The NSA slide you haven’t seen
washingtonpost.com
washingtonpost.com
All these revelations regarding call metadata, PRISM collection (albeit under a different codename at the time), modern fiber taps, and even more are covered.
You'll learn about how they shave fiber optic cables in order to intercept traffic and not be detected. You'll find out about the various facilities already reported, along with others like the NSA Georgia facility. You'll find out exactly where on what beach these fiber lines run in and out of. It's a very well-researched book.
You'll learn a lot more than what's been verified with these leaks.
http://www.amazon.com/The-Shadow-Factory-Eavesdropping-Ameri...
... I thought one of the points of Fiber was that you couldn't tap in without disturbing the optical signal? Did I just make that up in my head?
(The presentation was given by Evi Nemeth, who was sadly in the news recently due to being lost at sea.)
[1] http://www.caida.org/workshops/isma/9808/report.html "The coral/ocXmon family of monitors use optical splitters to tap fiber, filtering 5-10% of the light signal to interface cards in the coral monitoring host."
On the other hand, if you'd tap only a short distance downstream of the transmitter (or an inline amplifier), that 1% might be plenty, undisturbed by the distortions introduced further on the line, so probably that's the preferable tapping location anyway.
[I know that I'm oversimplifying a lot here and modern optical communication systems work much different.]
Well of course you can't. If you're going to split it off to read it, then you're "disturbing" it by definition.
Whether or not you can do such that it's not noticeable to the proper end parties, of course, is a different story.
Interfering with existing amplifiers/signal boosters would be fairly hard to hide unless the NSA was solely responsible for that units maintenance, and I suspect that as a general rule they aren't. It's much easier to hide a tap at some random point along the line where nobody has any reason to visit
Getting the signal out of the fiber pales in comparison, though, with the task of getting all of that data back to Maryland/Utah.
Unless they have specific cooperation of the cable owners and can tap/split the fibers at the landings, they must be spending a significant percentage of the cost of the original fiber runs (in parallel cables to return the tapped data). The mind reels.
Of course, this requires a friendly country at one end of the cable, but that's probably not too big a problem.
This is a nice primer on fibre:
http://www.redbooks.ibm.com/redbooks/pdfs/sg245230.pdf
And here is one talking about its security, in particular vs tapping (the conclusion: it can be done):
http://www.sans.org/reading_room/whitepapers/physcial/fiber-...
Finally, I always figured that tapping fibre was exactly what this was for:
I wouldn't be surprised if there are other esoteric techniques that somehow allow NSA to monitor emanations through an intact fiber optic cable and its shielding.
In any case, it's wildly interesting stuff.
Specifically relating to the recent revelations, this book was where I learned of the NSA's "vacuum cleaner" approach, in which all available messages are collected -- in this case, it was trans-Atlantic radio transmissions being monitored by ECHELON. So, an American citizen in the UK calling an American citizen in the US would have their call collected.
The approach (collect everything you can at the trunk line or server farm) is very similar to the e-mail collection strategy that's being documented now.
Edit: It looks like it's been removed from Netflix, but you can still stream it directly from PBS's website:
[irony] As we are used in Germany, we are kept in the dark. [irony end]
Maybe he's busy.
I'll check back.
Take off all the nicks, for maximum message resolution.
First, when it comes to programs by US intelligence agencies (both previously known, currently revealed, and yet to be revealed) there are multiple categories of evaluation: namely, ethical, legal, constitutional.
Generally speaking, everything the Feds are doing is legal in the sense that it follows a specific legal process that was setup in the scare over terrorism, which both expanded the powers of the executive branch and created "shadow courts" which presumably provide some checks and balances in the system. Of course, we can't really know how reliably these work since the process for National Security Letters and other aspects itself is secret. Nonetheless, there are specific process in places that seem generally speaking to be followed. How often there are "exceptions" to this process is difficult to ascertain, and has not really been a focus in the present debate.
When it comes to constitutionality, it is a hotly debated topic among Americans partially because it was the bedrock of the American state, but an increasing number of Americans (including justices) either aren't knowledgable or don't care about the specifics of the constitution. This is a huge topic, but it is sufficient to say that something can be unconstitutional (even blatantly so) and nonetheless be legal. In this specific case, it is difficult to know how or whether the protection against "unreasonable" searches includes storage of metadata associated with phonecalls that can be searched by an analyst.
Then, more broadly, there are a wide representation of ethical issues. For example, it is completely legal and constitutional to spy on non US citizens, but are there any boundaries that should be set on what is and is not acceptable behavior? My strongly held view is that, at least when it comes to US hq'ed companies with a large foreign user base that they provisions in places for non US citizens should at the very least be the same as those for US citizens. However, saying that something should exist and implementing it are two different things, and one is considerably more difficult than the other.
So this is all basically to defend tptacek and say that it is important to differentiate when accusing the US government of "crimes." In other words, there are lots of unethical things that you can do that are perfectly legal.
I fully expected Craig Timberg to be attacked, just like Glenn Greenwald was.
It is unfair that I'm using a nym, whereas tptacek's a real identity.
It may be unfair to single out tptacek out of the mob of people banging the "direct action" drum. He stands out here on HN. Since I'm using a nym, I won't belabor the point.
However, if any analyst can at whim look at the info associated with any gmail account / Facebook user / etc. then you have a clearly extra-legal approach with absolutely no accountability.
Also, there is a significant difference between capacity and use. If a analyst or a sys admin for the NSA has capacity to view things but does not actually have permission from the NSA to use that capability absent an NSL, then
To be honest, to date nothing has emerged that makes it seem that the NSA has this sort of capacity, except when it comes to Verizon phone calls, although I don't think we know much if anything about the NSA's downstream capabilities when it comes to major Silicon Valley firms.
In short, I assume that Google, Facebook, etc. are telling an important truth when they say that access is limited to legal processes. Whether or not the NSA also has and uses downstream access to similar data is another question altogether.
Remember when Mark Zuckerberg (Facebook), Marissa Mayer (Yahoo!) and Larry Page (Google) all denied "directly" giving the NSA everyone's data?
They claimed that all access was done through national security letters and warrants, because the slides that had leaked at the time supported that. Turns out new slides leaked, and everyone lied!
*snip* (I linked to the WaPo article, and the slide directly)
And for sources on the original denial (each claiming "no direct access"):https://www.facebook.com/zuck/posts/10100828955847631 (Zuckerberg/FB)
http://yahoo.tumblr.com/post/53243441454/our-commitment-to-o... (Mayer/Yahoo!)
http://googleblog.blogspot.com/2013/06/what.html (Page/Google)
However unlikely, it's still possible the NSA had moles or secret legal proceedings against certain employees that directed them to provide the NSA with a direct connection to the servers.
The reason why I say 'unlikely' is that such a setup would also involve data connectivity out of those data centers and additionally would probably trip all sorts of intrusion monitoring systems (if the big companies are doing their jobs right).
There's still a little wiggle room here, just not much very realistically.
EDIT: to clarify, GIVING someone access directly to a server and allowing/knowing about access to the data going in and out of a server are not technically the same thing.
When I saw the Google/Facebook responses, it was obvious that the posts had a lot in common. Both used the phrase "direct access to our servers".
When you see a phrase repeated like that, one of two things has happened. Either one copied the other's phrasing, or someone told them what to say. In either case, the legal department would definitely weigh in on a huge issue like this.
A smart lawyer would never let the company lie outright. They would advise everyone to speak the truth, but "the truth they speak may not be the truth you think you hear." No direct access to servers. Sure. They just had access to the data going in and out of the server. To someone used to reading political and legal documents, "no direct access to servers" almost screams "some form of access to something." Otherwise the denial would have been more
Zuck and Page didn't lie, but they were less than forthcoming. Myers didn't even bother addressing the claim directly.
I suspect a government lawyer fed them phrases they could use that sound like denials without actually lying.
I totally agree that these organizations used the phrase "direct access" intentionally, surely with legal advice. My point, however, was that at the time that these companies released their responses, the slide that actually said direct access verbatim had not yet leaked. Although it's impossible to tell what actually happened, it looks to me like they decided to deny "direct access" in the hopes that there were no slides indicating that direct access did exist. After all, it's unlikely that these companies had the full slide deck (or anything other than what the media had published).
So, either:
(A) Larry Page and Mark Zuckerberg actually didn't know that they provided "direct" access to data.
(B) NSA actually doesn't have "direct" access as indicated by this slide, meaning that the slide is incorrect or falsified.
(C) Page and Zuckerberg lied in their statements.
I don't see a fourth option regarding direct NSA access to these companies' data.
And you're right regarding Mayer not addressing the claim directly; I was a little bit off there. Still, by saying "well, we received between 12,000 and 13,000 FISA requests," Yahoo! is implying that there isn't any sort of "backdoor" access, which no longer seems to be the case.
My browser pulled the comment I'm replying to right now 'directly from the servers of' HN, but I don't have 'direct access' to HN.
It's also very possible that the slide traded some simplicity for accuracy because it was being presented to a group of people who didn't really care or understand the details and technicalities.
Also, (E), The companies didn't "give" the government direct access, but were quietly complicit in allowing them to collect data.
The slide I'm talking about ( http://www.washingtonpost.com/wp-srv/special/politics/prism-... ) states: "collection directly from the servers of these U.S. Service Providers."
Since there's currently no way to "browse" private data on, say, my Google search history or my GMail inbox, the conclusion seems to be that they either have broad backdoor access, or a specific way of directly downloading from these companies.
In a traditional warrant situation, the data would be collected by the companies and sent to the requesting agency that provided a warrant. Police officers that request, say, HTTP access logs do not download those logs directly.
However one wants to define 'directly from the servers of' or 'direct access' I think for all intents and purposes it means the same thing.
Yes, that's what PRISM is. Warrant compliance, automated and streamlined.
A good lawyer would always insist on such phrasing, only addressing the absolute minimum necessary, even if there is nothing to cover up.
Of course, the fact that such outspoken CEO's all let the lawyers use them as sock puppets is still a big red flag.
(And the subsequent transparency theater that carefully circumvented any of the actual accusations makes it even more suspicious.)
LOL
http://www.guardian.co.uk/world/2013/jun/08/nsa-prism-server...
I'm marking this one down to PowerPoint-specific rendering (vs, say, OpenOffice).
Fits perfectly with the "different software" idea. Pages, Google Docs, OpenOffice and even different versions of Office produce different results with the same PowerPoint.
EDIT: Also, on the US-zoomed/masked one, it makes the ellipses line up correctly with all the cable landings at the coastlines. I'm now sold that these differences are just PowerPoint-specific renderings.
What's really quite interesting is that they're typeset differently on the redacted/unredacted slides.
http://www.washingtonpost.com/wp-srv/special/politics/prism-...
http://static.guim.co.uk/sys-images/Guardian/Pix/pictures/20...
EDIT: Also, as the WaPo article points out, the map is different too...
It might be a good idea to read up on the guidelines [1] a bit though, since it seems your comments, while generally with good intent, often don't contribute much to the discussion at hand, like the comment I'm replying to here.
Another good way to get a feel for what is appreciated and what not is to check a bit of pg's comments [2]. You'll quickly get a feel of what's considered proper discourse and what isn't.
Good luck and enjoy your stay here!
[1] http://ycombinator.com/newsguidelines.html [2] https://news.ycombinator.com/threads?id=pg
Also, if you look between the two versions, you'll see that the Guardian's failed to render the transparency behind the PRISM logo. This definitely points towards rendering mishaps, rather than some sort of editing on their part.
http://www.washingtonpost.com/wp-srv/special/politics/prism-...
http://static.guim.co.uk/sys-images/Guardian/Pix/pictures/20...
* Red PRISM background should probably be rendered as transparent (as in the WaPo version) * Typesetting on the Guardian version looks incorrect * Guardian map looks to be misaligned/scaled, rather than changed (notice that the company logos are in America on the WaPo version, and the blue circles overlap fibre connections, but are not on the Guardian version.
[1] http://www.guardian.co.uk/technology/2009/aug/07/local-gover...
So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direct access would be better than these slides. I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Or maybe even the NSA, but we know they share inaccuracies under oath, so maybe that isn't worth so much.
Do you really have that much faith in those companies? Seems like some kind of super-power to me.
There is no way someone would risk perjuring themselves OR disclosing classified information under oath.
Yeah but what stops you from doing so? I mean, not lying, just giving the "least untruthful" statement you can:
http://www.washingtonpost.com/blogs/fact-checker/post/james-...
Because law enforcement (like everyone really) LOVES having their time wasted.
Either way, the tapping of cables is bad enough.
This might be what the slides meant. And the NSA has already lied under oath to congress. Maybe even twice.
Google et al. have fully complied with this law. The FBI manages the government-end of the CALEA tapping capabilities. The NSA makes requests to the FBI, which passes them on to Google, which flips a switch and enables the tapping of user "xyzzy123". From then on, xyzzy123's stored data and new communications get sent to the FBI through the CALEA connection, which forwards them to the NSA. CALEA also requires the service provider to provide all sorts of metadata about the user.
This IS "direct access" to Google's servers. The denials about this have been carefully worded things that all access is supported by some sort of legal process, etc. The denials are non-denial denials. Yes, GOOGLE (et al.), not the NSA, flips the final switch which sends the data. But Google is required by law to do so, so....... And once the switch is flipped, all of the data is flowing automatically to the NSA.
I hope this is clear.
Aside from that I'd say it's a very clear, and it's sad that there seems to be a pervasive inference that these companies are something something beyond what our elected law makers have forced them to do. Why isn't more angst directed at the politicians responsible for this?
Search for 51.
And as for warrants, no they do not always need a warrant. They only need that if both parties in the communication are US citizens. If none of them are no warrant is needed at all and if just one party is US then they (according to the Wikipedia article on PRISM) can wiretap for up to a week without getting a warrant.
CALEA does not apply to Google (except Google fiber and perhaps Google Voice). Google does have to comply with FBI requests for emails and stored data, but they do not have to comply with CALEA (which mandates technical standards for the wiretapping of the phone network and most internet networks). Google does NOT have to build real-time domestic spying tools for the government, though it is arguable whether the 702 program (which PRISM is part of) does.
The FBI would LOVE to extend CALEA to Facebook and Google, etc, but this has not happened yet.
That said, it is likely that the FBI's backbone spying network (DCSNET), which was built for CALEA, is being used for PRISM.
http://www.guardian.co.uk/world/interactive/2013/jun/06/veri...
Moreover the language it was written implies that the same order was made to the other providers, changing just the recipient.
(If you are on the network which blocks access to Guardian, http://www.guardian.co.uk/world/2013/jun/28/us-army-blocks-g... you're missing a lot! Visit some friends, surf from their computer.)
It's not clear at all that this is legal, especially given the Supreme Court's recent ruling in Jones, requiring warrants for GPS tracking of automobiles.
( The mentionend post for reference and sources: https://news.ycombinator.com/item?id=5965994 )
Some would interpret "direct access" to mean root level access to their entire infrastructure, which sounds absurd to me, yet some people seem to believe that's what's happening. And it's my understanding that this is what Google, facebook, etc. have been denying. They could instead be giving "direct access" to an FTP server or some other portal set up to provide the requested data, meaning that Snowden and these slides are being truthful in that context.
I also think it could be argued that we all gain "direct access" to Google's servers every time we type "www.google.com" into a browser's address bar. It is just not a useful term, and should be replaced with something more specific in all these instances.
How about "collection directly from the server of..." just like it appeared in the actual slide, instead of 'direct access' as everyone else misquotes it?
Also realize that Glenn Greenwald shares a good amount of blame for this misquote. The first line in the first article about PRISM is "The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants." (http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-n...)
I agree, and have said as much multiple times.
But that's no reason to continue to perpetuate the usage of a semantically-different variant of the original quote, especially with all the other data we have on PRISM now that can help disambiguate what the original quote could reasonably be construed as.
The real story here is the "Upstream" collection. Just horribly irresponsible behavior for a steward of much of the Internet's infrastructure. Shameful.
It's possible Snowden is making the whole thing up but the government haven't denied anything is going on. It should also be possible for at least some of Snowdens claims to be verified. For example he has claimed that the government was hacking Universities it might be possible to see evidence of that. Or he claimed people have been wiretapped, maybe he knows some of the conversations.
It's possible the government won't deny due to a policy of denial and are sticking to it despite the huge PR issues. Or maybe they want people to think they are watching. Or maybe the people in positions to deny stuff want the current government to look bad.
Maybe the government will deny later and it's taken a while due to bureaucracy. But by that time it will be to late since if there was anything they will have had time to clean house.
Only Google have so for made a post saying the whole thing is fake.
Such naivety.
It's not direct from the servers, but to the analysts it might as well could be the same. These slides might have been meant for tech-illiterate people, saying that might be clearer.
If so I feel that there's a certain lack of ethics involved in this. We now have a slide recommending "direct access", after weeks of denials and pointless discussion about it that would have been much clarified and bolstered if this slide had been released. On the other hand, we still don't know the full context of the slides. Perhaps the next one says "But we don't have direct access yet, we are still working on that". Or perhaps it says "for direct access, get a warrant". We just don't know.
I understand the motives of the WP in releasing these slides one by one. It will undoubtably be maximizing the publicity and traffic they get from it. But I am not at all sure it is serving the public interest.
Heh, well, I guess I fell for the incorrect headline then. Thanks.
Does Google, Apple, Skype, etc. physically own Internet infrastructure, or are they all leased lines from carriers?
If they owned any physical "lines", and the gov was tapping into these lines, then they would be lying about the direct access claim.
But if they don't own these lines, it seems the companies can't do anything about it, and that the telcos are the villains.
Apologies in advance if I'm oversimplifying.
What I am wondering at the moment is the "DNI" on the same slide, is this direct neural interface? /tinfoil
http://en.wikipedia.org/wiki/Blarney_Stone
Before the safeguards were installed, the kiss was performed with real risk to life and limb, as participants were grasped by the ankles and dangled bodily from the height.
I can reliably inform you that this is indeed as scary as it sounds.
And this is the first time I'm making this comment here.
These articles really need to be flagged/tagged by HN and by the newspapers that publish them. I don't want to see a TS/SCI-classified document and I don't want to be seen as seeking them out.
I love the technical stories on HN (95% of what we read here) but it bothers me that I'm risking my clearance when I read this site.
Using separate accounts for reading unsafe links and commenting safe ones can avoid detection based on writing style analysis.
Since Tor exit nodes can be compromised easily and HTTPS is vulnerable to attackers powerful enough to have the private keys of major certificate authorities, the passwords used should not be reused for other services.
Or quit.
Listening to Democracy Now this morning, one of the defense witnesses in the Manning trial explained that many, many of classified documented Manning is accused of leaking are also publicly available via government websites or in the media. For instance, personal details of detainees at gitmo.
I'm struggling to understand how information which is in the public domain can be classified.
If you are not permitted to use the internet like an adult, that is your problem.
Yeah, I thought so.
EDIT: Seriously, downvoters: you NEED TO WAKE THE FUCK UP !
- either your data
- and/or your money.
Sincerely, your NSA
That's why people are downvoting you. Not because they disagree but because your comment provides no actual information.
You CAN NOT continue to use products and services by NSA companies like Microsoft - Yahoo - Google - Facebook - PalTalk - AOL - Skype - YouTube - or Apple and THEN turn around and BITCH AND CRY ABOUT LOSING YOUR RIGHTS AND PRIVACY.
This is completely INSANE, you NEED TO WAKE UP!
EDIT: Yeah, let the censuring begin again. You know what? When I look at the people here on HackerNews, I'm beginning to see a SOCIETY THAT ACTUALLY WANTS TO BE FUCKED - DEEPLY EVEN.
1) Calling people insane won't win you any favors.
2) "WAKE UP" is an entirely useless platitude.
3) Simply not using "NSA companies" is completely impractical. Not everyone can afford to be a recluse eccentric by ignoring the largest software providers on the planet. Never mind the fact that switching to an alternative in mass would simply produce a new "NSA company". These companies aren't at fault, our government is.
Do you have any concrete proposals? Do you have anything new to share? It doesn't seem that you do.
I say exactly what it IS. It IS INSANE.
I do NOT give a fuck about any favors. I don't care about any fucking karma points - we're turning into a turn-key totalitarian system, and people act like nothing has changed.
You got https://prism-break.org/
Now go and do your homework, I'm not your dad.
Guess it's time to find the resources to buy thousands of miles of fiber optics and hope the NSA, GCHQ, and the rest of the global surveillance state doesn't tap those! :D
http://gadgets.ndtv.com/telecom/news/government-to-take-over...
I think the companies are also at fault. If instead of illegal surveillance the companies were being asked to illicitly expose employees to potentially harmful radiation, the moral culpability would be more obvious, regardless of the letter of the FISC laws their corporate counsel was shown.
There was clearly a decision on the part of the employees of the companies involved not to risk their own livelihoods by simply going along with what the government wanted.
I'd argue that major atrocities are possible via the combined impact of institutionally diffused acts of moral depravity such as those committed by our beloved tech companies.
No one should "bitch and cry about losing your rights and privacy" - they should be lobbying their representatives to change laws.
We try to have a reasoned, intelligent discourse here. There are many services provided by companies which may collaborate with the NSA or law enforcement which are pretty much unavoidable in modern society; the telephone network, the internet, and so on. Telling people that they need to completely disconnect from modern society or they shouldn't complain is unproductive.
Rather, we should be discussing realistic solutions. Pervasive end-to-end cryptography for everyday tasks would help. Better laws and legal oversight of both the government and of corporations would help. Protocols that encourage federated or decentralized use, rather than central storage that everything passes through unencrypted would help.
Everything has already been discussed. Multiple times over. And when you repeat yourself, you get downvoted.
It's not what you say (which frankly everyone here seems to agree with). It's how you say it.
I'm not trying to make the argument to stay, but without viable alternatives, people won't leave.
edit: also bbm is going cross platform soon, so that may give an encrypted social network alternative, haven't used it though. also I think they gave india/dubai a backdoor a couple years ago? so who's to say, whether they would be compelled to cough up to the nsa as well.
http://articles.economictimes.indiatimes.com/2013-07-10/news...
So is it by coincidence the products that have the most users are the ones watched by the NSA? Any product/service that will reach such a huge audience will be a target.
Not using the product is not a solution. Getting the NSA to respect the law is what we need.