Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Things like this are going to force a confrontation at some point. Either the existing programs for monitoring people are going to become progressively more useless as people switch to HTTPS for example, or the government will insist very forcefully to get access--getting private keys from certificate authorities, for example.


Well we effectively 'won' the last major confrontation (crypto code) so a confrontation is not bad per se.

However this does mean that systems like PRISM and phone metadata will simply become more important as 'upstream wiretaps' go away, and the NSA will surely have other tricks up their sleeves as well.

Of course, anything we can do to make their surveillance efforts require manual intervention (e.g. having to attack an ownCloud installation from within a rented system in the same datacenter) makes those efforts less of a threat to each of us than a completely automated tracking of anyone they wish.


And more worrying than even that, with the top four browser vendors all US-based, would pressure be put on them to not remove the root certificates? That, IMO, is more worrying than government interference in CAs: the system is designed to work around government interference in CAs (by removing the CA root as trusted), but isn't so capable at dealing with government interference of trusted roots.


Due to Firefox and Chromium both being open source, this won't be an issue. If the browser companies remove the ability to remove root certs, we can just fork and add it back.


This isn't a technological issue, it's a political issue. It requires a political solution, since laws can be enacted to make what you're proposing illegal.

The hacker mantra is indeed "There is a key to every lock" but what happens when 1) you unlock a door, 2) they know you unlocked that door, and 3) it's illegal to unlock that door?

Answer: Then they put you in prison.


I'd love to see that headline: Hacker Jailed for Not Updating Web Browser


It would read like this:

A hacker charged with changing YOUR Internet Browser, potentially making the entire country less secure in the face of terrorists, has been found guilty of crimes against the state.


Exactly. Let's not pretend they aren't experts at framing false narratives.

Actually, that's pretty much the #1 prerequisite for the job of a being a politician...


How about Hacker Jailed For Shipping Web Browser With Secure Encryption? That sounds crazy, no? Yet the US has limited availability of encryption before, so why should it not do so again?


What law would be so dumb as to force an American browser to include malicious CAs, publically, and not also force everyone to only use those American browsers?

In your imagined dystopia what you're talking about doing (using a browser with safe CAs) would be illegal no matter where the browser really comes from.


It's no different with locked-down phones/tablets where it's illegal to root it. You don't need to force everyone, just people using American ISPs/carriers.


That's not the issue. The issue is the majority of browser users will use the default set of root certificates. Forking and removing them is the least of the difficulties; getting people to use the fork is the problem.


but not my problem...


Oh, sure, some may know enough and care enough to do something about it, change browser, change root certs — whatever is needed. But this isn't about them, this is about society at large. This is about whether your mother, your father can use their webmail account without being spied on: would you want all your emails to and from them available because of a MITM attack on someone who is not you? (I realise email is not a great example, with emails typically being transmitted in plaintext between SMTP servers, but is reasonable in the generic digital communication sense.)


If you live in a police state where everyone you know is being spied on my the government, that's sounds kinda sucky.


Relevant infrastructure seems less likely to be developed and maintained if an insignificant number of people use it.


This is why HTTPS certificate pinning exists. Having a standardized way of requesting a pin would be a very good thing right now. (See: HPKP and TACK)


Isn't this how the march of technology always works?

Governments knew how to tap analog phone lines well, and when cell phones became popular they had to adapt methods.

Governments knew how to capture or analyze mail traffic, and when the Internet became popular they had to adapt methods.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: