Hacker News new | ask | show | jobs
by dmoy 547 days ago
His one about threat models[1] was hilarious and also scarily prescient. Specifically

> If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them.

Maybe not the "wants your data" part, but the whole pagers-are-actually-bombs thing.

[1]This World of Ours, pdf: https://www.usenix.org/system/files/1401_08-12_mickens.pdf

1 comments

The Mossad/Not Mossad duality is a funny idea, but it isn't true. The NSA doesn't send replacement cellphones to millions of US citizens, they scrape unencrypted data.

They're not going to use a quantum computer on you, if they have one. They're going to embed your emails into a vector space that they can project your sentiment out of.

I mean it's not literally mossad / not-mossad

It's <state-actor-you-basically-can't-stop> / <mostly-just-need-to-do-simple-stuff>

Mossad is just a particular type of the first set

That's the false duality. NSA cannot "be stopped," but they don't use every tool they have available on every mission. When conducting foreign intelligence operations against high-value targets they will use 0days you can't secure against. When they're unconstitutionally surveiling you they'll use http and a large language model. Your inalienable rights are going to be violated by a deal with Google Cloud, not a quantum computer, or even a kernel bug.

In this context, the purpose of tools like "five way secret sharing" is to communicate in a way that can't be broken without revealing the existence of the 0days and exceptions to the judicial process by using them on a hundred million citizens at once. The threat model is a lot of very smart engineers who can passively listen to anything that gets sent over the internet, not Perry the Platypus.