Live data from Hacker News

South African authorities admit to mass surveillance

iafrikan.com

131–140 of 145 posts

Re: South African authorities admit to mass surveillance

#131
post #57

Earlier quoted context omitted.

How do you think they're decrypting in real time? I have no idea how they're doing it. But I believe it can be done simply because the intelligence agencies have the best, largest, fastest, most advanced machines that money can buy. Machines that none of us have even heard of, that are years ahead of anything any of us will ever touch in our lifetimes.

Back of the envelope, to see scale: to brute force SHA-256 you need to try about 2^255 combinations, so you'd need to have 2^194x (1,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000x) the hashpower of the Bitcoin network (80 EH/s). If you told me you thought they had cracked a common algorithm so they could do it in only 2^60 time that would at least be plausible. But the idea that they…

You literally can't brute force SHA-256, there's a very tiny physical limit on the amount of energy it costs to flip a bit of information. Turns out that, summed over all the possibilities, that adds up to way more energy than is in the entire solar system.

Re: South African authorities admit to mass surveillance

#132

Earlier quoted context omitted.

It surprises me as a South African because I didn't know our government had the technical capability or capacity to store and process so much data, let alone splice undersea cables without detection.

I strongly doubt they spliced the cables. From the article it sounds like they got a court order (probably unconstitutional), allowing them to intercept the data. So they probably just needed to install a couple of big servers at the landing sites.

You don't splice cables, you split the light with a prism and siphon of 10% of the light. All of it.

Every telco has locked rooms full of kit for this job.

Re: South African authorities admit to mass surveillance

#133

The German BND snoops traffic at DECIX. UK snoops on transatlantic cables. Everyone snoops. Either we move to full e2e encryption or we organize democratically to tear down the modern Stasi.

Full end-to-end encryption, with occasional onion routing, is maybe the best path ahead.

The benefit is that it does not require any argumentation with other people, noone needs to be convinced or won over, and that it makes sense. It costs nearly nothing to deploy cryptographic solutions.

Re: South African authorities admit to mass surveillance

#134

Earlier quoted context omitted.

See also: Pascal's Wager[1] The leaks about mass-surveillance don't fit the criteria, as best I can tell. It's in their best interests not to, as you state. [1] https://en.wikipedia.org/wiki/Pascal%27s_wager

Pascal's wager suffer from the fact that it can be any of the myrriads of religions that are correct. The chance of picking the correct one is infinitely small (assuming there are aliens that also have religions). Only a subset of the religions have anything like hell/heaven, further diminishing the risk.

I think the main issue with Pascal's wager is that it puts all its eggs in the basket of some afterlife being a certainty.

You can very well waste all your life in pointless prayer, like the monk who basically imprinted his feet on the wooden floor by praying several hours a day for decades.

Even getting out of that room to help someone in a trivial task would have been much more useful than the praying.

Not to mention the huge amount of censorship over your own thoughts that some religions impose on your life.

So, IMO, if you get the wrong end of Pascal's wager, you can waste your only life, every infinitely valuable second of it (because there's no afterlife), over a non-existent afterlife.

That's a hell of a wager to lose.

Re: South African authorities admit to mass surveillance

#135
post #116
post #91

Earlier quoted context omitted.

My pet conspiracy theory is that at least some large governments have quantum computers of useful strength. It's probably more likely that they're just trudging along with side-channel attacks, CA fuckery, breaking into servers, and doing targeted attacks though. Cheaper and likely works well enough.

I'd be pretty surprised if they had quantum computers to where they could decrypt https, but it's at least possible. The more prosaic means you're describing, plus zero days and phishing (unless that's included in "targeted attacks"?), can still get them a long way.

Yeah, zero days, phishing and coopting servers to send exploits to specific targets are what I meant by targeted attacks (and some of those overlap).

You're probably right on the quantum computers of course, but I like comparing it against what was publicly know about say cryptanalysis vs what the NSA knew in the DES days, and also similar situations in the ww2 days.

Re: South African authorities admit to mass surveillance

#137
post #32

Earlier quoted context omitted.

Modern IRC servers tend to support TLS on port 6697 and SASL for authentication. I’ve been connecting to IRC over SSL for probably a decade at least.

> Modern IRC servers tend to support TLS on port 6697 and SASL for authentication. The OC's point was by default , meaning/inferring clear-text is still the modus operandi for generally getting onto IRC services. > Many applications still aren't encrypted by default, like IRC. SSL and SASL aren't, precisely, user-friendly implementations with some clients (e.g.: IRSSI[0] - but if you're using IRSSI, you don't want a…

This is mostly irrelevant; users using Web IRC gateways, services like IRCCloud or clients like HexChat[1] do not have to configure the server unless it isn’t already present in the list. If they do, they already will have to manually configure either TLS or plaintext. There is no “default.”

I mention SASL because it is relevant to security posture, especially if the user wasn’t connecting via TLS. Although of course the server could allow PLAINTEXT in practice there’s no point in supporting that because IRC already had native plaintext server authentication.

[1]: https://github.com/hexchat/hexchat/blob/3d1d9e1716d66abb6921...

Re: South African authorities admit to mass surveillance

#138

Earlier quoted context omitted.

HTTPS has downsides too, let's not kid ourselves.

What is the downside of using https over http?

Other than what the sibling posted, which is true, there's an extra round trip for the TLS handshake, which makes a real difference when you're on a horrible 3G connection in a poor country (thankfully HTTP 2.0 fixes a lot of this, but again - complexity). Infra will catch up hopefully but it is a pain point for those who are less well off.

Re: South African authorities admit to mass surveillance

#139
post #94

Earlier quoted context omitted.

You can't export the data wholesale from your ship though - you'd need another cable for that :D So you'd need sift and process that data on the ship.

You can't export the data wholesale from your ship though - you'd need another cable for that :D The key word, though, was "uplink." Go straight to satellite, and let the intelligence agencies sift through what they want.

Are there sat links with enough bandwidth to siphon data off undersea cables?

I have no knowledge of this area but I always thought sat links can't compete with multi gbps cables.

Maybe I'm wrong though.

Re: South African authorities admit to mass surveillance

#140

Earlier quoted context omitted.

It's surprising to me at least because South Africa has a GDP per capita of $~6.1k, and perhaps can't afford access to that expertise. Which I suppose suggests that they didn't pay for it, and another nation state 'helped out' via intermediaries.

GDP per capita isn't a great measurement for the capabilities of a state.

You're right, it's probably better to look at GDP overall, since that's basically the tax base theoretically.
Post reply on HN