Earlier quoted context omitted.
In the case of NSLs, or UK orders from the security services, it may be illegal to tell anyone who isn't mentioned in the order. Including the company's general counsel. In the event that you are asked to do something illegal, it may be illegal or inadmissible to mention that you were ordered to do so by the government (Matrix-Churchill trial passim)
I wonder how they think this is supposed to work. - CEO gets a Letter. Does the CEO start learning Python/C++/PHP and Cisco configuration? Or does he tell a worker bee "Shhh! And read this Letter" ? - Worker bee starts making changes to production code and systems. Suddenly he starts needing automated code reviews, and reconfiguration alerts go out when he frobs the firewalls. These changes are indistinguishable from…
Yahoo installed a backdoor for the NSA behind the back of the security team
291–300 of 302 posts
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#292Earlier quoted context omitted.
I'm not so sure of that. For example, it's not clear that Congress has the authority to create NSLs, a sort of not-a-warrant. It's not clear that they can issue gag orders like this. Even if they could do these things with warrants, they're not---and that matters. The judiciary is not meaningfully overseeing the parts of the state where law enforcement and national security intelligence mix. The FISC is a great examp…
> It can't steer---we see this because it never refuses a request. There are issues with FISC(like lack of transparency), but this specific point is unclear to me. Here are some possible scenarios where a low refusal rate wouldn't be a problem: * The judge could informally tell the agent that the request needs to be amended before he'll grant it. * FISC could publish clear guidelines on what is and is not allowed, so…
FISC is a court in name only. There is no oversight (I don't count the political appointees in the Senate as oversight), there are no checks and balances, there are no appeals. Calling it a court beggars the term.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#293Earlier quoted context omitted.
Google encrypting traffic flowing between data centers seems to reflect significant awareness of the issue too.
When I worked at Square we required mutual TLS for almost all service-to-service communication within a datacenter, so sniffing traffic within the datacenter wouldn't be fruitful either (assuming no weakness in the cipher or TLS stack). Is that not common elsewhere?
I get it why somebody would argue this before but things like letsencrypt make it easy to manage the certificates for your internal hosts. I guess it gets more complex if you have your apps in containers that need their certificates managed etc. Even that shouldn't be this big a deal to make sure renewal is automated with some scripting or even managed properly with a backend CA like r509 ... Also the argument for performance no longer counts when the sales argument could be "we guarantee you e2e encrypted services etc" ...
Also Data Engineering jobs become a lot more complicated when suddenly certain data-points are no longer available for visualization on "BI-dashboards" consumed by wann-be tech-savvy CxO's, so that too may be a factor.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#294Earlier quoted context omitted.
I don't know how common this is in general, but an ethics course was a required part of the engineering core curricula at my school (Case Western Reserve). Ultimately, though, an ethics course isn't going to make people stand up for their ethics. A professional organization along the lines of the American Medical Association (at least in terms of political strength) that stands up for its members and censures those w…
> When there are few professional consequences for unethical behavior at the behest of your employer, taking an ethical stand is ineffective and quixotic. You will be fired and another engineer will likely complete the job. I disagree. I've seen this in action where people who were CCIE-level senior network engineers at one of the five largest ISPs in Turkey quit and got new jobs elsewhere (outside of the country) ra…
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#295Earlier quoted context omitted.
That's why I said FISA warrant... which includes 3 hops. Otherwise they would collect any email ever sent unencrypted via submarine fiber wiretaps. While feeds into XKeyscore.
FISA warrants do not include 3 hops. There is nothing in Snowden's leaks that suggests the NSA uses submarine wiretaps to collect your emails either. You seem to have ignored the leaked documents entirely and made up a scary all-seeing Boogeyman.
> Turns out the data collection is not so limited. In testimony yesterday before the House Judiciary Committee, National Security Agency Deputy Director Chris Inglis said that the NSA’s probing of data in search of terrorist activity extended “two to three hops” away from suspected terrorists. Previously, NSA leaders had said surveillance was limited to only two “hops” from a suspect.
> Inglis said that the NSA looks at two to three hops from a suspect. To determine how many hops you are from Osama, for example, the NSA’s data analysis engine software constantly plows through information and builds a model of all the relationships between every phone number on record and every IP address. Other software robots query the graph to discover which “nodes”—phone numbers, IP addresses and email accounts—fall within three degrees of separation from an established suspect.
> If you have a direct relationship with a suspected terrorist or target (you’ve called them, you’ve emailed them, you’ve visited their website) that’s a “one hop” relationship; there’s a solid line connecting you to that person in the NSA’s relationship graph. If you talk with, e-mail, or visit the Facebook page or website of someone who’s got a one-hop relationship, you’re two hops away. Add one more person in between in the graph, and you’re three hops away.
> Under the NSA’s FISA requests, Google, Microsoft, and other Internet services companies can be compelled to hand over relevant data from their servers on any account that falls within the three-hop range and is flagged as belonging to a person of interest. If you’ve won this lottery, the NSA will get access to your e-mails on Gmail or Outlook.com as well as your chats and Web-stored contacts, your documents, your synced data from computers and mobile devices, your backups, and anything else that can be handed over—at least, so the documents Snowden leaked imply.
> Your raw Internet traffic will get more attention as well. Your IP address will be watched more carefully by deep packet inspection hardware at the NSA’s 'Net taps, and what you do online will get extra scrutiny.
https://www.google.ca/amp/arstechnica.com/information-techno...
I'm not sure if you're just a casual spectator, willfully spreading disinformation, or inclined to ignorance but the boogeyman dismissive posturing boat has long sailed. PRISM's only purpose is to fill in the gaps of passive collection by directly sourcing data, otherwise it comes in primarily from submarine wiretaps and the multitude of other various passive collection sources. Or associated five eyes programs.
And yes FISA warrants include 3 hops and if you know anything about the Internet you know that is a hell of a lot of data for a single warrant. And public data shows the FISA court only deny around 0.1% of warrant requests. Even rubber stamps have to pretend they are doing their job.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#296Earlier quoted context omitted.
You must have been folowing a different leak than me.
I read the documents released by Snowden. Which leaks are you referring to? Can you point me to any document that suggests the NSA has his friend's emails?
Snowden leaks showed that they get billions of hits each month from the various submarine cables as well as direct access from telco backbone fiber stations in the US, Europe, Middle East, and elsewhere.
> As this map shows that almost 3 billion data elements from inside the United States were captured by the NSA over a 30-day period ending in March 2013, Snowden stated that this tool was collecting more information on Americans located within the United States than on Russians in Russia
https://en.m.wikipedia.org/wiki/Boundless_Informant?wprov=sf...
In addition, the MUSCULAR program involved tapping the data links between data centers of Google and Yahoo.
https://en.m.wikipedia.org/wiki/MUSCULAR_%28surveillance_pro...
So I'd say there is an 80-90% chance the NSA has a good chunk of his friends email. Closer to 95% if he was located outside of the US.
The only thing stopping them from getting the full content of each Americans (plus 3 hops) passive data collection (besides 100% of metadata they get legally) is a FISA warrant. They have no restriction for foreigners.
Maybe you need to reread some of those slides because you clearly missed the big picture.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#297Earlier quoted context omitted.
Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…
Be found in contempt and go to jail... you first?
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#298Earlier quoted context omitted.
Be found in contempt and go to jail... you first?
No - Nelson Mandela first. Martin Luther King first. There's a precedent of people going to jail for standing up to civil rights violations.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#299Earlier quoted context omitted.
FISA warrants do not include 3 hops. There is nothing in Snowden's leaks that suggests the NSA uses submarine wiretaps to collect your emails either. You seem to have ignored the leaked documents entirely and made up a scary all-seeing Boogeyman.
Wrong. I don't even need to cite Snowden slides, congressional testimony will be sufficient: > Turns out the data collection is not so limited. In testimony yesterday before the House Judiciary Committee, National Security Agency Deputy Director Chris Inglis said that the NSA’s probing of data in search of terrorist activity extended “two to three hops” away from suspected terrorists. Previously, NSA leaders had said…
PRISM doesn't "fill in gaps." It is their main source of actionable intelligence according to the leaked slides, and it only contains the data of the person being watched, requested via court order, approved by the company, and then sent to the FBI.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#300Earlier quoted context omitted.
I read the documents released by Snowden. Which leaks are you referring to? Can you point me to any document that suggests the NSA has his friend's emails?
I'll cite a single program not even leaked by Snowden which would allow any unencrypted email sent to by intercepted https://en.m.wikipedia.org/wiki/Room_641A?wprov=sfla1 Snowden leaks showed that they get billions of hits each month from the various submarine cables as well as direct access from telco backbone fiber stations in the US, Europe, Middle East, and elsewhere. > As this map shows that almost 3 billion dat…
MUSCULAR provides similar filtering capability within Google's and Yahoo's networks, though not anymore because they encrypt all traffic. Again, only metadata. And again, the email envelope collection had already been shut down prior to the leaks according to the leaked documents. According to Snowden's leaks, the NSA is not allowed to keep communications from a US citizen or anybody even living inside the US without a court order, so no, his friend's emails don't reside with the US government.