And yet there are millions of people using the Internet and we have to protect them with the army we have. I hope we'll see something like Marlinspike's Notaries becoming widespread in our lifetime, though.
HN user
thingexplainer
Have you considered generating these screenshots automatically? It seems like if you did, this would protect you against both typos and insiders.
When will it be?
I think the solution is to formally verify your hardware with a prover that is aware of electromagnetic forces. Software has to assume correctness of hardware (rad-hard applications have to assume ridiculous hardware faults are possible, but that's to prevent solar flares from corrupting firmware, not Rowhammer).
Thought experiment; you are some sort of intrusion prevention system. You've detected that your hardware is untrustworthy. Now what?
"Formal verification makes your code invulnerable against a very specific (though very powerful) attacker"
Extortion in the form of ransom-ware, theft in the form of stealing bitcoin from exchanges. (Mt. Gox, and a more recent case.)
This is exactly what I meant. I guess I could have been more clear about that.
I don't have any data to back the assertion, and honestly I kind of forgot the markets were still extant, I just happen to know that people are making millions in illicit profits from these two methods, and I've never heard of a successful preminer (which was how I interpreted "Ponzi scheme") other than Mr. Nakamoto.
It doesn't have to become public. It probably shouldn't.
Perhaps the DNI should consider offering some form of clemency for other people who brought "homework" out of their SCIF to turn themselves in.
People are scammed out dollars, bitcoins, and iTunes gift cards. Ponzi schemes happen everywhere. The real money in bitcoin-denominated crime is in theft and extortion anyway.
If people disagree, I'd love to know why.
For a sufficiently large monitor I'd expect you to generate multiple five-pointed stars on the first try.
Regarding your first point, the trouble (at least in this instance) is that this logic doesn't apply when you're looking for Roger Waters and calling everyone in the phone book with his name. Each time someone picks up the phone it probably won't be the person you're looking for, but you certainly had reason to believe they could be.
They didn't find a strange phenomenon and point out it might be ETI, in which case you're right, the hypothesis wouldn't make sense until you had ruled out basically everything else. They made a hypothesis about what ETI would look like, looked for it, and claim to have found things that could fit the bill.
The correct answer would have been to pick a reasonable assumption (before you ask, your own judgement determines what is reasonable) for what "useful" is, and to clarify that that was the assumption you were using.
We don't have to question whether or not anything means anything in order to engage with every topic every time, but I appreciate the exercise.
Was the service you were receiving before they offered two-day shipping any better? Or just more consistent leading to less disappointment?
Saying "something is weird" certainly implies "this does not match my expectations."
This has been SOP in certain places for a long time.
Extraordinary claims don't require more evidence than other claims. A more accurate statement would be, "claims I'm skeptical of will require convincing evidence for me to be swayed." The "extraordinary" part makes this razor less useful, as if there were more than one category of evidence and one of them simply wasn't good enough for you.
Comey continues to advocate for backdoors in order to stop ISIS from being able to radicalize marginalized people within the US without them being able to listen. However, there are two obvious problems with this.
1. Why don't you just reach out to the marginalized yourself? Spend that $1M you paid to break into an iPhone on combatting Islamphobia and ISIS will have a tougher job.
2. What is to stop ISIS from using software written outside the US, or software they write themselves, or versions of software older than the mandated backdoors, or open-source software, or... on and on and on. His plan transparently will not work. To quote Schneier, "His problem isn't encryption, it's general purpose computers and a global market for software."
That is stupid.
Which is a pretty flimsy reason to believe an adversary might find leverage against you. But hoarding is a force multiplier in the adversary's favor.
I agree, I never meant to imply that I thought contractors were less loyal. I appreciate the depth of your responses and hope I haven't given offense.
There are just so many of them that it projects the attack surface of the DoD out; now you can attack contractors which aren't as tightly regulated, and they might hire people to, say, build their website that aren't even cleared. So now I can steal some web dev's credentials and pivot towards classified networks.
He must've hidden it in his Rubix cube.
As an outsider looking in, it seems like there have been a lot of DLEs due to contractors though. Theres the obvious example of Snowden, but also the QinetiQ breach (https://www.bloomberg.com/news/articles/2013-05-01/china-cyb...). Moonlit Maze might be a counterexample.
It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.
Active publishing contemporary historical smut fiction, it would seem.
How principled of you to ruin someone's career and let them spend the rest of their life in prison.
I'd love to hear more about why.
It's tedious and repetitive even when the benefit is obvious and substantial, unfortunately.
Because they're willing to do one thing but not the other?
... the key (or password) is kept obscure...
I often think about this, and the conclusion I've come to is secret != obscure. Obscurity describes information you do not know but can research to determine; secret describes information you do not know but and must guess.
But I agree that the argument that the NSA probably uses obscurity (I speculate to make messages harder to attribution to them and not to protect the secrecy of the content) isn't very moving.
I could learn to see past an insurance file for WikiLeaks and still regard them as journalists, the idealized WikiLeaks is struggling in an asymmetric conflict with nation states and could probably use some insurance.
It'd been a while since I'd read the article, and you're right, I oversimplified in my memory. I appreciate the counterpoint (though I can't watch it at the moment).
Wikileaks should not serve the agenda of it's sources in reporting information, but of the citizens of the world who need more transparency that they claim to represent.
Here you are:
https://theintercept.com/2016/08/06/accusing-wikileaks-bias-...
People talk a lot about how Putin is an opportunist. I think he saw how bitter Assange was becoming and understood if he gave him the documents, he could step back and let him carry out his vengeance against a woman who had a huge role in forcing him to ground in the embassy ("can't we just drone this guy?"). I'm told this is a Rule of Power. But that is speculation.