Live data from Hacker News

NSA slides explain the PRISM data-collection program

washingtonpost.com

61–70 of 121 posts

Re: NSA slides explain the PRISM data-collection program

#61
post #36

(note/edit: I've made an error of conflation between the recently reported massive phone record sweep-up and PRISM, which according to the WP, simply allows analysts to trace (essentially) the totality of someone's online interactions, though not everyone at once. So really, things don't seem that much different than last week when it was well known that the government has discretion to warrantlessly tap us. Still, $…

Does $20M include the cost that was borne by the companies?

Re: NSA slides explain the PRISM data-collection program

#62
post #36

(note/edit: I've made an error of conflation between the recently reported massive phone record sweep-up and PRISM, which according to the WP, simply allows analysts to trace (essentially) the totality of someone's online interactions, though not everyone at once. So really, things don't seem that much different than last week when it was well known that the government has discretion to warrantlessly tap us. Still, $…

To be honest I'm still catching up on a lot of the details with these stories, but it's this comment that made me wonder if there is a bit of hyperbole going around. Companies make leaks all the time on the most mundane things (hell Apple can barely contain the new iPhone that is usually coming out.) I'm hesitant to believe all the conspiracy theories going around that the companies willingly did this, or that it's a…

What really makes me suspicious is this passage:

> “They quite literally can watch your ideas form as you type,” said the “career intelligence officer” who gave documents describing PRISM to the Washington Post.

Think of the engineering needed at multiple endpoints to allow something like this...I can believe the NSA has some of the best cryptoanalysts, but our best front-end hackers as well (do they have their own Meteor.js)? I'm only being slightly pedantic here. If this is "literally" possible, then the amount of work needed for the collaborating companies is non-trivial. It's one thing to pass along uber-authentication credentials allowing an NSA-agent Zuckerberg-like privileges...that could be something implemented with as few as a couple people. But to bake in something right out of a hacker movie?

It just makes a few of the claims sound a bit suspect...because what is terribly frightening is the government's ability to aggregate and analyze this information in bulk, not to peep in on you as you're typing in real-time, which would be one of the least efficient ways ever to spy on the general American public's online activity.

And no, I'm not being an apologist for federal expansion of powers. I'm pointing out that some of what this source is leaking seems to be beyond reality, not because of technological sophistication, but because of the number of mundane moving parts and actors that would seemingly have to be involved (theoretically, wouldn't they have to have as many datacenters as all the companies they're vacuuming from?). The entire PowerPoint slide set looks like something a get-rich-quick contractor would whip up to win a fat contract that would never actually be scrutinized for viability.

But still, even if the government doesn't actually have the capability as described, it is wrong for them to not disavow it...it's not any good if their mindset is: "Oh we're not doing that...yet...but we would love to, some day)

Re: NSA slides explain the PRISM data-collection program

#63

Earlier quoted context omitted.

I hate to be this guy but there are people lighting off bombs out there and as soon as a big one goes off people will demand they do a lot more than this. Would you rather have your Facebook scanned or see a car bomb go off in Times Square during rush hour? That's not hyperbole, that's the decision we have to make.

That is hyperbole. The number of terrorist incidents is massively low, and the few that the government claims to have stopped were such laughably unrealistic plots that one wonders the government even bothered. Meanwhile, we have a government surveillance program that literally surpasses the level of the Stasi, here in the United States, and simultaneously an administration that will not even reveal the criteria used…

Bullshit, 'the Stasi"? Go talk to somebody who lived in East Germany. And they catch people all the time trying to get bomb materials, how did you think they were doing it, luck? (In the case of the car bomb in Times Square you're right, it was dumb luck, the timer malfunctioned.) If the average person didn't freak out and start yelling retarded things like 'Stasi!' I'd say fine, maybe my fucking Facebook is worth people's lives but they do freak out and then they pass things like the Patriot Act, or worse. So to prevent mindless fear I say fine, scoop up whatever crap you need, if I want something kept secret I know how to do it.

Re: NSA slides explain the PRISM data-collection program

#64

Now. Exactly which data is exposed for each provider? I'm thinking mostly about Gmail. Because virtually everyone now is using it… The whole content of any communications? Just origin/dest? This is becoming scary.

Here is hoping that there is zero.zero percent corruption in the FBI, NSA, and CIA. A lot of disruptive start-ups and research institutions use Google business[1] and education[2] apps...

[1] https://www.google.com/intx/en/enterprise/apps/business/ [2] http://www.google.com/enterprise/apps/education/customers.ht...

Re: NSA slides explain the PRISM data-collection program

#65

For what it's worth Apple and Google denie it: http://www.cnbc.com/id/100797046

IIRC, they're legally required to deny it. Plus, careful wording allows all sorts of out. Google says they don't provide a "back door", but this sort of thing could be defined as coming in the front door.

Gag orders don't require them to deny it, the require them not to confirm it.

Re: NSA slides explain the PRISM data-collection program

#66
post #42

I'm not sure why this is a big surprise to anyone. I'm a cynic, but if anyone asked me whether I think the NSA, CIA, or FBI are eavesdropping on personal communications, I would say, "of course they are." This is nothing new: ECHELON, Clipper/Skipjack, Carnivore, ...

How many times does some one have to say this? I'm sorry, but this sort of comment is getting pretty tiresome. Yes we all "knew". All of us "knew". Some of us have "known" for something like 15 years. (Which, BTW, is why I'm most sure why Obama is getting so much flack. Its a Clinton - Bush - Obama scandal.) But none of us, not one, actually did know anything at all. We suspected, or assumed. But we did not know. Not…

Am I the only one to think this is too good to be true? I mean, this can have the exact opposite effect, and become a big "don't trust what you read on the Internet, kids".

NSA doesn't even have to deny anything. Let the other interested parties wash their hands, and leave with a "told ya" smile.

Not sure if it was intentional or not, but seems a very convenient prank. I know, Conspiracy theory^-1. We'll see.

Re: NSA slides explain the PRISM data-collection program

#67
post #62

Earlier quoted context omitted.

To be honest I'm still catching up on a lot of the details with these stories, but it's this comment that made me wonder if there is a bit of hyperbole going around. Companies make leaks all the time on the most mundane things (hell Apple can barely contain the new iPhone that is usually coming out.) I'm hesitant to believe all the conspiracy theories going around that the companies willingly did this, or that it's a…

What really makes me suspicious is this passage: > “They quite literally can watch your ideas form as you type,” said the “career intelligence officer” who gave documents describing PRISM to the Washington Post. Think of the engineering needed at multiple endpoints to allow something like this...I can believe the NSA has some of the best cryptoanalysts, but our best front-end hackers as well (do they have their own M…

I think "as you type" means different things to an intelligence officer and a programmer. The intelligence officer probably means "real time" (no need for a judge/approval/etc). A Google Wave like interface is probably not in the backend, but if the FISA route took weeks and the new kit takes seconds I could see "literally as you type" being a description that fits.

Re: NSA slides explain the PRISM data-collection program

#69
post #36

(note/edit: I've made an error of conflation between the recently reported massive phone record sweep-up and PRISM, which according to the WP, simply allows analysts to trace (essentially) the totality of someone's online interactions, though not everyone at once. So really, things don't seem that much different than last week when it was well known that the government has discretion to warrantlessly tap us. Still, $…

The $20M is probably not a full number--that might be the portion of it that gets credited to the program while other major costs (storage!) are already covered somewhere else.

Re: NSA slides explain the PRISM data-collection program

#70
post #42

I'm not sure why this is a big surprise to anyone. I'm a cynic, but if anyone asked me whether I think the NSA, CIA, or FBI are eavesdropping on personal communications, I would say, "of course they are." This is nothing new: ECHELON, Clipper/Skipjack, Carnivore, ...

How many times does some one have to say this? I'm sorry, but this sort of comment is getting pretty tiresome. Yes we all "knew". All of us "knew". Some of us have "known" for something like 15 years. (Which, BTW, is why I'm most sure why Obama is getting so much flack. Its a Clinton - Bush - Obama scandal.) But none of us, not one, actually did know anything at all. We suspected, or assumed. But we did not know. Not…

I mean, I guess I see what you're saying, but obviously at least a handful of people at each of the member companies knew. I believe those are the people the parent comment is talking about.
Post reply on HN