The NSA’s Hidden Spy Hubs in Eight U.S. Cities
theintercept.com
theintercept.com
I know my way around the security industry. These weren't normal security guards that get paid to watch cctv and call the real cops. They don't give those guys guns or ballistic vests. To me it was completely bizarre that a telecom building would have that sort of security. Now it all makes sense. I actually wouldn't be surprised if they were actually military in disguise.
And I suspect try and run a gate with a vehicle at Sellafield would lead to a similar response from the Nuke Police.
It's on the corner of third and lenora.
3rd Ave itself is slightly notorious - hosting the surface entrances for the Seattle bus tunnel, and a large number of inter-city routes, the area has a reputation for crime and the occasional death by shooting. It was a bit worrying to commute through, as a bus rider, and seems like an odd location for an ISP street-level office.
It became a USWest site in 1984 through the breakup of the Bell monopoly system, and then Qwest and eventually Centurylink.
What's that?
There used to be some SAGE equipment at the Computer History Museum in Mountain View. I don't know if it's still there or not, but it was definitely interesting to see. The "light gun" user interface and the control consoles have a really pleasing aesthetic.
Edit: I'll wager it's a seismic upgrade. The building's vintage is from back when they didn't have as good of a handle on the seismic stuff. And the Cascadia Subduction Zone is no joke!
Just think of them as Stalin's New York Times - willing accomplices to Soviet genocide.
"Move along citizen"
Seattle, for example, also has the Elliot CO in Belltown: http://www.co-buildings.com/wa/206/
https://imgur.com/gallery/f1EGp
on this page is a photo of a 1200-pair: http://cityinfrastructure.com/single.php?d=RuralOutsidePlant...
"Ah there's your problem: you've patched the Fire Engine Red pair, it's meant to be the Ferrari Red. Rookie error."
It’s actually pretty simple. There are only 10 colors: blue, orange, green, brown, slate, white, red, black, yellow, and violet. They’re grouped in “binders” (using colored strings). You’re likely familiar with the first four pairs from network cables (which omit the white/slate pair). After cylcling through blue through slate paired with white through violet (25 pairs), the wires are bundled with binders starting with blue/white string. That gets you to 625 pairs (the first picture posted above is 600 or 625 pairs). After that, the binder groups are bound in a similar fashion (typically if you’re going beyond 625, the slate/violet binder is omitted to get a nice round 600 in the first group).
Wikipedia has a good article: https://en.m.wikipedia.org/wiki/25-pair_color_code
100-pair cable is only about 3/4” diameter. I have a 24-line 1A2 telephone that uses 75 pairs just to connect to the phone switch and two 100-pair cables feeding a telephone display case in my living room.
It takes me about a half hour to punch down 100 pairs on a 66-block. Old school telecom guys could probably do it in under 10 minutes.
At least I hope so, if not, then they really should exist.
The historic reasons from other posters give good justification for the current location.
Not saying correlation is causation here, but the interfernce is definitely a little unnerving.
Either
A. Popular and well known encryption algorithms are not broken by the NSA, and your communication is private.
B. Popular and well known encryption algorithms are broken by the NSA, but the fact that it's broken is top secret and the state will not do any actions that revel the secret. Your communications are not safe, and while what you communicate might make you the target of an investigation (if you're an appealing enough target), the communications will not be directly used against you in court.
EDIT: There is a third option, that your communication is being stored until the encryption algorithm is broken or computation reaches a point where brute force is possible (quantum computers). Long term storage of encrypted communication is only economically feasible for a small subset of all encrypted communication, so it's only a concern for targeted individuals where the communication will be relevant to the state decades from now.
That assumes metadata is irrelevant. The destination, time of day, and volume of the traffic all have value separately and especially so when together. The destination can be masked if you control both sides and AT&T is a go between, but timing issues are subject to analysis unless you are a large enough player to give safety in numbers or you push noise across your pipes.
Just decide how thoroughly it must be done, and do what it takes. Plus a safety factor.
Please tell me how i anonymize the metadata of where my cellphone is located, which the telco harvests from towers its connected to.
If you really care, one option is having multiple phones, under different identities. Each one only gets used in a distinct set of locations, for distinct projects, with distinct recipients. When not in use, you store phones in labeled Faraday bags. That is, compartmentalization.
Another option is to nuke the radio in your phone, use only WiFi and VPNs for internet access, and use hosted cellphones from multiple providers. You can still compartmentalize, but need only carry one phone. But you depend on WiFi access.
IIRC, the signals intelligence agencies like the NSA learn almost as much from traffic analysis (e.g. who's talking to who and when) and metadata than from actual message content. Mere encryption itself often doesn't protect much from that.
Isn't metadata, practically speaking, a subset of content? (If you have the latter, you almost certainly also have the former?)
Metadata is more useful than content if you're capacity constrained, technologically or legally, in collection and/or analysis.
Importantly to how we think about communication, no.
Metadata is the signature that accompanies or encapsulates content, viewable to the world. You can completely conceal content, through encryption for example, but you can't completely conceal metadata.
In other words there must be a physical exchange of energy somewhere (communication), and metadata tells you something about how the exchange happened, irrespective and ignorant of what the content is.
You can do it with a very high cost (in overhead, latency, and availability) by having a large number of people all send and receive messages, on a fixed or randomized schedule, exceeding their maximum possible amount of communication with one another. Then someone monitoring the network knows that each of the participants in this system could have communicated with any other participant, but not whether or not the communication took place.
The bottom line is that you are going to leave a signature of some sort through communications - the question is, can you properly build a comms system system that is functional within the limits of your risk/reward criteria.
To eliminate the statistical observability of metadata, the padding needs to reach or exceed the maximum capacity of the channel. So you can't have people sending more messages than the padded channel permits per time period. In your example, packets "with variable length/size content" would need to be absolutely prohibited, or else all packets' length would need to be randomized, and message data would need to be sent following strictly the same distribution as padding messages.
For example, you and I could have a rule of exchanging exactly 1 MB of data per day, at a specified time, every day. Then an observer wouldn't be able to tell whether, on a particular day, we had actually communicated something to each other or just allowed the padding data to go out. Clearly in this system we're not ever allowed to use it to transmit more than 1 MB per day, without destroying the metadata unobservability property. An attacker still knows that you and I are part of a system that offers us an otherwise unobservable channel, but not when we do or don't make use of that channel.
There are lots of variants that also allow many-to-many messaging, again at a high cost in overhead, latency, and availability.
You're also not ever allowed to transmit links or anything else that goads the user into fetching a remote resource in response to a message.
> For example, you and I could have a rule of exchanging exactly 1 MB of data per day, at a specified time, every day.
Depending on the size and popularity of the relay network, the fact the two parties are connected to it could be valuable metadata.
If you really wanted to minimize the amount of metadata to something that's almost useless, you'd probably need to use something like a continuously-operating broadcast numbers station.
My hunch is that it wouldn't be possible, and there would be a side-channel vulnerability somewhere.
Edit: the beginning of this research is the Dining Cryptographers.
https://en.wikipedia.org/wiki/Dining_cryptographers_problem
Although Chaum's solution has terrible availability properties, it's unconditionally secure against outsiders!
Bigger in this case is the pattern of life rendered by just inspecting headers. And they can get a lot of headers sitting on these ATT locations.
Directly. But via parallel construction...
I wish judges and defense attorneys would catch on to these tactics more quickly. The rate at which the prosecutors/FBI invent new tricks to fool the courts and defense attorneys so far seems to far outpace the judge and the defense attorneys' understanding of what's even happening.
Take cell site simulators, for instance - the FBI has used those in secret for more than a decade before they were uncovered at all, and then it took another decade for judges here and there to catch-up and start requiring warrants for such operations.
And this goes for a lot of FBI's "investigative techniques", too, which are often illegal, but what judge is really going to know the difference between those highly technical operations?
I feel otherwise.
When Microsoft was about to be broken up an appellate judge overruled the prior judge. That judge went on to be the FISA secret court judge.
Remember that the NSA Key was discovered around the same time[0].
So Microsoft was in bed with NSA prior to 1999 with a crypto key backdoor.
They were helped by an future FISA judge.(Does that background look like a national security judge?)
When I look at the Judges resume I can help but to wonder if she was an NSA plant the whole time.[1]
The Commerce Department is a frequent cover for the NSA.
I have to assume they use deep cover people all around us.
[0]https://www.heise.de/tp/features/How-NSA-access-was-built-in...
Is there a tech-law publication which targets judges and defense attorneys?
"It said the BND, a partner of the US National Security Agency (NSA), has placed so-called Y-piece prisms into its data-carrying fibre optic cables that give it an unfiltered and complete copy of the data flow."
https://www.thelocal.de/20180531/german-spies-can-keep-monit...
I'd really like to see CDNs like CloudFlare start requiring Cloud <--> Origin encryption; e.g. what CloudFlare calls "Full SSL" -- https://support.cloudflare.com/hc/en-us/articles/200170416-W.... Right now, you can do TLS termination ("Flexible SSL"), which end-users aren't aware of -- they see a padlock -- and I'm sure the NSA doesn't mind.
They do. They work with all of them.
http://www.businessinsider.com/the-story-of-joseph-nacchio-a...
AT&T just happens to have the oldest relationships and the largest infrastructure.
Which sane people call Man in the Middle and should not be allowed at all. I have seen people doing this Flexiable SSL with Credit Card data and other PII believing it is "secure"
Cloudflare may have started out with security in mind but their new services centered around centralization of key services (dns) and this kind of security breaking product means IMO they are a net negative in the world of Information Security
It's an easy box to check to pretend to offer HTTPS so you don't get penalized by Google. Before Let's Encrypt there was no free way to get a legit cert for your cat blog. Faking it via Flexible SSL was the next best thing.
Furhter before Lets Encrypt you would not have gotten dinged by google, Google only went that path when wide spread DV Certs where freely avaliable
Further still, the minor costs per year to get a paid DV cert should be factor when choosing to host your own content versus paying a 3rd party to do it, many of those 3rd parties provided SSL as part of their services.
There is zero need for a Man in the Middle for SSL,
Granted, like FB issues and others, we in this community need to realize that most users simply don't care (even many b2b ones) and not get upset when our users don't move their dollars on principle. For us it's a big deal, for many there are real, harmful issues going on in the world and volume collection of data by companies and governments is not one of them. And we can't make it so despite the deluge of articles by a supportive mass media.
EDIT: To clarify, you mentioned "other ISPs" but I want to be clear I'm talking about private pipes and not residential internet though I know they are often shared.
Yes, but they could also be lying about it.
Hell, this is pretty much the norm where MPLS is concerned. Your packet may hop through a dozen routers along its way without showing up in a traceroute -- you just see it go in one side (then it goes through a dozen routers) and you see it come out the other side.
Wouldn't be trivial for any other telco (whether foreign or domestic) than at&t to tap the data and lie about it too?
And it doesn't have to show up in the traceroute (they could mirror the traffic, etc)
At a proper one a single IP address belonging to the exchange, which will be assigned to the router port of one member, is only allowed to appear from a specific single MAC address, and specific port on the ix switch, which corresponds with a physical fiber cross connect that matches a specific patch panel port.
Maybe the comfortable relationship between NSA and at&t are more the driver for the location, and the fiber taps are all backhauled here.
From a voice perspective, though, I’d think this was still a useful surveillance point, given AT&T likely still tandems traffic here.
https://www.business.att.com/content/productbrochures/coloca...
Our servers there went through AT&T networks. Some companies I worked for co-located at Telehouse centers where you had a host of upstream options (including multiple options).
Stephen Colbert's studio was next door to the building when he was doing the Colbert Report 3-4 years ago, I used to see him walking around from time to time.
https://www.forbes.com/sites/robertlenzner/2013/09/23/attver...
Room 641A: https://en.m.wikipedia.org/wiki/Room_641A
Since there are rarely, if ever, any consequences for breaking the law or the Constitution, why would they stop?
At the very least, AT&T might be limited from upgrading their equipment until the NSA can revise their monitoring systems to keep up.
edit: I just moved down the street a bit and it says Bell Canada on the building. It's a CO.
Another way you can tell for sure with a building like that, is that there will be a locked panel or set of highly protected hose ports for generator diesel fuel refill, from alley or street side tanker truck delivery.
[1] https://transparencyreport.google.com/safer-email/overview
The rest of it - splitting data traffic and sending a copy to the NSA - I'd like to see how any international traffic is being sent through a land-locked city like Dallas, which should only have domestic traffic in it. Which the NSA shouldn't be looking at.
Well, Texas borders Mexico, and although DFW is on the other side of the state, it is a very large metro area. If it's a hub for domestic traffic, it seems logical for it to also act as an interchange for international traffic with Central and South America. The hostnames I see in a traceroute to telmex.com (a big telco headquartered in Mexico City) from my office in New England on Verizon FiOS appears to support the idea that at least some traffic routes through Dallas before it crosses the border.
EDIT: clarification
https://landing.google.com/sre/book/chapters/production-envi...
It used to be the case that they were mostly in POPs, but I think that with Maglev (https://research.google.com/pubs/pub44824.html) they can live in core clusters, too. Other Google sources go into more detail, e.g.
https://medium.com/@duhroach/profiling-gcps-load-balancers-9...
https://www.slideshare.net/MichelleHolley1/google-cloud-netw...
Back to your question, I'm not sure there is one good place to look up these things, but presentations/papers by companies like Google and Facebook are probably still your best bet. Stuff coming straight out of GCP teams will be a little more enthusiastic in tone, but that's easy to tune out. :-)
Another good example is Facebook's Ben Maurer and his Fail at Scale talk, which discusses a lot of details that are necessary for modern internet services, such as queuing, session/application-layer congestion control, canarying, advanced monitoring, etc. https://queue.acm.org/detail.cfm?id=2839461
That said, I would love some more in-depth books on the topic.
I guess they just expanded, but the basic facts here are not new.
"the capability to enable surveillance and analysis of internet content on a massive scale, including both overseas and purely domestic traffic."
AND
Klein claims he was told that similar black rooms are operated at other facilities around the country.
What is perhaps more worrying is common currency. The Euro has lead to a lot more trouble than it was worth, Frankly speaking.
Awwww....ain't that sweet??
We've known for years through the New York Times and others that AT&T helps the NSA.
We've known for close to a hundred years about AT&T Long Lines networks and hubs for that network.
It's only basic logic to put the two together and know that the NSA uses AT&T's hubs.
What's new here?
I don't know what The Intercept expects anyone to do with that information, but that is new information.
But my point stands.
We've known that these specific buildings are the key hubs in the network for close to a century. And that they're hardened against nuclear attack, etc...
Maybe I was too deep into the phreaking scene in the early days, but I thought this was common knowledge in technology circles.
> We've known that these specific buildings are the key hubs in the network for close to a century. And that they're hardened against nuclear attack, etc...
Yes, it's been known that these specific buildings were key to AT&T's infrastructure. But any speculation that these specific buildings (as opposed to other specific buildings) were also key to NSA projects was just an assumption. The new information, which comes from released NSA memos and documents, shows that these specific 8 buildings are key to the NSA, meaning it's not just based on assumption anymore.
There's some other new information in there from the memos/documents, too. You really should actually read the article before mounting your high horse and spouting off nonsense criticism about it.
To your point however this tidbit does give a good excuse to re raise the issue. Why are we allowed to spy on ourselves?
A privileged electrical technician torches your establishment to the ground and says he should be thanked for forcing you to rebuild stronger.
The problem is that even though this is all public record lying government officials continue to dismiss the obvious truth as "conspiracy theories" and so it becomes necessary to prove the same points over and over again in excruciating detail as long as government officials keep lying.
Exposed in 2006...it was a fucking huge deal at the time.
It's just America that pretends it doesn't have a secret police.
The term "secret police refers to intelligence, security or police agencies that engage in covert operations against a government's political opponents" [1]. We have no evidence the NSA is "used to protect the political power of an individual" or even political party. They're an intelligence agency, purely and simply.
I can agree on that
More recently e.g. https://www.aljazeera.com/news/2016/11/judge-orders-fbi-cia-...
In the past few years, the debate seems to have shifted from "What is appropriate oversight and behavior for intelligence agencies" to "Literally all national-level intelligence operations are a crime which must be stopped". The difference between the US and China/Russia is that in theory we have an intelligence community that is answerable for its actions to an elected civilian government. The extent to which that is true is obviously debatable, but to try to draw some equivalency here is absurd.
NSA spying to an extent is public knowledge, but the submission is full of new information. I'm sure it will be reported by other sources in a few hours.
Your post illustrates why they take these positions. Even an unsourced insignificant link to Russia is used to discredit anyone.
why would PRC provide a stable "work" and "exercise" routine when it can simply use a death-van?
PRC is wiser to do a quick off-with-their-heads when it wants to shush someone
This line of criticism is often brought up but there is no merit in it. How many Russian language news sources are you aware of?
The US on the other attempts to play like the US Government is high and moral, respecting the freedoms of their citizens, while in the background they are just as Authoritarian as Russia and China
with PRC operating quick-death-"police"-vans, aren't you telling the intercept reporters to risk their lives?
maybe you should try...?
Hold yourself to higher standards if you really are No. 1.
While I agree China/Russia has the intent, but do they have the ability to conduct wiretapping on this scale? It sounds like the US is uniquely able to do this since so much of the internet's backbones/services reside here.
The second thing also indicates a lack of reading comprehension, thus downvoted.
I was simply pointing out a minor (albeit, comical) factual error that immediately made me question the legitimacy of the rest of the article.
To me, it seems like this article is sensationalizing a practice most were aware of already. I suppose it is mildly interesting to highlight a bunch of locations where it may be happening, but certainly not breaking news.