Live data from Hacker News

The NSA slide you haven’t seen

washingtonpost.com

71–80 of 202 posts

Re: The NSA slide you haven’t seen

#71
post #13
post #2

> "collection directly from the servers" So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direct access would be better than these slides. I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Or maybe even the NSA, but we know they share inaccuracies under oath, so maybe that isn't worth so much.

I wonder if anyone would be brave enough to test this, i.e. use TLS 1.2/forward security to one of sites mentioned, send a message to a "friend" (dumby account) that says you are planning an attack, and see what happens (i.e. it's only viewable by facebook/google whatever, not in transit)

Sounds like a wonderful idea.

Because law enforcement (like everyone really) LOVES having their time wasted.

Re: The NSA slide you haven’t seen

#72

Earlier quoted context omitted.

They're getting the info directly from Google et al., but they don't have root on Google's servers. Google is required by law (CALEA, the Communications Assistance for Law Enforcement Act) to provide the ability for law enforcement to get information from them. This includes - required by law - the ability both to get stored data and to make real-time intercepts of new communications. Google is paid a fee to provide…

Correct me if I'm wrong, but you left out the step where a judge reviews the request to make sure it's not overly broad or based on flimsy reasoning. Aside from that I'd say it's a very clear, and it's sad that there seems to be a pervasive inference that these companies are something something beyond what our elected law makers have forced them to do. Why isn't more angst directed at the politicians responsible for…

A judge does review the request. Whether that judge "makes sure it's not overly broad or based on flimsy reasoning" is far from clear. The judge has been hand-picked by John Roberts and only hears the government's side of the case. The FISA court has rejected 0.03 percent of the government's requests. Now, maybe that's just an indication that 99.97% of the government's requests are reasonable, but here's the problem: we have no way of knowing, because it's all secret. THAT is the problem IMHO, more than the surveillance itself.

Re: The NSA slide you haven’t seen

#73
post #41

Earlier quoted context omitted.

You were downvoted into invisibility because this type of discourse is not appropriate for Hacker News. Please, no shouting. No vague pronouncements to "wake up". We try to have a reasoned, intelligent discourse here. There are many services provided by companies which may collaborate with the NSA or law enforcement which are pretty much unavoidable in modern society; the telephone network, the internet, and so on. T…

> Rather, we should be discussing realistic solutions. Everything has already been discussed. Multiple times over. And when you repeat yourself, you get downvoted.

You're not getting it.

It's not what you say (which frankly everyone here seems to agree with). It's how you say it.

Re: The NSA slide you haven’t seen

#74
post #2

> "collection directly from the servers" So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direct access would be better than these slides. I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Or maybe even the NSA, but we know they share inaccuracies under oath, so maybe that isn't worth so much.

If clapper was outright lying to congress about the data collection... what makes you think getting Zuck under "oath" is going to do any better. After all, he thinks we're all a bunch of "dumb fucks" and it would appear he happily sold all global user data to the USG without even a second thought.

Re: The NSA slide you haven’t seen

#75

Earlier quoted context omitted.

They're getting the info directly from Google et al., but they don't have root on Google's servers. Google is required by law (CALEA, the Communications Assistance for Law Enforcement Act) to provide the ability for law enforcement to get information from them. This includes - required by law - the ability both to get stored data and to make real-time intercepts of new communications. Google is paid a fee to provide…

Correct me if I'm wrong, but you left out the step where a judge reviews the request to make sure it's not overly broad or based on flimsy reasoning. Aside from that I'd say it's a very clear, and it's sad that there seems to be a pervasive inference that these companies are something something beyond what our elected law makers have forced them to do. Why isn't more angst directed at the politicians responsible for…

But these companies do more than what is required by law. They do not by law have to provide API access, only to provide the data in some form. None of the smaller webmail hosts cooperate in PRISM.

And as for warrants, no they do not always need a warrant. They only need that if both parties in the communication are US citizens. If none of them are no warrant is needed at all and if just one party is US then they (according to the Wikipedia article on PRISM) can wiretap for up to a week without getting a warrant.

Re: The NSA slide you haven’t seen

#76
post #67

Earlier quoted context omitted.

Who said this? It seems obviously false. All you would have to do is insert a detector and another emitter that simply replays everything the detector reads.

While I agree it's certainly false, your implementation idea would almost certainly introduce detectable delay. All you'd need is a beam splitter. You can manufacture them to only take 1% of the beam.

Sure. But "Hey guys, just to let you know, we moved our relay back a couple meters for reorganization" would also introduce detectable delay -- I doubt anyone actually cares about the delay.

Re: The NSA slide you haven’t seen

#77
post #33
post #20

Earlier quoted context omitted.

These come from the NSA originally - so it's probably SOP to make slight changes to every page of every document each time it is released to someone, so that they can track the exact source and path of any leaks.

Or someone just decided that a US map would look better for the other briefing.

On the US-map one, the ellipses line up correctly with the cable landings, and the PRISM-partner logos are over the US, not floating in the ocean. Also, the arrowheads on the cable-bundle ellipses aren't all distorted, and the drop shadow on the "You Should Use Both" text displays correctly.

I'm marking this one down to PowerPoint-specific rendering (vs, say, OpenOffice).

Re: The NSA slide you haven’t seen

#78

Earlier quoted context omitted.

> Rather, we should be discussing realistic solutions. Everything has already been discussed. Multiple times over. And when you repeat yourself, you get downvoted.

You're not getting it. It's not what you say (which frankly everyone here seems to agree with). It's how you say it.

Yes. I agree with the outrage, but exactly because of that, please, take my parent comment to heart.

Re: The NSA slide you haven’t seen

#79
post #2

> "collection directly from the servers" So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direct access would be better than these slides. I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Or maybe even the NSA, but we know they share inaccuracies under oath, so maybe that isn't worth so much.

They're getting the info directly from Google et al., but they don't have root on Google's servers. Google is required by law (CALEA, the Communications Assistance for Law Enforcement Act) to provide the ability for law enforcement to get information from them. This includes - required by law - the ability both to get stored data and to make real-time intercepts of new communications. Google is paid a fee to provide…

CALEA does not apply to Google, so this isn't correct. The reason they are required "by law" is that they get FISAs, which can be served on anyone and is unrelated to those specific laws.

Re: The NSA slide you haven’t seen

#80
post #13
post #2

> "collection directly from the servers" So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direct access would be better than these slides. I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Or maybe even the NSA, but we know they share inaccuracies under oath, so maybe that isn't worth so much.

I wonder if anyone would be brave enough to test this, i.e. use TLS 1.2/forward security to one of sites mentioned, send a message to a "friend" (dumby account) that says you are planning an attack, and see what happens (i.e. it's only viewable by facebook/google whatever, not in transit)

I suggested that on a forum 10 years ago (though about unencrypted emails) to see if the spooks were really monitoring email, and no one seems to want to take up that offer.
Post reply on HN