US and UK spy agencies defeat privacy and security on the internet
theguardian.com
theguardian.com
Not at all, now such laws going to be established across the world in order to "bring us in line with international law." Broad-sweeping and baseless surveillance is going to be called "nothing new" and "widely utilized for the benefit of law enforcement."
This is another effect of globalization -- if one government gets an advantage over another due to lax privacy laws then the rest have to follow suit.
The NSA's bottom line is this: If China has a Great Firewall and we can't have one, then we must have the capability to decrypt everything.
The zero-day exploit market[2] deserves fair mention too, especially since a variety of three-letter agencies across the planet are some of the largest purchasers. Zero-day exploit purchases and sales haven't had any news publicity at all, even though it's effectively comparable to trafficking nuclear warheads.
Both nuclear warheads and zero-day exploits are used as leverage between competing security organizations and competing nation states, both are being stockpiled, and both are exceedingly dangerous. We're on the cusp of global network warfare and it's just starting to become clear how terrifying and widespread it is. America's rivalry with China is in over-drive now.
I'm not saying that security researchers don't deserve to be paid for their work, but that we should be plain and honest about their work: it can be for the good of humanity or it can be for the destruction of humanity, there's very little inbetween.
And yet what is it for? Fighting terrorists and drug dealers, and protecting children and intellectual property?
[1] http://www.schneier.com/essay-146.html
[2] https://www.eff.org/deeplinks/2012/03/zero-day-exploit-sales...
Furthermore the splash damage from Stuxnet/Flame is a testament to the distinct lack of surgical precision normally afforded by missiles.
Also, zero-day exploits can retain their usefulness even after it's been deployed, meanwhile a missile is gone when deployed.
I was expecting more detailed evidence. How did they break SSL? Do they just have root certificate copies, or just the certs used for the certain specific sites that they're monitoring data transfer on passively?
The article claims that many VPN technologies are broken, but which ones? Are they talking about specific products here, or actual technologies in use?
The government wanted to use its treatment of Manning to deter leaking of future information, and it has already succeeded in doing so here. It's rule by intimidation, making our government little more than a well organized mafia.
However, some folks will want to know what's compromised to avoid becoming part of the collateral damage. I do, for example. Some other folks would like to know this in order to do some Forensic Economics. Like the mid-50s Central American coups, I imagine insiders could profit off this sort of thing in a big way.
It would be nice to know if the NSA has pushed Microsoft products solely because of the ability to influence weird little design decisions that could become trapdoors. That way, we could relieve the Linux people's big question about why the "Year of the Linux Desktop" never arrived.
The NSA does not hold control over the purchasing decisions made in countless governments and companies all over the world, for that to be a legitimate worry you'd have to show that in America linux was used substantially less where it should have been used compared to other countries. I doubt you could make that case convincingly.
-They can hack into people's computers (using zero day) and read the data before it's ever encrypted
-SSL/TLS do not offer forward security, so the encrypted data can be stored and then cracked if/when the keys become available later
-Man-in the middle attacks that substitute fake keys to both sides and capture the data anyway. It hepls if they captured one or more certificate authorities.
-Brute-force attacks against poorly-configured keys (too short) for SSL and VPNs.
* covert agents in companies -- * stealing certs -- * stealing plans -- * planting code
* direct (yet coerced) cooperation by the corps (goog, fb, etc)
* RNG prediction based on planted flaws in various components
* direct backdoors placed in certain mfr chips (see my comment about being told cisco was required to provide backdoors as early as 1997)
---
You're correct - that we knew that this was going to be revealed. We did not know if it was going to be "NSA's quantum computer the size of a datacenter cracks all encryption in real-time" or the above multi-vector attack.
What is important to see here though is that there is, effectively, absolutely NO escape from NSA eyes.
If you encrypt, they will get you. If you refuse them, they will shut you down. If you build a whole new service to thwart them - maybe they could even lean on PayPal to freeze your funds as well /tin-foil....
The three organisations removed some specific facts but decided to publish the story because of the value of a public debate about government actions that weaken the most powerful tools for protecting the privacy of internet users in the US and worldwide."
Was there a fuller version of this article available to the public at some point?
It's basically one globally conditioning effort to reveal and get the world to accept, there is utterly zero privacy. Everything you do is monitored and watched. Period. Oh - and we forcefully and violently protect our stealing of your income to fund this.
Laws need to be improved, but we may be able to find good point to point methods that don't rely on security methods with vulnerabilities baked into the silicon.
Take one wild guess at what that means.
Wonder what this means?
https://s3.amazonaws.com/s3.documentcloud.org/documents/7840...
>Appendix A lists specific BULLRUN capabilities.