Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You know who the intercept is, right? It was started by Glenn Greenwald and Laura Poitras, specifically for safely handling, processing, and releasing the Snowden documents and others like it.

Personally I would trust them MUCH more than the New York Times. Well, unless the documents were specifically only damaging to Trump.



Here's how Greenwald initially handled Snowden's leak [1]:

Snowden anonymously sent him an e-mail saying he had documents he wanted to share, and followed that up with a step-by-step guide on how to encrypt communications, which Greenwald ignored. Snowden then sent a link to an encryption video, also to no avail.

“It’s really annoying and complicated, the encryption software,” Greenwald said as we sat on his porch during a tropical drizzle. “He kept harassing me, but at some point he just got frustrated, so he went to Laura.”

From another source [2] I cited in another comment:

"it took Greenwald several more months and help from experts before he could learn relatively basic tools like PGP encryption."

That's not exactly trust-inspiring, I'd say.

[1] http://www.nytimes.com/2013/08/18/magazine/laura-poitras-sno...

[2] https://www.dailydot.com/layer8/edward-snowden-gpg-for-journ...


1. That doesn't refute or otherwise respond meaningfully to parent's points.

2. It makes clear that providing better channels to enable legitimate whistleblowers to find a publication channel was critically important.

3. It's exceedingly easy for anyone to ignore a critical insight -- whether it's some annoying anonymous leaker, or an odd set of lab results, monitoring readings, etc. Those insights are critical in large part because they fall outside norms and expectations. (This is, generally, a major block to creativity.)

4. There are a lot of contacts which aren't of mind-blowing significance. Filtering the noise is another problem.

5. Greenwald and The Intercept were specifically created to address these shortcomings. Among The Intercept's staff is Micah Lee, technologist with the EFF. (I've pinged Lee on Mastodon over the Intercept's gross failure here -- it is a massive fuckup.)


>That doesn't refute or otherwise respond meaningfully to parent's points.

It shows that Greenwald's association with the Intercept cannot be used to imply that it practices good security.


This seems pretty untrue. The excerpt shows that at one point, pre-Snowden, Greenwald was an unsophisticated user who didn't want to deal with PGP, just like 99% of reporters. But it's responding to a point about Greenwald, post-Snowden, establishing The Intercept specifically to handle security reporting and anonymous leaks. That's not a claim that he's Moxie Marlinspike, it's a claim that The Intercept has much more emphasis on security than news orgs without those origins.

And, more broadly, citing his pre-Snowden behavior seems unreasonable. For literally all people, there was a point where they didn't know PGP, and another point where they were confused and just learning to use it. If you trust their current knowledge of it, that's hardly a serious criticism.


You are responding as if I claimed that Greenwald's association with the Intercept implies that therefore it is insecure, but I did not. There seems to be a problem with logical quantification under negation in your response.


I think you misunderstood me - I'ma actually making a stronger statement than you think, so there's no issue with negation here.

As I read you, you did not say that Greenwald's association with The Intercept implies it is insecure. You did say that Greenwald's delays in adopting PGP mean "that Greenwald's association with the Intercept cannot be used to imply that it practices good security".

I didn't miss that distinction, but I'm making a stronger assertion - I think his presence does (weakly) imply good security. I think that "Greenwald's association... cannot be used to imply" is false.

If we're resorting to logic for this, you're suggesting that Greenwald's presence should not raise our expectation of good security (which is, as you point out, different than saying it should lower our expectation). I'm saying that it should raise that expectation, so we really do disagree.


You may not have claimed that, but ckastner's comment, "That's not exactly trust-inspiring, I'd say," pretty much directly impugnes The Intercept's security and trust.

https://news.ycombinator.com/item?id=14497729


I don't see that as the argument being made, which renders it a strawman.

It's possible for someone, without a specific talent X, to create an institution to ensure proper application of some talent X, when the need for competent execution of X makes itself apparent.

Again: you're not arguing a relevant point, despite the truth value of your statements. This is an irrelevant discussion.


> I don't see that as the argument being made, which renders it a strawman.

But that's how I, and apparently others, read the grandparent's argument.

The grandparent made a personal statement about trust in The Intercept, and did not really substantiate this trust other than by mentioning two key players.

> It's possible for someone, without a specific talent X, to create an institution to ensure proper application of some talent X

I fully agree -- one need only think of huge conglomerates who manufacture everything from light bulbs MRI machines to aircraft engines, to use GE as an example.

> when the need for competent execution of X makes itself apparent.

And therein lies one problem as I see it: it has to make itself apparent to the creator (resp. leader).

Because the converse is also true: It's possible for someone, without a specific talent X, to create an institution which fails ensure proper application of some talent X.

From another comment, we seem to agree that there should absolutely have been policies and procedures in place that should have prevented this mess in the first place.

I posit that this is one of the things that should have been apparent from the start (as preserving anonymity is crucial to The Intercept's cause), yet most probably weren't.


I differ on the first claim, though agree it's possible to read it that way, and accept that you have. I see this more as "a need was seen and the initiative was taken" argument, perhaps poorly articulated.

The following arguments you make, here, are actually pretty good. The one you you'd lead with was poor, as I've already addressed.

I'd especially like to emphasise your point on the failure of good intentions. That's highly salient, and something that should probably be kept generally in mind with tech startups -- many of which seem to sprout like mushrooms from the dark and ... fecund substrata of Silicon Valley and YC ... and yet fall short of their respective putative aiming points.

(That The Intercept can trace its roots to start-up culture may also be relevant here, through Omidyar.)

The interesting (and troubling) part of this story is that it involves four members of the staff, working together, none of whom is named "Glen Greenwald", and presumably with the technical support of Micah Lee. And yet we've still seen what we've seen.

Definitely room for improvement.

But it's still a bit rich to pin the fault on Greenwald specifically, and pre-Intercept Greenwald especially.


Who started it has no weight, that is just an appeal to authority. What does matter is how they conduct themselves and they made enough mistakes here to avoid them like the plague if you have something important.


>Glenn Greenwald

Uh, I suggest you read about how poorly he handled the Snowden materials and how he's about as tech savvy as my grandpa. This fuck-up alone is inexcusable.


Why is this downvoted, it is factually correct. Greenwald did not appear to be at all tech savvy or prepared to deal with such sensitive info. And this fuck up certainly does nothing to improve the picture.


Because it's actually irrelevant to, and a counterargument to, the case being made, as I've commented at length elsewhere in this post.


Notably, this article specifically points out a much more obvious NYT screwup - they released a Snowden doc using digital PDF 'black highlights' that didn't destroy the underlying data.

That's a mistake I think most security-conscious, tech-savvy non-professionals would avoid. The printer steganography here is a substantially more subtle error than the one we already say the NYT commit.


Even after this fuck up?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: