Live data from Hacker News

The NSA slide you haven’t seen

washingtonpost.com

111–120 of 202 posts

Re: The NSA slide you haven’t seen

#111

Earlier quoted context omitted.

Thanks for this! I've been looking for more to read (I just went back and re-read 1984). ... I thought one of the points of Fiber was that you couldn't tap in without disturbing the optical signal? Did I just make that up in my head?

I don't see why that would be true. This is classical signal transmitted optically, not quantum cryptography. There is no reason you couldn't splice the cable through a machine that recorded the signal and then recreated it. Or a beam splitter that removed just a small fraction of the signal; the effect would be a slight increase in transmission loss.

I had a professor who did optics research sponsored by the NSA. They didn't tell him the intended application, but he suspected it was to tap optical fibers by evanescent wave coupling (see http://en.wikipedia.org/wiki/Evanescent_wave#Evanescent-wave... ). It's as if photons are quantum tunneling out of the fiber, so there is no need to physically cut into it. That would have made the tapping nearly undetectable.

Re: The NSA slide you haven’t seen

#112
post #18

Once again, I suggest everyone interested read James Bamford's book Shadow Factory. All these revelations regarding call metadata, PRISM collection (albeit under a different codename at the time), modern fiber taps, and even more are covered. You'll learn about how they shave fiber optic cables in order to intercept traffic and not be detected. You'll find out about the various facilities already reported, along with…

Thanks for this! I've been looking for more to read (I just went back and re-read 1984). ... I thought one of the points of Fiber was that you couldn't tap in without disturbing the optical signal? Did I just make that up in my head?

You're likely thinking of quantum communications: https://en.wikipedia.org/wiki/Quantum_key_distribution

Re: The NSA slide you haven’t seen

#113
post #67

Earlier quoted context omitted.

Who said this? It seems obviously false. All you would have to do is insert a detector and another emitter that simply replays everything the detector reads.

While I agree it's certainly false, your implementation idea would almost certainly introduce detectable delay. All you'd need is a beam splitter. You can manufacture them to only take 1% of the beam.

Would such a splitter give you 1% of the messages passed, or 1% of a message?

Re: The NSA slide you haven’t seen

#114
post #18

Once again, I suggest everyone interested read James Bamford's book Shadow Factory. All these revelations regarding call metadata, PRISM collection (albeit under a different codename at the time), modern fiber taps, and even more are covered. You'll learn about how they shave fiber optic cables in order to intercept traffic and not be detected. You'll find out about the various facilities already reported, along with…

In addition to The Shadow Factory he also wrote The Puzzle Palace and Body of Secrets . I'm not sure how much material is shared between the three books, or if they're meant to be read in any certain order, but I'm plowing through The Puzzle Palace now. In any case, it's wildly interesting stuff.

Puzzle Palace is excellent.

Specifically relating to the recent revelations, this book was where I learned of the NSA's "vacuum cleaner" approach, in which all available messages are collected -- in this case, it was trans-Atlantic radio transmissions being monitored by ECHELON. So, an American citizen in the UK calling an American citizen in the US would have their call collected.

The approach (collect everything you can at the trunk line or server farm) is very similar to the e-mail collection strategy that's being documented now.

Re: The NSA slide you haven’t seen

#115
After seeing this article today, I made a post on Facebook to explain to some of my friends that aren't closely following the PRISM story that this is not compatible with the statements released by Mark Zuckerberg, Marissa Mayer, and Larry Page. I'll reproduce some of my post here--I'd link directly, but my Facebook is set to 'private.'

Remember when Mark Zuckerberg (Facebook), Marissa Mayer (Yahoo!) and Larry Page (Google) all denied "directly" giving the NSA everyone's data?

They claimed that all access was done through national security letters and warrants, because the slides that had leaked at the time supported that. Turns out new slides leaked, and everyone lied!

  *snip* (I linked to the WaPo article, and the slide directly)
And for sources on the original denial (each claiming "no direct access"):

https://www.facebook.com/zuck/posts/10100828955847631 (Zuckerberg/FB)

http://yahoo.tumblr.com/post/53243441454/our-commitment-to-o... (Mayer/Yahoo!)

http://googleblog.blogspot.com/2013/06/what.html (Page/Google)

Re: The NSA slide you haven’t seen

#116
post #91
post #88

Earlier quoted context omitted.

First I've heard of this 51% thing. If it's true (and I don't doubt it) then the situation is even worse than I thought. Do you have a reference?

Sure, it's from the Washington Post's reporting: http://www.washingtonpost.com/wp-srv/special/politics/prism-... Search for 51.

I see where it says in the caption "The supervisor must endorse the analyst's "reasonable belief," defined as 51 percent confidence, that the specified target is a foreign national who is overseas at the time of collection." But that's a caption written by the Post. What I don't see is any support for that statement in the actual slide itself, nor any of the other slides on that page.

Re: The NSA slide you haven’t seen

#117

After seeing this article today, I made a post on Facebook to explain to some of my friends that aren't closely following the PRISM story that this is not compatible with the statements released by Mark Zuckerberg, Marissa Mayer, and Larry Page. I'll reproduce some of my post here--I'd link directly, but my Facebook is set to 'private.' Remember when Mark Zuckerberg (Facebook), Marissa Mayer (Yahoo!) and Larry Page (…

Well, the best we can do is assume they lied.

However unlikely, it's still possible the NSA had moles or secret legal proceedings against certain employees that directed them to provide the NSA with a direct connection to the servers.

The reason why I say 'unlikely' is that such a setup would also involve data connectivity out of those data centers and additionally would probably trip all sorts of intrusion monitoring systems (if the big companies are doing their jobs right).

There's still a little wiggle room here, just not much very realistically.

Re: The NSA slide you haven’t seen

#119

After seeing this article today, I made a post on Facebook to explain to some of my friends that aren't closely following the PRISM story that this is not compatible with the statements released by Mark Zuckerberg, Marissa Mayer, and Larry Page. I'll reproduce some of my post here--I'd link directly, but my Facebook is set to 'private.' Remember when Mark Zuckerberg (Facebook), Marissa Mayer (Yahoo!) and Larry Page (…

They didn't lie - they just made the truth dance with help from legal advisers. I think we already knew that, but the slide just confirms that they knew exactly what they were doing.

EDIT: to clarify, GIVING someone access directly to a server and allowing/knowing about access to the data going in and out of a server are not technically the same thing.

When I saw the Google/Facebook responses, it was obvious that the posts had a lot in common. Both used the phrase "direct access to our servers".

When you see a phrase repeated like that, one of two things has happened. Either one copied the other's phrasing, or someone told them what to say. In either case, the legal department would definitely weigh in on a huge issue like this.

A smart lawyer would never let the company lie outright. They would advise everyone to speak the truth, but "the truth they speak may not be the truth you think you hear." No direct access to servers. Sure. They just had access to the data going in and out of the server. To someone used to reading political and legal documents, "no direct access to servers" almost screams "some form of access to something." Otherwise the denial would have been more

Zuck and Page didn't lie, but they were less than forthcoming. Myers didn't even bother addressing the claim directly.

I suspect a government lawyer fed them phrases they could use that sound like denials without actually lying.

Re: The NSA slide you haven’t seen

#120

After seeing this article today, I made a post on Facebook to explain to some of my friends that aren't closely following the PRISM story that this is not compatible with the statements released by Mark Zuckerberg, Marissa Mayer, and Larry Page. I'll reproduce some of my post here--I'd link directly, but my Facebook is set to 'private.' Remember when Mark Zuckerberg (Facebook), Marissa Mayer (Yahoo!) and Larry Page (…

You do realize that PRISM is a separate program from NSA's upstream data collection efforts, right?
Post reply on HN