Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

131–140 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#131
It seems this was meant to be declassified in 2032.. I guess by then they were hoping this would be so institutionalized and pervasive as to be the norm.

Also I wonder to what extent this is really used to hunt terrorists down and how much of it is used to gain political or economic advantages over other countries.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#132

Earlier quoted context omitted.

How long has https been an option with Facebook and messages? I don't think it was always required, if ever.

Connections secured with TLS aren't effective if a) you can compromise the CA, b) have the private keys, c) have cooperation of the appropriate company (most likely), d) have compromised the server, e) are aware of flaws in the encryption algorithm, f) weak keys have been used, or g) have compromised the client computer.

It's also not effective if h) TLS was never used in the first place. Facebook hasn't always been all that secure to eavesdropping.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#133
post #116

Earlier quoted context omitted.

The person is a user of storage media seized outside the U.s. Interesting, so everyone who ever hit a MegaUpload link is potentially a foreign entity?

Kind of puts into perspective why they would coordinate such a massive raid on Megaupload. The target may not have even been the data - merely seizing the data puts anybody who has accessed the megaupload website as an easy target.

You crossed the tinfoil line. Copyright infringement was sufficient motivation for the actions taken. The megaupload raid was not okay, but I am pretty sure Hollywood was behind it, not the NSA.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#134
I am curious: Suppose this is true and NSA analysts have the technical capability to access enormous amount of information with no authorization. But if they do do that, agains the law and the rules and their actions are recorded in the system, they could face penalties no? I mean I could kill someone with a hammer technically, that doesn't make hammer bad per se, does it ?

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#135

Um... surely this has to be a spoof. "Select foreignness factor"?? really? The user interface and way this is done just seems to amateur hour to believe this is actually true

The numbers seem way off and too keystone cop to be true. 20 terabytes is not large for the NSA.

It can search BCC?? Only the sender has them. so everything would have to be collected at each ISP (which isn't impossible).. but I think the guardian has been trolled.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#136

Um... surely this has to be a spoof. "Select foreignness factor"?? really? The user interface and way this is done just seems to amateur hour to believe this is actually true

The numbers seem way off and too keystone cop to be true. 20 terabytes is not large for the NSA. It can search BCC?? Only the sender has them. so everything would have to be collected at each ISP (which isn't impossible).. but I think the guardian has been trolled.

I'm calling this a troll.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#137
I wonder how Sencha (http://www.sencha.com/) feels about how the NSA is clearly using their ExtJS framework given the screenshots.

I guess this kind of puts different perspective to the whole debate that came from JSMin's "The Software shall be used for Good, not Evil." clause (http://wonko.com/post/jsmin-isnt-welcome-on-google-code) given that conceivably your open source framework might be a significant part of something like this.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#138
post #122
post #49

Earlier quoted context omitted.

I wouldn't for a second bet on it. A hidden service has exactly the same issue as traffic that exits the network. The topography looks like this. httpd > tor node > tor node > tor node > rendezvous point With enough monitoring, the location of the web server (or other hidden service) can just be found out by bombing the hidden service with traffic and seeing what end point lights up with traffic. With fine enough mon…

According to tor metrics only 17% of tor endpoints [1] and a similar percentage of relays [2] are in the USA. The kind of monitoring you propose would require a much higher portion of them to be under NSA control. [1] https://metrics.torproject.org/users.html [2] https://metrics.torproject.org/network.html?graph=relaycount...

Who said the NSA had to limit its nodes to the United States?
Post reply on HN