Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

171–180 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#171
post #170

Earlier quoted context omitted.

What? It's absolutely true in the US > But among the 64% of American voters who earn more than $50,000 a year, 49% chose Trump, and 47% Clinton. [1] https://www.theguardian.com/us-news/2016/nov/09/white-voters...

I agree with the general sentiment, but Trump is a very poor yardstick for conservative political beliefs. Out of Reagan, both Bushes, McCain, Romney, and Trump, Trump is the clear outlier.

You're right that Trump is not necessarily representative of other Republicans. But I think the skew is actually the opposite direction of what you're saying. I think Trump is actually less likely to be favored by wealthy people vs say Bush.

Look at this polling of support of Bush vs Kerry by income level[1], as income rises support for Bush almost always rises, and support for Kerry almost always decreases.

[1] https://www.cnn.com/ELECTION/2004/pages/results/states/US/P/...

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#172
post #141

Earlier quoted context omitted.

Care to enlighten us what some of the "dangers" of metadata are?

Your behavior is characteristic of a terrorist/pedophile/drug dealer. An automated computer system/bureaucracy, the workings of which are too complex for a human to intuit or critique, decides on the basis of this "fingerprint" that you should be dealt with. You are bombed by a drone / disparaged in authoritative media / shot by police along with your kids and dogs / have your possessions taken by force / have your l…

That seems more than just the dangers of metadata. That's more of the dangers of giving machines the authority to drop bombs with no human oversight at all. That same kind of problem could happen if the government wasn't spying on anything, or if the government was spying on content, not just metadata.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#173
post #26

Earlier quoted context omitted.

"Intelligence is probably the least understood and the most misrepresented of the professions. One reason for this was well expressed by President Kennedy when, on November 18, 1961, he came out to inaugurate the new CIA Headquarters Building and to say good-bye to me as Director. He then remarked: 'Your successes are unheralded, your failures are trumpeted.' For obviously you cannot tell of operatives that go along…

> Dulles One gets the impression his claim that all the CIA's successes are secret is a lie. Because there never were any. You would thing 50 years after the man kicked it that at least something would be come out. Not really surprising. If you look at how successful organizations are structured the CIA is not that.

If it gets out then by definition it's a failure.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#174
post #16

This article is about 10x better in terms of explaining XKEYSCORE than the mess which is XKEYSCORE's Wikipedia article: https://en.wikipedia.org/wiki/XKeyscore#Workings

The reason the Wikipedia article is so confusing is that it has to explain Greenwald's and Snowden's explanation of XKEYSCORE, which was wrong.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#176

Earlier quoted context omitted.

> upper middle-class are the most conservative elements of any society This very clearly is not the case in the US.

What? It's absolutely true in the US > But among the 64% of American voters who earn more than $50,000 a year, 49% chose Trump, and 47% Clinton. [1] https://www.theguardian.com/us-news/2016/nov/09/white-voters...

And both Clinton and Biden are very conservative candidates, by any reasonable standard.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#177

Earlier quoted context omitted.

The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with. The…

> upper middle-class are the most conservative elements of any society This very clearly is not the case in the US.

I think that conservative means "in support of a (certain kind of) status quo" in this case, rather than the American line-up of hot-button culture war issues. The upper middle-class wants stability, whatever it is, because of the structure of their income stream. That's why upper middle class people are basically centrists and don't want to rock the boat too much: they're doing very well in the boat, and rocking it will have them taking on water. Other folks have much less to lose (which we should all remember over the next month).

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#178
post #141

Earlier quoted context omitted.

The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with. The…

Care to enlighten us what some of the "dangers" of metadata are?

https://www.wired.com/story/inside-the-nsas-secret-tool-for-...

> Even by that account, the scale of collection brought to mind an evocative phrase from legal scholar Paul Ohm. Any information in sufficient volume, he wrote, amounted to a “database of ruin.” It held personal secrets that “if revealed, would cause more than embarrassment or shame; it would lead to serious, concrete, devastating harm.” Nearly anyone in the developed world, he wrote, “can be linked to at least one fact in a computer database that an adversary could use for blackmail, discrimination, harassment, or financial or identity theft.” Revelations of “past conduct, health, or family shame,” for example, could cost a person their marriage, career, legal residence, or physical safety.

> Mere creation of such a database, especially in secret, profoundly changed the balance of power between government and governed. This was the Dark Mirror embodied, one side of the glass transparent and the other blacked out. If the power implications do not seem convincing, try inverting the relationship in your mind: What if a small group of citizens had secret access to the telephone logs and social networks of government officials? How might that privileged knowledge affect their power to shape events? How might their interactions change if they possessed the means to humiliate and destroy the careers of the persons in power? Capability matters, always, regardless of whether it is used. An unfired gun is no less lethal before it is drawn. And in fact, in history, capabilities do not go unused in the long term. Chekhov’s famous admonition to playwrights is apt not only in drama, but in the lived experience of humankind. The gun on display in the first act—nuclear warheads, weaponized disease, Orwellian cameras tracking faces on every street—must be fired in the last. The latent power of new inventions, no matter how repellent at first, does not lie forever dormant in government armories.

take a look at the history of the behavior of intelligence services through the 20th century and ask yourself how comfortable you are with this power being wielded by anybody.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#179
post #24

All these comments about metadata not being useful are missing the point. Metadata is incredible valuable and sometimes just as valuable as the decrypted data itself. Knowing what sites a target visits, access patterns, changes in behavior: all this can be fed into ML algorithms to come up with fingerprints. You don't need to be able decrypt the data in transit if you know the endpoints and can somehow compromise the…

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

In the lead-up to Australia's metadata retention legislation, some org posted the following examples. I found them reasonably effective at convincing normal people, but we failed to convince the decision-makers in Parliament:

- "What if your call logs indicated a 45-minute call to a suicide hotline made from a bridge. Do they need to hear exactly what was said?"

- "What if your call logs showed you receiving a call from a sexual health clinic, and that you then called a bunch of people in rapid succession. Do they need to hear exactly what was said?"

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#180
post #59

Earlier quoted context omitted.

> they have no access to the text of the messages due to E2EE. Correction: they might not have access to the message text. It's entirely possible (if not plausible: FB doesn't exactly have a good track record) for FB to just self-MitM the E2EE and see everything that passes through their servers. From their site: > The verification process is optional for end-to-end encrypted chats, and only used to confirm that the…

> It's entirely possible (if not plausible: FB doesn't exactly have a good track record) for FB to just self-MitM the E2EE and see everything that passes through their servers. Why would they even need to MitM in transit when they control the endpoints? They can just analyze the raw text locally (in the app) and extract valuable information.

Excellent point, way less tinfoil-y.
Post reply on HN