Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

81–90 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#81
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

> Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Just adding an example for the people who don't see the value of metadata: WhatsApp is still a viable revenue source for Facebook even as they have no access to the text of the messages due to E2EE. Knowing who talks to who, at what times, the type and approximate size of messages, the members of groups, and the contents of…

Knowing who talks to who, at what times, the type and approximate size of messages, the members of groups, and the contents of the phone book of every user gives enough information to keep their business model without exposing them to court orders asking for the plaintext

Similarly Google runs 8.8.8.8 so they know what services you use that aren’t HTTP that they don’t have bugged already.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#82
post #69

Earlier quoted context omitted.

> Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Just adding an example for the people who don't see the value of metadata: WhatsApp is still a viable revenue source for Facebook even as they have no access to the text of the messages due to E2EE. Knowing who talks to who, at what times, the type and approximate size of messages, the members of groups, and the contents of…

> WhatsApp is still a viable revenue source for Facebook even as they have no access to the text of the messages due to E2EE. A friendly reminder to everyone that even if the encryption that is used to send the messages in WhatsApp seems to be solid they upload your entire chat history as unencrypted dumps to the cloud. Even if you turn it off your chats will still end up there as long as whoever you are chatting wit…

This is the first time i hear about WhatsApp storing unecrypted copies of my chats in their cloud.

Can you provide more information?

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#83
post #80

Earlier quoted context omitted.

As a non-US citizen, how can I be sure that all non-Huawei equipment is free of back doors, data-exfiltration and forwarding capabilities excluding the lawful interception feature set?

Well, there was the case where the the NSA intercepted hardware shipments (I think it was Cisco HW) to install their backdoors.

I have listened tales about backdoors in unmodified Cisco switches and routers so, I expect any country can try to backdoor another.

So it's something between a slippery slope and futile attempt unless you have a multi layer security from different vendors or roll your own defenses.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#84
post #34

It's very important that we keep Huawei out of our 5G networks! (what if they discovered things like this and told the citizens about it?)

Please stop equating totalitarian regimes with democracies.

Well, until that democracy decides you have something interesting they want to take away from you.

In that case, regardless of whether you're a grotesque dictator or a quasi-peasant just getting by with your life, better start counting the days before something bad happens to you...

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#85
post #80

Earlier quoted context omitted.

As a non-US citizen, how can I be sure that all non-Huawei equipment is free of back doors, data-exfiltration and forwarding capabilities excluding the lawful interception feature set?

Well, there was the case where the the NSA intercepted hardware shipments (I think it was Cisco HW) to install their backdoors.

Maybe they were just too cheap to buy the backdoor off the (black) market... ;)

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#86
post #19

I love how the politicians presume NSA is safe partner and their danish citizens are not in the data. It does not really help if every other neighbouring country does the same. NSA will get danish info elsewhere. Everyone gets played. It works as long as USA is an trusthworthy ally. They wouldn't dare to abuse the information for private gains... right?

Are you looking for more oversight than is expressed in the article? It says the Danes check to make sure what the NSA searches for on that system does not include Danish citizen identifiers.

The data used by XKEYSCORE is stored on multiple servers, including the NSA's long term storage servers. How could the Danes be certain the NSA wasn't conducting searches from some cache they do not have access to?

At the end of the day, this will rely on trusting the NSA despite their dubious history.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#87
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

> If we can't convince people with their ear to the ground, how does one convince the general public.

Convince them of what? Some of us don't believe the NSA are bad actors and and possibly we also believe they're doing their jobs and support them in that.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#88
post #85
post #80

Earlier quoted context omitted.

Well, there was the case where the the NSA intercepted hardware shipments (I think it was Cisco HW) to install their backdoors.

Maybe they were just too cheap to buy the backdoor off the (black) market... ;)

Internet was too ethical, naive and immature when NSA did that. We were happily using unencrypted connections to connect to forums, telnet based BBSes and such.

NSA, OTOH, intercepted the switches which would isolate high security networks (red/black separation) and bleed sensitive information with these enhanced hardware.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#89
post #67

Earlier quoted context omitted.

in terms of domestic espionage on private citizens they are pretty similar now days

Data collection and political system are VERY different. All governments collect data on their private citizens, but not all sell their organs for profit or do forced sterilization

As an European, does it really make a difference?

Is USA really much better than China?

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#90
post #59

Earlier quoted context omitted.

> Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Just adding an example for the people who don't see the value of metadata: WhatsApp is still a viable revenue source for Facebook even as they have no access to the text of the messages due to E2EE. Knowing who talks to who, at what times, the type and approximate size of messages, the members of groups, and the contents of…

> they have no access to the text of the messages due to E2EE. Correction: they might not have access to the message text. It's entirely possible (if not plausible: FB doesn't exactly have a good track record) for FB to just self-MitM the E2EE and see everything that passes through their servers. From their site: > The verification process is optional for end-to-end encrypted chats, and only used to confirm that the…

> It's entirely possible (if not plausible: FB doesn't exactly have a good track record) for FB to just self-MitM the E2EE and see everything that passes through their servers.

Why would they even need to MitM in transit when they control the endpoints? They can just analyze the raw text locally (in the app) and extract valuable information.

Post reply on HN