Live data from Hacker News

XKeyscore

en.wikipedia.org

61–70 of 117 posts

Re: XKeyscore

#61
post #56

The most interesting detail about the whole XKeyscore story is that it was apparently not leaked by Snowden https://www.schneier.com/blog/archives/2014/07/nsa_targets_p... https://www.reuters.com/article/opinion/commentary-evidence-... https://www.theguardian.com/us-news/2014/oct/11/second-leake... It is possible that the "second source" and the shadow brokers are one and the same. https://www.electrospaces.net/2017/…

The Guardian sourced information about it to Snowden's leaks in 2013. What makes you think it's from a separate leaker, and that it's the same leaker as the "shadow brokers"? All I see is conjecture in those links.

Multiple people who have seen the entire Snowden dump claim that various files leaked by specific sources were not contained within the Snowden dump.

Yes, the idea that the "second source" and TSB are the one and the same is necessarily based on conjecture. Nobody is presenting it as a fact, but as a rather likely option based on analysis of data released by TSB and NSA leaks which cannot be attributed to Snowden.

Both TSB leaks and "second source" leaks originate from the same time period, and the same locations within the NSA. That does not mean that they were leaked by the same person(s), but it is a fairly likely option.

Re: XKeyscore

#62

Earlier quoted context omitted.

You can't decrypt anything with letsencrypt root certs, you can issue your own certificates but it would be impossible to use those at any significant scale. It's also worth considering that CT makes it extremely noisy to use such certificates to attack web browsers.

I'd bet they could absolutely proxy large parts of people and make use of these certs. I wonder how much are CT logs scrutinized, would these "rogue" certs be found easily because we can't find traces of them being generated by letsencrypt ? Browsers checks CRLs but are they checking CT logs to be ensure the cert they're checking was logged ?

They couldn't do that at scale without being detected, no. There are various people actively looking for this, and the existing tooling makes it easy to detect.

>Browsers checks CRLs but are they checking CT logs to be ensure the cert they're checking was logged ?

Yes, all modern browsers require certificates to be in the CT logs in order for them to be accepted.

For example, we can easily pull up logs for gmail.com and see which certificates browsers would accept. https://api.certspotter.com/v1/issuances?domain=gmail.com&ex...

Re: XKeyscore

#63

Earlier quoted context omitted.

Support implies action, silence is inherently passive.

[flagged]

The existing evidence seems to suggest that Snowden was not actively trying to flee to Russia, but ended up stuck there due to reasons outside of his control.

Re: XKeyscore

#65

Earlier quoted context omitted.

NSAs collection capabilities have been greatly degraded. They can no longer read all internet traffic, basically everything is encrypted now. NSA does not have magic tools to break modern encryption.

>NSA does not have magic tools to break modern encryption. They don't. But they have other options. For example, Cloudflare is an American company that has plaintext access to the traffic of many sites. Cloudflare can be compelled to secretly share anything the NSA want.

Or if they have a deal or double agent working for them, there is a possibility for "full take" just like at AT&T. Seems pretty likely to me. Allegedly there are tens of thousands of undercover employees stationed throughout the economy in the "signature reduction" program. National security programs don't respect laws when there is something considered "important" if they can get away with it.

https://www.newsweek.com/exclusive-inside-militarys-secret-u...

Re: XKeyscore

#66

Earlier quoted context omitted.

>NSA does not have magic tools to break modern encryption. They don't. But they have other options. For example, Cloudflare is an American company that has plaintext access to the traffic of many sites. Cloudflare can be compelled to secretly share anything the NSA want.

>Cloudflare can be compelled to secretly share anything the NSA want. This is true given some possible interpretations, false given other possible interpretations. Cloudflare can be secretly compelled to share specific things, there's no legal mechanism to compel Cloudflare to share everything .

Wasn't the whole thing that the secret courts were too liberal in access they were granting?

Re: XKeyscore

#67

Earlier quoted context omitted.

>NSA does not have magic tools to break modern encryption. They don't. But they have other options. For example, Cloudflare is an American company that has plaintext access to the traffic of many sites. Cloudflare can be compelled to secretly share anything the NSA want.

Or if they have a deal or double agent working for them, there is a possibility for "full take" just like at AT&T. Seems pretty likely to me. Allegedly there are tens of thousands of undercover employees stationed throughout the economy in the "signature reduction" program. National security programs don't respect laws when there is something considered "important" if they can get away with it. https://www.newsweek.c…

A double agent would not get you "full take", it'd be impossible to hide the traffic. A double agent could maybe feasibly steal keys from Google, but they'd have to do that all the time because the keys are constantly rotated.

And even then, stealing keys does not give you passive decryption and active decryption would be incredibly noisy.

NSA does not have enough money to spend to be able to incentivize Google to give them full take intercepts either.

Re: XKeyscore

#68

Earlier quoted context omitted.

>Cloudflare can be compelled to secretly share anything the NSA want. This is true given some possible interpretations, false given other possible interpretations. Cloudflare can be secretly compelled to share specific things, there's no legal mechanism to compel Cloudflare to share everything .

Wasn't the whole thing that the secret courts were too liberal in access they were granting?

Not in the sense that they were ordering companies to facilitate full take collection of content by the NSA, no.

Hence the famous "SSL added and removed here ;-)" slide

Re: XKeyscore

#70
post #2

How relevant is this (and the NSA's general spying capability) in 2025? We hear a lot about local agencies perusing the services of private companies to collect citizens' data in the US, whether that's traffic information, IoT recordings, buying information from FAANG, etc. What's the NSA's position in the current administration? (e.g. we've heard a lot of noise in the past about the FBI and CIA getting the cold shou…

NSAs collection capabilities have been greatly degraded. They can no longer read all internet traffic, basically everything is encrypted now. NSA does not have magic tools to break modern encryption.

Dont need to break encryption if you read data from the source -- O/S vendors will do it for you.
Post reply on HN