Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

41–50 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#41
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

People have gone to jail for metadata. That is exactly what you are saying. That is its importance.

And that is only speaking of something within the Rule of Law (accessing metadata with a warrant)...

Outside of the Rule of Law, people have been killed for metadata.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#42
post #21

According to google, about 90% of the web traffic on chrome is now encrypted [1]. Does it matter that they are tapping a cable? The metadata can’t be that useful. [1] https://transparencyreport.google.com/https/overview?hl=en_G...

"We kill people based on metadata" ~~ General Michael Hayden, former director of the NSA

Yeah but he was referring to direct phone contacts. You connecting to a Skype or Facebook server doesn’t tell you anything.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#43
post #30
post #10

Earlier quoted context omitted.

They always sound so memorable yet mysterious, especially so the ones created by concatenation of two ordinary words, like ETERNALBLUE or FOGBANK. We should make a GPT-based generator of USA secret codenames ;)

> We should make a GPT-based generator of USA secret codenames ;) I'd read somewhere (can't remember where, unfortunately) that program code names were randomly generated by selecting words from two lists. The idea is that, if (accidentally) revealed, the name wouldn't provide any information about the program's function. The thing I read said people would often re-query the generator until they got a name that they…

Likely the British Military research projects.

>Each rainbow code name was constructed from a randomly selected colour, plus an (often appropriate) noun taken from a list

https://en.wikipedia.org/wiki/List_of_Rainbow_Codes

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#44
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

> Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself.

Just adding an example for the people who don't see the value of metadata: WhatsApp is still a viable revenue source for Facebook even as they have no access to the text of the messages due to E2EE.

Knowing who talks to who, at what times, the type and approximate size of messages, the members of groups, and the contents of the phone book of every user gives enough information to keep their business model without exposing them to court orders asking for the plaintext (that's the reason they added E2EE to start with, there is no incentive to improve the service when they have a billion heads of cattle to milk).

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#45

Earlier quoted context omitted.

Are you sure? I find it very convincing that NSA would not betray the trust, as it also says in the article. > "I can not at all imagine in my imagination that the NSA would betray that trust. I consider it completely and utterly unlikely. If the NSA had a desire to obtain information about Danish citizens or companies, the United States would simply turn to [the domestic security service] PET, which would then provi…

A statement is not a scientific fact. The head of the NSA lied to the American public about their extra-legal monitoring. What has changed since the Snowden revelations? Why would Danes be more respected by the NSA than US citizens themselves? This makes absolutely no logical sense.

To your point, the IC trades in misinformation and distraction as much as it trades in truth and fact. When any of those acronyms make a statement it's fitting to wonder if there's a broader arc, a bigger picture.

Their responsibilities and mission are clear. There are no style points. They'll do whatever it takes to accomplish that mission. History is very clear about this M.O.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#46

I love how the politicians presume NSA is safe partner and their danish citizens are not in the data. It does not really help if every other neighbouring country does the same. NSA will get danish info elsewhere. Everyone gets played. It works as long as USA is an trusthworthy ally. They wouldn't dare to abuse the information for private gains... right?

As I have pointed out in a comment some time ago [0], there have been multiple instances where US (ab)used their intelligence for economic gains - be it getting a US company to file a patent (that the NSA "obtained") before the German company who actually came up with the idea does, or subverting Airbus so contracts go to Boeing.

[0] - https://news.ycombinator.com/item?id=24546046

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#47
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

People have gone to jail for metadata. That is exactly what you are saying. That is its importance. And that is only speaking of something within the Rule of Law (accessing metadata with a warrant)... Outside of the Rule of Law, people have been killed for metadata.

[deleted]

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#48
post #21

According to google, about 90% of the web traffic on chrome is now encrypted [1]. Does it matter that they are tapping a cable? The metadata can’t be that useful. [1] https://transparencyreport.google.com/https/overview?hl=en_G...

Why can't the NSA just force a web PKI cert provider to create a fake certificate for them? We know from the Lavabit case that once you start keeping private keys away from the feds they start making problems for you. Prove to me that every single root your browser trusts is not compromised.

Who says they don't? TAO - tailored access operations - is known to intercept physical delivery and re-solder chips onto hardware to get access. It is all a question of "how much do you spent on a specific target".

However every such change could tip the target off: if you replace the certificate and the target knows the key of the cert they expect, that will tip them off. Now a lot of these tools are about mass surveillance and big data: collecting metadata about everyone, not about some well defined target, then run big data analysis on it to discover targets. Like you have one person who is flagged and they talk a lot to this "HackerNews-Server" and so all others who talk to that server get an increase in score and now multiple of those people have a score above a treshhold and get flagged. Can't do that if you don't spy on everyone.

But they can't run active intrusion against every civilian ever without exploding costs and high chance of being detected.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#50

I love how the politicians presume NSA is safe partner and their danish citizens are not in the data. It does not really help if every other neighbouring country does the same. NSA will get danish info elsewhere. Everyone gets played. It works as long as USA is an trusthworthy ally. They wouldn't dare to abuse the information for private gains... right?

https://www.windpowermonthly.com/article/960011/trans-atlant...

They already abuse this, I would even go as far and say that huge portion of data collection is just for industrial espionage to prop up government backed companies.

If you are developing a novel algorithm or even a different approach to AI then you should absolutely setup an offline work office otherwise either USA or China will take your work and give it to a government backed company. It also doesn’t matter if your company is located in the USA or if you are an American citizen, so long as you don’t have governmental connections, you have to be 100% more careful as game is pretty much rigged.

Post reply on HN