Room 641A
en.wikipedia.org
en.wikipedia.org
Super nice guy. Has the only two golden retrievers I've ever been frightened of, and if I were him, I'd probably have some assertive watchdogs, too.
Off topic question... Do golden retrievers have a mean side to them? I’ve always liked them and I dont like scary dogs in general
Walking into that courtroom later that day and getting stares from AT&Ts lawyers was, for lack of a better term, special.
Also Mark Klein is an underappreciated American hero.
Needless to say, the stuff that those fibers would go into and out of in that particular application, is way beyond my comprehension.
Also, TippingPoint had a pretty blazin' 40Gbps ASIC-based packet filter 10 years ago.
1: https://arstechnica.com/information-technology/2013/06/what-...
Not trying to argue for the sake of it here, but _is_ that a huge achievement? I assumed this was a simple device that splits the fiber beam, sending one part on it's way to AT&T and the other to some NSA database for further processing.
So they have to filter a lot of data for interesting bits really fast before storing / sending it anywhere else
From linked article on Jewel v. NSA[1]:
On March 10, 2014, Judge White imposed a temporary restraining order, requiring the NSA and other parties to halt the destruction of evidence until a final resolution of the case. On June 5, 2014, the EFF filed a motion for an emergency hearing requesting that the court enforce this temporary restraining order after discovering that the government had continued the destruction of evidence. A motion filed by the government claimed that doing so would have severe consequences "including the possible suspension of the Section 702 program and potential loss of access to lawfully collected signals intelligence information on foreign intelligence targets".[2]
[1] https://en.wikipedia.org/wiki/Jewel_v._NSA
[2] https://www.eff.org/files/2014/06/05/govtemergencymotion.pdf
That said, I would rather live in a country surrounded by people who take it for granted, than live in a country where there is no rule of law.
https://upload.wikimedia.org/wikipedia/commons/8/89/Room_641...
Hopefully the hinges have security pins.
That’s a bit of a myth. It won’t work on normal door hinges going back many decades. When the door is closed, the knuckles of the left and right sides of the hinge overlap, so the door won’t slide out even if the hinge pin is removed. You need to swing the door open at least 10-20 degrees to disengage the knuckles. (I wish I found a decent close-up picture of hinges on a closed door to include here.) The easiest way to see this is to walk over to the nearest door and look at the hinges.
PS. The room still exists and continue to serve its purpose.
And: https://en.wikipedia.org/wiki/33_Thomas_Street ; https://news.ycombinator.com/item?id=21555954
A few years ago I had to do an update to some of our sun servers in CAPITAL (the really big international Exchange in Edinburgh) interesting experience cavernous rooms and quite spooky with all the various clicks and bleeps
It's complicated.
Telcos that operate in the US are required to follow US laws and court orders and there are laws and orders that require them to submit data to the gov.
But they also don't seem to be trying to fight it: https://www.wired.com/2013/09/telcos-metada-orders/
I'd imagine if they fought it, a new law would magically appear in the books so it's hard to tell if they are being practical by not pursuing legal action that is bound to be overruled or just plain evil (the truth probably lies in the middle)
https://www.aftenposten.no/verden/i/Olkl/sources-we-were-pre...?
https://www.theguardian.com/business/2014/jun/06/vodafone-re...
My guess...some kind of reader hidden in the door that triggers a mechanical device that lifts the panic bar (another comment's comment) or otherwise disengages some such other locking mechanism.
- Data which is encrypted with a key they have access to (or which is encrypted with insecure methods)
- Data for which they might find a key in the future (If not yet secured by perfect forward secrecy)
State-sponsored attacks against crypto are targeted, they don't care about your online shopping cart contents secured by TLS. They go for VPN connections, IPSec tunnels, and Tor.
A classic example is the Dual_EC_DRGB (Dual Elliptic Curve Deterministic Random Bit Generator), which uses a public/private key pair to generate the random numbers. The NSA pinky swears that they destroyed the private key, and don't know what it is. Nobody in their right mind believed them. Yet, the NSA basically forced a bunch of VPN vendors such as Juniper to include it.
Now, fine, okay, in theory Dual_EC_DRGB is safe even if the private key is know to an adversary, unless ~40 bits of the internal state is leaked during the connection handshake, which seems terribly unlikely. That was NSA's argument for why everyone should trust them and their algorithm. Unfortunately, guess what... the Juniper ScreenOS had a "bug" in it that just so happened to leak a bit over 40 bits of the RNG state into the handshake packets. Accidentally, I'm sure. Ooops.
It's also a safe RNG if the private key is destroyed, and is not known to anybody. But unfortunately for Juniper, the Chinese government hackers broke into their source control and replaced the public key with their own, matching a private key they know. So for a while, all Juniper VPN connections were being spied on by the Chinese government instead of the US government. I'm not sure which is better.
I've read similar stories about Cisco, Citrix NetScaler, etc... They all have purposefully weak crypto, government mandated back doors, and so forth.
The various western governments' fears of Huawei being used by the Chinese government to hack them is absolutely warranted: this is exactly what they would do given the same opportunities!
And the encryption is getting better. For forever DNS queries were plaintexted on the wire, but now with most browsers adding a DoH feature, those days of passively sniffing DNS lookups on the wire are over. You might be shifting your queries to a centralized provider, but it's miles better than letting the NSA lift logs from an ISP.
I'm also surprised I haven't seen more pictures and stories of where these rooms actually located (or maybe I just haven't been paying attention)
https://www.wired.com/2007/05/spying-in-the-death-star-the-a...
> The ruling noted, "Klein can only speculate about what data were actually processed and by whom in the secure room and how and for what purpose, as he was never involved in its operation." The Court further went on to discredit other experts called upon, citing their heavy reliance on the Klein declaration.
https://theintercept.com/2018/06/25/att-internet-nsa-spy-hub...
Structural reinforcements as mentioned for datacenters are also fairly normal, they’re often designed to survive the worst imaginable environmental conditions for the area they’re being built into.