<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>BenLog - Latest Comments</title><link>http://benadida-benlog.disqus.com/</link><description></description><atom:link href="https://benadida-benlog.disqus.com/comments.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Mon, 29 Jul 2013 02:12:42 -0000</lastBuildDate><item><title>Re: benadida@square</title><link>http://benlog.com/articles/2013/07/08/benadidasquare/#comment-979746055</link><description>&lt;p&gt;Congrats Ben! Square seems like a great company, and they're lucky to have you.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Casey Oppenheim</dc:creator><pubDate>Mon, 29 Jul 2013 02:12:42 -0000</pubDate></item><item><title>Re: benadida@vacation</title><link>http://benlog.com/articles/2013/07/03/benadidavacation/#comment-953549422</link><description>&lt;p&gt;Bonne chance pour ton prochain voyage:-)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ivan Herman</dc:creator><pubDate>Sat, 06 Jul 2013 06:09:50 -0000</pubDate></item><item><title>Re: benadida@vacation</title><link>http://benlog.com/articles/2013/07/03/benadidavacation/#comment-951161673</link><description>&lt;p&gt;best of luck, ben! i look forward to more baking. ;)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kaitlin Thaney</dc:creator><pubDate>Wed, 03 Jul 2013 21:03:12 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-937247040</link><description>&lt;p&gt;This snooping has been going on a lot longer than 9/11. The US government has long opposed export of effective  technology to keep them from snooping. They placed strong cryptographic technology on the munitions export list regulating it the same as a weapon of war.&lt;/p&gt;&lt;p&gt;I remember the government persecution of privacy advocate Phil Zimmerman in the early '90s.  He had the temerity to publish the cryptographic source code for PGP.   As source code, it would be hard to force PGP to engineer in back doors like they apparently did with Microsoft (&lt;a href="http://www.cnn.com/TECH/computing/9909/03/windows.nsa.02/)" rel="nofollow noopener" target="_blank" title="http://www.cnn.com/TECH/computing/9909/03/windows.nsa.02/)"&gt;http://www.cnn.com/TECH/com...&lt;/a&gt;.  Remember, this was all pre-9/11.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">LUV2SKICO</dc:creator><pubDate>Thu, 20 Jun 2013 23:56:28 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-932929385</link><description>&lt;p&gt;I think Google Calendar and Facebook sharing can be done. Spam filtering's a hard one :-). I'll give it some thought; I don't want to waste any more of your time.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert O'Callahan</dc:creator><pubDate>Mon, 17 Jun 2013 05:59:42 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-929690159</link><description>&lt;p&gt;I guess I don't think it would be nearly that risky. Given how many aggressive viruses are out there on a regular basis, hiding among them is not that terribly hard.&lt;/p&gt;&lt;p&gt;As for services users rely on. Google email filtering. Google Calendar. Facebook sharing. And on and on. None of these can be done without trusting servers.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ben Adida</dc:creator><pubDate>Thu, 13 Jun 2013 15:45:34 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-929155252</link><description>&lt;p&gt;I just don't see the possibility of a government like the US government deploying 0days against millions of users. That would be an incredibly risky strategy compared to harvesting data from servers.&lt;/p&gt;&lt;p&gt;When you say "most features users rely on today", what services are you thinking of?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert O'Callahan</dc:creator><pubDate>Thu, 13 Jun 2013 10:23:14 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-929116436</link><description>&lt;p&gt;Sure, they are more detectable. But in practice, I don't think they are sufficiently more detectable to make a big difference. I also don't think they are more preventable. 0days are on the market constantly.&lt;/p&gt;&lt;p&gt;At the core of your argument is the idea that we *can* make this better with technology, and I strongly disagree with it. Most features users rely on today require trusting servers.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ben Adida</dc:creator><pubDate>Thu, 13 Jun 2013 10:02:22 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-929111658</link><description>&lt;p&gt;Robert: maybe I didn't make the point clearly enough in that blog post :) It's not that I'm burnt out, it's that key management done by users is simply not a viable solution, in my opinion. PICL will help by giving you a password-derived key, so if you remember your password you're fine. But if you don't, you will lose some data. So we're discussing which data is okay to lose if you both forget your password and lose all your devices. Some data may not be okay to lose, and in that case we would store it in a recoverable way in PICL.&lt;/p&gt;&lt;p&gt;In other words, if we want certain features like recoverability, we have to trust servers.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ben Adida</dc:creator><pubDate>Thu, 13 Jun 2013 09:59:51 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928599433</link><description>&lt;p&gt;Reading your posts on "encryption is not magic gravy", I sense you're a bit burned out by the Sync key management issue (and you're not alone!). But maybe that's because you've been focused on the most challenging part of the problem: provisioning users with truly secret keys (modulo dictionary attacks against passwords), and secure authentication. Once we can rely on PICL and Persona to solve those, it seems to me it's relatively easy to rearchitect a lot of applications to distrust servers, with no additional UX overhead.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert O'Callahan</dc:creator><pubDate>Thu, 13 Jun 2013 00:29:35 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928592238</link><description>&lt;p&gt;I think it deflates your "naive" point a bit: "If government agencies believe they have the authority to monitor all &lt;br&gt;Internet traffic, would they hesitate to create viruses that infect and &lt;br&gt;monitor endpoints? Would they hesitate to force software and hardware &lt;br&gt;vendors to build secret backdoors into their products?" The answer is yes, they could do those things, but those kinds of attacks are less threatening because they don't scale so easily and are more detectable and preventable.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert O'Callahan</dc:creator><pubDate>Thu, 13 Jun 2013 00:14:59 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928579837</link><description>&lt;p&gt;That's a fair point, though I'm not sure how much of a difference &lt;br&gt;that part can make in this particular discussion. Do you think there's a&lt;br&gt; big win in the surveillance game here? Certainly on the transport &lt;br&gt;front, yes!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ben Adida</dc:creator><pubDate>Wed, 12 Jun 2013 23:50:15 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928579271</link><description>&lt;p&gt;Chess has "rules". If your opponent plays by those rules, great!&lt;br&gt;If not, then your opponent is not playing chess.&lt;/p&gt;&lt;p&gt;My colon surgeon did not play by the "rules" by not telling me&lt;br&gt;and getting my written permission before directly and intentionally&lt;br&gt;incapacitating my memory for approximately one half hour.&lt;/p&gt;&lt;p&gt;My cousin had an allergy testing nurse not play by the "rules"&lt;br&gt;by not reading my cousins' chart to check for alcohol allergy&lt;br&gt;before wiping my cousins' arm with an alcohol wipe!&lt;/p&gt;&lt;p&gt;So, "laws" are not much use if the sociological equipment (people)&lt;br&gt;they "run on" is malfunctioning by not following them.&lt;/p&gt;&lt;p&gt;Thank you,&lt;br&gt;Eddie Maddox&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eddiemaddox </dc:creator><pubDate>Wed, 12 Jun 2013 23:49:12 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928563402</link><description>&lt;p&gt;Richard: great question.&lt;/p&gt;&lt;p&gt;I do think there is something to solve: users should control their data and, short of transparent due process, that includes protecting it from the government.&lt;/p&gt;&lt;p&gt;I don't think there is a purely technical solution to this problem for lay users. Expert users may be able to defend themselves if they're particularly careful... but I don't think that's relevant to the conversation since I think we need to be thinking about most users.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ben Adida</dc:creator><pubDate>Wed, 12 Jun 2013 23:20:49 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928508941</link><description>&lt;p&gt;Ben's post is on Planet! That's how I found it :-)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert O'Callahan</dc:creator><pubDate>Wed, 12 Jun 2013 22:04:58 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928403747</link><description>&lt;p&gt;Oh, and I agree that most crypto fantasies fall down hard when faced with the realities of human social structures. &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Richard</dc:creator><pubDate>Wed, 12 Jun 2013 20:02:13 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928402139</link><description>&lt;p&gt;I'm interested to know your thoughts on a possible next stage of this. Assume that either we fail to produce good law, or can assume that there is a layer circumventing the law that we know about. That is, you have *only* a technical framework within which to solve this problem; you cannot rely on government actors to behave in any way that you want them to. We can call this "the present day", I suppose. Do you think that there's no pure-technical solution, or no tech+education solution? Or do you reject the premise that there's something to 'solve', either due to a certain view on privacy, or a belief that all acceptable solutions have a legal component? &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Richard</dc:creator><pubDate>Wed, 12 Jun 2013 19:59:37 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928358255</link><description>&lt;p&gt;I think there's a big difference between surveillance methods that leave no trace on the user's system and those that do. For example most governments could get a CA to issue them a certificate to MITM &lt;a href="http://google.com" rel="nofollow noopener" target="_blank" title="google.com"&gt;google.com&lt;/a&gt;, but that can be detected by endpoints and probably cannot be done at large scale without actually being detected. Similar for backdooring systems. We can improve our ability to detect and prevent such attacks, and they don't scale so easily, so I'm more willing to live with them.&lt;/p&gt;&lt;p&gt;I totally agree that whatever we do has to preserve UX. But it seems to me there's a lot we can do to reduce trust in servers while sticking to that constraint, and it's clearly worth doing.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert O'Callahan</dc:creator><pubDate>Wed, 12 Jun 2013 18:52:03 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928279880</link><description>&lt;p&gt;Ben, that's what we're planning with Firecloud. Take a look and see if you think it looks promising&lt;/p&gt;&lt;p&gt;&lt;a href="http://literaci.es/firecloud" rel="nofollow noopener" target="_blank" title="http://literaci.es/firecloud"&gt;http://literaci.es/firecloud&lt;/a&gt;&lt;/p&gt;&lt;p&gt;I'm doug@ mofo :-)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Doug Belshaw</dc:creator><pubDate>Wed, 12 Jun 2013 17:21:27 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-928188931</link><description>&lt;p&gt;Ben, I could not agree more. Why are these not showing up on Planet? Please try to get them on there, there's way too much FUD coming out about Prism, we could use more public stabilizing influences.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Monica</dc:creator><pubDate>Wed, 12 Jun 2013 15:47:31 -0000</pubDate></item><item><title>Re: no user is an island</title><link>http://benlog.com/articles/2013/06/11/no-user-is-an-island/#comment-927508477</link><description>&lt;p&gt;Also &lt;a href="https://newsroom.fb.com/Fact-Check" rel="nofollow noopener" target="_blank" title="https://newsroom.fb.com/Fact-Check"&gt;https://newsroom.fb.com/Fac...&lt;/a&gt; (FB is my employer)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sid</dc:creator><pubDate>Wed, 12 Jun 2013 06:21:20 -0000</pubDate></item><item><title>Re: getting web sites to adopt a new identity system</title><link>http://benlog.com/articles/2013/04/30/getting-web-sites-to-adopt-a-new-identity-system/#comment-898714245</link><description>&lt;p&gt;This is not a "login agent". It is a complete replacement for username/password fragile system. In fact I think this is a direct open source competitor to One Id. Have you even tried the demo? &lt;a href="http://crossword.thetimes.co.uk/" rel="nofollow noopener" target="_blank" title="http://crossword.thetimes.co.uk/"&gt;http://crossword.thetimes.c...&lt;/a&gt;  Tell me the experience is the "same" as the facebook connect crap or etc..&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">FlightOfFancyBee</dc:creator><pubDate>Wed, 15 May 2013 20:57:19 -0000</pubDate></item><item><title>Re: so what if torture works?</title><link>http://benlog.com/articles/2013/04/23/so-what-if-torture-works/#comment-882506709</link><description>&lt;p&gt;+1&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andreas Kuckartz</dc:creator><pubDate>Thu, 02 May 2013 14:21:28 -0000</pubDate></item><item><title>Re: getting web sites to adopt a new identity system</title><link>http://benlog.com/articles/2013/04/30/getting-web-sites-to-adopt-a-new-identity-system/#comment-881528995</link><description>&lt;p&gt;Hi Yehuda,&lt;/p&gt;&lt;p&gt;Interesting, you are the first web developer to suggest this. I think it may be because you know too much about the Web ;)&lt;/p&gt;&lt;p&gt;But seriously, let's dig in and be more precise. Is there a site on which you've considered implementing Persona? What does native Firefox support give you that would push you over the edge? Would you still implement it if you had native Firefox support, but no support on iOS?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ben Adida</dc:creator><pubDate>Wed, 01 May 2013 15:20:32 -0000</pubDate></item><item><title>Re: getting web sites to adopt a new identity system</title><link>http://benlog.com/articles/2013/04/30/getting-web-sites-to-adopt-a-new-identity-system/#comment-881437485</link><description>&lt;p&gt;As a web developer, I can say without hesitation that native Firefox support for Persona would make me much more likely to adopt Persona. From my perspective. the primary advantage that Persona has over other identity solutions is the prospect of native Firefox support. Please prioritize this.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Yehuda Katz</dc:creator><pubDate>Wed, 01 May 2013 13:33:22 -0000</pubDate></item></channel></rss>