Technical Implications of the NSA's Prism Program
lahiri.me
lahiri.me
a) "We did hold back quite a bit from this story." "There are some things that we looked at on our own, and said we're not going to publish that, and there are other things we talked to the government about." What does that mean? We saw three slides of a very limited nature.
b) "This source believes that exposure was inevitable and is prepared to face that consequence." "He thinks what the NSA is doing exceeds all reasonable boundaries of privacy or necessity." This wasn't over mundane FISA court ordered data releases.
c) In response to the question, "Why do these companies authorize this?" Response: "There is a pretty complicated set of incentives and compulsions. The law does provide that they can give access and a secret surveillance court can make them give access, but in a situation that you have a clandestine program and a very rich and powerful component ... They don't want to litigate this with Facebook, they don't want a chance of it leaking ... Facebook also being a highly regulated industry, having all kinds of issues with privacy and whatever else doesn't want to antagonize the government, so they negotiate it. Now Apple took .. 5 years .. I don't know what happened, but Microsoft joined in 2007 and Apple didn't do it until the end of 2012."
So, the author, who saw all of the slides and talked to the source says that they they left great amounts out of the story, but absolutely confirms & goes in to detail that the companies were complicit with the NSA and that it went beyond what the legally mandated options.
If the denials issued by Facebook, Google, and their respective executives are not an outright lies, and this story is not a hoax (I am assuming it is real since Obama had an opportunity to deny its existence) then there is a compromise in the traffic streams entering and exiting these services provider's platforms, very possibly like the infamous AT&T Room 641A.
This may be more disturbing than we initially believed.
Imagine if the NSA has a copy of these companies' (Google and Facebook's) traffic, and has perhaps subpoena'd the TLS keys. Having the TLS keys is still not having "direct access" to their network, since the NSA at no point accesses internals of their network. But the NSA gets all the data and decrypts it.
Next, NSA engineers spend time reverse-engineering the company's protocols. Or maybe the companies hand over the specs. Anyway, the NSA can now recognize a request to Facebook representing posting a message; or it can recognize in Google's traffic someone reading or sending an email. It can tell when a file is stored into iDrive.
It saves copies of all of this - the date and time of the request to Facebook, the message, etc.; for Google, the entire copy of the email, or search query.
NSA stores all of this data into a searchable, queryable database, that is capable of looking up a person's activity in those systems. And retrieve the same Facebook message, Google meail, or iDrive file that the user had sent.
This is a version of events that seems to fit the data I've seen.
In another thread, someone suggested that PRISM records information without "tapping" the companies lines. Perhaps that is true, and the tapping happens at the Internet backbone level, without awareness by these companies (beyond giving up their TLS keys).
I think the question we need to ask Google, et al., is: did you divulge your SSL/TLS keys to any government, agent of the government, or any other entity?
False, one can't passively mitm SSL when perfect-forward-secrecy is used. I just checked, and google seems to be using it.
http://www.quora.com/SSL-Secure-Sockets-Layer/Is-it-ever-pos...
Google uses Diffie–Hellman key exchange which provides perfect forward secrecy.
So... If I understand everything correctly, it should be impossible to decrypt passively captured SSL-encrypted communication to/from google.com.
Edit: replying to the poster below, it doesn't have to be a passive attack, and I'm not sure what you mean about checksums. The scenario above would look exactly like normal Internet traffic. You're not mutating packets, you're sending entirely new ones.
Me in Europe ------200 ms------- MITM magic --1 ms-- Google
For the attacker not to introduce huge extra latency, it would need to complete the handshake with Google almost instantly. Someone would eventually notice instantaneous TLS handshakes.
Also 2 separate TLS connections would contribute to bufferbloat pretty badly, and someone would also eventually investigate that.
then there are 2 endpoints that are decrypted separately
"I realized that the U.S. government loves the "PRISM" acronym. There are literally dozens of projects and applications named PRISM at the state and federal level, many with delightfully goofy logos."
http://waxy.org/2013/06/these_arent_the_prisms_youre_looking...;
"In addition in Chromium 13, only a very small subset of CAs have the authority to vouch for Gmail (and the Google Accounts login page). This can protect against recent incidents where a CA has its authority abused, and generally protects against the proliferation of signing authority."
(disclaimer: I work for Chrome but not on these features.)
But yes, if PFS key exchange is used in TLS then having the private key alone would not help with decrypting previously gathered packet data. In that case the only thing I can think of for NSA to read the data is if they successfully created (in secret of course) a practical quantum computer which then renders RSA and DHE (anything that relies on integer factorization or discrete logs for that matter) completely broken.
Instead could it be describing intercepted bandwidth, leeching off of those pipes?
http://2.bp.blogspot.com/_F8MQ-8DbBQc/R7gSdBOntyI/AAAAAAAAAS...
As a nod to fiction like Eureka and the revelations like Los Alamos testing quantum communication for years [1], it's interesting to think what else the NSA is working on for (inter)national surveillance.
I think the backlash is going to be greater than the USG anticipates. One thing that engineers can do is to simply refuse to work for the US government, or leave if they already work there. Deprive them of talent. Stop them from recruiting on college campuses.
There's a precedent: the campus campaigns against Don't Ask, Don't Tell. The NSA of course has its own very unique interpretation of "Don't Ask (for permission), Don't Tell (what you're recording)". But it's probably just as worthy of censure.
The slides also show that providers join over time. If they were just intercepting you would expect all email providers to join at once; that doesn't appear to be the case.
There are also stuff like "online social networking detail" and "login notifications" which make it seem like facebook has given access to their systems.
The NSA analyst gets intel on such-and-such an account ID/phone number/email/etc., uses PRISM to send a request (probably something stupid like SOAP, it's the govt after all).
The company computer verifies a valid warrant ID, valid request type, "hoovers up" the data requested and spits it back to NSA.
Technically not direct access. Certainly not a direct wiretap into the entire company database. But NSA is able to get the "special source data" they need for correlation on their end (possibly using tools as provided by Palantir).
They figure out whatever network of conspirators they're researching, develop "actionable intel", good guys win (note: depends on your interpretation of good guys, obviously :P).
Zuck and Page are still right in this scenario. I just wish someone would speak up about what the hell is actually going on!
PRISM allows an analyst to load up a warrant and start exploring data immediately without having to wait for the company to verify it and then do a ETL operation back to the NSA.
Also, the published slides are just three out of forty-something. The bottom of the slide that lists the capabilities says "complete list and details on PRISM web page." I agree that if they're doing this, they probably are already intercepting all unencrypted SMTP traffic.
Even then, how much more do you have to pay someone? After all, it'll get done one way or another. There are plenty of intelligent people that will decide they might as well make a lot of money at it, and perhaps protest on the inside.