Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

121–130 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#121
post #12

This is brilliant, I love the screenshots: Foreignness factor: The person has stated that he is located outside the U.S. Human intelligence source indicates person is located outside the U.s. The person is a user of storage media seized outside the U.s. Foreign govt indicates that the person is located outside the U.s. Phone number country code indicates the person is located outside the U.s. Phone number is register…

> It's quite easy to lose the protections of a U.S. citizen indeed!

That, coupled with the fact that they only require 51% certainty in the foreignness factor makes me think this is intentionally designed to make every single person they come across a subject to surveillance.

I can see Weasel terms like "use of storage media seized outside of the U.s." be extended to mean pretty much anything.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#122
post #49

Earlier quoted context omitted.

Hidden services are still secure, presumably, because there is no exposed section of the network to inspect. All they can do is monitor and do statistical analysis, and maybe mess with the traffic to try to get more ideas of flow.

I wouldn't for a second bet on it. A hidden service has exactly the same issue as traffic that exits the network. The topography looks like this. httpd > tor node > tor node > tor node > rendezvous point With enough monitoring, the location of the web server (or other hidden service) can just be found out by bombing the hidden service with traffic and seeing what end point lights up with traffic. With fine enough mon…

According to tor metrics only 17% of tor endpoints [1] and a similar percentage of relays [2] are in the USA. The kind of monitoring you propose would require a much higher portion of them to be under NSA control.

[1] https://metrics.torproject.org/users.html [2] https://metrics.torproject.org/network.html?graph=relaycount...

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#123

Reading these slides, I'm trying to parse what these slides do or do not say. I'd like to leave aside the speculation about what the NSA is probably doing. First of all, XKeyscore seems to be primarily about the frontend query interface rather than the backend data storage, at least as far as I can tell. It looks like you can basically query their database by email address and get a set of records (email, chat, http…

Note regarding the amount of items, that the presentation is from 2008, and they claim to only be able to store 3 days worth of full data capture.

Regarding ability to query the full text of emails, this program does not seem to indicate that it would collect the data directly from the services servers in anyway. But consider that they do indicate the ability to monitor web traffic at the protocol level. Capturing e-mail is no harder, so it'd be surprising if they're not.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#124
post #33

Holy shit... Apparently, the only way to ensure privacy is to go Stallman . Funny how yesterday's "conspiracy crackpot" became today's visionary.

This is by far the best guide I've found to do exactly that:

http://crunchbang.org/forums/viewtopic.php?id=24722

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#125
post #107

Earlier quoted context omitted.

You probably don't need to break the encryption because eventually all traffic has to exit the VPN's company's endpoint, and at that point it can be captured. Meta data such as the browser's fingerprint can be used to tie traffic to an individual, for example, if you see them log in to a regular HTTP site with an email or a username, this information could probably be used to figure out who they are. Armed with this…

> all traffic has to exit the VPN's company's endpoint, and at that point it can be captured. If the only thing they're dealing with is VPN's used as a private proxy for access to the public internet, you're right, and if so it's not so troubling (well, as in it is "only" just as troubling as having them access everyones web traffic). But arguably most VPN traffic is exiting inside private networks and are intended f…

The slide talks about VPN startups. Some corporate VPN connections could be also compromised for a number of reasons. There are possibly undisclosed weaknesses in the "gold standard" VPN solutions, such as OpenVPN, as well as the protocols they use.

Security's dirty secret is that security is an unobtainable goal. The goal of designing secure systems isn't to create something impenetrable (i.e. secure), but something that's almost impossible to penetrate. 100% secure systems are about as common as rooster eggs.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#126
post #69

I don't think I have been more conflicted about this. I've just been talking to my cofounders about the technical feasibilities of XKeyScore, and honestly, our back-of-napkin engineering configurations indicate this is really an awesome project to be working on. On the other hand, this is categorically 'evil' by my and my cofounders' ethical standards, and really, no one is safe. And that bugs the hell out of me. On…

> On the one hand: really fucking cool.

I just don't see how this could be considered "cool". There are plenty of other marvels of modern computing that aren't so sinister.

I think a better word for this is "scary", due to the level of cooperation from corporations and the level of secrecy it was running under for so long.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#127
post #29

This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…

> edit: Gmail messages must only be captured when they leave the Google network.

It seems easier for the NSA to tap datacenter datacenter fiber links inside Google's network.

Why worry about decryption when you can have Google's frontend servers do it for you?

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#129

Reading these slides, I'm trying to parse what these slides do or do not say. I'd like to leave aside the speculation about what the NSA is probably doing. First of all, XKeyscore seems to be primarily about the frontend query interface rather than the backend data storage, at least as far as I can tell. It looks like you can basically query their database by email address and get a set of records (email, chat, http…

It doesn't show reading full emails in the screenshots, but the sentence right underneath reads: "The analyst then selects which of those returned emails they want to read by opening them in NSA reading software."

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#130
post #7

I wonder how they store all that. Surely a side benefit of this could be NSA contributions to CS journals about database techniques. Also I doubt the veracity of the claim that they collect "nearly everything". Wouldn't they show up on, say, Sandvine's Internet traffic reports? I think it's more likely this claim is made simply to generate FUD in the general population.

Another benefit could be realised in the future if historians and linguists manage to get access to all this data. I imagine that researchers of the social sciences would end up enjoying the same sort of large-scale collaborative projects that particle physicists or genomic bioinformaticians currently have with their huge datasets.
Post reply on HN