Live data from Hacker News

Unraveling NSA's TURBULENCE Programs

robert.sesek.com

11–20 of 28 posts

Re: Unraveling NSA's TURBULENCE Programs

#11
post #7

Earlier quoted context omitted.

Just as the historical perspective, the automatic data processing was used even before electronic computers, and even by the Nazi regime to support genocide: http://en.wikipedia.org/wiki/IBM_during_World_War_II That's why it's important to actively care and to organize the society to minimize the potential for the undesired use of the possibilities given by the technology: the technology can amplify both the good and…

In theory, I absolutely agree with you. In practice, every choice as to how to care and organize society become a question of what to control and what not to control. Who can be trusted, and who can't trusted. Then it just seems to go in a circle. Regulation on top of regulation. People make judgments and claim they are assertions rather than assumptions, based on correlative and observationally biased inferences. Th…

Then, not in theory, but in practice, do you think we should care about the topic of the article?

Is it good when we discover what is actually being done "behind the closed doors" related to our profession right now?

It's also a task of every engineer to consider what could go wrong.

Re: Unraveling NSA's TURBULENCE Programs

#12
post #11

Earlier quoted context omitted.

In theory, I absolutely agree with you. In practice, every choice as to how to care and organize society become a question of what to control and what not to control. Who can be trusted, and who can't trusted. Then it just seems to go in a circle. Regulation on top of regulation. People make judgments and claim they are assertions rather than assumptions, based on correlative and observationally biased inferences. Th…

Then, not in theory, but in practice, do you think we should care about the topic of the article? Is it good when we discover what is actually being done "behind the closed doors" related to our profession right now? It's also a task of every engineer to consider what could go wrong.

I don't think we will ever be at a point in our existence, where we know what to do before we have to do it.

> It's also a task of every engineer to consider what could go wrong.

Within a reasonably defined threshold. If I have a business making rubber ducks, I don't have to design those rubber ducks with the specification that they withstand temperatures of 200 degrees C.

> Then, not in theory, but in practice, do you think we should care about the topic of the article?

I do care. I choose to not work for places that I disagree with the intent and usage of such things. I know I have the capacity and capability to work at those places. I don't want to contribute my intellect to something I consider destructive, to the best of my knowledge and awareness to do so.

But even given my choices, I never feel like I have the right answers. I always can find perspectives in where I could be wrong. I try to pick the one I consider 'least wrong'. It's not really a lesser of two evils thing, it's more reducing the probability for things to go wrong. I'm also young and probably very naive in many ways.

Re: Unraveling NSA's TURBULENCE Programs

#13
post #2

This is so disturbing. I honestly feel that with every one of these revelations, my interest in the technology world is degraded more and more. The existence of such heinous things as the TAO, and its tendrils, brings on a serious depression. Just who do these people think they are, to defeat our lives so completely, for their own sakes? Despicable.

They have a very pro-end-justifies-the-means attitude. Just listen to DoJ defend most of the illegal spying they get caught with. They keep saying "...but it's effective!". As if that makes it less illegal . The sad part is the mass surveillance done by the NSA, by and large, isn't even that. Maybe it's effective for economic spying, or spying on political leaders, or hacking into other countries infrastructures, or…

A plug here that the promoted and stated goal "stopping the next 9/11" is a politics of fear and not what ultimately justifies the capabilities to each administration.

Reprised from an earlier comment:

If you look at the Snowden documents (and leaks by others) you'll see essentially nothing other than the international nature of the programs. For example, you'll remember from the Snowden leaks that the NSA hacked the Brazilian oil company PETROBRAS to help American oil companies win offshore oil drilling locations. The hacking of Merkle's cell phone was a big deal because it revealed that the US had information from Germany during the Eurozone crisis! Stuxnet was used to destroy Iran's nuclear program. The US also faces the same sort of pressure from other countries. This year alone the DoD was hacked, Wall Street, NASDAQ and JP Morgan were hacked and hundreds of defense contractors were hacked - all with foreign attribution. Israel's Iron Dome designs were hacked by China. Take a look at the NSA program HACIENTA, which "is used to port scan entire countries" and which uses other compromised (civilian) computers to disguise attribution.

Look at The Intercept reporting (where Glenn Greenwald is right now). He speaks at length about how the US uses NSA operations to benefit the global bargaining posture and competitiveness of US companies. https://firstlook.org/theintercept/2014/09/05/us-governments...

And take the Inspector General's report from the Boston Bombings - a great example of how and when the NSA domestic programs would be used if they were about terrorism. The NSA is hardly mentioned. The Inspector General investigates the failings of the FBI. (http://info.publicintelligence.net/IC-IG-BostonBombingReport...)

"We focused our review on the entities that were the most likely to have had information about Tamerlan Tsarnaev prior to the bombings – the FBI, the CIA, DHS, and NCTC, which maintains the U.S. government’s database of classified identifying and substantive derogatory information on known or suspected terrorists. We also requested other federal agencies to identify relevant information they may have had prior to the bombings. These agencies included the Department of Defense (including the National Security Agency (NSA)), Department of State, Department of the Treasury, Department of Energy, and the Drug Enforcement Administration."

The report on the failures to anticipate/stop the Boston Bombers barely mention the NSA. This is because the Federal Bureau of Investigation and the National Counterterrorism Center are in charge of counterterrorism, not the National Security Agency.

Or go to the NSA's own mission statement.

(https://www.nsa.gov/about/mission/index.shtml)

"The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both Signals Intelligence (SIGINT) and Information Assurance (IA) products and services, and enables Computer Network Operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances."

(Nothing to do with terrorism.)

Lots of news recently has called out Executive Order 12333's role in defining the goal and the means of intelligence capabilities. EO 12333 was passed in 1981. The Five Eyes, the key partnership of the NSA, has its origins in the 40's and ECHELON and other leaked programs (eg CARNIVORE/PREDATOR) predate 9/11 by decades. The Snowden leaks disclose a list with over thirty countries with competing digital intelligence programs.

The NSA is not about terrorism. Never was. Never will be. The NSA and CSS are the intelligence arm of the United States. Austrilia's programs are similarly not about terrorism. Canada, too. New Zealand? Which terrorists have been attacking New Zealand?!

Digital communications play a huge role in global communications and corporate and international power. That's not to say there no domestic component to the programs. Domestic programs are also useful to track and disrupt radical ideas and organization within the country (MINERVA), and can also be used to incite discontent in other nations (look up the USAID Cuban Twitter program). Countries are able to manipulate the appearance of consensus within citizens of nations and in this way actually affect this consensus. (Look at the GCHQ programs leaks with BIRDSONG/BADGER/GATEWAY/SLIPSTREAM/ETC.) They also are used to monitor, detect and perform forensics on breaches from other countries.

There's so much to say, but I'll leave the comment with this. Digital communications are so insecure that the attackers always win. Always. And digital communications play a huge role (next to satellite and radio communications) in modern espionage and sabotage. If you just play a defensive game, you lose. The US feels it needs these capabilities for these reasons - not because of terrorism.

Re: Unraveling NSA's TURBULENCE Programs

#14
post #8

So if you're a VPN user, you get extra special attention from the NSA. > In the case of VPN traffic, a system called HAMMERSTEIN identifies the traffic and sends the metadata to a database called TOYGRIPPE. The TOYGRIPPE database is a “repository of VPN endpoints”14 that is used by targeting officers to determine if that computer should be a target for further exploitation 13. The TURMOIL VPN module also looks up the…

C.f. stenography, hiding in plain sight, etc. Drawing less suspicion generally, and if you are in the "mainstream" e.g. a crowded place, your signal becomes more difficult to parse out of the chaos.

Re: Unraveling NSA's TURBULENCE Programs

#15

Would love to know more about the "Pairing and Crypt attacks" along with "Cryptovariable management". Probably the pairing here is referring to the pairing between client and server rather than the cryptographic technique of using pairings ... but it seems this hasn't surfaced in any of the other snowden docs. I often wish the journalists working on that story had released more source material.

They're only slides. We don't have audio of the presentations. :) I did wonder about that, but no "common" internet encryption protocols use pairing-friendly (in the open source cryptographic community sense) primitives. I think you're about right and it probably refers to matching public and private keys for CAs in SSL/TLS, looking up suitable intermediate CAs, for which they may have a few keys stashed away. They d…

To extend your statements:

* breaking 1024-bit RSA is believed to be well within the resources of the NSA given public research/attacks.[0]

* MD5 is already completely broken in the public research and the NSA has used MD5 collisions in malware attacks that are independent of public methods[1].

* RC4 has been attacked for a number of years, and someone who has seen unreleased Snowden documents claimed that the NSA has the ability to break RC4 in realtime[2]. Plenty of HTTPS traffic is protected by RC4.

[0]:"One estimate is made by Shamir & Tromer (2003) in their hypothetical TWIRL device. They suggested that for "a few dozen million US dollars", a hardware device could be built to break a 1024-bit RSA key within around a year. Franke et al (2005) similarly estimate a cost of 200 million dollars2 for a machine to factorise a 1024-bit number in one year. If these cost estimates are accurate, it's safe to assume that the NSA has built such a machine (unless they have another way of breaking RSA more efficiently). And by Moore's Law alone, we'd assume that their machine takes considerably less than a year." http://www.javamex.com/tutorials/cryptography/rsa_key_length...

[1]: "He discovered that for this spy malware an as yet unknown cryptographic attack variant of his own MD5 attack is used." http://www.cwi.nl/news/2012/cwi-cryptanalist-discovers-new-c...

[2]: "RC4 is broken in real time by the #NSA - stop using it." https://twitter.com/ioerror/status/398059565947699200

Re: Unraveling NSA's TURBULENCE Programs

#16
post #2

This is so disturbing. I honestly feel that with every one of these revelations, my interest in the technology world is degraded more and more. The existence of such heinous things as the TAO, and its tendrils, brings on a serious depression. Just who do these people think they are, to defeat our lives so completely, for their own sakes? Despicable.

I can understand that. For me this is just what I already assumed them to be doing and find it all rather unsurprising. I would rather have your mindset, I think.

Re: Unraveling NSA's TURBULENCE Programs

#17

Earlier quoted context omitted.

They have a very pro-end-justifies-the-means attitude. Just listen to DoJ defend most of the illegal spying they get caught with. They keep saying "...but it's effective!". As if that makes it less illegal . The sad part is the mass surveillance done by the NSA, by and large, isn't even that. Maybe it's effective for economic spying, or spying on political leaders, or hacking into other countries infrastructures, or…

A plug here that the promoted and stated goal "stopping the next 9/11" is a politics of fear and not what ultimately justifies the capabilities to each administration. Reprised from an earlier comment: If you look at the Snowden documents (and leaks by others) you'll see essentially nothing other than the international nature of the programs. For example, you'll remember from the Snowden leaks that the NSA hacked the…

> Digital communications are so insecure that the attackers always win. Always. And digital communications play a huge role (next to satellite and radio communications) in modern espionage and sabotage. If you just play a defensive game, you lose. The US feels it needs these capabilities for these reasons - not because of terrorism.

The role of NSA programs like BULLRUN in making digital communications insecure by default complicates the analysis.

Re: Unraveling NSA's TURBULENCE Programs

#18
post #8

So if you're a VPN user, you get extra special attention from the NSA. > In the case of VPN traffic, a system called HAMMERSTEIN identifies the traffic and sends the metadata to a database called TOYGRIPPE. The TOYGRIPPE database is a “repository of VPN endpoints”14 that is used by targeting officers to determine if that computer should be a target for further exploitation 13. The TURMOIL VPN module also looks up the…

[deleted]

Re: Unraveling NSA's TURBULENCE Programs

#19
post #2

This is so disturbing. I honestly feel that with every one of these revelations, my interest in the technology world is degraded more and more. The existence of such heinous things as the TAO, and its tendrils, brings on a serious depression. Just who do these people think they are, to defeat our lives so completely, for their own sakes? Despicable.

They have a very pro-end-justifies-the-means attitude. Just listen to DoJ defend most of the illegal spying they get caught with. They keep saying "...but it's effective!". As if that makes it less illegal . The sad part is the mass surveillance done by the NSA, by and large, isn't even that. Maybe it's effective for economic spying, or spying on political leaders, or hacking into other countries infrastructures, or…

My take is that there is a pretty even split in the arena on the reasoning. About half of the people involved in this truly believe that the move from a nation-state security model to a single-actor security model creates an environment where mass-surveillance is a requirement, and then they justify all the (il)legality away based on this ends-begets-the-means view, but don't often say it out loud. There is a second set of people though, closer to the top-tiers and involved in the high levels of the military-congressional-corporate-industrital-complex, who view the internet as a threat, not because of cyber-crime or cyber-terrorism, but because it allows a free anarchistic distribution of information, and feel it "Must be brought under control."

Throughout history, every form of communication that has enabled the proletariat open access to information has been brought under control. Printing press, telegraph (remember the Black Chamber for telegraphs?), radio, and television, all privatized and corporatized until they are barely public utilities at all.

The internet got ignored for a long time, and it wasn't until the late 90's that the three letters really started paying attention to it. Here we are now with a balkanization of the internet incoming, with TPP and other measures to ensure corporate profits, and mass surveillance as a tool of security and as a tool to deal with dissidents.

This is why you have seen and will see an increase in talking heads referencing internet-radicalism, because, it's the perfect setup for censorship. "We must prevent radicalism domestically, therefore please vote for legislation X, so we can censor radical information."

Re: Unraveling NSA's TURBULENCE Programs

#20
post #8

So if you're a VPN user, you get extra special attention from the NSA. > In the case of VPN traffic, a system called HAMMERSTEIN identifies the traffic and sends the metadata to a database called TOYGRIPPE. The TOYGRIPPE database is a “repository of VPN endpoints”14 that is used by targeting officers to determine if that computer should be a target for further exploitation 13. The TURMOIL VPN module also looks up the…

if you've ever seen

  TLS Error: local/remote TLS keys are out of sync
or

  Authenticate/Decrypt packet error: packet HMAC authentication failed
while using openvpn, you can expand the list of potential causes.
Post reply on HN