Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

91–100 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#91
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

What most people don't understand is that a targeted IP, with a stream size and a timestamp is enough to identify pretty every https page uniquely if it is accessible by a spider.

A headless chrome makes measurements of timings even easier these days. The order of how files are loaded, which file size e.g. jquery.123.min.js has, and where and when exactly in which order it is loaded from is very unique among all pages of a website.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#92

Earlier quoted context omitted.

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

> If we can't convince people with their ear to the ground, how does one convince the general public. Convince them of what? Some of us don't believe the NSA are bad actors and and possibly we also believe they're doing their jobs and support them in that.

"The NSA" - who do you mean here? The org in its official function doing unofficial things without oversight? Or the individual working for the NSA spying on his ex-lover for blackmail material?

I mean, either you're saying "no one within the NSA has ever been a bad actor", or you're saying "the bad actions are acceptable collateral damage; no oversight needs to be applied to ensure the trade off between effectiveness and collateral damage is balanced", or you're saying "not ALL actors are bad" and leaving it at that.

And...none of those strikes me as a particular defensible position to take.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#93
post #82
post #69

Earlier quoted context omitted.

> WhatsApp is still a viable revenue source for Facebook even as they have no access to the text of the messages due to E2EE. A friendly reminder to everyone that even if the encryption that is used to send the messages in WhatsApp seems to be solid they upload your entire chat history as unencrypted dumps to the cloud. Even if you turn it off your chats will still end up there as long as whoever you are chatting wit…

This is the first time i hear about WhatsApp storing unecrypted copies of my chats in their cloud. Can you provide more information?

I suppose the AFAIK (I do not use WhatsApp), it's Google backup services on Android. WhatsApp stores the local chat history unencrypted in the device and does not mark it as "do not backup", so the cloud sync service uploads it to the backup service. And Android does not encrypt this information.

For contrast, Signal does encrypt the local history and the backups (to the point that is a bit harder to backup the chat to outside in Android, you need to copy a randomly generate password manually to restore it. But it's a safe approach).

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#94

Yep, TOR is not secure. The other thing not mentioned enough is how insecure blockchain is. Both are vulnerable to time-correlation. https://www.wired.com/story/theres-no-good-reason-to-trust-b...

I wish people would emphasize this more. Bitcoin isn't anonymous, and with the legal requirements for reporting transactions, much of what happens on there can be corellated to real-world identities. Far as privacy goes, it's probably a step backwards even from bank accounts and credit cards since there's no warrant needed to access it.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#95
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with.

The comfortable upper middle-class are the most conservative elements of any society; they're providing the management and expertise to implement any dystopia that's coming. Beneath them are the tradespeople and unskilled laborers who choose between working or starving, and above them are morons.

Nobody who has spent more than a moment thinking about it fails to understand the dangers of metadata, they just don't think they it will be a problem for them. Hence the most common response is something about how their lives are boring, and how they have nothing to to hide. "Who cares if I'm at Starbucks at 2 o'clock?" Technologists know full well what they could do with that information, that's what they're paid to know, and they're who are going to be doing it, or they're going to have to find another job.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#96
post #34

It's very important that we keep Huawei out of our 5G networks! (what if they discovered things like this and told the citizens about it?)

> It's very important that we keep Huawei out of our 5G networks!

Huawei isn't working on behalf of a Gov that can imprison me for exposing it's wrongdoing. NSA is.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#97

Earlier quoted context omitted.

> If we can't convince people with their ear to the ground, how does one convince the general public. Convince them of what? Some of us don't believe the NSA are bad actors and and possibly we also believe they're doing their jobs and support them in that.

"The NSA" - who do you mean here? The org in its official function doing unofficial things without oversight? Or the individual working for the NSA spying on his ex-lover for blackmail material? I mean, either you're saying "no one within the NSA has ever been a bad actor", or you're saying "the bad actions are acceptable collateral damage; no oversight needs to be applied to ensure the trade off between effectivenes…

[deleted]

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#98
post #34

It's very important that we keep Huawei out of our 5G networks! (what if they discovered things like this and told the citizens about it?)

As a non-US citizen, how can I be sure that all non-Huawei equipment is free of back doors, data-exfiltration and forwarding capabilities excluding the lawful interception feature set?

>As a non-US citizen, how can I be sure that all non-Huawei equipment is free of back doors, data-exfiltration and forwarding capabilities excluding the lawful interception feature set?

Packet capture from the edge is where I'd start.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#99
post #16

This article is about 10x better in terms of explaining XKEYSCORE than the mess which is XKEYSCORE's Wikipedia article: https://en.wikipedia.org/wiki/XKeyscore#Workings

If all we have to go off of is the slides and rumors, it's still not super clear exactly how it works. Even for HN users, which are largely engineers, it can be confusing. If you're a wikipedia editor, probably more so.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#100
> In recent years, the NSA and the German BND have also been accused of massive illegal domestic spying. Thorough investigations have shown that was not the case, although their employees were sometimes careless and it was technically not always possible to do what was legally required.

Absurd statement from the article. What investigations? Internal from the NSA? It's like saying "No the NSA are not collecting data on Americans because Mr. Clapper said so to the Senate under oath."

Post reply on HN