Live data from Hacker News

New NSA Leak Shows MITM Attacks Against Major Internet Services

schneier.com

11–20 of 149 posts

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#11
Holy shit.

This means that The Netherlands was a high-level target with Diginotar, and they hit the frickin' jackpot.

Just for reference, read this: http://nl.wikipedia.org/wiki/Hack_bij_DigiNotar

The Diginotar hack basically exposed all of the information about the Dutch that NSA could ever want to digg through: Information about licenseplates (RDW) Tax info (DigiD) Phone records (OPTA) and the complete dutch encrypted government infrastructure (PKI Overheid)

Let's see what traction this new info will get now in The Netherlands...

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#12
post #9

If it is true that the NSA MITMed Google connections, then one could draw the conclusion that the NSA doesn't actually have a direct connection to Google data centers (as claimed by Google). If they had such a connection, then why would they use MITM attacks against people?

If you can't be sure your "backdoor" can be kept alive indefinitely, you better get used to using multiple approaches.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#13
post #9

If it is true that the NSA MITMed Google connections, then one could draw the conclusion that the NSA doesn't actually have a direct connection to Google data centers (as claimed by Google). If they had such a connection, then why would they use MITM attacks against people?

Hard to know for-sure, but it could be something as basic as redundancy. If one method of information-capture was eventually disallowed, they'd have an alternative. Or if one method of information-capture required more oversight than they wanted - they'd have an alternative.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#15

One more reason to not use any of the giant email providers like Yahoo, Google, and Hotmail.

And what makes any smaller providers any more safe?

A smaller provider with fewer clients probably provides a lower ROI for the NSA because of the economy of scale, although if they are specifically targeting you, it may still not make a meaningful difference.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#16

One more reason to not use any of the giant email providers like Yahoo, Google, and Hotmail.

And what makes any smaller providers any more safe?

Actually, they can be quite a bit safer. If they're small enough the NSA might not have any existing targets on them, which means they won't have tried to find a way to intercept their traffic yet. They could just do SSL traffic inspection, but it's too costly (and practically impossible) to do that everywhere, so they have to do it on specific target networks, which involves a lot of work to get the thing in the right place on the network.

It would be a huge pain in the ass to cover all the smaller providers.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#17
post #9

If it is true that the NSA MITMed Google connections, then one could draw the conclusion that the NSA doesn't actually have a direct connection to Google data centers (as claimed by Google). If they had such a connection, then why would they use MITM attacks against people?

The "direct access" that the NSA has to Google accounts probably requires sending a request for some set of information to Google. It likely needs to be signed off on (even if it's all automated). I'd imagine the NSA would like to hide some activities, especially corporate espionage, even from the watchers at Google--it reduces the risk of anyone at Google growing a spine.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#18

One more reason to not use any of the giant email providers like Yahoo, Google, and Hotmail.

And what makes any smaller providers any more safe?

I don't understand your question.

Bigger targets are always more interesting for mass surveillance, because, by definition, they have more users.

And that's what the recent revelations are all about: Mass surveillance.

Obviously, bitter targets are also more interesting for private/non-NSA/non-state hackers.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#19
post #9

If it is true that the NSA MITMed Google connections, then one could draw the conclusion that the NSA doesn't actually have a direct connection to Google data centers (as claimed by Google). If they had such a connection, then why would they use MITM attacks against people?

Requests to Google may be audited or logged; Google have an incentive to do this so they can pass the buck when the inevitable evidence of abuse comes out.

The NSA, on the other hand, would prefer there to be no audit trail so there's no evidence of the inevitable abuses.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#20
If this is true, and that NSA has been MITMing providers like Google, they are undermining the already shabby trust the US cloud-industry has attempted to build. I doubt Google and friends are very happy about that, since that's their one big basket where all the money comes in.

NSA in their eagerness to do rampant spying on everyone have had quite some collateral. They have decided to compromise the one thing which allows us to communicate securely on the internet: trust.

Right now we need to find out which (root?) CAs are compromised by the NSA. Long term it would probably be a very wise decision to revoke any US-based CA from the default trusted-list of browsers and OSes.

We cannot have untrustworthy CAs in a system based on trust. That's simply not an option.

Edit: As I've been pondering for a while (and which was also pointed out on reddit) we now have a situation where self-signed certs are more secure than CA-issued ones. They are the only ones you know can't be faked. How backwards is that?

The NSA is ruining the internet one piece at a time. The NSA needs to be dismantled.

Post reply on HN