HNHacker News
TopNewBestAskShowJobs

csandreasen

719 karma · joined March 26, 2011

submissionscomments
csandreasen··on Dual EC: A Standardized Back Door [pdf]
Alternately, it could just be that Certicom saw a means to profit off of an emerging standard by modifying it to support key escrow. It's not like key escrow in general was something that no had thought of before in 2005. If this was an NSA backdoor, why would the NSA reveal it publicly by having Certicom patent it? Not to mention that it this was a horribly unpopular algorithm long before any suspicion of it being a backdoor. If it was an NSA campaign to break public cryptography, it was a miserable failure long before Snowden ever hit the scene.
csandreasen··on Dual EC: A Standardized Back Door [pdf]
I think that this is overall a good paper, but I have one major issue with it. They quote from a presentation given by Richard George from the NSA twice in this paper. I had seen that presentation before, and in it he speaks to why the algorithm was put in the NIST standard[1] and directly answers a question regarding how the P and Q in the standard were generated[2].

His claim was that the NSA had issues in the past getting encryption devices certified for use in unclassified environments because NSA controlled the certification process for classified encryption algorithms (which were themselves generally classified), but NIST controlled the certification for government use in unclassified settings (and these algorithms could not be classified). The NSA wanted to be able to use an existing algorithm in an unclassified setting. As the article does point out, Mr. George stated that the algorithm was intended primarily for their own internal use and user should be able to use any P and Q, though they needed their own P and Q certified for their own use.

Later on in the presentation he states that the P and Q were both non-deterministically generated random numbers. He states that the NSA has office devoted specifically to producing random numbers for their own use, and they just got the P and Q from there.

Whether or not you believe this claim is an entirely different and reasonable question (there's no real way to verify it), but why bother quoting him if you're going to selectively quote like this? If the P and Q are in fact purely random as Mr. George claims, Dual_EC goes from being a grand conspiracy to just a slow, crappy PRNG. I think selectively quoting to make this guy sound more sinister makes it look like the author wants it to be a grand conspiracy and just undermines the argument.

Btw., the entire presentation is worth watching if you have time - he goes into the history of DES, espionage between the US and Soviets, getting cryptographic equipment working in tanks, etc...

[1] http://vimeo.com/97891042 (jump to 57:53)

[2] Same video, jump to 30:14

csandreasen··on Artificial Killing Machine
If you consider drone strikes to be indiscriminate, compare the upper bound of about 6,000[1] or so drone strike casualties over more than a decade to the 90,000[2] or so Vietnam bombing casualties, which in turn is dwarfed by the World War 2 bombing casualties[3]. Compared to the alternative of using traditional bombers or using ground forces, drone strikes represent a huge reduction in civilian casualties.

I don't understand the people who protest drone strikes. War is hell - if your country engages in any sort of violent military intervention, there will be civilian casualties. I can get behind opposing unnecessary usage of military force; I can get behind opposing attacks within the borders of a sovereign nation that we aren't at war with. Protesting the tools used to conduct war instead of the war itself makes little sense to me, particularly when that tool marks a dramatic improvement in reducing civilian casualties.

[1] https://www.thebureauinvestigates.com/category/projects/dron...

[2] http://thevietnamwar.info/operation-rolling-thunder/

[3] https://en.m.wikipedia.org/wiki/Civilian_casualties_of_strat...

csandreasen··on Der Spiegel Targeted by US Intelligence
I'd like to think that discussions on HN ought to be a little more rigorous than dropping unexplained links to a pre-FISA purely domestic FBI program from half a century ago when discussing today's interactions between the CIA, German government and German press...
csandreasen··on Der Spiegel Targeted by US Intelligence
> How do you know it?

The burden of proof rests on the person alleging it happened, not the person saying there is no evidence. You're asking me to concede that something must have happened in secret unless I can prove a negative. To top it off, Der Spiegel very strongly suggests that they just recently learned of the matter in the editor's note on the left hand of the page. Nowhere in their reporting (or, to my knowledge, anyone else's reporting) are they claiming that the government forced them to withhold a story.

> FOIA records on FBI and CIA show again and again ...

Could you provide links to these FOIA documents?

csandreasen··on Der Spiegel Targeted by US Intelligence
Reading through that paper, it seems pretty clear that the author is discussing the rights of foreigners inside the US. The idea that the US should be upholding US constitutional rights for non-US citizens residing in another country's sovereign territory is not something that legal scholars are arguing.
csandreasen··on Der Spiegel Targeted by US Intelligence
How so? Der Spiegel didn't even know they were being spied on (that is, assuming they were). No one stepped in to prosecute them, no one threatened them, and no one interfered with their ability to publish any story. If anything, that fact that nothing has come of this since the leaker was discovered back in 2011 sends a clear signal that the German press can publish any story it likes and their government won't lift a finger to interfere.
csandreasen··on Der Spiegel Targeted by US Intelligence
A couple of things...

1) The first half of the headline reads "An Attack on Press Freedom". How exactly was freedom of the press attacked? Did the US or German governments stop Der Spiegel from publishing something? Were they blackmailed into suppressing a story (but for some reason not so for this one)? As far as the story indicates, the only action that was taken was to move the person accused of leaking from one department to another. But, hey, "An Attack on Press Freedom" gets more people to view those 9 ad banners scattered throughout the article...

2) I just read this article twice over, and I can't actually see any evidence that US intelligence services were targeting Der Spiegel. Somehow the CIA station chief finds out that someone in the German Department Six is passing information to Der Spiegel, and informs the head of Department Six. They don't actually give any indication as to how the CIA got that information, but just state that it was most likely the NSA spying on Der Spiegel as if it were a foregone conclusion. How do they know this? I can think of a number of other situations where the CIA may have received this information...

  - The CIA had a source inside Der Spiegel
  - The CIA was spying on their source (not Der Spiegel)
  - The NSA was spying on their source
  - The CIA/NSA was spying on a third party that knew of the leaks
  - The source was drunk at a bar and bragged about it to or within earshot of a CIA agent
  - One of the journalists was drunk at a bar and bragged about it.
  - The CIA/NSA was spying on Russian intelligence (or any other country in the region) and that foreign intelligence service was doing any of the above
  - etc. ...
I accept that they don't want to reveal their source, but there's no mention of an anonymous source, or documents acquired by Der Spiegel, or anything else substantiate the US targeting the news outlet. As far as I can tell, this is the extent of their attribution:

Research conducted by SPIEGEL has determined the existence of CIA and NSA files filled with a large number of memos pertaining to the work of the German newsmagazine.

Really? That's it? They somehow know that documents exist which somehow make reference to a global news outlet known for breaking headlines concerning the work of these intelligence agencies? What kind of research was conducted, and what do these documents actually say? For god's sake - Der Spiegel is one of the few news agencies that has the whole Snowden trove and regularly releases documents from it, but they can't show anything from there proving their claim?

Not too long ago, the Sunday Times in England ran a story claiming that documents stolen by Edward Snowden were in the hands of Chinese and Russian intelligence services, relying solely on anonymous sources in the British government. They were rightly lambasted for it in a number of other media outlets. Der Spiegel is now doing almost the exact same thing.

csandreasen··on FISA court rules NSA can resume bulk data collection
> A pair of judges ... Do they spend an hour? A whole day? A whole week? All we have to go on is one vague article.

The FISC has its own website which happens to answer your question right on the "About" page[1]:

The Court sits in Washington D.C., and is composed of eleven federal district court judges who are designated by the Chief Justice of the United States. Each judge serves for a maximum of seven years and their terms are staggered to ensure continuity on the Court. By statute, the judges must be drawn from at least seven of the United States judicial circuits, and three of the judges must reside within 20 miles of the District of Columbia. Judges typically sit for one week at a time, on a rotating basis.

> ...and that article suggests that (if we accept they rotate duty and meet monthly say) they spend, on average, (8 hours / 133 * 60 minutes) ~3.5 minutes carefully evaluating each application. If not, it's ~30 seconds per application.

No, the article says 33 per week. The judges aren't meeting together every few months; the sitting judge is replaced by the next every week or so. Assuming an 8 hour work day and 33 warrants per week, that (8 * 5) / 33 = 1.2 hours per warrant on average.

[1] http://www.fisc.uscourts.gov/about-foreign-intelligence-surv...

csandreasen··on New WikiLeaks Documents Reveal NSA Spied on French Companies
> Could you provide a similar list ...

I may very well be able to do that, but it wouldn't do anything to disprove the notion that Wikileaks has a pro- Russian, anti-US bias.

I see two simple reasons for the lack of Russian coverage at Wikileaks: either Russians aren't providing material, or Assange isn't publishing it.

csandreasen··on New WikiLeaks Documents Reveal NSA Spied on French Companies
You could accuse him of being a shill if he repeatedly appeared on the BBC solely to advance the policies of the British government. Assange didn't merely appear on RT, he hosted a weekly show on RT entitled "The World Tomorrow with Julian Assange" which featured a who's-who of US critics. That's a bit more than an occasional appearance on BBC.
csandreasen··on New WikiLeaks Documents Reveal NSA Spied on French Companies
After surfing around https://wikileaks.org/wiki/Category:Countries for a minute or two:

  - Category:Russia - 57 pages total
  - Cyprus - 54 pages
  - Latvia - 50 pages
  - Lithuania - 47 pages
  - Estonia - 46 pages
    ------- 
  - Japan: 90 pages
  - Italy: 99 pages
  - France: 128 pages
  - Canada: 153 pages
  - Germany: 278 pages
  - United Kingdom: 384 pages
  - United States: 9729 pages
Interesting set of priorities they have there... I'm curious as to why a G8 country has as much information posted as a country with 1/140 its population.
csandreasen··on The privacy paradox: The privacy benefits of privacy threats [pdf]
I'll provide a quick TL;DR as the paper is somewhat lengthy but I think the message is worth discussing:

Much of what privacy advocates focus on in terms of privacy violations on the internet neglect to take into account privacy gains from those same technologies. A key factor to this is focusing on what information is being shared but neglecting to account who it is being shared with and the privacy benefits associated with interacting with that service instead of traditional alternatives. For example, Google can see every search a person conducts regarding their sexual preferences. However, a closeted homosexual might turn to Google to find social and support groups because they're afraid of judgement from their family and peers. Groups like the EFF would say that buying a book through a Kindle is awful for the privacy of the reader because Amazon tracks the fact that you specifically bought the book and can see when you're reading it and even what page you're on - but most readers don't care that Amazon knows they're reading 50 Shades of Grey; they'd rather that everyone else on the subway just sees them reading their Kindle instead of an erotic novel paperback.

In general, people are more afraid of having their sensitive personal details disclosed to the people they interact with in person - their families, friends, coworkers or even the checkout lady at the pharmacy. The loss of privacy to a remote party like Google is worth the net gain in privacy to avoid disclosing embarrassing information to people they are more concerned with. This is also dependent on the type information being disclosed - the set of information that you'd want to keep from your friends is not the same set that you'd want to keep from your spouse, which is not the same as what you'd keep from your coworkers, which is not the same as what you'd hide from the police.

For those that would prefer an audio version, Ben Wittes gives a good discussion of it on the Lawfare Podcast at http://traffic.libsyn.com/lawfare/Episode_129.mp3

csandreasen··on Breakdown of the NSA spying on French leaders
All of what you just provided are examples of methodology. What GabrielF00 was referencing is something like "Prime Minister Alice contacted Secretary Bob and discussed their recent dealings with President Carol." This is different from saying "This information was obtained by tapping Secretary Bob's Skype account", which in turn is different from saying "The NSA can tap Skype accounts." Most of what we've been seeing in the news is stuff like "The NSA can tap <technology>", and occasionally "the NSA spied on <person/group/country>" rather than "the NSA obtained <specific information> from <specific person> on <specific date>", which is what we're seeing with the recent Wikileaks disclosures.
csandreasen··on Breakdown of the NSA spying on French leaders
That's nothing new - the Electrospaces site has called into question the claims of Snowden and Greenwald on numerous occasions. For example:

- Snowden would not have been able to legally "wiretap anybody": http://electrospaces.blogspot.com/2015/02/snowden-would-not-...

- Snowden-documents show no evidence for global mass surveillance: http://electrospaces.blogspot.com/2014/06/snowden-documents-...

- Document shows that it was not NSA, but FBI that monitored 5 Americans: http://electrospaces.blogspot.com/2014/07/document-shows-tha...

- Screenshots from BOUNDLESSINFORMANT can be misleading: http://electrospaces.blogspot.com/2013/11/screenshots-from-b...

csandreasen··on Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs
I know I'm late to the conversation, but Bruce Schneier posted an update on the Lawfare website: http://www.lawfareblog.com/do-russians-and-chinese-have-snow...
csandreasen··on US hit by 'massive data breach'
> Perhaps you could go further and tease out why...

I suggested it for much more mundane than you suggested: Google is likely to have valuable political, economic and political information because politicians, businessmen and service members have personal Google accounts, and employees are the weakest link in an organization's security. I don't think anyone's going to be sending out the designs for the next stealth fighter over Gmail, but plenty of people would be sending out innocuous documents, contact information, personal problems, etc. Intelligence services thrive on innocuous information in aggregate.

csandreasen··on US hit by 'massive data breach'
> You being in the role and expertise that you are...

I didn't mean to imply that I have any inside knowledge of the hack - I'm basing my views on this from what I've read in news outlets. I doubt I have any more knowledge on the subject than you. (Unless I'm misinterpreting sarcasm on your part)

> China and the US hack each other for strategic purposes and that when China hacks the US it is not about dissidents.

The Chinese intelligence services are going to focus on targets that will forward their own national goals. This will off course include strategic goals such as increasing economic and regional military influence, but don't discount their desire to maintain internal stability. They invest a significant amount of resources into controlling content on the internet and other media venues. In recent memory, their Great Firewall infrastructure was used to target dissidents hosting their materials within the US (which incensed the HN crowd with the whole Github DDOS).

There's plenty of good reasons for China to target Google. They have every reason to distrust Google as the US government has to distrust Chinese tech companies, and there's bound to be a wealth of information on their servers useful for counter intelligence, economic, political and likely even military gain as well. I don't we'll ever know exactly what all of their reasons were for breaking in, but I don't think the theory that one of the primary motivations was targeting dissidents can be waved away as just spin.

csandreasen··on US hit by 'massive data breach'
I think the point you're trying to make is that this database of accounts under FBI surveillance is such a juicy target that it enticed China to go after Google. If the database didn't exist China wouldn't have had a reason to break in.

You have a point, but I don't think it applies in this situation. Google was a valuable target for Chinese intelligence for a whole variety of reasons. Google itself suspected that the primary motivation was to gather information on Chinese activists that were using the service.[1] The fact that there was apparently a database of FBI targets is just added benefit for them, and there's no evidence that I've seen to indicate that they knew of the database to begin with.

[1] http://www.independent.co.uk/news/media/china-google-cyberat...

csandreasen··on FBI: Companies should help us ‘prevent encryption above all else’
There are a few federal cases that say otherwise. In US v. Kirschner[1], it was ruled that forcing the defendant to reveal his password through a grand jury subpoena was a violation of his 5th Amendment rights. The prosecution used a loophole for In re Boucher[2]: though the defendant still had a 5th Amendment right to not reveal his password, he was required to decrypt his hard drive in order to produce files under subpoena that he had already admitted were in his possession. Because he had already incriminated himself by revealing to a border patrol agent that his laptop contained child pornography, he no longer had a 5th Amendment right against self-incrimination for the charges of possessing child pornography.

As I mentioned in a post above[3], in the case against Ramona Fricosu she didn't have a 5th Amendment right to not produce her password partly because she was granted immunity for any evidence that would have been collected from it (but her husband would not be). If you have evidence of a crime, you are required to provide to the courts when requested. You have the right to not provide evidence or testimony which incriminates yourself - if you cannot be incriminated for it, you no longer have the right to withhold it.

[1] http://cyb3rcrim3.blogspot.com/2010/04/passwords-and-5th-ame...

[2] http://cyb3rcrim3.blogspot.com/2009/03/5th-amendment-bummer....

[3] https://news.ycombinator.com/item?id=9662945

csandreasen··on FBI: Companies should help us ‘prevent encryption above all else’
Eventually her husband provided the cops with the correct password[1]. The 5th Amendment prevents you from providing testimony that would incriminate yourself. In this case, though, she was being compelled to decrypt the laptop to produce evidence against someone else - Ms. Fricosu was granted immunity against any evidence collected from the laptop[2], so she didn't have any 5th Amendment grounds. In general, a Grand Jury has the right to subpoena any evidence from a third party that is relevant to a criminal investigation, and you can be held in contempt if you don't produce it. She had already admitted in a wiretapped conversation that there were documents relevant to the case on the laptop, the laptop was in her possession and that she refused to give them the passwords.

[1] http://www.denverpost.com/ci_20080656

[2] http://www.wired.com/images_blogs/threatlevel/2012/01/decryp... (p.9)

csandreasen··on FBI: Companies should help us ‘prevent encryption above all else’
Jesus Christ - way to bury the lead. The headline reads 'prevent encryption above all else', but three paragraphs in:

"But Steinbach's testimony also suggests he meant that companies shouldn't put their customers' access to encryption ahead of national security concerns -- rather than saying the government's top priority should be preventing the use of the technology that secures basically everything people do online."

Here is the actual hearing: http://www.c-span.org/video/?326360-1/hearing-cartoon-contes...

The hearing was concerning ISIS use of social media as a recruitment platform and how it related to the recent shootings in Garland, Texas and in Boston on Tuesday.

The subject of encryption is not the primary focus of the hearing, but when it does come up I think he makes his point clear at about 39:30 when says this: "I think we need an honest conversation and get past the rhetoric of what we are talking about. We're not talking about large scale surveillance techniques. We are talking about going before the court, whether the criminal court or the national security court, with evidence, a burden of proof/probable cause, suggesting a crime has been committed or in our case there is a terrorist and showing that burden of proof, having the court sign off on it, and then going to those providers and requesting access to the stored information or communications that's ongoing. So we're not looking at going through a backdoor or being nefarious - we're talking about going to the company and asking for their assistance. We suggest and we are imploring Congress to help us seek legal remedies to that and asking companies to provide technological solutions to help that. We understand privacy. Privacy above all other things including safety and freedom from terrorism is not where we want to go. "

He later goes on to suggest expanding he scope of CALEA to include more than just telecommunications companies.

If people are going to debate this topic, I think they should start from his actual position and not a half sentence soundbite.

csandreasen··on Show HN: Hacker News reader for Android
Those UX elements are actually part of the OS and appear in every app. The triangle is "back", the circle is "home" (essentially the same thing as the circle button on iOS), and the square button opens the list of recent apps.
csandreasen··on Replacing welfare payments with “basic income” for all is alluring, but expensive
The US spends $454B on welfare programs[1], but has a population of 321M. If you scrapped the existing welfare program in favor of BI, you'd be able to give everyone only $117 per month. You can make adjustments for things like children not requiring as much, but we're still nowhere near a livable wage.

[1] http://www.usgovernmentspending.com/year_spending_2015USbn_1...

csandreasen··on Jonathan James and Aaron Swartz-Two Obituaries One Prosecutor
> At which point it doesn't matter whether you know an intrusion has occurred, you have to treat it as though it had...

Which gets you into benefits/trade-offs territory; I think it's probably an overreaction for NASA to take their internet facing servers and all computers on the connected networks down to investigate for possible intrusions every time a new security patch comes out. I don't think it's unreasonable for them to do so when they have credible evidence that they've been hacked. (of course, I don't work for NASA, so I have no idea what procedures they have in place)

csandreasen··on Jonathan James and Aaron Swartz-Two Obituaries One Prosecutor
> The sensible first response when you find a vulnerability is take a snapshot of the existing system ... without having to disable the production systems.

Which would involve taking the system down to conduct the snapshot. What gets put back in place will depend on the severity of the breach, perceived threat, sensitivity of data, etc. They had no way of knowing exactly how sophisticated the attack was until the cops finished their investigation - is this some script kiddie or the Chinese military? I'm not going to worry about a foreign intelligence service if I'm serving up web pages for an eCommerce site, but I would if I were working for NASA. Just because you patch the vulnerability in question doesn't mean you've denied the attacker access to your network...

If they suspected additional backdoors have been added during the breach, the affected systems would need to rebuilt entirely, patched, then have data selectively restored from backup (you don't want to reintroduce to the system any malware that was saved to a backup). What other systems were accessible from the one that was hacked? Are there rootkits sending beacons home on any of them? Is there reason to preemptively take them down and rebuild them? What if one of the affected systems is a mail server/file server/etc.?

No, I don't blame NASA for overreacting. The kid pulled back technical details for a space station. The Russian government would have done the same (and may even have already been in there). NASA took steps that they thought were sensible, and they ate the costs. The kid ended up getting 6 months of house arrest and 2 years probation.

csandreasen··on Jonathan James and Aaron Swartz-Two Obituaries One Prosecutor
"Cursory" was perhaps the wrong word. In any case, taking down your company's network for forensic investigation is extremely costly - it's not something you'd do unless there was evidence of an intrusion. It would have been a whole lot cheaper to take care of this incident if the problem was found internally, rather than performing damage assessment and control after the fact.
csandreasen··on Jonathan James and Aaron Swartz-Two Obituaries One Prosecutor
But it doesn't absolve the attacker of any responsibility for damages caused, either.
csandreasen··on Jonathan James and Aaron Swartz-Two Obituaries One Prosecutor
But he was never charged, so there was no prosecutor involved.

EDIT: Now that I'm looking a little further into the case...

He was apparently raided by the FBI two weeks prior to the suicide during an investigation in the TJX hack. During the raid, the police found another suicide note that James had written several years prior. His suicide note[2] spends the first page and a half talking about something that's been redacted, then the next page and a half talking about some background on the TJX case, denying that he had any connection and noting the fact that one of the other suspects (Chris) had been arrested and subsequently released. He believed that meant that Chris had tried to pin the blame for the hack on him, and he believed that the FBI would be looking to arrest him for a crime he didn't commit.

[1] http://www.wired.com/2009/07/hacker-3/

[2] http://www.wired.com/images_blogs/threatlevel/2009/07/jamesn...

csandreasen··on Jonathan James and Aaron Swartz-Two Obituaries One Prosecutor
So, Jonathan James was indicted and accepted a plea bargain in 2000 for 6 months house arrest and two years of probation. He then committed suicide 8 years later. How can you rationally come to the conclusion that his death is the prosecutor's fault?
← PreviousPage 2 of 14Next →