Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

201–210 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#201
post #122
post #49

Earlier quoted context omitted.

I wouldn't for a second bet on it. A hidden service has exactly the same issue as traffic that exits the network. The topography looks like this. httpd > tor node > tor node > tor node > rendezvous point With enough monitoring, the location of the web server (or other hidden service) can just be found out by bombing the hidden service with traffic and seeing what end point lights up with traffic. With fine enough mon…

According to tor metrics only 17% of tor endpoints [1] and a similar percentage of relays [2] are in the USA. The kind of monitoring you propose would require a much higher portion of them to be under NSA control. [1] https://metrics.torproject.org/users.html [2] https://metrics.torproject.org/network.html?graph=relaycount...

The question isn't how many endpoints the NSA has, it is how much bandwidth they have at the endpoints (actually, it is more about how many unique users use their endpoints). But, assume that 1% of Tor connections goes through an NSA exit node. 1% of that 1% would go through both an NSA exit node at both ends, and is therefore comprimised. Tor tries to mitigate this by always using the same exit nodes for your connection (reducing the chance of ever being compromised, but if you are compromised, it is for much longer). However, inevitably you occasionally do need to change your exit nodes, which gives the NSA another roll of the dice. Additionally, when talking about drag-net surveillance, 1% of 1% is still a lot.

The bigger protection is the ease with which the NSA can mount this attack on TOR. I have no doubt that they could do it, however I do question if they can do it on a massive scale.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#202
post #73

Earlier quoted context omitted.

No javascript tracking. Very strange behaviour (therefore, less behaviour tracking). That's what I can think of.

Honestly, if the NSA wanted to know what Stallman was up to, they'd apply the $5 wrench technique ( http://xkcd.com/538/ ). All the tin-foil in the world can't prevent them from getting what they want if you're suddenly a Person of Interest.

You're completely missing the point -- it's unfeasible, unpractical, and unproductive hitting millions of people on the head with $5 wrenches. This is the entire point -- they can do it easily with everyone now, they're not hitting people with wrenches -- that would invoke suspicion and retaliatory response that would curtail their legal powers to snoop around.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#204
post #181

Earlier quoted context omitted.

Interesting. So then this can be done with zero assistance from service providers? Could providers have taken any steps to render that stream of information inaccessible? And if so, is it a costly effort?

Yes, use HTTPS for everything. It's not a surprise that all the logos in this PowerPoint have since moved large portions of their traffic to SSL. SSL isn't perfect (you can still see what domain someone is requesting), but it does prevent a lot of the snooping outlined in the presentation (without vendor participation, it's always possible that Facebook is siphoning off their messages).

Why would we assume that TLS is safe? The NSA could just as easily compromise the CAs and get all the certificates they need.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#205
post #73

Earlier quoted context omitted.

No javascript tracking. Very strange behaviour (therefore, less behaviour tracking). That's what I can think of.

Honestly, if the NSA wanted to know what Stallman was up to, they'd apply the $5 wrench technique ( http://xkcd.com/538/ ). All the tin-foil in the world can't prevent them from getting what they want if you're suddenly a Person of Interest.

https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#206

Just a friendly reminder that if you looked at the slides, you have read a classified document, and therefore are guilty of a Federal felony. Cheers!

And the NSA is passing your details on to the FBI riiiight about now.

Enjoy your federally-funded vacation!

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#207

Earlier quoted context omitted.

How long has https been an option with Facebook and messages? I don't think it was always required, if ever.

Connections secured with TLS aren't effective if a) you can compromise the CA, b) have the private keys, c) have cooperation of the appropriate company (most likely), d) have compromised the server, e) are aware of flaws in the encryption algorithm, f) weak keys have been used, or g) have compromised the client computer.

Compromising the CA isn't as powerful as most would think. It does allow you to MITM, however it does not allow you to do so invisibly. Someone who is paying attention to the public key could notice that it changed.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#208
post #102

Earlier quoted context omitted.

The main thing that this new release reveals is not the scope of the data collection, but confirmation that analysts are given free reign to perform queries. Until this, there was an outside chance that the system required all database queries to be signed by a Judge prior to execution. This is not the case though; all queries are processed immediately, with essentially nothing more than a repo commit message as just…

Exactly. There were a lot of people from the government that came out in the past few months and said there are checks and balances and a lot of oversight in these processes. That clearly isn't true. It will be interesting to go back through all of those statements with this new information/evidence on hand. Greenwald has timed this well. He put out enough information early on to give Snowden opponents enough rope wi…

And if his comment further down in the thread is anything to go by then there is a lot more to come.

It's an interesting problem for the talking heads: How much will be revealed? They're caught between a rock and a hard place, if they start telling the truth they might reveal something that the leaked docs don't support, but if they tell a lie they might be found out.

This trickle strategy is working very well. The best cause of action for the people under the microscope would be to shut up and if they are compelled to talk to say the absolute minimum but to still tell the truth.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#209
post #181

Earlier quoted context omitted.

Interesting. So then this can be done with zero assistance from service providers? Could providers have taken any steps to render that stream of information inaccessible? And if so, is it a costly effort?

Yes, use HTTPS for everything. It's not a surprise that all the logos in this PowerPoint have since moved large portions of their traffic to SSL. SSL isn't perfect (you can still see what domain someone is requesting), but it does prevent a lot of the snooping outlined in the presentation (without vendor participation, it's always possible that Facebook is siphoning off their messages).

So let's assume the NSA still has these capabilities (a fairly reasonable assumption), and with SSL/HTTPS as a fairly feasible security option, how would these capabilities be possible? Either services aren't committed to and endorsing the use HTTPS/SSL and/or they are actively granting access to user information. Are those two reasonable conclusions?

I'm trying to understand why services are not taking a more active role in protecting their users' information if they are claiming to taking our privacy seriously.

To me, it comes down to being either incompetent or a liar, or both.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#210

>How do I find a strong-selector for a known target? >How do I find a cell of terrorists that has no known connection to strong-selectors? >Answer: Look for anomalous events >E.g. Someone whose language is out of place for the region they are in >Someone who is using encryption >Someone searching the web for suspicious stuff Lovely. Suspicious stuff and encryption. But wait! There's more! >Show me all the VPN startup…

>> Show me all the exploitable machines in country X.

> That's cool. I'm guessing this is what Snowden meant by weak endpoint security.

That, plus things like Microsoft and Apple operating systems. Don't forget: it's proven they work with the NSA, so backdoors certainly are guaranteed (plus, with Microsoft, we also know they hand 0-day exploits over to the NSA before they're fixed, plus you benefit from all the viruses, trojans, etc.). Again, if you missed it, start migrating now: https://prism-break.org/

Post reply on HN