When setting up multiple VPSs connected by "private networking" with a company like Linode, or Digital Ocean, or what-have-you, you need to assume that the inter-VPS links are not secure. It's a little piece of knowledge that comes with experience, hard for newbies to realize.
The first time you set up one of these clusters, you might follow one of Linode or DigitalOcean's handy guides, where they might suggest i.e. a reverse proxy server receiving (and decrypting e.g. HTTPS) inbound traffic, routing it out to multiple worker machines, and a single backend database system. Linode sells dedicated Load Balancers for the front end of exactly this sort of set-up.
These guides almost always fail to mention that the data is observable as cleartext in the internal network. They ought to be reedited with big bold warnings starting that these links ought to be secured. (Can Linode's Load Balancers even secure these links?) Besides other eavesdropping customers, there could potentially be little magic government agency plugs installed -- or the eavesdropping customers could be government security agencies themselves. (Sorry, tinfoil, I know...)
OpenVPN connections are a lightweight, efficient solution. They're also transparent once you change IPs from those of the virtual network interfaces to those of the secure virtual network interfaces. Such a configuration is still non-trivial, though, for someone configuring their VPS via a control panel rather than the command line.
The recent past seems like such a dark time for people who are skeptical of all this State Spycraft stuff.
An award to a good film about an essentially important issue, with a little dark (or darkly sinister, take your pick) levity by Mister Oscar, and you start to feel that there is a glimmer of hope...
The EFF can justifiably rant and rave and they do a good job at it. But a little nod from a general public institution seems, to me at least, to provide a special sort of boost.
I think the worst aspect of all these bad actors is how they use misleading language to hide what they are doing.
Consider PrivDog's sales pitch:
PrivDog® protects your privacy while browsing the web and more! Get safer, faster and more private web browsing today!
In fact, the point of the software from PrivDog's perspective is to replace web ads from third-party ad networks with web ads from PrivDog's own third-party ad network -- i.e. AdTrustMedia.
Similar language is used in Lenovo's ex-post-facto sales pitch for Silverfish:
The goal was to improve the shopping experience using their visual discovery techniques.
No, the goal from your point of view was to insert your own advertising network links into user's webpages. And it's installed by default (no need to worry... you can trust your new Lenovo machine!) as a self-encrypted subsystem (which underscores the tricky intentions).
Perhaps the use of misleading language is what primarily leads people to regard these sorts of things as inappropriate bait-and-switch badware installs? The problem is, of course, that these sales techniques work, or at least the offending companies seem to believe that they will work for enough unsophisticated users.
+1 no giant full-width+full-height responsive image
Okay this looks really interesting! And with no full-width+full-height responsive image, I can proceed... it's something different, something not exactly 100% what you would expect...
So intriguing... so what, dear MagicMan, is it? Would you kindly answer dear Sir, because I'm uncertain, and curiously in need of an answer before I text myself down the rabbit hole...
I think it's interesting that this BADWARE install was found more or less accidentally... apparently by some tech dude noticing that his bank login presented a Silverfish-issued CA cert.
Shouldn't the possiblity have been forseen and addressed beforehand?
Perhaps by...
(1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification?
(2) Microsoft. Do their license terms really allow OEMs to install MiTM proxies and screw around with the root certs? Microsoft could do a good thing here by disallowing this sort of malfeasance... or is there some problem I'm not seeing with such an action?
If this were done in, say, OS X (unrealistic, of course), it would be found out and the whole tech world would know about it in a jiffy. John Siracusa would be howling at the Internet moon within a couple of hours...
Dudes... I don't really care... I just want a way to synchronize my VPS clock with that of other, established, secure clocks... because DigitalOcean (okay, go ahead and downvote me) is not quite synched, and neither is Linode, and my server!!! Oh good Lord my server don't know the time at all! Dudes... just agree on something that I can install SIMPLY... 'cuz the infighting between ntp and openntp ain't nothing that I care to be involved with... JUST MAKE IT EASY!!!!
Okay, Brittney Bronson, it is what it is... You teach the young grown-ups / old kids at the college, and then you shuck it in your part-time service job... It is what it is...
I think people just want to see the film. I certainly want to see the film. It might have a crappy plot or a second-rate screenplay or subpar acting, but with this sort of publicity none of that matters. Just watching it will be an event, perhaps an even bigger event than watching The Last Temptation of Christ was way-back-when...
Anyway, Sony seems to be in a defiant stance. It doesn't seem like Sony is going to yield; it seems like they are going to just find an alternative distribution path: "No thanks, 2600. We got this. After all, this is the sort of hype that we'd... uhh... kill for.... uh..."
Seems like somebody in the DoJ just decided that Tor's balance between geeky CompSci curiosity and enabler of real-world criminal behavior has tipped too far in the latter direction. The legal case has been ripe for a while-- after all, Megaupload and many other networks have been disabled by the US government for enabling significantly LESS serious criminality. Ummm... world's biggest drug marketplace, anyone??? What's important to remember is that the gov't can't just go in and seize the directory authority servers willy-nilly. Instead, they must do it as part of a legal process against a specific, identified target. In this case, the likely target is going to be the Tor project itself and possibly the individuals leading it. The legal case might ruffle a few techie feathers but only an insignificant portion of the general public will care, and that portion can be mollified with the "stopping the bad horrible criminals" routine.
Dude. You come to SV to make it. Kids, house, schools... they all need to be taken into consideration, sure... but you can't just choose one part of your lifestyle while assuming that you'll be able to continue on with no effect on the other...
Yes, it's a cooker. So what? You want the cooker, sign up... You don't want it, then pass, and start counting your already-existing chickens...
Don't care about cars. Care about those devices called "humans". These dudes fixes and tuned the latter while appearing to fix and tune the former. And one will not be the same without the other. So many fond memories...
Dude. $750K for Intel. They spend more per day on psychological counseling for their chip geek employees who think they're living in the Matrix. Ain't gonna force them to backdoor nothin'... ain't gonna be punishment either for not doing a backdoor job when they were told nicely to do a nice backdoor job.
Sure, my tinfoil is as good as anybody's... REYNOLDS WRAP HEAVY DUTY... best there is... but this seems to be a clear case of some bureaucrat applying the rules he or she has been given to the case he or she has been given... Nothing else...
And if you need a "high-quality suite of tools for debugging", then all you need to do is look for them... Preferably not in Firefox Extensions, because they are malware-prone...
Yeah, but it still seems like a great service. This... versus the $5/mo to pay to DigitalOcean to host essentially nothing other than postfix & cyrus daemons... is quite reasonable. Please don't let the Spectre of Spammers discourage you from this very appealing old-school sort of venture...
The first time you set up one of these clusters, you might follow one of Linode or DigitalOcean's handy guides, where they might suggest i.e. a reverse proxy server receiving (and decrypting e.g. HTTPS) inbound traffic, routing it out to multiple worker machines, and a single backend database system. Linode sells dedicated Load Balancers for the front end of exactly this sort of set-up.
These guides almost always fail to mention that the data is observable as cleartext in the internal network. They ought to be reedited with big bold warnings starting that these links ought to be secured. (Can Linode's Load Balancers even secure these links?) Besides other eavesdropping customers, there could potentially be little magic government agency plugs installed -- or the eavesdropping customers could be government security agencies themselves. (Sorry, tinfoil, I know...)
OpenVPN connections are a lightweight, efficient solution. They're also transparent once you change IPs from those of the virtual network interfaces to those of the secure virtual network interfaces. Such a configuration is still non-trivial, though, for someone configuring their VPS via a control panel rather than the command line.