Earlier quoted context omitted.
Yeah I know about the AT&T splitters mentioned in the footnotes. But the Snowden leak was a lot bigger than that. Did 0xCMP know that the NSA was recording the full contents of every cell phone call in the Bahamas and keeping them around for at least 30 days?
We didn't know but it wasn't paranoid to assume it. The reason was the Echelon leaks and what was done about those. The answer: nothing.
Edward Snowden: The Internet Is Broken
51–60 of 180 posts
Re: Edward Snowden: The Internet Is Broken
#52Earlier quoted context omitted.
Foresight has been essential in this. Without Stallman's foresight of the need for public domain open source software, there would only be proprietary software, all subject to PRISM. Without the foresight of potential Government's to come the US founding fathers would not have written in such protections as still exist today. Before Snowden there were many that suspected but now everyone knows. >Um. Who thought this?…
"Without Stallman's foresight of the need for public domain open source software, there would only be proprietary software, all subject to PRISM." Or proprietary, shared-source software provided by nonprofits or companies in jurisdictions that aren't surveillance heavy. No, you don't need FOSS to avoid PRISM lol. It has its advantages in resisting totalitarianism for sure but you don't actually need them. More of aut…
Stallman saw it coming early enough that he had completed his GNU Free toolchain in time for Torvalds to use it.
A developer community is less likely to arise when your modifications can be closed and you cannot fork. If your business runs in someone elses walled garden it can be taken away.
Without the GPL's four freedoms we would not have the rich public domain of code we have today - a legally protected commons.
Before the GPL the public domain suffered from the tradgedy of the commons, a fantastic legal hack.
Re: Edward Snowden: The Internet Is Broken
#53Earlier quoted context omitted.
I heard about those taps in 2008/2009 I think. Snowden hasn't really given us anything truly new. It's also bizarre how quickly everything he presented was/is accepted as fact immediately without question. I think it's way more likely Snowden was intentional. He's still working for the Federal government and the leaks are intentional so that the Federal Government could announce to the world that they are spying on a…
> I heard about those taps in 2008/2009 Back then the excuse was that they were only being used to collect foreign traffic. Snowden revealed their loose interpretation of "foreign" and many more domestic activities happening outside of AT&T NOCs. Foreigners' rights aren't protected by the constitution. Citizens' are and now we have legal standing to force the government to respect the law which we didn't have before…
Those who knew how much the system had changed from satellite-intelligence gathering (from the era prior to transatlantic/transpacific submarine fiber, where most phone calls and international data were satellite based), to tapping fiber at submarine cable landing stations and "partnering" with major telcos, were totally unsurprised.
Re: Edward Snowden: The Internet Is Broken
#54The EFF warned long ago something was going on when AT&T was putting beam splitters on Internet backbones to feed the NSA. Then Snowden revealed how everything is tapped. Then, be sure all mainstream encryption is "NOBUS". Nothing is truly random. Someone somewhere has the master key: elliptic curve cryptography using magic numbers from NIST? "Secure boot" by Intel? OpenSSL? Microsoft software? All backdoored. Trust…
I heard about those taps in 2008/2009 I think. Snowden hasn't really given us anything truly new. It's also bizarre how quickly everything he presented was/is accepted as fact immediately without question. I think it's way more likely Snowden was intentional. He's still working for the Federal government and the leaks are intentional so that the Federal Government could announce to the world that they are spying on a…
Re: Edward Snowden: The Internet Is Broken
#55Earlier quoted context omitted.
You knew GCHQ tapped Google's datacenter-to-datacenter links?
http://archive.wired.com/science/discoveries/news/2006/05/70... This stuff has been going on, and widely discussed, for over a decade. But no one really cared or understood the full scope until Snowden's slapped everyone across the face with it.
I too knew about that whistleblower before Snowden. I didn't know about Google intranet being compromised, or things like hostile code uploaded to hard disk controllers, or data exfiltration via compromised in-transit routers, etc.
Re: Edward Snowden: The Internet Is Broken
#56The EFF warned long ago something was going on when AT&T was putting beam splitters on Internet backbones to feed the NSA. Then Snowden revealed how everything is tapped. Then, be sure all mainstream encryption is "NOBUS". Nothing is truly random. Someone somewhere has the master key: elliptic curve cryptography using magic numbers from NIST? "Secure boot" by Intel? OpenSSL? Microsoft software? All backdoored. Trust…
Trust no one
With this sort of attitude you might as well give up on life. Society doesn't work without trust between people.
Re: Edward Snowden: The Internet Is Broken
#57The EFF warned long ago something was going on when AT&T was putting beam splitters on Internet backbones to feed the NSA. Then Snowden revealed how everything is tapped. Then, be sure all mainstream encryption is "NOBUS". Nothing is truly random. Someone somewhere has the master key: elliptic curve cryptography using magic numbers from NIST? "Secure boot" by Intel? OpenSSL? Microsoft software? All backdoored. Trust…
I heard about those taps in 2008/2009 I think. Snowden hasn't really given us anything truly new. It's also bizarre how quickly everything he presented was/is accepted as fact immediately without question. I think it's way more likely Snowden was intentional. He's still working for the Federal government and the leaks are intentional so that the Federal Government could announce to the world that they are spying on a…
Oh for goodness sake. Reality is too boring for you? You could engage with the real campaign that EFF and Snowden and others are trying to get going, or you could wander off and make up some other story that protects you from having to do anything.
Since when does an NSA contractor working from home in Hawaii get VPN access to all the government secretes?
Since the NSA got reliant on huge networks that aren't understood by their own management and they needed to hire in techies to keep it running.
Essentially: big organisations have to choose between (a) crippling levels of security that prevent them from getting anything done or (b) getting things done with a small risk of leaks.
(a) is pointless so everything is heading for (b) and thats why every major news story of the last few years and the next few decades is going to be based around leaks.
Re: Edward Snowden: The Internet Is Broken
#58Earlier quoted context omitted.
Definitely. They could, targets were using it, they were known to tap backhaul microwaves/satellites, their own guideance in high-assurance side was using link encryptors between sites, its in their commercial recommendations (NIPSOM Industrial Security Manual), and so on. Everything in the world to make you think somebody was tapping your line and that they might. So, some groups that were wise went ahead and deploy…
Google's datacenter-to-datacenter links probably weren't going over the public internet, so they didn't feel the need to protect against man-in-the-middle attacks on physical lines that they owned. If you connected two computers to each other with a cross-over cable, would you feel the need to encrypt all communications between them, just in case?
Far as your contrived example, yes I did recommend Layer 2 or 3 encryption, authentication, and monitoring between all nodes for a variety of benefits. It was also in Red Book (Orange Book for networking) as a high-assurance security requirement due to malicious hosts or tapped lines. All the times I eavesdropped on and screwed with Intranets fully justified it. Moreover, reading the Security Monkey later showed he handled a situation where an intruder did a physical splice of the line into a nearby building for his attacks. Just more evidence.
So, yes, security must be applied to every layer inside of and around endpoints, networks, and more. The risk you mentioned, minus crossover part, resulted in numerous hacks in the real world that my methods and 80's era methods would've stopped. In a PCI form factor, too, as DiamondTEK secure LAN did exactly that.
Re: Edward Snowden: The Internet Is Broken
#59Earlier quoted context omitted.
> I heard about those taps in 2008/2009 Back then the excuse was that they were only being used to collect foreign traffic. Snowden revealed their loose interpretation of "foreign" and many more domestic activities happening outside of AT&T NOCs. Foreigners' rights aren't protected by the constitution. Citizens' are and now we have legal standing to force the government to respect the law which we didn't have before…
It was fairly widely known in the network engineering community in 2003/2004 that the "Echelon" system collected an extensive amount of domestic data for each of the five eyes, using legal dodges where a foreign agency (like GCHQ) would siphon american/canadian data and feed it to the NSA and CSE, and vice versa. Those who knew how much the system had changed from satellite-intelligence gathering (from the era prior…
Re: Edward Snowden: The Internet Is Broken
#60Earlier quoted context omitted.
Definitely. They could, targets were using it, they were known to tap backhaul microwaves/satellites, their own guideance in high-assurance side was using link encryptors between sites, its in their commercial recommendations (NIPSOM Industrial Security Manual), and so on. Everything in the world to make you think somebody was tapping your line and that they might. So, some groups that were wise went ahead and deploy…
The core infrastructure security people at Google didn't know it, from what I understand. Maybe they're all incompetent; maybe they were lying; or maybe the knowledge (not rumour or suspicion) wasn't as pervasive as you say it was.