Live data from Hacker News

The NSA slide you haven’t seen

washingtonpost.com

151–160 of 202 posts

Re: The NSA slide you haven’t seen

#151
post #18

Once again, I suggest everyone interested read James Bamford's book Shadow Factory. All these revelations regarding call metadata, PRISM collection (albeit under a different codename at the time), modern fiber taps, and even more are covered. You'll learn about how they shave fiber optic cables in order to intercept traffic and not be detected. You'll find out about the various facilities already reported, along with…

Was expecting to find comment by tptacek explaining how WP's Craig Timberg has no journalistic integrity because "direct access" clearly doesn't mean the NSA gets whatever data it wants by whatever means necessary. Rather, "direct access" can only imply the NSA administers the credentials of each and every server and database existent, which clearly couldn't be true. Maybe he's busy. I'll check back.

My thoughts exactly. I had assumed that tpateck would have magnified a figure of speech (e.g. full control -> judge can only appoint not remove), ranted about some obtuse point (e.g. which foreign government does not spy), and enjoyed the thread on violation of first/fourth amendment right derail from the issue. And all of his posts are moved to the top by HNers who recognize the name.

Re: The NSA slide you haven’t seen

#153

I'll say it again, because I was immediately downvoted into invisibility: You CAN NOT continue to use products and services by NSA companies like Microsoft - Yahoo - Google - Facebook - PalTalk - AOL - Skype - YouTube - or Apple and THEN turn around and BITCH AND CRY ABOUT LOSING YOUR RIGHTS AND PRIVACY. This is completely INSANE, you NEED TO WAKE UP! EDIT: Yeah, let the censuring begin again. You know what? When I l…

You're being down voted because your comment is entirely non-constructive. 1) Calling people insane won't win you any favors. 2) "WAKE UP" is an entirely useless platitude. 3) Simply not using "NSA companies" is completely impractical. Not everyone can afford to be a recluse eccentric by ignoring the largest software providers on the planet. Never mind the fact that switching to an alternative in mass would simply pr…

These companies aren't at fault, our government is

I think the companies are also at fault. If instead of illegal surveillance the companies were being asked to illicitly expose employees to potentially harmful radiation, the moral culpability would be more obvious, regardless of the letter of the FISC laws their corporate counsel was shown.

There was clearly a decision on the part of the employees of the companies involved not to risk their own livelihoods by simply going along with what the government wanted.

I'd argue that major atrocities are possible via the combined impact of institutionally diffused acts of moral depravity such as those committed by our beloved tech companies.

Re: The NSA slide you haven’t seen

#154
Is it possible that the CEOs are in fact telling the truth, but are unaware/ignorant that at the carrier level (before reaching the ingress points), data headed to their respective networks/server farms is being "copied"?

Does Google, Apple, Skype, etc. physically own Internet infrastructure, or are they all leased lines from carriers?

If they owned any physical "lines", and the gov was tapping into these lines, then they would be lying about the direct access claim.

But if they don't own these lines, it seems the companies can't do anything about it, and that the telcos are the villains.

Apologies in advance if I'm oversimplifying.

Re: The NSA slide you haven’t seen

#155
post #135
post #54

Earlier quoted context omitted.

> you couldn't tap in without disturbing the optical signal Well of course you can't. If you're going to split it off to read it, then you're "disturbing" it by definition. Whether or not you can do such that it's not noticeable to the proper end parties, of course, is a different story.

What's to stop a direct packet copy? The line goes in, a digital device sees the packets, copies them bit for bit and sends the original to their destination and a copy to the NSA. Similar to headphone splitting.

I think most of the taps they're referring to involve tapping light directly off the fiber, which reduces the light intensity at the receiving end and can therefore be detected in theory at least

Interfering with existing amplifiers/signal boosters would be fairly hard to hide unless the NSA was solely responsible for that units maintenance, and I suspect that as a general rule they aren't. It's much easier to hide a tap at some random point along the line where nobody has any reason to visit

Re: The NSA slide you haven’t seen

#156

Earlier quoted context omitted.

Would such a splitter give you 1% of the messages passed, or 1% of a message?

These splitter work in the domain of light-pulses transmitted over a fiber. So you get 100% of the messages, but the flashes of light representing the bits will be much weaker. Probably this will mean that you have to put in much more effort to decode the signal than a usual network-device will need, and also probably means that you will have a higher number of errors in your data. On the other hand, if you'd tap onl…

It depends on the power budget of the fiber link. A 3db splitter would tap 50% of the power, but if this was planned for in advance it would be easily integrated in the long haul network.

Re: The NSA slide you haven’t seen

#157
post #18

Once again, I suggest everyone interested read James Bamford's book Shadow Factory. All these revelations regarding call metadata, PRISM collection (albeit under a different codename at the time), modern fiber taps, and even more are covered. You'll learn about how they shave fiber optic cables in order to intercept traffic and not be detected. You'll find out about the various facilities already reported, along with…

Thanks for this! I've been looking for more to read (I just went back and re-read 1984). ... I thought one of the points of Fiber was that you couldn't tap in without disturbing the optical signal? Did I just make that up in my head?

There are different non-disruptive techniques, two known methods being "shaving" the cable and the other involves bending the fiber optic cable at certain angles.

I wouldn't be surprised if there are other esoteric techniques that somehow allow NSA to monitor emanations through an intact fiber optic cable and its shielding.

Re: The NSA slide you haven’t seen

#158

For those with security clearances, clicking on a random HN link is risking your job and livelihood. It's easy to see a link to WikiLeaks and avoid that but when it's the WP posting it, not so much. These articles really need to be flagged/tagged by HN and by the newspapers that publish them. I don't want to see a TS/SCI-classified document and I don't want to be seen as seeking them out. I love the technical stories…

Did you really just ask HN to support Doublespeak?

Re: The NSA slide you haven’t seen

#159
Are we agreed that the Washington Post has had access to the full set of slides all along and are choosing to dribble them out, one by one?

If so I feel that there's a certain lack of ethics involved in this. We now have a slide recommending "direct access", after weeks of denials and pointless discussion about it that would have been much clarified and bolstered if this slide had been released. On the other hand, we still don't know the full context of the slides. Perhaps the next one says "But we don't have direct access yet, we are still working on that". Or perhaps it says "for direct access, get a warrant". We just don't know.

I understand the motives of the WP in releasing these slides one by one. It will undoubtably be maximizing the publicity and traffic they get from it. But I am not at all sure it is serving the public interest.

Re: The NSA slide you haven’t seen

#160
post #18

Once again, I suggest everyone interested read James Bamford's book Shadow Factory. All these revelations regarding call metadata, PRISM collection (albeit under a different codename at the time), modern fiber taps, and even more are covered. You'll learn about how they shave fiber optic cables in order to intercept traffic and not be detected. You'll find out about the various facilities already reported, along with…

Was expecting to find comment by tptacek explaining how WP's Craig Timberg has no journalistic integrity because "direct access" clearly doesn't mean the NSA gets whatever data it wants by whatever means necessary. Rather, "direct access" can only imply the NSA administers the credentials of each and every server and database existent, which clearly couldn't be true. Maybe he's busy. I'll check back.

How is this related to the comment you're replying to? I don't understand the connection.
Post reply on HN