Live data from Hacker News

South African authorities admit to mass surveillance

iafrikan.com

51–60 of 145 posts

Re: South African authorities admit to mass surveillance

#51

> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.

I can imagine a sustainable business could be made operating a fleet of ships in international waters that pick up undersea cables, taps them, and uplinks the data in real time to whichever .gov subscribes to it. The company taking the risk gets a big fat government check every month, and the governments get to deny they're tapping anyone's data.

Global Passive Surveillance as a Service...

(BRB: making a pitch deck...)

Re: South African authorities admit to mass surveillance

#52
post #43

Earlier quoted context omitted.

Who now sends traffic over these links and doesn't encrypt them? Remember that the intelligence agencies don't only want today's data, they want yesterday's data. You get yesterday's data by storing it today. Then you can decrypt it at your leisure, or when computers become powerful enough to break through. I know a lot of people on HN earn a living making sure internet traffic is encrypted. But honestly, I really be…

How do you think they're decrypting in real time? Do you think there are backdoors in the crypto/protocols? Severe accidental flaws? How many times a speedup are you imagining? State of the non-TLA art is that modern https is completely impractical to break, even with enormous server farms working for years, let alone in real time.

How do you think they're decrypting in real time?

I have no idea how they're doing it. But I believe it can be done simply because the intelligence agencies have the best, largest, fastest, most advanced machines that money can buy. Machines that none of us have even heard of, that are years ahead of anything any of us will ever touch in our lifetimes.

Re: South African authorities admit to mass surveillance

#53

Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?

I think it’s naive to think that Google’s leadership was unaware of anything Edward Snowden revealed.

They reacted to the information becoming public.

Re: South African authorities admit to mass surveillance

#54

> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.

Someone makes this exact same comment every time there is a privacy story - not realising there is a very big gap between speculating on what a governments capability is and having it confirmed

Sure - people in privacy circles may suspect this and sneer at the general public for thinking it is news, but it is a big deal to have it confirmed, to raise awareness of it and actually do something about it

Re: South African authorities admit to mass surveillance

#55
post #25

Wasn't it 6 years ago when Snowden made public his revelations and Google said 'nope' and encrypted the lot? Who now sends traffic over these links and doesn't encrypt them? So, what value do the SA government have in intercepting these links now?

There were plenty of small samples in the various Snowden powerpoint slides of stuff NSA incepted from the pipes. It seems a ton of mobile apps are sending information with identifiers over HTTP (the ID is a key part for them legally to pick it up and store it in a DB, forever). I notified one developer that was sending real-time GPS data + an email address highlighted in one of the PPT slide's (just a screenshot of…

> Linux users currently have the lowest when using Chrome with 86%. I'm curious why this is.

This doesn't surprise me when you consider that package management over HTTP is considered ok since it's separately authenticated and verified is a very common view

That this view would also spread to not requiring HTTPS on documentation and other sites would also not be surprising

The Linux world really needs to get it's act together with providing confidentiality via SSL/TLS

Re: South African authorities admit to mass surveillance

#56

Earlier quoted context omitted.

HTTPS has downsides too, let's not kid ourselves.

What is the downside of using https over http?

Nobody said the downsides were over HTTP. When talking about state sponsored espionage, the glaring downside of HTTPS is PKI and buying into the CA model.

Re: South African authorities admit to mass surveillance

#57
post #43

Earlier quoted context omitted.

How do you think they're decrypting in real time? Do you think there are backdoors in the crypto/protocols? Severe accidental flaws? How many times a speedup are you imagining? State of the non-TLA art is that modern https is completely impractical to break, even with enormous server farms working for years, let alone in real time.

How do you think they're decrypting in real time? I have no idea how they're doing it. But I believe it can be done simply because the intelligence agencies have the best, largest, fastest, most advanced machines that money can buy. Machines that none of us have even heard of, that are years ahead of anything any of us will ever touch in our lifetimes.

Back of the envelope, to see scale: to brute force SHA-256 you need to try about 2^255 combinations, so you'd need to have 2^194x (1,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000x) the hashpower of the Bitcoin network (80 EH/s).

If you told me you thought they had cracked a common algorithm so they could do it in only 2^60 time that would at least be plausible. But the idea that they have hardware to straight up brute force it, though, is just impossibly wrong.

Re: South African authorities admit to mass surveillance

#58
It's worrying that developing countries can buy off-the-shelf solutions to surveil its citizens without going through the decades of cultural and social change other countries have. We asked questions like "Is this ethical?" before the technology became possible. For them, the tech is here and the social discussions were never started.

Maybe this is the same thing. We haven't upheld our ideals on privacy anyway.

Re: South African authorities admit to mass surveillance

#59

> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.

> I can’t understand how this news would surprise anyone

I tried to tell my family about the Snowden leaks and the implications just a year ago. They are all university educated people.

They categorically did not believe that what I was saying was real, and when I showed them all the leaks they did not believe the content was true.

Billions of people simply don't believe it's true.

Re: South African authorities admit to mass surveillance

#60

Earlier quoted context omitted.

It surprises me as a South African because I didn't know our government had the technical capability or capacity to store and process so much data, let alone splice undersea cables without detection.

if they don't have the expertise, someone else with the expertise interested in access to the data will help them.

It's surprising to me at least because South Africa has a GDP per capita of $~6.1k, and perhaps can't afford access to that expertise.

Which I suppose suggests that they didn't pay for it, and another nation state 'helped out' via intermediaries.

Post reply on HN