Live data from Hacker News

XKeyscore

en.wikipedia.org

81–90 of 117 posts

Re: XKeyscore

#81
post #2

How relevant is this (and the NSA's general spying capability) in 2025? We hear a lot about local agencies perusing the services of private companies to collect citizens' data in the US, whether that's traffic information, IoT recordings, buying information from FAANG, etc. What's the NSA's position in the current administration? (e.g. we've heard a lot of noise in the past about the FBI and CIA getting the cold shou…

NSAs collection capabilities have been greatly degraded. They can no longer read all internet traffic, basically everything is encrypted now. NSA does not have magic tools to break modern encryption.

This is naive to the point where it is indistinguishable from disinformation.

Aside from a tiny minority of people applying their own encryption (with offline confirmed public keys) at end points with securely stored air gapped private keys, this information is available to the US government, it’s the god damn job of the NSA.

Re: XKeyscore

#82

Earlier quoted context omitted.

Wasn’t room 641A just the NSA strong arming At&T to facilitate full take collection?

Getting AT&T to do that is not the same as getting Google to do that. AT&T does not have much to lose by doing that, Google does.

How do they not have much to lose? They are the ones that have their users on a subscription basis.

Re: XKeyscore

#83

Earlier quoted context omitted.

Getting AT&T to do that is not the same as getting Google to do that. AT&T does not have much to lose by doing that, Google does.

How do they not have much to lose? They are the ones that have their users on a subscription basis.

AT&T customers will not (and did not!) leave because of NSA surveillance, and generally don't have that many options anyway.

Re: XKeyscore

#84
post #55
post #29

Being familiar with the USG classification system, I was thrown off by the beginning of this article. It doesn't sound like something that would be classified merely as Secret. The article begins with: > XKeyscore (XKEYSCORE or XKS) is a secret computer system used by... This should be edited to: > XKeyscore (XKEYSCORE or XKS) is a classified computer system used by... The program is allegedly a Top Secret program.

Saying something is "secret" is not the same as saying it is "classified Secret"

It’s not secret. If it was it wouldn’t be on Wikipedia.

Re: XKeyscore

#85

Earlier quoted context omitted.

NSAs collection capabilities have been greatly degraded. They can no longer read all internet traffic, basically everything is encrypted now. NSA does not have magic tools to break modern encryption.

This is naive to the point where it is indistinguishable from disinformation. Aside from a tiny minority of people applying their own encryption (with offline confirmed public keys) at end points with securely stored air gapped private keys, this information is available to the US government, it’s the god damn job of the NSA.

The NSA can hack pretty much anybody, yes. The NSA can no longer collect everything as they were doing pre-Snowden.

The crucial difference is that it is no longer nearly as easy for the NSA to identify new targets as it used to be, because they don't have full take access to the vast amounts of content they used to.

Re: XKeyscore

#86

Earlier quoted context omitted.

How do they not have much to lose? They are the ones that have their users on a subscription basis.

AT&T customers will not (and did not!) leave because of NSA surveillance, and generally don't have that many options anyway.

Were the alternatives any better? I don't recall any telecom companies committing to warrant canaries or the like. And speaking of, whatever happened to those?

Re: XKeyscore

#87

Earlier quoted context omitted.

AT&T customers will not (and did not!) leave because of NSA surveillance, and generally don't have that many options anyway.

Were the alternatives any better? I don't recall any telecom companies committing to warrant canaries or the like. And speaking of, whatever happened to those?

> Were the alternatives any better? I don't recall any telecom companies committing to warrant canaries or the like.

Well, no. But Google does significant business in foreign countries and doesn't really want to give an excuse for foreign governments to start aggressively pursuing their own alternatives.

> And speaking of, whatever happened to those?

Cloudflare still has a warrant canary on their transparency report page, Reddit deleted theirs in 2016.

They were never very common.

Re: XKeyscore

#88

Earlier quoted context omitted.

I don't understand, all they have to do is tap submarine cables, why is that infeasible now? What specific thing do you think they were collecting before that they can't now? Metadata is extremely valuable!! lots of things can be inferred from it. In other comments I've decried companies like slack including your password reset or login codes in the email subject for example. They can take any packet and trace it bac…

That's perfectly feasible. It is not feasible to do the same kind of captures as NSA was doing pre-Snowden, when most of that traffic wasn't encrypted. > In other comments I've decried companies like slack including your password reset or login codes in the email subject for example That's still just as encrypted as the email body itself.

I think the disconnect is that you think all they do is passive listening and after the fact decryption.

Re: XKeyscore

#89
post #2

How relevant is this (and the NSA's general spying capability) in 2025? We hear a lot about local agencies perusing the services of private companies to collect citizens' data in the US, whether that's traffic information, IoT recordings, buying information from FAANG, etc. What's the NSA's position in the current administration? (e.g. we've heard a lot of noise in the past about the FBI and CIA getting the cold shou…

NSA is under Pete Hegseth's Department of War [sic] if that is any indication of their position and priorities.

Re: XKeyscore

#90

Earlier quoted context omitted.

That's perfectly feasible. It is not feasible to do the same kind of captures as NSA was doing pre-Snowden, when most of that traffic wasn't encrypted. > In other comments I've decried companies like slack including your password reset or login codes in the email subject for example That's still just as encrypted as the email body itself.

I think the disconnect is that you think all they do is passive listening and after the fact decryption.

Active listening is very noisy, we can be very confident they're not doing that at scale.

My whole point is that they're no longer able to do passive listening of unencrypted content and massive scale, but instead are forced to rely on much smaller scale active attacks.

Post reply on HN