Live data from Hacker News

The NSA’s Hidden Spy Hubs in Eight U.S. Cities

theintercept.com

71–80 of 192 posts

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#71
post #2

I’d love to see the intercept publish the equivalent for China, Russia, etc. It feels the press has very overindexed into the NSA.

Stories like this often rely on some access to privileged information. If you were in a non-English/Portuguese country and had that privileged information, what reason would you have to expose it to an online paper you've never heard of?

This line of criticism is often brought up but there is no merit in it. How many Russian language news sources are you aware of?

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#72
post #51

It's interesting to see this, and the reference to "one million emails", considering the prevalence of opportunistic TLS on MTA connections. Gmail reports 89% of their inbound and outbound flow is protected by TLS [1]. Wouldn't that eliminate the ability of the NSA to intercept those messages? [1] https://transparencyreport.google.com/safer-email/overview

They might still collect them, on the chance that they'll be able to break the encryption later

or, on the chance that they were able to undermine the establishment of the protocol to make it more amenable being broken using their methods.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#73
post #30

Earlier quoted context omitted.

It's not a secret in the West, or even in China, that there's a "Great Firewall" which surveils and regulates all internet access. It's just America that pretends it doesn't have a secret police.

> a secret police The term "secret police refers to intelligence, security or police agencies that engage in covert operations against a government's political opponents" [1]. We have no evidence the NSA is "used to protect the political power of an individual" or even political party. They're an intelligence agency, purely and simply. [1] https://en.wikipedia.org/wiki/Secret_police

That spies on members of Congress on the orders of the President... https://theintercept.com/2015/12/30/spying-on-congress-and-i...

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#74
post #57
post #46

Earlier quoted context omitted.

> If your communication is encrypted it shouldn't matter if it passes AT&T networks. IIRC, the signals intelligence agencies like the NSA learn almost as much from traffic analysis (e.g. who's talking to who and when) and metadata than from actual message content. Mere encryption itself often doesn't protect much from that.

I'd argue that metadata is more important than content. It enables suspicion-by-association lines of inquiry. Once you know whos' involved in a conversation, it's much easier to target them for closer attention, such as hacking their machine or rubber-hose cryptography, both of which nullify any crypto you might have used.

> I'd argue that metadata is more important than content

Isn't metadata, practically speaking, a subset of content? (If you have the latter, you almost certainly also have the former?)

Metadata is more useful than content if you're capacity constrained, technologically or legally, in collection and/or analysis.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#75
post #66

Earlier quoted context omitted.

> the communications will not be directly used against you >in court. Directly. But via parallel construction...

Yeah, gathering evidence not admissible in court really helps the investigation find evidence that is.

Exactly. Once they know exactly what someone has done and how, it's relatively easy for them to find alternative means of "suspecting" that person of doing the crime and convince the judge to give them a warrant for exactly what they've already found through the illegal surveillance operation.

I wish judges and defense attorneys would catch on to these tactics more quickly. The rate at which the prosecutors/FBI invent new tricks to fool the courts and defense attorneys so far seems to far outpace the judge and the defense attorneys' understanding of what's even happening.

Take cell site simulators, for instance - the FBI has used those in secret for more than a decade before they were uncovered at all, and then it took another decade for judges here and there to catch-up and start requiring warrants for such operations.

And this goes for a lot of FBI's "investigative techniques", too, which are often illegal, but what judge is really going to know the difference between those highly technical operations?

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#77
post #67

Earlier quoted context omitted.

Encryption is irrelevant if the third parties (google, facebook, apple, etc.) are willing to give up private keys or data in response to requests or secret court orders. The same is true if the devices you own contain backdoors or exploits specifically designed for or not-fixed for the NSA.

In the case that the data is being stored by third parties (google, facebook, apple) or insecure devices then it's also irrelevant if the data passes AT&T's network or not.

Well.. supposedly AT&T is the capture, right? So passing the AT&T network would increase the odds of your packets being read.. right?

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#78
post #55
post #9

Earlier quoted context omitted.

Couldn't the NSA start working with other ISPs than AT&T? I'd really like to see CDNs like CloudFlare start requiring Cloud Origin encryption; e.g. what CloudFlare calls "Full SSL" -- https://support.cloudflare.com/hc/en-us/articles/200170416-W... . Right now, you can do TLS termination ("Flexible SSL"), which end-users aren't aware of -- they see a padlock -- and I'm sure the NSA doesn't mind.

>Right now, you can do TLS termination ("Flexible SSL") Which sane people call Man in the Middle and should not be allowed at all. I have seen people doing this Flexiable SSL with Credit Card data and other PII believing it is "secure" Cloudflare may have started out with security in mind but their new services centered around centralization of key services (dns) and this kind of security breaking product means IMO t…

It has its uses though, even if it's misused.

It's an easy box to check to pretend to offer HTTPS so you don't get penalized by Google. Before Let's Encrypt there was no free way to get a legit cert for your cat blog. Faking it via Flexible SSL was the next best thing.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#79

Earlier quoted context omitted.

> a secret police The term "secret police refers to intelligence, security or police agencies that engage in covert operations against a government's political opponents" [1]. We have no evidence the NSA is "used to protect the political power of an individual" or even political party. They're an intelligence agency, purely and simply. [1] https://en.wikipedia.org/wiki/Secret_police

That spies on members of Congress on the orders of the President... https://theintercept.com/2015/12/30/spying-on-congress-and-i...

One of the few groups that should be spied on

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#80

Earlier quoted context omitted.

That spies on members of Congress on the orders of the President... https://theintercept.com/2015/12/30/spying-on-congress-and-i...

One of the few groups that should be spied on

No, their activities should largely be public. The NSA having privlaged information on their actions is dangerous, they have no incentive to share them with the public unless it benefits the NSA.
Post reply on HN