Live data from Hacker News

The NSA Furby Documents

404media.co

41–50 of 129 posts

Re: The NSA Furby Documents

#41
post #5

Whats gov policy around Alexas and like half the IOT market? My botvac even has a microphone. I'm sure it's "don't ever speak about outside of this room" sort of thing. I guess phone calls would be over a secure line. Are there secure cell phone towers/whatever? I'm curious how gov phones are hardened.

There is an entire industry for secure phones. Many have to be "unlocked" before dialing other secure phones. It isnt simple. Getting a normal phone line to passively carry an encrypted call is a bit of a hack.

A hack? The entire point of encryption is to permit messages to be sent over insecure channels, no?

Re: The NSA Furby Documents

#42
post #5

Whats gov policy around Alexas and like half the IOT market? My botvac even has a microphone. I'm sure it's "don't ever speak about outside of this room" sort of thing. I guess phone calls would be over a secure line. Are there secure cell phone towers/whatever? I'm curious how gov phones are hardened.

In any SCIF or SCIF-like office space, they're all prohibited. You leave your cell phone at the front door of the secured area. Internet access is via SIPRNet (for classified) or NIPRNet (non-classified, but secured). Phones are through dedicated secure switchboards. The above is common in the DC area (lots of DoD contractors).

I wonder how that's going to work in our augmented future. Especially if people replace non-functional eyes and ears with digital ones.

Re: The NSA Furby Documents

#43
post #5

Whats gov policy around Alexas and like half the IOT market? My botvac even has a microphone. I'm sure it's "don't ever speak about outside of this room" sort of thing. I guess phone calls would be over a secure line. Are there secure cell phone towers/whatever? I'm curious how gov phones are hardened.

There is an entire industry for secure phones. Many have to be "unlocked" before dialing other secure phones. It isnt simple. Getting a normal phone line to passively carry an encrypted call is a bit of a hack.

> It isnt simple. Getting a normal phone line to passively carry an encrypted call is a bit of a hack.

How so? It would seem fairly trivial considering we have ways of sending data over phone lines as sound for decades.

Re: The NSA Furby Documents

#44

Earlier quoted context omitted.

A relative of mine used to work in this space 20 years ago. Seems policies haven’t changed at all. Tangental story about how serious the Gov takes OpSec. When I was in Iraq, a Marine in my unit found a roll of red Classified tape. He thought it would be cool to put a strip on his personal laptop, which was confiscated almost immediately. It was very clearly a personal machine, but policy is policy, and he never got t…

Oh yeah, they take it seriously most of the time. But you do get seemingly odd outputs from those procedures. Case in point... Many years ago, I worked part-time for a small construction cost management contractor. They did some TS work for DoD/State (usually combo projects, where NSA/CIA/Army had a wing of a consulate that State managed). I did not have a TS (or any other clearance) at the time. One day, I'm tasked…

Thank you for publishing this info, comrade! Ve arr going to chek all old Munich hospitals.

Re: The NSA Furby Documents

#45
post #43

Earlier quoted context omitted.

There is an entire industry for secure phones. Many have to be "unlocked" before dialing other secure phones. It isnt simple. Getting a normal phone line to passively carry an encrypted call is a bit of a hack.

> It isnt simple. Getting a normal phone line to passively carry an encrypted call is a bit of a hack. How so? It would seem fairly trivial considering we have ways of sending data over phone lines as sound for decades.

Because the signal transmitted over normal phones has to be encrypted. That encrypted signal will then be digitized/compressed by the standard phone line. Any artifacts in the phone line digitization might turn the encrypted signal into gibberish. Its like compressing a jpeg too many times. So you need an encryption method that isnt simple digitization. You need something that is encrypted but essentially sounds like human speech so that the digitization/compression process does not damage it.

https://gdmissionsystems.com/products/encryption/secure-voic...

https://www.cryptomuseum.com/crypto/gd/viper/

Re: The NSA Furby Documents

#46
post #5

Whats gov policy around Alexas and like half the IOT market? My botvac even has a microphone. I'm sure it's "don't ever speak about outside of this room" sort of thing. I guess phone calls would be over a secure line. Are there secure cell phone towers/whatever? I'm curious how gov phones are hardened.

In any SCIF or SCIF-like office space, they're all prohibited. You leave your cell phone at the front door of the secured area. Internet access is via SIPRNet (for classified) or NIPRNet (non-classified, but secured). Phones are through dedicated secure switchboards. The above is common in the DC area (lots of DoD contractors).

How strictly are SCIF policies enforced? I'm just a civilian who's never had exposure to that world, but based on my experience with other parts of the government, I'd expect SCIF compliance to fall on a broad spectrum from "sloppy or non-existent" to "overly strict and paranoid." Is my intuition accurate? Who's accountable for the compliance of a given SCIF - can anyone with clearance "setup a SCIF" or does it need to be registered, audited, etc?

Re: The NSA Furby Documents

#47
post #41

Earlier quoted context omitted.

There is an entire industry for secure phones. Many have to be "unlocked" before dialing other secure phones. It isnt simple. Getting a normal phone line to passively carry an encrypted call is a bit of a hack.

A hack? The entire point of encryption is to permit messages to be sent over insecure channels, no?

The hack is getting the unsecure system not to damage your encrypted signal, to carry even though it is expecting plain voice talking rather than a stream of binary digits.

Re: The NSA Furby Documents

#48

Earlier quoted context omitted.

In any SCIF or SCIF-like office space, they're all prohibited. You leave your cell phone at the front door of the secured area. Internet access is via SIPRNet (for classified) or NIPRNet (non-classified, but secured). Phones are through dedicated secure switchboards. The above is common in the DC area (lots of DoD contractors).

How strictly are SCIF policies enforced? I'm just a civilian who's never had exposure to that world, but based on my experience with other parts of the government, I'd expect SCIF compliance to fall on a broad spectrum from "sloppy or non-existent" to "overly strict and paranoid." Is my intuition accurate? Who's accountable for the compliance of a given SCIF - can anyone with clearance "setup a SCIF" or does it need…

In my experience, they are seriously enforced, though any time you have a large number of people you'll definitely find exceptions. The threat of massive fines and long jail times tends to encourage compliance. Also, many of the people who work in SCIFs know they are dealing with information that, if released, could lead to a number of people getting killed (think intelligence sources) or a country being unable to defend itself because a US weapon system was compromised (think Ukraine). Nation-states are working to extract information from SCIFs, it's not a theoretical problem, and SCIF users know this.

Re: The NSA Furby Documents

#50
post #29

The FOIA documents are up on archive.org now: https://archive.org/details/nsa-furby-memo/ I'm amused at page 8 of the listserve doc, in which someone points out that the ongoing discussion may at some point be released to the public under FOIA and to consider how it might look after showing up on the front page of a news site

They wanted to avoid FURBYGATE. They avoided FURBYGATE. Sounds reasonable to me!

Right. The whole email thread seems very reasonable to me. TFA characterizing this as "freaking out" is nonsense.
Post reply on HN