Live data from Hacker News

NSA admits listening to U.S. phone calls without warrants

news.cnet.com

21–30 of 407 posts

Re: NSA admits listening to U.S. phone calls without warrants

#21
post #17
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

A copy of Google's SSL private keys, provided they don't use cipher modes that provide forward secrecy, would suffice if they'd already tapped all the transit fibers (though not gmail-to-gmail).

A copy of Google's private keys would be a more outrageous and damning discovery than NSA somehow having direct access to Google's servers. NSA doesn't have Google's private key.

Re: NSA admits listening to U.S. phone calls without warrants

#22
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

> the NSA would need direct access to the servers that run Google Mail. They do not have that access; Google has categorically denied it, and the Guardian walked the claim back.

Also, I don't necessarily buy this. I don't think Google's denials are lies, as Google is not a single brain, but thousands of individuals. Hard to prove a negative.

Re: NSA admits listening to U.S. phone calls without warrants

#23
post #17
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

A copy of Google's SSL private keys, provided they don't use cipher modes that provide forward secrecy, would suffice if they'd already tapped all the transit fibers (though not gmail-to-gmail).

> provided they don't use cipher modes that provide forward secrecy

They use a PFS cipher spec: http://googleonlinesecurity.blogspot.com/2011/11/protecting-...

Re: NSA admits listening to U.S. phone calls without warrants

#24
post #7

> "Rep. Jerrold Nadler, a New York Democrat , disclosed this week that during a secret briefing to members of Congress, he was told that the contents of a phone call could be accessed "simply based on an analyst deciding that."" I wonder if this will temper the shrill cries of "this is all partisan!" . Probably not.

As an extreme left-wing Democrat who opposes any attempt by government to acquire non-public information without a warrant, I must ask, what "shrill cries" are those?

As one extreme left-wing nut to another, let me suggest that you enter the word "partisan" in the search box below, sort by date, then start clicking back through the past few days.

Re: NSA admits listening to U.S. phone calls without warrants

#25
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

Well, Larry Page says "... we provide user data to governments only in accordance with the law"

If the law is that the NSA just has to request it, no warrant necessary, there you go.

Re: NSA admits listening to U.S. phone calls without warrants

#26
post #22
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

> the NSA would need direct access to the servers that run Google Mail. They do not have that access; Google has categorically denied it, and the Guardian walked the claim back. Also, I don't necessarily buy this. I don't think Google's denials are lies, as Google is not a single brain, but thousands of individuals. Hard to prove a negative.

You think it's possible that NSA got direct access to Google's servers in a way that was invisible to Google's CEO, it's general counsel, its Chief Architect, Justin Schuh of their security team, and any of their thousands of employees, most of whom would immediately report such a thing if they discovered it?

Moreover, having obtained this illicit access, in direct defiance of the corporation that owns and controls those servers, their use of that access is so routinized that it appeared in a "USE BOTH!" Powerpoint deck for NSA analysts?

Re: NSA admits listening to U.S. phone calls without warrants

#27
post #21
post #17

Earlier quoted context omitted.

A copy of Google's SSL private keys, provided they don't use cipher modes that provide forward secrecy, would suffice if they'd already tapped all the transit fibers (though not gmail-to-gmail).

A copy of Google's private keys would be a more outrageous and damning discovery than NSA somehow having direct access to Google's servers. NSA doesn't have Google's private key.

It'd also be vastly easier to do once, covertly, and then keep secret, versus a live connection that mirrors them the plaintext copies. I'm not so sure they wouldn't just do both.

Re: NSA admits listening to U.S. phone calls without warrants

#28
This will play out exactly like the waterboarding thing:

1. The journalists probably already warned the administration about this stuff a couple of months ago.

2. In the near future, the wh press secretary releases a statement about how this is already old news and how the prez already put a halt to this back in February (or whatever) which explains how all the recent statements by wh and Google etc can be truthful.

3. NSA spooks spend the next 5 years whining internally how they can't do their jobs anymore because of all the bothersome warrants.

4. The next top secret program is started in 2018 that does away with all the "cumbersome" oversight.

Re: NSA admits listening to U.S. phone calls without warrants

#29
post #12

So that's not good. You can see how that could be happening; NSA has trunk-level access to telephony circuits. Telcos are engaged in a long-running game of footsie with the government that makes billion dollar Internet companies look like anarcho-capitalists. But I'm not seeing how we get from there to the contents of email. To have the email of arbitrary Americans without a warrant, the NSA would need direct access…

I think that the (theoretical) MITM attack is played out not between the user and google, but google and the other email provider. For example, a person on gmail sending mail to a yahoo account could be comprimised when google talks to yahoo.

EDIT: Yahoo does NOT use TLS SMTP[1]. Also, Gmail fails Cert verification...[1]

[1]http://www.checktls.com/perl/TestReceiver.pl

Re: NSA admits listening to U.S. phone calls without warrants

#30
post #27
post #21

Earlier quoted context omitted.

A copy of Google's private keys would be a more outrageous and damning discovery than NSA somehow having direct access to Google's servers. NSA doesn't have Google's private key.

It'd also be vastly easier to do once, covertly, and then keep secret, versus a live connection that mirrors them the plaintext copies. I'm not so sure they wouldn't just do both.

You're saying that despite the fact that everyone who hits Google Mail with Chrome uses a ciphersuite for which Google's private RSA key only works if you actively man-in-the-middle the connection, no matter how many hard drives you have in Utah, that NSA stole Google's private key, and then (I repeat:) documented that fact in a slide deck for NSA analysts?

You could more easily and credibly argue that NSA has solved the conventional discrete log problem.

Post reply on HN