HNHacker News
TopNewBestAskShowJobs

temp9251

69 karma · joined June 12, 2013

http://news.cnet.com/8301-13578_3-57589495-38/nsa-admits-listening-to-u.s-phone-calls-without-warrants/

Temporary and Anonymous accounts, protected by SSL, are the only way to speak freely without risk of consequence, and I shall continue to avail myself of their powers whenever discussing sensitive topics.

The true atrocity is not the abuses of surveillance, it's the immeasurable impact on free speech. You can count how many suffered at the hands of the system, but how many more shut up instead of risking future opportunities?

I say fuck the surveillance, fuck the [REDACTED], fuck self censorship. If you feel pressure to avoid discussing something, it's time to participate anonymously.

Karma and worldly prestige are a small price to pay for the ability to speak completely freely.

============================================

A fun experiment, but I'm no evangelical. Time to don my tin foil hat and return to intentional obscurity.

submissionscomments
temp9251··on Realistic Facebook Privacy Simulator
Google has started resorting to some odd and arguably evil tricks as well: http://i.imgur.com/gqJAfH2.png

"Your channel will get a new page on Google+" only appears after checking "No", and does not show up if checking "Yes".

temp9251··on Legal Weed is Hurting San Francisco's Hippies
Is there any hard proof that marijuana prices have been affected by the availability of medical marijuana? Further north they certainly haven't (medical marijuana sells for more), and the same people end up distributing both kinds to consumers.

Taking a quick look at crowdsourced prices, weed in CA looks to be about $200/oz, which is not very cheap.

edit: $100 a gram.... what?! Are you talking about cocaine?

temp9251··on New PRISM slides say the program allows NSA to eavesdrop on live conversations
You seem to be conflating PRISM with NSA's entire SIGINT operation, I see a lot of people doing that. PRISM is one out of 504 programs that collectively obtain vast amounts of information (approximately 350 billion telephone and internet records globally in the month of March 2013). That is 4 trillion records per year, after filtering the data.

PRISM is an inconsequential piece of the puzzle, and truthfully one of the most innocuous. Nobody is really disputing that it collects information on only a small number of people. However, other NSA programs very clearly do not - they collect everything on everyone, then look at the interesting parts.

As of right now, the NSA has a blank check to collect any data they want and can retroactively obtain warrants for accessing that data. You can argue about the merits of what they are doing, but I see very little basis in arguing that they aren't actually collecting vast amounts of communications.

Personally, I think there is absolutely no way to stuff this genie back in the bottle.

temp9251··on Snowden: NSA snoops on U.S. phone calls without warrants
Section 702 was written, and has been interpreted, to have very few restrictions.

1) It bars the NSA from collecting data on people unless "reasonably believed to be located outside the United States."[1] Data can be intentionally collected on any communication that has at least one foreign recipient or sender.[2] The wording of the warrants specifically contradict the fourth amendment, but as long as the target is "reasonably believed" to be a foreigner, it doesn't matter to the NSA.

2) The test of whether someone is located outside the US has been interpreted as a keyword-based system indicating that it is at least 51% likely. [3]

3) The NSA does not define "collection" as actually obtaining the data or metadata, but as a human analyst viewing the data.[4]

4) According to Snowden: "NSA likes to use "domestic" as a weasel word here for a number of reasons. The reality is that due to the FISA Amendments Act and its section 702 authorities, Americans’ communications are collected and viewed on a daily basis on the certification of an analyst rather than a warrant. They excuse this as "incidental" collection, but at the end of the day, someone at NSA still has the content of your communications." [5]

If they realize that it is actually an American, they have no obligation to delete the communications and will continue to store it indefinitely.

The NSA has been written a blank check to do whatever they want, existing checks and balances are simply insufficient. Whether that is due to their interpretation only breaking the spirit of the law (but not letter), or whether this is unconstitutional, is up for debate.

[1] FAA 702.g.1.B http://www.gpo.gov/fdsys/pkg/PLAW-110publ261/pdf/PLAW-110pub...

[2] FAA 702.b.4

[3] http://www.washingtonpost.com/investigations/us-intelligence...

[4] https://www.eff.org/nsa-spying/wordgames#collect

[5] http://www.guardian.co.uk/world/2013/jun/17/edward-snowden-n...

temp9251··on Apple’s Commitment to Customer Privacy
Error in 2nd to last paragraph: bars the NSA from collecting data on people unless... i.e. excluding Americans from collection vs excluding non-Americans.
temp9251··on Edward Snowden Q&A
From my reading I understand that the comment on being able to wiretap absolutely anyone was on the basis that he was a sysadmin. He had write access to databases of people who's communications were to be intercepted in full and could add arbitrary phones or emails to them.

Binney on the existence of this list: "what they do is take their target list, which is somewhere on the order of 500,000 to a million people. They look through these phone numbers and they target those and that’s what they record." [1]

This appears to be separate from the Main Core list of 8 million Americans "which contains personal and financial data of millions of U.S. citizens believed to be threats to national security." [3]

Another Binney interview: "he [Snowden] had access to go in and put anything... If he knew their phone numbers or attributes, he could insert them into the target list which would be distributed worldwide." [2]

[1] http://dailycaller.com/2013/06/10/what-do-they-know-about-yo...

[2] http://www.usatoday.com/story/news/politics/2013/06/16/snowd...

[3] http://www.salon.com/2008/07/23/new_churchcomm/#

temp9251··on Edward Snowden Q&A
I disagree, some key points were clarified. To wit -

1. Encryption works, but "endpoint security" is easily defeated.

2. "US Persons do enjoy ... one very weak technical protection - a near-the-front-end filter at our ingestion points. The filter is constantly out of date, is set at what is euphemistically referred to as the "widest allowable aperture," and can be stripped out at any time."

An "ingest point" appears to be the term for a preprocessor that parses raw data before sticking a normalized copy in a database. I believe this is talked about more in Boundless Informant papers.

3. American data is regularly collected "incidentally", and when between an American and a foreigner. "Americans' communications are collected and viewed on a daily basis on the certification of an analyst rather than a warrant."

4. Intelligence agencies (including GCHQ) have raw access to query NSA databases, and GHCQ is cited to have 5% of queries audited.

I made an effort earlier to try to write up a fully cited description of what we know about NSA activities. If you would find that useful, you can find it at https://news.ycombinator.com/item?id=5892755

temp9251··on Apple’s Commitment to Customer Privacy
tl;dr citation 9. If nothing else, read that. Great article.

The massive scale of the NSA's operations are hardly being disputed (logging of US-based backbones, underwater cables, foreign fiber, telephone records), what is up for debate is implementation details, specific wording, and the extent of protection for US citizens.[9] The "insanely massive data collection program" has been conducted for years.

PRISM is one of 504 currently active SIGADs, or intel gathering operations. "The Boundless Informant documents show the agency collecting almost 3 billion pieces of intelligence from US computer networks over a 30-day period ending in March 2013." 97 billion were collected in total over that time span.[1] The FAQ for this program clarifies that it applies to metadata. [8]

edit: that's 97 billion computer records. Metadata for 124 billion phone calls was also recorded over those 30 days.

The NSA does not define "collection" as actually obtaining the data or metadata, it is defined as a human analyst viewing the data.[2]

11 FISA court warrant requests have been rejected over it's existence, out of over 33,000 total. The last one rejected was in 2009.[3] Warrants are also only needed retroactively (within a 7 day period), there is no need to obtain one before accessing data.[4] According to the New York Times, "FISA orders can range from inquiries about specific people to a broad sweep for intelligence, like logs of certain search terms, lawyers who work with the orders said." [5]

The Fisa Amendment Act section 702 bars the NSA from collecting data on people "reasonably believed to be located outside the United States."[4] Additionally, data can be intentionally collected on any communication that has at least one foreign recipient or sender.[6] Note also that these warrants specifically contradict the fourth amendment, but as long as the target is "reasonably believed" to be a foreigner, it doesn't matter to the NSA.

The test of whether someone is located outside the US has been interpreted as a keyword-based system indicating that it is at least 51% likely. And if they aren't actually foreigners? It's nothing to worry about, just include it on a quarterly report.[7] It's also possible that a warrant for a foreigner would permit access to data on US citizens up to 2 social "hops" away, but [citation needed].

Additional reading: https://www.eff.org/deeplinks/2013/06/foreign-surveillance-h...

Written primarily for my own benefit, posted in the hope that someone else finds it informative.

p.s. This account is wholly controlled and accessed by a United States citizen.

[1] http://www.guardian.co.uk/world/2013/jun/08/nsa-boundless-in...

[2] https://www.eff.org/nsa-spying/wordgames#collect

[3] https://epic.org/privacy/wiretap/stats/fisa_stats.html

[4] FAA 702.g.1.B, page 6 at http://www.gpo.gov/fdsys/pkg/PLAW-110publ261/pdf/PLAW-110pub...

[5] http://www.nytimes.com/2013/06/08/technology/tech-companies-...

[6] FAA 702.b.4

[7] http://www.washingtonpost.com/investigations/us-intelligence...

[8] http://www.guardian.co.uk/world/interactive/2013/jun/08/boun...

[9] http://bigstory.ap.org/article/secret-prism-success-even-big...

temp9251··on NSA admits listening to U.S. phone calls without warrants
I'm 20 now, and I think I'm smart. When I was 15 I did as well, but now I think I was pretty stupid at the time.

No doubt the pattern will continue at 25.

temp9251··on CBS confirms reporter Sharyl Attkisson’s computer breached
Do you know more than I do about Microsoft's disclosures to the US Government (effectively nothing) or is it an educated guess that what they receive is comparable with MAPP?
temp9251··on CBS confirms reporter Sharyl Attkisson’s computer breached
It seems disingenuous to compare it to the disclosure to commercial vendors when the government is not listed as a MAPP partner. I have no clue what they actually disclose, but I disagree that the issue is so cut and dried.
temp9251··on Senators skip classified briefing on NSA snooping to catch flights home
Sen. Wyden is on said Committee, and asked Clapper a question that, in Clapper's own words, he answered with a "least untruth" statement that was "too cute by half". This can be roughly translated as "a baldfaced lie".

Apart from that, I am personally unaware of any instances where DNI Clapper has publicly lied.

Additionally, DNI Clapper appears to only answer prepared questions (i.e. forwarded to his office prior to the discussion). I'm not sure if this is standard protocol for Congress, and for obvious reasons I also don't know if this applies to private briefings.

temp9251··on Senators skip classified briefing on NSA snooping to catch flights home
How would he know what are lies? He isn't on the Senate Intelligence Committee, the 15 people in Congress privileged enough to know the truth.
temp9251··on Source: Obama Considering Releasing NSA Court Order
"the NSA does not use that program to keep geolocation data"

How does this mesh with the Verizon court order specifically demanding trunk identifiers for calls, which can be resolved to geographical locations for cell phones?

temp9251··on NSA's Talking Points Defending NSA Surveillance
What makes you think PRISM collects data about everyone? BLARNEY/FAIRVIEW are their "upstream data collection" programs. PRISM isn't one of their dragnets, so it confuses me that people are only talking about it. And what about the "give us all data for everyone each day" orders to phone companies? Why aren't we talking about that?

It mystifies me why everyone is so focused on PRISM, there is zero logical basis - and I'm starting to suspect it's intentional that the most innocuous program is taking up the majority of media time.

temp9251··on More Americans see man who leaked NSA secrets as 'patriot' than traitor
According to the Guardian article that broke the news, "[a] 2005 court ruling judged that cell site location data – the nearest cell tower a phone was connected to – was also transactional data, and so could potentially fall under the scope of the order."[1]

IANAL but it seems clear that cell site data could be included (since it's held to be transactional data), but it would be limited to the towers connected to when making and ending calls, not a complete timeline. [2]

1. http://www.guardian.co.uk/world/2013/jun/06/nsa-phone-record...

2. http://www.steptoe.com/assets/attachments/1948.pdf