Live data from Hacker News

NSA admits listening to U.S. phone calls without warrants

news.cnet.com

121–130 of 407 posts

Re: NSA admits listening to U.S. phone calls without warrants

#121
post #92
post #65

Earlier quoted context omitted.

I can't find a reference and until recently would have assumed it was unencrypted SMTP like the olden days. What gives you that belief, and if it's TLS-secured, would you assume it has the same forward-security as (eg) Chrome-to-Gmail? Or might it be something else, because it happens out of sight, that is a little behind-the-times?

We've† already verified this downthread; I'm wrong about Yahoo (they do TLS for their retail SMTP servers but not for MX's), but Google does indeed do TLS on their servers. † Where by "we" I mean "the guy who isn't me that found the app that gives you the SSL connection details for arbitrary SMTP addresses"

Thanks, so it seems likely that Gmail->Yahoo email is in plaintext.

That Google will "do TLS" is ambiguous. Are we sure Yahoo attempts TLS on their SMTP-connect to Google's MX? It seems unlikely if they don't support it on their own receives, and also unlikely that Gmail would reject all non-TLS SMTP.

If so, NSA wouldn't need Google or Yahoo's private key to record the plaintext of all email between them. And if the GoogleYahoo interchange is representative, plenty of other email to or from Gmail will be similarly transparent.

Re: NSA admits listening to U.S. phone calls without warrants

#122
post #94

Earlier quoted context omitted.

Plaintext mail is only encrypted in transit when both endpoints are using encryption. Google cannot transmit secure messages to an insecure endpoint because the endpoint wouldn't know what to do with them. I think nobody knows what percentage of Gmail gets sent to foreign servers without encryption, similarly for received messages, but I am surprised by the claim that most SMTP is unencrypted.

We agree that there is no magic that makes TLS work for SMTP servers that don't support TLS.

So is your logic basically that even if most SMTP is unencrypted, that doesn't affect most Gmail because most Gmail is sent between Gmail accounts? If that isn't your logic, and we discount internal mail, I cannot understand how the majority of mail originating or terminating at Google would be encrypted, provided the claim that most SMTP is unencrypted is also true. Further pedantry, SSL can be used instead of TLS.

Re: NSA admits listening to U.S. phone calls without warrants

#123
post #112
post #65

Earlier quoted context omitted.

I can't find a reference and until recently would have assumed it was unencrypted SMTP like the olden days. What gives you that belief, and if it's TLS-secured, would you assume it has the same forward-security as (eg) Chrome-to-Gmail? Or might it be something else, because it happens out of sight, that is a little behind-the-times?

Here is a data point; take it for what it's worth. I run my own email service (Postfix) on 4 different domains. TLS is properly configured on all of my mailhosts, using certificates issued by StartCom. My servers routinely receive mail from Google, Apple, Yahoo, GNU, and other major email providers. Most of the messages are from various mailing lists. I occasionally peruse the mail logs, and in the last 3 years, at l…

You're seeing Yahoo inbounds with TLS enabled? Because the service posted downthread seems to show that Yahoo won't accept inbound mail with TLS.

Re: NSA admits listening to U.S. phone calls without warrants

#124
post #98
post #53

Earlier quoted context omitted.

Most SMTP does, but does most SMTP that originates or terminates at Google Mail? I don't think so. (Here it's worth noting that mail between Google Mail users doesn't ever hit the public Internet in plaintext SMTP). I do not think it's unfathomable that NSA has Google Mail's public key. I do think it's unfathomable that, having illicitly obtained that key, their possession of it wouldn't be one of the most closely gu…

Thank you for acknowledging that it is fathomable that NSA has Google Mail's keymatter, and that if they do, it would be one of the most closely guarded secrets in the agency, something they would burn other programs, and make other cover stories, to obscure. The term "direct access" may have been fuzzy speak, and indicative of an "impedance mismatch" between what different concentric layers of the NSA knows. The aut…

Since there's already a program (Ambinder reported on it) called PRISM that pertains to dropboxes used to handle data from FISA requests, Occam's Razor tells me that it's more likely that the slide deck author was referring to direct access to these dropboxes than it is that NSA would somehow have allowed it to become common knowledge within NSA that they had a capability to unilaterally take data from Google Mail.

Re: NSA admits listening to U.S. phone calls without warrants

#125
post #121
post #92

Earlier quoted context omitted.

We've† already verified this downthread; I'm wrong about Yahoo (they do TLS for their retail SMTP servers but not for MX's), but Google does indeed do TLS on their servers. † Where by "we" I mean "the guy who isn't me that found the app that gives you the SSL connection details for arbitrary SMTP addresses"

Thanks, so it seems likely that Gmail->Yahoo email is in plaintext. That Google will "do TLS" is ambiguous. Are we sure Yahoo attempts TLS on their SMTP-connect to Google's MX? It seems unlikely if they don't support it on their own receives, and also unlikely that Gmail would reject all non-TLS SMTP. If so, NSA wouldn't need Google or Yahoo's private key to record the plaintext of all email between them. And if the…

From the 'dhess comment downthread it looks like it's possible that Yahoo does TLS outbound but not inbound. Google, it seems, does both.

Re: NSA admits listening to U.S. phone calls without warrants

#126
post #113

Earlier quoted context omitted.

I think that's an excellent summary, but also: that SFTP-like access almost certainly keeps happening, for that targeted account, after the initial request. Perhaps it happens hourly, or even faster when relevant account events (login, message-received, message-sent, voip-call) occur. For most of the world -- those who have never SSH'd into a machine, nor had machine 'root' access -- that rapid-batch-dump access stil…

The Guardian went out of its way to characterize the access not only as "direct" but "unilateral".

I'd need to see the context to know if the Guardian was wrong where they used that exact word, or were simply describing something that exists with some companies or at another level of tapping.

Re: NSA admits listening to U.S. phone calls without warrants

#127
post #36

Earlier quoted context omitted.

"and the Guardian walked the claim back" No they didn't. "The Guardian has not revised any of our articles and, to my knowledge, has no intention to do so. That's because we did not claim that the NSA document alleging direct collection from the servers was true; we reported - accurately - that the NSA document claims that the program allows direct collection from the companies' servers. Before publishing, we went to…

I'm not interested in the semantic argument. Emily Bazelon called The Guardian out this week on the Slate political podcast, as have many others; this is now a mainstream criticism of how The Guardian reported the story. Either way: the original notion that NSA had direct access to the servers that actually operate Google Mail has been found to be unsupported by the evidence published thus far. I call this out contin…

I think you are making some poor semantic arguments yourself.

The simple case is that of the NSA document ("collection directly from the servers of these US service providers") against google ("The U.S. government does not have direct access or a “back door” to the information stored in our data centers"). These are two competing claims, neither of which have been supported by evidence and hence the burden of proof rests equally with both cases.

Anything else (By the Guardian, Slate, the 'mainstream view on HN' or yourself) is purely speculative.

You seem to place the burden of proof on one claim over another and hold a very specific view on what 'direct access' means.

You also seem to hold a strange interpretation of the Guardian's reporting, but I won't get into that as its largely immaterial to the real subject.

Re: NSA admits listening to U.S. phone calls without warrants

#128
post #94

Earlier quoted context omitted.

We agree that there is no magic that makes TLS work for SMTP servers that don't support TLS.

So is your logic basically that even if most SMTP is unencrypted, that doesn't affect most Gmail because most Gmail is sent between Gmail accounts? If that isn't your logic, and we discount internal mail, I cannot understand how the majority of mail originating or terminating at Google would be encrypted, provided the claim that most SMTP is unencrypted is also true. Further pedantry, SSL can be used instead of TLS.

SMTP between Google Mail and any server that supports TLS SMTP is encrypted. We seem to have identified one case --- inbound SMTP to a Yahoo MX --- where that TLS connection does't happen.

SSL and TLS are for the purposes of this discussion the same thing; the distinction between the two is actually less important in SMTP than it is with HTTP.

Re: NSA admits listening to U.S. phone calls without warrants

#129

Earlier quoted context omitted.

I don't see how you can possibly jump to that conclusion. But if you don't want to analyze the question from the position of the NSA (as you should be doing), then you are welcome to personalize it. So reiterating the question, which of your assumptions listed above do you think I suspect are wrong based on the kerfuffle over statistics reporting? Put another way, why on earth does NSA seem to care so much about aggr…

I'm having a hard time parsing your question but can I ask a different one: do you disagree with any of the bulleted points in my comment above? I don't want to waste a lot of time petulantly agreeing with each other.

Yes. My suspicion is that your first two assumptions are incorrect, and that (1) FISA requests are not personalized under PRISM, and that consequently (2) there is no manual review or check against the abuse of power by providers on an ongoing basis.

This is the only reasonable explanation I can think of for why the NSA would be trying to hide its request volume in the larger volume of overall requests from law enforcement: an attempt to massage the average user-accounts-compromised-per-request downwards when reported to the public. If there are any other explanations you can think of for why it matters how the aggregate statistics are reported, I would be curious to hear of them.

And obviously, abuse of the FISA process renders splitting hairs about what constitutes direct/indirect access meaningless. FISA abuse plus an automated dropbox provides exactly the sort of data access that Snowden and the NSA repeatedly insist they have, while reconciling Google's claims with those of the NSA.

Re: NSA admits listening to U.S. phone calls without warrants

#130
post #36

Earlier quoted context omitted.

I'm not interested in the semantic argument. Emily Bazelon called The Guardian out this week on the Slate political podcast, as have many others; this is now a mainstream criticism of how The Guardian reported the story. Either way: the original notion that NSA had direct access to the servers that actually operate Google Mail has been found to be unsupported by the evidence published thus far. I call this out contin…

I think you are making some poor semantic arguments yourself. The simple case is that of the NSA document ("collection directly from the servers of these US service providers") against google ("The U.S. government does not have direct access or a “back door” to the information stored in our data centers"). These are two competing claims, neither of which have been supported by evidence and hence the burden of proof r…

For those keeping score, this is another of the kind of comment that lead me to believe that most HN commenters take the obvious interpretation of "direct access".
Post reply on HN