Video. Excellent presentation, for those who are interested: https://www.usenix.org/conference/usenixsecurity14/technical...
HN user
deepblueocean
I think that's less than constructive. We know that intelligence and law enforcement have significant issues with Tor [1] that mostly are overcome by people missing the point of what Tor does and having bad operational security in general.
Also, when parts of the government have attacked the security provided by Tor, it's been visible (and kind of hamhanded) [2].
[1] http://cryptome.org/2013/10/nsa-tor-stinks.pdf [2] https://freedom-to-tinker.com/blog/felten/why-were-cert-rese...
I actually think the WIRED piece [1] to which OP refers does a good job of addressing this point. In particular, the WIRED article mentions PORTAL, a competing device called the SafePlug (which we did some research on to show that it does this job rather poorly), and something I'd never previously heard of called OnionPi.
Also, the article states very clearly states: "If you use the same browser for your anonymous and normal Internet activities, for instance, websites can use “browser fingerprinting” techniques like cookies to identify you.", which is basically the point of this post.
The WIRED piece even goes further, offering the same solution as is offered in this piece: "[an expert] suggests that even when routing traffic over Tor with Anonabox, users should use the Tor Browser, a hardened browser that avoids those fingerprinting techniques."
So while I understand the gripe that a transparent Torifying proxy doesn't necessarily do what you think it should, I would also praise WIRED for doing a pretty good job of handling these difficult and subtle issues in their article about the Anonabox.
[1] http://www.wired.com/2014/10/tiny-box-can-anonymize-everythi...
I noticed this, too. I think it speaks less of spell checkers and more about Time's ability to do copy-editing.
If I submitted a piece to a major outlet such as this, I would do so in full faith that they would assign at least one person to read through it and copy-edit it before publication. Apparently, Time is not a sufficiently reputable institution of journalism to believe in doing this, or at least is unwilling to spend enough money to have it done by competent people.
EDIT: As for Janet's credibility, I can speak to it personally, having spent a year with her working down the hall from my office. Probably the coolest stuff she's done relates to how decisions are made in big teams of scientists (she studied the sociology of scientists running some Mars rover missions: http://janet.vertesi.com/projects/social-life-spacecraft).
I did not previously know that there was work suggesting that mining is naturally an oligopoly. People have suggested to me that mining may already be a monopoly and that this could have been going on for a long time, with a monopoly pool "laundering" its work through rented time on other pools. So there are definitely interesting questions to consider in this area, including questions about how a rational mining monopolist will want to behave.
Apparently, the hearing focused mostly on issues of the appropriateness of the venue and not much on the computer crime aspects. That means the appeals panel may not actually rule on the merits, but may dismiss the case on what amounts to "a technicality". That would leave the gray area of the form of the original ruling against Weev about what does or does not constitute a CFAA violation.
Chromebook owner here. I haven't been able to convince the data on my machine to function on the free plan yet this month, but I'd chalked it up to the 3g modem being mostly iffy anyway. Looking forward to watching this.
People keep telling me that research I'm doing with some friends overlaps with what these people are proposing, so I've spent a little time trying to figure out what they do and how they do it from their website. I haven't yet played with their client or anything like that.
I really can't see any substance here. The name is also sort of darkly humorous: they've clearly poured a lot of effort into (at least marketing) what they're doing, but have yet to realize that they're just tilting at windmills.
It's definitely true that content blocking is the user's trump card in the online tracking vs. privacy debate.
How about a simple antitrust argument: if Google wants to use their power in the browser market, where they have majority power, to dictate the shape of the online advertising market, I think DoJ would have a pretty slam dunk case. Especially since Microsoft would be happy to pay for the best lawyers out there to write all the briefs in the case.
Single page version: http://www.wired.com/wiredenterprise/2013/11/bitcoin-and-def...
The important part of this post is here:
But the most important question about the dynamics of Bitcoin mining, which nobody has yet answered, is whether there is an equilibrium that can actually occur in which the Bitcoin economy can no longer function. This is the question that everyone would like to answer.
Indeed, the Cornell attack on Bitcoin mining claims to demonstrate that Bitcoin is not incentive compatible. This claim is demonstrably wrong. The burden of proof is on the original authors to rebut their (correct) detractors.
In the ES paper, and in your responses, the assumption is a colluding group of miners. I find myself agreeing with you there; it looks like the colluders have more incentive to break ranks. But suppose a single individual controlled 33%. Couldn't they use this same strategy to benefit more than we previously thought they could?
Yes, I think they could. I'm currently trying to model what happens in mining pools where the pool master attempts to keep the pool's state a secret from the pool members to deter the kind of hopping behavior necessary for fair weather mining.
I think it's interesting to calculate how much less the BTC/USD exchange rate would have to be as a function of how much power the ES-adversary has. It's substantial!
One could even imagine creating "poison pill" derivative instruments where someone agrees to sell a lot of BTC if some predicate over the blockchain becomes true (such as a predicate that's only true if ES-mining is happening).
Imagine I have N resources, and instead of hopping between pools, I'm deciding what percent to allocate to ES-mining and what percent to allocate to "honest" mining. I could certainly allocate 99% of my resources to one or the other in each round, which would be a good (99%) simulation of fair-weather mining.
Perhaps that's because there's already a bigger/more serious discussion over there and your thread is a repost:
http://www.reddit.com/r/Bitcoin/comments/1puk1a/arxiv_paper_...
How would such a proof protocol work? I spent most of yesterday trying to answer that question and came up with nothing. Imagine that you and I are mining and we've agreed to use the ES "selfish" strategy. When I want to getWork, I have to choose which branch I'm targeting as the parent of whatever block I'm trying to mine (I have to choose which hash to put into my block). But how do I prove this to you? I could send you a commitment to the hash and you could promise to come beat me up after the fact if I lied, but that's outside the stated protocol. In fact, if your model is that you can coerce me to follow your protocol when it's better for me to do something else, then you may as well coerce me to give you all my bitcoins.
Our argument is that the protocol, as stated, is not incentive compatible. That's ironic, because the protocol, as stated, is offered as an argument that Bitcoin is not incentive compatible.
Hi, Author of the referenced blog post [2] here (and one of Felten's grad students).
Let me lay out the argument from our post in a more technical way: the biggest problem with the Eyal/Sirer paper is that they don't think about the problem as an equilibrium problem, but rather argue about what's best from the perspective of a particular player. This leads them to propose a strategy which is not even optimal for any player (we prefer to think of Bitcoin as a kind of consensus game, in the game theoretic sense. See our earlier paper on the topic [1]).
They argue that Bitcoin is not incentive-compatible by virtue of the strategy they demonstrate. I think this question needs to be the crux of any Bitcoin research paper. I'll define "incentive compatible" to mean one of two things
(1) (weakly incentive compatible) If people follow their incentives, rather than the rules of Bitcoin as written down and understood by the community, then there exists an equilibrium in which all players follow the rules.
(2) (strongly incentive compatible) The above equilibrium is the only equilibrium in Bitcoin.
The question of whether the current Bitcoin ruleset is incentive compatible strikes me as the most important Bitcoin research question: it answers whether Bitcoin, as a system, will continue to be stable over the long term. A secondary question is to ask "what rule sets could exist which would be incentive compatible?" Obviously, if the answer to the first question is "no" then the second question is more important.
Stripe [1] seems to be a favorite around here. I don't know much about their competitors and a quick search of the archives didn't turn up the flamewars I remember seeing, but I do know a lot of the Stripe team and I can vouch that they're all top-notch.
It's hard to talk about great C&Ds without mentioning Chilling Effects, http://www.chillingeffects.org/notice.cgi, a repository/database of many C&Ds and copyright claims, which receives copies automatically of many letters sent to large websites.
Some of the content in there is particularly golden for humor value (search "perfect 10"), but more importantly, it serves as a first step to quantifying how many of these letters get sent and how many of those are legitimate. Chilling Effects doesn't track what happens afterwards, but it's one step above anecdote, anyway.
I believe that the staffers of many elected representatives typically count the number of constituents who were agitated enough even to send a form letter.
Think of it like a poll. Would you make the claim that politicians are willing to write off people who respond to polls just because they all answer the same question or the question isn't somehow the "right" one? Probably not.
Of course, it's not a poll because people self-select. But even still, if the report to the representative says "this week, we had 37 letters about gun control and 43,742 about surveillance", well, it's clear what the politician wants to say that he or she is doing something about when he or she next sees a reporter.
I've always been convinced that the name is a cruel joke played on American computer scientists by their French counterparts.
I was always under the impression that the core Hangouts protocol _was_ the Wave protocol, in which case it's _already_ an open standard. What would be awfully nice is if Google (which is a category mistake - what I really mean is "the Hangouts team") would clarify this, release any updates to the protocol that they've made, and perhaps define something more than the weak API provided for the current Hangouts platform.
In particular, the right test of openness is this: can I build an interoperable client that could participate in a Hangout as a first-class entity?
After seeing "off the record" chats synced across browser sessions a few times, I became convinced that Google was storing the chat session on its servers at least temporarily. I can't help but wonder if this is just a way to remind people that "off the record" really isn't, and nobody should be relying on that particular property.
Not only do these exist, there are significant institutional practices that exist to facilitate the sharing of detection signatures between companies and between companies and various governments.
It's good to prevent the re-sharing of child pornography, but a lot of companies don't like to talk about the systems because they're very much the same systems that the same companies are busy telling the content industry that they can't build to enforce copyrights. So they're generally kept pretty hush-hush by a kind of gentleman's agreement.
I think general copyright is actually a thornier problem and this secrecy is unnecessary. CP is just something you can block if you see it. Tracking down exactly which uses of a copyrighted work are intended to be allowed and which are not is really much harder. And I think that's a legitimate argument, especially because it recasts the copyright debate in terms of compromises that make sense: if clearing a bunch of rights is confusing, maybe certain types of compulsory licenses are more attractive. But that debate is for another thread...
A good starting place to think about the CALEA system (besides, as other comments mention, looking at CALEA itself) is this paper from Matt Blaze and his students: http://www.crypto.com/blog/calea_weaknesses/
Also interesting is Steve Bellovin et al.'s excellent report on security implications of extending CALEA to VoIP: https://www.cs.columbia.edu/~smb/papers/CALEAVOIPreport.pdf Steve Bellovin is now the FTC's Chief Technologist and spends his days trying to bring technical sanity to the government in various ways.
Nearly all the anti-Google groups that complain to competition authorities in any country are funded (at least in part, generally almost entirely) by Microsoft. The strategy seems to be "if we faced huge costs dealing with regulatory oversight, so should they."
I find this confusing. It's awesome, that's for sure. But it seems like lifting all the fuel needed to do a soft landing is inherently a tradeoff for less payload capacity. What is the benefit, then? Is it just so much cheaper to be able to re-use the first two stages?
This is a common misconception, I think. If you try to model the protocol economically, it's pretty clear that it's a majority of currency holders (what the core developers call an "economic majority"), not a majority of miners that matters in determining whether a protocol change is valid.
Exercise for the reader: determine whether these sets are different in a meaningful way.