http://googleonlinesecurity.blogspot.com/2013/05/changes-to-...
Seems like that could put a crimp on any beam split obtained data. At least for a short while.
51–60 of 107 posts
http://googleonlinesecurity.blogspot.com/2013/05/changes-to-...
Seems like that could put a crimp on any beam split obtained data. At least for a short while.
Earlier quoted context omitted.
Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have real…
This is exactly the conclusion I came to. My guess is they have the SSL/TLS keys. That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.
So... If I understand everything correctly, it should be impossible to decrypt passively captured HTTPS traffic to/from google.com.
http://www.quora.com/SSL-Secure-Sockets-Layer/Is-it-ever-pos...
Could someone more knowledgeable confirm this?
Earlier quoted context omitted.
A target's phone call, e-mail or chat will take the cheapest path, not the physically most direct path - you can't always predict the path Dates When PRISM Collection Began For Each Provider This is complete conjecture, but this reads to me like the NSA set up its own backhauls and set up peering agreements at artifically low prices to get traffic going over their pipes. Is there historical data for route announcemen…
OK, so when did Google push SSL everywhere? How does that fit with the graph at http://cdn.theatlantic.com/static/mt/assets/science/assets_c... ? It's possible Google come out as good guys in this...?
[1] http://blog.chromium.org/2013/01/google-search-in-chrome-get...
Earlier quoted context omitted.
Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have real…
This is exactly the conclusion I came to. My guess is they have the SSL/TLS keys. That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.
Could you link to tptacek's comments you're referring to?
His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…
The dates on the slides might be when a company has erected some convenient access point to grab the data "lawfully" obtained by a FISA order. Microsoft whipped something together quickly. Apple took years to get the UX just right.
Frankly, sucking in ALL of the Internet seems extremely difficult and useless. We're talking GOOG+AAPL+MS+YHOO+Skype+many more. And all for $20M/year? The gov't spends more on toilet paper.
Earlier quoted context omitted.
This is exactly the conclusion I came to. My guess is they have the SSL/TLS keys. That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.
Even without keys, the metadata from the packet headers and traffic analysis can be quite useful. Could you link to tptacek's comments you're referring to?
Earlier quoted context omitted.
I can't tell you want to believe, but maybe a place to start is: the world is a confusing place, full of miscommunication and gray areas. Why should we expect the world to be as it is in the movies, in which bad guys are obviously bad and that there is an "ending" in which things are clear? For starters, I just re-skimmed the Washington Post report and noticed that it has since been amended: > It is possible that the…
Well it's pretty clear now https://news.ycombinator.com/item?id=5843352 They don't have direct backdoor, but they have a system in place for a fast and effortless data sharing.
> The companies said they do, however, comply with individual court orders, including under FISA. The negotiations, and the technical systems for sharing data with the government, fit in that category because they involve access to data under individual FISA requests. And in some cases, the data is transmitted to the government electronically, using a company’s servers.
The data sharing is effortless. But the process to get it is still the bottleneck, because in the NYT article, the companies still assert that they conduct a lawyer review of the requests. And, moreover, FISA mandates that when the request involves an American citizen, that a court-approved is required.
If you're arguing that FISA is wrong and that companies should be doing everything they can, including sending the requested data in dot-matrix printouts, to hinder the process -- no argument from me there. But the question at hand is whether they are part of PRISM, which, according to the reports so far, is a program that is different in implementation and legality than FISA.
(And if you want to argue that sending any data upon a legal review is not at all different than direct, near-real-time access to a company's servers...I'm sure some infrastructure engineers would disagree with you, among other kinds of people required to make such a pipeline happen)
Earlier quoted context omitted.
This is exactly the conclusion I came to. My guess is they have the SSL/TLS keys. That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.
Even without keys, the metadata from the packet headers and traffic analysis can be quite useful. Could you link to tptacek's comments you're referring to?
https://news.ycombinator.com/item?id=5842915
I was being a bit devious. I am just so tired of tptacek dismissing stuff I say with asinine arguments and then watching my comment get downvoted to hell.
Earlier quoted context omitted.
This is exactly the conclusion I came to. My guess is they have the SSL/TLS keys. That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.
The linked quora answer (from the co-author of Firesheep) says that even in that case one can't launch a passive man in the middle attack if perfect forward secrecy is used. Google.com uses Diffie–Hellman key exchange which provides perfect forward secrecy. So... If I understand everything correctly, it should be impossible to decrypt passively captured HTTPS traffic to/from google.com. http://www.quora.com/SSL-Secur…
> openssl s_client -connect google.com:443 RC4-SHA > openssl s_client -connect dropbox.com:443 DHE-RSA-AES256-SHA
Again, this is usually done for speed, but all of the companies on the list are using "fast" SSL/TLS ciphers rather than more secure ones.
His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…
A target's phone call, e-mail or chat will take the cheapest path, not the physically most direct path - you can't always predict the path Dates When PRISM Collection Began For Each Provider This is complete conjecture, but this reads to me like the NSA set up its own backhauls and set up peering agreements at artifically low prices to get traffic going over their pipes. Is there historical data for route announcemen…
Acquire access to major routers, send routing commands, route target traffic into their hidden networks, and avoid physically wiretapping anything. And this framework can be done globally:
Your target's communications [...] flowing into and through the U.S. is as easy as announcing BGP route advertisements globally.
Actually the Great Firewall of China started investigated realtime and fine-grained control of national routing infrastructure as early as in 2003.[1] This allows them to apply routing policies to routers national-wide in seconds. One observable effect is that a single address can be null routed immediately after failure to get blocked by TCP resets. It is believed the HTTPS MITM of Github last time was also helped by this routing framework. And the GFW is viewed by the Chinese government as a national security framework. No wonder the USG is doing the same thing.
[1]: Liu, G., Yun, X., Fang, B., Hu, M. 2003. A control method for large-scale network based on routing diffusion. Journal of China Institute of Communications: 10.