Live data from Hacker News

Core Secrets: NSA Saboteurs in China and Germany

firstlook.org

81–90 of 130 posts

Re: Core Secrets: NSA Saboteurs in China and Germany

#81

Earlier quoted context omitted.

Are you saying it's retribution for participating in the global cyber intelligence war? Everybody is hacking everybody. Every major country has a cyberintelligence arm. The NSA is just one actor of dozens.

Right, and I hope nobody thinks Russia or China are saints, because they use their technical abilities to suppress dissent in frightening ways. While there's definitely a cyber war going on, you have to ask, why isn't the NSA actively disseminating knowledge to Americans on how to secure themselves? Why are they instead actively weakening encryption standards? America companies have the most to lose from weak encrypt…

> why isn't the NSA actively disseminating knowledge to Americans on how to secure themselves?

In fact, the NSA is disseminating such knowledge. You can find guides to secure operating systems (Windows, Linux, and OS X) and commonly used applications (Chrome, Adobe Reader). To what I assume is the chagrin of the FBI, you can even find guidance on full-disk encryption.

https://www.nsa.gov/ia/mitigation_guidance/index.shtml

Re: Core Secrets: NSA Saboteurs in China and Germany

#82
post #63
post #42

The document titled "ECI Compartments" is interesting: * It's possible work out the geographic region of certain compartments based on the organizational code attached to it. * The redactions in the "Control Authority" column are variable size, possibly even proportionate to character length. * The fact that document was merely classified "confidential" is odd. * I was able to identify[0][1] all but one item listed i…

What could "NSA/CSS Commercial Solutions Center (NCSC)" (from [1]) actually do? They write on their public web page: https://www.nsa.gov/business/programs/ncsc.shtml "The NSA/CSS Commercial Solutions Center (NCSC) addresses the strategic needs of NSA/CSS and the national security community by harnessing the power of U.S. commercial technology."

Two pieces of information that add up to a larger story:

* The NSA/CSS Commercial Solutions Center (NCSC) is specifically built around Elliptic Curve Cryptography that they acquired from Certicom.

>The NCSC also manages the Elliptic Curve Cryptography (ECC) program on behalf of the NSA/CSS. Elliptic curve provides greater security and more efficient performance than first generation public key techniques currently in use. NSA/CSS purchased a license that covers intellectual property in a restricted field of use to assist in the implementation of elliptic curves to protect U.S. and allied government information. - https://www.nsa.gov/business/programs/ncsc.shtml

* Certicom designed the Elliptic Curve DRBG (Dual_EC) algorithm including the backdoor (Certicom patented the backdoor functionality in 2005)[0]. The NSA then included this algorithm + backdoor into NIST standard and payed RSA 10 million dollars to make it the default DRBG.

Putting these two facts together suggests that the NCSC was responsible for the Dual_EC backdoor.

[0]: http://en.wikipedia.org/wiki/Dual_EC_DRBG

Re: Core Secrets: NSA Saboteurs in China and Germany

#83

I wonder what's in the tip of the pyramid, shaded in black. Somethings I like to imagine: - Kennedy was assassinated by CIA - Aliens transferred technology to US government - Former strongman of South Korea was assassinated by CIA - List of other assassinations by CIA - Iraq WMD was made up and knew about it but went ahead with war anyway. etc...

You're not allowed to be imaginative or speculate here about topics that people have been conditioned to patriotically think non-critically about! Just give it up man! We all know that the official stories about 9/11 are 100% true!

(For a group that hates censorship as much as these "hackers" do, isn't it funny how they love a site that lets everybody censor each other by downvoting comments into invisibility? See? Help meeee I'm meltinggggg....)

Re: Core Secrets: NSA Saboteurs in China and Germany

#84

The NSA has clearly recruited employees from companies like Google, Facebook, Cisco, etc to compromise and place vulnerabilities that the NSA can exploit. The fact that the NSA has decided that the legal channels to acquire data through warrants and actual investigations no longer applies must be stopped.

What surprise me about these recruitments is -- how do you convince people that it really is NSA/CIA/whatever that are asking them to be patriotic?

E.g. a Chinese spy in Silicon Valley probably say "I represent NSA, we _really_ need to get access to mail accounts without letting anyone know, including your corporate CEOs" (except to people which would be open to nationalist Chinese arguments).

A visit to Pentagon to shake some well known general's hand might be hard to arrange, since not only Google or Apple might monitor the GPS of the employees phone.

Re: Core Secrets: NSA Saboteurs in China and Germany

#85

Earlier quoted context omitted.

> Warantless surveillance of US citizens (this is bad whether it's by law enforcement, intelligence agencies, or anyone). Agreed very strongly. > Infiltration of foreign companies in allied or neutral nations purely for economic or geopolitical insight, not for military purposes (Brazil's Petrobras oil company, all sorts of spying in Germany and Norway and other places). See this is where the NSA really shines. We (T…

It seems you've decided that US hegemony is a "good thing" regardless of the moral implications for ourselves and the world. However, some find actions like the following to be dangerous, immoral, unnecessary: * "the US and Israel had the director assassinated" * "we won offshore drilling" * the blase assertion that a nuclear Iran is any worse than the existing nuclear powers (especially Israel!!!) "Energy security"…

>> the blase assertion that a nuclear Iran is any worse than the existing nuclear powers

Iran has one of the worst dictatorships around, it exports weapons and ammunition everywhere. The regime support groups that as SOP fire rocket artillery at civilians. The regime even support the politicians which organized the genocides/rapes of millions in Sudan. And so on.

Iran's priests is just not the kind of regime that should be immune to military threats, like Russia is now with Ukraine.

The really scary thing with that religious dictatorship, with both a fin de siecle attitude and nuclear weapons, is that they might get most of the Iranian population killed. Probably a majority of the Iranians really hates their priests and are a bit more west oriented than the average European. They have worked hard to push off their yoke, but their junta was ready for it. (I come from Sweden, there are lots of Iranian refugees there.)

That said, to use spying for economic reasons ("offshore oil drilling locations" in the GP comment) do deserve a total lack of trust. They lower themselves to the Chinese dirty level.

Re: Core Secrets: NSA Saboteurs in China and Germany

#86
post #29

Earlier quoted context omitted.

No, "everybody" doesn't do it. It is on the face of it ridiculous to say "everybody has a blue-water navy." It is equally ridiculous to say "everybody runs surveillance comparable to the NSA."

Page 123 of the documents released in Glenn Greenwald's "No Place To Hide" lists at least 37 countries (that the United States has cyber partnerships with). http://cryptome.org/2014/05/npth-docs-compare.pdf (on page 16 of the link)

Of those 37 countries, only a minor fraction have the budget to operate the way NSA does. That leaves approximately 160 other sovereign entities. Let's say half of them are despotic and don't count. That leaves 80. Out of those I'd wager that more than half are have governments too under-resourced to have the ability to put their people in the kind of panopticon Americans live in. In other words there may be hundreds of milllions of people who are more free than Americans. Who are not fearful Hobbeseans suckling at NSA'a teat. Somehow, those people have not yet succumbed to "terrorism" of whatever the scare du jour is.

Re: Core Secrets: NSA Saboteurs in China and Germany

#87

“The facts contained in this program constitute a combination of the greatest number of highly sensitive facts related to NSA/CSS’s overall cryptologic mission,” the briefing document states. “Unauthorized disclosure…will cause exceptionally grave damage to U.S. national security. The loss of this information could critically compromise highly sensitive cryptologic U.S. and foreign relationships, multi-year past and…

Come on, it's been 13 years now of this "grave damage to national security" talk. They claim it for everything. I'm reasonably sure every thinking person has started, in their mind, to replace any invocation of "national security" with "covering up either incompetence, negligence or breaches of law". Theres zero reasons we should be paying any attention to that label. (I like to remind people of the case of Ibrahim v…

The "grave damage to national security" wasn't something an official said. It was a warning inside the document.

Certainly there are instances where this is the case. I can think of a few others to add to your example.

But there's no good reason to assume that all invocations of classified and politically or strategically sensitive material are excuses to cover up incompetence, negligence or breaches of law. And in fact in this case I'm not sure what it would be covering up. What's listed here is hardly incompetence nor negligence and the argument for breach of law, while slightly stronger, wouldn't pass a smell test.

Re: Core Secrets: NSA Saboteurs in China and Germany

#88

I wonder what's in the tip of the pyramid, shaded in black. Somethings I like to imagine: - Kennedy was assassinated by CIA - Aliens transferred technology to US government - Former strongman of South Korea was assassinated by CIA - List of other assassinations by CIA - Iraq WMD was made up and knew about it but went ahead with war anyway. etc...

You're not allowed to be imaginative or speculate here about topics that people have been conditioned to patriotically think non-critically about! Just give it up man! We all know that the official stories about 9/11 are 100% true! (For a group that hates censorship as much as these "hackers" do, isn't it funny how they love a site that lets everybody censor each other by downvoting comments into invisibility? See? H…

When you speak in front of a crowd of people and are arrested by police for the things you're saying, that's censorship.

When the crowd boos you off the stage before you're finished, that's not censorship, it's other people also asserting their rights to free speech. Perhaps you should reconsider what you're saying or find a new group of people to say it to.

Re: Core Secrets: NSA Saboteurs in China and Germany

#89
post #74

“The facts contained in this program constitute a combination of the greatest number of highly sensitive facts related to NSA/CSS’s overall cryptologic mission,” the briefing document states. “Unauthorized disclosure…will cause exceptionally grave damage to U.S. national security. The loss of this information could critically compromise highly sensitive cryptologic U.S. and foreign relationships, multi-year past and…

Somewhat sad to see the cyber security war narrative becoming the top voted comment on hackernews. Until the public realize that they are themselves the target of those cyber security war activities by their own government, those revelations can not be damaging enough. Just to support the point: Today the new Snowden movie is all over the news, while practically nobody seems to care bout those revelations you claim b…

> Until the public realize that they are themselves the target of those cyber security war activities by their own government, those revelations can not be damaging enough

This is entirely true. Us plebes have been caught in the middle. And the surveillance programs are not just about cyber warfare. The NSA/DHS use them for other things as well (handing off to CIA/FBI/DEA, building profiles of people, social manipulation, etc). But this article from firstlook IS about cyber warfare.

The leaked document itself says "U.S. Strategic Command - Joint Function Component Command - Network Warfare".

> Today the new Snowden movie is all over the news, while practically nobody seems to care bout those revelations you claim being really damaging

Isn't that argumentum ad populum? The news media coverage of the Snowden revelations has been horrendous, limited and misleading through and through. In fact the Snowden movie being in the news is a great example of how the public is disconnected with what's going on. It's not a "Snowden documentary" or a "Snowden lecture" or a "Snowden document analysis". It's a short hour and change person story with a bleached narrative devoid of the content of the actual documents.

Re: Core Secrets: NSA Saboteurs in China and Germany

#90

Earlier quoted context omitted.

It's not all that speculative - it agrees what was in prior leaks that claim that American companies are routinely infiltrated. Also remember that the authors of these articles have read huge volumes of Snowden documents have have not been publicly released and that the security experts (likely referencing Schneier here) are not just guys working in private industry. If you work in the security space you very quickly…

It looks pretty speculative to me. Directly from this article: "The most controversial revelation in Sentry Eagle might be a fleeting reference to the NSA infiltrating clandestine agents into “commercial entities.”" , "It is not clear whether these “commercial entities” are American or foreign or both." and "The document makes no other reference to NSA agents working under cover. It is not clear whether they might be…

It's not really speculative. Remember that previous leaks showed definitively that the NSA had broken into Google and Yahoo, notwithstanding they had some partnerships/participation from them.

Bruce Schneier was given an opportunity to meet and review a large collection of documents but yes its true we don't really know.

Post reply on HN