Live data from Hacker News

The NSA: An Inside View

lorensr.me

241–250 of 323 posts

Re: The NSA: An Inside View

#241
post #88
post #32

"Even if you are not a citizen of the Five Eyes, you shouldn't be worried about your data being viewed unless you're involved with a group of interest, such as a foreign government or violent organization." Huh, so: - My best friend's dad was a spy in the CIA - During the 70s and 80s my dad worked with Russian scientists (also ones from Poland and other Communist Bloc countries). Ecology stuff, mostly. - I've been in…

> "Even if you are not a citizen of the Five Eyes, you shouldn't be worried about your data being viewed unless you're involved with a group of interest, such as a foreign government or violent organization." This really is a key quote. Even if OP's assertions about the NSA are totally correct, even if all security protocols are followed to the letter, the problem still remains that they have a tremendous amount of p…

It doesn't even have to be on the level of COINTELPRO. See here:

> The history of the FBI Lab hasn't been without controversy. Dr. Frederic Whitehurst, who joined the FBI in 1982 and served as a Supervisory Special Agent at the Lab from 1986 to 1998, blew the whistle on scientific misconduct at the Lab. In a subsequent investigation, it was found that evidence had been falsified, altered, or suppressed, or that FBI agents had testified falsely, in as many as 10,000 cases, resulting in many false convictions. More than a decade later, cases were still being overturned because of this massive fraud.

http://en.wikipedia.org/wiki/FBI_Laboratory#Controversy

Re: The NSA: An Inside View

#242
post #70

Earlier quoted context omitted.

What's particularly interesting is that some of the recent disclosures don't seem to be visible inside the bubble. Take this assertion, for instance: "The NSA copy of my emails won't be viewed by police or FBI investigating me about marijuana use, for instance. Law enforcement might get a search warrant and retrieve a copy from Google, but not from the NSA." In fact, it's been known for months that the DEA receives i…

What's the legal term? I think it's "double construction"? Where the prosecution knows it's you from illegal means (wiretap/NSA spying) but by that knowledge can go back and construct the legal case in reverse. It's been rumored that Dread Pirate Of SilkRoad case was figured out that way.

The story around DPR getting caught started in him making posts that had personally identifiable information from his anonymous accounts in the very beginning, not from illegal searches.

That's just a really long scraping / pattern-matching exercise of publicly available data, and the reminder that even particularly clever people won't be on point 100% of the time.

Re: The NSA: An Inside View

#243
He only describes his view from inside the system NSA. But it is the outside which really worries me. Governments and legal boundaries can change. DHS and TSA were such changes. And both agencies have a big impact on the lifes of citizens and visitors.

OP admitted, that NSA already gathers data of US citizens. But the current legal boundary prevents analysts to just add a "selector", except when it is allowed by a (secret) court. So the data is already there with the technology to query or filter it, which is a bad thing in itself. But it is a tiny change in the law, that would make it legally right to include US citizens' data into the query.

Looking back at DHS, TSA and the overall militarization of the security forces, it is not hard to imagine that NSA is an easy pick for a reactive government responding to the next terrorist threat.

BTW. When have government institutions ever been dissolved? Isn't that a lot harder than creating new ones or changing the rules in favor of more control?

Re: The NSA: An Inside View

#245
I spent four years in (2 years longer than the OP), but worked on a substantially broader swath of intelligence areas and in much more policy-oriented positions, and I can tell you that the vitriol that's been displayed on HackerNews is incredibly tiresome to see, because you are all missing a very key point about how the NSA conducts business (which I've pointed out in previous posts).

The key point is this: the NSA does not create policy for its operations. Those are written into law through executive, legislative, and judicial processes, and the three should theoretically balance each other out, which the public currently deems as not doing a sufficient job of balancing. The NSA acts as an instrument -- the employees (to include the director) are directed through a system of reporting and feedback, and determine how best to act in order to obtain more positive feedback from customers of the reports.

This isn't some theoretical system I'm talking about -- it's a database of reporting with attached feedback. The feedback shows who consumed the report, whether or not the party found it useful, any enclosed comments about the report, and how high up the report went. If my report made it into the president's daily brief and more information about the reporting subject is desired, that will show up in the feedback, and thus I have my "direction".

How does this translate into real world operations? Here is a theoretical conversation between Mr. Policy and Mr. NSA:

-----------------------------------

Mr. NSA: Here is some information I found about country X, which might indicate that they're conducting operation Y.

Mr. Policy: I would like to learn more about operation Y, and country X's intentions to expand it.

Mr. NSA: I don't currently have the capability to expound upon operation Y, unless you grant me the authority to access datastore Z.

Mr. Policy: We took a vote, and you have access to datastore Z on a thirty day trial basis, but then must shut down operations if nothing of value is found.

Mr. NSA: Here is the information you requested about operation Y and country X's intentions.

Mr. Policy: This information was not useful in directing policy, therefore datastore Z is to no longer be accessed.

-----------------------------------

From this, I think you can extrapolate my point. Do you blame the scalpel for being too sharp, or the surgeon for handling it incorrectly?

Re: The NSA: An Inside View

#246
It is really nice to get a coherent, human view from inside the security and intelligence community. To the best of my knowledge, the article reads as an honest and true account of security service culture of integrity and professionalism. Kudos to him, and kudos to his colleagues as well for their restraint and their service.

I am pleased to see him hint at the exposure and vulnerability of the general public to surveillance by third parties, when he describes of the ongoing battle to dominate electronic systems, being waged by various nation-states and criminal gangs around the world. (I refuse to use that horribly juvenile construction "cyber-war").

However, we still have some way to go before we fully confront the magnitude of the problem, and are able to formulate a sensible and coherent response.

Our military forces and security services are rightly part of our response to this vulnerability, but they cannot be the only tool that we deploy. Societies that lean to heavily on their armed forces and security services quickly feel the negative effects of their reliance, no matter how well-intentioned, well-disciplined and professional the servicemen and servicewomen may be.

Civil society needs to step up to the plate also. The problem is difficult, and the response needs to be multifaceted and broad. As engineers, we need to make our systems more secure and more trustworthy - and we need to make tools for the creation of secure and trustworthy systems ubiquitous.

For example, I am writing software for advanced driver assistance systems & autonomous vehicles -- I need to think very very carefully about how I can make my software secure and robust from attack; I need to educate my colleagues about the risky environment that we will be operating in, and together, we need to come up with standards and processes to help us ensure that the software we create minimises the risk posed by malicious actors.

Re: The NSA: An Inside View

#247

I spent four years in (2 years longer than the OP), but worked on a substantially broader swath of intelligence areas and in much more policy-oriented positions, and I can tell you that the vitriol that's been displayed on HackerNews is incredibly tiresome to see, because you are all missing a very key point about how the NSA conducts business (which I've pointed out in previous posts). The key point is this: the NSA…

> Do you blame the scalpel for being too sharp, or the surgeon for handling it incorrectly?

None of the above, if anything I'd blame people for being mere tools.

Re: The NSA: An Inside View

#248

Earlier quoted context omitted.

What's the legal term? I think it's "double construction"? Where the prosecution knows it's you from illegal means (wiretap/NSA spying) but by that knowledge can go back and construct the legal case in reverse. It's been rumored that Dread Pirate Of SilkRoad case was figured out that way.

The story around DPR getting caught started in him making posts that had personally identifiable information from his anonymous accounts in the very beginning, not from illegal searches. That's just a really long scraping / pattern-matching exercise of publicly available data, and the reminder that even particularly clever people won't be on point 100% of the time.

Or they did find him illegally and found later on the public pattern-matching exercise to justify their findings. Which is exactly the point of parallel construction.

We cannot know.

Re: The NSA: An Inside View

#249
The key thing that worries me about it is even if no-one reads all those emails that are stored, what if they are mined for data and used to make predictions?

Last.fm can guess the type of music I like about 25% of the time, Google can guess the type of information I'm interested in around 70% of the time (figure based upon potentially ambiguous web searches I do). Neither of those services have very much metadata from me about their respective subject areas.

If the NSA/GCHQ/5 eyes are hoovering up all this metadata about pretty much everything I do online, that's a ton of information to start mining for patterns - whilst legitimately say that no employees are reading it.

What sort of predictions can they make? What's the accuracy of it? When do they start acting on the predictions thrown up by the system? And who polices that?

Re: The NSA: An Inside View

#250
This is something that bothers me:

  Email that isn’t related to intelligence is rarely viewed, 
  and it’s even less often viewed if it’s from a US citizen. 
  Every Agency employee goes through orientation, in which we 
  are taught about the federal laws that govern NSA/US Cyber 
  Command: Title 10 and Title 50. We all know that it's illegal 
  to look at a US citizen's data without a court order.
I can rewrite this to:

  We are indoctrinated to believe that we shouldn't really
  invade the privacy of US citizens, and it is highly unlikely
  that we might mistakenly or otherwise read your private emails,
  however, if you aren't a US citizen then fuck you, you are our 
  enemy, you have no right to privacy because you weren't born 
  in the land of the free. Oh yeah, fuck you twice, cos we can.

  Ha ha
You know what, fuck you too.
Post reply on HN