Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

21–30 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#22
post #21

According to google, about 90% of the web traffic on chrome is now encrypted [1]. Does it matter that they are tapping a cable? The metadata can’t be that useful. [1] https://transparencyreport.google.com/https/overview?hl=en_G...

You're assuming that most traffic is web traffic (opposed to non-browser traffic) and that encryption is secure.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#23
post #21

According to google, about 90% of the web traffic on chrome is now encrypted [1]. Does it matter that they are tapping a cable? The metadata can’t be that useful. [1] https://transparencyreport.google.com/https/overview?hl=en_G...

If it didn't matter they sure would not tap it.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#24
All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints.

You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the endpoints at a later date. And that is way easier. Breaking encryption is hard and time consuming. Identifying a site a user regularly visits and exploiting that is more straightforward.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#25
post #21

According to google, about 90% of the web traffic on chrome is now encrypted [1]. Does it matter that they are tapping a cable? The metadata can’t be that useful. [1] https://transparencyreport.google.com/https/overview?hl=en_G...

I've heard that metadata can be very useful (sometimes more so than the actual data). I don't remember the argument very well or where I read it, but it was something along the lines of analyzing the timing of activities to connect individuals to groups and events iirc.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#26
post #8

Earlier quoted context omitted.

> abuse the information for private gains What do you think intelligence is?

"Intelligence is probably the least understood and the most misrepresented of the professions. One reason for this was well expressed by President Kennedy when, on November 18, 1961, he came out to inaugurate the new CIA Headquarters Building and to say good-bye to me as Director. He then remarked: 'Your successes are unheralded, your failures are trumpeted.' For obviously you cannot tell of operatives that go along…

> Dulles

One gets the impression his claim that all the CIA's successes are secret is a lie. Because there never were any. You would thing 50 years after the man kicked it that at least something would be come out. Not really surprising. If you look at how successful organizations are structured the CIA is not that.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#27
post #21

According to google, about 90% of the web traffic on chrome is now encrypted [1]. Does it matter that they are tapping a cable? The metadata can’t be that useful. [1] https://transparencyreport.google.com/https/overview?hl=en_G...

That metadata is surely still useful when you know frequency and target IP addresses. In addition not everyone uses google services and browsers, and so its really narrow to say 'chrome is encrypted, so who cares?'... This metadata by the way is exactly how you can calculate correspondence and association of graphs of people and information. How is that not exactly a breach of exactly what people fear most? It doesnt matter what data you are looking at, it matters who else is looking.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#28
post #21

According to google, about 90% of the web traffic on chrome is now encrypted [1]. Does it matter that they are tapping a cable? The metadata can’t be that useful. [1] https://transparencyreport.google.com/https/overview?hl=en_G...

> The metadata can’t be that useful.

Yet they are collecting it. It's almost as if it could be useful! You need to read the Snowden book.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#29

I love how the politicians presume NSA is safe partner and their danish citizens are not in the data. It does not really help if every other neighbouring country does the same. NSA will get danish info elsewhere. Everyone gets played. It works as long as USA is an trusthworthy ally. They wouldn't dare to abuse the information for private gains... right?

Are you sure? I find it very convincing that NSA would not betray the trust, as it also says in the article. > "I can not at all imagine in my imagination that the NSA would betray that trust. I consider it completely and utterly unlikely. If the NSA had a desire to obtain information about Danish citizens or companies, the United States would simply turn to [the domestic security service] PET, which would then provi…

A statement is not a scientific fact. The head of the NSA lied to the American public about their extra-legal monitoring. What has changed since the Snowden revelations? Why would Danes be more respected by the NSA than US citizens themselves? This makes absolutely no logical sense.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#30
post #10
post #3

Totally off topic, but I love that XKEYSCORE sounds like a Redis command. There has to be an opportunity for some sort of practical joke here but I can't find it.

They always sound so memorable yet mysterious, especially so the ones created by concatenation of two ordinary words, like ETERNALBLUE or FOGBANK. We should make a GPT-based generator of USA secret codenames ;)

> We should make a GPT-based generator of USA secret codenames ;)

I'd read somewhere (can't remember where, unfortunately) that program code names were randomly generated by selecting words from two lists. The idea is that, if (accidentally) revealed, the name wouldn't provide any information about the program's function. The thing I read said people would often re-query the generator until they got a name that they liked.

Post reply on HN