Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

131–140 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#131

Earlier quoted context omitted.

Welcome to six years ago, where Americans where shocked that the NSA had spied on US citizens but did not give a shit about the spying on regular innocent people in other countries around the world. As a Dane, I hope that the politicians a going to make it crystal clear the the FE is suppose to collect intel to protect the country, but not at any cost. Flat out lying and keeping secrets from the people who are tasked…

As someone living in Denmark I wonder how do they classify a Danish citizen? Someone living in Denmark, having permanent residence, living in Denmark and being EU national, holding passport or being born here? Also, from a fair amount of conversation with my Danish colleagues I find it odd how uncritical they are when describing the relationship of Denmark and USA, regardless if I myself find the specific view differ…

>how do they classify a Danish citizen?

I would guess by the same measure as voting and public benefits. You have to be a Danish citizen and have place of residence in Denmark.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#132

Earlier quoted context omitted.

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with. The…

I work in a factory doing factory stuff

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#133
post #34

It's very important that we keep Huawei out of our 5G networks! (what if they discovered things like this and told the citizens about it?)

As a european , i d rather have my surveillance camera phone china than the US. Google already knows too much about where and what i m doing, they dont need access to my camera. China OTOH doesnt have any kind of legal jurisdiction on me, we don't have some the kind of alliances that we share with US. Like during the cold war, arbitraging between spies was a safe bet.

Couldn't agree more. So many people are so scared of China (the new red scare) but in reality if you did something illegal who do you have to fear more gets their hands on the data: The FBI or some PRC equivalent? There are hundreds of stories of FBI (and CIA) working in other countries but I have never heard of any PRC people kicking in the door of someone outside the PRC.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#134

Earlier quoted context omitted.

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

Blame VCs (hi Ycom) When the time series data of conversations is MRR, gains, and ephemeral frameworks of the week 90% of the time, and 10% “same old physics” what do you expect from a bunch of humans still recovering from black & white “forever good life!” thinking? Tell the cohorts titillating people with fairy tales to bug off a bit, humanity. Or do like the Romans and watch it all die Only this time it could be t…

what are you talking about?

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#135

>The novelty of XKEYSCORE is that it enables analysts to find exactly those anonymous communications. For that purpose it reassembles IP packets into their original format ("sessionizing"), like Word documents, spreadsheets, chat messages, etc. This sounds interesting. Does it mean they write a sort of serialization/deserialization routine for whatever format they can grab at hand? For example maybe it's possible to…

Not quite. Many of our extractors are stateful - ie. They need to see previous packets in the session to extract keys, state, etc. This is done by having front ends which direct raw packets to backends based on which session they are a part of - the obvious one being the tcp 4-tuple. The backends then don't each have many sessions to look after - perhaps tens of thousands each. That means they can keep many kilobytes…

Very interesting. Is this written up anywhere?

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#136

Earlier quoted context omitted.

Absolutely. You should trust anything as much as you can verify it and no further. I submit that there is no better option right now.

If you are not trusting the people that are running these things, then Signal is just another siloed messenger where the servers are controlled by a single entity. There are certainly worse but Signal is not special.

Signal has open clients with reproducible builds. We know that they are keeping their promises wrt what information is communicated with the backends. That's a step above the other options in common use, and in fact does make Signal special.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#137

Earlier quoted context omitted.

Absolutely. You should trust anything as much as you can verify it and no further. I submit that there is no better option right now.

If you are not trusting the people that are running these things, then Signal is just another siloed messenger where the servers are controlled by a single entity. There are certainly worse but Signal is not special.

I would be interested to learn if you have examples of services whose privacy practices you admire more than signal’s.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#138

Earlier quoted context omitted.

You're one of the people this [0] comment is talking about. Also, how can you possibly believe that the NSA are not bad actors? Between trying to hobble encryption, spying on everything, and enabling bad individual actions, and having a horrible success rate [1], what is left to defend? [0] https://news.ycombinator.com/item?id=24962802 [1] https://www.newamerica.org/international-security/policy-pap...

NSA's competence or success rate doesn't invalidate the need for such an organization. Individuals part of the organization that behave badly don't either. Other states have organizations like the NSA and in order for the USA to defend itself from them the USA also needs one. We don't question the need for a military because one lieutenant burns down a Vietnamese village, we demand justice and changes, but we continu…

Well, let me metaphorically show where _your_ NSA should be as a person from a country that is not the USA.

To keep it all-ages, let's stick with "far away from existence, and even further from OUR personal data and metadata".

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#139

Earlier quoted context omitted.

If you are not trusting the people that are running these things, then Signal is just another siloed messenger where the servers are controlled by a single entity. There are certainly worse but Signal is not special.

Signal has open clients with reproducible builds. We know that they are keeping their promises wrt what information is communicated with the backends. That's a step above the other options in common use, and in fact does make Signal special.

Are you running an open client? Is anyone?

That's all a smoke screen. Nobody is running an open client with a reproducible build, everybody is running whatever version is downloaded from their app store of choice.

It's not special, and I don't trust it a bit.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#140
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

> Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Just adding an example for the people who don't see the value of metadata: WhatsApp is still a viable revenue source for Facebook even as they have no access to the text of the messages due to E2EE. Knowing who talks to who, at what times, the type and approximate size of messages, the members of groups, and the contents of…

There is no proof they didn't tamper with their OpenWhisper implementation - Whatsapp is proprietary software on client and server.

And looking at what has unfolded in the last decade, chances are against the user and we must, for ours and our peers' safety, assume the worst.

Post reply on HN