Live data from Hacker News

The NSA: An Inside View

lorensr.me

171–180 of 323 posts

Re: The NSA: An Inside View

#171
post #55

This reads like it was penned by someone who's never heard of the Stanford Prison experiment or Milgram's research. When I read "I have a very high opinion of my former coworkers ... NSA employees are the law-abiding type ... You take a long automated psych test that flags troubling personality traits," I take away "the NSA is full of the kind of person who won't look at the big picture, who will follow orders withou…

> As with any government agency, the more they insist that they must not be held accountable, the more accountability we should jam down their collective throats.

Did you read the same essay I did? He didn't argue for less accountability (indeed, he argued for more). He did argue that the capability had to remain in order for the U.S. to maintain its ability to survive in the ongoing shadow cyber battles.

I agree with you that the high-level concerns are the real key, but you seem to working at it in the opposite direction. You have a specific end in mind, seemingly independent of any high-level examination of the effects of achieving that end. Then you say that the high-level things (law, trust, comparisons, etc.) should be arranged to meet the specific end.

Rather I'd argue it from the other direction, just as I have from day 1 of all of this: Does a country need to have the ability to monitor the goings-on of electronic communications (including the Internet) for its welfare & national security purposes? If so, what capabilities are needed? Is "pre-emptive self defense" needed (or even allowed)?

Do the totality of these capabilities introduce a risk towards civil liberties, or otherwise conflict with law? If so, can they be mitigated, must the law be changed, or should the state simply abdicate its security/welfare reponsibility (noting that it would be only the US doing the "abdicating" here)? Can the state employ other capabilities that can achieve the same essential effect with less risk on civil liberties?

Some of these questions you touch on, e.g. "you haven't proven that you are doing more or better compared to other ways we could push back against scary people.", but many are ignored completely as it is simply assumed that absolute privacy on the Internet is sacred (but only for the NSA; criminal organizations, other nation's intelligence agencies, and the local cypherpunk wardriving around are obviously not a threat), even while absolute privacy on the old landline phones was never a reality.

The best argument I've heard so far has been that the sheer scale of this type of network surveillance, along with its near-undetectable nature, makes it different in kind. I actually agree with that viewpoint, but I also think that this matter of scale makes it possible to install good oversight and accountability if the capability is actually needed. It would take probably at least 10 people just from a "command + control" sense to launch a U.S. nuclear missile; there's no reason even better accountability, oversight, and specific legal guidance and safeguards can't be baked-in to a one-and-only central monitoring system.

But the question is whether we need the capability, and no one seems to want to take a specific answer as to why the U.S. (and the U.S. alone) can survive without it.

Re: The NSA: An Inside View

#172

Earlier quoted context omitted.

MINARET was used in the 60's and 70's. It led to the passing of FISA, which made it illegal to look at or pass on US citizen data unless a judge suspected them of being a foreign agent.

The NSA did these things both pre-FISA and post-FISA. For example: * 1980-present. MAIN CORE, which is shared between CIA, FBI, NSA, Contains data on 8 million Americans and is used by LE. http://en.wikipedia.org/wiki/Main_Core * ?-Present the DEA SOD program which uses NSA intelligence for drug cases. http://www.washingtonpost.com/blogs/the-switch/wp/2013/08/05... And these are just the cases we know about, they are…

I don't believe the NSA should be giving data (or even just "tips") on citizens to LE. It's either illegal or done under a law I don't know about. Do you know what this is talking about?

>FISA surveillance was originally supposed to be used only in certain specific, authorized national security investigations, but information sharing rules implemented after 9/11 allows the NSA to hand over information to traditional domestic law-enforcement agencies, without any connection to terrorism or national security investigations.

https://www.eff.org/deeplinks/2013/08/dea-and-nsa-team-intel...

Re: The NSA: An Inside View

#173
>in 2007 the US suffered an "espionage Pearl Harbor" in which entities "broke into all of the high tech agencies, all of the military agencies, and downloaded terabytes of information."

Man, I would hate if an entity downloaded my information! Poor agencies. But it's probably fine, I mean, those "entities" couldn't look at terabytes of information. It's probably just sitting in a database somewhere. So, nothing to worry about.

Re: The NSA: An Inside View

#174
post #37

Interesting to get a look at what it's like to be inside the bubble. It's compartmentalized enough that the individual actors can justify their actions by the assumed competence and benevolence of the others. > I didn't test it, but I'm sure there was automated analysis that prevented or flagged use of US selectors. The mental leap here is subtle, but substantial. Since I have been told I can't use US selectors , I a…

It all seems so sincere. Except when you see how closely this matches the talking points the NSA sent home with employees (https://s3.amazonaws.com/s3.documentcloud.org/documents/8445...)

Re: The NSA: An Inside View

#175
> everything the NSA collects is by default shared with your government

So... does that mean that even though the NSA supposedly doesn't analyze American communications, their colleagues in other countries can?

Also, while it may be reassuring for Americans to know that US IP addresses are not allowed in searches, how reassuring is it for Canadians, Mexicans, Germans, Australians, etc? Does this not harm both our reputation and business interests?

In general, this article assumes agents of the government are, and will continue to be, law abiding and respecting of citizens rights. Is that likely to remain the case in 20, 50, 100 years? How about after a major terrorist attack?

Re: The NSA: An Inside View

#176

Earlier quoted context omitted.

The NSA did these things both pre-FISA and post-FISA. For example: * 1980-present. MAIN CORE, which is shared between CIA, FBI, NSA, Contains data on 8 million Americans and is used by LE. http://en.wikipedia.org/wiki/Main_Core * ?-Present the DEA SOD program which uses NSA intelligence for drug cases. http://www.washingtonpost.com/blogs/the-switch/wp/2013/08/05... And these are just the cases we know about, they are…

I don't believe the NSA should be giving data (or even just "tips") on citizens to LE. It's either illegal or done under a law I don't know about. Do you know what this is talking about? >FISA surveillance was originally supposed to be used only in certain specific, authorized national security investigations, but information sharing rules implemented after 9/11 allows the NSA to hand over information to traditional…

No, and I had not read that article, thank you. I do not know the law, if any exists, that allows that, although it violates most readings of the 4th Amendment.

Re: The NSA: An Inside View

#177
post #55

This reads like it was penned by someone who's never heard of the Stanford Prison experiment or Milgram's research. When I read "I have a very high opinion of my former coworkers ... NSA employees are the law-abiding type ... You take a long automated psych test that flags troubling personality traits," I take away "the NSA is full of the kind of person who won't look at the big picture, who will follow orders withou…

I take away "the NSA is full of the kind of person who won't look at the big picture, who will follow orders without exercising critical thinking, and who can be counted upon to be a Good German." That is exactly right. Employees of intelligence agencies are selected primarily for loyalty, not critical thinking. Most people find that hard to believe, especially those inside who tend to have a very high opinion of the…

It feels like saying Bletchley Park just needed more diligent and loyal crib workers and they would have solved the Enigma.

Without Turing and the Bombe where would we all be?

Re: The NSA: An Inside View

#178

"I am an American patriot." If anything scares me, its that. I know what he has written straight afterwards, but it still makes the hairs on the back of my neck stand up. Its all very well the author trying to define the word to suit their own purpose, but Im afraid its not that easy to get others to accept it. Try using your own definition of the word "Nig r", and see how that flies. "Patriotism to me simply means t…

The author claims to be a patriot but I would like to ask him how can he justify mass surveillance and/or entrusting a government agency with so much power while forgetting the Fourth Amendment which was enacted just for this purpose. There is a reason that such protections exist because it is almost certain that people in power will exploit them. And yet, he claims to be a patriot while being oblivious to the basic…

What in the Fourth Amendment speaks to electronic communications? The Fourth Amendment speaks to a person, their home, and their effects.

Even things like postal mail do not technically fall under the Fourth Amendment. Rather, they fall under separately-passed Congressional law, and USPS regulations.

For instance, did you know that the addressee of a letter may authorize the USPS to open the letter in a sorting facility without a warrant, even if the sender was not asked?

Likewise, did you know that if you send a first-class letter but forget to put a stamp on it, that it is technically "unsealed mail" and a USPS employee may open the letter to inspect it for mailability and postage determination, and also "as expressly permitted by federal statute or postal regulations"?

So certainly the Fourth Amendment was intended to keep the government out of your personal stuff and away from your person, but everything else that people attribute to it is done without much evidence. Even in the real world there's not as much Fourth Amendment protection to communications than most people realize, once they leave your house.

Re: The NSA: An Inside View

#179
post #45
post #28

Earlier quoted context omitted.

As a US citizen, I assume foreign countries (esp. China) spy on me. But I don't go around bitching about that. Why? Because the US will protect me. China cannot hurt me. On the other hand, when the US spies on me, I am much more threatened, because nobody can protect me from the US. If the US turns against me (for instance, for supporting the Tea Party), declaring me part of a "violent organization", I'm in real trou…

I think you are missing a point: US (cloud) companies do business with for example European companies/customers. The leaks suggest that all data a non-US customer stores with them is fair game for being snooped by NSA etc. without any judge or due process. This turns "complain about your own country spying on you!" into "Don't do business with an American company if you care for legal protection/are not stupid". But…

U.S. law has never been compatible with E.U. data protection law as I understand it though, even before Snowden. The Europeans can't seriously have thought the U.S. wasn't engaging in surveillance (and indeed, they did know otherwise, with ECHELON), so what can be said for that other than "caveat emptor"?

Until multilateral treaties are passed dictating how one national jurisdiction will handle the data of another then every EU business using a US cloud service has just been using wishful thinking. And again, this was true even before Snowden.

Post reply on HN