XKEYSCORE: NSA’s Google for the World’s Private Communications
firstlook.org
firstlook.org
I'd always naively assumed that working at this scale would guarantee leaks much, much earlier.
Also, we knew the FBI was doing this in the 90s so it shouldn't be totally surprising to find the NSA doing it now.
The scale is the awesome data processing and operative capabilities. But is that so surprising to remain secret? I'm sure the NSA and other parts of big governments do all sorts of nifty shit and manage to keep it quite much longer than a decade.
It's just that... you know... literally no one wanted to talk about how a US military department was using capabilities traditionally described as acts of war to subvert US infrastructure and analyze the behaviors of US citizens. There were terrorists!
Just like they didn't want to talk about it in the 90s, when the US government tried to claim that encryption was a regulated government technology and while US citizens are technically entitled to munitions, something something 2nd amendment, if you export anything more than 44 bits, you're in serious trouble.
Now yes, the scope is amazing. And I was getting this technical excitement just reading the system. So many questions! Like, how do they distribute jobs fairly or deal with resource over use? What stops some dumbass oper from submitting a super-expensive query? How do they manage all this stuff? It's pretty damn neat.
I'm wondering what the impact of TLS is on all this. Cause it seems like that'd sort of destroy this system, eh?
Edit: https://www.documentcloud.org/documents/2116191-unofficial-x... - Interesting how they are really explicit how USSID 18 stops them from doing stuff. Like they give the example of finding a phone number without a country code. Not allowed! Unless you combine it with something that'd limit it to foreign countries. But they note it's not a 100% solution.
For example this one: https://www.documentcloud.org/documents/2115979-advanced-htt...
They are saying: are you unsure if an IP is a proxy? Well, given that you know so little about it, query all the users on the IP... you know, as long as the IP is USSID 18 compliant... given that you know so much about it already.
Hrm.
As a practical matter, what more can they do? I wouldn't expect them to actively try to give up on following leads. Seems like the intent of the law is being attempted to be followed.
https://www.documentcloud.org/documents/2116268-web-forum-ex...
It says they have "full take for US web forum servers under FISA coverage", and "passive collection for OCONUS [outside continental US] web forum server traffic". What does "FISA coverage" mean? They have warrants for specific forums, or a general warrant giving them access to thousands of forums?
I run a fairly large OCONUS message board. Are my visitors all in XKEYSCORE? I wish the release were more specific.
Traffic outside the US is collected, but probably doesn't need any approval to look at. I'd suspect that all your visitors are in XKEYSCORE.
I suppose I can have the BBCode alter the URLs to point to my domain, and use nginx to proxy the image loads. I'd have to be careful to make sure users can't proxy malicious scripts and stuff into the page (because it'd be same-origin); is there a standard solution for this?
> Chinese webmail users
> Iranian webmail users
Oh.
http://www.slate.com/blogs/future_tense/2013/07/31/xkeyscore...
It's also more efficient to just tap the connections of the users' ISPs, rather than tap each home. And since they're tapping backbones, a VPN will only help some. It'll limit the ability for them to easily search you via IP - they'll need to try to distinguish your traffic from the other users on the proxy/VPN. I didn't see anything about correlating timing information, and it'd seem like that'd be a much more difficult thing to analyze versus indexing HTTP requests.
But if you read the slides, the instructions to operates are VERY clear to never use this data (passwords and such), but only pass it on to TAO. I'd guess they'd want to be really certain before doing something active/noticeable which might involve spending some sort of identity.
Remember, most of these things have as their only threat model someone trying to gain access from the Wi-Fi side before authentication. I doubt many vendors seriously consider questions like "can the cable connection to the ISP be used to take over the router?" or take steps to prevent it. For many devices, that sort of access could be considered as a potentially legitimate feature (think, customer support and remote diagnostics).