Earlier quoted context omitted.
Why do you need a mole? Just have someone dig up the street, and intercept the fiber optic cable. I mean you still need to deal with private keys but the NSA might have the certificate authorities wrapped around their fingers.
If the NSA was MITMing SSL communications on a wide scale, presumably the companies would notice that the cert fingerprints were not what the companies expected.
Mark Zuckerberg addresses PRISM
111–120 of 298 posts
Re: Mark Zuckerberg addresses PRISM
#112Look at the two writeups (Zuckerberg's and Page's) side by side. Each has 4 paragraphs. Each of the pairs of paragraphs addresses the same thing. 1st paragraph: we wanted to respond to these claims. 2nd paragraph: never heard of PRISM, don't give direct access. 3rd paragraph: each request goes through legal channels. 4th paragraph: encourage governments to be more transparent. Terrifying. EDIT: It gets worse. Here's…
each were prepared by the same law / PR firm ... ( dont know could be :) ), or even worse , it is a template written directly by your government("if you get caught , say that"). The sad truth is most people dont even care ...
Re: Mark Zuckerberg addresses PRISM
#113Earlier quoted context omitted.
>>..another possibility is that they want people to notice the similarities and become more upset about PRISM. Ah, that makes sense, if they are under a gag order, but yet want to subtly convey that they are under a gag order! It would be a brilliant way of circumventing it.
Realistically though, can you imagine there being so many CEOs knowing that this thing is going on and being forced to lie about it, and not one of them spilling the beans? Even if the gov tries to arrest them for leaking classified information, they'd be near-impossible to convict following the inevitable massive public outcry.
Re: Mark Zuckerberg addresses PRISM
#114I would like to believe these reports from Google [1] and Facebook [2], but someone is not telling the truth. There is evidence that directly contradicts their stories (i.e. The Guardian has verified the authenticity of the document, a 41-slide PowerPoint presentation – classified as top secret with no distribution to foreign allies – which was apparently used to train intelligence operatives on the capabilities of t…
There is no contradiction if you accept the suggestion from http://financialcryptography.com/mt/archives/001431.html that the NSA got access to this information by planting moles at target companies who then created back doors for the NSA to use. This would be reasonably easy for the NSA to do, relatively hard for companies to catch, and perfectly explains all published facts.
Re: Mark Zuckerberg addresses PRISM
#115Re: Mark Zuckerberg addresses PRISM
#116Earlier quoted context omitted.
It's not just using the phrase 'direct access'. Anyone with half a brain knows that all these CEOs could not have released this responses that are so exactly the same except for choice of words independently. There has to be some explanation, whether it is completely innocent, or otherwise, is the question for me.
I guess anyone with half a brain would hire a really good legal team that would probably arrive at the optimum initial salvo in a lawsuit defense: * No direct access. * Never heard of Prism. * We review each request. * We want more government transparency. Edit: Formatted the list.
Re: Mark Zuckerberg addresses PRISM
#117Earlier quoted context omitted.
>>..another possibility is that they want people to notice the similarities and become more upset about PRISM. Ah, that makes sense, if they are under a gag order, but yet want to subtly convey that they are under a gag order! It would be a brilliant way of circumventing it.
That doesn't seem likely to me. If you want to let the truth be known, but you feel so much under the gun that you issue not just a minimum-compliance false statement but a fulsome one under your own name, would you really feel safe contacting a bunch of other Silicon Valley CEOs to co-ordinate such a subtle but intentional secret message?
Re: Mark Zuckerberg addresses PRISM
#118I'm now just confused. If I understand it correctly, the government has publicly acknowledged the program and tried to explain how it's "limited and legal," but extant nonetheless. Now the companies are all uniformly denying it. The options: - The companies are lying. - The government has infiltrated these companies and developed backdoor access the executive team is unaware of. - The government is intercepting traff…
#3 doesn't necessarily require breaking RSA, just TLS (via fake certificates or something else). Breaking RSA would be pretty interesting though.
It's safe to assume the NSA can easily do way more than 2 petaflops, and they have an exaflop goal, and that would be enough to run known attacks against DES, factor 1024bit RSA moduli ... and if they can compromise just one root CA (which uses 1024bit RSA) they can issue valid certifications of their own and MITM everyone, and none would be the wiser.
And all of this assuming the NSA relies on publicly known weaknesses in SSL/TLS. The matter of the fact is that they have very smart people with access to unlimited resources researching new vulns and actively exploiting them.
Re: Mark Zuckerberg addresses PRISM
#119Hmm, what I'd like to hear is tech CEOs say "the NSA does not have the private key for our SSL certs." Beam splitters are a pretty cheap buy.
Re: Mark Zuckerberg addresses PRISM
#120Hmm, what I'd like to hear is tech CEOs say "the NSA does not have the private key for our SSL certs." Beam splitters are a pretty cheap buy.