People became ambivalent. Snowden fled eventually to Russia. Some people viewed him less relevant over time as the archive merely trickled out. When he fled to Russia, he looked less like a martyr and more like a national security information leaker or spy like Robert
A lot of what sounded extraordinary in 2013 is now baked into everyday discussion like metadata and mass surveillance. He is also available less for interviews because he is in Russia.
Which ironically makes the Internet more surveillable, because now every single connection has to hit some TLS-terminating origin and can't be cached at the edge of our own networks. Don't confuse security with privacy.
The internet is only more concentrated because most people choose price and convenience over a foolproof level of security. The cost/effort required to surveil traffic in coordination with TLS-terminating CDNs is multiple orders of magnitude higher than the effort needed to throw some high-Tbps middlebox in an IX rack to siphon every packet passing through it.
Not what I'm saying. No coordination is necessary. I'm talking about metadata, not encrypted contents — just the fact that you made some number of connections, at a certain time, from a certain network, to a certain network, in a certain order, with requests and responses of a certain size. It really doesn't matter what's inside.
- <a href="https://youtu.be/kV2HDM86XgI?t=1072" rel="nofollow">https://youtu.be/kV2HDM86XgI?t=1072 “First of all, David's description of what you can do with metadata […] is absolutely correct. We kill people based on metadata.” ― Former NSA and CIA director General Michael Hayden (2014)
Sure, but hiding the contents provides a lot more value than hiding some parts of metadata.
It's ridiculous to argue otherwise.
It's true that general resources could be cached in some cases, but personalized information couldn't be (and yes was served over HTTP, not just HTTPS).
> It really doesn't matter what's inside
It certainly does matter what is inside, and it's trivial to think of cases where it does. Hiding that content is much much more valuable.
if you visit wikipedia.org/whistleblowing, what exactly value is there from hiding content but force revealing you visited it, making sure it can't be retrieved from a cache within your organization/school network?
and doesn't pervasive tls termination mean that Cloudflare/etc sees plaintext anyway? do we really believe that palantir isn't tapping into that?
i can imagine just a few scenarios where hiding content on the web actually achieves something. mainly stuff like webmail, web chats, banking.
firesteelrain · · focus · HN ↗
A lot of what sounded extraordinary in 2013 is now baked into everyday discussion like metadata and mass surveillance. He is also available less for interviews because he is in Russia.
Basically bigger fish to fry
commandersaki · · focus · HN ↗
Lammy · · focus · HN ↗
judge2020 · · focus · HN ↗
The internet is only more concentrated because most people choose price and convenience over a foolproof level of security. The cost/effort required to surveil traffic in coordination with TLS-terminating CDNs is multiple orders of magnitude higher than the effort needed to throw some high-Tbps middlebox in an IX rack to siphon every packet passing through it.
Lammy · · focus · HN ↗
Not what I'm saying. No coordination is necessary. I'm talking about metadata, not encrypted contents — just the fact that you made some number of connections, at a certain time, from a certain network, to a certain network, in a certain order, with requests and responses of a certain size. It really doesn't matter what's inside.
- <a href="https://kieranhealy.org/blog/archives/2013/06/09/using-metadata-to-find-paul-revere/" rel="nofollow">https://kieranhealy.org/blog/archives/2013/06/09/using-metad...
- <a href="https://youtu.be/kV2HDM86XgI?t=1072" rel="nofollow">https://youtu.be/kV2HDM86XgI?t=1072 “First of all, David's description of what you can do with metadata […] is absolutely correct. We kill people based on metadata.” ― Former NSA and CIA director General Michael Hayden (2014)
nl · · focus · HN ↗
It's ridiculous to argue otherwise.
It's true that general resources could be cached in some cases, but personalized information couldn't be (and yes was served over HTTP, not just HTTPS).
> It really doesn't matter what's inside
It certainly does matter what is inside, and it's trivial to think of cases where it does. Hiding that content is much much more valuable.
> We kill people based on metadata.
Sure, but they also kill people based on content.
ShinyLeftPad · · focus · HN ↗
and doesn't pervasive tls termination mean that Cloudflare/etc sees plaintext anyway? do we really believe that palantir isn't tapping into that?
i can imagine just a few scenarios where hiding content on the web actually achieves something. mainly stuff like webmail, web chats, banking.
nl · · focus · HN ↗
Just visiting, sure but if you edit it to leak a secret the protection is everything.
Say you are on your school network and leak something damaging about the school on Wikipedia.
Prior to Wikpedia switching to HTTPS, both the school and any intermediate network could see
After HTTPS, your school could see That's strictly better in every way.layer8 · · focus · HN ↗
It’s really not, because knowing when you edited it is already enough, given that there’s a timestamped edit history.