Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

181–190 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#181
post #72

Earlier quoted context omitted.

Can you please provide your definition of intelligence? I would argue that theoretically , a government (or other entity) could use intelligence but use it within a set of moral and/or ethical guidelines that uses a system of checks and balances.

Intelligence is the dirty-but-necessary stuff that makes it possible to accurately guide diplomacy, economic policy, trade, and military action to achieve the desired goals of a nation-state for a minimum of cost. It includes internal security. Generally, intelligence cannot operate openly, even under a strict set of guidelines. Further, there will always be situations where efficacy runs into guidelines and somethin…

Would you be willing to violate the privacy of 6 million people to commit genocide?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#182

Earlier quoted context omitted.

Germany's investigation found that it likely didn't happen and that the documents saying it did were possibly forgeries. http://mobile.reuters.com/article/idUSKBN0JP1QG20141211?irpc... > "the document presented in public as proof of an actual tapping of the mobile phone is not an authentic surveillance order by the NSA. It does not come from the NSA database. > "There is no proof at the moment which could lead to cha…

Did you RTFA?

The one I linked? Yes. Did you? What did I misrepresent, exactly?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#183

Isn't the NSA breaking US law by hacking into a commercial entity's network?

Which is probably why GCHQ was the one doing the actual hacking. NSA just got a share in the prize.

That seems to be the real value in the Five Eyes network.

Each member can undertake surveillance of the domestic communications of the other members, thus absolving the own-state surveillance apparatus from claims of domestic spying. But the poisoned fruit may be (and appears to be) freely shared.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#184
post #11

[deleted]

The SIM card bit is actually I think a distraction. The real issue should be the means: the NSA/GCHQ intentionally targeted innocent/non government affiliated people's personal email and social networking. That's different than collecting everyone'ss data and claiming you never look at it unless someone does something to loose their innocence. Orwellian nightmare that that is and probably bullshit, revelations along…

No, that's actually the bread and butter of intelligence work. At least it was in HUMINT, if not in SIGINT. You identify individual(s) with access to what you need and then work on/with them. This is not surprising or even controversial (mind you, I am not in any way in favour of such things, just playing the devil's advocate a bit) at all. Hard evidence of dragnet, massive, all encompassing surveillance really is the new revelation that has come out of Snowden leaks including this one. Targeting of individuals (especially if they're foreigners) was always going on.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#185

Earlier quoted context omitted.

Which is probably why GCHQ was the one doing the actual hacking. NSA just got a share in the prize.

That seems to be the real value in the Five Eyes network. Each member can undertake surveillance of the domestic communications of the other members, thus absolving the own-state surveillance apparatus from claims of domestic spying. But the poisoned fruit may be (and appears to be) freely shared.

If I receive and use/sell stolen property, I've broken the law even if I didn't steal it.

I would think if anyone could work their way through the "standing" restrictions, it could be shown in court that the NSA violated the Constitution by receiving "stolen" surveillance data.

The reason why we have the 4th Amendment is not because the act of spying is feared (as egregious as that is), it's because of what the government might do with the results. So receiving the data violates at least the spirit of the constitution, and I would think the letter also.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#186

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

But you might do something wrong. Or something innocent you did today may be illegal tomorrow. And when those days come, the NSA is ready and watching.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#187
post #185

Earlier quoted context omitted.

That seems to be the real value in the Five Eyes network. Each member can undertake surveillance of the domestic communications of the other members, thus absolving the own-state surveillance apparatus from claims of domestic spying. But the poisoned fruit may be (and appears to be) freely shared.

If I receive and use/sell stolen property, I've broken the law even if I didn't steal it. I would think if anyone could work their way through the "standing" restrictions, it could be shown in court that the NSA violated the Constitution by receiving "stolen" surveillance data. The reason why we have the 4th Amendment is not because the act of spying is feared (as egregious as that is), it's because of what the gover…

Maybe. Seems to me that there's a bit of an issue with the general operating mode of an intelligence agency. I've said in the past that I wasn't generally overly concerned with stories such as the NSA's reported monitoring of German chancellor Angela Merkel -- which later reports suggest might _not_ have happened -- apparently they're not even totally up on which close national ally heads-of-state they're spying on. But keeping tabs on other countries -- even friendly ones -- yeah, that's part of the basic remit.

But an organize "we'll spy on yours if you spy on ours" arrangement, particularly with a "don't ask for it, we'll just give it to you" understanding. That's violating the intent of legal and constitutional protections every which way.

At the same time, if a talent scout in North Whateveristan gets handed a sheaf of goatskins exfiltrated from the local TCP-over-parchment connectivity provider, the legality of that data's acquisition shouldn't be a hinderence.

But if North Whateveristan happens to be a friend and we're concerned with that the goatskins reveal, then breaking that information to the government (or other friends in slow places) should be possible at some level.

If there's a resolution by law in this, it's likely going to have to require explicit controls over how and when data of a given nation's nationals or residents is provided to that nation. And bars on mass transfers.

Perhaps mandating them outside intelligence services through diplomatic channels?

At least that'll give Wikileaks a sporting chance.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#188
post #185

Earlier quoted context omitted.

If I receive and use/sell stolen property, I've broken the law even if I didn't steal it. I would think if anyone could work their way through the "standing" restrictions, it could be shown in court that the NSA violated the Constitution by receiving "stolen" surveillance data. The reason why we have the 4th Amendment is not because the act of spying is feared (as egregious as that is), it's because of what the gover…

Maybe. Seems to me that there's a bit of an issue with the general operating mode of an intelligence agency. I've said in the past that I wasn't generally overly concerned with stories such as the NSA's reported monitoring of German chancellor Angela Merkel -- which later reports suggest might _not_ have happened -- apparently they're not even totally up on which close national ally heads-of-state they're spying on.…

> But an organize "we'll spy on yours if you spy on ours" arrangement, particularly with a "don't ask for it, we'll just give it to you" understanding. That's violating the intent of legal and constitutional protections every which way.

That is exactly my point. And it's horrible, it's the government thuggishly wiping its ass with the Constitution. East Germany would have swooned in ecstasy at all the intelligence porn collected by the NSA.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#189
I think one of the big issues here is that for an intelligence agency, good defensive security is essentially silent. There's not a lot of money or political capital in "nothing broke today."

On the other hand, good offensive capabilities, even if kept secret externally, are loud and flashy within the organisation, and come with lots of political capital beyond it.

Because of this asymmetry, I think it's almost impossible for an intelligence organisation to stop its "defense" mission being swallowed by the "attack" one. And so we all end up less free and less safe.

I do sometimes wonder what the world would be like if the NSA took it as its mission to secure the internet and chain of encryption, rather than constantly breaking it. If, for example, they used their resources to seek out vulnerabilities and exploits and fix them.

Maybe such a world is impossible. But I do think there's a valid space for a national cyber defense organisation that runs counter to this trend, that acts to shore up the infrastructure rather than constantly subverting it.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#190

Isn't the NSA breaking US law by hacking into a commercial entity's network?

The NSA is freely admitting to direct domestic mass surveillance at its website which details the extent of the domestic spying, the search, seizure, and indefinite storage of ALL citizen electronic data. The fact that there is no discussion or disagreement of this in the US media and amoung US Citizens is tacit approval given the transparency shown by the NSA Domestic Surveillance Website: http://nsa.gov1.info/utah-data-center/
Post reply on HN