Live data from Hacker News

NSA admits listening to U.S. phone calls without warrants

news.cnet.com

401–407 of 407 posts

Re: NSA admits listening to U.S. phone calls without warrants

#401
post #387

Earlier quoted context omitted.

Probably never. A lot of us "apologists" think that this is actually a good thing, but many are unwilling to admit it, even to themselves. For me, it's simply a matter of valuing truth over privacy.

It actually would be better for the apologists to come out and say that you want the government to have carte blanche access to all of our information. At least it's honest and doesn't waste people's time in these trivial non-debates about peripheral non-issues. OTOH, of course, that posture is all the more stupefying. Which "truth", exactly , is so important that we should all be willing to give up our privacy? And,…

It doesn't matter which truth exactly. The more information they have access to, the better the decisions they will be able to make (in theory, at least).

I don't trust them to wield that power because I don't need to trust them. I hope that by wielding that power, they destroy it by making it clear to the world that privacy no longer exists.

Re: NSA admits listening to U.S. phone calls without warrants

#402
post #271

Earlier quoted context omitted.

He might be interpreting the claim as being that Snowden could do that, which is, of course, false.

I don't follow your "of course, false". Maybe Snowden really could obtain wiretaps of federal judges and the President, either because he was given the discretionary permission to do so in the course of an investigation, or they were available to him with a little trivial privilege-escalation. Alexander might have meant Snowden wasn't supposed to have that capability. Or that Snowden had it but wasn't supposed to use…

What everyone misses about the comment on wiretapping the President is "if I had a personal email." There is no reason, none, that the President's Yahoo Mail account would be different from anyone else's Yahoo Mail account, so it's reasonable that that could be tapped without special permission. His statement did not preclude controls on tapping White House or other .gov emails.

Re: NSA admits listening to U.S. phone calls without warrants

#403

Earlier quoted context omitted.

I'll be happy to supply the sock. > NSA doesn't have Google's private key. And socks come in pairs.

What a classy comment, Jacques.

Get well soon Thomas, maybe you'll find your sense of humour again.

Re: NSA admits listening to U.S. phone calls without warrants

#404

Earlier quoted context omitted.

>Do not stereotype teenagers. So you can do it for him/her? >Yes, most in my generation are shallow and passive You seem very smart - maybe a genius. I've noticed that the smarter people are the more likely they are to denigrate their peers who don't hold the same values. And they're less likely to enjoy other parts of life due to the belief that these things are beneath them. It's not a cool attitude and it will not…

Just like very strong people aren't usually aggressive, really smart people aren't socially aggressive. Once you get past the point of "I can bash your head in and you know it", there's no use for overt aggressiveness. Really smart people are helpful, appreciative and generally nice. The almost smart are the dangerous ones.

I completely disagree with you. You're arguing purely off anecdotal evidence and my experience does not match up with your - for physical strength or intelligence.

Just because someone is smarter or stronger than those around him, does not mean he is confident enough to not rub it in their faces. I've known plenty of intelligent people who are quite aggressive. In fact, it's a bit of a stereotype.

Re: NSA admits listening to U.S. phone calls without warrants

#405
post #79
post #39

Earlier quoted context omitted.

You keep confidently asserting that, but many of the exact same compartmentalization and security procedures which protect the private keymatter also make a secret private key disclosure easier to keep hidden. How would we know otherwise? As you note, that "would be a more outrageous and damning discovery" - so there's more incentive to keep it closely held. It would help the NSA do what it feels it must, simply by u…

TLS client authentication allows the server to detect when an active MITM attempts to get into the connection[1]. This means that if you hold the theory that the NSA is acting as a MITM with Google's private keys, you also have to assume that they know they'll be detected the second anyone tries to use a client certificate to connect. [1] http://security.stackexchange.com/questions/26142/do-client-...

If you have the key from the server, and it's not using a cipher suite that supports forward secrecy, then you do not need to actively MITM to decrypt the traffic. All you need is the long term key and the intercepts. You can then decrypt the session key from the initial connection setup.

This is why the DHE/EDH modes exist. It uses DH to agree on a session key, then uses the long term key just to ensure the DH agreement hasn't been actively mitm'd. The session key is never transmitted or permanently stored, so once the connection cache expires, nobody can decrypt retroactively, not even the parties to the conversation.

Re: NSA admits listening to U.S. phone calls without warrants

#406
post #165
post #48

Earlier quoted context omitted.

I think you may be forgetting that it's not all-or-nothing. Not everyone uses Chrome. I can't speak to a slide deck; We've only seen some slides for one program (PRISM). I am quite sure that NSA has several different programs variously encompassing collection and decryption. Hopefully in the next few days or weeks we'll see details about more of them. I don't think it's beyond the realm of possibility for a nation-st…

Far more than enough people use Chrome (or a different browser with cert pinning) with GMail that such an activity by the NSA would already have been tripped. This is how other hacked SSL certs have been caught in the wild, remember? Do you think Iran has more GMail users than the U.S.? Even my own S/MIME private key the NSA wouldn't be able to get a hold of without actually having to take my smartcard, and I'd certa…

I am talking about entirely passive, offline decryption attacks, not MITM. Think beam splitters.

I'm sure there are browsers out there that won't negotiate PFS DHE modes with Google (which were only enabled a year ago serverside anyway). NSA has had long-haul and undersea fibers tapped for many years.

Cert pinning won't help because it's not MITM.

Re: NSA admits listening to U.S. phone calls without warrants

#407
post #320

Earlier quoted context omitted.

> Your comments have repeatedly attacked the credibility of whistleblowers, derided their claims as factually and technically impossible, and asserted that NSA statements about NSA capabilities are wrong. I'm glad I'm not the only one who's noticed tptacek's tendency to defend "The Establishment" at every turn, whatever naughtiness comes up. There he goes again. I wouldn't be surprised if he had some ties to the gove…

Not sure what you mean here by the establishment. I see him defending google, and rightfully so. I think google is one of the few companies who have been fighting for the privacy rights of users. It would be a shame if other companies saw the effort google puts into this, only to be tar and feathered for something they might not be guilty of.. Those other companies might decide its not worth sticking their neck out f…

> I think google is one of the few companies who have been fighting for the privacy rights of users

.. While happily shitting on their privacy behind their backs by giving a copy of all their communications to the NSA? -That kind of "fighting"?

Post reply on HN