HN user

E2EEd

11 karma
Posts0
Comments27
View on HN
No posts found.

If that helps to compartment knowledge in order to further UK security, one can expect it, eventually.

Nothing is scarier to me than a distant techno landscape where knowledge in irresponsible or irrational hands can be used for unimaginable horrors. Such extreme measures as censorship of undergrad STEM education would, in such a case, seem appealing to authorities.

Encryption offers table stakes for weaponization of math. I do, however, agree in spirit with your slippery slope arg

* Successfully hacked US citizen on US soil, from US soil, without a warrant. All hops were domestic. SIGINT then provided to celebrity's hired PI's.

* Stalked and gaslighted US citizen on US soil, using said SIGINT.

* Threatened US citizen on US soil with murder to deter investigation into previous federal crimes.

* Threatened to ruin US citizen as retaliation for not staying silent about above incidents

* Stalk and harass US citizen on US soil in public

etc

Clearance Holders

I built an app with a REST API a long time ago, now a defunct startup. In an effort to save API calls, the front end devs requested that I add various other resources in new endpoints, often a subset of another endpoint's response fields. The API spec ended up being fairly unwieldy.

I've often thought that this would be a great use case for GQL. Seems like a good choice if your front end wants to specify exactly what data to get.

User error is still the 600 lbs gorilla. Figure out how to make tech security idiotproof. This is increasingly difficult as IT systems become more complex over time, adopted by an expanding pool of participants.

It's all broken, but a purist will go off grid and live in the woods.

Perhaps you'd find passion in pursuing a PhD (or other avenue of professional R&/D) that focuses on resolving the fundamental issues with much of software development methodology, endpoint arch, and networking.

Barring that, the MO is to devise more robust bandaids.

The proprietary and secret nature of big tech security creates a playing field of fortified castles vs. self reliant survival in the wilderness. Tail end participants such as Google's core infra security will outmatch any independent actor. And, still, both google and apple consumer endpoints seem to have fundamental security flaws, entrenched due to being built on many billions in investment over decades.

Something like CHERI may take decades to bear fruit, hopefully turning over and pruning any insecure legacy systems sooner rather than later. Telecom is an example of why this will likely never occur anytime soon, and that we may be stuck with current security paradigms for many, many decades.

While I never investigated it personally, my understanding is that the quantization on the MPC60/3000 series was a big part of the feel. By definition, a quantized sequence is not a sample-accurate reproduction of a live MIDI perfomance.

Also, such idiosyncratic quantization is faithfully simulated in software nowadays, anyway.

Contrarily:

I challenge the notion that it is impossible to model the A/D, any DSP, and the D/A of the MPC3000 in software. While modeling non-linear response dependent on factors such as gains and impedances is not trivial, it is certainly feasible. Much of the pro audio world has moved on to plugins for their ability to reproduce the desirable aspects of analogue hardware while removing the undesirable aspects (such as noise).

A hardware sequencer/drum machine offers things that can't be modeled: tactile feel, low(er than some computers, still to this day) midi latency. Even the limitations such as a slow UI synchronously coupled to slow offline processes (which could be conceivably be modeled) affect the creative process in non-intuitive ways.

Similarly: reel to reel creates a smell that affects the vibe. Limited tape and no undo button affect the creative process as well.

DAW's are great but are essentially unlimited. This opens up horizons, but it does remove musicianship as a requirement in a recording context.

Go into the biz of robbing banks for profit. Like in Sneakers intro but adjusted for 2022, more automated, robotic, human-decoupled.

It'll make DHS salivate when you prove that the need for high speed, AI drone defense is greater than currently is deployed.

You'd probably sell a full stack solution with a "Jolly Bank Robber Cookbook Manual 2022" to prove the risks going fwd along with successful live field tests.

Issuers of tether that is unbacked are defacto short. They thus embody your theory by design.

Is there any derivatives market in tether to allow an outsider to open/create a futures contract as a seller (thus, short) that gives them the obligation to deliver tether upon expiry?

I suspect that such matters don't work as you believe they do.

Shorting generally is done by professionals in regulated assets. Tether doesn't seem to meet that requirement. No professional will want to take on short risk in any size in an unregulated asset. Shorting, in theory, has unlimited downside risk (to negative infinity). This would actually be a factor in an unregulated market controlled by scammers, depending (in large part) on the net positions of underlying and derivatives by opposing parties.

Very exciting. As this works on Fuchsia, a capabilities-based OS with a security-first design goal, is there any writeup on the security architecture for this project?

Is it correct to say that a convergent desktop environment exposes a large surface area via monolithic access to the underlying OS? It seems that the desktop environment is one of the hardest things to build securely, if embarking on such a journey.

Also, somewhat related: In light of forthcoming capabilities-based hardware (see: ARM Morello), is it a bit hasty to embark on a security-first rewrite of the entrenched Von Neumann / Harvard basis for incumbent OS environments?

Snowden is charged with theft, not treason. He knew that his actions would result in a closed-door trial without the possibility of a public interest defense. He signed a large stack of non-disclosure agreements that spelled out the consequences.

Whatever the perception may have been after 2013, it still is an open question as to Snowden's intent. His first stop in HK, along with his disclosure of US cyber activities against Chinese servers, indicated possible intent to defect to an adversarial state. His next stop was to Moscow, after he may have visited Russian handlers while still in HK. His Moscow voyage did occur a day after his passport was cancelled. He was almost certainly advised, via Assange's camp, that Russia would be a suitable destination. This almost certainly factored into his decision to seek a flight that stopped in Moscow. At best, this was likely a fall-back strategy as it was clear to him and his supporters that hiding in a South American country would not provide the same degree of protection afforded by Russia.

It is difficult to take Snowden's word on his account regarding motivations and (supposed lack of) conspirations. His actions took place during the Magnitsky debacle, including his initial contact to Greenwald.

(redacted)

Look at his agenda now. He speaks as if he's on USA's side. Yet he admits he no longer represents the USA, speaks out against the USA, and chooses to avoid facing justice. Defection is not a difficult working conclusion to reach at this point, possibly pre-meditated. He certainly had the opsec to cover his tracks while still stateside, having been trained by the CIA.

Snowden, you were silent when Putin declared war on Ukraine in 2014 by annexing Crimea, and you are voicing support for the Kremlin. From my point of view, you are, at this point, a defector to the Russian Federation. You will cowardly avoid facing justice. Your actions have had vast and largely immeasurable consequences to the detriment of western national security -- all of which will be revealed behind closed doors if you choose to return and face the charges against you.

Snowden's recent timeline suggests, at least, some degree of transferred loyalty to the Russian Federation. This is coincidental to his bid for citizenship.

At this time, Snowden is pushing the USA to de-escalate tensions by withdrawing support for Ukraine.

Snowden has changed to a full-blown supporter of Assange, as well as to an outspoken critic of recent US FP decisions. He has increasingly shown public loyalty to Russia.

E2EE is offered to all users, whether or not they are law-abiding. More precise is to say that E2EE is offered to users who are primarily law-abiding.

Your points are well-heard, even by those in the IC. What isn't occurring, is a good-faith discussion on solving the issues faced by law enforcement and the IC related to the growing entropy of E2EE wielded at scale by folks, a large subset of whom are engaging in criminal behavior. I strongly believe that fighting this issue with a hard-line no compromise response will result in an undesirable outcome for your agenda.

I am not a fan of kneecapped cybersecurity in consumer endpoints, which is the elephant in the room. It's a compromise borne of the E2EE entropy problem, intentional or not. I don't support unchecked recoverable encryption in any centralized fashion, nor do I support covert backdoors or skeleton keys.

Unfortunately, too many folks defend their position from libertarian ideals, a position which does have a technical justification. It just misses the bigger picture - that most folks in govt are just doing their job. A compromise will seek to enable those doing their job correctly while preventing abuses with technological means.

Telling the govt "too bad, you can't stop math" will backfire. The law can be used to force tech companies to literally stop doing math at scale.

Apple's on-device scanning experiment failed miserably. It was (at least, co-opted as) a litmus test for working around the post-Snowden E2EE-at-scale status quo in which we find ourselves.

I don't have enough background to understand the implications of EARN IT for the LGBT community. What is occuring, though, is a lack of common ground between libertarians and law enforcement:

If the tech idealists and law enforcement types fail to find common ground to develop robust compromises, EARN IT, which will be implemented sub-optimally out of convenience, will have the negative consequences noted by the techno-libertarian crowd.

However, a sound compromise does exist. It's just that nobody is talking about it, because most folks have strong opinions at one end or the other. The "edge", as it may be, is slated to introduce tens of trillions in new tech value in the coming decades -- all in support of hyperscale networking. It's a chance to find robust solutions that satisfy most parties, but not if the libertarians maintain the hard-line. It's up to the tech community to develop responsible encryption recovery techniques, because clearly law enforcement and congress are too provincial to understand what's at stake. Yet, by maintaining the hard line, congress will get their way, and we'll be less safe as a result.

Responsible encryption recovery is possible if you throw out the existing mechanisms of centralization along with "trust us, we're the NSA" mentality. Build your techniques around ideas that reject centralization, and reject mathematically unauditable recovery schemes. Reject techniques that exclude civil libertarians from the systems of checks and balances needed.

I say this with urgency because finding common ground is the only way we'll achieve a more responsible system of oversight for policing our private comms.