Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

41–50 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#41
post #32
post #29

This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…

Assume that Tor is broken. With this level of deep network monitoring, low-latency onion routing is essentially useless.

Hidden services are still secure, presumably, because there is no exposed section of the network to inspect. All they can do is monitor and do statistical analysis, and maybe mess with the traffic to try to get more ideas of flow.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#42
post #33

Holy shit... Apparently, the only way to ensure privacy is to go Stallman . Funny how yesterday's "conspiracy crackpot" became today's visionary.

Stallman never was a conspiracy crackpot, he always was a visionary. The only thing that changed is some people's judgment of him.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#43
My real issue with this isn't so much the fact that the NSA monitors everything I say and do. Its the fact that there is nothing preventing the NSA from obtaining insider information that can be exploited for personal financial gain.

I mean what stops an NSA analyst from being able to spy on an acquisition negotiation between corporation executives? What prevents that analyst from investing in the stock market using valuable info like this?

There really needs to be more accountability and transparency within the NSA.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#44
post #8

The Guardian strongly implies this system is used to intentionally target US citizens in violation of the law, but then admits that would be "illegal." I wonder if the leaked presentation touches on this point.

The Guardian doesn't 'admit' anything (it wasn't hiding anything in the first place), and legality doesn't predict whether actions are being taken or not.

>I wonder if the leaked presentation touches on this point.

That seems unlikely to me, as this is a technical presentation.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#45
post #31

From the slides http://www.theguardian.com/world/interactive/2013/jul/31/nsa... "Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users" Does this mean using VPN is not very safe from dragnet?

If Google, Facebook, et al provide direct access to users' data, I'm fairly certain such critical infrastructure as VPN is also under NSA control.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#46
post #15

At what point do the mathematical limits of data mining kick in here? How useful is all this information? I'm not an expert in this area of mathematics, so I could be wrong, but my impression is that as the haystack becomes larger the problem of false positives becomes more and more severe. As a data miner, what you want is the maximum number of "hits" (of whatever you're trying to hit) with the minimum number of mis…

so let's say there's a law that says "any American company doing business with a company that does business with a known terrorist organization will have a bad day"

you don't need to use some kind of fancy data mining algorithm for this to work (generating false positives), you just need a ho-hum graph traversal algorithm and unbelievable amounts of graph data to generate "candidates for investigation".

US Company A -> intermediate 1 -> known terrorist group B

US Company A -> intermediate 2 -> known terrorist group B

US Company A -> intermediate 3 -> known terrorist group B

Each set of links is just one lead to investigate, but having a giant graph to work off of would make generating those leads simply. You might find out that intermediate 1 is a local falafel delivery place that "US Company A" uses for lunch catering. Can probably strike that one off the list. intermediate 2 is a utility (no choice but to use the local water monopoly), but intermediate 3 is a material supplier that employs several low level delivery guys from known terrorist group B, and the founder of the company is a cousin of the founder of known terrorist group B.

So I'd wager it's not as simple as just running an algorithm and automatically sending out Skynet drones to blow things up. There's some kind of more subtle assessment being made, with the systems just providing help to the analysts.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#47
post #34
post #30

Slide 6 of the presentation clearly shows that pretty much every government is in on the program, with heavy concentration in western Europe. One question, how did the dot in China get there? http://www.theguardian.com/world/interactive/2013/jul/31/nsa...

And look at slide 17: "Show me all VPN startups in country X, and give me data so I can decrypt and discover users ." Holy crap. Is all encryption broken?

I find the "Show me all exploitable machines in country X" on page 24 pretty scary as well

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#48
post #35

You have to admit these guys are working on some cool problems. If you don't have a problem with the legality of it or potential for misuse it looks like a really interesting place to work.

That's exactly how they get people to work on it in the first place. If you have no conscience there are lots of places where you can work on 'cool problems'.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#49
post #32

Earlier quoted context omitted.

Assume that Tor is broken. With this level of deep network monitoring, low-latency onion routing is essentially useless.

Hidden services are still secure, presumably, because there is no exposed section of the network to inspect. All they can do is monitor and do statistical analysis, and maybe mess with the traffic to try to get more ideas of flow.

I wouldn't for a second bet on it. A hidden service has exactly the same issue as traffic that exits the network. The topography looks like this.

    httpd > tor node > tor node > tor node > rendezvous point 
With enough monitoring, the location of the web server (or other hidden service) can just be found out by bombing the hidden service with traffic and seeing what end point lights up with traffic. With fine enough monitoring you wouldn't really need long to find out the real location of the server. It's just not something the network can effectively hide, even if it used chaff (padding) to hide the wheat.

There's practical attacks for enumerating hidden service public keys, and so I wager that there's somebody somewhere with a complete map of the real server locations as well.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#50
post #33

Holy shit... Apparently, the only way to ensure privacy is to go Stallman . Funny how yesterday's "conspiracy crackpot" became today's visionary.

How does browsing the web via e-mails and cron jobs make for more privacy?
Post reply on HN