This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…
> how are they getting all Facebook private messages and Gmail?
Slide 6 of the presentation clearly shows that pretty much every government is in on the program, with heavy concentration in western Europe. One question, how did the dot in China get there? http://www.theguardian.com/world/interactive/2013/jul/31/nsa...
I just noticed that the presentation is from 2008. Imagine what capabilities they've added in the last five years.
Interesting; it appears someone failed to redact some data from the slides. In the Facebook chat example, the message is "to" 1536051595. Using the Facebook Graph API, we can gather information based on this ID: http://graph.facebook.com/1536051595 Which leads us to the Facebook profile ( https://www.facebook.com/arash.gorjipour.5 ) of an individual, real or contrived, named "Arash Gorjipour". His email address and p…
In keeping with that line of thought would it not be better to redact the information you are presenting? I don't see why you need to write it out in full.
You could say 153xxxxxxx and "Arxxx Goxxxxxxx" just to be sure and if you need to post links you could use a URL shortener.
If a non-US resident or NSA target posts a thread on HN, and a US person replies to the thread, is the US person now open to unlimited data collection?
Alternately, if you Facebook-like the same thing an NSA target has, are you then subject to unlimited data collection?
This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…
The main thing that this new release reveals is not the scope of the data collection, but confirmation that analysts are given free reign to perform queries. Until this, there was an outside chance that the system required all database queries to be signed by a Judge prior to execution. This is not the case though; all queries are processed immediately, with essentially nothing more than a repo commit message as justification, and basically any analyst can do it.
From the slides http://www.theguardian.com/world/interactive/2013/jul/31/nsa... "Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users" Does this mean using VPN is not very safe from dragnet?
If Google, Facebook, et al provide direct access to users' data, I'm fairly certain such critical infrastructure as VPN is also under NSA control.
I thought Google, Facebook etc. only had to provide access as they are compelled to under US law? If the VPN provider was non-US (and did not/claimed they did not keep logs of user activity), would this help? Or do you reckon the NSA has the ability to get at the data without the cooperation of the VPN provider? It would be great to have a couple of slides revealed on this area.
This bit both somewhat limits the impact and makes Greenwald et. al.'s claims that most everything is being Hoovered up a lot more credible: " The XKeyscore system is continuously collecting so much internet data that it can be stored only for short periods of time. Content remains on the system for only three to five days, while metadata is stored for 30 days. One document explains: "At some sites, the amount of dat…
But this was written in 2008. Storage capacity could/must have increased massively since then.