Remix.run Logo
MangoToupe 3 days ago

> At least one Jira support ticket shows evidence of plaintext capture of email

I would be surprised if western governments didn't do the same, and folks should act accordingly.

perihelions 3 days ago | parent | next [-]

The NSA was storing bulk plaintext emails from (at least) Microsoft, as of the time of the Snowden leaks. Microsoft actively assisted them.

https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-... ("Microsoft handed the NSA access to encrypted messages")

> "Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal;"

> "The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail;"

brookst 3 days ago | parent | prev | next [-]

In general none of the disclosures of what GFW is doing g should be seen as evidence that western governments do not do the same thing. Hope nobody is drawing that conclusion.

bjt 3 days ago | parent [-]

Western governments do not routinely block VPNs.

bigyabai 3 days ago | parent | next [-]

Western governments effectively control 99% of consumer technology, and hack whatever else they can't have. VPNs are a false sense of security going up against a nation-sized adversary like the US.

throwaway48476 2 days ago | parent [-]

They also can correlate packet streams in and out of the tor network.

hulitu 3 days ago | parent | prev [-]

Different phylosophy: why block VPNs when you can monitor them. Most Root CAs are in US.

immibis 2 days ago | parent [-]

Certificate transparency is mandatory in browsers; interception certificates appear in certificate logs to be accepted. Have you found one?

Edit: OCSP has been ended.

edgineer 2 days ago | parent [-]

He might be referring to OCSP. Browsers ping CAs by default, revealing to them the sites that are visited.

arcfour 2 days ago | parent [-]

OCSP is very much on the way out, this is hardly true anymore; although some things still check OCSP, many things do not.

nilamo 3 days ago | parent | prev | next [-]

We don't need to guess, we know they do. That was one of Snowden's big reveals.

oogali 3 days ago | parent | prev [-]

The US has been doing this for a long time (1997), on a targeted basis.

https://en.wikipedia.org/wiki/Carnivore_(software)