Secret to Prism program: Even bigger data seizure
bigstory.ap.org
bigstory.ap.org
e.g. Get FISA request on someone, gather the data, tap into the big pipes to see what else they are doing.
Does anyone remember this from 2005 ? They retrofitted a submarine (USS Jimmy Carter) to the tune of 1 billion to cable tap under the ocean, http://www.nytimes.com/2005/02/20/politics/20submarine.html . If they are trying to do that thousands of feet under water ( 7 years ago) imagine what they have on land now.
The more I read on PRISM, it seems that PRISM itself is a minor revelation (that being, PRISM just automates what used to be done manually).
Most of the outrage just flows naturally from the Protect America Act, which was never a secret. The public is just now hearing about how the act is used in practice.
I don't think that's the basis of the name at all.
Much more likely, the rainbow part represents all the sources they pull data from, each so different from the next, and the white part represents the single unified feed it provides the NSA agent using it.
(in case it's not obvious, I'm a cryptography n00b)
The basics: HTTPS is TLS/SSL transport level encryption of HTTP traffic (including HTTP headers).
The way it works is that client and server go through a handshake process where the server (and optionally client) present a public key and proof of ownership of a private key. The server public key is also normally signed by a certificate authority (e.g. Verisign), this is what is normally meant by a certificate.
Threat Models: There are a number of different threat models that crop up when talking about TLS. I'll talk briefly about each below.
1. Compromised Certificate Authority (CA)
If the CA is compromised then the rogue CA can be used to create new certificates that claim to be for the intended target server (e.g. Google or Facebook)[1]. The fake certificate can then be used to launch a Man-in-the-Middle (MITM) attack where the attacker convinces a victim to connect to them, and creates two separate TLS connections VICTIM<-TLS1->MITM<-TLS2->SERVER. The MITM can see the unencrypted messages since the victim is encrypting to the key in the fake certificate. Chrome's certificate pinning can be used to prevent this type of attack since the browser will check to see if the server has presented the _correct_ certificate for the intended server (by comparing public key fingerprints AFAIK). This attack can also be prevented if the connection is mutually authenticated by either a client certificate or an ephemeral ChannelID as discusses here[2].
2. Attacker has _correct_ private key for server
This threat model assumes the attacker has obtained the server's private key either via coercion / collusion. Certificate pinning doesn't prevent this type of attack.
2a. If the attacker is a passive attacker, meaning that they can only observe and record encrypted messages, then they can decrypt any messages that are sent over a cipher spec that doesn't have perfect forward secrecy (PFS). If the connection is setup using the Ephemeral Diffie-Hellman key exchange then the communication channel should be safe from a passive attacker. If the connection is mutually authenticated and the client certificate has not been compromised by the attacker, then the connection should also be safe from this attacker.
2b. If the attacker acts as a MITM then even PFS cipher specs can be compromised.
3. Attacker can break TLS encrypted channels and extract data without needing the keys
All bets are off if this can be done in a general way. There have been several attacks (BEAST, CRIME, Lucky13) that can extract small repeated bits of data (user authentication cookies), but no known attacks that can get at all of the data sent over a TLS encrypted channel.
[1] http://en.wikipedia.org/wiki/DigiNotar#Issuance_of_fraudulen...
[2] http://tools.ietf.org/html/draft-balfanz-tls-channelid-00
http://www.eweek.com/c/a/Security/Mozilla-Asked-to-Revoke-Tr...
Have we learned nothing from their public history? They simply don't do shit like that.
It looks like they have some sort of alerting system for real-time "incident surfacing" for things they feel they need to react to quickly, but I imagine most of their work is over the longer-term as far as building profiles of their targets.
Safe browsing does not transmit your browser history to anyone.