Live data from Hacker News

The NSA slide you haven’t seen

washingtonpost.com

131–140 of 202 posts

Re: The NSA slide you haven’t seen

#131
For those with security clearances, clicking on a random HN link is risking your job and livelihood. It's easy to see a link to WikiLeaks and avoid that but when it's the WP posting it, not so much.

These articles really need to be flagged/tagged by HN and by the newspapers that publish them. I don't want to see a TS/SCI-classified document and I don't want to be seen as seeking them out.

I love the technical stories on HN (95% of what we read here) but it bothers me that I'm risking my clearance when I read this site.

Re: The NSA slide you haven’t seen

#132

I'll say it again, because I was immediately downvoted into invisibility: You CAN NOT continue to use products and services by NSA companies like Microsoft - Yahoo - Google - Facebook - PalTalk - AOL - Skype - YouTube - or Apple and THEN turn around and BITCH AND CRY ABOUT LOSING YOUR RIGHTS AND PRIVACY. This is completely INSANE, you NEED TO WAKE UP! EDIT: Yeah, let the censuring begin again. You know what? When I l…

You CAN NOT continue to use products and services by NSA companies like Microsoft - Yahoo - Google - Facebook - PalTalk - AOL - Skype - YouTube - or Apple and THEN turn around and BITCH AND CRY ABOUT LOSING YOUR RIGHTS AND PRIVACY.

So is it by coincidence the products that have the most users are the ones watched by the NSA? Any product/service that will reach such a huge audience will be a target.

Not using the product is not a solution. Getting the NSA to respect the law is what we need.

Re: The NSA slide you haven’t seen

#133

After seeing this article today, I made a post on Facebook to explain to some of my friends that aren't closely following the PRISM story that this is not compatible with the statements released by Mark Zuckerberg, Marissa Mayer, and Larry Page. I'll reproduce some of my post here--I'd link directly, but my Facebook is set to 'private.' Remember when Mark Zuckerberg (Facebook), Marissa Mayer (Yahoo!) and Larry Page (…

They didn't lie - they just made the truth dance with help from legal advisers. I think we already knew that, but the slide just confirms that they knew exactly what they were doing. EDIT: to clarify, GIVING someone access directly to a server and allowing/knowing about access to the data going in and out of a server are not technically the same thing. When I saw the Google/Facebook responses, it was obvious that the…

Although personally I tend to agree with you, this isn't evidence that they did know something else was going on.

A good lawyer would always insist on such phrasing, only addressing the absolute minimum necessary, even if there is nothing to cover up.

Of course, the fact that such outspoken CEO's all let the lawyers use them as sock puppets is still a big red flag.

(And the subsequent transparency theater that carefully circumvented any of the actual accusations makes it even more suspicious.)

Re: The NSA slide you haven’t seen

#134
post #13

Earlier quoted context omitted.

I wonder if anyone would be brave enough to test this, i.e. use TLS 1.2/forward security to one of sites mentioned, send a message to a "friend" (dumby account) that says you are planning an attack, and see what happens (i.e. it's only viewable by facebook/google whatever, not in transit)

Great idea! I nominate you.

Yeah, I don't really want to be a "person of interest" for the rest of my life. :-)

Re: The NSA slide you haven’t seen

#135
post #54

Earlier quoted context omitted.

Thanks for this! I've been looking for more to read (I just went back and re-read 1984). ... I thought one of the points of Fiber was that you couldn't tap in without disturbing the optical signal? Did I just make that up in my head?

> you couldn't tap in without disturbing the optical signal Well of course you can't. If you're going to split it off to read it, then you're "disturbing" it by definition. Whether or not you can do such that it's not noticeable to the proper end parties, of course, is a different story.

What's to stop a direct packet copy? The line goes in, a digital device sees the packets, copies them bit for bit and sends the original to their destination and a copy to the NSA. Similar to headphone splitting.

Re: The NSA slide you haven’t seen

#136
post #127
post #121

Earlier quoted context omitted.

> It is just not a useful term, and should be replaced with something more specific in all these instances How about "collection directly from the server of..." just like it appeared in the actual slide, instead of 'direct access' as everyone else misquotes it?

But it seems like that still has all the ambiguity I mentioned. It could still be construed as root level access, or an FTP server, or anything in between. Also realize that Glenn Greenwald shares a good amount of blame for this misquote. The first line in the first article about PRISM is "The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants."…

The problem is with Greenwald / Snowden - they needed to provide indisputable evidence regarding their most garish claims; or `direct access` to a representation of the evidence

Re: The NSA slide you haven’t seen

#137

I'll say it again, because I was immediately downvoted into invisibility: You CAN NOT continue to use products and services by NSA companies like Microsoft - Yahoo - Google - Facebook - PalTalk - AOL - Skype - YouTube - or Apple and THEN turn around and BITCH AND CRY ABOUT LOSING YOUR RIGHTS AND PRIVACY. This is completely INSANE, you NEED TO WAKE UP! EDIT: Yeah, let the censuring begin again. You know what? When I l…

Can you USE MORE CAPITAL LETTERS, please? That would MAKE YOUR POINT MUCH MORE CREDIBLE, you know.

WHAT?!

Re: The NSA slide you haven’t seen

#138
post #127
post #121

Earlier quoted context omitted.

> It is just not a useful term, and should be replaced with something more specific in all these instances How about "collection directly from the server of..." just like it appeared in the actual slide, instead of 'direct access' as everyone else misquotes it?

But it seems like that still has all the ambiguity I mentioned. It could still be construed as root level access, or an FTP server, or anything in between. Also realize that Glenn Greenwald shares a good amount of blame for this misquote. The first line in the first article about PRISM is "The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants."…

> Also realize that Glenn Greenwald shares a good amount of blame for this misquote

I agree, and have said as much multiple times.

But that's no reason to continue to perpetuate the usage of a semantically-different variant of the original quote, especially with all the other data we have on PRISM now that can help disambiguate what the original quote could reasonably be construed as.

Re: The NSA slide you haven’t seen

#139

Earlier quoted context omitted.

They didn't lie - they just made the truth dance with help from legal advisers. I think we already knew that, but the slide just confirms that they knew exactly what they were doing. EDIT: to clarify, GIVING someone access directly to a server and allowing/knowing about access to the data going in and out of a server are not technically the same thing. When I saw the Google/Facebook responses, it was obvious that the…

> When I saw the Google/Facebook responses, it was obvious that the posts had a lot in common. Both used the phrase "direct access to our servers". When you see a phrase repeated like that, one of two things has happened. Either one copied the other's phrasing, or someone told them what to say. In either case, the legal department would definitely weigh in on a huge issue like this. I totally agree that these organiz…

(D) the slide doesn't actually say 'direct access', but says 'collection directly from the servers of', which is different.

My browser pulled the comment I'm replying to right now 'directly from the servers of' HN, but I don't have 'direct access' to HN.

Re: The NSA slide you haven’t seen

#140
post #124
post #89

Earlier quoted context omitted.

This is close but wrong in some very important ways. CALEA does not apply to Google (except Google fiber and perhaps Google Voice). Google does have to comply with FBI requests for emails and stored data, but they do not have to comply with CALEA (which mandates technical standards for the wiretapping of the phone network and most internet networks). Google does NOT have to build real-time domestic spying tools for t…

Even without CALEA, if I'm reading the press coverage right, the FISA orders to which Google comply once they check that they were issued by FISC can be very broad, including "give me ALL the metadata you have" in a single order. Because "taking all metadata an storing it indefinitely is nothing to be worried about" in NSA interpretations.

Well all metadata wouldn't work as that could be used to intercept U.S. persons' data. The warrant/NSL would have to list by name/UID at the very least, but once it's established that the UID in question is foreign and a part of an investigation then you are right that the warrant/NSL can be very broad.
Post reply on HN