Live data from Hacker News

South African authorities admit to mass surveillance

iafrikan.com

91–100 of 145 posts

Re: South African authorities admit to mass surveillance

#91
post #62

Earlier quoted context omitted.

I said nothing about brute forcing.

That's how I read being able to do it because you have "the best, largest, fastest, most advanced machines that money can buy".

My pet conspiracy theory is that at least some large governments have quantum computers of useful strength.

It's probably more likely that they're just trudging along with side-channel attacks, CA fuckery, breaking into servers, and doing targeted attacks though. Cheaper and likely works well enough.

Re: South African authorities admit to mass surveillance

#92
post #59

> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.

> I can’t understand how this news would surprise anyone I tried to tell my family about the Snowden leaks and the implications just a year ago. They are all university educated people. They categorically did not believe that what I was saying was real, and when I showed them all the leaks they did not believe the content was true. Billions of people simply don't believe it's true.

I know I should not post reaction-posts here. But this is Truly Horrifying in more than one way.

Did they not even investigate your claim? Or did they just settle with labeling you a crackpot conspiracy theorist?

Re: South African authorities admit to mass surveillance

#93
post #88

> it also covers information about organised crime Let's just pause a bit here. In South Africa, if your phone gets stolen and you go to the police, they may well respond with: "Yes we know the guy, but we're not going to do anything." [1] I think that surveillance doesn't have the same twang in South Africa that it has in the US and EU. Organised crime and unorganised violent crime for that matter in one thing that…

You seem to have meant to put citations in (e.g.: [1], [2]) but forgot to include them. :(

Re: South African authorities admit to mass surveillance

#94

> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.

I can imagine a sustainable business could be made operating a fleet of ships in international waters that pick up undersea cables, taps them, and uplinks the data in real time to whichever .gov subscribes to it. The company taking the risk gets a big fat government check every month, and the governments get to deny they're tapping anyone's data.

You can't export the data wholesale from your ship though - you'd need another cable for that :D So you'd need sift and process that data on the ship.

Re: South African authorities admit to mass surveillance

#95
post #32

Earlier quoted context omitted.

* Many applications still aren't encrypted by default, like IRC. * If you have compromised a private key, you can get useful data from the cable intercept. * If you can collect ciphertext today, and decrypt it tomorrow (with, say, quantum computers), the cable intercept is very useful.

Modern IRC servers tend to support TLS on port 6697 and SASL for authentication. I’ve been connecting to IRC over SSL for probably a decade at least.

>Modern IRC servers tend to support TLS on port 6697 and SASL for authentication.

The OC's point was by default, meaning/inferring clear-text is still the modus operandi for generally getting onto IRC services.

>Many applications still aren't encrypted by default, like IRC.

SSL and SASL aren't, precisely, user-friendly implementations with some clients (e.g.: IRSSI[0] - but if you're using IRSSI, you don't want a user-friendly GUI to begin with, so...).

SASL has less to do with the actual encryption mechanism and more to do with the authentication mechanism (think NTLM)[1].

If IRC services dropped clear-text, today, that would go a lot further to standardising (e.g.: making default) encryption but, back to the OC's original point, it is not the default today.

[0] - https://freenode.net/kb/answer/irssi

[1] - https://en.wikipedia.org/wiki/Simple_Authentication_and_Secu...

Re: South African authorities admit to mass surveillance

#96

> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.

I can imagine a sustainable business could be made operating a fleet of ships in international waters that pick up undersea cables, taps them, and uplinks the data in real time to whichever .gov subscribes to it. The company taking the risk gets a big fat government check every month, and the governments get to deny they're tapping anyone's data.

I wonder how they'd get the data off the ship again. I guess they'd need to mine the data on the ship before exporting it.

Re: South African authorities admit to mass surveillance

#97

> worrying is that the SSA has said that such surveillance and data collection is "common practice" globally I think if you believe that any major country is not intercepting all undersea fibre cable traffic within their reach or even beyond it then you’re being very naive. I can’t understand how this news would surprise anyone.

It surprises me as a South African because I didn't know our government had the technical capability or capacity to store and process so much data, let alone splice undersea cables without detection.

Fellow South African here, you'd be very surprised then with the capabilities of our spy agency. Very secretive by hugely funded. The former apartheid spies went on to consult for the current government, and they were all very highly trained. In fact one of the precursors to the mass surveillance tech made famous by Snowden, was actually developed at a firm in Stellenbosch in the late 90's to early 00's. That was then sold on to various other state intel agencies, of which SA got a cut of the profit.

We've been developing very high level intelligence tools for years in private/public partnerships. It's all just highly secretive, and one of the areas that really does work, so it doesn't get any attention. Most of us, like yourself, just assume that because other areas here are awful, that our intel community must be to, but nothing could be further from the truth.

Lastly don't forget JZ himself was Head of Intelligence, so he always held it in high regard, and gave it the funding it required.

Re: South African authorities admit to mass surveillance

#98
post #88

> it also covers information about organised crime Let's just pause a bit here. In South Africa, if your phone gets stolen and you go to the police, they may well respond with: "Yes we know the guy, but we're not going to do anything." [1] I think that surveillance doesn't have the same twang in South Africa that it has in the US and EU. Organised crime and unorganised violent crime for that matter in one thing that…

You seem to have meant to put citations in (e.g.: [1], [2]) but forgot to include them. :(

[1] Personal story from a fellow colleague from Botswana.

[2] http://www.statssa.gov.za/?p=11129

Re: South African authorities admit to mass surveillance

#99
post #43

Earlier quoted context omitted.

How do you think they're decrypting in real time? Do you think there are backdoors in the crypto/protocols? Severe accidental flaws? How many times a speedup are you imagining? State of the non-TLA art is that modern https is completely impractical to break, even with enormous server farms working for years, let alone in real time.

How do you think they're decrypting in real time? I have no idea how they're doing it. But I believe it can be done simply because the intelligence agencies have the best, largest, fastest, most advanced machines that money can buy. Machines that none of us have even heard of, that are years ahead of anything any of us will ever touch in our lifetimes.

> Machines that none of us have even heard of, that are years ahead of anything any of us will ever touch in our lifetimes.

That's a pretty bizarre thing to believe. Who is building these machines? Intel? No other organization within the US has the lithography capabilities to manufacture cutting-edge computing hardware, much less "years ahead of anything any of us will ever touch in our lifetimes". Perhaps it's aliens?

Re: South African authorities admit to mass surveillance

#100

Earlier quoted context omitted.

You seem to have meant to put citations in (e.g.: [1], [2]) but forgot to include them. :(

[1] Personal story from a fellow colleague from Botswana. [2] http://www.statssa.gov.za/?p=11129

Heads up: Either you're a different person, or your throwaway account is now linked to your other one.
Post reply on HN