Live data from Hacker News

NSA admits listening to U.S. phone calls without warrants

news.cnet.com

161–170 of 407 posts

Re: NSA admits listening to U.S. phone calls without warrants

#161
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

It's true, email is mostly transmitted over TLS.

But I'd be very reluctant to conclude that the NSA doesn't have clear-text for the vast majority of email that gets sent.

Google and other email providers have denied giving the NSA access to their servers, but if you think about it, that would be a lousy way to share data with the NSA, from a purely technical point of view. A company like Google is going to be constantly evolving their infrastructure. Giving the NSA direct access to the servers hampers that, because they'd have to break compatibility with whatever client software the NSA is using. It'd be easier to just send copies of all email that moves in and out of their system to the NSA and let them sort out how to process it. That would be more convenient for the NSA too.

Beyond that, all the denials issued by Google, Facebook et al mention that they do provide the government with information as required by law. We know that there are secret laws at work here, and if the law requires companies hand over everything, then that's what they're doing. The may even be required to lie about it. They're definitely absolved of any legal liability for doing so. I don't doubt that internet companies try to protect their user' privacy as much as they can, but that may amount to "not at all" where the U.S government is concerned.

Re: NSA admits listening to U.S. phone calls without warrants

#162
post #48
post #30

Earlier quoted context omitted.

You're saying that despite the fact that everyone who hits Google Mail with Chrome uses a ciphersuite for which Google's private RSA key only works if you actively man-in-the-middle the connection , no matter how many hard drives you have in Utah, that NSA stole Google's private key, and then (I repeat:) documented that fact in a slide deck for NSA analysts? You could more easily and credibly argue that NSA has solve…

I think you may be forgetting that it's not all-or-nothing. Not everyone uses Chrome. I can't speak to a slide deck; We've only seen some slides for one program (PRISM). I am quite sure that NSA has several different programs variously encompassing collection and decryption. Hopefully in the next few days or weeks we'll see details about more of them. I don't think it's beyond the realm of possibility for a nation-st…

Then we should definitely consider DDG, a much smaller company in the same country, sharing its keys with NSA. They too might be under some gag order that not only stops them from saying that they are compromised but also gagged to say that their users are anonymous so that all the terrorists, law breakers and cheating husbands use this service because of a false sense of security. It is not beyond the realm of possibility.

But everything that is plausible is not probable.

Re: NSA admits listening to U.S. phone calls without warrants

#163
post #161
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

It's true, email is mostly transmitted over TLS. But I'd be very reluctant to conclude that the NSA doesn't have clear-text for the vast majority of email that gets sent. Google and other email providers have denied giving the NSA access to their servers, but if you think about it, that would be a lousy way to share data with the NSA, from a purely technical point of view. A company like Google is going to be constan…

No, as 'DannyBee has been at pains to point out, no federal statute ever obligates anyone to lie about anything.

Re: NSA admits listening to U.S. phone calls without warrants

#164

Earlier quoted context omitted.

And I say that how we should treat Facebook collecting data and how we should treat governments collecting data (even data from Facebook) are entirely disjoint. Anything else is a peculiar brand of corporatism.

You realize that when you call something "a peculiar brand of corporatism", you're saying something equivalent to "a label that thus far exists only in my mind". Is there a more direct, refutable way you could construct your claim? How would anyone falsify your argument otherwise? You know what else is a (very) peculiar brand of corporatism? "Not corporatism".

I suppose I did not spell this out clear enough for you.

A traditional corporatist could be accused of trying to bring corporations up to the same level as governments. Rayiner seems to be playing at the idea of bringing governments up to the level of corporations. Despite appearing to be opposing positions, it should not take a rocket scientist to find the common ground.

Of course if you have no interest in doing so, it should not be surprising that you won't.

Re: NSA admits listening to U.S. phone calls without warrants

#165
post #48
post #30

Earlier quoted context omitted.

You're saying that despite the fact that everyone who hits Google Mail with Chrome uses a ciphersuite for which Google's private RSA key only works if you actively man-in-the-middle the connection , no matter how many hard drives you have in Utah, that NSA stole Google's private key, and then (I repeat:) documented that fact in a slide deck for NSA analysts? You could more easily and credibly argue that NSA has solve…

I think you may be forgetting that it's not all-or-nothing. Not everyone uses Chrome. I can't speak to a slide deck; We've only seen some slides for one program (PRISM). I am quite sure that NSA has several different programs variously encompassing collection and decryption. Hopefully in the next few days or weeks we'll see details about more of them. I don't think it's beyond the realm of possibility for a nation-st…

Far more than enough people use Chrome (or a different browser with cert pinning) with GMail that such an activity by the NSA would already have been tripped.

This is how other hacked SSL certs have been caught in the wild, remember? Do you think Iran has more GMail users than the U.S.?

Even my own S/MIME private key the NSA wouldn't be able to get a hold of without actually having to take my smartcard, and I'd certainly notice that.

Either way, there's something that the NSA has actually screwed up so I'm honestly a bit surprised that people are still arguing so much about a FISA compliance API. That horse is already essentially dead and buried. So dead and buried that others are saying that tptacek is tearing down a strawman for still mentioning it...

Re: NSA admits listening to U.S. phone calls without warrants

#166
post #109

There's something sick and wrong in the semantics of how the laws have been interpreted here. The authorities seem to have decided that they can record anything they want, any time they want. The legal boundary is only crossed when somebody listens to the recording. So it is fine for them to slurp up every bit of data they can tap into and then retrospectively figure out which bits they were authorized to listen to (…

Here is the video clip from General Alexander's congressional testimony three days ago, where he stated this was not happening:

http://youtu.be/ZmBAxEWxDFs?t=1h29m50s

It's not clear to me whether they were sworn in for this hearing or not, but if this new report is true, then this seems to be at least the second documented case of an exposed lie about the scope of surveillance during congressional testimony.

The first, of course, being Clapper's "not wittingly:" https://www.youtube.com/watch?v=T9ss2_0emOY

Re: NSA admits listening to U.S. phone calls without warrants

#167

Since the modus operandi seems to be for the NSA to suck up everything it can and decide later it seems (wild speculation follows) that the NSA might be sitting on audio recrodings of all your phone calls for the past several years. Can you imagine the number of divorce cases that would impact? Civil lawsuits? Proof of innocence or guilt in a crime? Hell, get a decade or two of this and historians alone would have a…

It really is appalling that this isn't more rejected. A couple decades ago impeachment, resignations, firings would happen. Everyone thinks about how this affects us now, how will it affect everyone decades from now? Pretty soon warrants won't be needed at all because Executive Orders override them and are 'legal'. We may as well just remove the 4th amendment since everyone is so scared and complacent.

Blasphemy. We've always been at war with Eastasia.

Re: NSA admits listening to U.S. phone calls without warrants

#168

Earlier quoted context omitted.

> If you read all my comments on this whole annoying story Your comments have repeatedly attacked the credibility of whistleblowers, derided their claims as factually and technically impossible, and asserted that NSA statements about NSA capabilities are wrong. > My point is that upon receiving them, a lawyer at Google approves or rejects them, not a SQL query. I don't think Google has much say in this, but what do I…

For fuck's sake. So you don't just disagree with (1) and (2), but with the whole thing. Why not just say that? Yes, to whatever extent that slide deck said NSA has direct access to the servers that run Google Mail, I am arguing with the slide deck.

Two days ago you were arguing with a slide deck. At this point, you're also arguing with a NSA brief of Congress and numerous public statements by members of Congress.

Swearing at me isn't the solution in any case. If you want to stop taking flack on HN, you should stop attacking the credibility of whistleblowers on the rhetorical basis that you know more about what the NSA is doing than the NSA does.

Re: NSA admits listening to U.S. phone calls without warrants

#169
post #102
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

tptacek why are you always defending ridiculous statements and behavior by the US administration and spy agencies? You seem willing to bend over backwards (or is it forwards) to justify any statement from the authorities but will attack the tiniest issue in a fellow HNers post. Have you and/or your company ever worked for them? If so it would explain a lot.

[deleted]

Re: NSA admits listening to U.S. phone calls without warrants

#170
post #104

Earlier quoted context omitted.

> If you're telling me that this is the understanding most HN people have about what "direct access" means, I'd direct your attention to this very thread to rebut that argument. I'm not at all saying that. I'm saying that most HN folks do not share your definition of what "direct access" means. I specifically said that it seems like most people are quite aware of the ambiguity of the meaning of "direct access" in a c…

Bullcrap. When people saw "direct access", they concluded direct access - as was reasonable, at the time, from what the leak seemed to show; I did the same. Many of the people on this site have since realized that that is not true (although there were sure a lot of crazy theories about the specific wording of the initial denials), but most of those people are no longer saying "direct access", and there are people sti…

[deleted]
Post reply on HN