So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…
NSA admits listening to U.S. phone calls without warrants
91–100 of 407 posts
Re: NSA admits listening to U.S. phone calls without warrants
#92Earlier quoted context omitted.
I believe so, yes.
I can't find a reference and until recently would have assumed it was unencrypted SMTP like the olden days. What gives you that belief, and if it's TLS-secured, would you assume it has the same forward-security as (eg) Chrome-to-Gmail? Or might it be something else, because it happens out of sight, that is a little behind-the-times?
† Where by "we" I mean "the guy who isn't me that found the app that gives you the SSL connection details for arbitrary SMTP addresses"
Re: NSA admits listening to U.S. phone calls without warrants
#93Earlier quoted context omitted.
> most of the people commenting on the NSA story on HN say things that make it clear that they believe NSA continues to have the direct access to Google's systems You're mincing words. Your comments clearly indicate that you think "direct access" unambiguously means "access to servers that run GMail that the NSA can snoop on any time they like." But from what I've seen, most comments on HN adopt and acknowledge a mor…
The process as I understand it: * NSA (or some other USG agency) issues a directive to the provider under authorization from FISA. No court order is required for NSA to issue directives under FISA. * If the provider is Google, Yahoo, or Facebook†, that directive is reviewed manually by the provider. * In at least the case of Yahoo, where this step is supported by court documents, but probably all the other cases too…
That doesn't change the fact that they're wrong.
Google couldn't possibly give the NSA "direct access" in the way you're defining it without creating a subsystem to service it--like, say, a secure staging server that requires being populated by processes which run and pull the data from disparate parts of their system, whose access would most easily be accesses via FTP. Anyone technologically literate who considers what "direct access" could mean deeper than a surface level should arrive at the obvious conclusion that "direct access" does not mean the Google equivalent of a MySQL console.
Re: NSA admits listening to U.S. phone calls without warrants
#94Earlier quoted context omitted.
Most SMTP does, but does most SMTP that originates or terminates at Google Mail? I don't think so. (Here it's worth noting that mail between Google Mail users doesn't ever hit the public Internet in plaintext SMTP). I do not think it's unfathomable that NSA has Google Mail's public key. I do think it's unfathomable that, having illicitly obtained that key, their possession of it wouldn't be one of the most closely gu…
Plaintext mail is only encrypted in transit when both endpoints are using encryption. Google cannot transmit secure messages to an insecure endpoint because the endpoint wouldn't know what to do with them. I think nobody knows what percentage of Gmail gets sent to foreign servers without encryption, similarly for received messages, but I am surprised by the claim that most SMTP is unencrypted.
Re: NSA admits listening to U.S. phone calls without warrants
#95Since the modus operandi seems to be for the NSA to suck up everything it can and decide later it seems (wild speculation follows) that the NSA might be sitting on audio recrodings of all your phone calls for the past several years. Can you imagine the number of divorce cases that would impact? Civil lawsuits? Proof of innocence or guilt in a crime? Hell, get a decade or two of this and historians alone would have a…
Re: NSA admits listening to U.S. phone calls without warrants
#96Earlier quoted context omitted.
How can you rule out: 1. Google is lying. 2. Prism (or the backend thereof) is genuinely unknown to most Google employees. Those few employees who do know of it are lying. The others (i.e. legal) are ignorant because they have no need to know, and because it provides plausible deniability. 3. There exist NSA agents capable of passing a Google interview and installing backdoors, perhaps with the collusion of other age…
Is it possible that through some elaborate conspiracy with specific unidentified Google employees unknown to Larry Page or Google's General Counsel that NSA has obtained access to the servers that operate Google Mail? Yes. Is it plausible that having gained that access, their use of it is so routine that it has an official name ("PRISM") and a logo and appears in slide decks targeted at NSA analysts and is used a pro…
Re: NSA admits listening to U.S. phone calls without warrants
#97I am confused by this particular piece of disclosure. Who is disclosing it? CNET or Rep. Darrel? If Rep. Darrel said it....y do they need comment? If he isn't disclosing it, how did CNET come by this statement? This is quite confusing.
This cleared it up for me: http://www.c-spanvideo.org/clip/4456141 * * - Originally posted by marshray. https://news.ycombinator.com/item?id=5886860
That is just.....why was this not picked up from before?
Re: NSA admits listening to U.S. phone calls without warrants
#98Earlier quoted context omitted.
First, most SMTP travels without encryption. Second, it's unfathomable to me to imagine the NSA isn't doing their damnedest to obtain all private keys. I have no idea how many they do have, but it seems foolish to assume they don't have a specific private key. Why do you think the NSA would regard private keys as some kind of sacred ground? For example, they could go after it the same way the Chinese do - phishing at…
Most SMTP does, but does most SMTP that originates or terminates at Google Mail? I don't think so. (Here it's worth noting that mail between Google Mail users doesn't ever hit the public Internet in plaintext SMTP). I do not think it's unfathomable that NSA has Google Mail's public key. I do think it's unfathomable that, having illicitly obtained that key, their possession of it wouldn't be one of the most closely gu…
The term "direct access" may have been fuzzy speak, and indicative of an "impedance mismatch" between what different concentric layers of the NSA knows. The author of the PRISM deck understood it to be "direct access" based on what he'd been told, and the low-lag operation he'd seen. But perhaps that was still be FISA-order based, just really fast: an analyst flags a name at their terminal. The name is forwarded the Google and the FISA court. Google does its "review" but knows a request of exactly this specific form always wins -- they don't get to challenge the reasons for the request, which they don't even see. Now it's 'reviewed', the SFTP dumps begin... but they aren't one-time, but perhaps daily... or even hourly or faster... to keep up with the target's ongoing mail activity. (They didn't go through the trouble of using one of their thousands of requests just to get old activity, did they?) To the PRISM deck authors, that still feels like "direct access" – and colloquially, it is.
But given compartmentalization within the NSA, what if some of the data is arriving via another, deeper capability? The PRISM deck author, the average analyst may just think it's from the other process. It's not their business to know more; the rows/records appear in their tool, and they get on with their work, happy for the bounty of info from other 'acquisition' programs which sometimes (often!) work in mysterious ways.
Re: NSA admits listening to U.S. phone calls without warrants
#99Earlier quoted context omitted.
> most of the people commenting on the NSA story on HN say things that make it clear that they believe NSA continues to have the direct access to Google's systems You're mincing words. Your comments clearly indicate that you think "direct access" unambiguously means "access to servers that run GMail that the NSA can snoop on any time they like." But from what I've seen, most comments on HN adopt and acknowledge a mor…
The process as I understand it: * NSA (or some other USG agency) issues a directive to the provider under authorization from FISA. No court order is required for NSA to issue directives under FISA. * If the provider is Google, Yahoo, or Facebook†, that directive is reviewed manually by the provider. * In at least the case of Yahoo, where this step is supported by court documents, but probably all the other cases too…
I'm actually curious how you rationalize this worldview given the bizarre news over the last few days that the Fed is insisting on burying NSA FISA requests among requests from every other law enforcement agency when reporting statistics?
Leaving aside the point that aggregated and anonymized information seems to pose absolutely zero security risk and should not be classified in the first place, there seems a fairly obvious reason for the move that contradicts at least one if not more of your assumptions above.
Re: NSA admits listening to U.S. phone calls without warrants
#100Earlier quoted context omitted.
This cleared it up for me: http://www.c-spanvideo.org/clip/4456141 * * - Originally posted by marshray. https://news.ycombinator.com/item?id=5886860
Wow....thanks for this. That is just.....why was this not picked up from before?