Live data from Hacker News

US intelligence mining data from 9 US Internet companies in broad secret program

washingtonpost.com

391–400 of 420 posts

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#391
post #289

Earlier quoted context omitted.

How does Skype's key exchange work? If the supernode hands out an address for a server that intercepts the call, would the Skype client still accept it and connect?

The protocol itself is highly obfuscated, but from my understanding of what has been published it works something like this: (lots of disclaimers here that nobody outside of Microsoft/Skype really knows for sure) When logging in an RSA public/private key pair is generated and the public key is sent up to the server. The username to public key mapping is seeded to supernodes and inserted into the global address book.…

Can you provide a source for the statement:

>If you are a government agency with a private key that matches one of the observer public keys (Russia, China, and India have openly claimed to have these

I am not calling bullshit, I just want to know more.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#392
post #289

Earlier quoted context omitted.

How does Skype's key exchange work? If the supernode hands out an address for a server that intercepts the call, would the Skype client still accept it and connect?

The protocol itself is highly obfuscated, but from my understanding of what has been published it works something like this: (lots of disclaimers here that nobody outside of Microsoft/Skype really knows for sure) When logging in an RSA public/private key pair is generated and the public key is sent up to the server. The username to public key mapping is seeded to supernodes and inserted into the global address book.…

Can you provide a source for the statement:

>If you are a government agency with a private key that matches one of the observer public keys (Russia, China, and India have openly claimed to have these

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#393
post #289

Earlier quoted context omitted.

How does Skype's key exchange work? If the supernode hands out an address for a server that intercepts the call, would the Skype client still accept it and connect?

The protocol itself is highly obfuscated, but from my understanding of what has been published it works something like this: (lots of disclaimers here that nobody outside of Microsoft/Skype really knows for sure) When logging in an RSA public/private key pair is generated and the public key is sent up to the server. The username to public key mapping is seeded to supernodes and inserted into the global address book.…

Can you provide a source for the statement:

>If you are a government agency with a private key that matches one of the observer public keys (Russia, China, and India have openly claimed to have these

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#394
post #232

Earlier quoted context omitted.

If you're referring to online petitions then you needn't waste your time, there are already petitions to make sure this never happens. It's called US Senate elections[1]. [1] http://en.wikipedia.org/wiki/United_States_Senate_elections,... That bullshit called the Presidential elections? It's a dog and pony show.

I totally understand that regarding the petitions and everything else - but John Q Public may not and seeing millions sign a petition that is ignored will hopefully cause a further awakening in people.

Did all the other ignored petitions cause any awakening?

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#395
post #171

I've lived under surveillance before, so I feel my perspective might be somewhat appropriate. I won't comment on the specifics (uninteresting and irrelevant, had to do with where I was living). I won't even make a statement about whether it's justified in my case or in general. I'd just ask everyone here to do one thing: Watch this, then ask yourself how you feel (if it doesn't go directly to 6:40, fastforward to it,…

And my guess is the following video is an example of why the NYT is now saying that Obama no longer has any credibility on this issue: http://www.youtube.com/watch?v=B6fnfVJzZT4

I cringed when he mentioned the National Security Letters. Didn't even realize he was supposed to be getting rid of those, too.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#396
post #317

Earlier quoted context omitted.

Here's a Devil's Advocate position (not necessarily my personal beliefs, so please don't downvote based on disagreement. Just rip it to shreds instead!): The fear of losing privacy to the government is based on the fear that this increased surveillance will be used by the government to smother dissent. This is a valid fear, but has the government yet used surveillance to smother dissent? If you can find a solid examp…

By the time they're using these extreme powers to smother dissent, you're fucked. It's game over and your ability to speak out using the first amendment is non-existent. The very reason why these things should never be allowed, is because the absolute protection of freedom of speech is ultimately the last safeguard against tyranny (before you get to violence anyway). Why let the guy into my house with a gun and roll…

>By the time they're using these extreme powers to smother dissent, you're fucked. It's game over and your ability to speak out using the first amendment is non-existent.

This is how revolutions are started. There's no "game over." A population always has the option to rise up against their brutal regime. Especially in a place like the United States, where individual freedoms are highly prized and there is a rather large contingent of heavily armed and often angry population.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#397

Earlier quoted context omitted.

As many have stated, the problem is with inevitable abuse of power. It may or may not be happening now, but it will. Recent IRS disclosure that they targeted Tea Party-linked organizations for audits is one example. I doubt it was deliberately ordered by the administration, but someone, somewhere thought it was a good idea. Search queries alone will probably tell you which way a person is leaning in an election. That…

Tea party groups weren't targeted for audits. Groups that applied for tax exempt status on basis of providing social welfare were sent for additional screening to ensure the group was not primarily a political group. There were over 300 applications sent for additional screening. 1/3 were conservative groups. 1/3 were liberal. The whole problem was the selection criteria for being reviewed - based on the name of the…

My bad, not audits, but still...

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#399

Question to the more experienced hackers here: Would such a massive undertaking be possible without the knowledge of the regular developers working at these companies? Some big names on that list, like Facebook (and I think Dropbox was 'coming soon'). If developers at these companies knew about these measures, I'm really skeptical in believing that it took an intelligence officer to expose this story. Chances would b…

I had the same question and it leads me to believe the companies saying they had no idea. Someone at Google/MS/Facebook would almost surely notice those extra servers over there, all that extra network traffic going somewhere, or those cables that seem to go into a locked closet.

I think it's far more likely this is built off the back of the data they're already known to be sucking down via major exchanges.

A national security letter for the TLS certs and you can take what you want, when you want off straight from the stream of packets.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#400
post #274

Earlier quoted context omitted.

Interestly enough, speed cameras and highway patrols have nothing to do with traffic safety either. Highways could easily have camera systems to monitor the exact time when cars get on and off exits to determine how fast on average they were going during their trip. These systems have been tested and work, but the fact is that actually cracking down on speeders is massively unpopular and a political non-starter.

Or you know, that there is such a thing as safe speeding, such as when overtaking or to avoid an accident, and creating a system which would require someone to slow down and become a traffic hazard in order to avoid a fine, is absurd, oddly draconian, and likely to increase accident rates?

This and the cost of deployment. Police, for all their foiles and failings are capable of judging a situation as another human would. Thus they can use their discretion in handing out tickets.

Simple fact is that speeding is not that much of a problem. Certainly people do it and it's dangerous, but most people obey speed limits within acceptable parameters and drive fairly safely. Present levels of speed enforcement are doing their job and greater levels would have a point of diminishing returns.

Post reply on HN