Live data from Hacker News

US and UK spy agencies scoop up private data from 'leaky' phone apps

theguardian.com

51–60 of 98 posts

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#51

Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…

The sad thing is that if I watched these sort of pronouncements in an episode of "Person of Interest" or some other show I would normally laugh them off like I do the infinite zoom/sharpen capability of security video.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#52
post #34

Earlier quoted context omitted.

Why not? It is technically feasible. There was essentially no legal oversight at NSA or GCHQ. It seems like they responded correctly to the incentives they were given. The problem is with the legislature (and the judiciary), voters, and the media.

Why should our government agencies not commit crimes just because no one is looking? I'm just going to assume you were being sarcastic and move on.

I'm specifically questioning "no way to run a successful organization"; it was morally wrong (and legally, but there's no legal oversight, so that doesn't matter), but in no way hindered their success at their mission.

So, because it's not hurting them in terms of success to operate this way, there's a need for external controls to prevent it. If being all-collecting hurt their effectiveness, we wouldn't need any new controls, because they'd be replaced for being unsuccessful.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#53
post #34

Earlier quoted context omitted.

Why not? It is technically feasible. There was essentially no legal oversight at NSA or GCHQ. It seems like they responded correctly to the incentives they were given. The problem is with the legislature (and the judiciary), voters, and the media.

Murdering people is technically feasible as well. If entities are given essentially no legal oversight then the correct response would be to act on the incentives they were given to murder freely. The problem is with the legislature (and the judiciary), voters, and the media.

I don't think the parent was trying to absolve the NSA of responsibility, merely pointing out that its mission incentivizes it to collect as much data as it can. It's ultimately the responsibility of Congress to ensure that the NSA and other intelligence agencies adhere to the law, and Congress has largely ignored this responsibility.

The more subtle point that the parent makes is that, rather than always trying to prevent bad actors from doing bad things (e.g. murdering), a working system of checks and balances can punish the bad actors and deter future abuses. But checks and balances obviously don't work when everything is classified. The legislature and the judiciary were essentially the only two institutions that had access to this information and they did nothing about it.

You can't vote judges out of office, but if large scale surveillance is an issue important to you I'd make sure my congressman or congresswoman knew about it.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#54
post #2

Anymore, it seems prudent to simply assume that if you use the internet at all, all of the details about you are available to determined individuals, public or private. Even details you've never consciously given out over the internet are available to those with the power and desire to infer from your browsing datasets (see: Target and the pregnant daughter). Someone, please tell me I'm wrong.

Somehow, people were able to convince users that something on the internet could be secure. Nothing on the internet is secret, that's not what the internet is for.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#55
post #34

One slide from a May 2010 NSA presentation on getting data from smartphones – breathlessly titled "Golden Nugget!" – sets out the agency's "perfect scenario": "Target uploading photo to a social media site taken with a mobile device. What can we get?" To me, this is quite telling. The NSA is not considering what data they need to achieve their mission, and then trying to find that data. Instead, they're just looking…

Why not? It is technically feasible. There was essentially no legal oversight at NSA or GCHQ. It seems like they responded correctly to the incentives they were given. The problem is with the legislature (and the judiciary), voters, and the media.

> It seems like they responded correctly to the incentives they were given.

What incentives were those? To create a police state with kind of distopian program "Overseer"? Because that's exactly what they are doing.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#56
post #52

Earlier quoted context omitted.

Why should our government agencies not commit crimes just because no one is looking? I'm just going to assume you were being sarcastic and move on.

I'm specifically questioning "no way to run a successful organization"; it was morally wrong (and legally, but there's no legal oversight, so that doesn't matter), but in no way hindered their success at their mission. So, because it's not hurting them in terms of success to operate this way, there's a need for external controls to prevent it. If being all-collecting hurt their effectiveness , we wouldn't need any ne…

It's not hurting them insofar as they can sell this kind of useless (in terms of catching terrorists) data collection to bureaucrats who will sign off on it. I would argue that it is compromising their ability to sift the wheat from the chaff, when so much of their efforts and funding seems to be dedicated to adding to the latter.

Plus, the inevitable outrage generated when these tactics became public is undeniably hurting their credibility and in the long term their ability to gather information.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#57
Exploiting phone information and location is a high-priority effort for the intelligence agencies, as terrorists and other intelligence targets make substantial use of phones in planning and carrying out their activities, for example by using phones as triggering devices in conflict zones.

That's a good point and a good reason why it's irresponsible for these newspapers to post the details about this technology. This kind of CI doesn't work as well once everybody knows what you're doing. It also gives a road map to more oppressive governments looking for ways to spy on their citizens.

The documents do not make it clear how much of the information that can be taken from apps is routinely collected, stored or searched, nor how many users may be affected.

Right, so this is just publishing some details of NSA/GCHQ counterintelligence technology without saying how they are using it. Unless they have some evidence of wide scale deployment of these techniques, how is this surprising? Do we not expect spy agencies to develop surveillance technology?

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#58
post #52

Earlier quoted context omitted.

Why should our government agencies not commit crimes just because no one is looking? I'm just going to assume you were being sarcastic and move on.

I'm specifically questioning "no way to run a successful organization"; it was morally wrong (and legally, but there's no legal oversight, so that doesn't matter), but in no way hindered their success at their mission. So, because it's not hurting them in terms of success to operate this way, there's a need for external controls to prevent it. If being all-collecting hurt their effectiveness , we wouldn't need any ne…

> in no way hindered their success at their mission

Except that their mission is deeply compromised by their actions: they've lowered domestic cyber-security, undermined the rule of law, and deeply shaken the public confidence in the armed forces - all of which are contrary to their core mission.

They seem to have lost sight of their high level goals in their quest for more power to accomplish specific secondary tasks.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#59
post #57

Exploiting phone information and location is a high-priority effort for the intelligence agencies, as terrorists and other intelligence targets make substantial use of phones in planning and carrying out their activities, for example by using phones as triggering devices in conflict zones. That's a good point and a good reason why it's irresponsible for these newspapers to post the details about this technology. This…

If the government offered a legitimate and effective way for whistleblowers to expose wrongdoing and unconstitutional behavior, perhaps they could limit this type of damage from being done. As it stands, the release of this information could be considered collateral damage as result of their continued persecution of whistleblowers.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#60
post #12

Earlier quoted context omitted.

Maps and other apps on the iPhone weren't using HTTPS in 08 (underpowered device, need to squeeze every last drop from battery). They do now however. It's not just a spy agency issue, anyone could have sniffed the unencrypted traffic.

(underpowered device, need to squeeze every last drop from battery) Really now? Is that the official reasoning for not using HTTPS?

Back then it was.
Post reply on HN