Earlier quoted context omitted.
They still read emails. No doubt they're inside Google, Microsoft, Apple. They might not be inside Proton Mail, it uses PGP but keys are stored server side so I wouldn't know. No doubt they still read texts. I think the US is still among the countries that use SMS a lot. They no doubt have access to the data big tech's mined out of the entire world's population. That capability alone puts them into "bring everything…
>They still read emails. No doubt they're inside Google, Microsoft, Apple. They might not be inside Proton Mail, it uses PGP but keys are stored server side so I wouldn't know. I don't doubt for a second that they can read specific emails, but to suggest that they have bulk collection capabilities within Google or Microsoft is a stretch. NSA lacks the legal authority to compel that, NSA lacks the money to bribe Googl…
XKeyscore
71–80 of 117 posts
Re: XKeyscore
#72Earlier quoted context omitted.
>They still read emails. No doubt they're inside Google, Microsoft, Apple. They might not be inside Proton Mail, it uses PGP but keys are stored server side so I wouldn't know. I don't doubt for a second that they can read specific emails, but to suggest that they have bulk collection capabilities within Google or Microsoft is a stretch. NSA lacks the legal authority to compel that, NSA lacks the money to bribe Googl…
The NSA lacked legal authority to do this bulk collection prior to the Snowden leaks, and yet that didn't stop them from collecting. Why would I believe that their lack of legal authority today would stop them?
It was certainly easy in a world where everything wasn't encrypted, that's not the case anymore.
Re: XKeyscore
#73Earlier quoted context omitted.
I'm not aware of there being a single lick of evidence to suggest that kookery, but even if he was a Russian agent, he certainly accidentally provided Americans a laudable service.
[flagged]
Re: XKeyscore
#74Earlier quoted context omitted.
Wasn't the whole thing that the secret courts were too liberal in access they were granting?
Not in the sense that they were ordering companies to facilitate full take collection of content by the NSA, no. Hence the famous "SSL added and removed here ;-)" slide
Re: XKeyscore
#75Earlier quoted context omitted.
Not in the sense that they were ordering companies to facilitate full take collection of content by the NSA, no. Hence the famous "SSL added and removed here ;-)" slide
Wasn’t room 641A just the NSA strong arming At&T to facilitate full take collection?
AT&T does not have much to lose by doing that, Google does.
Re: XKeyscore
#76Earlier quoted context omitted.
I'm not aware of there being a single lick of evidence to suggest that kookery, but even if he was a Russian agent, he certainly accidentally provided Americans a laudable service.
The shadow brokers are almost certainly Russian intelligence.
USG had no problem blaming Russian intelligence for many other things that were going on at the same time, but they never tied TSB to that bigger picture.
Given what we know about the likes of Hal Martin, there's little reason to believe that only Russian intelligence could have been behind the shadow brokers leaks. In fact, there were rather suspiciously timed twitter DMs written by Hal Martin within minutes of TSB releasing NSA files.
However Marcy Wheeler does argue rather convincingly that Hal Martin's twitter account may have been hacked by TSB in an effort to frame him.
A curious OSINT detail about Hal Martin is that he was using the email address teamtao999@gmail.com on fling.com while looking for women interested in fetishes and group sex. The email address is a reference to the tailored access operations team within the NSA.
His twitter account (@HAL_999999999) created in 2010, also referenced TAO2 in it's avatar at the time of the TSB leaks. It's unclear for how long that was the case, as it was changed later on and there are no archives. Interestingly, he also used to be fairly active on the infosec twitter between 2011 and early 2016 and is featured in tweet chains with many fairly prominent individuals.
His OPSEC wasn't very good, it's perfectly possible he was compromised by some random person.
Edit #89: Okay, I'll throw in one more detail. Very interestingly, it was allegedly Kaspersky who turned in Hal Martin to the NSA after he tried to approach them over twitter. This might seem like a big deal right now, but at the time it wasn't. Russian cybersecurity companies used to be quite happy to work with their western counterparts and law enforcement shortly after this incident when among others Ruslan Stoyanov from Kaspersky was charged with (and later convicted of) treason for allegedly giving information to an American researcher.
Re: XKeyscore
#77Earlier quoted context omitted.
Or if they have a deal or double agent working for them, there is a possibility for "full take" just like at AT&T. Seems pretty likely to me. Allegedly there are tens of thousands of undercover employees stationed throughout the economy in the "signature reduction" program. National security programs don't respect laws when there is something considered "important" if they can get away with it. https://www.newsweek.c…
A double agent would not get you "full take", it'd be impossible to hide the traffic. A double agent could maybe feasibly steal keys from Google, but they'd have to do that all the time because the keys are constantly rotated. And even then, stealing keys does not give you passive decryption and active decryption would be incredibly noisy. NSA does not have enough money to spend to be able to incentivize Google to gi…
There's lots of fun tricks you can think of when you have national resources at your disposal.
However, you are forgetting that NSA works for Google. It works to support the promotion of American companies worldwide. They're on the same team, and Google knows that. They even have the same mission: To usefully organize the world's information!
Now that Google is openly a military contractor, it's even easier to make this click. Back in the day, you had to read things like this Julian Assuage piece to understand this: https://wikileaks.org/google-is-not-what-it-seems/
Re: XKeyscore
#78Earlier quoted context omitted.
1) They don't necessarily need to break all encryption, just knowing who is talking to who and then delivering a tailored payload is their M.O.; The Tailored Access Operations division exists just for this. 2) They didn't build a Yottabyte-scale datacenter for no reason 3) They have the capability to compromise certificate authorities. Pinned certs aren't universal. 4) Speculation, but, Snowden's revelations probably…
None of your proposed solutions are stealthy enough to enable bulk collection at a pre-Snowden scale. Yeah, they can still collect lots of useful metadata.
Metadata is extremely valuable!! lots of things can be inferred from it. In other comments I've decried companies like slack including your password reset or login codes in the email subject for example. They can take any packet and trace it back to a specific individual, even if you're on Tor, chaining VPNs,etc.. without decrypting it. They can see what destinations you're visiting. they can build a pattern of life profile you and mine that. The ad industry does much of this without access to global internet traffic captures already lol.
Re: XKeyscore
#79Earlier quoted context omitted.
None of your proposed solutions are stealthy enough to enable bulk collection at a pre-Snowden scale. Yeah, they can still collect lots of useful metadata.
I don't understand, all they have to do is tap submarine cables, why is that infeasible now? What specific thing do you think they were collecting before that they can't now? Metadata is extremely valuable!! lots of things can be inferred from it. In other comments I've decried companies like slack including your password reset or login codes in the email subject for example. They can take any packet and trace it bac…
> In other comments I've decried companies like slack including your password reset or login codes in the email subject for example
That's still just as encrypted as the email body itself.
Re: XKeyscore
#80Earlier quoted context omitted.
A double agent would not get you "full take", it'd be impossible to hide the traffic. A double agent could maybe feasibly steal keys from Google, but they'd have to do that all the time because the keys are constantly rotated. And even then, stealing keys does not give you passive decryption and active decryption would be incredibly noisy. NSA does not have enough money to spend to be able to incentivize Google to gi…
I think you are not being creative enough with how one might attempt this. For example, splice the cables leading to the datacenter, put an inconspicuous chip in the servers that intercepts the keys and feeds them via wireless signals to a collection point. Perhaps you could even do something clever like put very short range EMF into a metal co-location rack and collect the signals almost totally invisibly using a me…
Google has a lot to lose by doing so, and not all that much to gain. Google has also been a leading force in pushing for broader use of encryption on the internet, making the NSAs work significantly more difficult even in a hypothetical scenario where Google is happy to give them anything they want.