Live data from Hacker News

South African authorities admit to mass surveillance

iafrikan.com

11–20 of 145 posts

Re: South African authorities admit to mass surveillance

#11

The German BND snoops traffic at DECIX. UK snoops on transatlantic cables. Everyone snoops. Either we move to full e2e encryption or we organize democratically to tear down the modern Stasi.

Why not both?

The possibility of wiretapping will always exist, even if not carried out wholesale by the government itself. And so will commercial services touting convenience in exchange for being MITMed.

Re: South African authorities admit to mass surveillance

#12

Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?

* Many applications still aren't encrypted by default, like IRC. * If you have compromised a private key, you can get useful data from the cable intercept. * If you can collect ciphertext today, and decrypt it tomorrow (with, say, quantum computers), the cable intercept is very useful.

IRC probably isn't the best example, I've been using TLS for a good while now. "By default" probably depends a lot on the client.

Re: South African authorities admit to mass surveillance

#13
post #9

Earlier quoted context omitted.

* Many applications still aren't encrypted by default, like IRC. * If you have compromised a private key, you can get useful data from the cable intercept. * If you can collect ciphertext today, and decrypt it tomorrow (with, say, quantum computers), the cable intercept is very useful.

IRC sure, but the big win is email.

Majority of email traffic is by now for sure use s2s encrypted. Also considering how big major players are most of mail never leave Google / Microsoft / etc servers anyway and connections between them always only ever go over TLS.

Re: South African authorities admit to mass surveillance

#14

The German BND snoops traffic at DECIX. UK snoops on transatlantic cables. Everyone snoops. Either we move to full e2e encryption or we organize democratically to tear down the modern Stasi.

> The German BND snoops traffic at DECIX.

To forward a lot of it to the NSA [0], the same NSA that also messed with Germanys G10 laws to "legalize" these kinds of practices in the very first place [1] for exactly that reason.

edit: UK is pretty much also NSA, because unlike the German BND they are at least part of FiveEyes [2] because real global surveillance is a rather exclusive club.

[0] https://en.wikipedia.org/wiki/Operation_Eikonal

[1] http://www.europarl.europa.eu/document/activities/cont/20140...

[2] https://en.wikipedia.org/wiki/Five_Eyes

Re: South African authorities admit to mass surveillance

#16
post #13
post #9

Earlier quoted context omitted.

IRC sure, but the big win is email.

Majority of email traffic is by now for sure use s2s encrypted. Also considering how big major players are most of mail never leave Google / Microsoft / etc servers anyway and connections between them always only ever go over TLS.

You can get some statistics from Google at https://transparencyreport.google.com/safer-email/overview

They're a lot better than I thought! (over 90% in each direction, although no data here about certificate verification and the presence or absence of backbone downgrade attacks)

If you run your own mail service, check out my colleague's project at

https://starttls-everywhere.org/

Re: South African authorities admit to mass surveillance

#17
post #16
post #13

Earlier quoted context omitted.

Majority of email traffic is by now for sure use s2s encrypted. Also considering how big major players are most of mail never leave Google / Microsoft / etc servers anyway and connections between them always only ever go over TLS.

You can get some statistics from Google at https://transparencyreport.google.com/safer-email/overview They're a lot better than I thought! (over 90% in each direction, although no data here about certificate verification and the presence or absence of backbone downgrade attacks) If you run your own mail service, check out my colleague's project at https://starttls-everywhere.org/

I was just about to post the same link. Outside the US the numbers are a lot lower. Outbound to some countries is 0%. South Africa wasn’t in the report though.

Re: South African authorities admit to mass surveillance

#19
post #13
post #9

Earlier quoted context omitted.

IRC sure, but the big win is email.

Majority of email traffic is by now for sure use s2s encrypted. Also considering how big major players are most of mail never leave Google / Microsoft / etc servers anyway and connections between them always only ever go over TLS.

Almost all of the SMTP over TLS will be opportunistically encrypted only and usually with pretty bad protocol / cipher choices.

It probably means your email to your aunt isn't intercepted and shoved onto an enormous pile of decrypted email to be parsed for keywords. Probably. But that's about all.

Against an adversary determined to intercept:

- They can probably just strip STARTTLS, so that everything happens in plaintext - Even if they can't do that because of MTA-STS or similar, they can probably just present self-signed certs and it'll pass the mandatory checks - If they can't do /that/ either (no idea what proportion of email but it may well be in the minority) they can downgrade because unlike in HTTPS nobody is just saying "Old garbage bad, never do that or we'll scream" and so people keep doing it. SSLv3 may even work with a lot of mail servers.

Still, what we have now with opportunistic SMTP encryption is equivalent to what you get with snail mail. The spooks CAN read anybody's mail, but it's a hassle so they mostly don't read yours.

Re: South African authorities admit to mass surveillance

#20
If there’s any comfort to be had, South Africa’s intelligence agencies are a shambles, and unable to deal with real-life threats right under their noses. The idea that they’d be able to do anything actionable with bulk—collected electronic intel is laughable.

The way things are going, wouldn’t be surprising if whole thing is a corrupt scheme linked to procurement of storage media.

Post reply on HN