This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…
XKeyscore: NSA program collects 'nearly everything a user does on the internet'
101–110 of 641 posts
Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#102This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…
The main thing that this new release reveals is not the scope of the data collection, but confirmation that analysts are given free reign to perform queries. Until this, there was an outside chance that the system required all database queries to be signed by a Judge prior to execution. This is not the case though; all queries are processed immediately, with essentially nothing more than a repo commit message as just…
It will be interesting to go back through all of those statements with this new information/evidence on hand.
Greenwald has timed this well. He put out enough information early on to give Snowden opponents enough rope with which to hang themselves.
Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#103Nice pre-emptive "attack" by Greenwald today, just before the NSA hearings.
I was worried the leaks may have peaked a bit early, but this was very well timed.
Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#104One of the screen shots: http://static.guim.co.uk/sys-images/Guardian/Pix/audio/video... says: Top Secret Comm(?) REL() to USA, AUS, CAN, GBR, NZL confirming the previous suspicions that many other governments are on board. Der Spiegel actually has reported a few weeks back about XKeyscore [1] and that it is used by the BND (Germany's NSA). I.e. all this data is also available to the NSA equivalents of Australia, Can…
Those are the Five Eyes countries: http://en.wikipedia.org/wiki/Five_Eyes
"This was a secret treaty, allegedly so secret that it was kept secret from the Australian Prime Ministers until 1973."
This is indeed a trend, and I speculate that NSA (and NSA-like entities in the other 4 eyes/countries) probably communicate information and abilities to prime ministers and presidents of the respective countries very selectively.
Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#105Interesting; it appears someone failed to redact some data from the slides. In the Facebook chat example, the message is "to" 1536051595. Using the Facebook Graph API, we can gather information based on this ID: http://graph.facebook.com/1536051595 Which leads us to the Facebook profile ( https://www.facebook.com/arash.gorjipour.5 ) of an individual, real or contrived, named "Arash Gorjipour". His email address and p…
They may have used an existing public profile since he's already displayed it openly. He's a realestate broker after all so, presumably, he's got "nothing to hide".
Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#106Interesting; it appears someone failed to redact some data from the slides. In the Facebook chat example, the message is "to" 1536051595. Using the Facebook Graph API, we can gather information based on this ID: http://graph.facebook.com/1536051595 Which leads us to the Facebook profile ( https://www.facebook.com/arash.gorjipour.5 ) of an individual, real or contrived, named "Arash Gorjipour". His email address and p…
Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#107From the slides http://www.theguardian.com/world/interactive/2013/jul/31/nsa... "Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users" Does this mean using VPN is not very safe from dragnet?
You probably don't need to break the encryption because eventually all traffic has to exit the VPN's company's endpoint, and at that point it can be captured. Meta data such as the browser's fingerprint can be used to tie traffic to an individual, for example, if you see them log in to a regular HTTP site with an email or a username, this information could probably be used to figure out who they are. Armed with this…
If the only thing they're dealing with is VPN's used as a private proxy for access to the public internet, you're right, and if so it's not so troubling (well, as in it is "only" just as troubling as having them access everyones web traffic).
But arguably most VPN traffic is exiting inside private networks and are intended for machines within those private networks. If they are capable of breaking or circumventing the crypto of those, then that's troubling at a whole different level because it potentially means massive unknown weaknesses in either specific crypto products, or in algorithms that have been assumed to still be reasonably safe.
Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#108Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#109>Foreignness factor I know NSA's mandate is to spy on foreigners , but it's still very jingoistic and xenophobic that not being American makes it OK to spy on you.
Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'
#110>How do I find a cell of terrorists that has no known connection to strong-selectors?
>Answer: Look for anomalous events
>E.g. Someone whose language is out of place for the region they are in
>Someone who is using encryption
>Someone searching the web for suspicious stuff
Lovely. Suspicious stuff and encryption. But wait! There's more!
>Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users.
Wait... what? I really hope that doesn't mean what it sounds like it means.
>Slide 22 [regarding determining who authored a Jihadist document] redacted.
Well that's interesting.
>Show me all the exploitable machines in country X.
That's cool. I'm guessing this is what Snowden meant by weak endpoint security.
>Over 300 terrorists captured using intelligence generated from X-KEYSCORE
>Slides 29 and 30 regarding this redacted.
What a shame.