Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

631–640 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#631

Earlier quoted context omitted.

It is excessively naive and completely discredits your otherwise potentially salient points to suggest President Obama is a puppet. You're wading far too deeply into conspiracy territory to suggest that this puppet 'was meant to quell' anything. He is a leader whose administration stands and falls on its own merits.

I think it is naive to believe that each and every administration "stands and falls on its own merits" -- and then in the same breath talk about partisanship. There is no party but the MIC party - and clearly, the NSA owns that party. America has died, completely, 100%. There is no such thing as "Land of the Free, Home of the Brave"

This is tin-foil hat territory. The CIA was practically dismantled under Bush 43, and the intelligence agencies fight amongst one another like boisterous stepbrothers. To think the intelligence agencies control the government is vastly overestimating their internal political cohesion and capability.

The IC isn't running the government. They've got their hands full just running themselves.

The idea that we are not free is absurd. If I want to hold a rally for the Ku Klux Klan, that activity will be protected by the full force and power of the United States government. I can worship as I wish, read the books I choose, and write whatever I want (excepting direct threats of violence) with little fear, knowing that laws and courts stand ready to vindicate my rights.

I would take our extensive package of rights over single party political control, strongman leadership, civil law jurisdictions, and common law libel standards any day.

We are certainly no longer the most free nation on the planet, which saddens me deeply. But we are certainly amongst the best on that metric.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#632
post #82

>Foreignness factor I know NSA's mandate is to spy on foreigners , but it's still very jingoistic and xenophobic that not being American makes it OK to spy on you.

One could assume that Americans are spied on by foreign governments and the data is just exchanged. The US spies on Brits, the UK spies on US persons, and the both compare notes.

Actually this is exactly what occurs. Intelligence exchange among America and its allies under Echelon, ANZUS, and UKUSA have been used in this exact way to end-run around anti-domestic surveillance laws.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#633

Just like suspected. If you use encryption like PGP, you become person of interest.

You've no information to back up that statement. Using PGP as part of a filter makes perfect sense. If you're looking for "bad guys" that do certain activities, as a starting filter , it doesn't hurt to say "OK, show me everyone in this region doing these activities. Now filter by language, etc. etc.". Just like if I was looking for gang members, I might start off a filter with "look for tattoos". It doesn't mean I'm…

Read the whole presentation linked in the article.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#634
post #522

Earlier quoted context omitted.

I think so. Yes. IIRC, the first time I saw this leaked was a combo leak by a Navy Seal and a member of the Executive. The Seal leaked that they powered down Bin Laden's computers to take his hard drives after they shot him. The Executive member said that the drives were encrypted and it would take a few days to get the data. Jihadis are known to use a custom version of PGP with 2048bit RSA keys. They either used tha…

Breaking RSA is just a matter of managing to factor prime numbers faster than anyone else, isn't it? Unless if there is some sort of oversight inside the RSA algorithm that allows the encryption to be broken easier. Do you have more information on the smooth barrier? I did a quick google but didn't see much relevant.

I'm not sure it's relevant whether the b-smooth barrier exists of not, since that assume use of NFS.

There's a reason the NSA is pushing folks to use Suite B ciphers including Elliptic Curve along specific curves. It's not unreasonable to think that the NSA mathematicians have proven some relationship between EC and prime number theory in general.

There is some public domain work on this topic. See [https://en.wikipedia.org/wiki/Lenstra_elliptic_curve_factori...].

This might help explain in part the NSA's desire for large memory vector supercomputers going back to the 1990s over distributed memory MP systems.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#635

Earlier quoted context omitted.

You've no information to back up that statement. Using PGP as part of a filter makes perfect sense. If you're looking for "bad guys" that do certain activities, as a starting filter , it doesn't hurt to say "OK, show me everyone in this region doing these activities. Now filter by language, etc. etc.". Just like if I was looking for gang members, I might start off a filter with "look for tattoos". It doesn't mean I'm…

Read the whole presentation linked in the article.

I did exactly that, which is what I based my comment on.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#636
post #628

Earlier quoted context omitted.

RMS reads the web via email because he's traveling virtually all the time and rarely has Internet access Surely you can't expect people to take this argument seriously. It's easy to get internet access on the go in much of the world already.

RMS emails in restaurants, cars, trains, etc., in Europe and the United States but also frequently in SE Asia and South America. There are pictures of him responding to email in the mountains in Nepal. It's easy to get Internet access on the go in most of the places I've been to, but I've been to a tiny fraction of the places RMS has been to.

I didn't say one should never use offline mail. I'm just disputing that it's a sensible default, rather than a backup.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#637

Honest, maybe naive question, but what types of programmers actively help build and maintain systems like this? I turned down a job for a company that is less than a mile from my house because I viewed their business as immoral. Hard for me to fathom anyone taking a job, helping to build systems like this. I get that many of the components of a system like this could be seen as harmless. However, a system of this com…

You might want to have a look at the HOPE9 keynote with one of the first NSA leakers:

http://www.youtube.com/watch?v=FOFtQ6n3WR4

Clearly a very smart guy, that went very far in the NSA -- and for a long time felt he was doing "the right thing" -- but eventually quit because of what the NSA were doing.

edit: He also touches on how compartmentalization leads to people not knowing what they're actually working on/how it will be used in some cases.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#638

Earlier quoted context omitted.

Breaking RSA is just a matter of managing to factor prime numbers faster than anyone else, isn't it? Unless if there is some sort of oversight inside the RSA algorithm that allows the encryption to be broken easier. Do you have more information on the smooth barrier? I did a quick google but didn't see much relevant.

I'm not sure it's relevant whether the b-smooth barrier exists of not, since that assume use of NFS. There's a reason the NSA is pushing folks to use Suite B ciphers including Elliptic Curve along specific curves. It's not unreasonable to think that the NSA mathematicians have proven some relationship between EC and prime number theory in general. There is some public domain work on this topic. See [ https://en.wikip…

Interesting comment! Yes, I have been trying to avoid EC because some of the random walk stuff I read made me uncomfortable given standardized curves. I always thought that NSA vector register desire was strictly due to block size of ciphers (particularly Russian). This was definitely true when DES/3DES where in use. Then again, I thought Bluffdale was just to crack old Russian intercepts with GPU like custom hardware. BTW, a Cray hw engineer and I talked about how Cray was trying to pivot into Bioinformatics since the gov biz was no longer robust (in 2004, IIRC?).

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#639
post #414

Earlier quoted context omitted.

> The technical possibility isn't the new and staggering part, it's the profound lack of morality, respect for any ideal whatsoever, and compete apathy towards the oaths these people took to serve us. Again, I'll chime in as the resident apologist. The people working at Fort Meade are not evil. They truly believe they're doing a great service to the nation. They may be wrong, and they've certainly thrown privacy out…

So concentration camps were understandable??? You are nuts if you think that that was acceptable given the circumstances. Just doing my job is not sufficient in jobs such as these.

You're confusing understandable with permissible.

I understand Nazi concentration camps. It was a manipulation of nationalist sentiment against an imagined internal enemy, conveniently one that could be dispossessed of a great deal of property, coupled with a never before seen combination of the pure survivalist id meeting modern state capitalism.

I understand United States concentration camps. While we certainly didn't starve, gas, or force Japanese, German, and Italian Americans, we did relocate large numbers of them to temporary camp facilities for the duration of the war. It was believed that recent immigrants and their children might harbor loyalty to extremely dangerous enemies and could serve as a fifth column in the event of an invasion. For what it's worth, despite the indignity and suspect constitutionality, that's a far cry better than most nations have acted in similar circumstances.

Both of those events are understandable, in that I can understand the thinking of the people involved. It does not mean I morally condone it. What I'm attempting to combat is the notion that all acts with which one disagrees must be the result of moral bankruptcy or internal failing.

Usually there is a logic, however skewed, behind even the most heinous events in human history. The first step to preventing those events is to understand that logic. Only then can we address the root causes of the problems we wish to solve.

In this case, I'm suggesting that the root cause was a panicked citizenry seeking shelter from a very real threat, not a government seeking to blindly expand its power. That's an unpopular opinion, but alternative interpretations lead to different actions.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#640
post #638

Earlier quoted context omitted.

I'm not sure it's relevant whether the b-smooth barrier exists of not, since that assume use of NFS. There's a reason the NSA is pushing folks to use Suite B ciphers including Elliptic Curve along specific curves. It's not unreasonable to think that the NSA mathematicians have proven some relationship between EC and prime number theory in general. There is some public domain work on this topic. See [ https://en.wikip…

Interesting comment! Yes, I have been trying to avoid EC because some of the random walk stuff I read made me uncomfortable given standardized curves. I always thought that NSA vector register desire was strictly due to block size of ciphers (particularly Russian). This was definitely true when DES/3DES where in use. Then again, I thought Bluffdale was just to crack old Russian intercepts with GPU like custom hardwar…

The whole reason the USG rescued Cray in the late-1990s/early-2000s was to insure the continued availability of large memory image vector supercomputers. Part of this may have been to it being less costly than converting their processing systems from vector codes and algorithms to massively parallel distributed processing ones. At that time the cluster interconnects were much, much slower in terms of both bandwidth and latency than they are today. Solving very large sparse matrices would have been tougher on an MPP system than on a vector one. You can read about some of this history in Bamford's "Shadow Factory."

There have been a number of very cost effective hardware approaches proposed for significant acceleration of both the sieving and linear algebra components of the NFS. Many of these proposals could successfully and cost effectively attack a 1024-bit number in the 2003/2004 era. The process at that time was around 130-nm. Today's process would have features at the 32-nm or 22-nm size. Today there has been a 100-fold increase in performance since 2003. (See http://tau.ac.il/~tromer/cryptodev/ for an overview.)

Combine this specialized hardware with an algorithmic improvement that gets to O(log n) or O(n log n)....

AES appears fine. The NSA and USG in general make a very strong effort in the 2000s to move all civilian command and control systems for satellites to AES-256 with TRANSEC capabilities. A brute force attack on AES-256 with a quantum computer should be on the order of 2^128 operations with currently know QC factoring algorithms. AES-128 looks weak at 2^64.

If the NSA can break something, they need to assume that their primary opponents can do so or will do so soon. China specifically comes to mind here. The can not release cryptography suites with known vulnerabilities. It is widely thought that it is more importantly to secure one's own signals before intercepting and decrypting one's enemies.

I think everything on the internet needs to be moved to Suite B protocols with forward secrecy enabled. AES-GCM overcomes all the known attacks (i.e. CRIME) against AES-CBC and AES-CTR.

I get the impression that the NSA is eight to ten years ahead of the public domain cryptographers in some areas. I think this gap is shrinking slowly. However, I have also heard that the NSA is preventing publication of some papers developed in the public domain due to national security reasons.

Post reply on HN