. So I'm much more responsible than those who are trying to propose second option.
Yes. I agree with this. Just don't recommend this as 'enough' to people who have serious need to protect their communications. If someone is worried about their porn habits, sure. But recommending this for sensitive use (journalists, dissidents, organizers, politicians, administrators) can lead to very serious outcomes.
For these cases, it is important to have frank conversations about the limitations of freely available and widely distributed tools.
They do, if your connection can be forced into using a low grade cipher, or you made the mistake of allowing DH[E] with a common group. Both mistakes which were (are?) common, incidentally. They were decrypting a good fraction of global TLS traffic not so long ago...
I understand that you wrote what you wanted to write.
Unfortunately what you wrote was FUD in the worst case and misinformed in the best.
Anyway I think we both are at a point where we understand the other's point of view. Thank you for the conversation. I believe we both hope a lot of HN folks will stumble over it over the next few days. :)
And again you are trying to offend me even when i'm trying to stay calm in this conversation. And it's all just because I recommended to use encryption, lol.
Fuck off and bye.
We disagree about it's limitations, and how to use it effectively.
Unfortunately this isn't a theoretical debate. Journalists, for example, around the world are being killed at increasing rates by governments, with this year reaching an all time high. State surveillance is an issue of tremendous importance for civil rights and personal freedoms. Our conversation and recommendations have to be sober and give candid, informed advice.
I think you absolutely have the right motivations: to encourage people to protect themselves from state coercion and violence.