Live data from Hacker News

XKeyscore

en.wikipedia.org

111–117 of 117 posts

Re: XKeyscore

#111

Earlier quoted context omitted.

> would have tied right in with all the other election related hacking allegations. That's not how it works. There is no coordinated messaging campaign across agencies against adversarial nations. It might seem that way based on media reports, but there isn't.

FBI would be the primary agency investigating TSB leaks, so no need for a coordinated messaging campaign. If the FBI believed that TSB was Russian intelligence, it is perhaps somewhat surprising that it's not mentioned in the Mueller report. We also still don't know how Hal Martin was related to TSB, the timing of the messages sent from his twitter account to Kaspersky (who apparently reported him to the NSA!) does p…

The FBI would still need to coordinate with the NSA for an investigation and public declaration of findings, neither would be in the interest of the NSA to cooperate for.

And the Mueller report was specifically scoped down to not include anything outside of the 2016 presidential election. I don't know why you keep going back to that.

Re: XKeyscore

#112

Earlier quoted context omitted.

You don't think exposing American intelligence operations and providing fodder for bad faith influence operations is not in Russia's benefit? With every interview he gives, he's the gift that keeps on giving.

None of that makes him a Russian agent. That doesn't even make him an useful idiot. Just useful.

You're confusing terminology. You can be an agent or an asset of a foreign government without formally working for them.

You could argue Snowden never intended to become an asset of the Russian government but you can't argue that he didn't eventually become one.

Re: XKeyscore

#113

Earlier quoted context omitted.

> no control over when his passport > wanted to stay in Moscow if he had a choice None of this has to do with his decision to seek protection from the Russian government, which is a formal arrangement with their security services, whether you want to acknowledge it or not.

I don't think you can approach this subject in good faith and arrive at that conclusion. His options at that point were pretty much limited to prison in the US or seeking protection from the Russian government. If you wouldn't have made the same choice as him in that situation, you can reasonably criticize his choice, you'll just have a hard time convincing anyone that you would've chosen prison in that situation. Th…

> His options at that point were pretty much limited to prison in the US or seeking protection from the Russian government

You're just justifying his decision, not refuting that he made it.

Re: XKeyscore

#114

Earlier quoted context omitted.

Alright, well in the interest of a conclusion, I'll say that you made really good points, I've changed my opinion on some but not all of the topics. > "they want to know who's downloading tails, who's using signal, who the source of some journalist is" They don't care about random people doing those things, but if someone with a known terrorist cell association is in the US talking over signal. Or if someone is visit…

Yeah, the specific capabilities and operations of intelligence agencies like the NSA are a topic I’ve spent far too much of my life obsessing about. Fortunately, mostly because I’ve been paid to do so, but I should really find better things to do with my free time than rehashing work stuff in HN comments. I think we broadly agree on the details, and whatever differences remain are probably mostly attributable to us l…

Agreed, enjoyed the discussion either way, and thanks for the OSINT rabbithole.

Re: XKeyscore

#115
post #21

This is a reminder why all the traffic should be encrypted and obfuscated (i.e. no SNI in clear text). Ideally, the traffic should be encrypted to resemble a random noise. If you are making an app, you can embed public keys and use those to completely encrypt traffic, without relying on CAs. For example, Telegram does this, using a homemade encryption protocol that has no clear-text SNI like HTTPS. As I remember, WeC…

Isn't the whole issue with net neutrality that ISPs would be incentivized to prioritize their own traffic (or that of companies they collaborate with)? How does making it harder for them to identify traffic for my app/service/whatever stop them from doing that? As long as they can identify the traffic they do want to prioritize (by companies who haven't done the process you describe), it's not obvious to me why they…

> How does making it harder for them to identify traffic for my app/service/whatever stop them from doing that?

You can masquerade your protocol as HTTPS with SNI of that company, for example. Filtering by IP is very inconvenient (they change all the time), so the telecom would probably look at SNI.

Re: XKeyscore

#116

Earlier quoted context omitted.

I don't think you can approach this subject in good faith and arrive at that conclusion. His options at that point were pretty much limited to prison in the US or seeking protection from the Russian government. If you wouldn't have made the same choice as him in that situation, you can reasonably criticize his choice, you'll just have a hard time convincing anyone that you would've chosen prison in that situation. Th…

> His options at that point were pretty much limited to prison in the US or seeking protection from the Russian government You're just justifying his decision, not refuting that he made it.

Whistleblowers know that jail is a real possibility. That's why whistleblowers are brave, and that's why Edward Snowden is not one.

Re: XKeyscore

#117
post #21

Earlier quoted context omitted.

Isn't the whole issue with net neutrality that ISPs would be incentivized to prioritize their own traffic (or that of companies they collaborate with)? How does making it harder for them to identify traffic for my app/service/whatever stop them from doing that? As long as they can identify the traffic they do want to prioritize (by companies who haven't done the process you describe), it's not obvious to me why they…

> How does making it harder for them to identify traffic for my app/service/whatever stop them from doing that? You can masquerade your protocol as HTTPS with SNI of that company, for example. Filtering by IP is very inconvenient (they change all the time), so the telecom would probably look at SNI.

I still think I'm missing something. My understanding of how telecoms would abuse identifying traffic to violate net neutrality would be that they need to identify the traffic they want to prioritize, not deprioritize. Is your understanding different, or does this somehow give the ability to make your traffic indistinguishable to traffic that they favor (and therefore would either control directly or would be able to provide instructions to the controller to be able to make identifiable in some way)? What you're describing to me sounds like you're saying my traffic isn't possible to distinguish from other random traffic, but my argument is that they're never going to be prioritizing random traffic; they'll be prioritizing traffic that they can identify, which will likely not act in the way you describe precisely because it would make it impossible to prioritize. My traffic being anonymous doesn't somehow stop them from throwing it in to the lower priority lanes with everyone else because they don't recognize it; if anything, it seems like it's likely to guarantee it as well, because anything not recognizably a VIP doesn't get to go in the VIP lane.
Post reply on HN