Hacker News new | ask | show | jobs
by tptacek 27 days ago
I think the whole US vs. non-US thing is total crap and there's nothing you can reasonably do with it in any direction, but I always think it's important to point out that US signals intelligence can lawfully compromise foreign communications; that's literally their chartered purpose.
2 comments

> there's nothing you can reasonably do with it in any direction

I wholeheartedly agree. That's why bringing nation state threats into these kinds of discussions is so pointless. If you want security from governments, the amount of security work you have to do is so far beyond what any reasonable person is willing to endure that it makes no sense to talk about on hackernews. That stuff is for real professional discussions at real professional congresses.

> I think the whole US vs. non-US thing is total crap

It's not. US companies can be subpoenaed in the US.

> I always think it's important to point out that US signals intelligence can lawfully compromise foreign communications; that's literally their chartered purpose.

Of course they can. But it's significantly easier to get a warrant to target a company under US jurisdiction.

Foreign companies don't have to be subpoenaed. NSA can simply break in and take whatever they want, lawfully. In light of that, the warrant point you're making doesn't make sense: they don't need a warrant to go after foreign assets.
> NSA can simply break in

You can't be serious …

The NSA can break in the same way the Mossad can assassinate you anywhere in the world. That doesn't mean it's a it's going to happen anytime soon unless you're an exceptionally high priority target. Authorities getting legal access to your personal informations from US companies on the other hand is routine practice. Equating the two is a crazy take.

By the way, you read the argument completely backwards in the first place: the original argument was that even if using an American company means the US law enforcement have full access to your data if they want to, your data is still pretty safe from anyone else there (unless, of course, if you are a high priority target again).

See the original sentence:

> Using e2e from a US-based entity means you are prone to spying from the US government, but at least you know you're reasonably secure against the IRGC, the Chinese intelligence service, the FSB, and so on.

Saying someone's argument is “total crap” without even having taken enough time to properly read the sentence you're criticizing is kinda lame IMHO.

I am 100% dead serious and I kind of don't understand the rebuttal you're trying to write here.
“Cryptography is useless because governments agencies will kidnap you and hit you with a wrench” isn't the hill I expected you to die on TBH.

> I kind of don't understand the rebuttal you're trying to write here.

Fill free to make the effort to read it (again).

I have no idea who you're responding to because nobody on this thread has made that argument.