Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

301–302 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#301
post #295

Earlier quoted context omitted.

Wrong. I don't even need to cite Snowden slides, congressional testimony will be sufficient: > Turns out the data collection is not so limited. In testimony yesterday before the House Judiciary Committee, National Security Agency Deputy Director Chris Inglis said that the NSA’s probing of data in search of terrorist activity extended “two to three hops” away from suspected terrorists. Previously, NSA leaders had said…

I see what you've misread now. To explain: they look two to three hops away using the metadata (phone records and until Obama cancelled the program before Snowden leaked anything, the email envelope data — from and to). They did not actually request the data of everybody three hops away, and nowhere in your quote is that claim made. PRISM doesn't "fill in gaps." It is their main source of actionable intelligence acco…

Read the transcripts of the Yahoo court case where they challenged the FISA court order. Then tell me they weren't asking for 3 hops...

Further proof:

> 50 U.S.C. § 1861 (b)(2)(C). These call detail orders cannot last longer than 180 days. Additionally, in an application for call records “two hops” from target—call records from people in contact with the identified target—the government must base its request on “session-identifying information or a telephone calling card number identified by the specific selection term” used in its first request. In December of 2015, the FISC ruled that USA Freedom does not require the government to show that these “two hops” call records are relevant to an ongoing investigation.

The only development Ive found has been that they promised to use 2 hops instead of 3. Which is good. But I'm not convinced the 2, previously 3, hops is limited to simply metadata.

Additionally this whole discussion of FISA warrants and limitations are strictly for Americans. They can collect full content and metadata of every foreign traffic they passively intercept.

The issue with metadata that was debated is primarily because they had unlimited warrantless access to American metadata since it's basically public data in their view. No one cared about non-americans. The FISA orders are for granting analysts access to full content on Americans (most likely they already have most of this data, they just aren't allowed to query it without a warrant.

They don't need warrants to collect metadata.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#302
post #301

Earlier quoted context omitted.

I see what you've misread now. To explain: they look two to three hops away using the metadata (phone records and until Obama cancelled the program before Snowden leaked anything, the email envelope data — from and to). They did not actually request the data of everybody three hops away, and nowhere in your quote is that claim made. PRISM doesn't "fill in gaps." It is their main source of actionable intelligence acco…

Read the transcripts of the Yahoo court case where they challenged the FISA court order. Then tell me they weren't asking for 3 hops... Further proof: > 50 U.S.C. § 1861 (b)(2)(C). These call detail orders cannot last longer than 180 days. Additionally, in an application for call records “two hops” from target—call records from people in contact with the identified target—the government must base its request on “sess…

Point me to anything in the Yahoo court case that says they were asking for three hops.

Your "further proof" also shows that they don't ask for three hops. It says that in order to request call records (phone call metadata, not the communications themselves: https://en.wikipedia.org/wiki/Call_detail_record), the investigator must show that the user is two hops by communication from a target. They determine this from the full-take phone metadata collection program that ended last year (https://www.washingtonpost.com/world/national-security/nsas-...) despite being ruled legal by the courts (http://www.reuters.com/article/us-usa-court-surveillance-idU...). According to Snowden's leaked documents, analysts have neither the authority nor the tools to look at anybody's call records in that full-take data but are only able to query it in specific ways (e.g., list the anonymized numbers that are 3 hops away from a particular number). The government can then apply for a court order to request the call records for a particular number according the rules you quoted.

> They can collect full content and metadata of every foreign traffic they passively intercept.

They can, but according to Snowden's leaks, they don't outside of a handful of hostile countries. The poster's friend is unlikely to live in one of those countries. This is not unique to the US -- Pretty much every country's laws allow the government to collect any data on foreigners.

> The issue with metadata that was debated is primarily because they had unlimited warrantless access to American metadata since it's basically public data in their view.

Also false, as I explained above. They have legal access to collect it, as I showed above, but the law allows them to query it in only a few restricted ways.

> The FISA orders are for granting analysts access to full content on Americans (most likely they already have most of this data, they just aren't allowed to query it without a warrant.

Completely wrong. FISA Section 702 orders can only be for non-Americans living outside of America. Data for a non-American living in the US cannot be requested, and data for an American living outside the US also cannot be requested. You're thinking of NSLs, which also must specify the particular user whose data is requested.

Post reply on HN