this post was submitted on 24 Jan 2024
23 points (87.1% liked)

Privacy

31253 readers
661 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS
 

If any of you have been browsing r/privacy lately you would have come across the British student who had the Air-force literally swarm the flight he was on. This is because he made some joke about a bomb sitting in an airport.

Current speculation suggests that Snapchat has a word-filter and could locate the IP as that of an airport, and notified authorities immediately. Another, somewhat less plausible reason posited is that the government holds the private keys for TLS-encrypted traffic for Snapchat and could decrypt and read the message and that's how they knew.

~~For the paranoid people here: the latter claim, even if it is not true, poses great concern to us. If im may be permitted to run with it; It essentially means that using a public CA isn't exactly safe anymore. For all of you homelabbers using Let's Encrypt - think again.~~ Don't listen to me, I don't understand certificates well.

Talking on a tangent: let us consider the position of TOR. It has been said that TOR devs accommodate the government and the government has backdoors built in TOR. And even if they didn't, the technique of owning a majority of instances running TOR nodes will allow them to identify and associate traffic. TOR is not safe if you want to really keep your content private. On a similar vein, I am a bit skeptical of the privacy advantages of using session, but I have yet to read their whitepaper.

I haven't read much about i2p, but I wouldn't be surprised if the government has their paws in there too.

What are you doing to browse and communicate privately today?

all 7 comments
sorted by: hot top controversial new old
[–] [email protected] 13 points 7 months ago (3 children)

I don't believe it's possible for a CA to decrypt TLS traffic with their private keys. They sign a site's public key with their own private key after verification but are never given the private key itself. Public CAs only provide identity verification, they do not take part in the encryption process itself. Let's Encrypt is perfectly safe in that regard.

[–] [email protected] 3 points 7 months ago

This is correct.

[–] [email protected] 2 points 7 months ago* (last edited 7 months ago)

Yep, until you find out who owns the most widely used elliptic curves...

That's exactly what's going to happen here in the EU, CA for europe with special EU elliptic cruves with known weakness to spoof on the traffic !

[–] [email protected] 1 points 7 months ago

You're right. I'll edit the post

[–] [email protected] 6 points 7 months ago (1 children)

The Snapchat has a word-filter suggestion makes most sense. But then again Cloudflare is very popular on the Internet as the cheap and well-known MITM anti-DDOS tool.

I haven’t read much about i2p, but I wouldn’t be surprised if the government has their paws in there too.

You will have to trust something if you want to communicate, there's also GNUnet, ZeroNet, DeltaChat, and probably a lot more.

[–] [email protected] 2 points 7 months ago

Ah, I completely missed this. Of course they use Cloudflare, perhaps the biggest MiTM-service on the planet.

Thanks, this makes a lot of sense