Live data from Hacker News

NSA revelations could hurt collaboration with 'betrayed' hackers

reuters.com

71–80 of 106 posts

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#71

It's worth pointing out that you don't need to work "for the NSA" to be contributing to state surveillance. If someone is hired straight out of college to work for any type of cloud services provider with revenues over a billion, it's probably safe to say that they your prospective employer has enough market reach to have attracted the attention of state surveillance programs. Of course, by law, your prospective empl…

> It's worth pointing out that you don't need to work "for the NSA" to be contributing to state surveillance.

The flip is also true: you're not necessarily contributing to state surveillance just because you work "for the NSA". Two easy examples are SELinux and the various NSA Guides to Securing .

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#72
post #9

Earlier quoted context omitted.

If their friends, condemned their actions i.e. working for a bunch of incompetent, paranoid spooks, their job outlook would change as well.

How would their friends know you you are working for the NSA? Shurly you sign the official secrets act (the US version of it) at the interview stage and have an agreed cover story for your referees.

I believe they let you tell people who ask since being evasive would raise more suspicion.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#73
post #67

Earlier quoted context omitted.

All of the truly remarkable intelligences I met, I met at NSA. There are certainly people that aren't (as with any organization), but the NSA is probably the only meritocracy in the USG. The pipeline for advancement is one of either taking a technical route or a management route. This means that you can reach the highest levels of the organization and pay grades simply by being good at what you do in an analytical se…

> I couldn't imagine the comments that I've seen about blacklisting former government workers and publicly shaming service men and women coming from anyone who has carried this kind of responsibility. I think the 'activists' that were derided are also working hard in the interest of the country. As for blacklisting and shaming former servicemen, see the aforementioned Bill Binney, and Thomas Drake, former NSA workers…

Bill Binney's complaint about the NSA was that they were wasting money on a system that did a poorer job of handling US-centric SIGINT. He was not himself opposed to collecting intelligence on US citizens; his own "ThinThread" system was designed to do exactly that, but with better technical controls over who could view the data.

The problem with the NSA's programs isn't that they lack technical controls; it's that they're allowed to supervise their own collection efforts and build their own controls in the first place.

The notion that Binney is a staunch opponent of PRISM-style surveillance is revisionist.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#74
post #46
post #29

The most dangerous and stupid meme percolating in pop tech culture is that the people engaged with tech culture have a unique claim to computer science, electrical engineering, cryptography, information security, and privacy technology. The Slashdot diaspora genuinely believes that most of the world's computer engineering talent reads their comments. The reality is that not only does money do a fine job of buying tal…

Bear that in mind when you design your NSA-proof email applications. Oh the patrony!

Sorry about that; you're right.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#75
post #73
post #67

Earlier quoted context omitted.

> I couldn't imagine the comments that I've seen about blacklisting former government workers and publicly shaming service men and women coming from anyone who has carried this kind of responsibility. I think the 'activists' that were derided are also working hard in the interest of the country. As for blacklisting and shaming former servicemen, see the aforementioned Bill Binney, and Thomas Drake, former NSA workers…

Bill Binney's complaint about the NSA was that they were wasting money on a system that did a poorer job of handling US-centric SIGINT. He was not himself opposed to collecting intelligence on US citizens; his own "ThinThread" system was designed to do exactly that, but with better technical controls over who could view the data. The problem with the NSA's programs isn't that they lack technical controls; it's that t…

> his own "ThinThread" system was designed to do exactly that, but with better technical controls over who could view the data.

That's plainly false. His system was specifically designed to throw-out private data, that is, never to store it. There is no data to view if it's not stored. See his 29C3 technical talk where he goes over it. [1]

>The notion that Binney is a staunch opponent of PRISM-style surveillance is revisionist.

This ignores nearly everything Binney has actually said when asked about why he came forward to blow the whistle on NSA's spying activities. Also, see above.

[1] https://www.youtube.com/watch?v=XDM3MqHln8U

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#77
post #75
post #73

Earlier quoted context omitted.

Bill Binney's complaint about the NSA was that they were wasting money on a system that did a poorer job of handling US-centric SIGINT. He was not himself opposed to collecting intelligence on US citizens; his own "ThinThread" system was designed to do exactly that, but with better technical controls over who could view the data. The problem with the NSA's programs isn't that they lack technical controls; it's that t…

> his own "ThinThread" system was designed to do exactly that, but with better technical controls over who could view the data. That's plainly false. His system was specifically designed to throw-out private data, that is, never to store it. There is no data to view if it's not stored. See his 29C3 technical talk where he goes over it. [1] >The notion that Binney is a staunch opponent of PRISM-style surveillance is r…

New Yorker:

Pilot tests of ThinThread proved almost too successful, according to a former intelligence expert who analyzed it. “It was nearly perfect,” the official says. “But it processed such a large amount of data that it picked up more Americans than the other systems.” Though ThinThread was intended to intercept foreign communications, it continued documenting signals when a trail crossed into the U.S. This was a big problem: federal law forbade the monitoring of domestic communications without a court warrant. And a warrant couldn’t be issued without probable cause and a known suspect. In order to comply with the law, Binney installed privacy controls and added an “anonymizing feature,” so that all American communications would be encrypted until a warrant was issued. The system would indicate when a pattern looked suspicious enough to justify a warrant.

But this was before 9/11, and the N.S.A.’s lawyers deemed ThinThread too invasive of Americans’ privacy. In addition, concerns were raised about whether the system would function on a huge scale, although preliminary tests had suggested that it would. In the fall of 2000, [General Michael Hayden, the director of the N.S.A.,] decided not to use ThinThread, largely because of his legal advisers’ concerns… .

I'm sure it discarded some things, but the basic technical control that ThinThread appeared to have that Trailblazer (and PRISM) lacked is cryptographic authorization controls.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#78
We do have a pretty clear historical precedent. In the late Vietnam era and immediately after, the prestige of the military, and thus the quality of recruits and soldiers in the US military was basically at its lowest point ever (at least since we started having a big standing military with WW2). I mean, really bad. I'm not sure how much of this was due to "evil babykillers" meme about Vietnam, or the stink of failure from losing our first (and unpopular) war, or what, but it's conceivable the same kind of thing could affect NSA recruiting. The post-Snowden fiasco is about 5% of the way toward doing that, though -- until we see evidence of actual people that "we" "care about" seriously harmed, it won't get much closer than we are now.

(It was bad enough that they had to pass laws to consider Vietnam-era veterans a "protected class" for discrimination. From everything I've read and heard about the post Vietnam military, especially the Army, it was even worse (at least until the 1980s, and really until Gulf War I in a lot of ways.)

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#79
This is sadly far from true. There is plenty of talent to be bought for the right amount of money and plenty of talented people who can divorce morality from their job.

Besides that though there have been quite a bit of growth in nationalistic sentiment in the hacker community for some time. It seems that its been present in non-US/EU parts of the culture for quite some time, but I've noticed in recent years it becoming a bigger and more accepted part of US circles. Joking about popping boxes in .cn, seeing the whole country as an enemy, etc. It was a lot quieter on those topics in Vegas this year, but it was certainly a very present part of the dialogue 2010/11, etc.

Re: NSA revelations could hurt collaboration with 'betrayed' hackers

#80
The state are purposely allowed to break laws the citizens are not allowed to break.

It is illegal for a citizen to hack other persons and organizations computers and take their data. It is allowed for the government to hack other persons computers and steal their data. The government now has professional teams of hackers doing just that.

Thus the same laws does not apply for citizens as the government, thus the government thinks they are above the law.

It is almost the same as the government would have teams that steal credit cards and make drugs.

We are walking towards a Internet 3.0 which be heavily encrytped anonymized and reinvented by hackers. Imagine encrypted mesh sockets. ifconfig anoninet up Peer2Peer dns and trust authorities.

Not to mention the banks the government are protecting and the central banks, which purposely steals peoples money through inflation. The Fed is privately owned by the banks they are as Federal as Federal express not at all. The creature from Jekyll island.

Post reply on HN