Live data from Hacker News

Core Secrets: NSA Saboteurs in China and Germany

firstlook.org

41–50 of 130 posts

Re: Core Secrets: NSA Saboteurs in China and Germany

#41

Earlier quoted context omitted.

I actually condone a lot of the NSA's activities, but I take serious issue with: -Warantless surveillance of US citizens (this is bad whether it's by law enforcement, intelligence agencies, or anyone). -Infiltration of foreign companies in allied or neutral nations purely for economic or geopolitical insight, not for military purposes (Brazil's Petrobras oil company, all sorts of spying in Germany and Norway and othe…

> Warantless surveillance of US citizens (this is bad whether it's by law enforcement, intelligence agencies, or anyone). Agreed very strongly. > Infiltration of foreign companies in allied or neutral nations purely for economic or geopolitical insight, not for military purposes (Brazil's Petrobras oil company, all sorts of spying in Germany and Norway and other places). See this is where the NSA really shines. We (T…

If your excuse for doing plainly immoral things is 'geopolitics is important', where do you draw the line? Your excuse can be used to justify pretty much any form of self-serving barbarity. How about if we just don't do evil shit and deal with the lack of an ill-gotten advantage? Works well enough in everyday life (assuming you aren't a mafioso). Why hold people who work for government agencies to such a pitifully lower standard of decency?

Re: Core Secrets: NSA Saboteurs in China and Germany

#42
The document titled "ECI Compartments" is interesting:

* It's possible work out the geographic region of certain compartments based on the organizational code attached to it.

* The redactions in the "Control Authority" column are variable size, possibly even proportionate to character length.

* The fact that document was merely classified "confidential" is odd.

* I was able to identify[0][1] all but one item listed in the "Organization" column.

The sole item that eluded identification was "S0242". It is listed alone under two compartments. I couldn't find anything on it; one can only surmise it is something within the Signals Intelligence Directorate (probably something boring, despite the mystique).

[0] http://en.wikipedia.org/wiki/National_Security_Agency#Struct...

[1] http://www.matthewaid.com/post/58339598875/organizational-st...

Re: Core Secrets: NSA Saboteurs in China and Germany

#43
post #35

Earlier quoted context omitted.

You summarized already in your sentences ("I'm bewildered by this article. It seems really damaging, and like it doesn't really add very much to the corpus they've already published") how you feel and why you feel that way: it appears damaging because it contains the paragraphs that explicitly contain the words "it's damaging." But it's just a general introduction to the "juicy bits" without the bits themselves. In f…

To clarify I mean that I don't believe it adds much to the corpus of information about domestic and civil rights infractions. On the other hand it deals a pretty big blow geopolitically/internationally. The big deal about this article is that it reveals the major tactical capabilities and efforts the NSA has invested in the intelligence war. Edit: Right now HN is limiting the number of replies I can initiate. Will re…

> The big deal about this article is that it reveals the major tactical capabilities and efforts the NSA has invested in the intelligence war.

It does? What is actually new and specific I fail to see. But it's a really, really nice summary.

Re: Core Secrets: NSA Saboteurs in China and Germany

#44

Earlier quoted context omitted.

Are you saying it's retribution for participating in the global cyber intelligence war? Everybody is hacking everybody. Every major country has a cyberintelligence arm. The NSA is just one actor of dozens.

Right, and I hope nobody thinks Russia or China are saints, because they use their technical abilities to suppress dissent in frightening ways. While there's definitely a cyber war going on, you have to ask, why isn't the NSA actively disseminating knowledge to Americans on how to secure themselves? Why are they instead actively weakening encryption standards? America companies have the most to lose from weak encrypt…

>While there's definitely a cyber war going on, you have to ask, why isn't the NSA actively disseminating knowledge to Americans on how to secure themselves?

https://www.nsa.gov/research/selinux/

Re: Core Secrets: NSA Saboteurs in China and Germany

#45
post #38

Earlier quoted context omitted.

Oh nobody thinks they are saints. I hope not. > they use their technical abilities to suppress dissent in frightening ways I'm just going to mention so called "Fusion Centers", which have been used to investigate and disrupt the organization of The Tea Party movement and Occupy Wall Street but spare my usual rant. No it does not compare to Russia or China. Oh and I'm also going to link this: https://firstlook.org/the…

> When it comes to hacking, the attacker always wins. Just playing defense is a losing game. Firstly, why only hacking? What is true for a cyber-attack is true for a physical attack as well. Both sides lose resources in both types of attacks. Secondly, the reason for defending something is because something is worth defending. If it has been defended in an unsuccessful attack, that is a win. And thirdly, the thing be…

> why only hacking? What is true for a cyber-attack is true for a physical attack as well.

A couple reasons. One is that 0day vulnerabilities have no defense. There is no way to defend against certain vulnerabilities.

The second is that there are no international rules of conduct that apply to cyber warfare. After the Georgia/Russia event there was an effort to pass agreements in NATO but AFAIK nothing came of it.

The third is that that a successful attack usually means the victim remains in a compromised state for months or years (look up advanced persistent threat).

Finally, it's also usually the case that cyber attacks go completely undetected.

> the reason for defending something is because something is worth defending

Right, well the NSA does engage in defense as well. There's just less that can be done. There are hundreds of millions of devices in America with an extremely long tail of software/update state and configuration, saying nothing of networks. There's a ton to protect and even protecting small amounts is costly. This is one of the main reasons companies (and governments) are looking to the cloud - you can consolidate your threat area if you concentrate operations and run broadly the same configuration/state across many systems.

> thing being defended often includes a higher-moral-ground

But this is espionage and sabotage. It's dirty business. I don't think it's a good thing. I don't really advocate for it. I'm just here explaining the broader context of the Snowden disclosures and this article. If you missed it there was a link containing 37 other countries that have cyberwar programs (the list is not exhaustive).

Re: Core Secrets: NSA Saboteurs in China and Germany

#46

Earlier quoted context omitted.

> Warantless surveillance of US citizens (this is bad whether it's by law enforcement, intelligence agencies, or anyone). Agreed very strongly. > Infiltration of foreign companies in allied or neutral nations purely for economic or geopolitical insight, not for military purposes (Brazil's Petrobras oil company, all sorts of spying in Germany and Norway and other places). See this is where the NSA really shines. We (T…

If your excuse for doing plainly immoral things is 'geopolitics is important', where do you draw the line? Your excuse can be used to justify pretty much any form of self-serving barbarity. How about if we just don't do evil shit and deal with the lack of an ill-gotten advantage? Works well enough in everyday life (assuming you aren't a mafioso). Why hold people who work for government agencies to such a pitifully lo…

It's not my excuse. It's the NSA's (really the US Gov's) excuse.

I don't know where they draw the line.

If you didn't see it, there's a link on another branch of the conversation containing (at least) 37 other countries involved in cyberwarfare.

It's happening. I'm not excusing it. Honestly, it really sucks.

Re: Core Secrets: NSA Saboteurs in China and Germany

#47
I wonder what's in the tip of the pyramid, shaded in black. Somethings I like to imagine:

- Kennedy was assassinated by CIA

- Aliens transferred technology to US government

- Former strongman of South Korea was assassinated by CIA

- List of other assassinations by CIA

- Iraq WMD was made up and knew about it but went ahead with war anyway.

etc...

Re: Core Secrets: NSA Saboteurs in China and Germany

#48
post #43

Earlier quoted context omitted.

To clarify I mean that I don't believe it adds much to the corpus of information about domestic and civil rights infractions. On the other hand it deals a pretty big blow geopolitically/internationally. The big deal about this article is that it reveals the major tactical capabilities and efforts the NSA has invested in the intelligence war. Edit: Right now HN is limiting the number of replies I can initiate. Will re…

> The big deal about this article is that it reveals the major tactical capabilities and efforts the NSA has invested in the intelligence war. It does? What is actually new and specific I fail to see. But it's a really, really nice summary.

SENTRY EAGLE and the 13 page draft (summarized in the article) is new.

SENTRY EAGLE is the protection program outlined jointly by the NSA and the U.S. Strategic Command.

The first line reads:

"SENTRY EAGLE... compartmented program protecting the highest and most sensitive level [by] NSA/JFCC to support the U.S. government's efforts to protect America's cyberspace."

https://firstlook.org/theintercept/document/2014/10/10/natio...

The document goes on to specify the broad U.S. cyber protection strategy broken down into Sentry Hawk, Sentry Falcon, Sentry Osprey, Sentry Raven, Sentry Condor, and Sentry Owl - all of which are new.

Add on top data about infiltration into (allied) South Korea and Germany. Not a good day for the NSA.

Re: Core Secrets: NSA Saboteurs in China and Germany

#49
post #43

Earlier quoted context omitted.

> The big deal about this article is that it reveals the major tactical capabilities and efforts the NSA has invested in the intelligence war. It does? What is actually new and specific I fail to see. But it's a really, really nice summary.

SENTRY EAGLE and the 13 page draft (summarized in the article) is new. SENTRY EAGLE is the protection program outlined jointly by the NSA and the U.S. Strategic Command. The first line reads: "SENTRY EAGLE... compartmented program protecting the highest and most sensitive level [by] NSA/JFCC to support the U.S. government's efforts to protect America's cyberspace." https://firstlook.org/theintercept/document/2014/10/…

The names are certainly new, but AFAIK the names themselves aren't classified. What's behind the names is classified, but more details about such actions were already published. We just learn more names, that is, how they call these actions internally. And we get a nice summary of the previous disclosures. Written by the authorities who otherwise denied the parts of it even as the specific documents were published. It's that everything is written together that's new. The new potential to embarrasment of the officials is in having it all in one document, which makes the denials much harder.

Re: Core Secrets: NSA Saboteurs in China and Germany

#50
post #49

Earlier quoted context omitted.

SENTRY EAGLE and the 13 page draft (summarized in the article) is new. SENTRY EAGLE is the protection program outlined jointly by the NSA and the U.S. Strategic Command. The first line reads: "SENTRY EAGLE... compartmented program protecting the highest and most sensitive level [by] NSA/JFCC to support the U.S. government's efforts to protect America's cyberspace." https://firstlook.org/theintercept/document/2014/10/…

The names are certainly new, but AFAIK the names themselves aren't classified. What's behind the names is classified, but more details about such actions were already published. We just learn more names, that is, how they call these actions internally. And we get a nice summary of the previous disclosures. Written by the authorities who otherwise denied the parts of it even as the specific documents were published. I…

It's like seeing certain plays from a sport team before, and then after a game seeing their notebook with their general game strategy. Yeah everything we saw before 'fits in' to what was released today - for example we already knew from examples that the NSA works to break encryption - but now we also know that it is considered one of six key investments and that it probably has its own leadership separate from the others. This is useful because you know what programs have more overhead talking to each other/partnering. For example to speculate that corporations probably aren't helping very much with the crypto breaking effort.

(The names are most definitely classified.)

Post reply on HN