Live data from Hacker News

Core Secrets: NSA Saboteurs in China and Germany

firstlook.org

101–110 of 130 posts

Re: Core Secrets: NSA Saboteurs in China and Germany

#101

Earlier quoted context omitted.

>But I will say that the NSA's perspective is that: it is only because of the Snowden leaks if we have lost face with allies. To the NSA, the secrets were kept well enough until Snowden and friends disclosed them. Of course that's their perspective, as is the perspective of anyone committing an embarrassing or morally unscrupulous act. "The thing I regret most is getting caught." Secrets of this nature have a tendenc…

> the perspective of anyone committing an embarrassing or morally unscrupulous act In this instance it was embarrassing because it brought into question how well the US would be able to keep secret strategic information. And yeah hacking into allies is pretty unscrupulous. A bunch of the Snowden leaks showed that Israel, France, Germany and others have hacked into us. It's the way it all works. > Secrets of this natu…

> ... Germany and others have hacked into us.

Could you elaborate? As far as I know, Germany has some kind of agreement to not spy on the US.

Re: Core Secrets: NSA Saboteurs in China and Germany

#102

Earlier quoted context omitted.

It looks pretty speculative to me. Directly from this article: "The most controversial revelation in Sentry Eagle might be a fleeting reference to the NSA infiltrating clandestine agents into “commercial entities.”" , "It is not clear whether these “commercial entities” are American or foreign or both." and "The document makes no other reference to NSA agents working under cover. It is not clear whether they might be…

It's not really speculative. Remember that previous leaks showed definitively that the NSA had broken into Google and Yahoo, notwithstanding they had some partnerships/participation from them. Bruce Schneier was given an opportunity to meet and review a large collection of documents but yes its true we don't really know.

The previous leaks did not definitely show anything like that. In fact its not clear they showed anything beyond an informational briefing on issues with intercepting Google related data.

There's a Chinese whispers effect to all this where vague assertions are repeated over and over until they become considered definite facts.

Re: Core Secrets: NSA Saboteurs in China and Germany

#103
post #86

Earlier quoted context omitted.

Of those 37 countries, only a minor fraction have the budget to operate the way NSA does. That leaves approximately 160 other sovereign entities. Let's say half of them are despotic and don't count. That leaves 80. Out of those I'd wager that more than half are have governments too under-resourced to have the ability to put their people in the kind of panopticon Americans live in. In other words there may be hundreds…

>Of those 37 countries, only a minor fraction have the budget to operate the way NSA does. There will be differences in cost and budget for each nation. The United States has 25% of the world GDP (compared to 4%) of the population. That we can afford to fund the Lamborghini of intelligence operations isn't to discount other states that have less well funded capabilities. You'll see plenty of parallels with traditiona…

Addendum: we help fund partners programs.

http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl... (pg 124)

Re: Core Secrets: NSA Saboteurs in China and Germany

#104

Earlier quoted context omitted.

> the perspective of anyone committing an embarrassing or morally unscrupulous act In this instance it was embarrassing because it brought into question how well the US would be able to keep secret strategic information. And yeah hacking into allies is pretty unscrupulous. A bunch of the Snowden leaks showed that Israel, France, Germany and others have hacked into us. It's the way it all works. > Secrets of this natu…

> ... Germany and others have hacked into us. Could you elaborate? As far as I know, Germany has some kind of agreement to not spy on the US.

Found the reference to Israel/France, looking for Germany references.

http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl... (pg 40/125)

Why the downvote here? The comment contributes to the conversation...

Re: Core Secrets: NSA Saboteurs in China and Germany

#105

Earlier quoted context omitted.

Because of this. It's likely the NSA is actively subverting American companies. "The most controversial revelation in Sentry Eagle might be a fleeting reference to the NSA infiltrating clandestine agents into “commercial entities.” The briefing document states that among Sentry Eagle’s most closely guarded components are “facts related to NSA personnel (under cover), operational meetings, specific operations, specifi…

This article seems a bit speculative. They don't seem to know for sure that "(A/B/C)" means American companies in this case. Everything else just seems like commentary from themselves and other security experts. As for foreign companies, it's pretty obvious that NSA and CIA have been conducting operations like these for many decades. I'm not going to argue that the NSA has not subverted American companies before (see…

It doesn't matter if the companies are American or not.

When will Americans realize that 96% of the global population are "foreigners", and are still considered human.

Re: Core Secrets: NSA Saboteurs in China and Germany

#106

Earlier quoted context omitted.

You're not allowed to be imaginative or speculate here about topics that people have been conditioned to patriotically think non-critically about! Just give it up man! We all know that the official stories about 9/11 are 100% true! (For a group that hates censorship as much as these "hackers" do, isn't it funny how they love a site that lets everybody censor each other by downvoting comments into invisibility? See? H…

When you speak in front of a crowd of people and are arrested by police for the things you're saying, that's censorship. When the crowd boos you off the stage before you're finished, that's not censorship, it's other people also asserting their rights to free speech. Perhaps you should reconsider what you're saying or find a new group of people to say it to.

don't worry I got another account with lot of karma, gonna go for a coffee and you will feel my wrath.

Re: Core Secrets: NSA Saboteurs in China and Germany

#107

Earlier quoted context omitted.

I wonder if they're subverting open source encryption software.

Most certainly 100% yes. Here's a pretty swell talk on some of the programs they use to do it. http://mirror.as35701.net/video.fosdem.org//2014/Janson/Sund...

the really excellent part of this presentation is that he calls attention to the exceptionally poor nature of openssl's code months before heartbleed

Re: Core Secrets: NSA Saboteurs in China and Germany

#108
It is unfortunate the shadowing did not also go to homework and extra curricular activities. This is an area that is neglected too. If he had sat through a practice, then gone home to read 200 pages and do two hours of homework, his conclusions would be even more dramatic.

Re: Core Secrets: NSA Saboteurs in China and Germany

#109

Earlier quoted context omitted.

I wonder if they're subverting open source encryption software.

Most certainly 100% yes. Here's a pretty swell talk on some of the programs they use to do it. http://mirror.as35701.net/video.fosdem.org//2014/Janson/Sund...

What happened in the jump cut at 44m50s?

Re: Core Secrets: NSA Saboteurs in China and Germany

#110

The NSA has clearly recruited employees from companies like Google, Facebook, Cisco, etc to compromise and place vulnerabilities that the NSA can exploit. The fact that the NSA has decided that the legal channels to acquire data through warrants and actual investigations no longer applies must be stopped.

As an example, I have a small VoIP company. At one point, we were processing about a billion calls a week. A malicious employee could probably setup a trace and collect call records or record calls. I'd have no real defense against hiring someone that worked for the NSA.

An employee at a hosting company could do huge amounts of damage. Consider SSL certs can be issued just by checking email to prove "ownership". At some large ISPs/datacenters, it'd be "fairly easy" to intercept the confirmation email and get SSL issued in a company's name "legitimately" (that is, no bad effects to the CA and not traceable to the NSA).

Subverted employees is a huge threat and we should really consider that when looking at security in general.

Post reply on HN