XKeyscore: NSA program collects 'nearly everything a user does on the internet'
theguardian.com
theguardian.com
I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail?
I was also looking for another unique ID that users are identified by - perhaps a machine or browser fingerprint or some form of intel that can 'glue' different browsers together and make a best guess if they are the same person (Facebook does this with device and user cookies) but couldn't find anything. It seems they rely solely on email addresses, IP addresses, cookies and HTTP headers.
So if you are browsing via 16 tor circuits and a browser that defaults to incognito with session histories being wiped, they couldn't reconstruct your history.
Users of PGP/encryption products being singled out is terrifying. The sooner we have the whole world using decent encryption tools, the better.
Edit: Gmail messages must only be captured when they leave the Google network. They are the only provider to support server-to-server TLS: https://twitter.com/ashk4n/status/346807239002169344/photo/1
They must only be getting a slice of the Facebook chat data, since the transport there is also https.
Facebook Messenger, on the other hand, uses MQTT, so it transmits and stores in plaintext. It has support for encrypted + signed messages with OTR if you are using an alternate client such as Adium or Pidgin.
Really need to go out an audit all of these services and let users know which are better.
httpd > tor node > tor node > tor node > rendezvous point < tor node < tor node < tor node < client
With enough monitoring, the location of the web server (or other hidden service) can just be found out by bombing the hidden service with traffic and seeing what end point lights up with traffic. With fine enough monitoring you wouldn't really need long to find out the real location of the server. It's just not something the network can effectively hide, even if it used chaff (padding) to hide the wheat.There's practical attacks for enumerating hidden service public keys, and so I wager that there's somebody somewhere with a complete map of the real server locations as well.
[1] https://metrics.torproject.org/users.html [2] https://metrics.torproject.org/network.html?graph=relaycount...
The bigger protection is the ease with which the NSA can mount this attack on TOR. I have no doubt that they could do it, however I do question if they can do it on a massive scale.
Think you're getting your entry and exit nodes mixed up there. Tor chooses a small number of entry nodes (entry guards) and attempts to only use those.
So I would think these tools are available only to a select few, and those are more interested in more high-profile tasks like catching extremists or going after political opponents.
I, frankly, don't think SR is that high on government list. Not yet.
Furthermore intelligence agencies are well aware that every action communicates information back to their adversaries. It's a no-brainer to let Silk Road exist if you think doing so gives you the edge on terrorism, or otherwise furthers the national interest.
Once they've revealed that, then people take account of it, and it becomes harder for the NSA to monitor them.
Half of the signals intelligence game is keeping your capabilities secret, so you can keep monitoring the signals, rather than have your target change their game.
That is to say, if they can get into Silk Road, then they probably ARE already monitoring everything that happens on Silk Road, and they'd rather it stay UP so they can keep monitoring the people on it (being very careful never to reveal that they can monitor it), then bust it so the people go elsewhere.
Perhaps you missed the news about PRISM? :)
[0] https://www.facebook.com/blog/blog.php?post=486790652130
Gag warrants existed before PRISM.
EDIT: "National Security Letters"
I think PRISM is just the public-private partnership aspect of this, where they have to go to service providers and install kit, as they can't tap SSL traffic.
So they didn't have access to private messages, they just intercepted internet traffic and relied on it being unencrypted. Facebook didn't always enforce https by default like it does now
Take facebook for example. By default, almost any and all activity on the site is catalogued for you by email -- for your convenience. Someone mentioned you in an update, you get a notification. A friend sent you a private FB message, you can an email notification with the content in line (even with the support of replying to message via email as well).
Now, because email traffic on the internet is not encrypted by default, one is able to piece together the contents of communications just by looking at the email.
Essentially anything that you receive via email (e.g. password reset links; credit card statement summaries etc) is subject to capture and analysis. Given this, it may make sense to perhaps disable (potentially sensitive) email notifications as a workaround around this particular collection method.
It will be interesting to go back through all of those statements with this new information/evidence on hand.
Greenwald has timed this well. He put out enough information early on to give Snowden opponents enough rope with which to hang themselves.
It's an interesting problem for the talking heads: How much will be revealed? They're caught between a rock and a hard place, if they start telling the truth they might reveal something that the leaked docs don't support, but if they tell a lie they might be found out.
This trickle strategy is working very well. The best cause of action for the people under the microscope would be to shut up and if they are compelled to talk to say the absolute minimum but to still tell the truth.
It's like the Socratic method for public/government relations.
The goal seems not just to be exposing the magnitide of this surveillance system, but also the government's systemic disregard for public mandate in the USA right now.
I have to wonder if the staggered deployment of the leak has anything to do with savvy, or more with his own need to digest what he's got as he works through it and reports as he goes.
Either way, the story has more legs than past revelations, so I'm happy for that, and I certainly would love for it to be the case that there is a degree of effective calculation behind the deployment of the info with the goal of keeping the conversation alive and neutering critics. Goodness knows that this story needs all the help it can get. It's up against not only the resources of some of the most powerful governments on the planet, but also the lacking attention spans of their populations combined with relatively disinterested media.
I'm heartened that the noise level has remained so high since the first Guardian article (in this latest series).
Q: Thanks for reporting this. I have to ask though, why is it that you are doling out this information now after the recent congressional inquiry into NSA spying and not earlier?
A: We've published almost two dozen exclusive articles about NSA spying in the last 7 weeks, in multiple different countries around the world. Is that pace not fast enough?
There are thousands upon thousands of documents and they take time to read, process, vet, and report. These are very complex matters. On top of everything else that has to be done with these articles, from explaining, debating and defending them in the media to dealing with the aftermath.
People can accuse us of many things. Not publishing enough or fast enough is hardly one of them.
That House vote was about one specific topic - bulk collection of phone records - that this newest article has nothing to do with. That House vote isn't the be all and end all: it's just one small battle in what I can assure you will be a sustained and ongoing discussion/controversy.
There is a lot more to report still. Accuracy is the number one priority. That takes time.
And some proof: http://www.haaretz.com/news/diplomacy-defense/1.528529
It seems easier for the NSA to tap datacenter <-> datacenter fiber links inside Google's network.
Why worry about decryption when you can have Google's frontend servers do it for you?
This XKS business seems about intercepting non-encrypted traffic as the references to HTTP payload quoted in the article would suggest.
The NSA has clearly tapped trans-oceanic fiber -- why not also tap high-volume inter-datacenter links?
Who says Google has a choice or is even complicit? The backbone providers have mostly stayed mum and it's known that the likes of AT&T split their fiber for the NSA. If we're willing to go to the bottom of the ocean to tap fiber lines it's pretty easy to believe that we'd tap terrestrial lines too.
"They have no direct access to our servers"
I wonder what a beam splitter consists of. Oh. A PRISM.
When one refers to a beamsplitter, it's usually a partially silvered mirror.
http://www.thorlabs.us/newgrouppage9.cfm?objectgroup_id=914
If it's fancy, it might use an evanescent wave to do the coupling, as in some cube beamsplitters.
Beamsplitters for optical fiber are more generally referred to as 'couplers' and involve bringing two fiber cores close enough for a long enough distance that the probability of coupling light from one to the other is the desired amount.
http://www.thorlabs.us/newgrouppage9.cfm?objectgroup_id=374
It is possible to split beams with a birefringent prism, but it is much less common.
http://www.thorlabs.us/newgrouppage9.cfm?objectgroup_id=745 http://www.thorlabs.us/newgrouppage9.cfm?objectgroup_id=917
Disclaimer for the following: I only work with optical fiber couplers occasionally, and not for telecom. Someone who works on telecom fibers daily will be more informed.
In summary, if someone wanted me to tap an optical fiber, I'd call up ThorLabs, get a matching coupler shipped overnight, cut the relevant fiber, slap APC ends on the fiber ends, and jack in. Splitting the beam in free space (outside of a fiber) with a prism is far more errorprone, unstable, and no more efficient. A fiber coupler has no moving parts, can't break, and won't take down a telecom's trunk line if someone breathes on it funny.
If they're actually using a prism, it's because of some sort of impedance/reflection minimization scheme; I can't conjure one that would work better than using simpler techniques though.
Anyway, you're probably right, it's probably just bog standard parts, and PRISM was a buzzword for management.
http://www.guardian.co.uk/technology/blog/2013/jun/19/google...
And I tend to believe him.
We should start lobbying for broader support for server-to-server TLS with perfect forward secrecy. While it alone is not sufficient to prevent the wiretapping of targeted individuals, it still makes fishing expeditions or "Big Data" level surveillance much harder. It would help keeping ordinary users' emails protected on the wire and secure the meta data of PGP emails.
They can use plugins / extensions installed. Fonts installed. If cookies are enabled or not, etc. Check out: https://panopticlick.eff.org/
(That is, unless you visit panopticlick.eff.org, which then sends all of the processed information over the wire in the clear...)
> I can see how they get HTTP information, since they would intercept at transit hubs - but how are they getting all Facebook private messages and Gmail?
I don't know how they're getting GMail(and this is probably a slide from when GMail was accessible via HTTP and not HTTPS), but Facebook chat specifically is done over a non-secure XMPP server. The only 'secure' part of that transaction is login, as far as I remember, once you're past that none of it is encrypted.
But even then gmail is the only webmail service that offers server-to-server encryption, so data can still get intercepted when communicating with someone using yahoo mail or hotmail for example: http://news.cnet.com/8301-13578_3-57590389-38/how-web-mail-p...
You think HTTPS keeps you safe? All it takes is ONE recipient to have an insecure connection and the entire thread is revealed.
Isn't it nice how every email conveniently includes a copy of the entire preceding conversation.
It has become a bit of a pet peeve of mine recently to see self-aggrandizing comments from users around the net about how "we should have known" and "none of this is new."
I'm a practically addicted news junkie (especially tech news) and while I've been aware of a fair amount of what has been exposed in this latest leak, it seems that every day there are revelations new to me, and what is revealed absolutely shocks the conscience. And I'm an outlier. I'm more plugged in to reporting on this subject than 99% of the globe's population, and this subject tangles with the rights and treatment of a large portion of the population of said globe.
The staggering majority had no clue, has no clue, and no, they were never informed. For all intents and purposes, the global media has been asleep or complicit.
It's staggeringly important to keep telling this story at every level specifically because "we" don't know, and still don't.
FYI, it should be "For all intents and purposes". :)
Second: realizing that "we should have known" and "none of this is new" isn't so much about reading news articles and being "plugged in", but rather having an understanding of how the Internet works. To oversimplify greatly, you're essentially playing a very precise game of telephone between around 10-20 different people, and usually about 1-3 different publicly-owned corporations. To be surprised at the possibility of storing packets is somewhat naive considering how simple it is to do.
Funny enough, I wrote a post on this subject matter too before the Snowden leaks where I included the video as well…[1]
[0]: http://techtv.mit.edu/embeds/21783?html5=true&size=full&cust...
[1]: http://blog.pictobar.com/post/47787766458/why-so-silent
The emotions are most likely to be anger and disgust of having their sense of reality shattered, inciting most people who feel powerless to change their habits, to go and protest. And as we all have seen around the world and even within the united states, protests can get pretty hairy, pretty quickly and not in the favor of people who want to live peacefully…
Outside of the issue of inciting the masses to act out physically, there is very little public "mainstream" acknowledgement that corporations are collecting and sharing the same types of data (and more) between one another, where issues surrounding any type of morality become selling points for products. So then the theoretical situation becomes: Government agrees to stop its dragnet programs, non governmental entities will continue to do so as long as people use their services… where's the protest for that (and when that comes they'll hire private contractors to protect them and their interests [remember OWS 2011])?
I posted this a while back on information asymmetry and the surveillance state [0], which lays out simply what is going on now in the minds of people and what is at the core of the issue people are talking about. I also propose an idea about the direction I feel would be more beneficial for the energy to be placed on my post as apposed to the logical conclusion of where all the anger will be placed by people who are now willing to enter the conversation from recent "mainstream" exposure [1].
[0]: https://news.ycombinator.com/item?id=6042241 [1]: http://blog.pictobar.com/post/52533760444/the-nsa-is-closed-...
That being said, I can also imagine how frustrating it must be to be a person who's spent years (maybe decades) worrying about something that's really happening, only to have their concerns dismissed with a wave of the hand or marginalized as "tinfoil hat" conspiracy theories. It's not hard to imagine how that could sour the disposition of even the sunniest person.
They have compeley misused the power we granted them in sacred trust. We should remove it from them at once. If this has become impossible, we need to know that as soon as we can.
Most Americans still believe they have more to lose than to gain by asserting themselves...
Again, I'll chime in as the resident apologist. The people working at Fort Meade are not evil. They truly believe they're doing a great service to the nation. They may be wrong, and they've certainly thrown privacy out the window. But they are following an ideal: national security.
Post 9/11, the nation went on a war footing. We reacted the way we did to the Nazis and the Soviets. And in their search for an existential threat, the intelligence community seized on nuclear terrorism. These analysts live in constant fear of the day they miss a piece of information and New York, Washington, or London is enveloped in a mushroom cloud.
The best explanations for this type of reasoning that I have heard came from an unlikely source, my grandfather. He's a former FBI agent and WWII Navy veteran. In war time, we threw all sorts of civil, economic, and political liberties out the window to defend ourselves. When I asked him how this was allowed to happen, he said simply, "When you're facing an enemy that wants to cross over the hill into the valley where you, your family, and everyone you've ever known or loved lives, you'll do anything to protect them."
Our grandparents grew up with the threat of the Nazis. Our parents faced the prospect of annihilation by the Soviets. We have had the luxury of coming of age in a time where there is no credible threat to our very national and physical existence.
As a result, it's difficult for us to understand the mindset of someone that spends all day, every day, thinking of the most horrible ways we could be attacked, and then trying to devise countermeasures. It's almost inevitable their perspective on the balance between security and privacy is altered.
I'm not saying this reasoning is morally correct or justifiable, especially when applied to the current surveillance programs, but simply that it is understandable.
The key danger is that these efforts are qualitatively distinct from those in previous generations. The difference between extraordinary measures now and then is twofold.
First, our capacity to surveil the citizenry has exploded over the past two decades, and our legal framework is still grappling with that change. The courts are having trouble understanding that a change in scale can be a change in kind.
For example, it's one thing to have the occasional surveillance flight to search for drug operations. It's quite another to have aerostats and quadrotors watching every inch of a city all the time. But the legal rational that there is no right to privacy in public spaces allows both.
Similarly, it's one thing to say the records generated by my water company are business records not subject to the Fourth Amendment, but it's quite another to use that rationale to justify monitoring the location of my cell phone simply because my cellular provider maintains the records.
Second, wars have a point where they end, and the extraordinary measures are supposed to be reversed. That's why the "war on terror" and the "war on drugs" are so dangerous to civil liberties. They essentially extend the extraordinary measures during wartime to police problems that have no logical end.
I agree that we've gone too far as a nation. The fact that these queries don't require FISA orders flat out shocked me, even as a careful observer of these issues. But let's not demonize the individuals. After all, they're only doing what the people demanded after we were attacked. This is a democracy, and immediately after 9/11 such measures were resoundingly approved by the public and our representatives, beginning with the PATRIOT Act.
None of that changes the current reality however. We must slowly learn the lesson the British did when dealing with terrorism. If you treat it as an ordinary police matter, something that will always be present, you deprive it of its power to shock, from which it derives its effectiveness.
The fact is that the war on terror must now end. It's time for a return to normalcy.
Same with the politicians; were they really for it, or simply incredibly afraid of the political suicide that would be the results of standing up against it? Because this was a time when people did not question Bush. From today's perspective on his administration's actions, that seems odd, but it was the reality at the time.
> incredibly afraid of the political suicide
Afraid is not the right word. Aware. When all (public) evidence concerning a law says "fight the terror!" and buildings are still blowing up, you'd have to represent a very interesting district to be "soft on terror".
It was obvious from the length of the act alone that even Congressional staffers couldn't have read it carefully between the time of submission and the time it passed. Quite a few people that I knew were weakly opposed, but the sunset provisions may have made it more palatable.
It takes character to stand up and defend doing nothing when something "must be done".
This is a little off topic, but I always see this trotted out when people talk about big laws (like Obamacare, PATRIOT Act, etc) and it's not really true. Lawmakers usually work with and read a "normal language" version of laws that then gets transformed into a stricter legal version by staffers and experts. They will look at the actual legal version of the law if they care about a specific rule or section, but they usually don't need to.
Of course, I expect my lawmakers to actually read the legal language.
It's important too to note that this isn't a "big law" or even an American thing. Virtually all bills of any substance work this way and it's pretty much standard practice in most countries.
That being said, I'm not defending the PATRIOT Act. I just think the argument that not enough people read it is weak, especially considering all the real arguments you can make that actually attack the substance of the act.
The point is that for all lawmakers, there is both a need and sworn obligation, in addition to national expectation, that they read all the nitty gritty legal language they are voting on, by which all Americans are bound to abide.
That's what lawmakers are there for--to know what in the hell they are passing as laws. If they can't be bothered to do their job--which, at the national level, goes far beyond just securing corn subsidies, because they're voting on legislation that touches on all Americans--then fuck 'em. Throw the bastards out on their asses, and send them back to the cornfields.
To be clear, the "hawk" politicians (and let's be honest, -many on the left) believed in the legislation but also exploited the tragedy to ram it through and neutered the ability of the other side to have a reasoned debate.
Our population was attacked, angry, and for the most part followed the lead of politicians who said we needed these laws to fight the people that attacked us.
In the aftermath, the scrutiny on the part of the American people never materialized. You're basically witnessing the moment where the most scrutiny on these types of programs/laws has ever occurred since 9/11. Worth keeping in mind that many components of these surveillance programs also predate 9/11.
Only 66 Representatives voted against it--62 Democrats, 3 Republicans, 1 Independent. Only 1 Democratic Senator voted against it, while another Democrat abstained from the vote.
At the time the Act passed, Americans were in the midst of a fear frenzy. It was a pervasive culture of fear and panic, the likes of which I can only compare to anti-Soviet fears of the Cold War. People all over the country actually went to stores to buy all kinds of emergency and survival supplies to build up their own anti-terror kits (I forget the name for this that was popular at the time).
Many of us questioned Bush from the moment he was declared the winner of the 2000 election by the Supreme Court. We took part in protests all over the country after 9/11 to oppose the buildup to war in Iraq. I took part in protests in D.C. It was all ineffectual. Fear gripped the country and few paused to consider the long-term ramifications of the actions taken in September's wake.
Demonizing people and falsely assigning ill-intent doesn't help us address and correct the problem, even if it feels good to do so. I personally have to fight the urge constantly myself because I feel so strongly in the immorality of the net output of the programs themselves.
GHW Bush
GW Bush
D Cheney
D Rumsfeld
C Rice
G Clapper
G Alexander
P Wolfowitz
These are the guys that created the orders that the soldiers are following, and the war they are dying in for these criminal's profits.
The people I listed have a decades long history which brought them to the US Coup of 9/11: Cheney in particular.
The above are at the core of PNAC, the CIAs takeover of the executive branch (both Clinton and Obama are their puppets here)
GHW Bush has been running shit since the 70s.
Cheney setup the framework for the current MIC exploitation of the world when he was in Sec. Defense position in the early 90s - then setup Halliburton to be in the position to receive all the mandated private-sector contracts so the military could focus on its "core" -- the same with the Carlyle group.
(Carlyle owned CRG West (MAE WEST) and other fiber infra and DCs)
These guys worked diligently to put all this into place. Obama is just a puppet who was meant to quell the outrage that the Bush regime was bringing.
I posted a list of the key players in this, I did not post any party affiliation....
I can provide a hell of a lot more detail than this too - going back to 1920 with these guys...
You're wading far too deeply into conspiracy territory to suggest that this puppet 'was meant to quell' anything. He is a leader whose administration stands and falls on its own merits.
There is no party but the MIC party - and clearly, the NSA owns that party.
America has died, completely, 100%. There is no such thing as "Land of the Free, Home of the Brave"
The IC isn't running the government. They've got their hands full just running themselves.
The idea that we are not free is absurd. If I want to hold a rally for the Ku Klux Klan, that activity will be protected by the full force and power of the United States government. I can worship as I wish, read the books I choose, and write whatever I want (excepting direct threats of violence) with little fear, knowing that laws and courts stand ready to vindicate my rights.
I would take our extensive package of rights over single party political control, strongman leadership, civil law jurisdictions, and common law libel standards any day.
We are certainly no longer the most free nation on the planet, which saddens me deeply. But we are certainly amongst the best on that metric.
You're clearly being partisan.
The American people overwhelmingly approved the Patriot Act, and the idea of surveillance, and the war on terror, and the actual wars on place.
The Obama administration resumed surveillance programs which had been previously shut down.
The military industrial complex has been growing steadily larger since the 1950s.
Congress people from both parties repeatedly approve the growth of the defense budget, and especially parts which gain them money and jobs for their own states and districts.
There are certainly people to demonize, but sorting them out from the well intentioned would be incredibly complicated.
That isn't really a strong argument. Firstly, their actions is supposed to reflect the ideology of the US citizens in general. If it doesn't, either they are not being administered as well as they should be or they are purposefully ignoring the will of the citizens. Secondly, the idea that because they truly believe that they are doing great service doesn't actually justify any of the actions. If we are forgoing the label of evil because they think that they are doing great work (and I am OK will that, I hate the label 'evil'. It is unconditionally partisan) then it does question whether Nazis/Soviet union deserved the label as well. Because I fear that they too believed in their actions.
> our legal framework is still grappling with that change
US legal framework does not seem to be struggling (I am not a native speaker, so I am assuming that is what you meant). It has expanded the power to monitor and interfere knowingly and willfully. Let's not blame this on misunderstanding or incompetence. While it is the first thing that this should attribute to, the people who have built this system seem highly skillful and knowledgeable. If you claim that decision makers do not understand the new world that has suddenly bubbled up, well it's your responsibility and that of the NSA employees who seem to be following orders without questioning, to either make them understand or replace them. And in all fairness, US voters did. The man even won a Nobel Peace Prize for some reason I cannot understand. But his actions behind the doors seem totally contrary to what his words have been in past. Not really the fault of the voters but it definitely raises questions if he truly understood the costs and still took the leap.
[Edit: grammar]
I think this is a very difficult question to answer. If you're a lowly NSA tech tasked with something seemingly mundane (say, writing some automated tool to be used by an internal billing dept), at what point do you refuse to contribute to an organization that may be operating against the will of the people? Who is responsible?
Evil doesn't require intent. Some of the most evil acts in history were carried out by people who believed they were doing a good and moral thing. Most evil people don't go around thinking "I'm going to be so evil today!"
I suspect you are correct and that the vast majority of NSA employees think they are doing the right thing for America. That doesn't make their actions any less evil.
I don't want to Godwin the discussion here, but it's not at all rare for people to act in an evil (or whatever you want to call it -- bad, harmful) way while not recognizing their own actions as evil.
That people don't think their actions are evil doesn't prove that their actions aren't evil.
Add to that, evil acts are almost always done in service of an ideal. For example the USA has economically and socially gutted many nations by force in service of the democratic/free-market ideal. Yet it's rare to find an American who sees it this way. US-USSR proxy wars in the Middle East and Latin America from the 60s-90s weren't destructive, we were just trying to help those countries out. We wanted to modernize them, to improve their lives, not to destroy them. They were just too uncivilized, too barbaric to get it. Why would they hate us for that?
Hence 'ideology'. Easy to serve, hard to view objectively when you've spent a lifetime on the inside.
>We have had the luxury of coming of age in a time where there is no credible threat to our very national and physical existence.
The Berlin wall didn't fall until 1989. The Soviet Union didn't dissolve until 1991. The period of 1991-2001 was spent fighting proxy wars in former USSR terrories or allies [1]. Iraq. The Yugoslav Wars in Bosnia, Macedonia, Kosovo. Haiti. All of this was an extension of the cold war. The Red threat didn't officially end until 09/11/01, Communism continued to be a spectre held over the head of the American public. It's just the discourse shifted from "the USSR has bombs that can kill us right now" to "Communism is bad therefore we're preventing it from spreading". The constancy of threat and surety of the potential for complete annihilation was always there.
And of course, from 2001 on everyone spent all day, every day thinking of the most horrible ways they could be attacked by terrorists. With great encouragement by media and government apparatuses.
>But let's not demonize the individuals. After all, they're only doing what the people demanded after we were attacked.
Again avoiding Godwinning, but to a certain extent you must demonize the individuals. Else there is no incentive for people to be vigilant of runaway ideology, like the US is operating under currently. Else there is no incentive for individuals to formulate a moral compass external to the state, because why bother when "they told me to do it" is a legitimate excuse? The state idology becomes your morality. After all, you're just tryin' to put food on your family.
[1] - https://en.wikipedia.org/wiki/Timeline_of_United_States_mili...
Certainly not. The issue is not their beliefs, but rather the reasoning behind them. Different experiences of the world give rise to different world views. The world view of those that operate, condone, and approve the surveillance arises from a set of historical understandings and modern experiences that neither you nor I share.
To suggest that the scare tactics of CNN and the like is comparable to the psychological effect upon an ordinary analyst of regular intelligence reports of weapons-grade uranium being smuggled out of Russia via Kazakhstan is naive at best.
The threat of true national annihilation, not a specter concocted by a manipulative elite, has been the norm rather than the exception throughout history.
Modern totalitarianism has its roots in a not too distant past in which totalitarianism was the surest defense against large armed groups of humans that would burn your fields, kill your family, and subjugate your people.
That threat didn't disappear until very recent times. The cultural history of the American people is replete with threats to our existence: the CCCP and Warsaw Pact, the Axis, the German Empire, Spanish colonial North American empires, the British Empire, the Quadruple Alliance, the Normans. The intelligence community takes it's cues from a long history of existential threats.
What seems so obvious to us is that the current world is stable, and thus extraordinary measures to protect our safety aren't justified. Those charged with national security take a longer view. They see our nation as balanced on a knife's edge between internal strife and external threats. And thus, threats to either must be vigilant observed, documented, and understood, so that if the time should come when a conflict does occur, we stand prepared.
That line of reasoning is often alien to privacy advocates. I neither endorse it nor deny it. I simply acknowledge that those who study, train, and practice for our defense are not naive when it comes to the risk of violating civilian privacy. They simply set a different value to each of the variables in the risk-reward equation. You may disagree with those values, but it is important to understand them. Blindly denouncing such views as morally bankrupt simply factually incorrect.
> The Berlin wall didn't fall until 1989. The Soviet Union didn't dissolve until 1991. The period of 1991-2001 was spent fighting proxy wars in former USSR terrories or allies [1]. Iraq. The Yugoslav Wars in Bosnia, Macedonia, Kosovo. Haiti. All of this was an extension of the cold war.
The wars you cited were in no way related to the Cold War. Yugoslavia was a strategically unimportant area, relevant to no one in the geopolitical sphere.
The intervention occurred as a direct result of ethnic cleansing that was taking place in obvious, organized, and deliberate fashion. To suggest otherwise is simply incorrect. I've spoken with the head of UNPROFOR from the Srebrenica Massacre. It was a war crime on par with the worst parts of World War II. Clinton himself stated that his reluctance to intervene was based upon the "ancient ethnic hatreds" argument of Balkan Ghosts. The Yugoslavian intervention was about genocide. As a simple fact, it had nothing to do with the Cold War.
> Communism continued to be a spectre held over the head of the American public. It's just the discourse shifted from "the USSR has bombs that can kill us right now" to "Communism is bad therefore we're preventing it from spreading".
Containment of communism was simply not a factor during the nineties. Moscow was crushed, the former Soviet block in shambles, and Russian interests retreating from throughout the world. Hence the remarkable cooperation on nuclear arms, energy policy, and democratization between the Yeltsin administration and the Clinton administration.
>I don't want to Godwin the discussion here... Again avoiding Godwinning...
I believe the Romans had a term for emphasis by pretended omission.
> to a certain extent you must demonize the individuals. Else there is no incentive for people to be vigilant of runaway ideology, like the US is operating under currently. Else there is no incentive for individuals to formulate a moral compass external to the state, because why bother when "they told me to do it" is a legitimate excuse? The state idology becomes your morality. After all, you're just tryin' to put food on your family.
In a totalitarian state, this argument would indeed hold water. However, you gloss over the most significant part of the counterargument. We didn't simply allow extraordinary efforts against terrorism, the people of the United States overwhelming endorsed it.
A democracy is beholden to its people. Its morality is, by definition, derived from the consent of the governed as expressed through the democratic process. Vox populi, vox dei, as it were. To point fingers at talented and intelligent programmers, people with whom we would be excellent allies and friends in other circumstances, excuses the true culprits: us.
We are to blame for this leviathan. Not the NSA, not Obama, not Bush, not the DNI, DIA, CIA, FBI, or any other amorphous acronym.
We need to understand the reasoning of the those that built these programs, not simply dismiss them as callous power hungry sociopaths. We need to grasp the history that informed their reasoning, both recent and that which began far before that day in September.
Most importantly, we need to remember that blaming individuals does nothing to prevent the true failure, a systematic disregard for the right to privacy and the guarantees thereof provided by the Constitution.
"War is peace. Freedom is slavery. Ignorance is strength."
Orwell in 1984: "Part of the reason for this was that in the past no government had the power to keep its citizens under constant surveillance. The invention of print, however, made it easier to manipulate public opinion, and the film and the radio carried the process further. With the development of television, and the technical advance which made it possible to receive and transmit simultaneously on the same instrument, private life came to an end. Every citizen, or at least every citizen important enough to be worth watching, could be kept for twenty four hours a day under the eyes of the police and in the sound of official propaganda.")
It's a surprisingly interesting novel.
I have a tremendous amount of respect for those in the security services, who have been given a rather difficult job to do, and who seem (from the vanishingly small amount that I know) to be approaching it in a professional and objective manner.
I have no desire to be nasty, and if I have personally offended anybody by what I have written, I most profoundly apologize for the hurt.
However.
This is an important issue, and it deserves public attention and a detailed debate. I hope that some of my provocative wailing and doom-mongering has done what was intended: provoked some thought and consideration.
This is, after all, politics, and, as I have mentioned before, we sometimes need to make a caricature out of our own positions in order to make a point. Omlettes and eggs and all that.
You are nuts if you think that that was acceptable given the circumstances.
Just doing my job is not sufficient in jobs such as these.
I understand Nazi concentration camps. It was a manipulation of nationalist sentiment against an imagined internal enemy, conveniently one that could be dispossessed of a great deal of property, coupled with a never before seen combination of the pure survivalist id meeting modern state capitalism.
I understand United States concentration camps. While we certainly didn't starve, gas, or force Japanese, German, and Italian Americans, we did relocate large numbers of them to temporary camp facilities for the duration of the war. It was believed that recent immigrants and their children might harbor loyalty to extremely dangerous enemies and could serve as a fifth column in the event of an invasion. For what it's worth, despite the indignity and suspect constitutionality, that's a far cry better than most nations have acted in similar circumstances.
Both of those events are understandable, in that I can understand the thinking of the people involved. It does not mean I morally condone it. What I'm attempting to combat is the notion that all acts with which one disagrees must be the result of moral bankruptcy or internal failing.
Usually there is a logic, however skewed, behind even the most heinous events in human history. The first step to preventing those events is to understand that logic. Only then can we address the root causes of the problems we wish to solve.
In this case, I'm suggesting that the root cause was a panicked citizenry seeking shelter from a very real threat, not a government seeking to blindly expand its power. That's an unpopular opinion, but alternative interpretations lead to different actions.
These are exactly the kinds of comments I'm talking about. The preponderance of people affected by this program on the globe (a staggering amount if you will) had no knowledge of this because the media failed, and are not, in fact, technically savvy on any level and don't understand, at all how the internet works in relation to the technologies employed by these programs.
>To be surprised at the possibility of storing packets is somewhat naive considering how simple it is to do.
For the vast majority of the potential consumers of this knowledge, this just simply is not the case. At all. They aren't being naive. This is highly technical to them and severely under-reported, and where it was reported it was not explained terribly well, nor was there meaningful conversation surrounding the reporting's aftermath.
But congratulations, rmrfrmrf, on being one of the select few that are not naive. We need to get you some sort of prize.
Of course at least the mainstream media (MSM) failed. Why? It's a very old story, rock solid in the media: An MSM media company is in business to make money. They have some old techniques for doing so. Their main technique is to get eyeballs for ad revenue; for that their main technique is to grab people by the heart, gut, and below the belt, always below the shoulders, never between the ears; the content is essentially only light entertainment following the framework of the ancient Greeks we now call formula fiction; the content is nearly never the information needed by an "informed citizenry".
The best hope for the information citizens need is Web sites on the Internet and search engines that can help people find that information.
If you feel that the outrage is in fact without merit, then attack that on logical/rational grounds, not by appealing to social proof.
This is staggering, and to chide others for being staggered is the worst kind of truculence.
More relevant, and useful: What are we going to collectively do about it now that we know, beyond a doubt, what exactly is happening?
It is, however, VERY easy not to have been able to have that foresight, and I think that the insights people were expecting the government to have been constrained by the fact that all the information of value is collected by neutral third parties. Google, Yahoo, Twitter, etc., aren't likely colluders with the government.
Plus, at the time of the PATRIOT Act's passage, there wasn't quite as much information being put on social media, or out to the public in general. Not as much was online, digital, or otherwise easily indexable.
There were those predicting this sort of possibility before the PATRIOT Act's enactment, and since, to be sure, but you shouldn't feel responsible for not having seen the signs yourself, or for having heeded the words of what probably seemed like kooky overreactionaries from back in the day.
The funniest part about this, to me, is that somewhere, very quietly, Richard Stallman is quietly telling us all the he told us so, and he's absolutely right, and always has been. Neverminding that, he's largely seen as a crazy old paranoiac who we should respect for his IT knowledge, while having to forgive the rest of his eccentricities.
Aside from that, I didn't mean to seriously suggest that he's out there passing judgement on us so much as I was attempting to acknowledge how hypocritical we are for having disregarded his message because of his eccentricities. I think your statement, that he should actively try to be more popular for us to care, is further proof of how wrong we are to be that way.
In an ideal world, your response would have made a perfect satire of how Americans are likely to react in the face of the responsible elder telling us to eat our proverbial vegetables. That is isn't saddens me.
Think about that for a minute, and then explain to me why that makes more sense.
You're in the bizarre position of criticizing him for being right. You're expecting Stallman to figure out a way to market to you, rather than expecting yourself to figure out how to evaluate arguments and evidence rationally. Think about that for a minute, and then explain to me why that wouldn't make more sense.
Where our expectations start to misalign is the part where he's been ignored because he doesn't know how to be a consummate human being (let alone marketer), and you say it's everyone else's fault. Idealism is fucking useless.
More like a news sheep. The mass market news is and has always been 49% fluff and 49% lies.
Comments from people who already knew what the NSA does are not "self aggrandizing". The are other-insulting. You should rightly be ashamed that you walk through life in a news fog of up-to-the-minute minutiae. Read books by retired insiders, talk to current insiders and contractors. That's the only way you will learn anything about anything. To wait for the newsmen to do it for you is to sign your mind over to tampon salesmen.
The NSA story is staggeringly unimportant. Every government, many companies, and rather a lot of organized criminals run intel and counterintel operations. It is just a fact of life, like antibiotics and highway construction. It is inevitable that there must be a national American signals intelligence organization.
What os staggetingly important is why the NSA alone, out of all the spy organizations, is being singled out for a comprehensive media war. The most likely explanation is that the Democratic Party needed something to distract from its pecadillos. The next most likely explanation is that a foreign government is getting themselves some payback. In any event, if you care about this non-news, you are just another mindless pawn.
1. Downvoted to oblivion by a hivemind, and
2. Somebody like you chimes in with a content-free emotional outburst.
So exactly what did I misunderstand?
The incontrovertible fact that this really isn't news?
The fact that every history and exposé on the NSA has been saying this for decades?
The fact that the NSA tried cramming the Clipper chip and key length restrictions down our throats to make domestic spying easier? For half a decade this was a weekly running joke on Slashdot that you had to have been living under a rock to miss.
That the previous commenter claimed to be a "news junky" and then admitted that by news he means the mass media—a pack of tampon salesmen and political hatchetmen.
Absolutely nowhere did I say, or even begin to imply that. In fact, I explicitly called out the mainstream media for being complicit and/or not reporting on this issue while indicating that much of what is being reported was already known to me. Not only did I NOT say that I get my news from the mainstream media, the implication was, if anything, that I did not. The mainstream media is about the last place I'd look for competent coverage of this issue.
You're terrible at reading comprehension. Terrible. You make a lot of assumptions, all of them wrong, then proceed to insult other people based off your incorrect assumptions.
Additionally, the only thing incontrovertible is that this is news to the vast, vast majority of people who are affected by these programs. Those are the real numbers. But I know you. You're part of the Pedestal Crowd furiously patting themselves on the back. Good for you Danny. Atta boy.
I agree that "know" is a bit too glorifying. I propose "suspected".
I don't find this surprising at all. Practically 99.99% of a normal user's Internet activity is centered on Facebook, Google (including Gmail) and a handful of other sites. The amount of data everyone is requiring in order to provide a service also includes pretty much anything you need in order to track someone.
It's not news you need to pay attention to but some of the more theoretical aspects of networking in a second-year course.
Ultimately, whether they intend to or not, such statements end up making other people who are hearing about this for the first time more complacent about it because they come into the comments and see a bunch of people going on about how it's nothing new and therefore the new information is no big deal.
A good theory, as I have an extremely difficult time imagining anyone in an activist (non-complacent) stance on this issue ever reacting like that to these revelations.
Then back at HQ, can send the node what are essentially 'filters' to return 'alerts' and the associated content.
So, point: As a system, it's quite obvious. As software, it's quite routine.
And, from their description of working with anomalies, they are being just intuitive and elementary and not at all advanced or powerful.
It would appear that a terrorist Internet user could do fairly well beating that system by using a proxy server also used by many other Internet users and also using a lot of strong encryption -- PGP used well might be strong enough.
See? No "direct access!" Google/FB/Apple's statements, totally reassuring.
I'm glad that people are paying attention, but especially early on, it wasn't entirely clear that Snowden's leaks were substantially different from the leaks that have been coming out of the NSA for years that never got traction in the media.
There is good independent media that has been covering the story for years though. Here's a Democracy Now story from February 2005:
http://www.democracynow.org/2005/2/10/no_place_to_hide_award...
Democracy Now has an incredible archive on this subject too. Right now it starts here:
http://www.democracynow.org/topics/nsa/7
Specifically, they've done some great interviews with previous whistleblowers:
http://www.democracynow.org/appearances/william_binney http://www.democracynow.org/appearances/russell_tice http://www.democracynow.org/appearances/thomas_drake http://www.democracynow.org/appearances/jesselyn_radack
Other interesting guests:
http://www.democracynow.org/appearances/jacob_appelbaum http://www.democracynow.org/appearances/laura_poitras http://www.democracynow.org/appearances/james_bamford
And the purpose of Tor might be different than you imagine:
https://www.torproject.org/docs/faq.html.en#WhatIsTor
Or are you just trying to discredit Appelbaum, Assange, and/or Wikileaks?
Also, is that your article? Should you disclose that? And is there any reason you linked to it rather than the original New Yorker article here:
http://www.newyorker.com/reporting/2010/06/07/100607fa_fact_...
I was shocked by having this laid out as well but I really did just assume this was probably going on. It was technically possible, it was politically possible and it was financially possible. If I shared the worldview of the people doing this and been in the position to do this, I would have been itching to start this level of collection and data mining.
I will admit to part of it being satisfaction at no longer getting the "oh put your tinfoil hat away, no one would do that" response whenever it came up, which was always based solely on the old "I don't like the implications of this being true therefore it can't be" argument. It's also relief that there is finally a discussion about a subject that was previously only seriously discussed by a small number of people.
I take your point that the I-told-you-so gloating isn't helpful and doesn't reflect well on those who do it but I disagree that that was ever meant to discourage discussion, if anything it was anger at the fact this discussion has taken so long to occur.
If you're waiting for someone like Snowden to come along and spoon-feed you all the ways the government can screw you, you're doing things completely wrong. Oversight requires foresight.
https://www.grc.com/securitynow.htm
Briefly summarized, the only way to do secure mail is pgp, the only way to do secure chat is to avoid all the main chat networks. And microsoft actively designs their systems to be easier to access for the NSA (far beyond their legal obligation) so you may assume that any microsoft product is a direct line to the NSA.
Even Gmail HTTPS use is somewhat recent and not original to the product.
Further, one might combine this with reporting about initiatives to gain company SSL/TLS private keys, account passwords, and the like, in some interesting speculation -- if speculation it remains.
Amongst all the rest, I would point readers towards browser fingerprinting. It's difficult for me to imagine they are not using it.
If the public is going to have some degree of counter-measures, this will include browser and other client software becoming more pro-active about anonymizing its own profile / usage profile. For one thing, stop sending highly unique fingerprint data such as font listings to every Tom, Dick, and Harry. Just one thing amongst many...
It was reported earlier that the NSA has installed hardware at their "partner" companies. As you certainly remember from the slides, they are: Facebook, Google, Microsoft/Skype, AOL, Paltalk, ...
Somewhere there is an architectural diagram of these systems that describes how to make people check checkboxes before releasing information. CYA-oriented programming that has clearly driven the entire design of this thing.
I didn't see that in the article. Do you have a citation?
Slide 16: "Show me all PGP usage in Iran"
Moreover, the technological trend is clear; and the avenues for sharing intimate personal information proliferate and multiply with every passing month. The debate therefore needs to shift. The question cannot be over whether the state should have access to this information. We are powerless to push on that point.
The question has to be this: Given that our state (and others) will necessarily know the most intimate details of our lives, how do we want it to behave? How do we want this information to be used? What do we want the newly intimate relationship between individual and state to look and feel like? It may well be that we come to a startling different conclusion than our initial starting points might presuppose.
There are tremendous social benefits to be had by using this treasure-trove of information wisely, just as there are tremendous dangers to be risked by using this trove with carelessness or malicious intent. However, we need to think very carefully about how we manage the relationship between individual and state; how we manage the relationship between individual and peer; and how we manage the relationship between individual and technology.
I feel strongly that this is the most important debate of our generation; perhaps the most important debate to be had in this new millennium.
* Industrial espionage -- it's big business, and I'm sure it pays better than being an NSA analyst.
* Foreign espionage -- since this gives unlimited querying power to every agent, a single "turned" agent could inflict massive damage on U.S. government and industry interests on behalf of a foreign power. The potential for double agents is huge.
* False positives and guilt by association -- being flagged as a "person of interest" and then essentially persecuted because you have fringe ideological interests, are looking up a lot of info on terrorism for a book project, have a friend who knows radical Muslims, etc.
* Corrupt use in political campaigns by incumbent politicians with access -- obvious.
* Blackmail and other corruption.
* Use by government agencies with access to spy on other agencies.
... I'm sure creative people can think of more.
The "nothing to hide" trope seems to me to be entirely based on a false dichotomy that contrasts "nothing to hide" with "unpatriotic/criminal". I think this is primarily because people lack the imagination to consider the other seedier and more lucrative uses of surveillance.
If they were confronted with these other possibilities, would your acquaintances change their thinking? Or do these other risks--for example, the risk of having an employer targeted by competitors unfairly (potentially leading to layoffs), or the risk of having a representative vote against the interests of his or her district because of blackmail (potentially leading to a loss of government services and investment)--simply not resonate?
According to a New Zealand whistleblower back in the 90s, this was one of the main purposes of the Echelon network. Imagine what happens when your larger competitor gets in bed with the NSA. According to whistleblower Russ Tice, the Bush NSA was able to request intercepts on Senator Obama, so there certainly could be enough corruption for back room deals to occur for your startup's private information.
This is yet another reason to encrypt your git traffic.
People need to look at this long term and realise that abuses of power will continue to intrude larger and larger sets of the population unless they are stopped now.
I would also like to add /family/ as a huge pressure point, akin to your guilt by association.
IOW, one may have nothing to hide, but their family member does and one can be controlled by threats to that family member. It's disgusting and insidious, but that's how bad, scared and dangerous people operate. We are not using our intelligence if we allow ourselves to be vulnerable in this way.
The whole of your life may be innocent, but a single interaction (searched for porn? vented about someone in a private conversation?) taken out of context can almost certainly destroy you.
We need to wake up, your post would help a lot.
Privacy is important. But vastly more important is unaccountable power.
But that has never happened and probably never will. Nixon was caught quickly. Besides, that wouldn't even affect me, only people who do bad things or are in positions of political power.
There's a staggering lack of basic competance around protecting this stuff. The CIA director who lost his job over Aimes must be wondering what the modern mob have to do to get fired.
Using the Facebook Graph API, we can gather information based on this ID: http://graph.facebook.com/1536051595
Which leads us to the Facebook profile (https://www.facebook.com/arash.gorjipour.5) of an individual, real or contrived, named "Arash Gorjipour". His email address and phone number are all exposed in one of his uploaded photos: http://i.imgur.com/0UUk5cB.jpg
I wonder what the reason for this man being in these slides is.
I suspect, or maybe just hope, that politicians are protected in some way from this. While it is unfair, at least it would mean less opportunities to extort or threaten lawmakers. Though, obviously, it would be best if we ALL were safe from that kind of crud.
If I were putting together a deck on that system I'd also probably favor test data over live data, if for no other reason than it's easy to come by.
You could say 153xxxxxxx and "Arxxx Goxxxxxxx" just to be sure and if you need to post links you could use a URL shortener.
I'm a little worried now because I visited his page, and this will surely be logged, hence my past online activities may now be investigated.
HN fields roughly 200,000 unique visitors each day, most of which have a markedly anti-gov't-spying slant[1], that's enough evidence to be in their cross-hairs.
[1]: Such that in some capacity you might participate in the creation/promotion of methods or software to get around their snooping technologies.
Oh bum..
http://www.theguardian.com/world/interactive/2013/jul/31/nsa...
He's (almost certainly) a real person, by the way. I called his office. He wasn't in, but they offered to page him for me.
Foreignness factor:
The person has stated that he is located outside the U.S.
Human intelligence source indicates person is located outside the U.s.
The person is a user of storage media seized outside the U.s.
Foreign govt indicates that the person is located outside the U.s.
Phone number country code indicates the person is located outside the U.s.
Phone number is registered in a country other than the U.S.
SIGINT reporting confirms person is located outside the U.S.
Open source information indicates person is located outside the U.s.
Network, machine or tech info indicates person is located outside the U.s.
In direct contact w/ tgt overseas no info to show proposed tgt in U.S.
It's quite easy to lose the protections of a U.S. citizen indeed!
Interesting, so everyone who ever hit a MegaUpload link is potentially a foreign entity?
For instance, need data from a server's hard drive? Accuse someone you know who has data on that server, not necessarily the data you want, to have an excuse to seize said hard drive and analyze it. Nope, turns out the accusation was incorrect, here's the hard drive back. Ah, is getting other data not covered by the warrant illegal? It just might be, but you can't complain if you don't know they did it and you probably don't have standing to sue over it to find out. Plus with authorities able to get double-secret warrants based on triple-super-secret laws issued by not-so-secret courts with "you can't even admit you were here" secret proceedings, how would anyone know in the first place?
Remember, government agents have the authority to lie to you in an effort to complete their goals.
Not that I'm saying the NSA was behind MegaUpload or anything, just saying it's feasible.
Just to be clear, Kim Dotcom was a NZ resident, and had broken no NZ laws.
At this point it would be a bold man who made the claim that the NSA had nothing to do with investigating a foreign person and/or their company, tracking that company's international internet usage, monitoring their involvement in possible illegal activities and providing that information to US authorities who could use it to reach out across the world and attempt to have that person extradited to the US.
In fact, I cannot understand for a second why you are trying to make that claim?
That, coupled with the fact that they only require 51% certainty in the foreignness factor makes me think this is intentionally designed to make every single person they come across a subject to surveillance.
I can see Weasel terms like "use of storage media seized outside of the U.s." be extended to mean pretty much anything.
That then provides an audit trail, where something, or more likely, nothing is done to check that decision was valid,.
What we need is strict limitations on what can and should be collected, and how it's used, plus better methods of securing what's being exchanged. For example, sending email as plain-text, leaving it on the server as plain-text, maybe that's a bad idea.
The NSA isn't necessarily the only reason you'd do this. Foreign governments are going to take an interest in this, too, and it's only a matter of time before someone gets access the data the NSA is hoarding. No program of this scale is ever 100% secure.
This is very important. What do you mean by "crackpot"?
* Reading the web via email only
* Using completely free software and hardware (which as far as I can tell, limits you to a very small subset of Linux on a single Chinese-made netbook)
* Not carrying a cellphone
* Not using any social networks.
Stallman's principled stand is admirable, but untenable for most. I need to violate every single one of these tenets in an average day at work.
And that's before we even enter the realm of entertainment, which is even worse as far as the FSF's definition of freedom goes.
Over unity energy generation from the vacuum is rightly labeled as 'crackpot' imo, Stallman's position, while extreme should (again, imo) not be labeled as such.
Calling proprietary software evil is an opinion, and there are plenty of examples of evidence that proprietary software was created in ways that one could label as evil. Give it a while and there might be some revelation which will cause lots of people to go 'oh, that Stallman was such a visionary, calling proprietary software evil'.
Now on this particular aspect of Stallman's reasoning I find him hard to follow because that would mean a whole class of something is bad whereas I believe it should only apply to instances on a case-by-case basis. But I'm going to hedge my bets here and sit it out for the next decade or two (assuming I have that much time remaining) to see if he might not be on to something again that is still hard to see from where we are standing right now.
One way in which this could play out is that in order to avoid certain societal fates is to have nothing but open source for certain classes of application (for instance, voting computers, software in use by the government in general or software that is used to power network infrastructure).
Don't be too quick to judge, Stallman has been right more often than I'm comfortable with on some of his most 'extreme' views.
He's not the only one that's been crowing about electronic surveillance. Ever since things like Carnivore (http://en.wikipedia.org/wiki/Carnivore_(software)) were uncovered in the 1990s, it's been obvious that there's a lot going on we will never be fully informed about, that the internet is no longer a safe playground devoid of malevolent actors. Mailing lists and USENET groups at the same period of time were constantly aflame with these sorts of issues.
If you can cite an occasion where Stallman has had a unique insight into the situation, I'd be surprised.
Stallman, for all his posturing and relentless drum beating, which is at least admirable from the point of dedication, is still no Alan Kay, Marvin Minsky, Marshall McLuhan or Raymond Kurzweil.
In the real world, that shows a distressing lack of critical thinking and a further distressing abundance of dogmatism.
"Proprietary software is bad" -- Subjective value judgement.
"Properitary software is evil" -- Subjective value judgement that shows a lack of thought.
"You should always use free software wherever possible." -- Subjective value judgement.
"You should use absolutely nothing but free software ever" -- Subjective value judgement that shows a lack of thought.
I mean, the FSF "disapproves" of software that is completely free on its own (Fedora, Firefox), merely because they point out nonfree things you can use. (Fedora's firmware bundles and some repos, and Firefox's addons site).
That's completely idiotic. Apparently the FSF's "freedoms" do not include the freedom to run whatever software you choose if it's "unfree".
Guess what the solution to the proprietary software problem is? Not using or promoting proprietary software or platforms that enable it.
You are getting upset that the Free Software Foundation has standards to be met to consider software as "free". To dismiss their agenda as existing in 'crackpot' territory is invalidating a legitimate argument to support your shaky conclusion.
Then it seems that crackpottery is a term that may be removed in retrospect. I'm sure at some point in the future someone will crack the energy from the vacuum riddle, who knows.
* The FSF uses computers other than Yeeloongs. The FSF also doesn't really care about free hardware. The Yeeloong has chips with non-free firmware burnt in, and the FSF doesn't care because that isn't software. It's the Free SOFTWARE Foundation, after all.
* Stallman is on a few social networks, notably identica @rms@identi.ca (possibly now defunct). He probably has a GNU Social endpoint.
I think you're conflating Stallman's willingness to be uncompromising in his own lifestyle with his calls for reform. Stallman is fairly intelligent and understands that not everyone can live like he does, but I suppose he feels the need to answer the question of "what should you do in the present beyond push for reform."
I also don't know what "entertainment" you're talking about. The FSF is against proprietary video game engines, but their mission pertains to software, not music/movies/etc.. They campaign against DRM because DRM requires non-free software to enforce.
Surely you can't expect people to take this argument seriously. It's easy to get internet access on the go in much of the world already.
It's easy to get Internet access on the go in most of the places I've been to, but I've been to a tiny fraction of the places RMS has been to.
Suggesting that people abandon social networks, never own cellular phones, avoid using the web almost entirely, these are extreme positions. What makes them crazy is when he's an advocate that everyone should follow these edicts.
Surely it's some kind of "geek social fallacy" that's being applied here. Stallman has come up with what he perceives as the optimal strategy and anyone who diverges from this is doing it incorrectly, just as how free, open-source software is the only kind of software that's acceptable, and everything else is "evil".
Not really. At that point, you are just using the term as an ad hominem in a childish attempt to ward off cognitive dissonance.
You don't win an argument by calling the other guy a weirdo.
I think Stallman's observations are valid, but his method of dealing with the implications of those observations are impractical, if not completely wrong.
More specifically, what is so impractical or "completely wrong" about not using smartphones?
Given that the cellular providers are capturing and archiving location data, this is fact, his conclusion is we should avoid using these sorts of phones completely. Why? The reasoning here is a awfully thin, but has something to do with "being tracked = bad" and then goes into crazy territory from there. It's the same thing with credit and debit cards. They can be tracked, therefore bad, therefore nobody should use them.
If he's concerned about remaining invisible, then this must be applied rigorously across all aspects of his life. Does he wear dazzle face-paint or glasses with bright IR LEDs on them so that CCTV cameras can't pick him up? Does he only use methods of travel that require no identification? If the FBI wanted to retrace Stallman's activity on any given day, it'd take hours at most to piece it together.
The sign that someone's a crackpot is in how inconsistent they are in applying what they've concluded. It means they're missing something important.
For example, there are people that have a genuine need for absolute secrecy, that need to remain invisible, yet they still use cellular phones, email, and social networks. They're aware of the same risks as Stallman, but they take precautions instead of avoiding them completely.
It's notable that Osama Bin Ladin was taken down because he'd gone to such great lengths to avoid being tracked that he stood out as an anomaly, an approach that proved to be self-defeating. He had this large house, but a paranoia about electronic snooping so severe that he had no internet connection, and that alone made that house highly suspicious. If you're that affluent, you have an internet connection, even if you barely use it.
Everything Stallman advocates to avoid detection just makes him an even bigger target.
You don't understand why tracking may be bad? Or are you just trying very hard to mock his very valid conclusion?
Here's other people's thoughts about cellphone tracking: http://www.zeit.de/datenschutz/malte-spitz-data-retention/ (totally crazy, right!)
> If he's concerned about remaining invisible, then this must be applied rigorously across all aspects of his life
No, it mustn't. Every bit helps.
> Does he wear dazzle face-paint or glasses with bright IR LEDs on them so that CCTV cameras can't pick him up?
Perhaps he does not yet live in an area with seamless CCTV tracking.
> The sign that someone's a crackpot is in how inconsistent they are in applying what they've concluded. It means they're missing something important.
You must be a crackpot then because you're clearly missing that Stallman has probably managed to avoid having his daily movements tracked by some carrier.
> Everything Stallman advocates to avoid detection just makes him an even bigger target.
To whom, with what (crackpot-like) line of thought? Stallman is very open about his principles, his reasons and his actions. It would be extremely dumb for anyone to derive from this information that he is dangerous or a worthwhile target.
When I engage with social networks, use a cellular phone, I'm aware of the liability. I'm making a conscious trade-off. I really would like it to be less of a big deal, that the privacy implications were minimal, but this is the world we live in. I support political parties and representatives that would restrict how this sort of information can be used, making it less likely to be collected in the first place.
> No, it mustn't. Every bit helps.
Either you're trying to avoid being detected, or you're not. There's no half measures here.
> I'm making a conscious trade-off.
No, you're not. If you and the people who have had what you wrote happen to them (they obviously would have been more careful than you) were making conscious trade-offs, nothing bad would have happened to anyone as a result. In fact, you do not even know what information you are disclosing to FB (it's more than you are writing) and other, unknown to you, parties, so a conscious trade-off is impossible. You are just patting yourself on the back for being satisified with your ignorance.
> Either you're trying to avoid being detected, or you're not. There's no half measures here.
From what I understand, he is refusing to provide personal information to a carrier and possibly other unknown parties, because that is potentially harmful and not beneficial in any way to him. Why are you insinuating that he is trying to avoid detection, as if he were some criminal? And by the way, even criminals aren't stupid enough to do everything wrong because they cannot do everything right.
I've even got Facebook's site and associated flam blocked on my computer so I'm not bombarded with their inane commenting system, "Like" buttons, tracking features, or other garbage I want nothing to do with.
I'm taking a risk by using a cellular phone, I understand thins, however I believe the down-side of using one is better than the down-side of not using one. That I'm not a politician or celebrity factors in to this decision.
I'm not even sure what Stallman's full reasoning is behind cellular phones as it's always glossed over with some kind of hand-waving about tracking.
> I think the thing to realize here is life can change very quickly. What if, for one reason or another, you become a celebrity all of a sudden - Or happen to acquire particularly well-connected enemies. When this kind of powerful info is used against you things look quite different.
As is only using the FSF's definition of free software (where it matters less that the software itself is free, but that the software doesn't point out to you any nonfree addons. Fedora Linux is free software, as is Firefox but since they allow nonfree firmware blobs, and addons respectively, they don't count).
Or free hardware, Good Luck With That, unless you like a single netbook made by a single company in China.
Using a crappy computer from some no-name company in China is a protest vote and is not pushing things forward.
On the other hand, getting hardware hackers together to create a 100% free hardware platform would. The Raspberry Pi is close, all that's really needed is for some more aggressive lobbying to get the PowerVR driver component open-sourced.
Or consider, given how people are taping out custom Bitcoin ASICs, why is it inconceivable that someone could tape out an open-source CPU?
On the other hand, I totally understand the people who firmly believe that neither governments nor rogue personnel will ever abuse this information to their disadvantage. After all, billions of people firmly believe in some arbitrary deity and we haven't managed to prove them wrong.
You're conflating the FSF's definition of free software, and the FSF's criteria for recommending software to users.
The FSF sees Firefox as free software (now that the proprietary error-reporting system they used is removed); they won't recommend Firefox, because it recommends non-free software. Fedora is a distribution, not a specific program, and they won't recommend it because it recommends non-free software.
By the FSF definition, a license is free if it protects the Four Freedoms; but software licensed under that could be something the FSF doesn't wish to endorse.
One of the slides literally says that users must be careful to and their query with another parameter to avoid running afoul of the law.
I'm sure they know everything they need to know about Stallman, just as they do about everyone else, apparently. Unless he's sitting in a cave writing EMACS source on goat hides, they'll have a window into his activities.
Only if we are talking about the same types of attack, which we aren't. If you do "wrench" style targeted attacks at a large scale, you'll leave 10%+ of the population injured, how is that supposed to work out for a government?
Stallman's counter-measures probably work as long as only very few people use them. The same is probably true for terrorists, which is why this whole dragnet surveillance does not really work towards the stated goals and "crackpots" like me suspect it may have more to do with bullying people into self-censorship.
It isn't impossible to beat information out of millions of people. It's been done before and it'll be done again.
You say it'd invoke suspicion, but it wouldn't. If you're at the wrench phase of interrogation, you're already in a world where legal powers don't matter.
Are including the USA in the list of 'brutal military dictatorships'? Because the USA disappears people: https://en.wikipedia.org/wiki/Khaled_el-Masri
It's an update to what was already going on.
First of all, XKeyscore seems to be primarily about the frontend query interface rather than the backend data storage, at least as far as I can tell. It looks like you can basically query their database by email address and get a set of records (email, chat, http logs) back. It looks like there are separate tools for viewing specific records as well. I assume they're joining records on some combination of email address, IP address, timestamp, etc -- not unlike a modern ad server.
A few practical thoughts: * It's worth noting what's not shown in these slides. Specifically, I don't see any ability to query the full text of emails. The more I see about this, the more I'm convinced the NSA is not collecting email body texts directly from corporate servers. Facebook messages I'm less sure of. * How are they collecting HTTP data? I assume intercepting at network hubs? * Given that it appears that individual records are HTTP requests, I'm shocked at how few requests are in the database. 41 billion seems an order of magnitude smaller than I'd expect. Could it be a record is something else? * Interesting to note the "Miranda number" and "Foreign Factor" fields that look like ways of saying "yes, I have permission to do this." Might explain why a sysadmin could bypass these things but your everyday NSA analyst could not.
Regarding ability to query the full text of emails, this program does not seem to indicate that it would collect the data directly from the services servers in anyway. But consider that they do indicate the ability to monitor web traffic at the protocol level. Capturing e-mail is no harder, so it'd be surprising if they're not.
[1] https://image.guim.co.uk/sys-images/Guardian/Pix/audio/video...
I always said saying "I told you so." when stuff like this started getting revealed would feel like a hollow phrase. Some of us have spent quite a bit of time talking about these issues, and were mostly rejected as crackpot "conspiracy theorists". While there are plenty of those around, maybe I could use this slight moment of pseudo-clarity to propose something.
I could tell you where this is going (removal of ex post facto, and eventually algorithmic based pre-crime), and who is largely behind it, but once again most of you would probably perform the standard knee-jerk reaction against "conspiracy theory", only to wait around and repeat the same kind of stuff you are saying now, whenever the next steps are put into action.
We curious geeks have been too cocky, always thinking we could use our superior knowledge of technology to beat "the man". Well boys, the man is learning our tricks, and he's starting to get better at them than us...
The NSA is but a cog in a greater machine, and until we all realize that and start conversing on what/who that machine is, we will continue to spin our wheels uselessly.
In the overall game it simply makes much more mathematical sense to treat conspiracy theorists as crackpots since they will so often get it wrong. Even a broken clock is correct twice a day.
For example, you deride an entire "group" of people for believing their postulations to be 99% probable and assert that instead they are more likely 1% probable. I would say you just fucking pulled those statistics out of your ass, the very act for which you are deriding the group for! Such irony in a single sentence has been seldom found.
Sure, I agree with you that there are a plethora of quite frankly ridiculous conspiracy theories (not to be confused with the theorists themselves, who can often be just as ridiculous). That being said though, you are in fact completely wrong when you say "In the overall game it simply makes much more mathematical sense to treat conspiracy theorists as crackpots since they will so often get it wrong." and here is why.
Conspiracies are a driving factor throughout history. To ignore them in the past and in the present is to dismiss the very core their historicity. To dismiss them based on some flawed, arbitrary assertions about mathematical calculations that have no academic backing is simply daft.
Also, as I said before, there are indeed plenty of logically absurd theories... but why exactly are they absurd? One, they defy logic, but more importantly, the more absurd ones are often based on no evidence whatsoever. If you have such a difficult time sifting through the completely absurd to find the logically probable/possible in order to more finely tune your engagement, that is a deficiency on your part, and no one else.
I'm trying to think of an analogy to this... It's very much like the general reaction to homeless people. Many people have a general reaction to homeless people in which they assume they are either scammers, drug addicts, or lazy. They may have had a bad experience with a homeless person, and now seem to think almost all homeless people are not worth the time/effort. I understand how they can come to that conclusion, but the statistical facts do not support their argument, and, similarly, the statistical facts do you not support yours either, because you have essentially taken the same approach to "conspiracy theorists".
"Terrorists are the problem we must address" is no different from "Satan is trying steal your soul" or "Commies are gonna destroy our way of life" as a means of manipulating the more gullible people in a population. It's worked for centuries.
"You can fool some of the people all of the time, and those are the ones you need to concentrate on."
-George Bush, repeating advice given to him by Robert Strauss
Here is my take:
You do not need to posit an organized Illuminati-like conspiracy to have cause for concern. We can find plenty to worry about even if we limit ourselves to properties of the system that are either emergent or driven by natural human behavioural traits.
For example, a lot of people in positions of authority got there because they have authoritarian instincts, and seek self-validation not only by dominating and controlling others, but by ensuring that their position of authority and dominance is recognized by others.
This is very human, and very instinctive, and operates at an unconscious, almost sexual level. The alpha male will seek to dominate the pack and to remind competing males of his superior status. You do not have to consciously be aware that you are seeking power, money and sex, but you are, nonetheless.
This instinct can operate both consciously and unconsciously. Those who make decisions to concentrate power and authority, to separate and elevate themselves from the general population - they do not have to be consciously aware of what they are doing. They can and will rationalize their beliefs and actions to make it fit in with the dominant culture of their peers. This process is called confabulation (http://en.wikipedia.org/wiki/Confabulation) and everybody does it all the time - it is the only way that we can make sense of our lives and live in a human body without going insane with the sheer irrationality of it all.
These instincts manifest themselves in lots of small, individually inconsequential decisions. Normally, this is OK, because our social and bureaucratic technologies are (were) too ineffective for too much harm to be done. The ongoing march of modern information technology, however, looks likely to change that, meaning that the unconsciously malicious instincts of humans in positions of authority can become amplified and magnified.
I would be particularly worried if this resulted in a feedback loop - so that increased power and increased power-seeking behaviour mutually reinforce one another in a runaway process. I cannot readily identify such a loop in operation though -- can anybody else?
I agree completely that we do not necessarily need to posit and organized "Illuminati-like conspiracy" to have cause for concern. There are plenty of studies showing increasing likely-hood of sociopaths rising to the top of power structures, and is often just due to how to system as an autonomous entity functions.
What I do posit though, is that, in fact, there is, borrowing your own term for lack of a better one, an "illuminati-like conspiracy". I have been considering an attempt at scholarly paper on the matter for some time now, but let me try to be terse and possibly just point you in the right direction, because I don't think I'm quite prepared to defend the full assertion in public yet.
I will start with your question about power feedback loops. Here is a paper regarding the global network of corporate control that anyone interested in the global power structure should read. http://arxiv.org/pdf/1107.5728v2.pdf
I even contacted one of the researchers (Glattfelder) during the Libor scandal, wondering if we could use some of the new information to analyze the scandal better. He said it would be extremely difficult due to how good the companies are at obfuscating their dealings.
Now, as far as the conspiracy, I would like to point out one thing. I do not claim that there is but a single conspiracy (a trap assertion many fall into making), and instead would say there there are but a small number of very powerful ones operating at any one time, sometimes in competition and sometimes cooperatively. Regarding the "illuminati-like conspiracy" itself, I have one primary reading source for you, if you are genuinely interested in the subject. It should be enough to get you started on the more serious analysis of what I am talking about. http://www.amazon.com/Anglo-American-Establishment-Quigley-C...
Since we know that our (USA) entire financial system is backed by (Federal Reserve) bankers that loan money without moral guidelines, it could be conceived that a family like the Rothschild are at the top of the world power hierarchy. What do they always say in the detective movies, "follow the money".
Indeed. I always follow The Money because that's who owns the government.
America, including the NSA, is owned by the same small cartel that have the monopoly on the issuing of our currency and credit. Coincidentally, they're the same cartel we're "indebted" to.
Most people have never heard of the four largest banks in the world:
http://www.northerntrust.com/documents/white-papers/asset-ma...
I'm don't think that is a stable long term system. Either some effective limitations (technical and political) are put in in the next several years, or a few decades of "us vs them" and self justifying security crises will produce a horrible result.
Now, the thing that prevents that from happening is money.
So much money is concentrated on so few people that it protects itself and the owner becomes invulnerable. Add to that that too much money very often corrupts its owner. The predictable result for society seems pretty obvious.
The other factor is that the NSA's reputation is irreparably tarnished, and they will continue to attract the wrong kind of people. I think we need to prepare for some dark times ahead.
Hard for me to fathom anyone taking a job, helping to build systems like this. I get that many of the components of a system like this could be seen as harmless. However, a system of this complexity must have some talented engineers bringing it all together and making it work. How can they feel good about what they are doing?
It's called Power.
I can now look into any person's email and whatever legally. You and I may get a squishy feeling in the stomach about this but I can tell you that 1 out of 2 people will be OK with this if they aren't called out. (like watching porn, most people won't admit in front of kids and their parents but they will do it because they think they won't get caught)
Or they just like the paycheck, that's a big possibility. I imagine the NSA is probably happy to pay a lot with a large amount of bonuses to keep people in roles.
So, it's easy to imagine NSA recruiters coaxing potential hires with convincing lines like "we have internal courts, procedures, and checks and balances systems to prevent abuse of citizens' privacy".
In the spirit of the 'Shire' quote they should have also realised 'with great power comes great responsibility'. No one has demonstrated that they are responsible enough to have that level of power over millions of people.
You'd be amazed.
THAT certainly wouldn't risk an apathetic response.
E.g. Chinese hackers steal plans for American-designed products. Instead of Americans working, building and selling the things we consume, inexpensive imported versions are available b/c those companies didn't pay for the overhead of design and didn't take any risk. We need to protect ourselves from this.
I'd also imagine that a lot of folks only work on one small part of this, that in and of itself, is not objectionable. Where it becomes scary is when you expand the scope to cover every US citizen regardless of wrongdoing.
They will tell you that there are rules in place to prevent spying on Americans (and if you take a look at the Foreignness Factor screenshots, there is a sense in which this is true)
They will also tell you that the benefits outweigh the cost. Here we have a system that has allegedly caught 300 terrorists, and they would tell you that spying on foreign people to catch 300 terrorists is a good trade.
I disagree with them on both counts, but you asked what they would say.
surely you don't believe the premise, but as a thought experiment pretend it were true. would the NSA actions be justified?
But in order to save 900,000 people, it required a bold attempt to eavesdrop on all ~1.3 billion people currently using the entire internet, leaving us with an efficiency of 0.1%.
Not only that, but the process needed to occur continuously, for a decade, ramping up, over time.
But wait! It took nearly 20 hijackers to accomplish one 9/11, so that means it only stopped 15 9/11's in a decade, or rather 1 and a half per year.
So that means we saved 4,500 people a year, by eavesdropping on over one billion each year.
But remember, when you tally up all those ten long years of life saving:
Those 45,000 people weren't just ordinary human beings...
They were Americans. They were Freedom.
And at the end of the day... well... ✼sniff!✼ I think you and I both know that you can't put a price... on FREEDOM.
bottom line is anything can be justified if you want to justify it.
Didn't you hear? The system is used to help track down bad guys who want to hurt America.
It sounds trite, but people really and truly believe that the issue is just that simple.
http://www.youtube.com/watch?v=FOFtQ6n3WR4
Clearly a very smart guy, that went very far in the NSA -- and for a long time felt he was doing "the right thing" -- but eventually quit because of what the NSA were doing.
edit: He also touches on how compartmentalization leads to people not knowing what they're actually working on/how it will be used in some cases.
What I'm trying to ask is: with all the hullabaloo Google, Facebook, Yahoo, Microsoft, etc have made about individual, manual reviews of information requests, are we still being lied to? I suspect that we obviously haven't been told the whole story by these companies, and that they are a lot more implicit in this than they let on, but this article seems almost like definitive proof that they did indeed allow unlimited access to user information.
If this is saying what I think it's saying, then I feel seriously back stabbed by the startup darlings -- Zuckerberg, Brin and Page, etc -- that so many people here love and idolize. They should absolutely be held accountable.
I was doing similar things in the mid-1990s on shared Ethernet. It's really only a question of speed and scale and then of writing code that recognizes particular traffic (such as "this HTTP connection is a Facebook chat session").
The TSA can't crack or impersonate a cert at will; they can only 1) try to trick you into accepting a phony one or 2) demand/steal the private key from the site.
It does however give you the ability to issue yourself new public keys to conduct man-in-the-middle attacks [1]. If you compromise the same CA as the site whose traffic you're trying to intercept, you can bypass certificate pinning which is supposed to detect MITM attacks. So for example you can MITM gmail without certificate pinning detecting it if you compromise Verisign, Equifax or GeoTrust [2]
[1] http://googleonlinesecurity.blogspot.co.uk/2011/08/update-on... [2] http://src.chromium.org/viewvc/chrome/trunk/src/net/http/tra...
They're taking it a step further and using certificate pinning in Chrome to catch MITM attacks in real time across a large portion of the internet. http://blog.chromium.org/2011/06/new-chromium-security-featu...
It's not scalable at all, but cuts out a large attack vector for a lot of communications. It wouldn't take a ton of pinned certificates to make a big dent in these NSA programs--really just look at the logos and make sure that each has their certificates pinned.
I'm trying to understand why services are not taking a more active role in protecting their users' information if they are claiming to taking our privacy seriously.
To me, it comes down to being either incompetent or a liar, or both.
> * Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users.
> * These events are easily browsable in XKEYSCORE
As I understand it (and I may be wrong), most encrypted VPN traffic uses SSL. Given that XKeyscore data is only held for a few days (due to the immense volume) and given how nonchalantly they just throw out that they can decrypt VPN traffic, it sounds to me like they've either got the root SSL certs and are MITM'ing every connection they can or they've somehow broken SSL, either by breaking the actual encryption used or by exploiting vulnerabilities in how browsers handle it. If that's the case, then they don't need to ask Google or anyone else for your data, they can just read anything they want.
Even better would be for the NSA to penetrate Thwate, Verisign etc and make the keys they "generate" non-random (perhaps only for a subset of certificates sold)
Perhaps they own or subsidize many of the cheaper VPN like has been rumoured for Private Internet Access? https://www.privateinternetaccess.com/
We believe what the NSA is referring to when talking about "VPN startups" is the initial stages of PPTP sessions. PPTP has been crackable for a while, check out moxie's cloudcracker.com. We believe it highly unlikely that they have broken OpenVPN (which is what our application uses) or SSL.
Please see our stance on PRISM: https://www.privateinternetaccess.com/blog/2013/06/prism/
http://www.washingtonpost.com/business/economy/the-nsa-slide...
The answer will always be "yes".
"Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users"
Does this mean using VPN is not very safe from dragnet?
You could also break into the VPN company's servers and do interesting things too. There's also the possibility of timing attacks to determine the real IP address of the VPN user, although that's fairly a sophisticated method and quite difficult to do.
Bear in mind that this presentation dates back to 2008, which is a long time in tech years. Who knows what they're capable of now. All that's known is that they're not capable of less.
VPNs are useful for three things: protecting yourself against relatively unsophisticated bad guys sniffing traffic on a local network (for example, an unsecured wireless network), bypassing geographic content restrictions (e.g. using Pandora in Sweden), and circumventing ISP traffic shaping (often they'll not shape VPN traffic because it's used for businesses, and businesses can be whale customers).
[-1] http://en.wikipedia.org/wiki/Device_fingerprint
[0] http://blog.calyptix.com/2012/08/pptp-is-so-insecure-it-shou...
If the only thing they're dealing with is VPN's used as a private proxy for access to the public internet, you're right, and if so it's not so troubling (well, as in it is "only" just as troubling as having them access everyones web traffic).
But arguably most VPN traffic is exiting inside private networks and are intended for machines within those private networks. If they are capable of breaking or circumventing the crypto of those, then that's troubling at a whole different level because it potentially means massive unknown weaknesses in either specific crypto products, or in algorithms that have been assumed to still be reasonably safe.
Security's dirty secret is that security is an unobtainable goal. The goal of designing secure systems isn't to create something impenetrable (i.e. secure), but something that's almost impossible to penetrate. 100% secure systems are about as common as rooster eggs.
I took that to mean establishment of VPN connections, rather than companies operating VPN services.
Of course total security is impossible. But it would still be troubling if breaking common VPN services is not only possible but also doable with small enough resources that "any analyst" at NSA can just request it.
But that's actually the one thing that makes the most sense now:
>How do I find a cell of terrorists that has no known connection to strong-selectors?
>Answer: Look for anomalous events
>E.g. Someone whose language is out of place for the region they are in
>Someone who is using encryption
>Someone searching the web for suspicious stuff
Lovely. Suspicious stuff and encryption. But wait! There's more!
>Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users.
Wait... what? I really hope that doesn't mean what it sounds like it means.
>Slide 22 [regarding determining who authored a Jihadist document] redacted.
Well that's interesting.
>Show me all the exploitable machines in country X.
That's cool. I'm guessing this is what Snowden meant by weak endpoint security.
>Over 300 terrorists captured using intelligence generated from X-KEYSCORE
>Slides 29 and 30 regarding this redacted.
What a shame.
How is one labeled a terrorist by this program I wonder?
That the NSA is in the business of total surveillance is bad enough. But there is the faint hint that the NSA is in the business of making people disappear.
Pretty fucking scary if you ask me.
Check (German browsing in English)
>Someone who is using encryption
Check (my PGP Key is on my website)
>Someone searching the web for suspicious stuff
Check (I'm a curious person, what did you expect?)
I guess I'm considered a terrorist nowadays.
> That's cool. I'm guessing this is what Snowden meant by weak endpoint security.
That, plus things like Microsoft and Apple operating systems. Don't forget: it's proven they work with the NSA, so backdoors certainly are guaranteed (plus, with Microsoft, we also know they hand 0-day exploits over to the NSA before they're fixed, plus you benefit from all the viruses, trojans, etc.). Again, if you missed it, start migrating now: https://prism-break.org/
One question, how did the dot in China get there?
http://www.theguardian.com/world/interactive/2013/jul/31/nsa...
"Show me all VPN startups in country X, and give me data so I can decrypt and discover users."
Holy crap. Is all encryption broken?
Also, it was leaked that NSA TAO had a 70%+ success rate compromising Chinese systems. Even with the tech companies giving them secret zero days for an extended period of time, anyone that has been a blackhat knows they're not getting to a 70% success rate through exploits. Therefor, it's highly likely they can decrypt VPN/SSH (TLS) traffic encrypted with AES256/RC4-128/3DES and/or the RSA/EC public cryptography used. As you noted the leaked slide seems to indicate that.
I don't recall the source of the Executive comment. It was kind of buried in a news piece with a broad focus that I read. I'll look for it. Unfortunately, I can't recall the exact language to do a good search and find it. Sorry.
But, here they are saying they have it, it's encrypted, and they can get it in "weeks or months" (despite the large number of drives/filesystems with presumably different keys): http://www.cbsnews.com/8301-31727_162-20059825-10391695.html
The Executive and Legislature couldn't keep something secret to save their lives. And, JSOC leaks like a fucking sieve. If I can't find that particular leak on the web, I'm sure there will be another one soon with the same info. Every guy likes to talk to pretty news reporters and seem important.
Claimed 75%+ success rate attacking Chinese systems: http://www.scmp.com/news/hong-kong/article/1260306/edward-sn...
Asrar al-Mujahideen (the Jihadi PGP fork w/ 2048bit RSA): http://www.rbijou.com/2013/03/18/an-overview-of-jihadist-enc...
The news coverage sucks something awful. The thing is having enough knowledge of mil/ir/tech/math to put all the leaks together.
Do you have more information on the smooth barrier? I did a quick google but didn't see much relevant.
There's a reason the NSA is pushing folks to use Suite B ciphers including Elliptic Curve along specific curves. It's not unreasonable to think that the NSA mathematicians have proven some relationship between EC and prime number theory in general.
There is some public domain work on this topic. See [https://en.wikipedia.org/wiki/Lenstra_elliptic_curve_factori...].
This might help explain in part the NSA's desire for large memory vector supercomputers going back to the 1990s over distributed memory MP systems.
There have been a number of very cost effective hardware approaches proposed for significant acceleration of both the sieving and linear algebra components of the NFS. Many of these proposals could successfully and cost effectively attack a 1024-bit number in the 2003/2004 era. The process at that time was around 130-nm. Today's process would have features at the 32-nm or 22-nm size. Today there has been a 100-fold increase in performance since 2003. (See http://tau.ac.il/~tromer/cryptodev/ for an overview.)
Combine this specialized hardware with an algorithmic improvement that gets to O(log n) or O(n log n)....
AES appears fine. The NSA and USG in general make a very strong effort in the 2000s to move all civilian command and control systems for satellites to AES-256 with TRANSEC capabilities. A brute force attack on AES-256 with a quantum computer should be on the order of 2^128 operations with currently know QC factoring algorithms. AES-128 looks weak at 2^64.
If the NSA can break something, they need to assume that their primary opponents can do so or will do so soon. China specifically comes to mind here. The can not release cryptography suites with known vulnerabilities. It is widely thought that it is more importantly to secure one's own signals before intercepting and decrypting one's enemies.
I think everything on the internet needs to be moved to Suite B protocols with forward secrecy enabled. AES-GCM overcomes all the known attacks (i.e. CRIME) against AES-CBC and AES-CTR.
I get the impression that the NSA is eight to ten years ahead of the public domain cryptographers in some areas. I think this gap is shrinking slowly. However, I have also heard that the NSA is preventing publication of some papers developed in the public domain due to national security reasons.
I guess this kind of puts different perspective to the whole debate that came from JSMin's "The Software shall be used for Good, not Evil." clause (http://wonko.com/post/jsmin-isnt-welcome-on-google-code) given that conceivably your open source framework might be a significant part of something like this.
A tool is a tool. I don't think Henry Ford should feel guilty for enabling people to kidnap children with greater speed.
Those 60TB density HAMR[1] drives that are due in 2016 are really going to take invasive to a whole new level.
[1] http://storageeffect.media.seagate.com/files/2012/03/perpham...
Oh, wait...
But note that you can buy off the shelf PCIe cards with SSD's mounted that will give you 1TB storage and an aggregate read bandwidth of more than 1GB/sec today. I've got three sitting in various servers. They're expensive, and frankly for the future I'll rather get a couple of extra SATA III controllers and get multiple "regular" SSDs on separate controllers for that reason, but they're available.
For NSA style data collection, though, the collection is trivially to do in parallel: Hash all keys to a "virtual bucket", and hold a map of virtual buckets to physical servers. Then when you want more capacity, you add some physical servers, reassigns some of the virtual buckets from other physical servers to the new ones, and synchronises any old data (given that NSA claims they could only hold the full data stream for three days, you don't even need the hassle of moving data, just make collection on different days map to different virtual buckets, so that on day one you "just" reassign virtual buckets the content of which is being expired on the old servers anyway, on day two, the next set etc. - you maintain full spread of read/write traffic by ensuring that in normal operation all servers have an even spread of "day 1", "day 2" and "day 3" buckets).
It's amusing they see storage as an issue, but of course this was in 2008. Today I have 6TB in my home NAS, and my perfectly off the shelf tower case can easily fit 40TB+ with current size harddisks (though I doubt the noise would make me popular at home).
[1] http://www-03.ibm.com/systems/storage/tape/ts3500/index.html
[2] http://www.quantum.com/products/tapelibraries/scalari6000/in...
I live in Columbia, South Carolina. A mile from my house there is a prominent statue of Ben Tillman. Tillman was an explicit advocate of terrorism, and indeed personally engaged in it [1], which drove his popularity and ensured his election to the governorship and the United States Senate.
Government programs such as the NSA's exist to protect the interests of the powerful. Same as it ever was.
I know NSA's mandate is to spy on foreigners, but it's still very jingoistic and xenophobic that not being American makes it OK to spy on you.
Just wanted to add a note and say that if you're angry about this, the best thing that you can do is to get out into the streets and protest everything that's been going on. Check out the Restore the Fourth rallies happening this weekend, share them on social media, and sign up for your local event.
Getting out into the streets is the single most significant thing you can do - even more effective than calling your legislators. The events on Sunday need to be bigger than the events July 4th for this to really be a success.
URL looks like: https://gamut-wakefield.ein.nsa/utt/UTT/do/FRNewSelector#sel...
http://www.techcareers.com/job.asp?id=64332188&aff=C014D02C-...
Job posting, requiring top-secret clearance, looking for people that have experience using certain tools including "GAMUT/UTT" - notice the URL from the NSA doc has "gamut" and "UTT". So i further looked into GAMUT/UTT and found this:
http://williamaarkin.wordpress.com/2012/03/13/nsa-code-names...
http://static.guim.co.uk/sys-images/Guardian/Pix/audio/video...
says: Top Secret Comm(?) REL() to USA, AUS, CAN, GBR, NZL
confirming the previous suspicions that many other governments are on board.
Der Spiegel actually has reported a few weeks back about XKeyscore [1] and that it is used by the BND (Germany's NSA). I.e. all this data is also available to the NSA equivalents of Australia, Candana, Great Britain and New Zealand.
Many Americans trust their government (unfortunately), will they also trust the other governments?
[1]:
http://www.spiegel.de/international/world/german-intelligenc...
http://www.spiegel.de/international/germany/german-intellige...
"This was a secret treaty, allegedly so secret that it was kept secret from the Australian Prime Ministers until 1973."
This is indeed a trend, and I speculate that NSA (and NSA-like entities in the other 4 eyes/countries) probably communicate information and abilities to prime ministers and presidents of the respective countries very selectively.
REL TO likely means release to.
As I've said before, the realisation that most countries do this sort of thing comes as no surprise.
As of this moment it's all about FISA. Wonder if this new allegation will be talked about.
IBM & Nazi Germany, Nazi Germany in general, etc. Ironically, sillicon valley came into existence building military SIGINT/ELINT systems for the cold war.[0]
[0] www.youtube.com/watch?v=hFSPHfZQpIQ
I guess I felt the need to comment because it sounded like you were saying, "Hey, I get why they're doing it. Sounds like it'd be fun!", and I feel like having that attitude (even if I trust someone like you to know to stop before things get truly out of control) is dangerous.
http://newsdiffs.org/diff/290704/290768/www.nytimes.com/2013...
> That House vote was about one specific topic - bulk collection of phone records - that this newest article has nothing to do with. That House vote isn't the be all and end all: it's just one small battle in what I can assure you will be a sustained and ongoing discussion/controversy.
> There is a lot more to report still. Accuracy is the number one priority. That takes time.
If a non-US resident or NSA target posts a thread on HN, and a US person replies to the thread, is the US person now open to unlimited data collection?
Alternately, if you Facebook-like the same thing an NSA target has, are you then subject to unlimited data collection?
In reality you are always a valid target, US citizen or not.
On the other hand, this is categorically 'evil' by my and my cofounders' ethical standards, and really, no one is safe. And that bugs the hell out of me.
On the one hand: really fucking cool. On the other, I really do not like the idea that I am being spied on.
I'm not sure how to process this information.
I just don't see how this could be considered "cool". There are plenty of other marvels of modern computing that aren't so sinister.
I think a better word for this is "scary", due to the level of cooperation from corporations and the level of secrecy it was running under for so long.
Moscow, Russia
Caracas, Venezuela
Tripoli, Libya
Hubei Province, China
Burma
Lagos, Nigeria
Saudi Arabia
Iran (and geograhically surrounding Iran)
Ukraine
Based on page 13, I wonder if Google have any servers at these locations?Oh, what a surprise: http://royal.pingdom.com/2008/04/11/map-of-all-google-data-c...
Does that look familiar?
Were we looking at the same map?
Again, page 13; a local Google Pakistan search query.
The NSA is accomplishing some pretty impressive things, what are they doing differently?
Probably also not having to follow government contracting rules (lowest bidder, preferring minorities and veterans) because who would have the authority to review their purchases?
GeoIP City Edition, Rev 1: PK, 08, Islamabad, N/A, 33.700001, 73.166702, 0, 0
5.157.65.58.in-addr.arpa domain name pointer mbl-65-157-5.dsl.net.pk.
23674 | 58.65.157.0/24 | MBL-AS | PK | NAYATEL.PK | MICRONET BROADBAND (PVT) LTD.
For years all of this was in the back of my mind as being capable but my not wanting to think like a conspiracy crackpot just dismissed the thought as it couldn't be possible. A conspiracy takes a lot of co-operation from within large corporations who must also remain it a secret. Surely someone would have a conscious and leak it? Or one of companies we all look up to as a modern example of do-good company would say "Hell NO" to the attempt and then let the world know what was attempted. Guess that was eventually proven true with Snowden (a real hero imo), just shocked they were able to operate to the scale they did for so long before a Snowden came along.
In my mind, this is not so much a shock to me regarding the NSA as well as the current evil government we have had in place. Doesn't take a genius to realize the president lies to our face on TV about trivial issues/promises, so expected for top secret stuff.
What is the BIG stomach churning shock to me is the very companies that we have come to know that are multi-billion dollar conglomerates providing service/products for millions for every day use has been a part of it. A part of this secret web while all the while proclaiming privacy for it users. I guess at end of day profits still rule the roost. "Just do this for us, turn a blind eye, and you get to go on making your billions". I wonder how many CEO's knew of all this. Gates? Zuckerburg? Etc etc.
I feel like I have no outs now. There are no alternatives to current establishment of companies that make our lives easier. Should we all wipe our PC's and use Linux, sell our phones and use Ubuntu Phone, not pay for SSL certs anymore (another mafia), etc?
We should start hold our public servant to task for lying to the American people about these programs.
I'm not an expert in this area of mathematics, so I could be wrong, but my impression is that as the haystack becomes larger the problem of false positives becomes more and more severe.
As a data miner, what you want is the maximum number of "hits" (of whatever you're trying to hit) with the minimum number of misses and the minimum number of false positives. My impression is that this becomes progressively harder-- the golden region between too many false positives and too many false negatives becomes smaller and smaller and harder to hit.
Eventually you either miss important hits, namely the next terrorist attack, or you get swamped with false positives that you have to manually investigate and rule out.
I'd love someone who does know more here to chip in, but my personal suspicion is that this actually has a pretty huge pork angle to it. How much money are the contractors getting for building this stuff?
The XKeyscore system is continuously collecting so much internet data that it can be stored only for short periods of time. Content remains on the system for only three to five days, while metadata is stored for 30 days. One document explains: "At some sites, the amount of data we receive per day (20+ terabytes) can only be stored for as little as 24 hours."
you don't need to use some kind of fancy data mining algorithm for this to work (generating false positives), you just need a ho-hum graph traversal algorithm and unbelievable amounts of graph data to generate "candidates for investigation".
US Company A -> intermediate 1 -> known terrorist group B
US Company A -> intermediate 2 -> known terrorist group B
US Company A -> intermediate 3 -> known terrorist group B
Each set of links is just one lead to investigate, but having a giant graph to work off of would make generating those leads simply. You might find out that intermediate 1 is a local falafel delivery place that "US Company A" uses for lunch catering. Can probably strike that one off the list. intermediate 2 is a utility (no choice but to use the local water monopoly), but intermediate 3 is a material supplier that employs several low level delivery guys from known terrorist group B, and the founder of the company is a cousin of the founder of known terrorist group B.
So I'd wager it's not as simple as just running an algorithm and automatically sending out Skynet drones to blow things up. There's some kind of more subtle assessment being made, with the systems just providing help to the analysts.
The more worrying thing is that they're still apparently using IE6. [EDIT: OK the presentation is from 2008 but still!]
It just about proves that it's not true, to me.
"There are thousands upon thousands of documents and they take time to read, process, vet, and report. These are very complex matters..... there is a lot more to report still. Accuracy is the number one priority. That takes time."
Enjoy your federally-funded vacation!
>I wonder if the leaked presentation touches on this point.
That seems unlikely to me, as this is a technical presentation.
So, even IF this number is not just another lie, XKeyscore has been made worthless, with something ridiculously small as the 2 prison breaks of the recent days.
That means: What remains is a police state that is not even "secure".
Good job, governments/lobbyists/"defense" corporations.
Also I wonder to what extent this is really used to hunt terrorists down and how much of it is used to gain political or economic advantages over other countries.
I guess what we need to ask ourselves now is whether we want any secrets at all. A true Panopticon -- a society where everyone could see what everyone else was doing -- might bring a "freedom" from certain types of subterfuge, and attack.
Then again, I don't want to live in it.
That leads us to the question of how we handle the flood of data when looking for hostile activity, because governments are certain to use available technology to trap, parse and search that flood.
When I was a kid, my father, had told me a story that in Russia people are scared to speak their minds, for fear of being snooped via any hidden gadgets in the walls.
The fibre intercepts would fairly easily give access to HTTP traffic, and Facebook/Google/etc. would probably 'come online' at about the same time (there will likely be some differences as it appears there is a need to code a plug-in/processing engine for each major source to pull out usernames etc.[2])
What exactly the dates in the PRISM slide mean is somewhat unclear without more information. It could be, for example the date that the first court order is made, or the date when the company provides to the NSA a more automated way to query the data. I doubt that those dates are related to the fibre intercepts though.
[1] https://image.guim.co.uk/sys-images/Guardian/Pix/pictures/20...
[2] https://image.guim.co.uk/sys-images/Guardian/Pix/audio/video...
The key now is to see who exactly is letting the NSA tap their network hubs to sniff the entire Internet. These will be your Internet Service Providers...
Does MS Excel store your MAC address in the xlsx file?
The user interface and way this is done just seems to amateur hour to believe this is actually true
It can search BCC?? Only the sender has them. so everything would have to be collected at each ISP (which isn't impossible).. but I think the guardian has been trolled.
http://www.theatlantic.com/technology/archive/2013/06/bombsh...
In one sense, it is amateur hour ... but if you buy enough hours from enough amateurs ...
It seems like everyone's been attacking the wrong folks. From this article it appears that bulk of the data is being tapped at the data center level and then parsed. This begs the question how it would be able to make sense of https traffic.
Most people might speak against it (include people here) but at the end, they have the "I'm not doing anything wrong, who cares, not worth the effort" mentality.
Also I doubt the veracity of the claim that they collect "nearly everything". Wouldn't they show up on, say, Sandvine's Internet traffic reports? I think it's more likely this claim is made simply to generate FUD in the general population.
I think the era of government being far ahead of commercial tech capability is over. The government mostly outsources now (a problem Snowden identified in terms of information control) or develops in-house with vendors.
[0] http://online.wsj.com/article/SB1000142412788732349560457853...
There are a lot of fingers in that pie. Oracle, for example, has a National Security Group, whose job is to come up with "solutions" and then try to sell them to three-letter-agencies.
Why would they? They deal with ISPs, backbones and such.
Well, now they have a massive data center in Utah. That's most likely where it's all going today. Standard open source tools are all you really need.
> Wouldn't they show up on, say, Sandvine's Internet traffic reports?
No. If some script kiddie/hacker type installs a packet sniffer and logs all your traffic to your ISP, that won't show up anywhere. Traffic goes somewhere. You're sending packets out. Merely logging packets is entirely passive and undetectable.
And More says: “You’d break the law to punish the devil, wouldn’t you?”
The prosecutor says: “break it? I’d cut down every law in England if that would take it to catch him”.
“Yes you would, wouldn’t you?” And then “When you would have cornered the devil and the devil would turn around to meet you, where would you run for protection, all the laws of England having been cut down and flattened? Who would protect you then?”
Every time you violate – or propose the violate – the right to free speech of someone else, you in potentia you’re making a rod for your own back. Because (…), to who do you reward the right to decide which speech is harmful, or who is the harmful speaker? Or to determine in advance what are the harmful consequences going to be, that we know enough about in advance to prevent? To whom would you give this job? To whom you’re going to award the task of being the censor?
http://howtoplayalone.wordpress.com/hitchens-on-free-speech/
A huge problem with the NSA's activities is that they are, or at least have been, so secret that it is impossible to even discuss in a meaningful way the political question you posed. This should be unacceptable even to those who think catching the 300 terrorists made the surveillance ok.
[1]http://www.latimes.com/news/politics/la-pn-secret-nsa-survei...
If "caught" means convicted and "terrorist" means bomb maker or airline pilot with intent to crash a plane into skyscrapers it may be a discussion worth having. If "caught" means arrested or "terrorist" means gave $5 to an Islamic Medical Charity that turns out to have been shady it isn't even close to worth it on a practical level without even considering the principles and general human rights aspects.
My guess is somewhere in between but with people with as weak grasp of the language as the NSA seem to have I would be very careful.
"We don't gather any data."
"We only gather metadata."
"Ok fine, we gather everything."
G�#��$�5�%�����V��5�F�'98u�x�)�w���[_Fa��6�1f�!��['��"���VGu~w� ����|�U���Z�hep���G��^7{��K�wq��h|ڛ�m=�$L ��t� _��pM<�q��;����Y��C �M]!C�6ҝnV[�c�ϾWa�?C�M�"X*��b]0�Aļ��Li3`�P�#�j�f�u���!wb�]t_�q�&EԞw�����r�.<?K��{
I dont want to detract from Snowden's very noble act, but I hazard a guess that Snowden knew that the documents he leaked could be traced back to him, or at a minimum a small team that he worked with.
Every time a thread on this hits the top it gets mod-deleted.
Missing: How much did this cost? Did the government (taxpayers) overpay?
As I recall it, our right to privacy is defined by the "reasonable expectation of privacy".
Currently, I see any such "reasonable" expectation to be almost zero.
Therefor, I have to conclude that we have already lost the right to privacy.
The FBI was doing this decades ago with Carnivore. Why is it at all surprising that such a program continues to collect unencrypted information you sent over the Internet?
any citizen can go out and listen to public conversations, but we are not all invited to put our e-stethoscopes up to the internet backbone.
> While this computer won't have a record of your browsing history, your internet service provider or employer can still track the pages you visit.
They should include government spooks in that warning!
>Going Incognito doesn't affect the behaviour of other people, servers or software. Be wary of:
> ...
>Surveillance by secret agents
Does this indicate that they have broken HTTPS, or simply that they own VPN companies like Private Internet Access?
This system logs HTTP metadata and data (think the address on the envelope and the contents of the envelope), the metadata for 30 days the contents for 3 days.
This http data is essentially everything that goes over the wire all of which is then shovelled into a database with a fairly sophisticated (if not pretty) front-end that allows really invasive searches.
You can search for stuff like "all emails that contain the words sex doll" or "nudes" and contain jpegs...of course the users would only use this system for legitimate operations covered by warrants.../s.
This is the first of these releases that have really made me stop and go "whoa" mostly because this is "better" (bigger, more complex and capable) than anything I expected them to have now (and this was in 2008).
As to the how they are taking feeds directly off major internet routers (the vast majority of traffic will go through a major router at some point particularly if it is international though it's quite possible for a packet sent from one side of your country to another to go international as well).
So yes they do have email content capabilities (if you look at the actual slides they also have a sophisticated filtering system, they can do stuff like "show me emails from iran with word documents attached containing IAEO").
This system is absolutely terrifying, it genuinely is the work of a dystopian sci-fi author from 30 years ago.
----
If you want to get right down in the trenches email is SMTP and POP over TCP/IP (normally), email is fundamentally a human readable text protocol which makes it trivially easy to parse (this was kind of the intention after all) so once they have the captured stream reconstructing the mail is not much harder (if any) than writing a mail client.
You can see an example of SMTP if you open a console/shell and type "telnet smtp.gmail.com 25" and then when it has logged in type HELO the response is just plain text.
"The XKeyscore system is continuously collecting so much internet data that it can be stored only for short periods of time. Content remains on the system for only three to five days, while metadata is stored for 30 days. One document explains: "At some sites, the amount of data we receive per day (20+ terabytes) can only be stored for as little as 24 hours.""
Of course, as the article goes on to detail, anything that's found to be of interest in that window can be saved permanently, and NSA analysis do that a lot.
It does not describe "interesting". Maybe metadata, encrypted sessions etc? Any conversations in threads linking to these articles?
It's total power, I think it's unlikely that they'll want to give up on this kind of power, they'll probably keep signing governments and 'the tech' will eventually be exported and in the hands of governments everywhere, they'll keep building this and they'll create tons of algorythms of course because it's just too much data, any resistance can be crushed... and it's so much power eventually some dark times will begin... I'm done with the topic.
Kinda surprising why all the people who are 'overwhelmed' and 'terrified' in the parent thread don't come out and protest. Oh wait, there's kids to feed. My bad, sorry.
(no snark)
The real consequences of this news will be seen in the actions of companies. As 'cloud' (oh I hate buzzwords) technology becomes increasingly more efficient and cheaper, as Amazon, Microsoft, Openstack and VMware duke it out over cloud customers, will those customers trust them with their data? Will companies invest in private clouds for increased security, or will large public cloud service providers be able to win over and keep their trust? How much money have public cloud service providers lost since the leaks began? How many companies are now unwilling to use cloud services from US-based companies?
Many hands make light work.
If yesterday we were "conspiracy theorists" when we suspected things like XKeyscore, what are we today if we suspect things like "Person of Interest"-like programs?
(from season 1 opening)
It's scary how this is actually not fiction.
Using PGP as part of a filter makes perfect sense. If you're looking for "bad guys" that do certain activities, as a starting filter, it doesn't hurt to say "OK, show me everyone in this region doing these activities. Now filter by language, etc. etc.".
Just like if I was looking for gang members, I might start off a filter with "look for tattoos". It doesn't mean I'm saying everyone with a tattoo is gang member, it's just a way to start filtering.
The NSA analysts are presumably actually trying to get something done (find people they think are bad). How stupid do you think they are? If you were an NSA analyst, would you tag "person of interest" on everyone using PGP? How would that help your goal of finding actual people of interest?
They say they caught 300 "terrorists" with this program and other success stories. Presumably, they didn't achieve any success by wasting lots of time flagging random PGP users.
The article states that there is a query interface using the email address as the key. But Where does it say that every single email/webpage from every single person is being collected? Such a task would be technically impossible. It seems far more likely that it's querying a database of pretargeted people.
There is so much hysterical nonsense regarding this topic. The cancer of conspiracy theory spreads.
Arthur C. Clarke's first law of technology: 'When a distinguished but elderly scientist states that something is possible, he is almost certainly right. When he states that something is impossible, he is very probably wrong.'