Live data from Hacker News

The NSA’s Hidden Spy Hubs in Eight U.S. Cities

theintercept.com

41–50 of 192 posts

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#41
post #15

Earlier quoted context omitted.

Please, explain to me how I misread the map. It clearly labels Washington DC as a city in the state of Maryland.

You've misread the map by assuming "Maryland" was a state label, when evidence within the same map clearly indicates it is not. "Northern California" and "Southern California" are not states. Instead, they are areas, and Washington D.C. is in the area of Maryland.

This is ridiculous, but I'll play along. California absolutely is a state. Further defining the location of a city in a state does not really explain how Washington DC ends up being classified as part of Maryland. Washington DC is not part of the state Maryland. There is also no area (I assume by "area" you mean metro area or region) that is commonly defined as Maryland. Washington DC is part of the DC metropolitan area or "DMV," however it is in no way part of Maryland anymore than New York city is part of New Jersey.

I was simply pointing out a minor (albeit, comical) factual error that immediately made me question the legitimacy of the rest of the article.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#42
post #6

One wonders if a CDN might advertise, "we promise once your data enters our network at our edge locations outside of the US, it does not traverse any AT&T networks while reaching your server inside the US". Same with cloud companies' private networks across regions.

If your communication is encrypted it shouldn't matter if it passes AT&T networks.

Either

A. Popular and well known encryption algorithms are not broken by the NSA, and your communication is private.

B. Popular and well known encryption algorithms are broken by the NSA, but the fact that it's broken is top secret and the state will not do any actions that revel the secret. Your communications are not safe, and while what you communicate might make you the target of an investigation (if you're an appealing enough target), the communications will not be directly used against you in court.

EDIT: There is a third option, that your communication is being stored until the encryption algorithm is broken or computation reaches a point where brute force is possible (quantum computers). Long term storage of encrypted communication is only economically feasible for a small subset of all encrypted communication, so it's only a concern for targeted individuals where the communication will be relevant to the state decades from now.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#43
Wow, just made a crazy realization. A while back I was downtown with my 5yo kid, and we were by the bus stop right next to this building (You can actually see the bus stop in the picture). The bus was late, and my kid was hyper, and he tried going through the revolving doors. They were locked, no big deal. After a while, he tried going through the doors again. At this point, three security guards with ballistic vests come busting out of the door with their hands on their holsters, and chewed me out for letting him play near the door.

I know my way around the security industry. These weren't normal security guards that get paid to watch cctv and call the real cops. They don't give those guys guns or ballistic vests. To me it was completely bizarre that a telecom building would have that sort of security. Now it all makes sense. I actually wouldn't be surprised if they were actually military in disguise.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#44

Wow, just made a crazy realization. A while back I was downtown with my 5yo kid, and we were by the bus stop right next to this building (You can actually see the bus stop in the picture). The bus was late, and my kid was hyper, and he tried going through the revolving doors. They were locked, no big deal. After a while, he tried going through the doors again. At this point, three security guards with ballistic vests…

Like a lot of federal agencies, NSA has its own police force to secure their buildings. A few years ago they somewhat infamously shot someone who drove through the Fort Meade gate and then refused an order to stop. They were driving a stolen car, but apparently made a wrong turn.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#45

Earlier quoted context omitted.

Did you even read the article? The new information is that these specific 8 buildings are specifically noted within NSA documents as the 8 locations within AT&T's network that the NSA utilizes. I don't know what The Intercept expects anyone to do with that information, but that is new information.

I admit, I didn't read the full article because it's only barely readable on my device, but if my scroll bar is accurate, I did read about 70% of it. But my point stands. We've known that these specific buildings are the key hubs in the network for close to a century. And that they're hardened against nuclear attack, etc... Maybe I was too deep into the phreaking scene in the early days, but I thought this was common…

You're still missing the point.

> We've known that these specific buildings are the key hubs in the network for close to a century. And that they're hardened against nuclear attack, etc...

Yes, it's been known that these specific buildings were key to AT&T's infrastructure. But any speculation that these specific buildings (as opposed to other specific buildings) were also key to NSA projects was just an assumption. The new information, which comes from released NSA memos and documents, shows that these specific 8 buildings are key to the NSA, meaning it's not just based on assumption anymore.

There's some other new information in there from the memos/documents, too. You really should actually read the article before mounting your high horse and spouting off nonsense criticism about it.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#46
post #42
post #6

One wonders if a CDN might advertise, "we promise once your data enters our network at our edge locations outside of the US, it does not traverse any AT&T networks while reaching your server inside the US". Same with cloud companies' private networks across regions.

If your communication is encrypted it shouldn't matter if it passes AT&T networks. Either A. Popular and well known encryption algorithms are not broken by the NSA, and your communication is private. B. Popular and well known encryption algorithms are broken by the NSA, but the fact that it's broken is top secret and the state will not do any actions that revel the secret. Your communications are not safe, and while…

> If your communication is encrypted it shouldn't matter if it passes AT&T networks.

IIRC, the signals intelligence agencies like the NSA learn almost as much from traffic analysis (e.g. who's talking to who and when) and metadata than from actual message content. Mere encryption itself often doesn't protect much from that.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#47
It's interesting to see this, and the reference to "one million emails", considering the prevalence of opportunistic TLS on MTA connections. Gmail reports 89% of their inbound and outbound flow is protected by TLS [1]. Wouldn't that eliminate the ability of the NSA to intercept those messages?

[1] https://transparencyreport.google.com/safer-email/overview

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#49
post #10
post #6

One wonders if a CDN might advertise, "we promise once your data enters our network at our edge locations outside of the US, it does not traverse any AT&T networks while reaching your server inside the US". Same with cloud companies' private networks across regions.

Trouble is, internet exchanges are often flat insecure layer 2 networks that operate on trust. Anyone on that network can suddenly decide to advertise anyone else's address space, and start receiving traffic.

Shitty IXes, maybe.

At a proper one a single IP address belonging to the exchange, which will be assigned to the router port of one member, is only allowed to appear from a specific single MAC address, and specific port on the ix switch, which corresponds with a physical fiber cross connect that matches a specific patch panel port.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#50
post #41

Earlier quoted context omitted.

You've misread the map by assuming "Maryland" was a state label, when evidence within the same map clearly indicates it is not. "Northern California" and "Southern California" are not states. Instead, they are areas, and Washington D.C. is in the area of Maryland.

This is ridiculous, but I'll play along. California absolutely is a state. Further defining the location of a city in a state does not really explain how Washington DC ends up being classified as part of Maryland. Washington DC is not part of the state Maryland. There is also no area (I assume by "area" you mean metro area or region) that is commonly defined as Maryland. Washington DC is part of the DC metropolitan a…

Perhaps you shouldn't discount the entire content of the article based on what could be perceived as a minor mistake. There's quite a bit of corroborating material in regards to the core theme of the Intercept piece (AT&T/NSA collaboration); for example, the engineer who's quoted in the Intercept article has been speaking out about NSA surveillance for several years. He's been referenced in similar articles in various publications going back to at leat 2007. The San Francisco address in the article was Mark Klein's former workplace and he ostensibly witnessed fiber splitting equipment being installed for use by government agencies. So if we are to take him at his word, then his account certainly lends credence to the Intercept article.
Post reply on HN