Earlier quoted context omitted.
> He needs good friends who host VPNs for him then the state actors would just bug that good friend.
which would require infecting the VPN machines themselves? Just wiretapping isn't sufficient because of public key encryption Assuming the nodes themselves are not compromised (big ask) and identity can be confirmed(like via key exchange), state actors can listen as much as they want to the wires, they won't be getting much. Except if some private key were out there...
Please explain, I was under the impression that the above could not reasonably be claimed anymore with any kind of certainty [1][2][3]. Perhaps I'm misunderstanding something important here or the 'Happy Dance!!' slide [4] made me paranoid.
[1] http://arstechnica.com/security/2016/10/how-the-nsa-could-pu... [2] http://arstechnica.com/security/2016/08/cisco-firewall-explo... [3] http://arstechnica.com/security/2015/10/how-the-nsa-can-brea... [4] http://www.spiegel.de/media/media-35515.pdf