Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

101–110 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#101
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

Both you and these commenters are missing the point. They're not just collecting metadata. We know from the Snowden leaks that the NSA was able to decrypt most https traffic as well as most SSH and VPN traffic around 2013. Although protocol security has been beefed up a bit and many bugs have been weeded out since then, it's still naive to assume they've lost this capability.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#102
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

Just chiming in here: it’s almost all about the graph. If you have the graph, the content is almost irrelevant. This is why Signal hiding the graph as best they can, using SGX, is incredibly important work. Say what you want about Secure Enclaves, we know of no better way to conceal social graphs. Yes there is still potentially some metadata analysis that can be done at the server to coordinate IP addresses but we kn…

>...we know signal doesn’t keep those logs because of their response to the sealed subpoena ...

That doesn't prove that. If Signal was, say, a NSA project they would have to respond to such things in that way to protect the signal intelligence value of the metadata they were collecting for their primary mission.

After Crypto AG we know it is a bad idea to trust any particular entity. Something like Signal can only be trusted as much as can verified.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#103
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

Just chiming in here: it’s almost all about the graph. If you have the graph, the content is almost irrelevant. This is why Signal hiding the graph as best they can, using SGX, is incredibly important work. Say what you want about Secure Enclaves, we know of no better way to conceal social graphs. Yes there is still potentially some metadata analysis that can be done at the server to coordinate IP addresses but we kn…

> Say what you want about Secure Enclaves, we know of no better way to conceal social graphs.

I'm not following. Secure Enclaves have nothing to do with protecting the social graph of Signal users. They're used to store the contact list (and other things) in the "cloud" in a safe way – things that weren't even shared / stored anywhere by Signal before Secure Value Recovery was introduced.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#104
post #35

The fact that Danish intel has access to me just emphasizes how much of a free for all this is on that level. (nothing against the Danish - but think about what that implies about "trusted" relationships like five eyes)

Welcome to six years ago, where Americans where shocked that the NSA had spied on US citizens but did not give a shit about the spying on regular innocent people in other countries around the world. As a Dane, I hope that the politicians a going to make it crystal clear the the FE is suppose to collect intel to protect the country, but not at any cost. Flat out lying and keeping secrets from the people who are tasked…

As someone living in Denmark I wonder how do they classify a Danish citizen? Someone living in Denmark, having permanent residence, living in Denmark and being EU national, holding passport or being born here? Also, from a fair amount of conversation with my Danish colleagues I find it odd how uncritical they are when describing the relationship of Denmark and USA, regardless if I myself find the specific view different than mine. The people in question are of the right political spectrum and not overly political but still.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#105
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

In general, entities like the NSA need to treat metadata as important because that is often all they have. That is because most everything is encrypted these days. The NSA has known about the "going dark" problem for a long time now and this is the reaction.

So this situation can be considered a sort of a triumph. For most people metadata is no real threat to them. Generally it is already publicly known who your friends and family are and those are the people most interact with online. It is mostly valuable that no one else know what those interactions are even if they know when they occurred.

For the important instance of businesses the situation is much the same although sometimes there might be value in traffic analysis for larger businesses that have enough traffic to analyze.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#106
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

Michael Hayden, former director of the NSA and CIA:

“We kill people based on metadata.”

https://youtu.be/PxwEwwlDM8Q (39s clip)

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#107
post #19

I love how the politicians presume NSA is safe partner and their danish citizens are not in the data. It does not really help if every other neighbouring country does the same. NSA will get danish info elsewhere. Everyone gets played. It works as long as USA is an trusthworthy ally. They wouldn't dare to abuse the information for private gains... right?

Are you looking for more oversight than is expressed in the article? It says the Danes check to make sure what the NSA searches for on that system does not include Danish citizen identifiers.

The very concept that people should have their basic human right to privacy protected or denied based on the happenstance of their location of birth is insanity.

Governments that gate human rights on nationality are fundamentally amoral, and should never be trusted to self-regulate.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#108

Earlier quoted context omitted.

A statement is not a scientific fact. The head of the NSA lied to the American public about their extra-legal monitoring. What has changed since the Snowden revelations? Why would Danes be more respected by the NSA than US citizens themselves? This makes absolutely no logical sense.

To your point, the IC trades in misinformation and distraction as much as it trades in truth and fact. When any of those acronyms make a statement it's fitting to wonder if there's a broader arc, a bigger picture. Their responsibilities and mission are clear. There are no style points. They'll do whatever it takes to accomplish that mission. History is very clear about this M.O.

An interesting thing is no one is willing to say "lies" anymore. It's always "misinformation" because it gives the perpetrator a way out to claim it wasn't intentional. The NSA and CIA do LIE.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#109
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

An analogy I like is that they know you called a suicide hotline from a tall bridge in the middle of the night, but they don't know what you discussed.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#110

Earlier quoted context omitted.

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

> If we can't convince people with their ear to the ground, how does one convince the general public. Convince them of what? Some of us don't believe the NSA are bad actors and and possibly we also believe they're doing their jobs and support them in that.

You're one of the people this [0] comment is talking about.

Also, how can you possibly believe that the NSA are not bad actors? Between trying to hobble encryption, spying on everything, and enabling bad individual actions, and having a horrible success rate [1], what is left to defend?

[0] https://news.ycombinator.com/item?id=24962802

[1] https://www.newamerica.org/international-security/policy-pap...

Post reply on HN