HN user

axonic

113 karma
Posts2
Comments84
View on HN

Couldn't we put the onion address on the site, signed by the site/publishers key? Ignoring key exchange methods for a moment, once you have a key for "Bob the Blogger" you can verify Bob says the address is X and your url is X, so this is Bob's site.

Nothing, really. Nothing negative at least. Russia has broken no laws, is only guilty of being shady in the same manner as we are lol. I think we're overreacting to what essentially amounts to a symptom of a disease. The real problem isn't Russia expressing an opinion, but how it was presented. They did sneaky things TM like we all do. The reason being open diplomacy in a paranoid world is challenging.

Why not offer the world a vote, since every American fart in the wind has the potential to impact everyone's life, economy, food supply, etc. The world is pissed, like Americans, that the USG doesn't listen and take everyone's interests into account. We've developed a bad habit as a world here, of mistrust, secrets, and information wars. I think that the world [other nations and their people] feel they should have a voice, and I agree.

Russia can't run political ads openly, obviously, but why not? If myself, Rush Limbaugh, or David Duke can buy an ad, why not? State clearly whose opinion it is, and be done with it. If Justin Beiber put out an anti-trump campaign, would everyone panic? Besides, read the reports, no harm was done or could have been done. RT was the most watched news on YouTube with over 5 billion views. A few Facebook ads or tweets made all the difference? If they were gonna change peoples' opinions, wtf was another $200k USD gonna do? Don't forget they were approached and asked to buy ads in the first place.

Perhaps their arguments bear consideration since we've spent over half a century examining each other and analyzing each other's systems for flaws and coming up with every creative way imaginable to rebut the rationale, suggest improvements to processes, and criticize legislature. Such an opinion sounds valuable as hell to me. I love when people tell me I'm ate up, please do so I know.

Is it so hard to accept that Americans might agree with non-Americans on issues? WTF is so terrifying? I went to elementary school during the Cold War in a school which was an underground bomb shelter designed with 18 ft. of reinforced concrete to withstand nuclear strikes in the area. We heard every piece of propaganda there was to hear, I met Reagan on the playground, and I'm a Veteran now myself. The brainwashing failed I guess because I still, rather more than ever, think we need to grow up and re-prioritize our efforts. Why can we not accept that we're on the same dirt ball? We're neighbors in fact, with so much in common that it's laughable.

I gave it a lot of thought, and realized there is really no way I can understand Russians. After spending over a year studying Russian language, culture, intercultural communication, and history, I realized everything I thought was wrong. We've been misled quite badly on both sides by assumptions, misgivings, preemptive fuckery, and old emotions. How many of your friends know we got Alaska from Russia, or about Valentina Tereshkova? I mean we're being guided by the provably unfounded opinions of people not qualified to even have an informed perspective on the subject, to everyone's detriment.

Invite Russia to roast us, and have a public analysis of the feedback. Let's act like we give a shit and hear them out instead of forcing these silly spy games as our only means of discourse. Look how fast people flipped out when Trump wanted to establish a line to Putin. Wtf? Because 'I'm not talking to you because you don't think just like me' always works wonderfully, no?

To go a step further we could declare amnesty for all offenses in the spirit of understanding, truly forgive each other, and invite our governments to literally come over and talk. No secrets, complete data exchange. Invite Russian agents to NORAD, sit down and do an AMA. Tour the Kremlin with US officials. We think they did this, they think we did that, maybe we did maybe they did... Labor stories.

I'd bet if we laid all the cards on the table for each other and agreed to a cooperative path forward with an exchange of intelligence, defense, science, and medical information, we would find atrocities we never imagined on both sides as well as tons of wrong assumptions. Can't we have a laugh, exchange some glares, and hug before walking out before the press to announce that the notion of destabilizing the free world is over, and the games are too? That from this moment forward, we will consider our impact on all people of all nations and abandon the fallacious thinking that either of us has the right answers all the time?

Or are we really so self-serving that we cannot bear criticism of our beliefs and methods, even when we cause harm to others. Fuck 'em then? Frustration leads to wanting to feel this way, but nobody really means it and we all pay for it when we give up.

Or maybe I'm crazy. o/ There is no Deep and Mysterious Russian Soul, and Americans are so ignorant they can't even see how ignorant they are. Accept this and be friends without completely agreeing on everything? Maybe? Sounds like just having respect for others to me, which is also having respect for yourself.

As an experiment, here is a Soviet propaganda film from 1979. Check it out, at the time it seemed extremist, insulting, a danger to the free world... But how does it look now? Did we change, or did perceptions? Does the concept, the warning about dangers of western extravagance, seem unfair or untrue to you?

https://www.youtube.com/watch?v=LRSsybt9wAo&t=518s

I stumbled upon this when searching for examples of successful open source games. Great list, thanks for this.

I agree that trusting the government is out of the question, perhaps we could try an open source solution. Publish drug data, studies, manufacturing knowledge, and all of the usual pages of warnings, indications, contraindications, pharmacokinetics, etc. GitDrugs.org? I think India might have the right strategy with prioritizing human need over economic factors, at least in the short term. I think the problem with funding is a multidisciplinary one, unrelated to how much they can charge for the product. If we can figure out how to match problems->researchers->funding efficiently and effectively, finding drugs and researching existing ones won't be a problem.

Noted lol, I've had caffeine now. Sorry wow that was disjointed, but the comment aged past edit. I know the big red privacy flag is difficult to see this far off, so lets take off our serious hats and I'll explain this bit of nonsense and paranoia. You should probably dismiss all of this however.

TL;DR

I see freedom and privacy as something which cannot be combined with this concept as the project currently stands, due to reasons which are not immediately apparent but which I believe have at least enough substance to raise an eyebrow and question things.

I am left with the following questions after examining SEC documents, SM accounts, financial relationships, and company activities of parties involved and technologies used:

   1) Do I want to build on a platform which can never be truly safe
      because the stakeholders have a compelling interest in undermining
      its anonymous usage? (See explanation below)
   
   2) Why do things smell fishy...

        2c) Realizing I personally equate P2P with privacy, free speech, etc.,
            I wonder, why Chrome? Then I think of all of my compatriots. How 
            many of them would like using hacked-chrome to access sites? Why
            not mainline it on Chrome?
                Google doesn't do privacy <flag> hmm.

        2d) Where the heck is Firefox in this... or anything free/open...?

        WHAT KIND OF PEOPLE ARE THESE?!!! ZOPMG?!
Let's find out...

[Exhibit A] The guy who designed the protocol this depends on says in his paper on the subject that he offers an alternative to GitHub, then they build this derivative project on Electron and host on GitHub lol. o.O Okay, not by itself suspicious but weird and it stuck in my head, spurring more curiosity about individuals/projects/affiliations/home planets.

[Exhibit B] An ex-Mozillan building on a Chrome fork. Huh? Okay. It's a free world, but odd nonetheless. This makes me imagine where the project will go in the future. Will this get mainlined and become a feature in Chrome? What might prevent that? What if I don't wanna... Where's the alternatives? I don't want a Chrome-fork of ill repute on my systems to create more security vulnerabilities. Who reviews their changes? How quick do they roll out patches from upstream? Ack... Hang on a minute.. Google wouldn't want a P2P distributed web.

[Exhibit C] A handful of logos, a little namedropping... That makes me question who/why. Okay, let's see what their actual affiliation is. Code for Science turns out to be legit, and cool, but a tiny group so funding is... personal donations? The others seem to be foundations granting them some cash. Let's see who they are...

[Exhibit D] Upon looking up the Knight Foundation's recent dealings, I find they're now owned by a media company making its money from advertising, according to their SEC filings. Woah now, not friends of privacy, or P2P. What gives? Maybe the company has nothing to do with the foundation's activities, so I dig. Well, they're not in a position to spend money on bleeding edge tech, holy cow they're hemorrhaging money and have been for a while. Let's Google em and see why... Googling turns up fiascoes with the NSA, undermining counter-terrorism activities at a level the Inspector General's office deemed greater than all of the leaks by Edward Snowden. Wow that's a lot of heat, it can change a place - and who runs it. $1,000,000,000 USD/yr is a big fucking crowbar to leverage a company with. Susceptible to control? Yes. Motives to control? Yes. Opportunity to infiltrate? That reminds me that I haven't Googled the rest of the staff. This yields information that an adviser on the project is a GSA employee, in 18F - data. By itself that means little, but...

[Exhibit E] Giving their Fed (lol can't resist, sorry Jay-quith, it's meant in good fun) the benefit of the doubt, I Google him and find his anti-Trump tweetfest. Lol, ok, but you're a fed right? So why the Hillarsque feed? When I was in service, I wouldn't have undermined POTUS publicly, but kids these days are different, still seems like a weird fed. So I look up the 18F department handbook, hiring policies, and what kinds of people work there. He wouldn't fit in for a second by the sound of it, and... what is this? Don't they need clearances? Yes... For Open Data, we need an SF85a/SF86 do we? Huh, okay. Wtf? Moving on... Secretly Open Data?

Ok, so basically what I meant to say this morning is that the software, the project, its apparent contributors, and purpose all seem very nice, open, pro- freedom and sharing, targeted at people interested in decentralization and P2P sharing. Cool, they've got ex-mozilla people and they're 100% javascript buzzword compliant. They've got inspiring LinkedIns and professionally written bios. What hacker-for-public-good has traditional academia roots, gov ties, and likes Google/GitHub and Big Data _TM_ but aligns with Mozilla in a past life? Kinda strange, not incriminating, but those cool looking people are dependent on organizations and technology which they Beaker/Dat/Codeforscience.org) do not control. These forces have agendas which oppose the goals of this project.

One adviser is employed by the US government in an agency concerned with these matters, which seems fine, but I don't like single government anything really <tin foil hat>. Where is everyone else at the party? Curiouser still: When does gov+P2P anything mix? Who is accountable when I serve pirated media content I am unknowingly hosting via P2P using beaker? In some places using such software is illegal for that reason. Who takes down the page when I serve up bomb plans? There's one strong reason privacy may be intentionally broken, or at least cast aside. Deniability for people hosting the mirrored content is there, but it leaves nobody accountable for a DMCA notice or law enforcement action right? Unless they can come kick my door, then it's fine. See why they might not wanna have any kind of anonymity on such a network? Call it paranoia if you wish - whatever. It demonstrates a conflict between the design, and the objectives of involved parties. There are dozens of reasons why gov+p2p typically have nothing to do with one another, which would give some compelling reasons for a gov to want to put some boots on the ground, maybe manipulate the playing field a little. At least, they're solid grounds for gov to be anti-(beaker+privacy) combos.

One company which owns a foundation supporting the project makes its money primarily in an industry which is infamous for tracking, privacy invasions, selling and mishandling of user data, and exploiting user browsing behavior, but they are asking me to trust their modified browser and server, you need to run a modded httpd to serve "legacy browser" users with normal DNS etc.) I was under the impression that the contemporary cybersecurity concerns of users and governments were focused on improving privacy, not creating monetary partnerships with media companies.

So, wondering what the biz model is, where the money flows and why, and why government (read: THATS _YOU_ FED! lol) _may_ be interested and might present challenges to using it in the way I would like, for anonymous and open exchange of data. If you've been involved in research, defense, or fedgov the reasons are apparent. Well, doesn't mean they _are_ involved, or even _care about it_, but they may at some point care a lot, if history is an indicator. GitHub stands to lose a little here, maybe, so I doubt they'll jump to the front with their credit card in hand to help. Google sure won't benefit, and that sure is a lot of work for such a small team to tackle, so how are they gonna maintain this? Is this gonna be a forever-separated fork of Chrome? Will Google get shitty and try to break compatibility or prevent usage of Beaker or its features to protect their investments? Doubt they'll help at any rate.

Summary It seems like they're a project which is working for open data and an open web with the very people who want to prevent this at any cost and are in a position to be forced by those people to alter their behavior. The software this is built on is not privacy focused or even aware, and the project itself in no way ensures privacy or anonymity, and is controlled by parties who have interests counter to the goals of the project, so why would I invest my time-money in helping something which is at best naive, and at worst doomed to fail. I love the concept but WTF, how is _this_ the way to accomplish the goals of Dat, Beaker, or the pro-P2P community? By building in anti-privacy technologies and stakeholders?

I hope this makes more sense. Thanks!

I did. Interestingly, I also tried to view a related bug to find "You are not authorized to access". How fitting. There seems to be a fight between people trying to raise the issue to Mozilla's attention, and the staff. So they get caught doing something shady again, get told to stop, and react by posting pseudopolite comments about how we've made their work experience difficult, close comment threads, and come spread misinformation here? What should be done?

Oh, because everyone else's story was told but theirs? Rly... 2017, year of the pro-female SEO and marketing. BBC is doing what about it?

Flag this all you want, I'm a transgender female coder with a wife who also is a computer scientist. Silence me some more while you post headlines about women you hypocrites. Be sure to preach about freedom of speech too.

Sections in Article: a) An introduction b) Why was Go needed c) Target Audience d) Go’s strengths e) Go’s weaknesses f) Towards Go 2 g) Go’s design philosophy h) How to get started i) Who is using Go

So... Next, when I write a similar app now it will be classified as some kind of "medical" app and be barred from distribution without a prescription and the years of paying off the FDA for approval? To protect profits of Big Pharma Apps huh? Is this where we're headed?

If I understand the OP correctly, he means could the blockchain be attacked by a vast number of infected hosts, causing a malware-induced change in the consensus of nodes, allowing BTC to be illicitly acquired, spent, or produced.

I believe controlling a massive number of nodes in the network via infection techniques like WannaCry used would open the door for many actual and hypothetical attacks. Please see the Bitcoin Wiki page titled Weaknesses [1] for more details about attacks involving the control of network resources.

More realistically, a simpler attack would be to go for control of the wallets if you have that kind of access to the infected hosts. However, if an actor had an interest in devaluing Bitcoin, to buy after a crash and sell after recovery perhaps, or just destabilize users' trust and destroy it (states?) then there could be a lot of profit in it I believe. Bitcoin has many competitors and enemies, is this something we should worry about?

[1] https://en.bitcoin.it/wiki/Weaknesses

ProtonVPN 9 years ago

TL;DR: The Identity to BTC link has to be broken, no matter how you do it, and not in a way that is human-indecipherable but truly distanced.

If your target uses BTC to avoid CC payments, then they had better know how to prevent tracking the payment on the blockchain as well. If I were targeted by a bad actor with state level resources, I would assume any bitcoin transactions to ProtonVPN would be spotted easily and I would assume any wallets I've used are hot. There were lots of ways to do this explored by users of onion sites who purchased illegal items. One of the most popular was to 'launder' the coins using a mixing service which shuffles around the BTC (for a fee) and sends it to a wallet of your choice, typically a one time use wallet which sends the balance to your account on the onion site for purchases from other users. The onion site operators may also mix up their coins, making it a little harder still. The coins from origin are received, split into a bunch of tiny transactions all over in various wallets, like shuffling cards, then many wallets send small amounts whose sum is the amount laundered minus fees, to the final destination one way or another. I encourage you to browse forums on such sites for the scoop on what the users think they know, as well as what security researchers have published on the subject.

Example: User Alice wants to pay for services from Bob. Bob's services are a little questionable in Alice's jurisdiction and she is concerned about someone finding out about her payment. If Alice is being surveilled directly, and the attacker knows about the wallets Alice uses because they got records from the company she buys coins from (or somewhere else like sniffing her traffic), and the service is priced at $X on Y date given the bitcoin value at the time, the attacker can look for any transactions for that amount on dates which Alice visited the site and compare the transactions.

In our example, lets say Alice wants to upgrade to paid ProtonVPN service but doesn't want Throckmorton's Sign Company [1] to find out about it. TSC suspects Alice may be trying to smuggle information through a VPN. Alice is smart and uses all the best practices. She's got a locked down mobile device with no cellular antenna connected to a long range directional antenna. She leaves her phone at home, drives the most secure route available by avoiding main streets with traffic cameras and license plate scanners. She parks in a cheap apartment complex parking lot (no guards/cams) at the base of the mountain. She pulls a mountain bike from the trunk and places her handgun in a waist pack, and rides to a higher elevation scenic point with no security/safety cameras and infrequent civilian or police traffic, aims her high gain antenna at the hotels below, and gets a WiFi signal. She connects with a spoofed MAC address, from a Tails ISO on optical media, to somewhere she cannot be physically linked to, using a device modified for safety. She has a script which changes her apparent desktop resolution, browser size on every page load, user agent strings, window dimensions, all kinds of fingerprinting avoidance. Alice uses a virtual keyboard which randomizes the delay between keystrokes before forwarding her input. Alice checks her configuration for holes, checks TOR, checks DNS, etc. and everything is solid. Feeling secure now, Alice logs into a brand new Proton account not associated with her, checks the price, and pays via Bitcoin. She bought bitcoin from a reputable exchange and had it deposited to a new wallet. She then transfers these coins to another wallet which is brand new and uses this to pay Proton.

An unknown actor at a TSC subsidiary agency has absconded with classified intelligence reports. Agent A is being watched, his stuff searched, no reports found, and Agent A won't talk. TSC thinks Agent A leaked it. Surely he sent it to some damn media hippie who loves communism and Vegemite, and now the whole world will know. They must stop the leak. TSC knows Agent A is a Vegemite sympathizer and is known to talk with people from the media sometimes, which is why they were watching him. They know he eats at Joe's Restaurant. A TSC agent dresses in a shabby suit he rented and puts on a local law enforcement badge and ID. He goes to Joe's and interviews the manager under the auspices of a criminal investigation. The manager at Joe's was all too happy to point out that he comes in every Wednesday, sits at a table near the rear fire exit facing the door with his back to a wall in a part of the dining room with no clear window views. He always orders Vegemite sandwiches and dresses nice. But he noticed that once a month or so, Agent A has someone with him, a real pretty lady friend. He assumes they are having an affair, and he's curious about it, so he pays a little more attention to Agent A and thought there was something funny about him, and he's eager to tell the "policeman" all about it. Agent A always looks sharp but on those days he dresses down a little, wears sunglasses, and removes his wedding ring. The manager calls over Agent A's usual waiter and asks him to tell the nice officer all about this suspicious character. Agent A's waiter says he saw a media ID sticking out of her wallet when she paid one night, so he knows she works for XYZ media. Our friendly TSC agent thanks them for their time and leaves, giving them a business card with a "detective" to contact with any new details.

TSC has only to look at all bitcoin transactions received by Proton since the leak, and I imagine this is a small set, and look at where those coins came from. TSC can and does keep banking and financial records for companies who sell Bitcoin. They run a search against the transactions looking for any wallets associated with those used to pay Proton during the period since the leak. They find 666 wallets. 420 are from Alice's country. Of these payers, only 42 paid with BTC from a wallet which had no other appreciable history. They check these 42 and the wallets connected to them by BTC transactions and find exactly one which was separated by 2 degrees and funded by BTC from Alice's reputable exchange. They quickly search the exchange's records and find that the wallet in question was funded by an account with a CC# belonging to one Alice Suspect who lives right there in Big Brotherville, and her name is on the list of XYZ media employees. TSC now knows Alice bought a VPN account, and to some courts that might be enough to escalate this. In some jurisdictions that shit will get you killed. Alice lives in a civilized democratic nation however, so instead she becomes the target of a massive and focused TSC investigation. They raid her home or intercept her vehicle, maybe they throw her in a van with a burlap sack over her head. Regardless of how they get her, TSC agents find encrypted disks, and order her to unlock them or go to prison (or face a $5 hammer). Alice sure did a lot to cover her ass, for nothing. One leaker, one media contact locally with a BTC wallet which paid Proton. Even assuming they don't target Proton, but check against all records of all VPNs on a list, doesn't change much but computing requirements to find out who is buying VPN service with BTC on their list. Assuming they don't ever go to Joe's restaurant, or even know about the pretty lady, they know local media only has so many journalists, fewer who travel these circles, and fewer still who would touch something that hot. Even assume they check ALL journalists in the entire country, how freakin hard would you have to look? How many suspects would there be who have bitcoin exchange accounts? Monitoring their search entries or IP traffic would reveal a lot and narrow the list down. Assume this is all happening in a state with a highly developed legal system and TSC has to request warrants and subpoena records to get them, and show to the satisfaction of a court that she is guilty, they still have the authority needed to grab the rest of the info they need once they have a short list of targets and they can acquire the rest through this investigation. Assume TSC never found the actual documents on Alice or in her property, the original problem of Alice being known to use a VPN is still not solved. Another approach would be to check all persons of interest for bitcoin exchange accounts by CCs, emails, names, etc., and then check those accounts for direct or indirect payments to VPN receiving wallets. Let's even assume that Alice purchased a prepaid credit card and for some reason was able to buy bitcoins with it, now they just ask FailMart to give them the register record and the video from that time. Even assume Alice isn't a journalist but a source as the OP says, and this source doesn't want people knowing they got a VPN. Follow the same breadcrumbs and you still have a bloody short list, the rest is old school tradecraft and detective work. In a not so developed legal system, only a shred of suspicion can end your life without needing anything solid at all. You see where I'm going I hope. The moral of the story is, BTC come from money, money is watched, BTC are watchable, so without a mixnet or something between purchase of coins and purchase with said coins, or a way to acquire them with complete anonymity, you're holding up a sign with your name on it which is just obfuscated enough to seem anonymous to average people. Money and identity are linked thanks to our current global financial system and all of the people who have exploited it. Selling BTC is regulated to "prevent drug lords and child sex traffickers" and other evil persons of the week from using BTC to launder money, but it's watched anyhow and every technique to link identities of individuals to bitcoin purchases can be assumed to be in use.

[1] This is actually funny, a medical joke. https://radiopaedia.org/articles/throckmorton-sign-pelvis

Seriously, go run an Eve Online player corporation. Try setting up a persistent chat server, wiki, etc. for the corp and securing it. Try managing players in fleets from several time zones and scheduling engagements and operations. This is analogous to setting up collaboration infrastructure for remote teams in development settings, as well as scheduling for international workers, wrangling cats, and you will be fully qualified to wrestle Mongolian Tigers. These players are volunteers, which is synonymous with the real meaning of "employee" held by some of the people you may work with. Loosely held by honor, perhaps loyal based on their relationship with the organization, some are hard workers and motivated, others require a leader or mentor be assigned to them. Once your eyes bleed and you wish for death every night for ever deciding to be in charge, try also making it profitable. Use your knowledge of business practices to balance the corp accounts, make good deals, and save money where you can to be able to pay dividends to members of the corp. If you really want to do a "dry run" to test your mettle, that is one way. I'm not saying this will make you CEO of Intel material but you'll at least have the confidence to proceed and have some idea of what the minefield really looks like so you don't jump on every one.