Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

361–370 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#361

Reading these slides, I'm trying to parse what these slides do or do not say. I'd like to leave aside the speculation about what the NSA is probably doing. First of all, XKeyscore seems to be primarily about the frontend query interface rather than the backend data storage, at least as far as I can tell. It looks like you can basically query their database by email address and get a set of records (email, chat, http…

One of the slides [1] has the full message text for a Facebook message. If they have it for Facebook, I'd be surprised if they also don't have it for email.

[1] https://image.guim.co.uk/sys-images/Guardian/Pix/audio/video...

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#362

Honest, maybe naive question, but what types of programmers actively help build and maintain systems like this? I turned down a job for a company that is less than a mile from my house because I viewed their business as immoral. Hard for me to fathom anyone taking a job, helping to build systems like this. I get that many of the components of a system like this could be seen as harmless. However, a system of this com…

I have "friends" (read: we mostly argue about this) who fit your description.

They will tell you that there are rules in place to prevent spying on Americans (and if you take a look at the Foreignness Factor screenshots, there is a sense in which this is true)

They will also tell you that the benefits outweigh the cost. Here we have a system that has allegedly caught 300 terrorists, and they would tell you that spying on foreign people to catch 300 terrorists is a good trade.

I disagree with them on both counts, but you asked what they would say.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#364
post #216
post #113

Earlier quoted context omitted.

Don't worry, you were already on their list. HN fields roughly 200,000 unique visitors each day, most of which have a markedly anti-gov't-spying slant[1], that's enough evidence to be in their cross-hairs. [1]: Such that in some capacity you might participate in the creation/promotion of methods or software to get around their snooping technologies.

Thoughtcrime.

Quite.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#365
post #29

This is overwhelming. Even when you always hear the claims about we knew this was going on, somehow it is still shocking when you see it all laid out infront of you with screenshots and the capabilities described. I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I was also looking for another unique ID that users ar…

> edit: Gmail messages must only be captured when they leave the Google network. It seems easier for the NSA to tap datacenter datacenter fiber links inside Google's network. Why worry about decryption when you can have Google's frontend servers do it for you?

Why assume that inter-datacenter links are not encypted?

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#366

Um... surely this has to be a spoof. "Select foreignness factor"?? really? The user interface and way this is done just seems to amateur hour to believe this is actually true

The numbers seem way off and too keystone cop to be true. 20 terabytes is not large for the NSA. It can search BCC?? Only the sender has them. so everything would have to be collected at each ISP (which isn't impossible).. but I think the guardian has been trolled.

That's 20TB per site. Who knows how many collection sites they have?

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#367

Earlier quoted context omitted.

If Richard Stallman is quietly berating us somewhere, he can go fuck himself. Part of educating the masses is being a person who people want to listen to. If he failed at that, he's no better than anyone else, and perhaps far worse, because of all the lost potential.

In my experience, telling people to do something hard (open source, keep privacy, etc.) in the face of a barely perceived danger (government is coming to get you) is kind of a hard message to get heard. Aside from that, I didn't mean to seriously suggest that he's out there passing judgement on us so much as I was attempting to acknowledge how hypocritical we are for having disregarded his message because of his ecce…

So you're expecting the world to come to terms with Stallman, rather than the other way around.

Think about that for a minute, and then explain to me why that makes more sense.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#368

Earlier quoted context omitted.

His observations are correct, but his conclusions are incorrect, just as people like Glenn Beck start out with facts and end up with paranoid delusions and fantasies. I think Stallman's observations are valid, but his method of dealing with the implications of those observations are impractical, if not completely wrong.

When you are done attacking Stallman with a false analogy, would you care to name a few of his invalid conclusions? More specifically, what is so impractical or "completely wrong" about not using smartphones?

He's not opposed to smartphones, he's opposed to cellular phones as these can serve as a tracking beacon, following your movements.

Given that the cellular providers are capturing and archiving location data, this is fact, his conclusion is we should avoid using these sorts of phones completely. Why? The reasoning here is a awfully thin, but has something to do with "being tracked = bad" and then goes into crazy territory from there. It's the same thing with credit and debit cards. They can be tracked, therefore bad, therefore nobody should use them.

If he's concerned about remaining invisible, then this must be applied rigorously across all aspects of his life. Does he wear dazzle face-paint or glasses with bright IR LEDs on them so that CCTV cameras can't pick him up? Does he only use methods of travel that require no identification? If the FBI wanted to retrace Stallman's activity on any given day, it'd take hours at most to piece it together.

The sign that someone's a crackpot is in how inconsistent they are in applying what they've concluded. It means they're missing something important.

For example, there are people that have a genuine need for absolute secrecy, that need to remain invisible, yet they still use cellular phones, email, and social networks. They're aware of the same risks as Stallman, but they take precautions instead of avoiding them completely.

It's notable that Osama Bin Ladin was taken down because he'd gone to such great lengths to avoid being tracked that he stood out as an anomaly, an approach that proved to be self-defeating. He had this large house, but a paranoia about electronic snooping so severe that he had no internet connection, and that alone made that house highly suspicious. If you're that affluent, you have an internet connection, even if you barely use it.

Everything Stallman advocates to avoid detection just makes him an even bigger target.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#370

>How do I find a strong-selector for a known target? >How do I find a cell of terrorists that has no known connection to strong-selectors? >Answer: Look for anomalous events >E.g. Someone whose language is out of place for the region they are in >Someone who is using encryption >Someone searching the web for suspicious stuff Lovely. Suspicious stuff and encryption. But wait! There's more! >Show me all the VPN startup…

>> Show me all the exploitable machines in country X. > That's cool. I'm guessing this is what Snowden meant by weak endpoint security. That, plus things like Microsoft and Apple operating systems. Don't forget: it's proven they work with the NSA, so backdoors certainly are guaranteed (plus, with Microsoft, we also know they hand 0-day exploits over to the NSA before they're fixed, plus you benefit from all the virus…

There was a document released by the Guardian a few weeks to a month back showing how they also monitor open source issue trackers to find exploitable flaws.
Post reply on HN