I was doing similar things in the mid-1990s on shared Ethernet. It's really only a question of speed and scale and then of writing code that recognizes particular traffic (such as "this HTTP connection is a Facebook chat session").
I was doing similar things in the mid-1990s on shared Ethernet. It's really only a question of speed and scale and then of writing code that recognizes particular traffic (such as "this HTTP connection is a Facebook chat session").
The TSA can't crack or impersonate a cert at will; they can only 1) try to trick you into accepting a phony one or 2) demand/steal the private key from the site.
It does however give you the ability to issue yourself new public keys to conduct man-in-the-middle attacks [1]. If you compromise the same CA as the site whose traffic you're trying to intercept, you can bypass certificate pinning which is supposed to detect MITM attacks. So for example you can MITM gmail without certificate pinning detecting it if you compromise Verisign, Equifax or GeoTrust [2]
[1] http://googleonlinesecurity.blogspot.co.uk/2011/08/update-on... [2] http://src.chromium.org/viewvc/chrome/trunk/src/net/http/tra...
They're taking it a step further and using certificate pinning in Chrome to catch MITM attacks in real time across a large portion of the internet. http://blog.chromium.org/2011/06/new-chromium-security-featu...
It's not scalable at all, but cuts out a large attack vector for a lot of communications. It wouldn't take a ton of pinned certificates to make a big dent in these NSA programs--really just look at the logos and make sure that each has their certificates pinned.
I'm trying to understand why services are not taking a more active role in protecting their users' information if they are claiming to taking our privacy seriously.
To me, it comes down to being either incompetent or a liar, or both.
> * Show me all the VPN startups in country X, and give me the data so I can decrypt and discover the users.
> * These events are easily browsable in XKEYSCORE
As I understand it (and I may be wrong), most encrypted VPN traffic uses SSL. Given that XKeyscore data is only held for a few days (due to the immense volume) and given how nonchalantly they just throw out that they can decrypt VPN traffic, it sounds to me like they've either got the root SSL certs and are MITM'ing every connection they can or they've somehow broken SSL, either by breaking the actual encryption used or by exploiting vulnerabilities in how browsers handle it. If that's the case, then they don't need to ask Google or anyone else for your data, they can just read anything they want.
Even better would be for the NSA to penetrate Thwate, Verisign etc and make the keys they "generate" non-random (perhaps only for a subset of certificates sold)
Perhaps they own or subsidize many of the cheaper VPN like has been rumoured for Private Internet Access? https://www.privateinternetaccess.com/
We believe what the NSA is referring to when talking about "VPN startups" is the initial stages of PPTP sessions. PPTP has been crackable for a while, check out moxie's cloudcracker.com. We believe it highly unlikely that they have broken OpenVPN (which is what our application uses) or SSL.
Please see our stance on PRISM: https://www.privateinternetaccess.com/blog/2013/06/prism/
http://www.washingtonpost.com/business/economy/the-nsa-slide...