HN user

1101010010

366 karma
Posts0
Comments75
View on HN
No posts found.

This is only the tip of the iceberg. A majority of the "user content" (product reviews, brand engagement, comments on social media sites, etc) is completely fake, bought for and paid by big money interest aka bots. No different than automated scans of the IPv4 address space: simple, unsophisticated, low-cost and without any repercussion.

Social media access to user data (whether foreign or domestic) is bad, but it is a distraction from the real evil: behavioral management at scale. When you can target specific demographics and control what they see 8-10 hours of the day, you can change what they think, say, do, and most importantly, how they vote. People are literally being programmed (euphemistically, "conditioned") by the specific triggers and stimuli with almost surgical precision, and completely unbeknownst to them. This is uncomfortable to recognize and discuss, so the conversation is sadly reduced to "China/AI is bad/evil" to further foment hate and division.

Forgetful Browsing 3 years ago

https://browserleaks.com/canvas

Open it in a regular and "incognito" browser tab. This is a long term identifier of your browser which persists across cookie clearing, IP address changes and other ritualistic totems privacy-seeking individuals still inexplicably cling to.

Forgetful Browsing 3 years ago

Most of the nefarious tracking is taking place via canvas fingerprinting these days, clearing cookies does nothing but make the unaware user feel good they're "doing something".

How else do you expect they get your device on a surveillance list? Or do people honestly believe that the 0.001% of mobile phone users that unlock their bootloader for custom operating systems are not subject to additional scrutiny by big brother? NSA flagged Linux Journal as an "extremist forum" and flagged readers for extra surveillance - and that was a decade ago.

There’s a big difference between identity keys and session keys. It makes total sense to use lots of throw away keys (this is how tls works) but making a new identity key for every message is madness.

That's not what happens (new identity for each message) and compromise of a Signal identity key has no impact on message security, unlike GPG. Also it's not how all TLS works; it's how TLS works with perfect secrecy ciphers only.

There is no empirical evidence for how frequently to rotate your identity keys.

Certainly not if you refuse to look for it.

A few years ago NIST started recommending never changing passwords unless they are compromised

Passwords derive session keys (cookies) which rotate very frequently. You have a lot to learn about computer security, I'm happy to make some reading recommendations if you're sincerely interested.

Never sharing keys reduces the risk too.

That's not up you, it's up to your adversary.

How much does rotating credentials reduce risk? Should I rotate once a year? Once a month?

As frequently as possible. Signal for example uses ephemeral keys for each message.

Rotating every day would be even more secure, right? But how much more? I think not very much.

Stop guessing and use empirical evidence to support your reasoning.

The risk is that I don’t know if I’m compromised. But I think that risk is less than the errors involved in rotating keys according to some arbitrary schedule.

It's arbitrary because you are making a strawman argument to support a foregone conclusion.

You asked for a citation, you were provided one. If you think 300 unarmed civilians being murdered by the government because of their race is "nothing" then there is nothing left to discuss. I am honestly worried about what you might think of Mao's China or Hitler's Germany and their respective civilian disarmament; I bet very few lives were lost to "civilian gun violence" under their rule, too.

People with guns kill more people than people without guns.

The irony of this statement is government is historically responsible for the most deaths as they are best armed. When technology like firearms are decentralized and more people have access to them, fewer overall deaths occur and more individual freedom ensues.

Same concept for cameras, when they are pointed at police and agents of the state by citizens.