Either way, call me when someone finds out they can decrypt and examine all the SSL traffic in real-time.
Either way, call me when someone finds out they can decrypt and examine all the SSL traffic in real-time.
Since this is a mirrored copy of their entire backbone, they're also catching traffic to and from peering points. In Mark Klein's deposition[1], he testifies:
Starting in February 2003, the "splitter cabinet" split (and diverted to the SG3 Secure Room) the light signals that contained the communications in transit to and from AT&T's Peering Links with the following Internet networks and Internet exchange points: ConXion, Verio, XO, Genuity, Qwest, PAIX, Allegiance, Abovenet, Global Crossing, C&W, UUNET, Level 3, Sprint, Telia, PSINet, and MAE-West.
Even if you're completely awesome and use SSL everything (like, say, Gmail), eventually that e-mail you sent is going to find its way from Google's servers to its final destination. That, with almost no exception, is plaintext. If the final destination's MX lives on AT&T's backbone and transits those peers (there might even be more possible scenarios I haven't thought of, such as AT&T selling transit), they are able to copy that e-mail in flight. All of the public information about this case is dated; I can't imagine that the NSA hasn't improved the facilities since.
This is a very specific example, but you get the idea. There are a lot more examples of why this sucks. It's not just your browsing they're catching; there's a shitload of traffic going into that room.
Aside: I'm really surprised this is coming up again. FISAAA mostly and grudgingly killed this story for me in what, 2008? 2009?
[1]: https://www.eff.org/files/filenode/att/Mark%20Klein%20Unreda...
2) Do you think every CA with a cert on your system is incapable of being bullied by the US government?
The real danger would come if they didn't have to target you and could just mass mine every single encrypted packet.