TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

My Privacy Plan

58 pointsby benrmatthewsalmost 12 years ago

10 comments

u2328almost 12 years ago
Well, I don't think I've ever felt so paranoid. Thanks President Obama, this is the exact opposite thing we wanted you to do when we voted for you.
评论 #5851337 未加载
dkokelleyalmost 12 years ago
There is a fundamental problem with being truly secure online. That flaw is that the sites and services we use are compromised. In order to me to write this comment, I&#x27;m relying on the free wifi at Starbucks to not log my actions. I&#x27;m relying on their ISP to not log the traffic to HN&#x27;s servers. I&#x27;m relying on Google&#x27;s Chrome browser to correctly recognize HN&#x27;s certificate and encrypt my packets properly, and I&#x27;m relying on Entrust Certification Authority to correctly assert that I am actually sending my data to HN and not an intermediary. Then I&#x27;m relying on HN to receive my data and store it securely (well, as secure as I should expect a public forum to be, but the scenario applies just as well to banks and email providers). Finally, I&#x27;m relying on all software installed on my laptop (including the operating system) to respect my privacy by not logging keystrokes.<p>Any 3-letter agency that wanted to track my internet usage only needs to collude with one of these services to compromise my privacy. I think the solution to privacy is a combination between government transparency and accountability, and our own due diligence to carefully vet the programs and services we use.
评论 #5851757 未加载
RexRollmanalmost 12 years ago
In today&#x27;s environment, the most secure person computing set-up might be Richard Stallman&#x27;s. I don&#x27;t think I could do it though, as it is too restrictive.<p><a href="http:&#x2F;&#x2F;stallman.org&#x2F;stallman-computing.html" rel="nofollow">http:&#x2F;&#x2F;stallman.org&#x2F;stallman-computing.html</a>
lake99almost 12 years ago
There&#x27;s one more thing all Tor users with good bandwidth should consider: start relaying.<p>I relay when I can, which is not very often because I am mostly behind a NAT which I have no control over.
jd007almost 12 years ago
If everyone uses Adblock, it could be detrimental to a lot of free web services that are supported solely on ad revenue. I am not sure if there is a good solution here...
friscoalmost 12 years ago
I feel like this is a rather porous plan for privacy.<p>&gt; 1. Sign up to relevant pressure groups<p>Ok, I like this one. No reason not to. Support the EFF.<p>&gt; 2. Install HTTPS Everywhere<p>Since I believe that the NSA likely already have all of the relevant private keys, I&#x27;m not sure about this one. HTTPS is still better than no HTTPS, but don&#x27;t overestimate it.<p>&gt; 3. Install Adblock Plus<p>Yep ok. Making it harder to be tracked across the internet is good.<p>&gt; 4. Review my browser use<p>Sure. Use Chrome + best practices.<p>&gt; 5. Review web services I use and switch if necessary<p>Suddenly this appears: a catch-all &quot;change everything I do on the internet&quot;. Stop using Facebook, Skype, Gmail, etc. Probably not going to happen. I&#x27;ll come back to this in a second.<p>&gt; 6. Download and Use Tor<p>Given my belief that the government is probably running enough nodes to reconstruct Tor identities, I&#x27;m not convinced that this helps much.<p>&gt; 7. Use the Onion Browser on my mobile<p>See #6.<p>&gt; 8. Run &quot;host-proof&quot; Web applications<p>This is an extension of #5. I like the idea, but this is hard. Startups like Ciphercloud and Social Fortress are ostensibly working on it; I look forward to when they&#x27;re available. I imagine that if any significant percentage of people start using, say, Social Fortress on Facebook, Facebook will make it against the TOS.<p>I do think that the NSA has probably broken RSA. It&#x27;s notable that they haven&#x27;t approved it for securing classified data, despite the fact that it would significantly simplify the DOD&#x27;s current pains around key distribution. This, of course, takes SSL with it, but importantly takes PGP, too. Running GPGMail on a desktop isn&#x27;t enough.<p>###<p>My privacy plan will involve learning more about politics. Who are our representatives? What districts play disproportionate roles here? How are the oversight committees formed? Who&#x27;s on them and why? What can we do to be involved? This is a much longer timescale play -- it&#x27;s a lifetime of being involved, rather than a quick technological fix now. I&#x27;m not confusing a personal interest here with having influence -- I&#x27;m just one person, and not a high-profile one, and alone I won&#x27;t have much impact. But, I don&#x27;t believe that there&#x27;s any substitute for a politically engaged constituency.<p>I don&#x27;t believe that Washington is fundamentally corrupt or irreversibly damaged. In the Snowden video he spoke about how these decisions are viewed as policy and not law -- so a future president may decide to go off the deep end into despotism. But since it&#x27;s still policy, there are systems for this. It&#x27;s not ok to simply complain that the system will defend itself and there&#x27;s nothing you can do. Apply the same mindset that drives you through the multiple brick walls that are a startup to changing Washington.
评论 #5851051 未加载
评论 #5851148 未加载
评论 #5851765 未加载
评论 #5851209 未加载
评论 #5851432 未加载
mtctalmost 12 years ago
This is a good start, but in the end the NSA can bypass any of these measure if needed (even the cryptography). The only think that really can change this situation is a protest versus your political representatives.
评论 #5850829 未加载
noerpsalmost 12 years ago
Learn and understand crypto, develop and follow procedure to embrace secure end-to-end communications with your peers.
yekkoalmost 12 years ago
Move out of the US.
评论 #5851553 未加载
Hyrum_Graffalmost 12 years ago
Here&#x27;s what I did. <a href="http:&#x2F;&#x2F;www.battle-school.co.uk&#x2F;Blog&#x2F;2013&#x2F;06&#x2F;08&#x2F;its-our-own-fault-deal-with-it&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.battle-school.co.uk&#x2F;Blog&#x2F;2013&#x2F;06&#x2F;08&#x2F;its-our-own-f...</a> Got rid of every cloud based service I use.
评论 #5852056 未加载