Live data from Hacker News

XKeyscore: NSA program collects 'nearly everything a user does on the internet'

theguardian.com

441–450 of 641 posts

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#442

>How do I find a strong-selector for a known target? >How do I find a cell of terrorists that has no known connection to strong-selectors? >Answer: Look for anomalous events >E.g. Someone whose language is out of place for the region they are in >Someone who is using encryption >Someone searching the web for suspicious stuff Lovely. Suspicious stuff and encryption. But wait! There's more! >Show me all the VPN startup…

I'd like to know where they are keeping these "over 300 terrorists" that have been captured due to this program. How is one labeled a terrorist by this program I wonder?

Well, we know what happens when they're "caught" - they're put in Guantanamo forever.

Pretty fucking scary if you ask me.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#443
As one slide indicates, the ability to search HTTP activity by keyword permits the analyst access to what the NSA calls "nearly everything a typical user does on the internet".

It seems like everyone's been attacking the wrong folks. From this article it appears that bulk of the data is being tapped at the data center level and then parsed. This begs the question how it would be able to make sense of https traffic.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#444

Earlier quoted context omitted.

I'd like to know where they are keeping these "over 300 terrorists" that have been captured due to this program. How is one labeled a terrorist by this program I wonder?

This. This is what worries me more than anything. Where have these 300 people gone? There should be records, trials, something. 300 suspected terrorists going on trial over a period of 5 years should have resulted in huge wave of almost 24/7 publicity. That the NSA is in the business of total surveillance is bad enough. But there is the faint hint that the NSA is in the business of making people disappear.

Black sites are still there. Black sites with dubious givernments do the disappearances for the CIA, wihout them getting their hands dirty unless they have to.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#445
This has been up here for 5 hours and on the Guardian's website for nearly 6 hours. How is it possible that not the NYTimes, FOX, NPR, the Washington Post, or CNN have picked this up? These organizations are an embarrassment to the profession of journalism.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#446

Earlier quoted context omitted.

Why would we assume that TLS is safe? The NSA could just as easily compromise the CAs and get all the certificates they need.

Not exactly. Compromising a CA would let them fool a browser into thinking that a fake Google certificate is a real one. However, if Google were diligent, they could publish their valid cert signatures anywhere they like, and users could check the signatures of the certs that are presented as genuine. The TSA can't crack or impersonate a cert at will; they can only 1) try to trick you into accepting a phony one or 2)…

Google is actually quite diligent in this regard and have caught CAs with their pants down in the past.

They're taking it a step further and using certificate pinning in Chrome to catch MITM attacks in real time across a large portion of the internet. http://blog.chromium.org/2011/06/new-chromium-security-featu...

It's not scalable at all, but cuts out a large attack vector for a lot of communications. It wouldn't take a ton of pinned certificates to make a big dent in these NSA programs--really just look at the logos and make sure that each has their certificates pinned.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#447

Earlier quoted context omitted.

Stallman's stance is against all cell phones, not just smartphones. And I'd argue that in 2013, to the point where we're issuing basic phones to welfare recipients for the purpose of job searching, that this is an invalid conclusion. As is only using the FSF's definition of free software (where it matters less that the software itself is free, but that the software doesn't point out to you any nonfree addons. Fedora…

I fail to see how not owning a cellphone, only using free software and suitable hardware puts me at a greater inconvenience than, say, having all my life (movements, communication, interests) digitally recorded and made available for later arbitrary use (by any type of government we might have ...). I honestly wish I had the willpower and independence to pull it off. On the other hand, I totally understand the people…

That's a laughably false dichotomy. Using free software does not in any way guarantee that you won't be tracked online.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#448
post #294

Earlier quoted context omitted.

Just want to clarify something: > I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail? I don't know how they're getting GMail(and this is probably a slide from when GMail was accessible via HTTP and not HTTPS), but Facebook chat specifically is done over a non-secure XMPP server. The only 'secure' part of that transacti…

With Gmail, all it takes is one request to almost any Google service to leak through a non http connection and they have your Auth cookie. Once they have that, they are you. And yes it is that easy, anyone can pull it off at Starbucks, hotels, even some ISPs.

Not speaking for Google, but in general, auth cookies (rather than identity cookies) will only be sent over HTTPS using the "Secure" cookie attribute. This is something done at the browser level, so short of using a very badly behaved browser or HTTP client, this is unlikely to happen.

Re: XKeyscore: NSA program collects 'nearly everything a user does on the internet'

#450
post #414

Earlier quoted context omitted.

The technical possibility isn't the new and staggering part, it's the profound lack of morality, respect for any ideal whatsoever, and compete apathy towards the oaths these people took to serve us . They have compeley misused the power we granted them in sacred trust. We should remove it from them at once. If this has become impossible, we need to know that as soon as we can.

> The technical possibility isn't the new and staggering part, it's the profound lack of morality, respect for any ideal whatsoever, and compete apathy towards the oaths these people took to serve us. Again, I'll chime in as the resident apologist. The people working at Fort Meade are not evil. They truly believe they're doing a great service to the nation. They may be wrong, and they've certainly thrown privacy out…

I'm not American, so I'm wondering: was the public really actually behind the PATRIOT Act, or were they merely giving leeway in a time where everyone was supposed to go along? Or were you thinking that's the same thing?

Same with the politicians; were they really for it, or simply incredibly afraid of the political suicide that would be the results of standing up against it? Because this was a time when people did not question Bush. From today's perspective on his administration's actions, that seems odd, but it was the reality at the time.

Post reply on HN