Live data from Hacker News

NSA admits listening to U.S. phone calls without warrants

news.cnet.com

111–120 of 407 posts

Re: NSA admits listening to U.S. phone calls without warrants

#111
post #104

Earlier quoted context omitted.

> If you're telling me that this is the understanding most HN people have about what "direct access" means, I'd direct your attention to this very thread to rebut that argument. I'm not at all saying that. I'm saying that most HN folks do not share your definition of what "direct access" means. I specifically said that it seems like most people are quite aware of the ambiguity of the meaning of "direct access" in a c…

Bullcrap. When people saw "direct access", they concluded direct access - as was reasonable, at the time, from what the leak seemed to show; I did the same. Many of the people on this site have since realized that that is not true (although there were sure a lot of crazy theories about the specific wording of the initial denials), but most of those people are no longer saying "direct access", and there are people sti…

> there are people still saying "direct access".

Undeniably. What tptacek thinks though is that those people are "most" people on HN.

burntsushi thinks this is plainly false, and I agree with him. I think tptacek is seeing whatever it takes to stroke his ego.

Re: NSA admits listening to U.S. phone calls without warrants

#112
post #65
post #58

Earlier quoted context omitted.

I believe so, yes.

I can't find a reference and until recently would have assumed it was unencrypted SMTP like the olden days. What gives you that belief, and if it's TLS-secured, would you assume it has the same forward-security as (eg) Chrome-to-Gmail? Or might it be something else, because it happens out of sight, that is a little behind-the-times?

Here is a data point; take it for what it's worth.

I run my own email service (Postfix) on 4 different domains. TLS is properly configured on all of my mailhosts, using certificates issued by StartCom. My servers routinely receive mail from Google, Apple, Yahoo, GNU, and other major email providers. Most of the messages are from various mailing lists.

I occasionally peruse the mail logs, and in the last 3 years, at least, I have never seen an unencrypted SMTP connection. I'm not saying it never happens, I've just never seen it. The most common protocol is TLSv1 with a variant of AES (nearly always 256-bit). Apple's listservs use TLSv1 with 128-bit RC4-MD5, but they're the exception.

Re: NSA admits listening to U.S. phone calls without warrants

#113
post #66

Earlier quoted context omitted.

> most of the people commenting on the NSA story on HN say things that make it clear that they believe NSA continues to have the direct access to Google's systems You're mincing words. Your comments clearly indicate that you think "direct access" unambiguously means "access to servers that run GMail that the NSA can snoop on any time they like." But from what I've seen, most comments on HN adopt and acknowledge a mor…

The process as I understand it: * NSA (or some other USG agency) issues a directive to the provider under authorization from FISA. No court order is required for NSA to issue directives under FISA. * If the provider is Google, Yahoo, or Facebook†, that directive is reviewed manually by the provider. * In at least the case of Yahoo, where this step is supported by court documents, but probably all the other cases too…

I think that's an excellent summary, but also: that SFTP-like access almost certainly keeps happening, for that targeted account, after the initial request. Perhaps it happens hourly, or even faster when relevant account events (login, message-received, message-sent, voip-call) occur.

For most of the world -- those who have never SSH'd into a machine, nor had machine 'root' access -- that rapid-batch-dump access still would be fairly described as "direct access". Word meanings vary based on context and the expertise of the discussion participant; the slide deck and the journalistic reports were all written at the level of fuzzy understanding, not technical precision. Practitioner nitpicks about the implementation details don't refute them.

Re: NSA admits listening to U.S. phone calls without warrants

#114
post #107
post #72

Earlier quoted context omitted.

Where by illicit I mean "is occurring without the knowledge of Google's CEO or General Counsel, despite their publicly voiced opposition to any such program."

I'm not sure. It could be that they know about it and are gag-ordered (can't fight city hall!), or that they were intentionally left out of the loop for purposes of plausible deniability. This is military intelligence we're talking about here, they take their mission very, very seriously. I wouldn't be surprised if there were multiple, independent, redundant programs for monitoring this data.

As 'DannyBee, himself a lawyer, pointed out a few days ago: no provision of any Federal law requires anyone to issue false statements. There are times you're prevented from saying things†, but there aren't times when NSA gets to put words in your mouth.

... we think; the ultimate Constitutionality of this is up in the air.

Re: NSA admits listening to U.S. phone calls without warrants

#115

Earlier quoted context omitted.

Still arguing with the NSA over their own capabilities? I'm actually curious how you rationalize this worldview given the bizarre news over the last few days that the Fed is insisting on burying NSA FISA requests among requests from every other law enforcement agency when reporting statistics? Leaving aside the point that aggregated and anonymized information seems to pose absolutely zero security risk and should not…

See what I mean? This is the kind of comment that makes me think most HN people commenting on NSA think NSA has direct, unilateral access to Google Mail's servers --- as The Guardian (incorrectly) reported.

I don't see how you can possibly jump to that conclusion. But if you don't want to analyze the question from the position of the NSA (as you should be doing), then you are welcome to personalize it. So reiterating the question, which of your assumptions listed above do you think I suspect are wrong based on the kerfuffle over statistics reporting?

Put another way, why on earth does NSA seem to care so much about aggregating its FISA requests with other law enforcement agencies when reporting statistics to the public?

Re: NSA admits listening to U.S. phone calls without warrants

#116

Earlier quoted context omitted.

See what I mean? This is the kind of comment that makes me think most HN people commenting on NSA think NSA has direct, unilateral access to Google Mail's servers --- as The Guardian (incorrectly) reported.

I don't see how you can possibly jump to that conclusion. But if you don't want to analyze the question from the position of the NSA (as you should be doing), then you are welcome to personalize it. So reiterating the question, which of your assumptions listed above do you think I suspect are wrong based on the kerfuffle over statistics reporting? Put another way, why on earth does NSA seem to care so much about aggr…

I'm having a hard time parsing your question but can I ask a different one: do you disagree with any of the bulleted points in my comment above? I don't want to waste a lot of time petulantly agreeing with each other.

Re: NSA admits listening to U.S. phone calls without warrants

#117
post #62

Earlier quoted context omitted.

So what? The NSA is harvesting data on an unprecedented scale. It might be legal but it is definitly unethical. Whether the initial reports were 100% accurate or not is irrelevant. What does matter is that this now out in the open and hopefully something changes.

The ethics of data collection in the age of people sharing all sorts of information with Google, Facebook, etc, are not a clear cut thing. Moreover, it's not meaningless whether its illegal or not. Indeed, it makes all the difference in the world. Laws can be changed if we don't like their outcomes--a government that's ignoring the law is something else entirely.

> The ethics of data collection in the age of people sharing all sorts of information with Google, Facebook, etc, are not a clear cut thing.

It is a peculiar brand of corporatism that thinks the privileges afforded to corporations should somehow be considered when talking about the privileges given to governments. Quite the opposite of what one normally sees, but still curiously the same.

Re: NSA admits listening to U.S. phone calls without warrants

#118
post #113
post #66

Earlier quoted context omitted.

The process as I understand it: * NSA (or some other USG agency) issues a directive to the provider under authorization from FISA. No court order is required for NSA to issue directives under FISA. * If the provider is Google, Yahoo, or Facebook†, that directive is reviewed manually by the provider. * In at least the case of Yahoo, where this step is supported by court documents, but probably all the other cases too…

I think that's an excellent summary, but also: that SFTP-like access almost certainly keeps happening, for that targeted account, after the initial request. Perhaps it happens hourly, or even faster when relevant account events (login, message-received, message-sent, voip-call) occur. For most of the world -- those who have never SSH'd into a machine, nor had machine 'root' access -- that rapid-batch-dump access stil…

The Guardian went out of its way to characterize the access not only as "direct" but "unilateral".

Re: NSA admits listening to U.S. phone calls without warrants

#119

Since the modus operandi seems to be for the NSA to suck up everything it can and decide later it seems (wild speculation follows) that the NSA might be sitting on audio recrodings of all your phone calls for the past several years. Can you imagine the number of divorce cases that would impact? Civil lawsuits? Proof of innocence or guilt in a crime? Hell, get a decade or two of this and historians alone would have a…

If they were obtained without a warrant, wouldn't they be inadmissible as evidence, especially if they were being used in an inculpatory rather than exculpatory manner?

Unless I'm mistaken (IANAL), they can still be used as exculpatory evidence.

Re: NSA admits listening to U.S. phone calls without warrants

#120
post #75

Earlier quoted context omitted.

Is it possible that through some elaborate conspiracy with specific unidentified Google employees unknown to Larry Page or Google's General Counsel that NSA has obtained access to the servers that operate Google Mail? Yes. Is it plausible that having gained that access, their use of it is so routine that it has an official name ("PRISM") and a logo and appears in slide decks targeted at NSA analysts and is used a pro…

Note that I am not taking sides in this argument in this particular reply, but the PRISM referred to in the leaked manuals appears to be an entirely separate program, for managing responses to emergency events.

I understood there to be references to both; to other DOD programs called "PRISM", and to programs called "PRISM" that probably are the NSA program. Other DoD agencies are clients of NSA.
Post reply on HN