Khannie wrote: » I use gmail for example. Have their SSL keys been compromised?
AnCatDubh wrote: » If they are sitting with a fat pipe running from the gmail or any other server to their data center then i'm guessing they won't need to worry about security measures like SSL. Encrypt before you hit gmail perhaps. At least that will slow them down and by the time they figure out it was an email from your mother for chicken curry, you'll have long left the country :pac:.
Khannie wrote: » SSL is sufficiently difficult to decrypt that you wouldn't bother attempting to unless you had direct access to the keys, and even then it would take quite a bit of compute power to keep decrypting the volume of traffic that gmail generates.
Khannie wrote: » Is anyone else freaking out about the possible implications of PRISM as a non-US citizen?
syklops wrote: » Am I freaking out? Nope. Im not doing anything that the NSA would be interested in. If I was, I certainly wouldn't have a gmail account.
AnCatDubh wrote: » On ssl, won't your ssl only be useful to your email in transit between you and the google gmail server and not as your email is stored on the google server? (i've no particular inside track on what happens on the gmail server so apologies if they are doing something very different).
bedlam wrote: » This? 'I've Got Nothing to Hide' and Other Misunderstandings of Privacy - Daniel J. Solove
Khannie wrote: » Is anyone else freaking out about the possible implications of PRISM as a non-US citizen? I use gmail for example. Have their SSL keys been compromised? I use lastpass. Have they received an order to hand over passwords on an ongoing basis? (I am seriously considering switching to keepass, what a pain in the face though). and so on, and so on. The possible implications of "lawful intercept" on that scale are staggering.
bedlam wrote: » That it is, though it does not handly pgp/mime well which is a big downside. The word of the week is metadata, they may not know what you are saying but that will know who you are talking to and that may be enough. Do it for all to see, that way a wider audience can benefit.
bedlam wrote: » They may be easy to set-up but they are hard to get right when you factor in the human element. People will fsck up and no amount of crypto will protect you from that. This talk on OPSEC is worth a watch. To clarify this, more people using Tor will not make it faster and more reliable. More people running nodes will.
silentrust wrote: » The most important thing to bear in mind is that there is no guarantee of privacy for those people who use it to access facebook or other social media unless you create an entirely new account.
CrinkElite wrote: » You mean possibility. Also, it's long been established that someone who can control a relatively small number of exit and entrance nodes can perform trivial traffic analysis to uncover your identity.
bedlam wrote: » This talk on OPSEC is worth a watch.
josip wrote: » Has anyone had a look at the map of countries monitored? According to newspaper reports it shows data volumes per country, not per capita per country. Is this understanding correct?
Khannie wrote: » I moved to keepass2 today. I had to assume that lastpass was compromised given all the recent revelations. I must say I feel better already. There was a bit of messing to get it working with my phone and resetting passwords but it was worth it.
Khannie wrote: » I haven't seen the map. Have you a link there?
Rev Hellfire wrote: » The heat map moves from green (least) through yellow (more) to red(most), we're a dark green the UK a lighter one. You could read it as we're less monitored.