Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

151–160 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#151

I love how the politicians presume NSA is safe partner and their danish citizens are not in the data. It does not really help if every other neighbouring country does the same. NSA will get danish info elsewhere. Everyone gets played. It works as long as USA is an trusthworthy ally. They wouldn't dare to abuse the information for private gains... right?

I don't think people are that naive. The reason for that arrangement is simply that it is only necessary for the NSA to collaborate with one Danish intelligence agency (foreign intelligence, which is probably forbidden from spying on Danes), rather than two (foreign and domestic).

In a larger sense, the arrangement might, to a degree, defeat the purpose of having separate foreign and domestic intelligence agencies, but that is a more abstract notion. I guess we'll see what the Danish public will think or do about.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#152

In the 90s I remember critical media linking Sandagergård to the Echelon Project. There were also rumors about foreign contractors operating at the facility. I've always thought about this when I was near Sandagergård (it's situated in a beautiful place off the beaten path not far from Copenhagen) but as far as I remember the stories where mostly based on speculation without any hard facts. With these recent disclosu…

> it seems that there might have been some truth to those old stories

It's really weird to see confirmed, year after year, that all those "conspiracy theories" (first circulated on the '90s internet) turned out to be almost entirely true, when it comes to network-based espionage.

Echelon/five eyes? Check.

Massive network surveillance? Check.

Compromised ciphers? Check.

Compromised hardware manufacturers? Check.

NSA being fundamentally devoid of oversight? Check.

US espionage targeting allies for industrial gain? Check, check, aand check.

This shit was ridiculed back then, and it makes so hard to discern what is true in contemporary news reporting.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#153
post #67

Earlier quoted context omitted.

Data collection and political system are VERY different. All governments collect data on their private citizens, but not all sell their organs for profit or do forced sterilization

As an European, does it really make a difference? Is USA really much better than China?

USA has your data already (internet cables), why send it to China?

Not going to answer the 2nd question for personal reasons.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#154

Earlier quoted context omitted.

If you are not trusting the people that are running these things, then Signal is just another siloed messenger where the servers are controlled by a single entity. There are certainly worse but Signal is not special.

Signal has open clients with reproducible builds. We know that they are keeping their promises wrt what information is communicated with the backends. That's a step above the other options in common use, and in fact does make Signal special.

What's better, Signal or Telegram?

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#155
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

> All these comments about metadata not being useful

I only see one

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#156

Earlier quoted context omitted.

> Say what you want about Secure Enclaves, we know of no better way to conceal social graphs. I'm not following. Secure Enclaves have nothing to do with protecting the social graph of Signal users. They're used to store the contact list (and other things) in the "cloud" in a safe way – things that weren't even shared / stored anywhere by Signal before Secure Value Recovery was introduced.

https://signal.org/blog/private-contact-discovery/ This is the relevant blog post.

Ohh right, sorry about that – I totally forgot about that feature!

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#157

Earlier quoted context omitted.

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with. The…

> upper middle-class are the most conservative elements of any society

This very clearly is not the case in the US.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#158

Earlier quoted context omitted.

Signal has open clients with reproducible builds. We know that they are keeping their promises wrt what information is communicated with the backends. That's a step above the other options in common use, and in fact does make Signal special.

> Signal has open clients with reproducible builds. Not really. First of all, there is only one Signal client allowed to connect to Signal’s servers. And in the real world, the vast majority of Signal uses are getting their APK for that app from the Google Play store (the Signal team has said that they prefer you to use the Play store as well, instead of direct-downloading an APK from their website which they offer o…

> That means that a state-level actor could possibly carry out a targeted attack to replace the Signal app on a given person's phone with a malicious build.

No, they couldn't. They would need the Signal developers' key. Android requires app updates to be signed with the same key as the original app.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#159
post #82

Earlier quoted context omitted.

This is the first time i hear about WhatsApp storing unecrypted copies of my chats in their cloud. Can you provide more information?

I suppose the AFAIK (I do not use WhatsApp), it's Google backup services on Android. WhatsApp stores the local chat history unencrypted in the device and does not mark it as "do not backup", so the cloud sync service uploads it to the backup service. And Android does not encrypt this information. For contrast, Signal does encrypt the local history and the backups (to the point that is a bit harder to backup the chat…

Additionally, WhatsApp heavily encourages storing backups in Google Drive as well, with semi-regular popups asking users to configure backups in GDrive and to set the backup interval, if not already done. Obviously this doesn't mean Facebook has the information and the straightforward interpretation is that it's the least involved way of creating backups without sending it all to facebook

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#160

Earlier quoted context omitted.

Signal has open clients with reproducible builds. We know that they are keeping their promises wrt what information is communicated with the backends. That's a step above the other options in common use, and in fact does make Signal special.

What's better, Signal or Telegram?

In contrast to Signal, Telegram doesn't end-to-end-encrypt messages by default (they get stored in plaintext on their servers), it also doesn't protect the social graph and even stores your contact list on their servers. Even WhatsApp is more secure than Telegram.
Post reply on HN