Live data from Hacker News

XKeyscore

en.wikipedia.org

71–80 of 117 posts

Re: XKeyscore

#71

Earlier quoted context omitted.

They still read emails. No doubt they're inside Google, Microsoft, Apple. They might not be inside Proton Mail, it uses PGP but keys are stored server side so I wouldn't know. No doubt they still read texts. I think the US is still among the countries that use SMS a lot. They no doubt have access to the data big tech's mined out of the entire world's population. That capability alone puts them into "bring everything…

>They still read emails. No doubt they're inside Google, Microsoft, Apple. They might not be inside Proton Mail, it uses PGP but keys are stored server side so I wouldn't know. I don't doubt for a second that they can read specific emails, but to suggest that they have bulk collection capabilities within Google or Microsoft is a stretch. NSA lacks the legal authority to compel that, NSA lacks the money to bribe Googl…

The NSA lacked legal authority to do this bulk collection prior to the Snowden leaks, and yet that didn't stop them from collecting. Why would I believe that their lack of legal authority today would stop them?

Re: XKeyscore

#72

Earlier quoted context omitted.

>They still read emails. No doubt they're inside Google, Microsoft, Apple. They might not be inside Proton Mail, it uses PGP but keys are stored server side so I wouldn't know. I don't doubt for a second that they can read specific emails, but to suggest that they have bulk collection capabilities within Google or Microsoft is a stretch. NSA lacks the legal authority to compel that, NSA lacks the money to bribe Googl…

The NSA lacked legal authority to do this bulk collection prior to the Snowden leaks, and yet that didn't stop them from collecting. Why would I believe that their lack of legal authority today would stop them?

Because it's not possible for them to get the same easy access anymore?

It was certainly easy in a world where everything wasn't encrypted, that's not the case anymore.

Re: XKeyscore

#73
post #19
post #17

Earlier quoted context omitted.

I'm not aware of there being a single lick of evidence to suggest that kookery, but even if he was a Russian agent, he certainly accidentally provided Americans a laudable service.

[flagged]

His life literally depends on Putin's whims - a situation which the USA and EU have forced him into. How could you possibly fault him for not poking the bear that he was forced in a cage with?

Re: XKeyscore

#74

Earlier quoted context omitted.

Wasn't the whole thing that the secret courts were too liberal in access they were granting?

Not in the sense that they were ordering companies to facilitate full take collection of content by the NSA, no. Hence the famous "SSL added and removed here ;-)" slide

Wasn’t room 641A just the NSA strong arming At&T to facilitate full take collection?

Re: XKeyscore

#75

Earlier quoted context omitted.

Not in the sense that they were ordering companies to facilitate full take collection of content by the NSA, no. Hence the famous "SSL added and removed here ;-)" slide

Wasn’t room 641A just the NSA strong arming At&T to facilitate full take collection?

Getting AT&T to do that is not the same as getting Google to do that.

AT&T does not have much to lose by doing that, Google does.

Re: XKeyscore

#76
post #17

Earlier quoted context omitted.

I'm not aware of there being a single lick of evidence to suggest that kookery, but even if he was a Russian agent, he certainly accidentally provided Americans a laudable service.

The shadow brokers are almost certainly Russian intelligence.

Curiously, the US Government has never made that allegation. There's significant circumstantial evidence to suggest that the US Government may not believe TSB to be Russian intelligence.

USG had no problem blaming Russian intelligence for many other things that were going on at the same time, but they never tied TSB to that bigger picture.

Given what we know about the likes of Hal Martin, there's little reason to believe that only Russian intelligence could have been behind the shadow brokers leaks. In fact, there were rather suspiciously timed twitter DMs written by Hal Martin within minutes of TSB releasing NSA files.

However Marcy Wheeler does argue rather convincingly that Hal Martin's twitter account may have been hacked by TSB in an effort to frame him.

A curious OSINT detail about Hal Martin is that he was using the email address teamtao999@gmail.com on fling.com while looking for women interested in fetishes and group sex. The email address is a reference to the tailored access operations team within the NSA.

His twitter account (@HAL_999999999) created in 2010, also referenced TAO2 in it's avatar at the time of the TSB leaks. It's unclear for how long that was the case, as it was changed later on and there are no archives. Interestingly, he also used to be fairly active on the infosec twitter between 2011 and early 2016 and is featured in tweet chains with many fairly prominent individuals.

His OPSEC wasn't very good, it's perfectly possible he was compromised by some random person.

Edit #89: Okay, I'll throw in one more detail. Very interestingly, it was allegedly Kaspersky who turned in Hal Martin to the NSA after he tried to approach them over twitter. This might seem like a big deal right now, but at the time it wasn't. Russian cybersecurity companies used to be quite happy to work with their western counterparts and law enforcement shortly after this incident when among others Ruslan Stoyanov from Kaspersky was charged with (and later convicted of) treason for allegedly giving information to an American researcher.

Re: XKeyscore

#77

Earlier quoted context omitted.

Or if they have a deal or double agent working for them, there is a possibility for "full take" just like at AT&T. Seems pretty likely to me. Allegedly there are tens of thousands of undercover employees stationed throughout the economy in the "signature reduction" program. National security programs don't respect laws when there is something considered "important" if they can get away with it. https://www.newsweek.c…

A double agent would not get you "full take", it'd be impossible to hide the traffic. A double agent could maybe feasibly steal keys from Google, but they'd have to do that all the time because the keys are constantly rotated. And even then, stealing keys does not give you passive decryption and active decryption would be incredibly noisy. NSA does not have enough money to spend to be able to incentivize Google to gi…

I think you are not being creative enough with how one might attempt this. For example, splice the cables leading to the datacenter, put an inconspicuous chip in the servers that intercepts the keys and feeds them via wireless signals to a collection point. Perhaps you could even do something clever like put very short range EMF into a metal co-location rack and collect the signals almost totally invisibly using a mesh network of devices built into the metal.

There's lots of fun tricks you can think of when you have national resources at your disposal.

However, you are forgetting that NSA works for Google. It works to support the promotion of American companies worldwide. They're on the same team, and Google knows that. They even have the same mission: To usefully organize the world's information!

Now that Google is openly a military contractor, it's even easier to make this click. Back in the day, you had to read things like this Julian Assuage piece to understand this: https://wikileaks.org/google-is-not-what-it-seems/

Re: XKeyscore

#78

Earlier quoted context omitted.

1) They don't necessarily need to break all encryption, just knowing who is talking to who and then delivering a tailored payload is their M.O.; The Tailored Access Operations division exists just for this. 2) They didn't build a Yottabyte-scale datacenter for no reason 3) They have the capability to compromise certificate authorities. Pinned certs aren't universal. 4) Speculation, but, Snowden's revelations probably…

None of your proposed solutions are stealthy enough to enable bulk collection at a pre-Snowden scale. Yeah, they can still collect lots of useful metadata.

I don't understand, all they have to do is tap submarine cables, why is that infeasible now? What specific thing do you think they were collecting before that they can't now?

Metadata is extremely valuable!! lots of things can be inferred from it. In other comments I've decried companies like slack including your password reset or login codes in the email subject for example. They can take any packet and trace it back to a specific individual, even if you're on Tor, chaining VPNs,etc.. without decrypting it. They can see what destinations you're visiting. they can build a pattern of life profile you and mine that. The ad industry does much of this without access to global internet traffic captures already lol.

Re: XKeyscore

#79

Earlier quoted context omitted.

None of your proposed solutions are stealthy enough to enable bulk collection at a pre-Snowden scale. Yeah, they can still collect lots of useful metadata.

I don't understand, all they have to do is tap submarine cables, why is that infeasible now? What specific thing do you think they were collecting before that they can't now? Metadata is extremely valuable!! lots of things can be inferred from it. In other comments I've decried companies like slack including your password reset or login codes in the email subject for example. They can take any packet and trace it bac…

That's perfectly feasible. It is not feasible to do the same kind of captures as NSA was doing pre-Snowden, when most of that traffic wasn't encrypted.

> In other comments I've decried companies like slack including your password reset or login codes in the email subject for example

That's still just as encrypted as the email body itself.

Re: XKeyscore

#80

Earlier quoted context omitted.

A double agent would not get you "full take", it'd be impossible to hide the traffic. A double agent could maybe feasibly steal keys from Google, but they'd have to do that all the time because the keys are constantly rotated. And even then, stealing keys does not give you passive decryption and active decryption would be incredibly noisy. NSA does not have enough money to spend to be able to incentivize Google to gi…

I think you are not being creative enough with how one might attempt this. For example, splice the cables leading to the datacenter, put an inconspicuous chip in the servers that intercepts the keys and feeds them via wireless signals to a collection point. Perhaps you could even do something clever like put very short range EMF into a metal co-location rack and collect the signals almost totally invisibly using a me…

If we were to accept that the NSA works for Google, there's even less reason to believe that Google would grant NSA full take access to plaintext content.

Google has a lot to lose by doing so, and not all that much to gain. Google has also been a leading force in pushing for broader use of encryption on the internet, making the NSAs work significantly more difficult even in a hypothetical scenario where Google is happy to give them anything they want.

Post reply on HN