Jamming XKeyScore
blog.erratasec.com
blog.erratasec.com
Yet it would be trivial to defend against trivial attacks like this. They just need to set a length limit on ingested messages, clean up those regexes, and they're done. A clever NSA developer (of which I'm sure they have several) might implement a garden-variety spam filter.
We're trying to inject noise, but this noise is obvious. It's like a nation-state playing Cold War-era radio games by broadcasting "DOUBLE AGENT X COME HOME, DOUBLE AGENT Y COME HOME", etc. Sure it's noise, and it might distract them for five minutes, but it doesn't win the war.
Want to fight XKeyscore? Make the noise impossible to distinguish. Set up free email accounts that bounce randomly-generated "interesting" messages among themselves, in between notes to Mom about the World Cup. Get open source software that uses network communication to piggyback some keyword-laden (though non-incriminating) text onto messages it would send anyway. Run a Tor exit node that blocks illegal activity in your country (so you don't go to jail).
Or someone else should, at least. I'm busy. And now, I'm on a list.
edited to be more verbose
This is the federal obstruction of justice statute, could you point out the part that applies to jamming the illegal collection of inadmissible evidence by an agency that enforces no laws or regulations and conducts no criminal or administrative investigations or proceedings?
Wikipedia link on chilling effects: https://en.wikipedia.org/wiki/Chilling_effect
https://www.youtube.com/watch?v=PIPjmmmh_os#t=1614
He talks about how he and his associates were dissidents and had meetings and they agreed on a protocol to talk gibberish at the end. Fake, military sounding code words and stuff. It was a fun thing to do. Years later they discovered the amount of head-aches and resource drain they caused on the secret police who tried in vain to discover the meaning in this nonsense, thinking that perhaps there was some serious stuff going on.
That is why I hope one good thing comes out of it, and that is people might start taking cryptography slightly more seriously and they'll also start actively fighting back. This is one way and it is fun too. (for some strange value of "fun").
So what are we doing here? Let me tell you a wonderful, old joke from Communist times. A guy was sent from East Germany to work in Siberia. He knew his mail would be read by censors, so he told his friends: “Let’s establish a code. If a letter you get from me is written in blue ink, it is true what I say. If it is written in red ink, it is false.” After a month, his friends get the first letter. Everything is in blue. It says, this letter: “Everything is wonderful here. Stores are full of good food. Movie theatres show good films from the west. Apartments are large and luxurious. The only thing you cannot buy is red ink.” This is how we live. We have all the freedoms we want. But what we are missing is red ink: the language to articulate our non-freedom. The way we are taught to speak about freedom— war on terror and so on—falsifies freedom.
I, for one, am not aware of any. And that's the real big problem here. They all this sh1t, invade everyone's privacy, and to what ends?
*I am not talking about the NSA spying on non-US citizens.
edit: fixed link
Looks to me like a typical sample config file that you rename xkeyscorerules100 after editing just like how you would create /etc/udev/rules.d/51-android.rules or SELinux custom module policy before compiling.
edit not to mention that the source of these rules is from a non-verified document that is at least 2 years old and woefully incomplete.
The key is real, effective, targeting of that tiny minority who actually organise terrorist acts. Unless this is just some huge job creation scheme/security theatre for politicians.
It sure would be amusing if most of HN did this. Everybody has to do their part, right?