Live data from Hacker News

The NSA slide you haven’t seen

washingtonpost.com

121–130 of 202 posts

Re: The NSA slide you haven’t seen

#121
post #49
post #2

> "collection directly from the servers" So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direct access would be better than these slides. I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Or maybe even the NSA, but we know they share inaccuracies under oath, so maybe that isn't worth so much.

The real problem is that "direct access to servers" is not a specific term. Given the various definitions it could have, everyone could be being truthful. Some would interpret "direct access" to mean root level access to their entire infrastructure, which sounds absurd to me, yet some people seem to believe that's what's happening. And it's my understanding that this is what Google, facebook, etc. have been denying.…

> It is just not a useful term, and should be replaced with something more specific in all these instances

How about "collection directly from the server of..." just like it appeared in the actual slide, instead of 'direct access' as everyone else misquotes it?

Re: The NSA slide you haven’t seen

#122

After seeing this article today, I made a post on Facebook to explain to some of my friends that aren't closely following the PRISM story that this is not compatible with the statements released by Mark Zuckerberg, Marissa Mayer, and Larry Page. I'll reproduce some of my post here--I'd link directly, but my Facebook is set to 'private.' Remember when Mark Zuckerberg (Facebook), Marissa Mayer (Yahoo!) and Larry Page (…

They didn't lie - they just made the truth dance with help from legal advisers. I think we already knew that, but the slide just confirms that they knew exactly what they were doing. EDIT: to clarify, GIVING someone access directly to a server and allowing/knowing about access to the data going in and out of a server are not technically the same thing. When I saw the Google/Facebook responses, it was obvious that the…

> When I saw the Google/Facebook responses, it was obvious that the posts had a lot in common. Both used the phrase "direct access to our servers". When you see a phrase repeated like that, one of two things has happened. Either one copied the other's phrasing, or someone told them what to say. In either case, the legal department would definitely weigh in on a huge issue like this.

I totally agree that these organizations used the phrase "direct access" intentionally, surely with legal advice. My point, however, was that at the time that these companies released their responses, the slide that actually said direct access verbatim had not yet leaked. Although it's impossible to tell what actually happened, it looks to me like they decided to deny "direct access" in the hopes that there were no slides indicating that direct access did exist. After all, it's unlikely that these companies had the full slide deck (or anything other than what the media had published).

So, either:

(A) Larry Page and Mark Zuckerberg actually didn't know that they provided "direct" access to data.

(B) NSA actually doesn't have "direct" access as indicated by this slide, meaning that the slide is incorrect or falsified.

(C) Page and Zuckerberg lied in their statements.

I don't see a fourth option regarding direct NSA access to these companies' data.

And you're right regarding Mayer not addressing the claim directly; I was a little bit off there. Still, by saying "well, we received between 12,000 and 13,000 FISA requests," Yahoo! is implying that there isn't any sort of "backdoor" access, which no longer seems to be the case.

Re: The NSA slide you haven’t seen

#123
post #57

Any speculation as to what the redaction next to "Processing" in the "PRISM Collection Data Flow" slide is?

It is next to "Protocol Exploitation," so it could be anything from "Data" to "Public Key." What I am wondering at the moment is the "DNI" on the same slide, is this direct neural interface ? /tinfoil

Though I can't look at the slide, DNI should stand for Director of National Intelligence.

Re: The NSA slide you haven’t seen

#124
post #89

Earlier quoted context omitted.

They're getting the info directly from Google et al., but they don't have root on Google's servers. Google is required by law (CALEA, the Communications Assistance for Law Enforcement Act) to provide the ability for law enforcement to get information from them. This includes - required by law - the ability both to get stored data and to make real-time intercepts of new communications. Google is paid a fee to provide…

This is close but wrong in some very important ways. CALEA does not apply to Google (except Google fiber and perhaps Google Voice). Google does have to comply with FBI requests for emails and stored data, but they do not have to comply with CALEA (which mandates technical standards for the wiretapping of the phone network and most internet networks). Google does NOT have to build real-time domestic spying tools for t…

Even without CALEA, if I'm reading the press coverage right, the FISA orders to which Google comply once they check that they were issued by FISC can be very broad, including "give me ALL the metadata you have" in a single order. Because "taking all metadata an storing it indefinitely is nothing to be worried about" in NSA interpretations.

Re: The NSA slide you haven’t seen

#125
post #18

Once again, I suggest everyone interested read James Bamford's book Shadow Factory. All these revelations regarding call metadata, PRISM collection (albeit under a different codename at the time), modern fiber taps, and even more are covered. You'll learn about how they shave fiber optic cables in order to intercept traffic and not be detected. You'll find out about the various facilities already reported, along with…

Thanks for this! I've been looking for more to read (I just went back and re-read 1984). ... I thought one of the points of Fiber was that you couldn't tap in without disturbing the optical signal? Did I just make that up in my head?

I don't believe fibre cables are single length. Between your point of signal origin and the destination are already a number of boxes that act as repeaters. To split the cable, you'd effectively add in another one (or subvert the provider, of course). Or I believe you can tap the cable anyway:

This is a nice primer on fibre:

http://www.redbooks.ibm.com/redbooks/pdfs/sg245230.pdf

And here is one talking about its security, in particular vs tapping (the conclusion: it can be done):

http://www.sans.org/reading_room/whitepapers/physcial/fiber-...

Finally, I always figured that tapping fibre was exactly what this was for:

https://en.wikipedia.org/wiki/USS_Jimmy_Carter_(SSN-23)

Re: The NSA slide you haven’t seen

#126
post #67

Earlier quoted context omitted.

While I agree it's certainly false, your implementation idea would almost certainly introduce detectable delay. All you'd need is a beam splitter. You can manufacture them to only take 1% of the beam.

Would such a splitter give you 1% of the messages passed, or 1% of a message?

These splitter work in the domain of light-pulses transmitted over a fiber. So you get 100% of the messages, but the flashes of light representing the bits will be much weaker. Probably this will mean that you have to put in much more effort to decode the signal than a usual network-device will need, and also probably means that you will have a higher number of errors in your data.

On the other hand, if you'd tap only a short distance downstream of the transmitter (or an inline amplifier), that 1% might be plenty, undisturbed by the distortions introduced further on the line, so probably that's the preferable tapping location anyway.

[I know that I'm oversimplifying a lot here and modern optical communication systems work much different.]

Re: The NSA slide you haven’t seen

#127
post #121
post #49

Earlier quoted context omitted.

The real problem is that "direct access to servers" is not a specific term. Given the various definitions it could have, everyone could be being truthful. Some would interpret "direct access" to mean root level access to their entire infrastructure, which sounds absurd to me, yet some people seem to believe that's what's happening. And it's my understanding that this is what Google, facebook, etc. have been denying.…

> It is just not a useful term, and should be replaced with something more specific in all these instances How about "collection directly from the server of..." just like it appeared in the actual slide, instead of 'direct access' as everyone else misquotes it?

But it seems like that still has all the ambiguity I mentioned. It could still be construed as root level access, or an FTP server, or anything in between.

Also realize that Glenn Greenwald shares a good amount of blame for this misquote. The first line in the first article about PRISM is "The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants." (http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-n...)

Re: The NSA slide you haven’t seen

#128
post #103
post #84

Earlier quoted context omitted.

The prevailing theory is that they do the latter; the former would be both easy to detect (at the time of splice) and locate (via TDR). Getting the signal out of the fiber pales in comparison, though, with the task of getting all of that data back to Maryland/Utah. Unless they have specific cooperation of the cable owners and can tap/split the fibers at the landings, they must be spending a significant percentage of…

I don't know much about undersea cables (although it is a fascinating subject), but I imagine there's no need to tap a cable in the middle of the ocean. If instead you tap it a couple miles offshore (even tens of miles), suddenly have a lot less undersea fiber to run. And if multiple cables come ashore at the same place, you can probably disguise it as just another fiber. Of course, this requires a friendly country a…

Yes but there is a problem, other countries also have submarines/boats that protect their assets.

Re: The NSA slide you haven’t seen

#129

Not to sound like a conspiracy theorist, but does anyone else think this prism thing was all something made up by PalTalk as a PR stunt?

It's never been published "there" before, so it's technically true.

And this is the first time I'm making this comment here.

Post reply on HN