XKeyscore
en.wikipedia.org
XKeyscore
1–10 of 117 posts
Re: XKeyscore
#2We hear a lot about local agencies perusing the services of private companies to collect citizens' data in the US, whether that's traffic information, IoT recordings, buying information from FAANG, etc. What's the NSA's position in the current administration? (e.g. we've heard a lot of noise in the past about the FBI and CIA getting the cold shoulder internally. I wonder how this applies to the NSA.)
Re: XKeyscore
#3https://www.schneier.com/blog/archives/2014/07/nsa_targets_p...
https://www.reuters.com/article/opinion/commentary-evidence-...
https://www.theguardian.com/us-news/2014/oct/11/second-leake...
It is possible that the "second source" and the shadow brokers are one and the same.
https://www.electrospaces.net/2017/09/are-shadow-brokers-ide...
https://www.emptywheel.net/2017/09/15/shadow-brokers-and-the...
And here's an interesting tidbit about a possible link between TSB and Guccifer 2.0
https://www.emptywheel.net/2020/11/01/show-me-the-metadata-a...
Re: XKeyscore
#4Re: XKeyscore
#5For example, Telegram does this, using a homemade encryption protocol that has no clear-text SNI like HTTPS. As I remember, WeChat also uses some home-grown form of obfuscation.
As a bonus, this makes it more difficult for telecoms to discriminate against certain sites or apps and helps enforce net neutrality no matter if they like it or not.
Re: XKeyscore
#6This is a reminder why all the traffic should be encrypted and obfuscated (i.e. no SNI in clear text). Ideally, the traffic should be encrypted to resemble a random noise. If you are making an app, you can embed public keys and use those to completely encrypt traffic, without relying on CAs. For example, Telegram does this, using a homemade encryption protocol that has no clear-text SNI like HTTPS. As I remember, WeC…
Consider that TAO (or SSF) can probably get through your firewall and router, and maybe into the management engine on the servers with your critical data.
The only thing you've got going for you is that they will (probably) keep your data secure (for themselves).
Re: XKeyscore
#7The most interesting detail about the whole XKeyscore story is that it was apparently not leaked by Snowden https://www.schneier.com/blog/archives/2014/07/nsa_targets_p... https://www.reuters.com/article/opinion/commentary-evidence-... https://www.theguardian.com/us-news/2014/oct/11/second-leake... It is possible that the "second source" and the shadow brokers are one and the same. https://www.electrospaces.net/2017/…
Re: XKeyscore
#8Re: XKeyscore
#9This is a reminder why all the traffic should be encrypted and obfuscated (i.e. no SNI in clear text). Ideally, the traffic should be encrypted to resemble a random noise. If you are making an app, you can embed public keys and use those to completely encrypt traffic, without relying on CAs. For example, Telegram does this, using a homemade encryption protocol that has no clear-text SNI like HTTPS. As I remember, WeC…
It's also a reminder that no mater how secure you think you are, some third party may have access. Consider that TAO (or SSF) can probably get through your firewall and router, and maybe into the management engine on the servers with your critical data. The only thing you've got going for you is that they will (probably) keep your data secure (for themselves).
I don’t like these general observation comments. This kind of makes it unappealing to learn about encryption, but it’s worth it and makes you choose either a proper encrypted software or use a key for secret messages.
Re: XKeyscore
#10The most interesting detail about the whole XKeyscore story is that it was apparently not leaked by Snowden https://www.schneier.com/blog/archives/2014/07/nsa_targets_p... https://www.reuters.com/article/opinion/commentary-evidence-... https://www.theguardian.com/us-news/2014/oct/11/second-leake... It is possible that the "second source" and the shadow brokers are one and the same. https://www.electrospaces.net/2017/…
[flagged]