Live data from Hacker News

Encrypt your Google chats and make the NSA sad

github.com

181–190 of 195 posts

Re: Encrypt your Google chats and make the NSA sad

#181

Earlier quoted context omitted.

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

This is not my area, so excuse the ignorance, but this statement: A: "The NSA has built an infrastructure that allows it to intercept almost everything. With this capability, the vast majority of human communications are automatically ingested without targeting. If I wanted to see your emails or your wife's phone, all I have to do is use intercepts. I can get your emails, passwords, phone records, credit cards." Spec…

"Does that not imply they have found a weakness in TLS/SSL?"

Would it not be simpler to get access to a root CA?

Re: Encrypt your Google chats and make the NSA sad

#182
post #136
post #97

Earlier quoted context omitted.

Which would be trivial if they had agreements with the various mostly US providers to quickly get man-in-the-middle signed keys from their CA's. Although this seems like it would be quick to spot since if you were watching certificate fingerprints change then you'd see the switchover and switchback.

I use the Cert Patrol plugin ( http://patrol.psyced.org/ ) and I've noticed periods of a few days to a week where SSL certs on major sites like google have changed rapidly. Usually they were all from the same authority so I didn't think much of it. But now I am even more paranoid. Thanks man.

Me too, I stopped using that plugin because Facebook and Google would constantly change their certificates, so I'd end up just clicking OKOKOKOK, never looking at the certificate, defeating the whole point.

At the time, I assumed it was just a snag with the umpteen layers of caching and content-distribution networks that they must be using. Now it looks quite a bit more sinister.

Re: Encrypt your Google chats and make the NSA sad

#183

Earlier quoted context omitted.

Why did he not give even a small technical overview on what they are capable of? He should've been able to given he has a lot of technical expertise and it would've helped his evidence a lot. Did they figure out how to tap complicated SSL? Is it hardware based? He gave no hints but could have easily. Instead it's this blanket statement that's supposed to imply that all encryption is pointless.

This is not my area, so excuse the ignorance, but this statement: A: "The NSA has built an infrastructure that allows it to intercept almost everything. With this capability, the vast majority of human communications are automatically ingested without targeting. If I wanted to see your emails or your wife's phone, all I have to do is use intercepts. I can get your emails, passwords, phone records, credit cards." Spec…

He was a sysadmin and he didn't finish high school, let alone receive an actual technical education -- he's said a lot of very difficult to believe technical things. I don't mean to imply that only educated people know anything important, but unless he just had an amazing aptitude for learning this stuff on his own, I find it plausible that he had only a slight idea of how consumer encryption works and he actually didn't know what he was looking at when he saw whatever made him leak. Who knows without his documents -- I could be all wrong.

At some point I think he claimed that he could've copied the list of all US intelligence assets, even those undercover. Well, given that the NSA developed selinux to compartmentalize filesystem access in such a way as to make such a breach difficult, I am not sure how to reconcile his statements. I also find it beyond belief that a contractor could actually access what he claims he could've.

Re: Encrypt your Google chats and make the NSA sad

#184
post #136
post #97

Earlier quoted context omitted.

Which would be trivial if they had agreements with the various mostly US providers to quickly get man-in-the-middle signed keys from their CA's. Although this seems like it would be quick to spot since if you were watching certificate fingerprints change then you'd see the switchover and switchback.

I use the Cert Patrol plugin ( http://patrol.psyced.org/ ) and I've noticed periods of a few days to a week where SSL certs on major sites like google have changed rapidly. Usually they were all from the same authority so I didn't think much of it. But now I am even more paranoid. Thanks man.

Could you make a showhn or maybe just reply with a pastebin of security/privacy tools you would recommend?

Re: Encrypt your Google chats and make the NSA sad

#185
post #168

Earlier quoted context omitted.

Possibly, if they had say, a backdoor in all Intel/AMD processors. The question is what he meant by "We can plant bugs in machines."

Any experts firmware / low level OS hackers can chime in? I imagine this would be Windows focused, then I guess all bets are off. MS would surely cooperate. Now what about an Open Source OS. NSA and DoD loves them some RHEL (Redhat Enterprise Linux). Would they pay RHEL enough to produce binaries that have backdoors in them? Yeah, CentOS compiles the sources and that's cool. But most organizations buy RHEL for suppor…

The hardware would have the backdoor, independent of the software. Think magicpacket http://en.wikipedia.org/wiki/Wake-on-LAN but with a hypervisor rootkit. At least that is what I would do.

Re: Encrypt your Google chats and make the NSA sad

#186

Earlier quoted context omitted.

http://www.pewforum.org/Muslim/the-worlds-muslims-religion-p... The _low_ end is 15-20% who think honor killing is rarely/sometimes/often justified. The high end is 60-70%. How is this "fringe"?

That survey is flawed because it's based on culturally influenced beliefs of Muslims in tribal-based societies where the concept of honor has a higher precedence than religion itself. I believe you would find similar results among Christian and Jewish populations in the Middle-east. For instance, in Egypt, where I've lived for a considerable time, Christians and Muslims share practically the same family values with v…

And similar concepts in certain parts of the US, e.g. the South. "Honor cultures"; correlates with nomadic heritage. Why you can call someone an asshole in NYC and they shrug it off, but south of Mason-Dixon they have to make something of it.

The classic paper: http://mypages.valdosta.edu/mwhatley/7670/activity/honor.htm

Re: Encrypt your Google chats and make the NSA sad

#187

Earlier quoted context omitted.

Glenn Greenwald is a partisan hack, his opinion is worth basically nothing.

In what way is he a partisan? He has condemned as equally bad both the Bush and Obama administrations. When Bush was President, Democrats loved him because he regularly wrote scathing criticisms of Bush's overreaching actions, and now that Obama has carried on Bush's programs (and made them worse, apparently) and Greenwald's criticized him with the same level of intensity, Obama's supporters now seem to loathe him. R…

Partisan means predjiduce in favor of a cause, one can criticize Bush and Obama and still be partisan.

Re: Encrypt your Google chats and make the NSA sad

#188

Earlier quoted context omitted.

Glenn Greenwald is a partisan hack, his opinion is worth basically nothing.

Partisan towards... what? He is a very strong civil libertarian.

Which makes him a partisan. Perhaps you should lookup the word, it doesn't mean what you seem to think it means.

Re: Encrypt your Google chats and make the NSA sad

#189
post #159
post #83

Earlier quoted context omitted.

Further thinking along this line: most people in the world today are dependent on their phones and internet for information and communication. A lot of people suspected total listening capabilities and now we mostly know that's the case. But what if the NSA had total interference capabilities, as Snowden's quote implies? I suspect it does. I've been finding HN to be a hub for all the facets, ideas, and fallout from t…

Today was the first day of WWDC 2013 which announced iOS 7, Mac Pro, OS X Mavericks, and iTunes Radio. Strenuous traffic load is expected this time of year.

Yeah, not sure what I should think about HN when NSA surveillance threads had more points, but Apple announcement thread (MacPro) had more comments (and typical fanboy and haters comments).

Re: Encrypt your Google chats and make the NSA sad

#190
post #102

Earlier quoted context omitted.

I was wondering the opposite: How do you get as many people as possible to trigger the match so that it becomes a losing proposition to do this sort of traffic monitoring.

I don't know how many known terrorist organizations would you like to correspond with on a regular basis?

You wont catch me that easily Mr CIA Man ;)

#

I don't know, I mean that is is a concern: If not enough people fake the attributes you'll get shit-listed. My answer is really that it would depend on the terms of the activity.

I've thought of a couple of ways of doing it.

One is that:

You need to be part of something, I think, that's in general use and automatically sends junk data that can't be read (i.e. encrypted nonsense) between its nodes such that being part of a network isn't distinguishable from the junk connections that the program makes on its own.

The other way I can think of is that:

you have all communications public but encrypted and posted in one (or several depending on the throughput of the service) online bins. Since many people access the same bin and download the same data but can only read their own the meaning of the message becomes dramatically more worthwhile than the traffic-a stuff.

....

The second one might actually - kinda - be being done already in some form or another now I think of it. Encrypt your message, steg it into a meme-pic, stick it on a popular forum. Since the forum is accessed by thousands of people the knowledge of who it's downloaded by doesn't get you very much :/

Post reply on HN