Live data from Hacker News

The NSA’s Hidden Spy Hubs in Eight U.S. Cities

theintercept.com

131–140 of 192 posts

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#131
post #75
post #66

Earlier quoted context omitted.

Yeah, gathering evidence not admissible in court really helps the investigation find evidence that is.

Exactly. Once they know exactly what someone has done and how, it's relatively easy for them to find alternative means of "suspecting" that person of doing the crime and convince the judge to give them a warrant for exactly what they've already found through the illegal surveillance operation. I wish judges and defense attorneys would catch on to these tactics more quickly. The rate at which the prosecutors/FBI inven…

All this assumes the judiciary is fair.

I feel otherwise.

When Microsoft was about to be broken up an appellate judge overruled the prior judge. That judge went on to be the FISA secret court judge.

Remember that the NSA Key was discovered around the same time[0].

So Microsoft was in bed with NSA prior to 1999 with a crypto key backdoor.

They were helped by an future FISA judge.(Does that background look like a national security judge?)

When I look at the Judges resume I can help but to wonder if she was an NSA plant the whole time.[1]

The Commerce Department is a frequent cover for the NSA.

I have to assume they use deep cover people all around us.

[0]https://www.heise.de/tp/features/How-NSA-access-was-built-in...

[1]https://en.wikipedia.org/wiki/Colleen_Kollar-Kotelly

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#132
post #121

Earlier quoted context omitted.

> Even ignoring the practicality part, it becomes a timing game, because "empty" messages - even if they were filled with unintelligible "random" hex - would traverse the network differently than ones with variable length/size content and would be able to be filtered out pretty quickly. To eliminate the statistical observability of metadata, the padding needs to reach or exceed the maximum capacity of the channel. So…

On it's face such a scheme seems theoretically robust, but for frequency correlation only. I'd be curious if in practice it would be possible to eliminate all other variability though, of which there are many. For example I'm unaware of any true solution to latency triangulation. My hunch is that it wouldn't be possible, and there would be a side-channel vulnerability somewhere.

I'm not proposing a low-latency interactive approach, so latency triangulation shouldn't apply. In my example mechanism, we always have to wait a full day until sending any reply, so there's no event that an attacker can use to measure latency from.

Edit: the beginning of this research is the Dining Cryptographers.

https://en.wikipedia.org/wiki/Dining_cryptographers_problem

Although Chaum's solution has terrible availability properties, it's unconditionally secure against outsiders!

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#136

Earlier quoted context omitted.

No, their activities should largely be public. The NSA having privlaged information on their actions is dangerous, they have no incentive to share them with the public unless it benefits the NSA.

> No, their activities should largely be public. I can agree on that

As important as that is, even if they're completely corrupt you still don't want a secret police watching them.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#137

I'm struggling to find the new information here. We've known for years through the New York Times and others that AT&T helps the NSA. We've known for close to a hundred years about AT&T Long Lines networks and hubs for that network. It's only basic logic to put the two together and know that the NSA uses AT&T's hubs. What's new here?

Did you even read the article? The new information is that these specific 8 buildings are specifically noted within NSA documents as the 8 locations within AT&T's network that the NSA utilizes. I don't know what The Intercept expects anyone to do with that information, but that is new information.

This is kind of a no-duh though. If you're the NSA, of course you're going to set up shop at peering facilities, there isn't anywhere else that makes practical sense.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#138
post #55
post #9

Earlier quoted context omitted.

Couldn't the NSA start working with other ISPs than AT&T? I'd really like to see CDNs like CloudFlare start requiring Cloud Origin encryption; e.g. what CloudFlare calls "Full SSL" -- https://support.cloudflare.com/hc/en-us/articles/200170416-W... . Right now, you can do TLS termination ("Flexible SSL"), which end-users aren't aware of -- they see a padlock -- and I'm sure the NSA doesn't mind.

>Right now, you can do TLS termination ("Flexible SSL") Which sane people call Man in the Middle and should not be allowed at all. I have seen people doing this Flexiable SSL with Credit Card data and other PII believing it is "secure" Cloudflare may have started out with security in mind but their new services centered around centralization of key services (dns) and this kind of security breaking product means IMO t…

Even Cloudflare's "Full SSL" mode is a man in the middle: Cloudflare is the man in the middle who sees the plaintext of connections going through them.

Re: The NSA’s Hidden Spy Hubs in Eight U.S. Cities

#139

Earlier quoted context omitted.

It seems odd to have an ISP office in the middle of downtown?

Every major north american city has a legacy telco central office in downtown, in a very central location, from the days of pulse-dial and then DTMF dial analog phones. Always owned by whatever corporate entity the Bell System and then ILEC eventually became. Seattle, for example, also has the Elliot CO in Belltown: http://www.co-buildings.com/wa/206/

Yeah, you have to remember that in pulse dial days a central office station had a reach of roughly 3 miles. The longer you go, the more you're paying for cable, repeaters, or just losing quality. 90 volt AC for ringing has a limited range!
Post reply on HN