Now majority of web runs on public cloud and "encrypted" by CloudFlare MiTM engine. These are literally centralised mass surveillance platforms.
If you can prove any of the big public clouds are breaking TLS for surveillance purposes, they'll be dead within months. Now is your chance, short them and expose them (or you can even combine with professionals, like Hindenburg Research).
It's about having to extend trust past your comfort zone. Would you be fine with total strangers having your address and your house keys, and a pinky swear to never use them, or would you rather them not have your keys in the first place?
Nothing wrong with TLS. It's just funny how author suggests that someone actually cared about Snowden revelations.
It's like "We were worried about mass surveillance after Snowden so decided to host everything directly on FBI servers" because CloudFlare is exactly this.
> a Frankenstein bill more than 200 pages long, combining the choicest parts of a stack of cannibalized privacy bills that rarely made it past committee. The patchwork effect helps form a comprehensive package, targeting various surveillance loopholes and tricks at all levels of government—from executive orders signed by the president, to contracts secured between obscure security firms and single-deputy police departments in rural areas ... The GSRA is a Christmas list for privacy hawks and a nightmare for authorities who rely on secrecy and circumventing judicial review to gather data on Americans without their knowledge or consent.
Comments
If you can prove any of the big public clouds are breaking TLS for surveillance purposes, they'll be dead within months. Now is your chance, short them and expose them (or you can even combine with professionals, like Hindenburg Research).
These are facts:
1. CloudFlare and clouds obliged to follow US law.
2. Gag orders exist.
It doesn't matter if they actively used for mass surveillance or not. This "encryption" dont protect anything from US government or it's allies.
Uh. Hetzner and Linode just got caught doing it.
https://notes.valdikss.org.ru/jabber.ru-mitm/
https://www.devever.net/~hl/xmpp-incident
You mean how all the telco corporations that, as Snowned releaved, helped NSA conduct mass survailance are now bancrupt? Oh, wait!
It's about having to extend trust past your comfort zone. Would you be fine with total strangers having your address and your house keys, and a pinky swear to never use them, or would you rather them not have your keys in the first place?
I don’t think the concern here is TLS, but rather how CloudFlare works. This is a unique problem to CloudFlare. TLS itself is not the issue.
Nothing wrong with TLS. It's just funny how author suggests that someone actually cared about Snowden revelations.
It's like "We were worried about mass surveillance after Snowden so decided to host everything directly on FBI servers" because CloudFlare is exactly this.
A decade late, but there's a draft bill, https://news.ycombinator.com/item?id=38185720
> a Frankenstein bill more than 200 pages long, combining the choicest parts of a stack of cannibalized privacy bills that rarely made it past committee. The patchwork effect helps form a comprehensive package, targeting various surveillance loopholes and tricks at all levels of government—from executive orders signed by the president, to contracts secured between obscure security firms and single-deputy police departments in rural areas ... The GSRA is a Christmas list for privacy hawks and a nightmare for authorities who rely on secrecy and circumventing judicial review to gather data on Americans without their knowledge or consent.
That's actually a great news. At least some legal barrier is better than none.