Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Get you killed? Don't be so melodramatic.

This implementation is a bad idea to use because of the aforementioned security smell.

Another implementation would have to solve the problem of how to ensure message security while still being able to deliver the message at the right time.

The "right" answer for something like this is as you said, lawyers, but "get you killed" is... overly dramatic. Snowden is, after all, still alive.



We detached this subthread from https://news.ycombinator.com/item?id=12629216 and marked it off-topic.


It's not off topic, though.

Can we discuss this over email?


It became off topic by turning into a flamewar.

If you don't want this to happen, I suggest taking more care to edit flamebait out of your comments. Leading with "Don't be so melodramatic," "That's so unbelievably false it makes me sad that you," "You stop", etc. guarantees poor results and therefore off-topic snippage.


Stop. Broken privacy tools have gotten people tortured and killed. Just because you can't imagine it happening to white dudes in the US and western Europe doesn't mean it isn't the norm pretty much everywhere else.

You were fine before your "Snowden is still alive" thing. I don't have an opinion about whether Stavros's site is a serious privacy application. Maybe it isn't. But other manifestly unqualified people have tried to deliver privacy to people and failed catastrophically.


It is definitely not a serious privacy application. It's meant for sending things like last goodbyes to loved ones, not state secrets. I will make this clearer on the front page, on a second read the "stored securely" part might be misread as "secure against the NSA" rather than "secured against a curious DB admin", thanks for the clarification.


I'd go pretty far in that direction, were I running this service. Something along the lines of "hey, I do my best, but anything that'd significantly impact anyone's life if it were disclosed accidentally or compromised is best stored offline, with information on how to find it being all that's actually set up to go out via my service." And maybe I wouldn't even be comfortable with that.

Actually, on further reflection, I wouldn't be comfortable running a service like this at all, for reasons amply detailed elsewhere in these comments - in short, it's a great way to paint a target on your chest for everybody from random scammers to state-level actors. I must admit I am considerably impressed by your courage in continuing to do so. Don't get me wrong - I think you must be a madman. But I can respect a very brave madman!


I added something here (https://deadmansapphr.appspot.com/help/), hopefully it's clear enough, but let me know if you have any feedback. I would hate to have people thinking this is secure against the NSA or anything.


It's clear as far as it goes, but as I said before, I don't think it goes nearly far enough. It's not just that messages stored with your service aren't secure against state actors - messages stored with your service aren't secure against anyone with the nous to compromise the host(s) on which it runs. And I hope you'll forgive me for saying that, given that you managed to overlook trivial CSRF for a year in the application's request handling code, I'm not entirely sanguine that your host configuration is strongly secure against any, perhaps even most, non-state actors.

That's not something I like saying, and I can't imagine it's all that pleasant to hear, either. I wouldn't say it at all if I did not feel it necessary, and I feel it necessary precisely because there seems to be a severe mismatch here between the gravity of any potential compromise of your service and the measures taken to prevent such a compromise from occurring. You know a lot more about the nature and scope of those measures than I do, of course, and it's possible I'm underestimating them here. I do hope that's the case. If it is, please accept my apologies for having spoken harshly where doing so was unwarranted. If it isn't, I hope you'll attend to that situation as best you can without delay. If you're not sure, then for the sake of your users, I hope you'll bring in someone with the capability to evaluate and resolve whatever security issues exist, and do so with as little delay as possible.

In any case, you've (perhaps accidentally) put yourself in a position that encourages people to invest a great deal of trust in you, and it seems that many people have done so. Had I put myself in such a position, I would not be comfortable remaining in it if I could not be entirely confident I had either done everything within my power to fulfill that trust, or removed myself from that position without betraying the trust I'd found myself ultimately unable to fulfill. But that's just my own evaluation, and perhaps you feel differently.


Sorry. I totally believe you --- but if I were you, I'd take extra care to make it clear that this isn't a security tool, just because of the nature of the secrets you're inviting people to vouchsafe with you.

I'm responding more to the indignant claim that casual security/privacy tools can't harm people. It's true: they are very unlikely to harm the kinds of people who read and write comments like these. Like I said, it was the allusion to Snowden that moved me to comment.


> if I were you, I'd take extra care to make it clear that this isn't a security tool, just because of the nature of the secrets you're inviting people to vouchsafe with you.

Yes, definitely. I need to spend a bit of time clearly communicating "it's fine for telling people you love them, but not that your multinational's CEO defrauded millions of pensions".


> Maybe it isn't.

Given the way people are likely to use it, I can't see how it would not be.


That's so unbelievably false it makes me sad that you, a respected member of the security community, are touting it like a clear and present danger to anyone reading this site.

You stop.

Edit: I'm being absolutist because it's easier, rhetorically, but if I have to be explicit, I'm saying that the realistic occurrence of murder as a result of privacy tool usage, one way or another, is low, to understate things. To talk about murder as a problem in cybersecurity is like talking about meteors hitting car windshields.


>To talk about murder as a problem in cybersecurity is like talking about meteors hitting car windshields.

Have meteors hit car windshields? Because people have died by not correctly securing sensitive information.

Read this: https://www.washingtonpost.com/news/worldviews/wp/2016/06/13...

Then consider that 'coming out of the closet' would be a very viable use of a site like this if someone is gay and they live in an oppressive country.


Yes, meteors have hit cars windshields, a Google will reveal.


Are you suggesting it's "unbelievably false" that broken privacy tools have gotten people tortured and killed? A lot of us in the "security community" know this to be true, with specifics.


I'm suggesting it's not worth talking about seriously for a toy like in the submission.


There's a paid subscription option, and its developer's comments elsewhere in this thread very strongly suggest people are using it in a serious fashion. If you're thinking of it as a toy, your threat model is bogus.


It's a toy, regardless of what the developer says.


But not regardless of how people use it.


Yes, actually, regardless of how people use it. You can't stop people from using the wrong tools.


You can, and I think ethically must, take responsibility for the fashion in which people use the tool you make.

If you intend it to be only a toy, then you can, and I think ethically must, make that clear.

If people persist despite all warnings in using it in ways that might cause them harm, then you can, and I think ethically must, cease to make it available.

To do otherwise is dangerously cavalier at best, and incompatible with the minimal degree of responsibility which I would require of an employee or a colleague. Perhaps you feel otherwise. That's your prerogative. But, if so, I do hope, for the sake of any users you might have, that you aren't in a position to make similar decisions yourself.


I didn't write it, you're going to have to take that up with the author, on what his intended use case was for his website.

Sounds like he did what you said, anyway.


I'm not talking about 'StavrosK's service here. I'm talking about your evaluation of threat models, which seems to include a great big exception around "well, if people aren't using it the way I want them to, then to hell with them."


Well yeah, actually that's how threat models are built -- you can't protect users from themselves, if a user wants to store all their passwords in a greeting card website, in the little "special message to your loved one" field, there's realistically no way you can stop them.

Your greeting card website's threat model doesn't include this.


Reductio ad absurdum helps no one, you know.


It helps illustrate how what you said isn't clear or true.


Does it? It seems like you'd need to argue that this notional greeting card website made some specific claim of security around the content of that field.


No, because Dead Man's Switch doesn't do that either.


How do you reach that rather startling conclusion?


No, I'm done. The author of the tool has come out and explained things to you directly, and if you're going to keep playing games, you can do that with someone else.


Who's playing games? I've read the comments in this thread from 'StavrosK. You and he don't appear to be talking about the same service, and he's the dev. But if you don't feel any purpose would be served by your continued participation, that's your call to make, of course.


You might try re-reading my comment, all the way through.


I'm not sure, but perhaps the parent poster's idea was that if you have secrets that would be released if you die, you might give people who want to know those secrets an incentive to kill you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: