Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

341–350 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#341
post #225

The thing that blows my mind, is you hear over and over again about Billions of dollars being spent on large software projects for the government that seem fairly simplistic that ultimately fail. The NSA is accomplishing some pretty impressive things, what are they doing differently?

Hiring mathematicians and computer scientists instead of MBAs and public policy people.

Probably also not having to follow government contracting rules (lowest bidder, preferring minorities and veterans) because who would have the authority to review their purchases?

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#342
post #218
post #29

This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…

>This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. It has become a bit of a pet peeve of mine recently to see self-aggrandizing comments from users around the net about how "we should have known" and "none of this is new." I'm a practically addicted news j…

From the slides, apparently a node in the system just connects at an ISP or peering site and grabs all the packets. Then they essentially 'parse' the packets to TCP/IP sessions, logical user sessions, e-mail messages, etc.

Then back at HQ, can send the node what are essentially 'filters' to return 'alerts' and the associated content.

So, point: As a system, it's quite obvious. As software, it's quite routine.

And, from their description of working with anomalies, they are being just intuitive and elementary and not at all advanced or powerful.

It would appear that a terrorist Internet user could do fairly well beating that system by using a proxy server also used by many other Internet users and also using a lot of strong encryption -- PGP used well might be strong enough.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#343

Earlier quoted context omitted.

"You can be completely correct and still be a crackpot." Not really. At that point, you are just using the term as an ad hominem in a childish attempt to ward off cognitive dissonance. You don't win an argument by calling the other guy a weirdo.

His observations are correct, but his conclusions are incorrect, just as people like Glenn Beck start out with facts and end up with paranoid delusions and fantasies. I think Stallman's observations are valid, but his method of dealing with the implications of those observations are impractical, if not completely wrong.

When you are done attacking Stallman with a false analogy, would you care to name a few of his invalid conclusions?

More specifically, what is so impractical or "completely wrong" about not using smartphones?

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#344
post #292
post #218

Earlier quoted context omitted.

>This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. It has become a bit of a pet peeve of mine recently to see self-aggrandizing comments from users around the net about how "we should have known" and "none of this is new." I'm a practically addicted news j…

> It has become a bit of a pet peeve of mine recently to see self-aggrandizing comments from users around the net about how "we should have known" and "none of this is new." I agree that "know" is a bit too glorifying. I propose "suspected". I don't find this surprising at all. Practically 99.99% of a normal user's Internet activity is centered on Facebook, Google (including Gmail) and a handful of other sites. The a…

I have nothing wrong with people having suspected it for a long time, or even saying so. I suspected it for a long time as well. My problem is with the attitude many people seem to have once evidence confirming those suspicions comes out and they go on about how the evidence means nothing because they knew it all along. No, the evidence confirms their suspicions, which makes it incredibly important!

Ultimately, whether they intend to or not, such statements end up making other people who are hearing about this for the first time more complacent about it because they come into the comments and see a bunch of people going on about how it's nothing new and therefore the new information is no big deal.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#345

Earlier quoted context omitted.

First of all: keep the staggering to a minimum. Second: realizing that "we should have known" and "none of this is new" isn't so much about reading news articles and being "plugged in", but rather having an understanding of how the Internet works. To oversimplify greatly, you're essentially playing a very precise game of telephone between around 10-20 different people, and usually about 1-3 different publicly-owned c…

Maybe I am just having trouble seeing the point of "see I was right all along"? Why would we be upset at the newcomers to the ranks of the enlightened? I would prefer to just nod, point to the preexisting evidence, instead of driving people away with unproductive "I told you so" hostility.

I agree completely. We need more education on the subject as opposed to back patting, and we definitely don't need to attack the very people that need to hear and understand the reporting most, as the person you are replying to is doing, by calling them naive. A bit sad imho.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#346
post #218
post #29

This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…

>This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. It has become a bit of a pet peeve of mine recently to see self-aggrandizing comments from users around the net about how "we should have known" and "none of this is new." I'm a practically addicted news j…

For me, personally, it's not about "look how smart I am" as it is genuine surprise that the story actually seems to be sticking this time.

I'm glad that people are paying attention, but especially early on, it wasn't entirely clear that Snowden's leaks were substantially different from the leaks that have been coming out of the NSA for years that never got traction in the media.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#347

Earlier quoted context omitted.

I'm calling this a troll.

If you or I was in charge of the NSA there would not be a visual basic interface or a select foreignness dropdown. I'm calling bullshit on this.

In the PRISM related documents they used that exact term, "foreignness".

http://www.theatlantic.com/technology/archive/2013/06/bombsh...

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#348

Earlier quoted context omitted.

Not exactly. Compromising a CA would let them fool a browser into thinking that a fake Google certificate is a real one. However, if Google were diligent, they could publish their valid cert signatures anywhere they like, and users could check the signatures of the certs that are presented as genuine. The TSA can't crack or impersonate a cert at will; they can only 1) try to trick you into accepting a phony one or 2)…

Wouldn't having the private cert allow you to decrypt all communications encrypted using that cert?

Traditionally you generate an SSL public and private key, and send only the public key to the certificate authority for signing, so compromising the certificate authority doesn't give you the private key.

It does however give you the ability to issue yourself new public keys to conduct man-in-the-middle attacks [1]. If you compromise the same CA as the site whose traffic you're trying to intercept, you can bypass certificate pinning which is supposed to detect MITM attacks. So for example you can MITM gmail without certificate pinning detecting it if you compromise Verisign, Equifax or GeoTrust [2]

[1] http://googleonlinesecurity.blogspot.co.uk/2011/08/update-on... [2] http://src.chromium.org/viewvc/chrome/trunk/src/net/http/tra...

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#349

I asked this in a deeper thread, but i would like to reask anyone that can explain. If the NSA is tapping pipelines as it seems they are, wouldn't the sources such as facebook and google all come online at the same time? if they were in fact referring to the pipeline access as their way into facebook and company, why did they all have different onboarding times? wouldn't they have all come on at the same time: the ti…

My interpretation is that the NSA basically have two main forms of collection: data directly from fibre intercepts, and data obtained (via voluntary agreement, court order, or otherwise) from private companies. This slide [1] would certainly suggest such an arrangement.

The fibre intercepts would fairly easily give access to HTTP traffic, and Facebook/Google/etc. would probably 'come online' at about the same time (there will likely be some differences as it appears there is a need to code a plug-in/processing engine for each major source to pull out usernames etc.[2])

What exactly the dates in the PRISM slide mean is somewhat unclear without more information. It could be, for example the date that the first court order is made, or the date when the company provides to the NSA a more automated way to query the data. I doubt that those dates are related to the fibre intercepts though.

[1] https://image.guim.co.uk/sys-images/Guardian/Pix/pictures/20...

[2] https://image.guim.co.uk/sys-images/Guardian/Pix/audio/video...

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#350
post #336

Earlier quoted context omitted.

First of all: keep the staggering to a minimum. Second: realizing that "we should have known" and "none of this is new" isn't so much about reading news articles and being "plugged in", but rather having an understanding of how the Internet works. To oversimplify greatly, you're essentially playing a very precise game of telephone between around 10-20 different people, and usually about 1-3 different publicly-owned c…

>Second: realizing that "we should have known" and "none of this is new" isn't so much about reading news articles and being "plugged in", but rather having an understanding of how the Internet works. These are exactly the kinds of comments I'm talking about. The preponderance of people affected by this program on the globe (a staggering amount if you will) had no knowledge of this because the media failed, and are n…

> These are exactly the kinds of comments I'm talking about. The preponderance of people affected by this program on the globe (a staggering amount if you will) had no knowledge of this because the media failed, and are not, in fact, technically savvy on any level and don't understand, at all how the internet works in relation to the technologies employed by these programs.

Of course at least the mainstream media (MSM) failed. Why? It's a very old story, rock solid in the media: An MSM media company is in business to make money. They have some old techniques for doing so. Their main technique is to get eyeballs for ad revenue; for that their main technique is to grab people by the heart, gut, and below the belt, always below the shoulders, never between the ears; the content is essentially only light entertainment following the framework of the ancient Greeks we now call formula fiction; the content is nearly never the information needed by an "informed citizenry".

The best hope for the information citizens need is Web sites on the Internet and search engines that can help people find that information.

Post reply on HN