Live data from Hacker News

Core Secrets: NSA Saboteurs in China and Germany

firstlook.org

111–120 of 130 posts

Re: Core Secrets: NSA Saboteurs in China and Germany

#111
post #102

Earlier quoted context omitted.

It's not really speculative. Remember that previous leaks showed definitively that the NSA had broken into Google and Yahoo, notwithstanding they had some partnerships/participation from them. Bruce Schneier was given an opportunity to meet and review a large collection of documents but yes its true we don't really know.

The previous leaks did not definitely show anything like that. In fact its not clear they showed anything beyond an informational briefing on issues with intercepting Google related data. There's a Chinese whispers effect to all this where vague assertions are repeated over and over until they become considered definite facts.

"This is a major leap forward in the NSA's ability to exploit Facebook using FISA and FAA authorities" - NSA

"...by exploiting inherent weaknesses in Facebook's security model." - GCHQ

http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl...

That's Facebook. The Yahoo and Google stuff has been very widely reported and are direct from Greenwald and the Snowden leaks. Other links (in particular the PKH link) contain other information.

http://www.washingtonpost.com/world/national-security/nsa-in...

Re: Core Secrets: NSA Saboteurs in China and Germany

#112

Earlier quoted context omitted.

I wonder if they're subverting open source encryption software.

Most certainly 100% yes. Here's a pretty swell talk on some of the programs they use to do it. http://mirror.as35701.net/video.fosdem.org//2014/Janson/Sund...

While that is an excellent talk, it seems worth pointing out that it's speculative fiction, these things aren't necessarily happening (though it is quite plausible).

Re: Core Secrets: NSA Saboteurs in China and Germany

#113

Earlier quoted context omitted.

It seems you've decided that US hegemony is a "good thing" regardless of the moral implications for ourselves and the world. However, some find actions like the following to be dangerous, immoral, unnecessary: * "the US and Israel had the director assassinated" * "we won offshore drilling" * the blase assertion that a nuclear Iran is any worse than the existing nuclear powers (especially Israel!!!) "Energy security"…

> It seems you've decided Nah that's not what I think or believe. I'm trying to explain broader context. The US is not hacking in a vacuum. It has to make strategic decisions. We can arm chair the US strategic command all we want. There seems to be a presumption that the US is doing these things 'just because'. What I believe is that the US is making decisions based on incentives, costs, benefits and other tradeoffs.…

Presumably, I could better my negotiation position on pretty much any deal by spying or sabotaging the other party. Say I am negotiating a salary offer from a company, having access to the CEO email and that of other key decision makers (even just the prospective team and the HR reps) would presumably give me information I can use to secure a higher comp package, no? Without disrupting their operations in general, if I don't make a mistake in the process.

Is the previous an ethically valid way of conducting business? Should I not expect to be scrutinized if/when I got caught doing that, because it might imperil my interests? If I do the same, not for me but for a collective (a company, a union), would that be any less unethical? If not, why would it be different if I did it for my country?

Why is it that we consider that sort of behavior pathological for individuals, criminal for organizations and "just the way things are" when talking about (advanced, inter-dependent, presumably-friendly) nations?

Re: Core Secrets: NSA Saboteurs in China and Germany

#114
post #91
post #65

Earlier quoted context omitted.

> To clarify I mean that I don't believe it adds much to the corpus of information about domestic and civil rights infractions. As a foreigner, I'm actually more interested in non-domestic stuff.

Of course, but to be honest, that was the previous expectation of the NSA. It's not that apparent that there is anything useful to gain by leaking their attempts to spy on foreign counties like every other country does.

Since when is sabotage an act of spying, or for that matter acceptable behavior in peace time?

Lets say Swedish spies was sent to the US in order to infiltrate and weaken the 911 system, the power grid, or other key infrastructures of the US. Would you shrug at that also, since after all, what should people expect from spies?

Sabotage and spying is two different activities. Sabotage is a tactic employed during war. Spying is a tactic employed during peace. Confusing the two simply states that peace is war, and war is peace, and anything goes so long its against foreigners.

Re: Core Secrets: NSA Saboteurs in China and Germany

#116

I read the entire article with the hopes that company names would be mentioned. Let's see who took cash to weaken encryption. Let's see who helped the government create back doors. That would have made this article stand out. But alas it contained more of the same things we already knew or assumed was going on. Here's hoping for next time.

All large corporations weaken encryption for the government. Some articles. If you want more, I'm sure I can dig up a few. https://en.wikipedia.org/wiki/Communications_Assistance_for_... http://www.foia.cia.gov/sites/default/files/DOC_0006231614.p...

> All large corporations weaken encryption for the government

This is simply false. It is untrue to claim that all U.S. companies have somehow "weakened" encryption or inserted backdoors in their products for the Feds. I normally wouldn't waste my time correcting conspiracy theories, but sometimes it's necessary to stop the more credulous from believing them.

Yes, the NSA has boasted of having a surveillance "partnership" with certain U.S. companies, but those are telecommunications carriers -- AT&T, Verizon, Sprint, etc., not Silicon Valley firms: http://www.cnet.com/news/surveillance-partnership-between-ns....

For an additional indictment of AT&T, look at the sworn affidavit that EFF obtained from local SF bay area whistleblower Mark Klein -- an AT&T technician who revealed the existence of the NSA's fiber taps at the 2nd & Folsom Street SF facility.

But the Silicon Valley companies that we know and more-or-less love have done the opposite. Look at the announcements about device encryption by Google and Apple in the last month (that have irked the Feds so much they're threatening new laws). Look at Google's Adam Langley, Wan-Teh Chang, Ben Laurie, and Elie Bursztein deploying a better TLS cipher suite in Chrome. Look at Twitter's surveillance lawsuit this week against the Feds over, apparently, the legality of a warrant canary.

And of course the two links in the conspiracy theory posted above prove the opposite of the "weaken encryption" claim. First, CALEA doesn't apply to web companies. And even the carriers it does apply to are permitted to (at 47 USC 1002(b)(3)) provide secure end-to-end encryption: "A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication."

Second, the FOIA'd doc was written in the late 1990s before the Feds liberalized encryption export controls. It's 15+ years out of date. You can now freely export strong crypto. And even in the dark days of the 1990s, there were no domestic controls on encryption use, though the TLAs did give it a shot at one point.

A better argument for the conspiracy theory set is the very odd relationship between EMC Corporation's RSA business unit and NSA. But even if allegations of intentional security flaws are true, EMC is a Massachusetts company, not a left coast firm, and a cozy relationship between the NSA and EMC/AT&T/VZ/etc. certainly does not indict all companies and their founders.

Re: Core Secrets: NSA Saboteurs in China and Germany

#117

The NSA has clearly recruited employees from companies like Google, Facebook, Cisco, etc to compromise and place vulnerabilities that the NSA can exploit. The fact that the NSA has decided that the legal channels to acquire data through warrants and actual investigations no longer applies must be stopped.

Hey BugBrother, I don't know who is downvoting all your comments, but they seem within scope and inoffensive to me, so don't let the cowardly phibjobblers get to you.

Re: Core Secrets: NSA Saboteurs in China and Germany

#118
post #57

Earlier quoted context omitted.

//FOUO is a classified designation.

Almost correct, FOUO is a designation used to effectively classify the unclassified information from the public (really! [1]) but he looked at the wrong line. ------ [1] "unclassified but which the government does not believe should be subject to Freedom of Information Act requests" (wikipedia)

//FOUO is a classified designation.

Re: Core Secrets: NSA Saboteurs in China and Germany

#119

“The facts contained in this program constitute a combination of the greatest number of highly sensitive facts related to NSA/CSS’s overall cryptologic mission,” the briefing document states. “Unauthorized disclosure…will cause exceptionally grave damage to U.S. national security. The loss of this information could critically compromise highly sensitive cryptologic U.S. and foreign relationships, multi-year past and…

>But I'm bewildered by this article. It seems really damaging, and like it doesn't really add very much to the corpus they've already published.

Really damaging for whom? 99% of the worlds population are victims (them or their countries) to the stuff described in the article, not cheering for its continuation.

Re: Core Secrets: NSA Saboteurs in China and Germany

#120
post #35

Earlier quoted context omitted.

You summarized already in your sentences ("I'm bewildered by this article. It seems really damaging, and like it doesn't really add very much to the corpus they've already published") how you feel and why you feel that way: it appears damaging because it contains the paragraphs that explicitly contain the words "it's damaging." But it's just a general introduction to the "juicy bits" without the bits themselves. In f…

To clarify I mean that I don't believe it adds much to the corpus of information about domestic and civil rights infractions. On the other hand it deals a pretty big blow geopolitically/internationally. The big deal about this article is that it reveals the major tactical capabilities and efforts the NSA has invested in the intelligence war. Edit: Right now HN is limiting the number of replies I can initiate. Will re…

>On the other hand it deals a pretty big blow geopolitically/internationally.

So? For me (Godwin's law be damned) it's like leaked documents about Nazi germany practices. If you were not a German you'd cheer, and if you were a non-Nazi German you'd also cheer.

Post reply on HN