China Spying on Undersea Internet Cables
schneier.com
schneier.com
Can't agree more!
It doesn't matter if Facebook is going to be accessible trough TOR only or not if the NSA or any other capable intelligence agency can compromise Facebook.
Even if you do somehow manage to put all physical transport links in the hands of some impenetrable organization the US and China would just send a sub to the ocean and tap the cables.
And just like it's granted that AT&T cables can be accessed by US authorities China can access anything that a Chinese company lays down and likely even with more ease.
Yes but a vast swathe of attacks are stopped with good encryption.
Recall for example that TLS ("HTTPS") provides integrity verification, not just encryption.
Simply cutting the connection because the signal was interupted won't work, not to mention that many taps can be inserted without interruption and it's not like the NSA can't figure out how to work around maintenance windows.
But in this case it's not even a covert unauthorized tap it's a Chinese company ofc they'll cooperate with the Chinese government.
But again encryption doesn't prevent physical attacks of this sort they can still suck all the data out and while it maybe useless unless they can decrypt it this vector has nothing to do with building a secure internet.
The problem is that even if you encrypt everything state actors can simply go one step up the chain at the end of the day someone needs to be able to decrypt your packets besides you.
For example, a link from Vatican City to San Marino should be protected from Italy. A link from Bolivia to Switzerland should be protected from all the other countries along the route.
They are perhaps tapping at point where cables leave the shore, but even that is old hat. With everything being encrypted, and the sheer volume of traffic, intel agencies these days find it much easier to go to the source. If the NSA or China want to read your email, they don't tap undersea cables. They go directly to your email/text/cell service and siphon only the data they want. Or, for things like meta data/location tracking, they can just buy the data like any other company. That is the real future: the commoditization of espionage.
All of it.
If they can't decrypt it now they'll save it until they can.
Save it on what? Can someone do a back of the envelope calculation on what it takes to back "all of it" for an indeterminate amount of time?
https://www.statista.com/statistics/275336/global-shipment-f...
In 2017, global IP traffic was 1.5 ZB per year, or 1.5 billion terabytes. So assuming you were using 10TB drives you'd need 150 million hard drives per year, or about 37% of global production.
https://www.cisco.com/c/en/us/solutions/collateral/service-p...
You can dump any traffic that originates from a bulk traffic provider like Netflix, Youtube, Prime, Xbox Live Download, etc - it would be sufficient to collect metadata if you were interested in this at all. This source suggests that content makes up about 33% of global IP traffic, with unspecified media providers (probably porn) making up another 15% or so, so on the whole you can probably round that up to between 40 and 50%.
https://www.cbronline.com/news/internet-encryption-sandvine
From there the numbers get a little squishy depending on your estimates of various categories of traffic and how conservative you want to be about discarding content.
In theory you can discard anything that you can collect from another source - i.e. stuff like gmail, you can get from google directly, no need to capture that. If you are not interested in retaining un-encrypted content, you could dump a bunch more. Only about 50% of traffic is encrypted, although that is probably weighted towards non-bulk content being the encrypted stuff.
If you can dump, let's say 75% of all non-bulk content then you'd be looking at retaining about 12.5% of total IP traffic, 187.5 million terabytes per year, which would require 18.75 million drives per year, or about 4.69% of global production.
You could, of course, blow it all down to tape filed according to cipher, and then read it back in when you have broken it. No need to keep everything online forever when it's not broken yet. LTO-8 tapes are 12 TB each (encrypted data will not compress), so the numbers work out similarly to 10 TB drives. LTO tape production is a lot smaller though, about 20 million tapes per year, so there is not enough tape sold to do that, unless you are doing a private factory to produce your own tapes. But at that scale, it would probably be more affordable than drives.
Some people speculate that Amazon Glacier is actually a library of BDXL discs and that they are purchasing big batches from factories. That's about 125 GB per disc, but in bulk they are probably also cheaper than drives as well.
https://en.wikipedia.org/wiki/Linear_Tape-Open#/media/File:L...
FWIW Snowden's docs suggested that they were only retaining data for a month (iirc) and then dumping it, but it's possible they could be selectively retaining encrypted data for longer. Presumably the Utah datacenter was built for a reason. I would assume that at this point they have "high-risk" selectors that automatically get pulled out but that they are probably not collecting everything everything and keeping it forever.
Also, a footnote here is that this would be a logistically significant operation, you would either need your own parallel data links with a significant fraction of the capacity of the primary backbone (far beyond what SIPRNET/NIPRNET likely can support), or you would need to be moving shipping containers of drives/tapes back to Utah like Amazon Snowmobile. You'd also need people regularly going into those tap rooms to change out the drives and so on. It would be high maintenance to attempt this.
It is naive to say that the NSA does or does not use a particular collection method. The truth is they use them all to varying levels of success.
Upstream collection (targeting the communication medium and infrastructure) has been confirmed dating back to the 70s and as recent as 2013 with the Snowden leaks. Even the PRISM program with its "direct access" to providers like Yahoo and Google was eventually discovered to be tapping the fiber optic links between the companies datacenters without their knowledge or consent.
- Fisherman goes to X location because he knows at that time he will be able to catch tuna & mackerels.
- Fisherman goes to a random location capturing whatever he can. He can later decide what is of value or not, whether he will throw it back into the ocean or not is up to the captain.
- Fisherman goes to a random location and captures everything. There seems to be some stuff he doesn't know if it is edible or not, but it doesn't matter. He can store the catch and see if he can cook it later.
Some of the catches will spoil before you are able to figure out whether it is edible or not, others can be useful decades later.
How many times is the average packet on the internet copied for surveillance purposes, and how much does it slow down the net as a whole?
The huge difference is the NSA collects to achieve political goals. China spies for political and economic benefit. Foreign businesses are frequently targeted with the singular goals of IP theft or gaining leverage in business negotiations.
The NSA claims it doesn't do economic espionage but there's evidence suggesting otherwise. Google brings up plenty of articles. For example:
https://theintercept.com/2014/09/05/us-governments-plans-use...
https://www.techdirt.com/articles/20150629/16134031494/nsa-d...
The Americans just hide it better and it's entirely within their mandate. China couldn't care less if the world finds out. France is absolutely running wild and has been for decades. Australia has been caught planting bugs in foreign leaders offices for the sole purpose of an oil companies business deal.
I apologize, I didn't mean to come off as snarky. What I mean is that it's my own country. If I was from say Sweden, I'd likely trust the Swedish government more as a Swedish Citizen.
You wouldn't believe. Sweden is really a high-trust society. You can look up any person in the country online, etc, etc.
For a limited definition of 'power projection'.
I am of the opinion that we are in the midst of a paradigm shift from overt physical power to weaponized and atomized informational power.
That is to say, the use of information technology and very fine-grained details about individuals to achieve ends that suit those projecting power.
As a US citizen living in the US, even if the Chinese were to have every bit of my private data, they wouldn't really pose any threat to me as I'm not in their jurisdiction. The US, on the other hand, has a very real ability to use my data against me.
With very few exceptions (e.g. you are being explicitly targeted by a hostile nation-state for high-profile activities), surveillance by foreign governments will always pose less risk than surveillance by your own government.
However, I'll counter with the idea that while I as an individual am at minimal risk from direct legal action from China, the greater collection of data as a whole on say American's could be used maliciously. One example would be "Cambridge Analytica style" targeting of advertising, similar to the previous US election.
What I mean to say is that this data may pose a strategic advantage for China in ways other then targeting individuals. Yes the US can do this to me as well, but again I'm more confident in our system of checks/balances to at least minimize the damage.
Again, I do oppose all State surveillance, I just mean to voice my opinion the "lesser of the two evils"
I think two simple principles should be remembered to facilitate this:
1. Most end users will choose convenience over security
2. Security without usability is a compromise to security
If developers of these innovative technologies take the time to implement tried-and-tested security/privacy controls while providing easy-to-undersatnd education for non-technical users, then I believe things can certainly improve.
You can see the conflict spanning the South China see to trade relations and economic investment to accusations both directions of misconduct in technology manufacturing.
China has been getting more aggressive due to perceived US weakness, and this kind of PR is part of a multi-pronged US response. As are increased prosecutions for financial crimes and kicking up a fuss over the trade deal.