Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

431–440 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#431
post #211

A couple years ago there was an AMA on Reddit from someone saying he was very deeply involved in spying on the general public's online lives, "at a level you can't imagine". Many technical questions were asked, all answered properly. I could never get it out of my head and now that Snowden has emerged I can't stop thinking he was the OP. Wish I could find this AMA again.

Do you happen to have a link to this AMA? Not sure what to search for to find it.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#432

Earlier quoted context omitted.

> Why? The reasoning here is a awfully thin, but has something to do with "being tracked = bad" and then goes into crazy territory from there. You don't understand why tracking may be bad? Or are you just trying very hard to mock his very valid conclusion? Here's other people's thoughts about cellphone tracking: http://www.zeit.de/datenschutz/malte-spitz-data-retention/ (totally crazy, right!) > If he's concerned abo…

Tracking can be bad for some people, it can ruin their careers, destroy their marriage, completely upend their life if that sort of information got out. However, for most of us, it's not especially valuable information and any one day will look like any other. When I engage with social networks, use a cellular phone, I'm aware of the liability. I'm making a conscious trade-off. I really would like it to be less of a…

> it can ruin their careers, destroy their marriage, completely upend their life if that sort of information got out.

> I'm making a conscious trade-off.

No, you're not. If you and the people who have had what you wrote happen to them (they obviously would have been more careful than you) were making conscious trade-offs, nothing bad would have happened to anyone as a result. In fact, you do not even know what information you are disclosing to FB (it's more than you are writing) and other, unknown to you, parties, so a conscious trade-off is impossible. You are just patting yourself on the back for being satisified with your ignorance.

> Either you're trying to avoid being detected, or you're not. There's no half measures here.

From what I understand, he is refusing to provide personal information to a carrier and possibly other unknown parties, because that is potentially harmful and not beneficial in any way to him. Why are you insinuating that he is trying to avoid detection, as if he were some criminal? And by the way, even criminals aren't stupid enough to do everything wrong because they cannot do everything right.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#433
post #40

Noticed one of the screenshots have a URL. It's a little blurry, but I suppose it's an intranet URL since the TLD looks like .nsa URL looks like: https://gamut-wakefield.ein.nsa/utt/UTT/do/FRNewSelector#sel...

Interesting addition. I wondered what some of these abbreviations in the URL stood for. Upon searching, I found this:

http://www.techcareers.com/job.asp?id=64332188&aff=C014D02C-...

Job posting, requiring top-secret clearance, looking for people that have experience using certain tools including "GAMUT/UTT" - notice the URL from the NSA doc has "gamut" and "UTT". So i further looked into GAMUT/UTT and found this:

http://williamaarkin.wordpress.com/2012/03/13/nsa-code-names...

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#434

I asked this in a deeper thread, but i would like to reask anyone that can explain. If the NSA is tapping pipelines as it seems they are, wouldn't the sources such as facebook and google all come online at the same time? if they were in fact referring to the pipeline access as their way into facebook and company, why did they all have different onboarding times? wouldn't they have all come on at the same time: the ti…

My interpretation is that the NSA basically have two main forms of collection: data directly from fibre intercepts, and data obtained (via voluntary agreement, court order, or otherwise) from private companies. This slide [1] would certainly suggest such an arrangement. The fibre intercepts would fairly easily give access to HTTP traffic, and Facebook/Google/etc. would probably 'come online' at about the same time (t…

so if that's the case, then it would seem that facebook, google, etc. are still lying? or could this be more gag order stuff?

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#435

Why is the commentry on this topic always braindead? The article states that there is a query interface using the email address as the key. But Where does it say that every single email/webpage from every single person is being collected? Such a task would be technically impossible. It seems far more likely that it's querying a database of pretargeted people. There is so much hysterical nonsense regarding this topic.…

> Such a task would be technically impossible.

Arthur C. Clarke's first law of technology: 'When a distinguished but elderly scientist states that something is possible, he is almost certainly right. When he states that something is impossible, he is very probably wrong.'

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#436
post #122

Earlier quoted context omitted.

According to tor metrics only 17% of tor endpoints [1] and a similar percentage of relays [2] are in the USA. The kind of monitoring you propose would require a much higher portion of them to be under NSA control. [1] https://metrics.torproject.org/users.html [2] https://metrics.torproject.org/network.html?graph=relaycount...

The question isn't how many endpoints the NSA has, it is how much bandwidth they have at the endpoints (actually, it is more about how many unique users use their endpoints). But, assume that 1% of Tor connections goes through an NSA exit node. 1% of that 1% would go through both an NSA exit node at both ends, and is therefore comprimised. Tor tries to mitigate this by always using the same exit nodes for your connec…

"Tor tries to mitigate this by always using the same exit nodes for your connection"

Think you're getting your entry and exit nodes mixed up there. Tor chooses a small number of entry nodes (entry guards) and attempts to only use those.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#437
post #12

This is brilliant, I love the screenshots: Foreignness factor: The person has stated that he is located outside the U.S. Human intelligence source indicates person is located outside the U.s. The person is a user of storage media seized outside the U.s. Foreign govt indicates that the person is located outside the U.s. Phone number country code indicates the person is located outside the U.s. Phone number is register…

What is really interesting here, is that this disproves what has been said. EVERYBODY'S DATA IS COLLECTED, but to query the data of a US citizen you need to simply provide a 'mitigation reason' as to why you accessing that data.

That then provides an audit trail, where something, or more likely, nothing is done to check that decision was valid,.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#438

Earlier quoted context omitted.

>> Show me all the exploitable machines in country X. > That's cool. I'm guessing this is what Snowden meant by weak endpoint security. That, plus things like Microsoft and Apple operating systems. Don't forget: it's proven they work with the NSA, so backdoors certainly are guaranteed (plus, with Microsoft, we also know they hand 0-day exploits over to the NSA before they're fixed, plus you benefit from all the virus…

There was a document released by the Guardian a few weeks to a month back showing how they also monitor open source issue trackers to find exploitable flaws.

Oh I'm sure they're fighting on all fronts (which we will have to do as well...). But I do believe there are higher-hanging and lower-hanging fruits.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#439
post #376

I'm getting seriously irritated at the "I have nothing to hide" crowd. For starters, here are a few ways this can go horribly wrong: * Industrial espionage -- it's big business, and I'm sure it pays better than being an NSA analyst. * Foreign espionage -- since this gives unlimited querying power to every agent, a single "turned" agent could inflict massive damage on U.S. government and industry interests on behalf o…

Thank you for making that post. I've been repeating these points on broken-record for the last few months.

I would also like to add /family/ as a huge pressure point, akin to your guilt by association.

IOW, one may have nothing to hide, but their family member does and one can be controlled by threats to that family member. It's disgusting and insidious, but that's how bad, scared and dangerous people operate. We are not using our intelligence if we allow ourselves to be vulnerable in this way.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#440
post #376

I'm getting seriously irritated at the "I have nothing to hide" crowd. For starters, here are a few ways this can go horribly wrong: * Industrial espionage -- it's big business, and I'm sure it pays better than being an NSA analyst. * Foreign espionage -- since this gives unlimited querying power to every agent, a single "turned" agent could inflict massive damage on U.S. government and industry interests on behalf o…

Your points are excellent. And even if we all do have nothing to hide, an agency of the government that decides on its own to break the 4th and 1st amendments, and reinterpret the law practically out of existence, in secret, and lies about it to Congress in its oversight capacity, is A Bad Thing(tm).
Post reply on HN