Live data from Hacker News

It's Time to Break Up the NSA (2014)

schneier.com

11–20 of 140 posts

Re: It's Time to Break Up the NSA (2014)

#11
It's easy to casually propose such things, on a blog, while lobbing the same tired criticisms about over-zealous intelligence gathering programs. But to actually implement such grand, sweeping measures would require resources that don't justify the benefits. Just scale back and increase oversight on troubling programs, and otherwise let the NSA do its critical job as an intelligence gathering agency.

Re: It's Time to Break Up the NSA (2014)

#12
Imagine if the Centers for Disease Control, instead of researching cures for diseases, had a budget in the billions for buying weaponized viruses and bacteria, and was subverting disease prevention. Nobody would stand for that. It would be poisoning health care worldwide.

As another commenter pointed out here: "Can we just flip their budget over to making sure US companies are secure?" That is, of course, what should be done. We get the results we spend money on. If the NSA's budget were spent on making security easy and routine, we would have easy and routine security. But that's not how we express our intentions with the budget right now.

Re: It's Time to Break Up the NSA (2014)

#14
post #3

I think an even better argument for breaking up the NSA is that there's a fourth category of work they (should) do that's totally unrelated to surveillance and that I'd classify as "very good:" actively working to secure the communications of US government and companies against the NSA-equivalents of other nation-states and rogue actors. Having this is on the same list as encryption sabotage is a recipe for mismanage…

Yes. Imagine if the NSA were tasked with being a gatekeeper for data privacy and integrity that large companies like Facebook had to work with any time they pushed an update that sent data somewhere new, in the same way that the FDA verifies safety and efficacy of pharmaceuticals when they're applied to a new problem-domain. (I know that sounds almost satirically over-the-top, but it could work—if it were limited to companies [and branches of government] that were handling enough user data that, say, identity fraud attacks would be made possible just by having it. And any system where the government itself has specified the data-integrity requirements: voting terminals, library checkout systems, etc.)

Come to think of it, this NSA would probably also be responsible for chasing down companies who ask you for your SSN, wouldn't it?

They could also offer free pen-testing services (presumably through their defense subcontractors; they wouldn't have to employ any whitehats themselves) for small businesses who can't afford pen-testers, like a specialized form of industrial-development grant.

And, of course, they could also do the only legitimate/legal "active no-advance-notice" pen-testing for infrastructure they're concerned about (ISPs, hosts like AWS, etc.), converting taxpayer dollars directly into those "eyes that make bugs shallow."

Effectively, the NSA are to our sovereign data boundaries as the coast guard is to (most of) our physical ones. Since that's the case—where's our Lighthouse Service?

Re: It's Time to Break Up the NSA (2014)

#15

Read "The Puzzle Palace" and find out why the NSA is structured like it is. The US gov has been re-orging the NSA and factions inside the gov have been fighting over its control since its inception. To use an annoyingly beat to death phrase: we haven't seen its final form yet. Actually a pretty good article overall, but these two lines bother me greatly: > "What was supposed to be a single agency with a dual mission—…

Technically, you are wrong. NSA has a signals intelligence side and an information assurance side. It does have two dual missions. You may argue that they haven't done a good job with the information assurance side of their mission, but you cannot argue that it is not a stated mission of the NSA.

Re: It's Time to Break Up the NSA (2014)

#16

Second, all surveillance of Americans should be moved to the FBI. The FBI is charged with counterterrorism in the United States, and it needs to play that role. Any operations focused against U.S. citizens need to be subject to U.S. law, and the FBI is the best place to apply that law. No no no a thousand times no . One of the only saving graces about the massive surveillance from the NSA is that, I'm willing to wage…

But.. what about parallel construction? We know that the NSA is feeding tips to, among others, the DEA and ATFE -- they're just pretending to find out about criminal activity in other-than-blanket-surveilance ways. The practice is so commonplace that the NSA has a special division for seeding the evidence to other agencies, and there are indications that even state and local law enforcement agencies are in on the fun.

Re: It's Time to Break Up the NSA (2014)

#17
Bruce makes a good point here. There is a balance between the COMSEC and SIGINT. Any advance you make in SIGINT is a failure of COMSEC and vice versa. The issue is then the 'viruses' of our internet ecosystem, the hackers and state level threats. How do you balance the two? Will the nature of the system self-balance as threats are discovered and then bandaged?

Still, good job not just demonizing the NSA, they serve a purpose in the game of international relations, one that the free world may not like, but that we all need.

Re: It's Time to Break Up the NSA (2014)

#19

It just seems that you can do anything on paper but covert agreements between the agencies after break up will still occur.

Not necessarily. It's just a matter of dis-empowering the people who are on a die-hard mission of "spy on everything, and to hell with civil rights."

That is not the whole NSA; it's just a few key people in leadership positions that have been steering the ship lately.

If you keep those same people in power but split up the agency, yes, you'll just get the same thing again.

Post reply on HN