Live data from Hacker News

An Apology to my European IT Team

fredlybrand.com

31–40 of 97 posts

Re: An Apology to my European IT Team

#31
post #23

Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…

The safeguards for actual analysts who use the data "officially" are probably a lot stronger than for sysadmins (like Snowden) who have access through side channels. They probably log access through the front door of the webapp and would question someone doing queries on blatantly non-work related things -- this has caught people in healthcare looking up the medical records of famous people, in the past. They could p…

Exactly, except for the logging part: It would appear that either Snowden was able to circumvent the logging policies via his admin privs or they were not in place.

When I was head of an IT division within lockheed (non-classified) I could have accessed anything - with admin accounts i was the sole owner of. I was ethically precluded from doing so...

At a company where there is "open access" with "logging the shit out of access (e.g. Facebook) -- then this situation could arise where an arbitrary employee could access any data, assuming they had the knowledge of where to find the info they were looking for, didn't get caught and the logging was either faulty, ignored or fictitious -- or the employee used an account other than their own to avoid suspicions.

It would be interesting,actually, to understand to what deep level of privs B.A.H - as a company - was afforded to NSA data/systems/programs/etc...

One thing I am not clear on is how this employee of a 3rd party def contractor (albeit, supposedly the biggest to the NSA) was able to access information that is considered to be so deeply secret to the USG? Is this an indication that a significantly "important" program (PRISM) was, for the most part, outsourced to be run by contractors such as Snowden within BAH?

Did Snowden systematically seek out, deftly, access to information over a long period of time through his privs afforded him as a sys ad? This to me is the most intriguing and unknown part: For how long was Snowden planning this? Was this something he truly accomplished on his own? Or was there a cast of supporting characters that we are unaware of"

If there is no supporting characters who helped him put this together - that this guy is one of the most brilliant high-school drop-outs I have heard of.

If there is a cast of supporting characters were they operating as whistleblowers in support of the seemingly patriotic reveal that we have thus far seen?

Or was there a supporting cast of characters that have helped snowden architect this whole event, masterfully - it seems, for a motive that we, the outsiders, are not yet aware: There seem to be three possible realities if this is true:

1) Snowden plus team is a smokescreen designed to purposefully air this info to further the surveillance agenda by seeing how far the world acquiesces to it. Stir up a reaction that can result in tighter controls of liberty when protesting pops up and the USG can claim that these are all threats to our national security and these efforts are vital.

2) Snowden plus team are truly patriots and heroes and are looking to stop the furtherance of USG/tyranny over individual freedom and are airing this info to allow for an open dialogue.

3) Snowden and team really are double/triple agents and are an attack on the USG directly attempting to make the USG look bad and have the US lose face/credibility...

(I am sure there are countless other potential scenarios that the NSA/USG have mapped out... I would be REALLY interested in hearing them for consideration)

---

My personal opinion is simple - I am very happy this series of events has taken place as I have known of Echelon for decades - and now feel that there is 100% irrefutable proof that it is in place... what the next steps are is unclear, but I hope that it is an awakening and invigoration of people all over the world to fight to make this place a better world to live in rather than a worse one.

Re: An Apology to my European IT Team

#32
post #27

Earlier quoted context omitted.

According to Google "NSA powers" in their case are restricted to FISA orders, so I'm not sure how a random worker at a government contractor can produce these. Snowden was a sysadmin for a contractor and that is how he got his hands on their internal documents. Is no one else paying attention to anything beyond the "slides" in this story?!

Aren't the NSA claiming they only need a FISA warrant if both ends of the correspondence are (reasonably believed to be) US citizens on US territory? For those of us in "the rest of the world" or any Americans corresponding with us I believe the restrictions on the NSA are "Yeah, do whatever the hell you want!"

[deleted]

Re: An Apology to my European IT Team

#33
post #28
post #25

Earlier quoted context omitted.

Even just setting START TLS REQUIRED might solve your spam problem, as long as only a tiny minority of people did it. That would have the added benefit of protecting you from Yahoo Mail users, the FBI, and such. At this point, I'd consider NOT using START TLS for your MTA to be nearly as irresponsible as not using ssh instead of telnet/rsh, or not using secure passwords. It correctly pushes all the pain onto the sysa…

Do you know if a successful response to a START TLS command endured end-to-end TLS secured mail transport? I kinda doubt it - if for some reason your outgoing mail server connects to one of my secondary/relaying MX servers, I don't think there's any way for you to ensure that server bothers trying to set up a TLS session when it relays my mail(which I guess is mostly my problem/fault) - and similarly, if your ISP req…

Usually people do not block 465 or 587 (if they do, they really really suck, and you need to VPN through that network anyway). For outgoing mail, you just do STARTTLS directly to your own smarthost over those ports.

Re: An Apology to my European IT Team

#34

Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…

Snowden directly answers this -- he claims NSA analysts can get away with it:

http://www.guardian.co.uk/world/2013/jun/17/edward-snowden-n... and

http://www.guardian.co.uk/world/2013/jun/17/edward-snowden-n...

This is getting overlooked, but a 2009 NYT article claimed an NSA analyst looked through Bill Clinton's email out of curiosity (he was caught). I think this is very revealing.

http://www.nytimes.com/2009/06/17/us/17nsa.html?pagewanted=a...

Re: An Apology to my European IT Team

#35
Sadly the NSA programs are strongly anti-business as it is based on 'trust in me'.

American businesses could and should lobby Congress to fight this and to find ways to protect US stored data, I know I wouldn't trust a Chinese cloud company not to snoop or steal business/corporate ideas and trade secrets.

But if there were assurances for US cloud businesses that this doesn't affect their business ideas accidentally or deliberately then we could set a global example on how to run cloud data storage that is safe and business friendly. There is an opportunity here for Google, Amazon, Apple etc for cloud data.

Lots of damage control to be done here for international clients. As an American I would always trust our systems more but international companies may have a very hard time trusting without the US being a shining example of how to correctly protect business data in clouds here, especially encrypted data that is automatically subject to storage/filtering if international.

Re: An Apology to my European IT Team

#36

Sadly the NSA programs are strongly anti-business as it is based on 'trust in me'. American businesses could and should lobby Congress to fight this and to find ways to protect US stored data, I know I wouldn't trust a Chinese cloud company not to snoop or steal business/corporate ideas and trade secrets. But if there were assurances for US cloud businesses that this doesn't affect their business ideas accidentally o…

[deleted]

Re: An Apology to my European IT Team

#37
post #23

Earlier quoted context omitted.

The safeguards for actual analysts who use the data "officially" are probably a lot stronger than for sysadmins (like Snowden) who have access through side channels. They probably log access through the front door of the webapp and would question someone doing queries on blatantly non-work related things -- this has caught people in healthcare looking up the medical records of famous people, in the past. They could p…

Exactly, except for the logging part: It would appear that either Snowden was able to circumvent the logging policies via his admin privs or they were not in place. When I was head of an IT division within lockheed (non-classified) I could have accessed anything - with admin accounts i was the sole owner of. I was ethically precluded from doing so... At a company where there is "open access" with "logging the shit ou…

Snowden didn't circumvent anything, because he hasn't released anything. Snowden has made a lot of grandiose claims which he can't actually back up, because beyond a few slides and some very common knowledge stuff (NSA hacking China) which he could've outright made up he hasn't been able to show he could do any of the stuff he claims.

If you were aware of any notable hacking incidents in China, and could claim to have privileged knowledge, then it's easy to say the NSA were behind whatever you want (just in this case, obviously the NSAs mission would imply it attempts hacking of foreign networks).

PRISM is disclosed via a powerpoint presentation. Presentation as in, a thing you tend to show to a large audience. Its highly likely he was simply given a copy of it after being shown it, since good internal education and knowledge sharing is a pretty core concept to running a successful enterprise.

Re: An Apology to my European IT Team

#38

Sadly the NSA programs are strongly anti-business as it is based on 'trust in me'. American businesses could and should lobby Congress to fight this and to find ways to protect US stored data, I know I wouldn't trust a Chinese cloud company not to snoop or steal business/corporate ideas and trade secrets. But if there were assurances for US cloud businesses that this doesn't affect their business ideas accidentally o…

But what protection of stored data do you mean should Congress find, by introducing some Laws? Because, well, if the data are not encrypted on the server, then someone could still take them... that's how Internet works. For now, the only solution I can think of is that you encrypt the data locally, and upload only the encrypted data - but this way, the cloud provider will not able to provide any additional value. Or are there some other possibilities?

Re: An Apology to my European IT Team

#39
While OP's apology is appreciable, there was more than enough information available in 2008 to understand that his Czech colleagues were right.

The Prism scandal may have come as a surprise to US citizens, but the US has been spying foreign nationals and companies for years, and we've long known about it - haven't you heard of Echelon? It was also well known that these systems were used for industrial espionage.

Re: An Apology to my European IT Team

#40
I just wonder why telcos I've been dealing with have always required to encrypt all information which is not classified as public information. All customer, project, system, configuration, documentation, contracts etc. must be encrypted before transit. - Surely they must have known about this. So if telcos won't trust privacy of telecommunication, why should anyone else think that telcos are trustworthy?
Post reply on HN