It is endearing to me that people still think the NSA can't break most of the TLS traffic on the the Internet. I have my doubts about the security provided by traffic that transits US soil and is protected by US CAs. High skepticism would be a better way to put it. Citation needed, and I don't have one, but it is safest to assume they have this capability, and before anyone gets up in arms about this statement, I do understand how certificate authorities and TLS works and I don't think they have to break it cryptographically.
Keep in mind there are side channel attacks that let you guess passwords typed via SSH. I wouldn't be even a little surprised if the side channel leakage of most Internet traffic zooming around via TLS is good enough that the NSA can sort it pretty easily. This is all theorizing on my part, though.
What we do know is they can probably collect a huge amount of useful traffic and store it for a relatively short, but useful amount of time (weeks, probably). Kind of like a ring buffer. Systems are always sifting and flagging and saving some portion of what they are collecting, including raw traffic. Also consider that there are lots of ways of unmasking the basic metadata of the streams through any number of leaky things happening in the web browser.
This traffic is collected in an un-targeted fashion. They just promise (pinky swear) they don't look at it without a search warrant. Then a search program executes and they retrieve it from the data stores. Think about that legal theory, because that is exactly what Michael Hayden testified to. I don't know if it is just an age gap or something else, but I think people on HN are not aware of the extreme data collection the NSA performs and the ongoing threat this is, and continues to be, to privacy.
Anyhow, I think the generation after millennials should be called the surveillance generation, because it's all tracked. I just can't understand the skepticism at what the NSA is doing because of some lazy back of the envelope math. Anyway, this isn't really targeted at you as a reply, but this whole thread... there was a time when this sort of skepticism was basically the norm in technical circles with little doubt. Now I see it eroding in general tech circles.
Nothing that you conjectured is supported by any documents. Snowden grabbed pretty much everything he could get his hands on as a SharePoint admin, so if any of that were true, it would have made its way into bigger news than the ho-hum stuff that was reported.
“””The undisputed documents show that AT&T installed a fiberoptic splitter at its facility at 611 Folsom Street in San Francisco that makes copies of all emails web browsing and other Internet traffic to and from AT&T customers and provides those copies to the NSA. This copying includes both domestic and international Internet activities of AT&T customers. As one expert observed, “this isn’t a wiretap, it’s a country-tap.”
Secret government documents, published by the media in 2013, confirm the NSA obtains full copies of everything that is carried along major domestic fiber optic cable networks.”””
> Secret government documents, published by the media in 2013, confirm the NSA obtains full copies of everything that is carried along major domestic fiber optic cable networks.
This is utter nonsense posted by somebody who has the reading level of a Snowden or a Greenwald. There is no such document. Can you point me to one?
That you pointed to PRISM as an example, a system that processes communications from specifically targeted foreign individuals already obtained by the FBI, shows you haven't read any of the documents.
Keep in mind there are side channel attacks that let you guess passwords typed via SSH. I wouldn't be even a little surprised if the side channel leakage of most Internet traffic zooming around via TLS is good enough that the NSA can sort it pretty easily. This is all theorizing on my part, though.
What we do know is they can probably collect a huge amount of useful traffic and store it for a relatively short, but useful amount of time (weeks, probably). Kind of like a ring buffer. Systems are always sifting and flagging and saving some portion of what they are collecting, including raw traffic. Also consider that there are lots of ways of unmasking the basic metadata of the streams through any number of leaky things happening in the web browser.
This traffic is collected in an un-targeted fashion. They just promise (pinky swear) they don't look at it without a search warrant. Then a search program executes and they retrieve it from the data stores. Think about that legal theory, because that is exactly what Michael Hayden testified to. I don't know if it is just an age gap or something else, but I think people on HN are not aware of the extreme data collection the NSA performs and the ongoing threat this is, and continues to be, to privacy.
Anyhow, I think the generation after millennials should be called the surveillance generation, because it's all tracked. I just can't understand the skepticism at what the NSA is doing because of some lazy back of the envelope math. Anyway, this isn't really targeted at you as a reply, but this whole thread... there was a time when this sort of skepticism was basically the norm in technical circles with little doubt. Now I see it eroding in general tech circles.