Live data from Hacker News

AT&T has a fiberoptic splitter copying our data to NSA

eff.org

191–200 of 233 posts

Re: AT&T has a fiberoptic splitter copying our data to NSA

#191

Earlier quoted context omitted.

That could be construed as a denial of service attack and would be illegal (or at least in a very murky legal grey area). Also you seem to have forgot that most AT&T customers have bandwidth caps in place that would make it difficult for them to run this attack in the first place.

The idea isn't to spew data at AT&T like a DoS, just taint all your boring communication to make them have to sift through more junk. For example, add extra "scary" keywords in your outgoing HTTP headers. X-Spook: Hamas subversive War on Terrorism Kosovo Delta Force

I am pretty sure it doesn't bother them. They don't actually go through the data, otherwise encryption would defeat the surveillance.

There are many other more useful signals (and the fact that you use encryption is probably one). The goal is to find outliers, not people using scary words Furthermore it would be probably quite easy for them to filter that kind of "DoS", it is just too simplistic. If you come up with something more clever they probably are interested about knowing more about you anyway.

Re: AT&T has a fiberoptic splitter copying our data to NSA

#192
post #115

Earlier quoted context omitted.

Basically if you see a certificate on the interwebs, it goes through and says: "This particular website is X". And it can back this up with all sorts of fancy math. The problem then, is how do you know that the particular certificate is correct? I can go through and make a certificate saying that i'm santa clause. How you get around that is by using another certificate that you already have, and using that to certify…

Thanks for the explanation. After taking a look at the certificates that come with Windows, I can see that there are dozens of trusted root certificates, issued by some organizations that I've never heard of. Can I really trust those "root ca"? especially that I noticed some differences between the two PCs that I've checked!

Usually the OS or browser vendor chose them, so it is normal that they differ between computers. But the CA trust chain really sucks, as one compromized CA compromizes everything (the security of the system relies on the security of the weakest root CA).

Re: AT&T has a fiberoptic splitter copying our data to NSA

#193
post #134
post #81

Earlier quoted context omitted.

Original image available through EFF's flickr account: http://www.flickr.com/photos/hughelectronic/3531668253/

They _need_ to make some version of that bird picture into a t-shirt.

They did, last year (and I have seen people with it in conferences). I donated and asked for this t-shirt but I never received it :(

Re: AT&T has a fiberoptic splitter copying our data to NSA

#194

Earlier quoted context omitted.

Haha, this doesn't make any sense. How can you possibly know the real cert from the one generated by NSA?

Call them on the phone and ask them to read you their cert fingerprint. Or use this: http://www.networknotary.org/firefox.html

Phone lines are secure of course ...

Re: AT&T has a fiberoptic splitter copying our data to NSA

#195
post #136

AT&T isn't the only one to do this. So long as it isn't used against citizens in criminal trials/etc I don't really care all that much if it helps make intelligence people more efficient.

How would you know that it isn't being used that way? Even if the evidence isn't being used directly at trial, it could sure be used to help 'guess' when a good time to stake out someone's house might be.

Yeah, but if most of the world is doing this wouldn't we be losing a vital ability to "protect and insure interests" of country? In the real honest way and not patriot act bs.

Maybe you guys are just clueless about us having real enemies out there or something. No fucking way is FBI or local law enforcement going to be granted anything from NSA for shit. Because it's unlawful.

Re: AT&T has a fiberoptic splitter copying our data to NSA

#196

Earlier quoted context omitted.

> do you ever wonder why there is no consumer hardware PGP telephone? Not on the analogue phone. But you can easily get a TLS-enabled or ZRTP-enabled hardware or software VoIP phone. Many vpbx providers will also provide you with a vpn tunnel endpoint if you ask about it often enough. Also, since the analogue phone PSTN interface is pretty trivial to handle, there are multitude of analogue encryption boxes which work…

> Not on the analogue phone. And not on a consumer cell phone, either. > But you can easily get a TLS-enabled or ZRTP-enabled hardware or software VoIP phone. In theory, arbitrarily strong/usable encryption products can be marketed within the USA. In practice, from this list: A) Usable by non-experts (requires no software fiddling, hardware mix-and-match, or other wastes of time) B) Based on uncrackable/de-facto uncr…

How would a phone use an OTP? Would you send the key by carrier pidgeon to the guy every time you wanted to make a phone call?

There's absolutely no way to get security without some sort of verification by the user. At the very least, you need someone to verify that the keys are correct "can you read me your phone's security serial?". It shouldn't be too hard to create affordable, usable phones based on PKC. The problem is that nobody cares who listens to their conversations, because it's all "where are we meeting tonight/that movie was shit/i can't believe X did Y".

Re: AT&T has a fiberoptic splitter copying our data to NSA

#197
post #83

Earlier quoted context omitted.

I think the point is government that is not necessarily led by a single person. Though the president of the US is the 'leader,' he does share power with the Supreme Court and Congress. Just because everyone likes to point to the president when things go wrong doesn't mean there aren't others that share in the blame... The current problem with the system is that: 1) the Federal government has grown too large, and 2) t…

May I suggest that the current US political debate is virulently polarizing and unproductive? Perhaps the issue Good Governance vs Bad Governance would be effective/useful? (as opposed to the current axis of big vs small) As was said by Deng Xiapong "it doesn't matter if the cat is white or black.."

Big government has more chance for corruption because the system ends up growing ever-more complex. Parts the of the system that are useless never get culled, they just keep finding ways to retain minimal amounts of relevance, while attempting to maintain or increase their funding levels.

It's harder to have 'good government' when there are more ways for it to fail.

Re: AT&T has a fiberoptic splitter copying our data to NSA

#198

Earlier quoted context omitted.

> Not on the analogue phone. And not on a consumer cell phone, either. > But you can easily get a TLS-enabled or ZRTP-enabled hardware or software VoIP phone. In theory, arbitrarily strong/usable encryption products can be marketed within the USA. In practice, from this list: A) Usable by non-experts (requires no software fiddling, hardware mix-and-match, or other wastes of time) B) Based on uncrackable/de-facto uncr…

How would a phone use an OTP? Would you send the key by carrier pidgeon to the guy every time you wanted to make a phone call? There's absolutely no way to get security without some sort of verification by the user. At the very least, you need someone to verify that the keys are correct "can you read me your phone's security serial?". It shouldn't be too hard to create affordable, usable phones based on PKC. The prob…

> How would a phone use an OTP?

A year of 9600 baud is ~36.1 GB.

Hand-deliver a flash stick once a year.

Obviously this is not a solution for everyday telephony between strangers. But RSA could be.

> nobody cares who listens to their conversations

This is true mostly because seriously caring is at present impractical.

Re: AT&T has a fiberoptic splitter copying our data to NSA

#200

Earlier quoted context omitted.

I'm guessing those other big companies are just as bad, however. Might not have the facts yet, but being paranoid leads me to think that way....

I feel the same. What we would need is a telecommunication company that puts the respect of privacy as one of its core goals (think Zappos), and not just in the boilerplate license agreements. Although entering that arena has high entry costs, it seems like a huge demand for such a service exists.

Quest communications was allegedly the only telecom co that didn't roll over to the NSA:

http://en.wikipedia.org/wiki/Qwest#Refusal_for_NSA_spying

A lot of time has passed, and they have a new CEO. I wonder if they have continued to hold out, or have quietly installed the black-room...

EDIT: I see they were just acquired last year by CenturyLink. I have to doubt that they have now not rolled over (call me a pessimist).

Very sad that corporations are so willing to forsake the privacy of the entire country's citizens (on the level of a constitutional breach) in order to make a dime or curry favor. Beyond sad, it is terrifying that the government then used warrantless wiretapping to specifically target our journalists:

http://www.theregister.co.uk/2009/01/25/tice_nsa_revelations...

...at least according to the same source that was responsible for leaking the existence of the black-rooms in the first place.

Sigh. Maybe I'll pick up my old copy of 1984. It's getting ironic now.

Post reply on HN