Live data from Hacker News

The NSA slide you haven’t seen

washingtonpost.com

191–200 of 202 posts

Re: The NSA slide you haven’t seen

#191
post #2

> "collection directly from the servers" So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direct access would be better than these slides. I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Or maybe even the NSA, but we know they share inaccuracies under oath, so maybe that isn't worth so much.

Or the slides use shortened terminology, because it's sorta equivalent in that the processes seem very streamlined.

It's not direct from the servers, but to the analysts it might as well could be the same. These slides might have been meant for tech-illiterate people, saying that might be clearer.

Re: The NSA slide you haven’t seen

#192
post #18

Once again, I suggest everyone interested read James Bamford's book Shadow Factory. All these revelations regarding call metadata, PRISM collection (albeit under a different codename at the time), modern fiber taps, and even more are covered. You'll learn about how they shave fiber optic cables in order to intercept traffic and not be detected. You'll find out about the various facilities already reported, along with…

Was expecting to find comment by tptacek explaining how WP's Craig Timberg has no journalistic integrity because "direct access" clearly doesn't mean the NSA gets whatever data it wants by whatever means necessary. Rather, "direct access" can only imply the NSA administers the credentials of each and every server and database existent, which clearly couldn't be true. Maybe he's busy. I'll check back.

I think this is a bit of a cheap shot at tptacek so will defend him in his absence.

First, when it comes to programs by US intelligence agencies (both previously known, currently revealed, and yet to be revealed) there are multiple categories of evaluation: namely, ethical, legal, constitutional.

Generally speaking, everything the Feds are doing is legal in the sense that it follows a specific legal process that was setup in the scare over terrorism, which both expanded the powers of the executive branch and created "shadow courts" which presumably provide some checks and balances in the system. Of course, we can't really know how reliably these work since the process for National Security Letters and other aspects itself is secret. Nonetheless, there are specific process in places that seem generally speaking to be followed. How often there are "exceptions" to this process is difficult to ascertain, and has not really been a focus in the present debate.

When it comes to constitutionality, it is a hotly debated topic among Americans partially because it was the bedrock of the American state, but an increasing number of Americans (including justices) either aren't knowledgable or don't care about the specifics of the constitution. This is a huge topic, but it is sufficient to say that something can be unconstitutional (even blatantly so) and nonetheless be legal. In this specific case, it is difficult to know how or whether the protection against "unreasonable" searches includes storage of metadata associated with phonecalls that can be searched by an analyst.

Then, more broadly, there are a wide representation of ethical issues. For example, it is completely legal and constitutional to spy on non US citizens, but are there any boundaries that should be set on what is and is not acceptable behavior? My strongly held view is that, at least when it comes to US hq'ed companies with a large foreign user base that they provisions in places for non US citizens should at the very least be the same as those for US citizens. However, saying that something should exist and implementing it are two different things, and one is considerably more difficult than the other.

So this is all basically to defend tptacek and say that it is important to differentiate when accusing the US government of "crimes." In other words, there are lots of unethical things that you can do that are perfectly legal.

Re: The NSA slide you haven’t seen

#193
post #139

Earlier quoted context omitted.

(D) the slide doesn't actually say 'direct access', but says 'collection directly from the servers of', which is different. My browser pulled the comment I'm replying to right now 'directly from the servers of' HN, but I don't have 'direct access' to HN.

> (D) the slide doesn't actually say 'direct access', but says 'collection directly from the servers of', which is different. My browser pulled the comment I'm replying to right now 'directly from the servers of' HN, but I don't have 'direct access' to HN. The slide I'm talking about ( http://www.washingtonpost.com/wp-srv/special/politics/prism-... ) states: "collection directly from the servers of these U.S. Service…

> In a traditional warrant situation, the data would be collected by the companies and sent to the requesting agency that provided a warrant.

Yes, that's what PRISM is. Warrant compliance, automated and streamlined.

Re: The NSA slide you haven’t seen

#194
post #192

Earlier quoted context omitted.

Was expecting to find comment by tptacek explaining how WP's Craig Timberg has no journalistic integrity because "direct access" clearly doesn't mean the NSA gets whatever data it wants by whatever means necessary. Rather, "direct access" can only imply the NSA administers the credentials of each and every server and database existent, which clearly couldn't be true. Maybe he's busy. I'll check back.

I think this is a bit of a cheap shot at tptacek so will defend him in his absence. First, when it comes to programs by US intelligence agencies (both previously known, currently revealed, and yet to be revealed) there are multiple categories of evaluation: namely, ethical, legal, constitutional. Generally speaking, everything the Feds are doing is legal in the sense that it follows a specific legal process that was…

I'm mocking the "direct action" fabricated controversy. I apologize that wasn't more clear.

I fully expected Craig Timberg to be attacked, just like Glenn Greenwald was.

It is unfair that I'm using a nym, whereas tptacek's a real identity.

It may be unfair to single out tptacek out of the mob of people banging the "direct action" drum. He stands out here on HN. Since I'm using a nym, I won't belabor the point.

Re: The NSA slide you haven’t seen

#195
post #5

Earlier quoted context omitted.

So, if you're under oath, you're not allowed to lie. And if you're read into an SCI program that controls the disclosure of the existence of such access, you're most definitely not allowed to say anything about it (or, in many cases, even acknowledge that such a thing exists). There is no way someone would risk perjuring themselves OR disclosing classified information under oath.

Not saying anything would say a lot. It would be enough to affect consumer confidence in that products are not being accessed by the NSA.

I wonder if it could be construed as disclosing classified info by taking the 5th when asked. You didn't say anything, but did you say anything without saying anything?

Re: The NSA slide you haven’t seen

#196
post #10

It may have been published at the Post for the first time, but Guardian released this over a month ago. http://www.guardian.co.uk/world/2013/jun/08/nsa-prism-server...

There are a number of differences between the two slides including the Post version having no redactions.

Ah, so that's what it is. This morning, we got an e-mail : "If you open this link on any computer, including your home computer, you are required to report this through Security channels as a classified spillage. " I was wondering why the Post was being singled out. (I had not yet had a chance to look at it.)

Re: The NSA slide you haven’t seen

#197
post #10

Earlier quoted context omitted.

There are a number of differences between the two slides including the Post version having no redactions.

Ah, so that's what it is. This morning, we got an e-mail : "If you open this link on any computer, including your home computer, you are required to report this through Security channels as a classified spillage. " I was wondering why the Post was being singled out. (I had not yet had a chance to look at it.)

excuse me?

Re: The NSA slide you haven’t seen

#198

Earlier quoted context omitted.

Ah, so that's what it is. This morning, we got an e-mail : "If you open this link on any computer, including your home computer, you are required to report this through Security channels as a classified spillage. " I was wondering why the Post was being singled out. (I had not yet had a chance to look at it.)

excuse me?

Hey tomgirl1, welcome to Hacker News. Good to have you here.

It might be a good idea to read up on the guidelines [1] a bit though, since it seems your comments, while generally with good intent, often don't contribute much to the discussion at hand, like the comment I'm replying to here.

Another good way to get a feel for what is appreciated and what not is to check a bit of pg's comments [2]. You'll quickly get a feel of what's considered proper discourse and what isn't.

Good luck and enjoy your stay here!

[1] http://ycombinator.com/newsguidelines.html [2] https://news.ycombinator.com/threads?id=pg

Re: The NSA slide you haven’t seen

#199
post #192

Earlier quoted context omitted.

I think this is a bit of a cheap shot at tptacek so will defend him in his absence. First, when it comes to programs by US intelligence agencies (both previously known, currently revealed, and yet to be revealed) there are multiple categories of evaluation: namely, ethical, legal, constitutional. Generally speaking, everything the Feds are doing is legal in the sense that it follows a specific legal process that was…

I'm mocking the "direct action" fabricated controversy. I apologize that wasn't more clear. I fully expected Craig Timberg to be attacked, just like Glenn Greenwald was. It is unfair that I'm using a nym, whereas tptacek's a real identity. It may be unfair to single out tptacek out of the mob of people banging the "direct action" drum. He stands out here on HN. Since I'm using a nym, I won't belabor the point.

As I assume tptacek would also say, the specifics of the "direct access" are rather a big deal. If the access is constrained to NSLs approved by judges in regulated quantity, you have a legal process. Perhaps there is no independent oversight or accountability to the public at large, yet you still have legality.

However, if any analyst can at whim look at the info associated with any gmail account / Facebook user / etc. then you have a clearly extra-legal approach with absolutely no accountability.

Also, there is a significant difference between capacity and use. If a analyst or a sys admin for the NSA has capacity to view things but does not actually have permission from the NSA to use that capability absent an NSL, then

To be honest, to date nothing has emerged that makes it seem that the NSA has this sort of capacity, except when it comes to Verizon phone calls, although I don't think we know much if anything about the NSA's downstream capabilities when it comes to major Silicon Valley firms.

In short, I assume that Google, Facebook, etc. are telling an important truth when they say that access is limited to legal processes. Whether or not the NSA also has and uses downstream access to similar data is another question altogether.

Re: The NSA slide you haven’t seen

#200

Earlier quoted context omitted.

Maybe the creepy illuminati hoodie makes more sense now.

In have to tell you, it warms my skeptic heart to see HN so damn discerning over all this info regarding the true state of the world; HN has really surprised me at how many people here are really paying attention!!

It was said in jest.
Post reply on HN