Live data from Hacker News

Looking Back at the Snowden Revelations

blog.cryptographyengineering.com

81–90 of 244 posts

Re: Looking Back at the Snowden Revelations

#81

> ... — the agency spent $250 million per year on a program called the SIGINT Enabling Project. Its goal was, basically, to bypass our commercial encryption at any cost. Now that things have actually started going dark for these overfunded and completely unaccountable entities this is where the biggest danger lies. They have become so desperate for continued access to endless funding that they are actually turning ag…

There is no reason to think that didn't happen long ago. Indeed, MK-ULTRA was directed at the American public, and its perpetrators were never even demoted, never mind prosecuted.

Everybody who believes the CIA had ESP teams, trying to use clairvoyance to extract secrets and kill goats, is evidence of the program's success.

Re: Looking Back at the Snowden Revelations

#82

Earlier quoted context omitted.

My initial statement was nothing else as colloquial and should be regarded as such of course. I would say implementing mass surveillance would equally make it impossible to clear the NSA from such accusation.

The NSA is subject to oversight from all three branches of government. So, to the point that you don't believe two or three entire administrations are/were actively working for a foreign power, you can reasonably assume that the NSA is not committing treason. A lot is going wrong there, but there are limits imposed by the transparency and rule of law. Compare that situation to a country like the Russian Federation.

Of course that is not to say that any number of people employed by or contracted to the NSA are not committing treason or any of myriad other felonies under cover of NSA-provided secrecy.

The only check on that is their higher-ups' jealousy of their income, provided they know of it.

Re: Looking Back at the Snowden Revelations

#83

Earlier quoted context omitted.

Hypothetically, a benevolent NSA would primarily develop cryptographic security tools for the populace.

In fact, there is no clear indication that they did not act in what they perceived as the interest of the US and its citizens. Many would disagree with that perception, and I also believe that amount of surveillance to have been wrong and counterproductive, but there hasn't been any evidence or significant hints into possible corrupt motivations. One mustn't forget that all of this was put into motion after the 9/11…

"They" is an expansive word.

We could better say there is no indication that nobody who had access to illegally-obtained information misused it.

We have plenty of evidence of cops misusing databases they have access to, and that stuff is way less juicy.

Re: Looking Back at the Snowden Revelations

#84

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

> https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf The author dismisses CPU-level backdoors in favor of Intel ME backdoors mainly on the basis that, since CPUs can't save state, they can't protect themselves against replay-"attacks", and hence Intel would lose any sort of plausible deniability once an "activation sequence" was ever found in the wild. But I don't really see how ME is protected against repl…

You assume a device can not be tracked from creation to dsitribution. Why?

Re: Looking Back at the Snowden Revelations

#85

Isn't the practice of the NSA just plainly treason? And why would it not be?

What if Snowden was a deep state pawn sent to take down the NSA, or at least give other agencies total control over it? It is holding the crown jewels after all. The rabbit hole on this one is extremely deep. Hint: What agency did Snowden work for before the NSA?

It doesn't matter if he was put up to it. The facts are the same.

That criminal misuses of the data were not also exposed suggests that he knew what line not to cross.

Re: Looking Back at the Snowden Revelations

#86
post #71

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

One of the most interesting revelations was the security agencies apparent spying on members of Congress. But it’s like nothing happened. No investigation, no nothing. If they can’t be bothered by that, it’s little surprise they’re not bothered by their spying on regular folk.

That should tell us who is really in charge.

Re: Looking Back at the Snowden Revelations

#87
post #50

Earlier quoted context omitted.

Description of my life. I was telling people for years what is going on, not from position of daydreaming, but what I would be able to pull off. I got back everything from tin foil hat to "I have nothing to hide". Snowden changed that and I am gratefull to him for exactly that... And for one more sentance, that is a work of pure genius: “Arguing that you don't care about the right to privacy because you have nothing…

> “Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say.” I find this sentence interesting because it is very specific to the American public. I am European and personally I care a lot more about privacy than free speech, and America's obsession with free speech boggles my mind. It might hav…

I am European too. But without the freedom of speech, we wouldnt be discussing this. They are both liberties and we need them both. There is no "I care more about X". We need them both as fundamental human rights.

Re: Looking Back at the Snowden Revelations

#88

Earlier quoted context omitted.

> https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf The author dismisses CPU-level backdoors in favor of Intel ME backdoors mainly on the basis that, since CPUs can't save state, they can't protect themselves against replay-"attacks", and hence Intel would lose any sort of plausible deniability once an "activation sequence" was ever found in the wild. But I don't really see how ME is protected against repl…

You assume a device can not be tracked from creation to dsitribution. Why?

supply chain tracking is extremely difficult even for entire ecosystems that make it their near maximum priority (such as say, military procurement).

There isn't a hope in hell you can reliably keep track of who has which Intel CPU.

Think of all the stages involved, and how each one has to cooperate and how many times Intel's CPU is sitting on "undifferentiated palette of X units".

Re: Looking Back at the Snowden Revelations

#89

> ... — the agency spent $250 million per year on a program called the SIGINT Enabling Project. Its goal was, basically, to bypass our commercial encryption at any cost. Now that things have actually started going dark for these overfunded and completely unaccountable entities this is where the biggest danger lies. They have become so desperate for continued access to endless funding that they are actually turning ag…

Last year the Australian government even went so far as to pass a law allowing them to force companies to sabotage their own products/services in cases where a government agency wants to get access to someone's communications.

https://www.engadget.com/2018/12/07/australia-access-assista...

Re: Looking Back at the Snowden Revelations

#90

Oh yeah : - Before Snowden, if you spoke about these issues, you were dismissed as paranoid. - After Snowden, if you dismiss these issues, you are dismissed as hopelessly naive... Oh, also - considering all this - you can bet that Intel's Management Engine has likely been backdoored by the NSA, so using Intel's processors is not recommended, especially if you're a non-US company... (industrial espionage !) https://bl…

There is nothing to suggest an ME backdoor. I’d call it unlikely.

Watch this Blackhat 2017 talk and maybe it'll change your mind: https://www.youtube.com/watch?v=KrksBdWcZgQ
Post reply on HN