Live data from Hacker News

Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

electrospaces.net

221–230 of 243 posts

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#221
post #37

Earlier quoted context omitted.

Why can't the NSA just force a web PKI cert provider to create a fake certificate for them? We know from the Lavabit case that once you start keeping private keys away from the feds they start making problems for you. Prove to me that every single root your browser trusts is not compromised.

To catch that we have Certificate Transparency. It's not 100%, but makes it a risky proposition and not viable for large scale.

These kinds of attacks are usually run by a major threat actor (i.e. nation state), targeted, and not run at large scale. Certificate transparency is unlikely to help in this case. Key pinning was the more secure option. For some issues see:

https://www.agwa.name/blog/post/how_will_certificate_transpa...

https://tools.ietf.org/html/draft-ietf-trans-threat-analysis...

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#222
post #34

It's very important that we keep Huawei out of our 5G networks! (what if they discovered things like this and told the citizens about it?)

Please stop equating totalitarian regimes with democracies.

I don't want to be the wise guy, but you know that technically, the People's congress was elected correctly, right?

And yes, they had multiple parties until the republicans had two elections in a row, and managed to influence the supreme court so much that they could gain total power over new arising parties (declaring them illegal from the start if they do not represent the congress's opinion), up until there was no way to get elected because the media was controlled by the very same laws.

See any parallels regarding Fox News and the Republicans or say, Dick Cheney?

No? Maybe do some research on your own and sleep over this.

China is actually the only country I would compare US's democracy with, because a lot of candidates have no choice but to join one out of two partied to even get considered to be elected. And it's not the 1st vote that decides this, because democracy in the US doesn't differ between party votes and candidate votes (whereas most other democracies have moved on, for like hundreds of years, and fixed this).

Thr problem I see here is that the US didn't have a revolution. Europe had to be crushed a couple of times in order to learn how to prevent their architectural mistakes in future.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#223

Earlier quoted context omitted.

The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with. The…

> The people who visit this website are the people who are paid to create and administer all of this technology. Exactly, some falsely assume all technologists somehow share an enthusiasm for morality. Many of the most successful technologists I know simply work for the highest pay from military/intelligence contracts.

Your comment implies that working for military/intelligence is automatically immoral. Nothing could be further from the truth. Believing that freedom is "free" is highly delusional. This civilization that we have, and enjoy, almost entirely depends on having more, better, bigger guns than the "bad guys" (in fact, having more, better, bigger guns is the best way to ensure you don't have to use them).

What you do with the guns is a different issue, but there's clearly many nations worldwide that focus on defense but not offense (maybe not US, but probably Switzerland).

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#224

Earlier quoted context omitted.

Signal has open clients with reproducible builds. We know that they are keeping their promises wrt what information is communicated with the backends. That's a step above the other options in common use, and in fact does make Signal special.

> Signal has open clients with reproducible builds. Not really. First of all, there is only one Signal client allowed to connect to Signal’s servers. And in the real world, the vast majority of Signal uses are getting their APK for that app from the Google Play store (the Signal team has said that they prefer you to use the Play store as well, instead of direct-downloading an APK from their website which they offer o…

Both these attacks indicate a problem that doesn't have anything to do with using Signal. If the actor can replace apps on your specific phone, then you're pretty fucked no matter what app you use.

If the attack is on the android dev kit, but not on signal, then.. the attack isn't on Signal, it's on the dev kit. Unless Signal's using an unusual version of the dev kit, your risk exposure to this attack is equal to any other app that you would use instead of Signal.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#225
post #129
post #26

Earlier quoted context omitted.

> Dulles One gets the impression his claim that all the CIA's successes are secret is a lie. Because there never were any. You would thing 50 years after the man kicked it that at least something would be come out. Not really surprising. If you look at how successful organizations are structured the CIA is not that.

> One gets the impression his claim that all the CIA's successes are secret is a lie. Because there never were any Who do you think fought and won the cold war, Seal Team Six?

What won the cold war was the West's consumer industrial base. Not the military industrial complex, and certainly not the incompetent people at the CIA with their cunning plans.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#226

Earlier quoted context omitted.

The term "hacker" in "hacker news" is too misleading, especially those of us who use the more RMS-esque definition of it. Petition to change to something more appropos.

Lol petition to stop naming anything because eventually all labels become bad. /s

we should made labels by hashing publicly registered semi-precise definitions, and maybe add markers to indicate how closely what we mean fits said registered definition of the label.

(I don't actually think this is what people should do, but I do think it might be a cool expirament.)

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#227

Earlier quoted context omitted.

It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…

What most people don't understand is that a targeted IP, with a stream size and a timestamp is enough to identify pretty every https page uniquely if it is accessible by a spider. A headless chrome makes measurements of timings even easier these days. The order of how files are loaded, which file size e.g. jquery.123.min.js has, and where and when exactly in which order it is loaded from is very unique among all page…

>stream size and a timestamp

I think that's more complicated than you realize. That list would be impossibly large to scrape and search, not to mention collisions and dynamic content problems.

>The order of how files are loaded

It's a good idea, but you don't know what files I have in my cache and when they expire, or what files my extensions are blocking. This'd only work in an ideal-case scenario.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#228

Earlier quoted context omitted.

As an European, does it really make a difference? Is USA really much better than China?

I think the US is much better at collecting data. The US has been proven to collect data and plant backdoors, China has not, despite how much the US states that eg. Huawei has backdoors in their 4G/5G equipment. So either China is much better when it comes to privacy online, or just way more competent as they manage to avoid getting caught. They both suck in their own way, that's for sure.

Answering to both responses to my post: as an European citizen I know that technically US is better at doing data collection, even more so because it's a "friend" country and we can't wait to give our data to them

But my question really is: does it really matter to me, provided that the data is gonna be collected anyway, who does it?

They're both, at my eyes, not doing it to my advantage.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#229
post #129

Earlier quoted context omitted.

> One gets the impression his claim that all the CIA's successes are secret is a lie. Because there never were any Who do you think fought and won the cold war, Seal Team Six?

What won the cold war was the West's consumer industrial base. Not the military industrial complex, and certainly not the incompetent people at the CIA with their cunning plans.

> West's consumer industrial base. Not the military industrial complex

Imagine thinking those are two separate things.

Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA

#230

Earlier quoted context omitted.

That seems more than just the dangers of metadata. That's more of the dangers of giving machines the authority to drop bombs with no human oversight at all. That same kind of problem could happen if the government wasn't spying on anything, or if the government was spying on content, not just metadata.

Humans follow orders which are given by humans on the basis of data which is analyzed by machines and interpreted by humans. If the machine says "dude is terrorist based on XYZ" and the human cannot realistically verify all of that is factually correct (perhaps the subject's phone was lost as the subject walked by a mosque?), then it is much easier for the human to say "Data says this dude is terrorist" than it is to…

I believe the core problem there is still making extreme decisions without proper evidence. This could happen if the government knows much less about you (e.g. just the info on your driver's license) or much more about you. That is, the problem in these specific examples is not the existence of the data, but rather the willingness to throw caution to the wind and operating on shaky foundations.
Post reply on HN