Live data from Hacker News

NSA admits listening to U.S. phone calls without warrants

news.cnet.com

71–80 of 407 posts

Re: NSA admits listening to U.S. phone calls without warrants

#71
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

Am I missing something? The telcos control many of the internet backbones, and Email isn't encrypted. If the telcos give you unrestricted access, it seems trivial to harvest the contents of email.

FWIR, Google enforcing HTTPS connections to gmail is pretty recent as well: since firesheep, so that's another vector for someone who can read data from the wires.

Re: NSA admits listening to U.S. phone calls without warrants

#72
post #57
post #42

Earlier quoted context omitted.

I don't have to build a straw man. I'd just say people should read your comment, work out its narrative in their heads, and ask which is more likely: that PRISM is an elaborate scheme by which NSA gained illicit access to Google's servers, or that it is what other reporters have now reported that it is: a unified collection system for documents manually provided by Internet companies in response to FISA directives. P…

I never claimed it was illicit. I just said it was secret, and that disclosure of such secrets carries an incredibly harsh penalty. You're doing the strawman thing again, despite claiming otherwise. :/ Just because they've pushed back doesn't mean the system isn't automated. It could have been a matter of "implement the automated system now, per the FISA order, and then we can have a go-round in front of the FISA cou…

Where by illicit I mean "is occurring without the knowledge of Google's CEO or General Counsel, despite their publicly voiced opposition to any such program."

Re: NSA admits listening to U.S. phone calls without warrants

#73
post #36

Earlier quoted context omitted.

"and the Guardian walked the claim back" No they didn't. "The Guardian has not revised any of our articles and, to my knowledge, has no intention to do so. That's because we did not claim that the NSA document alleging direct collection from the servers was true; we reported - accurately - that the NSA document claims that the program allows direct collection from the companies' servers. Before publishing, we went to…

I'm not interested in the semantic argument. Emily Bazelon called The Guardian out this week on the Slate political podcast, as have many others; this is now a mainstream criticism of how The Guardian reported the story. Either way: the original notion that NSA had direct access to the servers that actually operate Google Mail has been found to be unsupported by the evidence published thus far. I call this out contin…

If I'm on helm of NSA, I would recruit spys on important positions so that the agency can have access to any data on minutes notice. Of course, in accordance to the law. And I believe it is legal for NSA to recruit somebody in a company to spy / give NSA access to the data.

My point is that it is irrelevant whether it is true or not that NSA has capability to access to all our emails. The key is whether our legal framework allows that or not. My understanding is that NSA can collect all the data it needs (emails, phone calls, etc.) and they will not break the law - even without FISA court order. So maybe the law needs to be changed...

Re: NSA admits listening to U.S. phone calls without warrants

#75
post #26

Earlier quoted context omitted.

You think it's possible that NSA got direct access to Google's servers in a way that was invisible to Google's CEO, it's general counsel, its Chief Architect, Justin Schuh of their security team, and any of their thousands of employees, most of whom would immediately report such a thing if they discovered it? Moreover, having obtained this illicit access, in direct defiance of the corporation that owns and controls t…

How can you rule out: 1. Google is lying. 2. Prism (or the backend thereof) is genuinely unknown to most Google employees. Those few employees who do know of it are lying. The others (i.e. legal) are ignorant because they have no need to know, and because it provides plausible deniability. 3. There exist NSA agents capable of passing a Google interview and installing backdoors, perhaps with the collusion of other age…

Is it possible that through some elaborate conspiracy with specific unidentified Google employees unknown to Larry Page or Google's General Counsel that NSA has obtained access to the servers that operate Google Mail? Yes.

Is it plausible that having gained that access, their use of it is so routine that it has an official name ("PRISM") and a logo and appears in slide decks targeted at NSA analysts and is used a program whose existence is known outside NSA (there are DOD manuals that refer to the same PRISM program)? No. That is not plausible.

Re: NSA admits listening to U.S. phone calls without warrants

#76
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

They can get all unencrypted SMTP messages which means they can get all messages between gmail and outside mail servers. They would only be missing internal gmail to gmail messages.

Re: NSA admits listening to U.S. phone calls without warrants

#77
Since the modus operandi seems to be for the NSA to suck up everything it can and decide later it seems (wild speculation follows) that the NSA might be sitting on audio recrodings of all your phone calls for the past several years.

Can you imagine the number of divorce cases that would impact? Civil lawsuits? Proof of innocence or guilt in a crime?

Hell, get a decade or two of this and historians alone would have a field day with such material.

Oh, and by the way, it's completely fucked.

Back in the day, the FBI recorded folks that they suspected were subversives and it caused a huge stink. People were rightly outraged. It was considered a blemish on the FBI. Now we do the same thing -- only with everybody. And still 45% or so of the population hasn't figured out what the problem is. Amazing.

Re: NSA admits listening to U.S. phone calls without warrants

#78
post #71
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

Am I missing something? The telcos control many of the internet backbones, and Email isn't encrypted. If the telcos give you unrestricted access, it seems trivial to harvest the contents of email. FWIR, Google enforcing HTTPS connections to gmail is pretty recent as well: since firesheep, so that's another vector for someone who can read data from the wires.

Email is encrypted, far more often than you think it is. If you send email to someone else at Google Mail via Google Mail, your message is never on the Internet except in a retail-level TLS connection to Google Mail. If you send email via Google Mail to someone at some other email provider and that provider does SMTP+TLS, it's also never on the Internet in plaintext.

Re: NSA admits listening to U.S. phone calls without warrants

#79
post #39
post #21

Earlier quoted context omitted.

A copy of Google's private keys would be a more outrageous and damning discovery than NSA somehow having direct access to Google's servers. NSA doesn't have Google's private key.

You keep confidently asserting that, but many of the exact same compartmentalization and security procedures which protect the private keymatter also make a secret private key disclosure easier to keep hidden. How would we know otherwise? As you note, that "would be a more outrageous and damning discovery" - so there's more incentive to keep it closely held. It would help the NSA do what it feels it must, simply by u…

TLS client authentication allows the server to detect when an active MITM attempts to get into the connection[1]. This means that if you hold the theory that the NSA is acting as a MITM with Google's private keys, you also have to assume that they know they'll be detected the second anyone tries to use a client certificate to connect.

[1] http://security.stackexchange.com/questions/26142/do-client-...

Re: NSA admits listening to U.S. phone calls without warrants

#80
post #66

Earlier quoted context omitted.

> most of the people commenting on the NSA story on HN say things that make it clear that they believe NSA continues to have the direct access to Google's systems You're mincing words. Your comments clearly indicate that you think "direct access" unambiguously means "access to servers that run GMail that the NSA can snoop on any time they like." But from what I've seen, most comments on HN adopt and acknowledge a mor…

The process as I understand it: * NSA (or some other USG agency) issues a directive to the provider under authorization from FISA. No court order is required for NSA to issue directives under FISA. * If the provider is Google, Yahoo, or Facebook†, that directive is reviewed manually by the provider. * In at least the case of Yahoo, where this step is supported by court documents, but probably all the other cases too…

> If you're telling me that this is the understanding most HN people have about what "direct access" means, I'd direct your attention to this very thread to rebut that argument.

I'm not at all saying that. I'm saying that most HN folks do not share your definition of what "direct access" means. I specifically said that it seems like most people are quite aware of the ambiguity of the meaning of "direct access" in a couple slides and that we can only guess at what it precisely means.

Your comment clearly indicates otherwise:

    Either way: the original notion that NSA had direct access to the servers that 
    actually operate Google Mail has been found to be unsupported by the evidence 
    published thus far.
    
    I call this out continuously and obnoxiously on HN because it is very much not 
    the mainstream view on HN
Which seems like you're implying that most here believe literally in some direct tap on a provider's servers. But that isn't my experience.
Post reply on HN