Snowden Disclosures Finally Hit 12 on a Scale of 1 to 10
motherjones.com
motherjones.com
"For what it's worth, this is about the point where I get
off the Snowden train. It's true that some of these
disclosures are of clear public interest. In particular,
I'm thinking about the details of NSA efforts to
infiltrate and corrupt the standards setting groups that
produce commercial crypto schemes."
If anything this new information should put more people on the Snowden train. In the 90s, legislation was proposed which would have put backdoors everywhere via the Clipper Chip. Back then, we voted against that bill and all was good. This new information is shocking because we've already told the government that backdooring things was unacceptable behavior, yet they've done so anyways. We should all be outraged by this because it clearly doesn't represent the interest of the people.I refer you to Michael Froomkin's lengthy but readable analysis from 1996: http://osaka.law.miami.edu/~froomkin/articles/planet_clipper...
Of course, that isn't to say that this justifies recent actions or is really even relevant to the latest releases, but you made the connection.
From my understanding left-wing ideology has always placed the interest of the collective, represented by the state, over the interest of the individual. So the article and the author's conclusion seems to me completely in line with this way of thinking.
Anarchism, a doctrine that explicitly negates the State, is rooted squarely in the leftist camp as classically intended, and gives individuals freedom from being coerced in any collective action whatsoever.
You also have Libertarian Socialism, probably the most romantic of all leftist ideologies, which tries to bring collectivist and individualist theories together.
And then of course, the very source of the meaning of "left": the French Revolution, with its rights trifecta of freedom, fraternity and equality, which was born in complete opposition to the notion of the superiority of the State over individuals.
Saying "left-wing ideology has always placed the interest of the collective, represented by the state, over the interest of the individual" is like saying "right-wing ideology has always placed the interest of the rich, represented by the individual, to screw the poor, over the interest of society to improve as a whole" -- a simplistic mystification.
Sorry Kevin, I think you've gotten off the wrong train - you landed in the land of complacency.
Have you solved the problem of bright-line jurisdictional boundaries on the Internet? That doesn't just interest the NSA, it would surely interest tax agencies around the world.
The sentences that you quoted are examples of leaks that Kevin Drum believes were in the public interest. Kevin supports these leaks because they are about what the NSA chooses to do, and are therefore necessary for public debate about US policy.
Kevin clearly distinguishes between leaking NSA behavior (as in your quote) and leaking NSA capabilities (which is in the following paragraph). The ability to decrypt certain types of encryption is the sort of technological advancement that we should expect military and intelligence agencies to make and to keep secret.
Here's the part where Kevin talks about specific Snowden leaks (about NSA capabilities) that he disagrees with:
"But the rest of it is a lot more dubious. It's
not clear to me how disclosing NSA's decryption
breakthroughs benefits the public debate much,
unlike previous disclosures that have raised
serious questions about the scope and legality of
NSA's surveillance of U.S. persons. Conversely,
it's really easy to see how disclosing them harms
U.S. efforts to keep up our surveillance on
genuine bad guys. Unlike previous rounds of
disclosures, I'm a lot less certain that this one
should have seen the light of day."It tells us nothing about whether the NSA does more harm than good. That is the key point that distinguishes this leak from previous leaks. This leak does more to reduce the NSA's effectiveness than to improve the quality of public debate about NSA policy.
(Previous Snowden leaks make me suspect that the NSA does do more harm than good... but I can disagree with Kevin's conclusion and still respect his position.)
The vast majority of human history shows the powerful controlling the weak, usually through "legitimate" rule of convenient laws. Democracy, which inverts this with varying levels of effectiveness (the rich can still mostly buy their laws), is an aberration. But what the NSA has built is a turnkey system for an effective subversion of democracy: a database that can find anyone's dirty secrets, or, if necessary, plant the right kind of evidence.
It doesn't matter what the NSA has done so far. Sooner or later, someone with evil intent will use it. It's too much power, too centralized, too hidden, too tantalizing, for it not to be used.
And what is it all being built for? Stuff that is less risky than you getting in your car. There is zero existential threat to the USA from terrorism. It's not a credible excuse given the danger.
I think at this point we have to treat the NSA as guilty until proven innocent. Nothing they say, either to the public or publicly to our elected representatives Congress holds any water. How can we ever trust them again to be truthful?
If this argument is made convincingly in Congress, the NSA could lose funding, but that's a hard decision to make. Even if I am opposed to individual wars, that doesn't mean I would support complete disarmament. Foreign intelligence (and counter-intelligence) is an important part of any modern military. There needs to be public oversight without crippling US intelligence efforts. It's not clear how to accomplish that oversight. That is the discussion we really need to be having.
====
Edit: Looks like there is an official effort to increase oversight of the NSA. Quoting from a Sept 4 article on http://icontherecord.tumblr.com/
"On August 12, 2013 President Obama directed the establishment
of the Review Group on Intelligence and Communications
Technologies."
Link to the press release about this review group:
http://www.whitehouse.gov/the-press-office/2013/08/12/presid...That said, at the big crypt-a-geddon moment, when Leon Panetta said [1] "It does not mean that the Department of Defense will monitor citizens’ personal computers. We're not interested in personal communication or in e-mails or in providing the day to day security of private and commercial networks. That is not our goal. That is not our job. That is not our mission." he was lying. Both by omission and by commission.
And perhaps the most painful aspect of Snowden's act is that by exposing this failure of integrity in the NSA, they will never again be able to take the "high road" of we need this to defend the nation.
[1] http://www.defense.gov/speeches/speech.aspx?speechid=1728
He seems to believe that all commercial crypto is suspect; and there exists some other nebulous category called "strong crypto." D'oh! If only we had all been so smart enough to use this obviously better "strong crypto" instead of "commercial." It's meaningless. The NSA has it's hands in all the crypto cookie jars.
The NY Times slides:
http://www.nytimes.com/interactive/2013/09/05/us/documents-r...
give us some new details that have some usable specifics that can be gleaned.
Just some managment type in the government saying a single time that the government has made "major breakthroughs" in cracking SSL does not meet the standard of ETRAORDINARY EVIDENCE.
That's certainly one point of view, but it's not one I expected to see in Mother Jones, or on HN. Isn't the whole point of this uproar that we do not trust these unelected (by the US, never mind the global population) spooks with unfettered access to all communications?
Yes, however some people think "the government" can do no wrong because it "works for the people." The government they support also happens to be fighting a "War on Terror" where terror can include personal opinions that are critical of the American government and her corporate pillars[1][2][3][4].
Many still see distrust of government as indicative of mental illness, where such distrust is born from paranoia and anarchist/libertarian propaganda.
[1] http://en.wikipedia.org/wiki/Big_oil
[2] http://en.wikipedia.org/wiki/Pharmaceutical_lobby
[3] http://en.wikipedia.org/wiki/Media_conglomerate
[4] http://en.wikipedia.org/wiki/Iron_triangle_(US_politics)
The issue isn't the fact that the NSA snoops. That's their job and it has value when their power to do so is used judiciously. The problem is that its not being used judiciously. Rather than singling out as few people as possible to root out the bad guys their just collecting everything they can. They don't need to do this and doing so opens up the possibility for huge abuses of power. That's the issue.
I think the article is right that the crypto revelations aren't pertinent to this discussion. I would even consider the crypto revelations a red herring. Is it important how the NSA spies on everyone? No, its only important to know that they do it at all when speaking in the context of how the Snowden leaks are important to creating a national debate and, hopefully, by some miracle, create reforms.
I think its reasonable that as a US citizen you're okay with the NSA being able to break crypto. You just want to be able to trust that they're using it against the bad guys and not you. Even now that we know they're probably using it against innocent civilians its more harmful to the NSA's ability to go after the "bad guys" when they legitimately do (and they still do serve that purpose) and isn't really helping the debate over whether their over collection of data is okay and how to reform that system.
This is very interesting and got me thinking. I think that yes, in principle I agree, but there are limits.
I draw a distinction between types of "breaking encryption". There's the standard kinda that "anyone" can do: social engineering, secret mathematical hacks, 0day exploits, brute force attacks, etc.
Then there's the special stuff that only organizations in the position of the NSA can do: putting backdoors in cryptosystems (and pressuring commercial vendors to do so), influencing development of new cryptosystems to make them weaker, etc.
I'm ok with the first set of methods, but not the latter. When you weaken a cryptosystem, you weaken it for everyone, not just the people you want to be able to spy on. Even if the NSA's activities were completely above-board and their power was used appropriately, weaker crypto that everyone uses means that no one can trust their crypto, whether it's to secure corporate communications, keep discussion of an unpopular idea secret, or just trust that when you access your bank's website, a random attacker can't use an NSA backdoor to steal your banking info.
The incentives are aligned; crypto that only the NSA can compromise is far more valuable to the NSA than crypto that anybody can crack.
I think you have forgotten the phrase "absolute power corrupts absolutely." Humans with unchecked access to information (=power) will NEVER be completely trustworthy. Never. It is by definition. That's why we have checks and balances. That's why we had democracy. No one should be absolutely above democracy. But that's what today's NSA is.
You realize these guys (in the NSA) have been using intelligence resources to spy on their girlfriends and neighbors? How much more human and fallible does it get than that?
There are so many frightening powers out there, trying to prevent them from existing is a complete waste of effort. You simply cannot make it technologically impossible to shoot you with a bullet, or snoop in your house, or track your car. This is why gov't is regulated, and answers to the people. You simply cannot prevent everyone from having the technical capabilities to take the advantage of you.
So, IMO, forget about whether they can or they cannot. Even if you manage to prevent them from breaking strong crypto, if it can be done someone will do it. Focus on controlling what they do with it.
When every phone call can go through a voice recognition system and a set of filters to detect anyone talking about Topic X, that's a very different world. The NSA can't hire half the country to spy on the other half, but they can hire a few thousand people to build a computer system to spy on everyone.
Hey, look. The Internet. Whoops.
And they get caught and fired for it. Such stories even made the WaPo pages pre-Snowden.
Are you saying that any government agency which ever has any civil servant misuse their position should be shutdown?
I think that is by far the most important thing.
Imagine a hypothetical world in which it's been revealed that the NSA is spying on the entire internet through the means we generally expected them too, i.e. an army of super-smart crypto people and access to more computing power than God. What would happen following this revelation?
I anticipate that there would be outcry similar to what we've seen, followed by efforts to block their access. Companies like Google, Apple, Microsoft, all the tech heavyweights, would lead the charge. I think there'd be a lot of newfound interest in moving from crypto that's "good enough" to crypto that's deeply over-engineered. 1024-bit AES variant, anyone?
Instead, the NSA has gained their access largely through influence. This is smart, considering their mission. Why crack good crypto when you can just bypass it, or at least ensure that the crypto is not so good? It's certainly way easier. As far as we know, there's still no realistic way for them to crack a solid implementation of things like AES, so it's really the only way.
Are Google, Apple, Microsoft, et al leading the charge for better crypto in our world? No, because they're hopelessly compromised. Nobody trusts them, because the NSA has subverted all of them.
I anticipate that any new crypto, whether algorithm, system, or implementation, involving the United States in any way will be completely shunned. The US's tech giants will be shut out of a lot of activities. A huge chunk of the US's tech dominance will shift elsewhere. This will hurt the US economy and the US's security.
In short, the question comes down to, how do you avoid NSA spying? And that depends on how the NSA spies. If they spied due to math and computers, then you avoid NSA spying with better math and better computers. If they spied by broadly subverting a huge number of companies and organizations, as appears to be the case, then you avoid NSA spying by avoiding the American tech industry. This is tremendously damaging.
You could say that technically he wants the NSA to secretly have the ability to secretly snoop on anyone but somehow not use it widely despite the complete lack of oversight, the fact that they have done each time they were given the option, etc.
http://www.washingtonpost.com/world/national-security/obama-...
I have to admit though, I'm okay (as a citizen of any country) with my government's spy agency violating the privacy rights of citizens and foreigners when it's done in a targeted way. There's a big difference between spying on a person and their network of connections because you've got some evidence to suggest something bad is coming from them and just collecting everything you can and looking for reasons to go after people after the fact. The former is how it should work, the latter is how its being described now.
Because the world is divided to US citizens or the bad guys? C'mon, there is a non-US world out there, who are not bad guys, but who've just lost every respect for the US tech sector.
Yes, the Snowden disclosures have tipped many people (who were on the fence) toward an active dislike of what US intelligence agencies are doing, but I think there is still a very large percentage of people -- perhaps even still a majority -- who truly think all this makes them safer, and that the cost is worth it. I won't pretend to understand that point of view, but... there it is.
Do you think these initiatives are strictly done at the NSA level? At one point an elected official (being the top of the chain in the executive and the legislative) agreed to this stuff happening.
In what universe do we build a government where everyone is an "elected official"?
Personally, I can't blame the NSA for trying to intercept and read lots of "suspicious" internet traffic: that's their job. Governments do this, and whether it's good or bad, it's expected. (I'm not happy about the degree to which the NSA seems to be stretching the rules against them acting domestically, nor am I happy about massive all-encompassing interceptions rather than targeted ones, but those are separate issues.)
So there really is a legitimate argument that these latest Snowden disclosures damage national security. The thing is, they also indicate that the NSA has been doing its expected work by actively weakening the protections that we (and large parts of the global economy) depend on. Their actions and strategies have also undermined global confidence in American technology companies. And those are factors that I think the average watcher (like the author of this article) may not recognize unless folks like us point it out.
"Nothing you do online is anonymous. There is a record of everything you do."
He understood it right away and ( I think ) has always treated everything online as public. No need to go into any technical details.
Recall, for example, Glenn Greenwald's admission that he "almost lost one of the biggest leaks in national-security history" because Snowden initially insisted on communicating with strong crypto and Greenwald didn't want to be bothered to install it.
What exactly did Snowden insist Greenwald do, precisely? Whatever Snowden insisted on, it's guaranteed to be an NSA-proof method of communication. So it seems like it's an essential first step to figure out the details and train people to use it habitually.
As tptacek and others frequently say: "Crypto is hard to do right".
There is sufficient encryption technology to evade the NSA (at this point in time) but the social-engineering aspects and difficulty confirming a bug-free, secure implementation present the most issues.
EDIT: Ah, it appears to be confirmed at http://www.huffingtonpost.com/2013/06/10/edward-snowden-glen... ... Thanks!
Second paragraph into the article describes Snowden's requirement to use PGP while contacting Greenwald at the least (although it's a tertiary source and very sparse in technical details).
It's not enough to merely tell people "install PGP." Snowden presumably went into meticulous detail about precisely how to be completely secure. Even something small like "here is the exact exe installer to download" is probably significant, because that would mean that specific installer is clean and free of NSA tampering.
Bruce Schneier has said something similar, having seen some of the guardian documents. https://www.schneier.com/blog/archives/2013/09/the_nsas_cryp...
[1] http://www.huffingtonpost.com/2013/06/10/edward-snowden-glen...
I wish Greenwald would publish that step-by-step email. It's probably one of the most valuable HOWTOs ever written, because only Snowden (and his colleagues) know for a fact what steps are NSA-proof.
Glenn Greenwald is really not very technical at all, so I imagine it was really about getting GPG installed and an appropriate plug-in for his mail client. I actually bet most of the e-mail was spent explaining why he needed to do this, because even now people are still reluctant to use GPG. There's been no explosion in it's use. People are still lazy.
But this is just the logical conclusion if you believe: a) Crypto math works b) The NSA has zero-day exploits for every system.
But to anticipate those who will say, "do you think the bad guys are really dumb enough to use basic encryption techniques?" -
The 1993 (failed) World Trade Center bombers were caught because they went back to the rental truck company to try to collect the deposit on the "stolen" truck.
So yes, some of them certainly are.
I'd imagine the NSA is concerned about future intelligent adversaries who have finesse, which is why they stay as far as possible ahead of the curve.
(I'm trying to come up with an alternative to our standard explanation of "the NSA does this because it's a soulless governmental machine that wants access to the world's information for corrupt purposes.")
I'd imagine the NSA already has such adversaries. Note how difficult it appears to be to track down members Al-Qaeda, and how relatively well-informed bin Laden's hiding scheme was. There are doubtless also other less-publicized malicious operations of the same breed.
Well, that's the problem with trying to keep everything secret. If the majority of these "disclosures" were in the public interest - they should have been public knowledge. That would have made it far less likely for someone like Snowden to feel the need to "blow the whistle".
There is such a thing as a "presumption of trust", which the NSA has squandered. They likely had it before these leaks began, but now they have lost it, no-one listens even when they might have a good point.
The distinction matters here since we're meant to believe that most "bad guys.. figured that ordinary commercial crypto provided sufficient protection." But this translates to, they trusted Google, Microsoft et al. That seems less likely to me.
Disclaimer: I am not a cryptographer or security researcher. (On the other hand, given that I've done various kinds of antiwar political organizing and associated with members of Muslim Student Associations whose infiltration by NYPD later became a matter of public record, maybe I can speak as a government-classified "bad guy!" I should really do an FOIA request one of these days...)
In fairness, it would be grossly unprofessional if they did not. The three letter agencies take pride in their craft and part of their job is staying in front of any wide spread encryption technology.
Backdoors, bought or coerced. If I obtain crypto capability, I expect it to be at least as good as advertised.
Or, in other words, they went to the public in the 90s and asked for Clipper. They were denied. So they went against the public and implemented what they were told, by their supposed masters, that they couldn't have.
If your dog is eating your children, is he your dog?
So far, I do not think the NSA has lost any of the capabilities it previously had. I have not heard of any NSA backdoors being removed from existing software.
> Nonetheless, this is truly information that plenty of bad guys probably didn't know, and probably didn't have much of an inkling about. It's likely that many or most of them figured that ordinary commercial crypto provided sufficient protection ...
> Now every bad guy in the world knows for a fact that commercial crypto won't help them, and the ones with even modest smarts will switch to strong crypto techniques that remain unbreakable.
If you accept that most bad guys were using commercial crypto and not strong crypto, NSA may have been tapping communications but now won't be able to
They're also an item of debate now, which could potentially result in loss of capability further on. At the next round of elections, Democratic candidates will likely have to defend an unpopular intervention in Syria, they'd rather not add to that pile a defence of some invented Federal right to unwarranted spying on everyone's communications; and it's a potentially easy target for small-government Republicans.
In the bizarre logic of American politics, Republicans and Democrats are both pro-NSA, while the Greens and Libertarians are anti-NSA.
[1]http://www.globalpost.com/dispatch/news/afp/130711/kremlin-t...
I think the rest of the article is hyperbole too, but not much more than that.
The capability to decrypt everything is largely outside of their control, however they can exert pressure of ISPs, SSL certificate authorities, commercial software vendors, social networking services, and a variety of other organizations.
The rationale being that the US Government pressures those organizations to intentionally implement weaker security measures to facilitate the ongoing capabilities of the government's suspicionless surveillance systems.
Since this system of clandestine supportive relationships is potentially unreliable (since it is directly outside of their control and it relies on reciprocal partnerships) then it stands to reason that the simply revelation of these relationships could jeopardize the US Government's surveillance capabilities.
Integer overflow!
This one doesn't just go to eleven. Twelve is greater than eleven.
"No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks."
More than that, we need the names of those involved.
I don't think people would have reacted the same. On this subject i believe what piss people off is the mean rather than the result. Somehow people hoped for a smarter NSA, not for a meaner one.
But that's a bit naïve isn'it ? After all they're here to save lives in the end.
This really means that thousands (hundreds of thousands?) of people which ultimate goal is to get money, and have little to none auditing on what they do, some NSA employees, some from private companies, can access your trade secrets, your bank account, or whatever that can be used to blackmail you, and make any kind of profit from it, no matter from where you are, or who you are. And that won't be even noticed by the authorities (if they even care, they have the "state secret" wildcard) unless they become public on that (they noticed what Snowden did because he went public, on pourpose). And that also means that that information (that they are "careful" having it safe) on which vulnerabilities they introduced on pourpose on every kind of "secure" software, if ever leaks, get reverse engineered or found out by luck, will be exploited by the bad guys too.
Hanlon's razor is not an excuse for this kind of article anymore.
This quote was particularly eye opening to me.
In the early 2000's I remember speaking to a Verizon engineer who said their encryption on CDMA was bulletproof. He went on to explain over the course of an hour how impossible it was to crack their encryption or even eavesdrop on their network.
See page 34 here: http://www.scribd.com/doc/22599374/Security-Encryption-in-GS...
"The security protocols with CDMA-IS-41 networks are among the best in the industry. By design, CDMA technology makes eavesdropping very difficult, whether intentional or accidental. Unique to CDMA systems, is the 42-bit PN(Pseudo-Random Noise) Sequence called “Long Code” to scramble voice and data. On the forward link (network tomobile), data is scrambled at a rate of 19.2 Kilo symbols per second (Ksps) and on the reverse link, data is scrambled ata rate of 1.2288 Mega chips per second (Mcps). CDMA network security protocols rely on a 64-bit authentication key(A-Key) and the Electronic Serial Number (ESN) of the mobile"
Here's an idea: if you don't want your neckbeard anime discussions pinged by the world's intel/ad agencies, don't digitize and broadcast them over the internet.
That's a statement designed to mislead.
"the adversary" certainly assumes that the NSA does what it does and acts accordingly.
Now, if "the adversary" is the general public, then the statement actually makes sense.
EDIT: The consumer is indeed part of "the adversary":
Extract of one of Snowden's documents: "These design changes make the systems in question exploitable through Sigint collection … with foreknowledge of the modification. To the consumer and other adversaries, however, the systems' security remains intact." Taken from http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryp...