Forget Finding A Needle In A Haystack… How About Actually Finding Haystack

from the security-through-obscurity dept

We recently wrote about Newsweek’s coverage of Austin Heap and Haystack, a program he supposedly wrote to help Iranian internet users avoid being spied on by the Iranian government. Some of our commenters questioned the overall legitimacy of the story. It has a very too-perfect Hollywood sort of feel to it — and some pointed out the fact that no one seems to be able to actually look at Haystack. It sounds like a lot more folks are skeptical of the claims around Haystack as well. Glyn Moody points us to a post by Evgeny Morozov that rips apart the total secrecy around Haystack, to suggest the whole setup is pretty hard to believe.

I like Hollywood as much as the next guy — and yet something just doesn’t feel right about Haystack. What really bothers me is that one cannot download and examine their software; as far as the Internet is concerned, Haystack doesn’t exist. In fact, Heap says that it is only distributed to trusted contacts inside Iran; putting it online would create a situation where the government could easily get hold of it as well and then reverse-engineer it or ban it or find a way to track its users.

So, in essence, the outside public – including Iranians — are asked to believe that a) Haystack software exists b) Haystack software works c) Haystack software rocks d) the Iranian government doesn’t yet have a copy of it, nor do they know that Haystack rocks & works. (And who could fault them for not reading Newsweek? I certainly can’t). For someone with my Eastern European sensibilities, that’s a lot of stuff to believe in. Even Santa — we call him Ded Moroz — appears more plausible in comparison.

He goes on to note that, at the very least, this security by obscurity actually could be quite dangerous for Iranians actually using this program, since it may be giving them a very false sense of security:

To me, it seems like a no-brainer: if you want to distribute technology that may endanger lives, make sure that the technology is secure. The only good way that I know of to make sure that it’s secure is to let outsiders test it.

Indeed. In retrospect, the Newsweek version of this story had too many holes that should have acted as red flags.

Filed Under: , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Forget Finding A Needle In A Haystack… How About Actually Finding Haystack”

Subscribe: RSS Leave a comment
Anonymous Coward says:

Most other projects are open source and well suited for the task why bother with something so suspicious?

I2P(is java based be warned)

And a lot of others including steganography that is practically undetectable and can be used in any platform securely(i.e. video, image, text, net traffic…). (look in “[edit] Steganography Tools”)

Anonymous Coward says:

Great resource for anonymous networks although is more focused on P2P.

Some other programs:

Omemo motto “Browse the world’s biggest hard drive” (operational) (operational, high security) (Creation of anonymous websites, soon to be open sourced) (the stealth internet, internet overlay that runs on top of the internet and it is anonymous)

RetroShare is a Open Source cross-platform, private and secure decentralize communication platform.
It lets you securely chat and share files with your friends and family, using a web-of-trust to authenticate peers and OpenSSL to encrypt all communication.
RetroShare provides filesharing, chat, messages, forums and channels

Now why with all the options one has, somebody would trust a newcomer that is secretive?

That raises all kinds of red flags.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...