Live data from Hacker News

XKeyscore

en.wikipedia.org

21–30 of 117 posts

Re: XKeyscore

#21

This is a reminder why all the traffic should be encrypted and obfuscated (i.e. no SNI in clear text). Ideally, the traffic should be encrypted to resemble a random noise. If you are making an app, you can embed public keys and use those to completely encrypt traffic, without relying on CAs. For example, Telegram does this, using a homemade encryption protocol that has no clear-text SNI like HTTPS. As I remember, WeC…

Isn't the whole issue with net neutrality that ISPs would be incentivized to prioritize their own traffic (or that of companies they collaborate with)? How does making it harder for them to identify traffic for my app/service/whatever stop them from doing that? As long as they can identify the traffic they do want to prioritize (by companies who haven't done the process you describe), it's not obvious to me why they wouldn't have trouble deprioritizing my stuff based on them at least knowing that it's not their own, effect if they don't know whose it is? "Random noise" isn't likely to look like it's their special favorite traffic.

If everyone including the priority traffic did this, then I guess it would have an effect on net neutrality, then I could see that it would make a difference, but I don't see how that could be construed as "whether they like it or not" given that they could just as easily not implement this if they didn't "like it".

That's not to say this isn't worth doing for the privacy and security benefits, but I'm struggling to see how this would have any real-world influence on net neutrality.

Re: XKeyscore

#22

Earlier quoted context omitted.

So instead of collecting at AT&T Room 631 you now collect at Google Room Whatever. The NSA has spent no small amount of time in the last decade obviously interfering with NIST and public encryption standards. The obvious reason is they _want_ to have the magic tools to break some modern encryption.

>So instead of collecting at AT&T Room 631 you now collect at Google Room Whatever. Even if true, significantly degraded. Probably not true though, NSA has been very leaky and such a story would be kind of devastating for Google. NSA lacks the legal capability to force Google to do so, the money to bribe Google to do so and also almost certainly lacks the political backing to put one of the biggest US companies in su…

Google, along with all other major service providers, has a legal portal so law enforcement can process warrant orders. I think all you have to do is hack that portal or process.

Re: XKeyscore

#23
post #19
post #17

Earlier quoted context omitted.

I'm not aware of there being a single lick of evidence to suggest that kookery, but even if he was a Russian agent, he certainly accidentally provided Americans a laudable service.

[flagged]

Not really, he'd be risking whats left of his life by doing so.

There's also rather little reason for Snowden to bother commenting on the very widely known abuses by Russian government, what could he possibly have to offer on that topic that hasn't already been said?

Re: XKeyscore

#24
post #2

How relevant is this (and the NSA's general spying capability) in 2025? We hear a lot about local agencies perusing the services of private companies to collect citizens' data in the US, whether that's traffic information, IoT recordings, buying information from FAANG, etc. What's the NSA's position in the current administration? (e.g. we've heard a lot of noise in the past about the FBI and CIA getting the cold shou…

NSAs collection capabilities have been greatly degraded. They can no longer read all internet traffic, basically everything is encrypted now. NSA does not have magic tools to break modern encryption.

They surely don't have any kind of access to letsencrypt root certs whatsoever

Re: XKeyscore

#25
post #2

How relevant is this (and the NSA's general spying capability) in 2025? We hear a lot about local agencies perusing the services of private companies to collect citizens' data in the US, whether that's traffic information, IoT recordings, buying information from FAANG, etc. What's the NSA's position in the current administration? (e.g. we've heard a lot of noise in the past about the FBI and CIA getting the cold shou…

NSAs collection capabilities have been greatly degraded. They can no longer read all internet traffic, basically everything is encrypted now. NSA does not have magic tools to break modern encryption.

1) They don't necessarily need to break all encryption, just knowing who is talking to who and then delivering a tailored payload is their M.O.; The Tailored Access Operations division exists just for this.

2) They didn't build a Yottabyte-scale datacenter for no reason

3) They have the capability to compromise certificate authorities. Pinned certs aren't universal.

4) Speculation, but, Snowden's revelations probably set off an "arms race" of sorts for developing this capability. Lots more people started using Tor, VPNs, and more, so it would almost be dereliction of duty on their part if they didn't dramatically increase their capability, because the threats they are there to stop didn't disappear.

5) ML/LLM/AI has been around for a while, machine learning analysis has been mainstream for over a decade now. All that immense data a human can never wade through can be processed by ML. I would be surprised if they aren't using an LLM to answer questions and query real-time and historical internet data.

6) You know all the concerns regarding Huawei and Tiktok being backdoored by the Chinese government? That's because we're doing it ourselves already.

7) I hope you don't think TAO is less capable than well known notorious spyware companies like the NSO group? dragnet collection is used to find patterns for follow-up tailored access.

Re: XKeyscore

#26

Earlier quoted context omitted.

NSAs collection capabilities have been greatly degraded. They can no longer read all internet traffic, basically everything is encrypted now. NSA does not have magic tools to break modern encryption.

So instead of collecting at AT&T Room 631 you now collect at Google Room Whatever. The NSA has spent no small amount of time in the last decade obviously interfering with NIST and public encryption standards. The obvious reason is they _want_ to have the magic tools to break some modern encryption.

It’s not Google room whatever, it’s Cloudflare room whatever. That’s why you don’t hear much about undermining encryption standards anymore, who needs that when you have SSL termination for 40% of the internet?

Re: XKeyscore

#27
post #19

Earlier quoted context omitted.

[flagged]

Not really, he'd be risking whats left of his life by doing so. There's also rather little reason for Snowden to bother commenting on the very widely known abuses by Russian government, what could he possibly have to offer on that topic that hasn't already been said?

[flagged]

Re: XKeyscore

#28

Earlier quoted context omitted.

Could you be more specific? It's really hard to have an useful conversation based on a comment like this, but really easy to have one based on a comment which links to specific cases and perhaps even explains how the obvious parallel construction appears.

It's a common "conspiracy theory" that this happened in the Luigi Mangione case even thought I don't agree he's "probably innocent": https://www.reddit.com/r/LateStageCapitalism/comments/1hlmq3... The FBI apparently attempted to use this in the Bryan Kohberger case: https://www.nytimes.com/2025/02/25/us/idaho-murders-bryan-ko... It's hard to find solid coverage of this because obviously the methods are often hidden a…

I don't think the Mangione case is a particularly good example, you wouldn't use a 911 call by a random McDonald's manager to disguise parallel construction.

The caller is easy to identify, how could the government ever trust this person to not reveal their parallel construction? If they were planted by the government, that'd be extremely difficult to hide. The government also likely wouldn't be able to compensate them in any meaningful way for telling such a lie.

The Kohlberger case also does not suggest parallel construction, the DOJ policy isn't binding and the DOJ can in fact legally violate that whenever they want.

Re: XKeyscore

#29
Being familiar with the USG classification system, I was thrown off by the beginning of this article. It doesn't sound like something that would be classified merely as Secret.

The article begins with:

> XKeyscore (XKEYSCORE or XKS) is a secret computer system used by...

This should be edited to:

> XKeyscore (XKEYSCORE or XKS) is a classified computer system used by...

The program is allegedly a Top Secret program.

Re: XKeyscore

#30
post #2

How relevant is this (and the NSA's general spying capability) in 2025? We hear a lot about local agencies perusing the services of private companies to collect citizens' data in the US, whether that's traffic information, IoT recordings, buying information from FAANG, etc. What's the NSA's position in the current administration? (e.g. we've heard a lot of noise in the past about the FBI and CIA getting the cold shou…

NSAs collection capabilities have been greatly degraded. They can no longer read all internet traffic, basically everything is encrypted now. NSA does not have magic tools to break modern encryption.

They don't break encryption, they circumvent it. They get into people's computers and access the stored data after it's been decrypted. They stockpile zero day vulnerabilities and use them against their targets in order to install persistent malware. They intercept equipment and literally implant hardware onto the PCBs that let them access the networks. They have access to hordes of government CCTVs. They have real time satellite imaging. They have cellphone tower data.
Post reply on HN