Live data from Hacker News

It's Time to Break Up the NSA (2014)

schneier.com

1–10 of 140 posts

Re: It's Time to Break Up the NSA (2014)

#2
To me, it's pretty obvious that the supposedly "dual" mission of NSA, that of both anti-terrorism and cybersecurity, are completely incompatible. They are at the extreme ends of the spectrum.

One seems to need the abolishing of (true) secure systems and privacy (although, so far there is no evidence that mass surveillance actually helps thwart terrorist plots - and it may never be able to do so [1] [2]), and the other is supposed to be about having super-secure systems and strong encryption.

However, since the NSA is in charge of both, it seems the anti-terrorism side has won, and it now causes the NSA to make terrible cyber-policy.

To Schneier's new post, I believe the EU is already getting ready to propose that a civil agency (not one that is run in secret) should be in charge of cybersecurity in EU nations. Although, I think the NSA is working hard to convince EU spy agencies to push legislation that makes them responsible for cybersecurity, at least in some EU countries that are more easily "persuaded".

EDIT: So I actually disagree with Scheneir here. I see no reason why a secretive unaccountable agency should be in charge of cybersecurity. Why should it be a state secret that a hacker hacked into a US company? Just because the NSA has the "expertise" in cybersecurity? If you want to keep the experts, fine, but then turn the NSA into a civil agency.

I agree with his suggestion that surveillance (not mass surveillance, though - that should be banned for all agencies) should only be the domain of FBI.

To recap:

1) Cybersecurity = civil agency

2) Surveillance of local citizens = civil agency (FBI in US, I guess. Mind you, this is what already happens, when referring to targeted surveillance, so the real proposal here is that the NSA or anyone else shouldn't be spying on local citizens, too - only the FBI and with warrants. This is not, or should not be about giving the FBI "mass surveillance powers". If that's what Schneier is proposing, then I completely disagree with this, too)

3) Cyber-offense/cyber-war = military/Pentagon/whatever

4) I'm unsure whether we need another agency for spying on "world leaders", but right now I'm strongly inclined to give this one to the military too. Also, it would be best if this wasn't actually targeted at allies (like Merkel), but actual rival (Russia) or rival-like (China) countries. I think it's just good foreign policy not to do nasty stuff to your allies, just to be slightly "ahead" in negotiations.

[1] - https://www.schneier.com/blog/archives/2006/03/data_mining_f...

[2] - https://www.schneier.com/blog/archives/2006/07/terrorists_da...

Re: It's Time to Break Up the NSA (2014)

#3
I think an even better argument for breaking up the NSA is that there's a fourth category of work they (should) do that's totally unrelated to surveillance and that I'd classify as "very good:" actively working to secure the communications of US government and companies against the NSA-equivalents of other nation-states and rogue actors. Having this is on the same list as encryption sabotage is a recipe for mismanagement and bad policy.

Re: It's Time to Break Up the NSA (2014)

#6
Second, all surveillance of Americans should be moved to the FBI.

The FBI is charged with counterterrorism in the United States, and it needs to play that role. Any operations focused against U.S. citizens need to be subject to U.S. law, and the FBI is the best place to apply that law.

No no no a thousand times no.

One of the only saving graces about the massive surveillance from the NSA is that, I'm willing to wager, very little of it at all has made it over to where it could be used to oppress the citizens directly.

Bruce's claim that "FBI is charged with counterterrorism" means that they are also charged (along with DEA, ATFE, etc.) with the application of undue force on citizens--something we've been only somewhat spared from because of the difficulty they have in collecting information.

Turning over to them that capability--or even the just the current stockpile and archives of information!--would be a gigantic blow against freedom.

Re: It's Time to Break Up the NSA (2014)

#8
Is it possible to hold the position that the NSA should be conducting signals intelligence, data collection, and code-breaking (and yes, email snooping) -- yet at the same time hold the position that the blatantly malicious activities: 0day exploits, software and hardware backdooring, etc should not be allowed?

Why commit ourselves to a massive overhaul of the entire NSA when we can address the actual problem here with some granularity and minimal cost yielding an impact almost all of us would enjoy?

Re: It's Time to Break Up the NSA (2014)

#9
Read "The Puzzle Palace" and find out why the NSA is structured like it is. The US gov has been re-orging the NSA and factions inside the gov have been fighting over its control since its inception. To use an annoyingly beat to death phrase: we haven't seen its final form yet.

Actually a pretty good article overall, but these two lines bother me greatly:

   > "What was supposed to be a single agency with a dual mission—protecting the security of U.S. communications and eavesdropping on the communications of our enemies"
That was never the mission and is not the mission of any similar org in the past 100+ years. It is to eavesdrop on everyone, including ones allies. The Brits were eavesdropping on everyone's telegrams over 100 years ago. This isn't something new.

   > "The result is an agency that prioritizes intelligence gathering over security"
Again, that is the #1 goal of the NSA and other similar organizations. Security never has and never will be its #1 goal.
Post reply on HN