Live data from Hacker News

NSA admits listening to U.S. phone calls without warrants

news.cnet.com

91–100 of 407 posts

Re: NSA admits listening to U.S. phone calls without warrants

#91
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

[deleted]

Re: NSA admits listening to U.S. phone calls without warrants

#92
post #65
post #58

Earlier quoted context omitted.

I believe so, yes.

I can't find a reference and until recently would have assumed it was unencrypted SMTP like the olden days. What gives you that belief, and if it's TLS-secured, would you assume it has the same forward-security as (eg) Chrome-to-Gmail? Or might it be something else, because it happens out of sight, that is a little behind-the-times?

We've† already verified this downthread; I'm wrong about Yahoo (they do TLS for their retail SMTP servers but not for MX's), but Google does indeed do TLS on their servers.

Where by "we" I mean "the guy who isn't me that found the app that gives you the SSL connection details for arbitrary SMTP addresses"

Re: NSA admits listening to U.S. phone calls without warrants

#93
post #66

Earlier quoted context omitted.

> most of the people commenting on the NSA story on HN say things that make it clear that they believe NSA continues to have the direct access to Google's systems You're mincing words. Your comments clearly indicate that you think "direct access" unambiguously means "access to servers that run GMail that the NSA can snoop on any time they like." But from what I've seen, most comments on HN adopt and acknowledge a mor…

The process as I understand it: * NSA (or some other USG agency) issues a directive to the provider under authorization from FISA. No court order is required for NSA to issue directives under FISA. * If the provider is Google, Yahoo, or Facebook†, that directive is reviewed manually by the provider. * In at least the case of Yahoo, where this step is supported by court documents, but probably all the other cases too…

It's possible, I suppose, that most HN people think that Google has, somehow, given the NSA a way to access their Bigtable database directly and query it--thereby entrusting the information on the structure of their database, and subsequently their billions of dollars, to NSA analysts making a few tens of thousands of dollars a year--ignoring entirely the ridiculous notion that such access is even physically possible or enabled.

That doesn't change the fact that they're wrong.

Google couldn't possibly give the NSA "direct access" in the way you're defining it without creating a subsystem to service it--like, say, a secure staging server that requires being populated by processes which run and pull the data from disparate parts of their system, whose access would most easily be accesses via FTP. Anyone technologically literate who considers what "direct access" could mean deeper than a surface level should arrive at the obvious conclusion that "direct access" does not mean the Google equivalent of a MySQL console.

Re: NSA admits listening to U.S. phone calls without warrants

#94
post #53

Earlier quoted context omitted.

Most SMTP does, but does most SMTP that originates or terminates at Google Mail? I don't think so. (Here it's worth noting that mail between Google Mail users doesn't ever hit the public Internet in plaintext SMTP). I do not think it's unfathomable that NSA has Google Mail's public key. I do think it's unfathomable that, having illicitly obtained that key, their possession of it wouldn't be one of the most closely gu…

Plaintext mail is only encrypted in transit when both endpoints are using encryption. Google cannot transmit secure messages to an insecure endpoint because the endpoint wouldn't know what to do with them. I think nobody knows what percentage of Gmail gets sent to foreign servers without encryption, similarly for received messages, but I am surprised by the claim that most SMTP is unencrypted.

We agree that there is no magic that makes TLS work for SMTP servers that don't support TLS.

Re: NSA admits listening to U.S. phone calls without warrants

#95

Since the modus operandi seems to be for the NSA to suck up everything it can and decide later it seems (wild speculation follows) that the NSA might be sitting on audio recrodings of all your phone calls for the past several years. Can you imagine the number of divorce cases that would impact? Civil lawsuits? Proof of innocence or guilt in a crime? Hell, get a decade or two of this and historians alone would have a…

Part of the book 1984 was the complacence of the lower class. I am not targeting any class here but pointing out that a culture of complacency by division was a large warning in that book that is often overlooked.

Re: NSA admits listening to U.S. phone calls without warrants

#96
post #75

Earlier quoted context omitted.

How can you rule out: 1. Google is lying. 2. Prism (or the backend thereof) is genuinely unknown to most Google employees. Those few employees who do know of it are lying. The others (i.e. legal) are ignorant because they have no need to know, and because it provides plausible deniability. 3. There exist NSA agents capable of passing a Google interview and installing backdoors, perhaps with the collusion of other age…

Is it possible that through some elaborate conspiracy with specific unidentified Google employees unknown to Larry Page or Google's General Counsel that NSA has obtained access to the servers that operate Google Mail? Yes. Is it plausible that having gained that access, their use of it is so routine that it has an official name ("PRISM") and a logo and appears in slide decks targeted at NSA analysts and is used a pro…

Note that I am not taking sides in this argument in this particular reply, but the PRISM referred to in the leaked manuals appears to be an entirely separate program, for managing responses to emergency events.

Re: NSA admits listening to U.S. phone calls without warrants

#97

I am confused by this particular piece of disclosure. Who is disclosing it? CNET or Rep. Darrel? If Rep. Darrel said it....y do they need comment? If he isn't disclosing it, how did CNET come by this statement? This is quite confusing.

This cleared it up for me: http://www.c-spanvideo.org/clip/4456141 * * - Originally posted by marshray. https://news.ycombinator.com/item?id=5886860

Wow....thanks for this.

That is just.....why was this not picked up from before?

Re: NSA admits listening to U.S. phone calls without warrants

#98
post #53

Earlier quoted context omitted.

First, most SMTP travels without encryption. Second, it's unfathomable to me to imagine the NSA isn't doing their damnedest to obtain all private keys. I have no idea how many they do have, but it seems foolish to assume they don't have a specific private key. Why do you think the NSA would regard private keys as some kind of sacred ground? For example, they could go after it the same way the Chinese do - phishing at…

Most SMTP does, but does most SMTP that originates or terminates at Google Mail? I don't think so. (Here it's worth noting that mail between Google Mail users doesn't ever hit the public Internet in plaintext SMTP). I do not think it's unfathomable that NSA has Google Mail's public key. I do think it's unfathomable that, having illicitly obtained that key, their possession of it wouldn't be one of the most closely gu…

Thank you for acknowledging that it is fathomable that NSA has Google Mail's keymatter, and that if they do, it would be one of the most closely guarded secrets in the agency, something they would burn other programs, and make other cover stories, to obscure.

The term "direct access" may have been fuzzy speak, and indicative of an "impedance mismatch" between what different concentric layers of the NSA knows. The author of the PRISM deck understood it to be "direct access" based on what he'd been told, and the low-lag operation he'd seen. But perhaps that was still be FISA-order based, just really fast: an analyst flags a name at their terminal. The name is forwarded the Google and the FISA court. Google does its "review" but knows a request of exactly this specific form always wins -- they don't get to challenge the reasons for the request, which they don't even see. Now it's 'reviewed', the SFTP dumps begin... but they aren't one-time, but perhaps daily... or even hourly or faster... to keep up with the target's ongoing mail activity. (They didn't go through the trouble of using one of their thousands of requests just to get old activity, did they?) To the PRISM deck authors, that still feels like "direct access" – and colloquially, it is.

But given compartmentalization within the NSA, what if some of the data is arriving via another, deeper capability? The PRISM deck author, the average analyst may just think it's from the other process. It's not their business to know more; the rows/records appear in their tool, and they get on with their work, happy for the bounty of info from other 'acquisition' programs which sometimes (often!) work in mysterious ways.

Re: NSA admits listening to U.S. phone calls without warrants

#99
post #66

Earlier quoted context omitted.

> most of the people commenting on the NSA story on HN say things that make it clear that they believe NSA continues to have the direct access to Google's systems You're mincing words. Your comments clearly indicate that you think "direct access" unambiguously means "access to servers that run GMail that the NSA can snoop on any time they like." But from what I've seen, most comments on HN adopt and acknowledge a mor…

The process as I understand it: * NSA (or some other USG agency) issues a directive to the provider under authorization from FISA. No court order is required for NSA to issue directives under FISA. * If the provider is Google, Yahoo, or Facebook†, that directive is reviewed manually by the provider. * In at least the case of Yahoo, where this step is supported by court documents, but probably all the other cases too…

Still arguing with the NSA over their own capabilities?

I'm actually curious how you rationalize this worldview given the bizarre news over the last few days that the Fed is insisting on burying NSA FISA requests among requests from every other law enforcement agency when reporting statistics?

Leaving aside the point that aggregated and anonymized information seems to pose absolutely zero security risk and should not be classified in the first place, there seems a fairly obvious reason for the move that contradicts at least one if not more of your assumptions above.

Re: NSA admits listening to U.S. phone calls without warrants

#100

Earlier quoted context omitted.

This cleared it up for me: http://www.c-spanvideo.org/clip/4456141 * * - Originally posted by marshray. https://news.ycombinator.com/item?id=5886860

Wow....thanks for this. That is just.....why was this not picked up from before?

Exactly what I was thinking. Not sure.
Post reply on HN