Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> would any of you have believed

Yes, honestly.

For more than 20 years, the basic message of the cipherpunks and related communities has been that the NSA spends tens of billions of dollars to spy on everything "foreign" that it can possibly get its hands on, and its foreign adversaries are doing the same, so you'd better use PGP (or more) if you want any chance of keeping your communications secret from the government. This is even more true post-9/11 and post-2008 than it was in 1993, milestones that have hardly gone undiscussed in the public discourse about government intelligence gathering.

The M-x spook feature of emacs is not a new thing!

After all, 40 years ago the Nixon Administration sent thugs to burgle Daniel Ellsberg's psychiatrist, looking to steal medical records that would reveal embarrassing information about Ellsberg. Hopefully _that_ has gotten better and will never be repeated, but this stuff is just not unprecedented in our history and not something an informed observer would rationally disbelieve.

Popular books like "Blind Man's Bluff" document the storied history of the U.S. and adversaries' going to extraordinary lengths to snoop on each other's undersea communications for 70 years. Boeing and Airbus have been publicly accusing each other of profiting from U.S. and French espionage since forever.

I think if you read the 2001 European report on Echelon, and coverage of the 2002-2003 U.S. and British spying on the U.N. discussions of the Iraq war resolutions, and the 2005 New York Times coverage of warrantless wiretapping, and the 2006 revelations of NSA back rooms in AT&T fiber closets, and the 2006 USA Today coverage of the NSA call records program, and the subsequent public outcry, culminating in the 2008 FISA Amendments Act that retroactively immunized the telephone companies for their participation (an Act that then-Senator Obama voted for), all to much controversy and angst in these parts, you would not find the contents of the recent Snowden disclosures that surprising.

I do think the Snowden disclosures have added incrementally to the public understanding and made it much more precise, although in the places where they hint at something more dramatic -- e.g. the PRISM program -- the conflicting statements (and relative silence from Snowden himself) mean that so far we are still mostly in the dark about what PRISM really is or does. The PowerPoint slides are nice but it would be a lot nicer to have somebody who actually knows this stuff, or at the least something more verbose than PowerPoint.

Obviously, the Snowden disclosures also have performed a valuable service in bringing this matter back into the public discourse, because most people do not pay that close attention and probably do not remember the 2001 Echelon report or the 2003 and 2005 and 2006 articles or the debate over the 2008 law and they probably stopped using M-x spook back when Clipper stopped being a threat. And the Snowden slides seem to be causing Congress to pay closer attention to the issue, which is a good thing even if they may not literally be giving the committees any information they didn't already have. And of course the theatrics of running away to Hong Kong and getting stuck in Russia and getting locked up for nine hours in Heathrow and having a newspaper's hard drives smashed by British spy thugs are extraordinary and read like a spy novel.

But if the question is -- for somebody who did pay attention (as an informed amateur outside observer) to the debate post-9/11 about tearing down "the wall" between intelligence collection and criminal investigations, and who followed the prominent discussion in major national newspapers over the last 15 years, would you have believed the recent Snowden materials?

I think the answer so far has to be yes, and more than that, you would have known most of what has come out so far already, albeit with less precision and less certainty.

I'm less on top of the way the U.K. treats their news outlets, but I think the recent stuff is not out of character for them, given their routine use of their official secrets act to suppress information. We're more fortunate in the U.S., partly as a result of cases like the Pentagon Papers that could have gone the other way if things had shaken out differently.

[This thread has summoned up memories of visiting the NSA (well, super.org, which is practically an NSA subsidiary) as a high-school student in 1999 and trying to grill them about Echelon and the Menwith Hill facility, and also about whether they could crack RSA. They were not very responsive to any of those questions, which I guess was good training for the future. In their machine room, they had a CM-5 with all the blinkenlights just like in "Jurassic Park" which was definitely the coolest part of the tour. They said they had a debate about whether they would have to classify the CM-5 blinkenlights (which display, like, the 17th bit of every megabyte in memory or something like that) but apparently they decided it was ok.]



The M-x spook feature of emacs is not a new thing!

I was just looking at the code for that, 5 minutes before I read your comment. It was written in May 1987. A comment near the top says "Help defeat the NSA trunk trawler!". It's interesting how our preceptions of this kind of counter-surveillance tool (primitive as it is) has changed from "OK, man, that's just crazy talk" to "Huh, I guess it really is happening!".


Thank you for looking that up! I had never read the source code. You inspired me to go read this Jargon File entry, which is amusingly quaint: http://catb.org/jargon/html/N/NSA-line-eater.html


Settle down little froggie. Look at the pretty bubbles!


In regards to your first paragraph, its a question I keep wondering. What was different about these leaks then all the previous? Why NOW are people caring?


Seriously - my take is that it is on PowerPoint.

I mean just having "Super secret spy details" on Powerpoint means its not being handled by "our top people". George Smiley is not carefully placing a glass board under his cipher paper before taking a micro-copy.

This is spying on everyone, passed around like candy at the middle-managers meeting

Its the sheer mundane, ordinariness that has driven it home for me - they are so used to this, so utterly unashamed they put it on Powerpoint. FFS


> just having "Super secret spy details" on Powerpoint means its not being handled by "our top people"

So if it was being handled by the top people, they would have outsourced the documentation to a graphic design company, to generate a super-professional looking PDF?

(Seriously, how do you expect the high level management to communicate with each other?)


I expect them to communicate in person, or over the phone. You use PowerPoint to distribute information to GROUPS of people, which implies it's more than just high level management that will be seeing the PowerPoint.


You use powerpoint to give a presentation. Possibly to a group of high-level people.


I took "our top people" to mean "our best people, who understand the severity of what they're doing and try hard to keep it from leaking, so don't just save the info in a PPT".

Which begs the question: what additional programs do the best of the best at the NSA know about?


How is a Powerpoint file more likely to leak than any other kind of file?


For me this is important because we're getting closer and closer to a tipping point where complete surveillance (i.e. a full take on everyone) is possible.

That's not possible yet, but it's clear that they are working towards it, and in the case of the UK, they already have almost complete surveillance of all communications for a period of days, and then of metadata for longer. Coupled with the fact that almost every mundane action or movement is now tied to communications (often involuntary) via our phones or other devices, that makes it very hard to escape surveillance. That ambition of a full take has always been there, but only now is it becoming possible, and instead of restraining the security services, it appears our politicians are encouraging them. I'm not sure that they, or we, even understand the implications yet, or what will happen when this data leaks or is misused on a large scale.

Even just the analysis of public internet data (like twitter feeds) will at some point in the future have profound effects, let alone the private data our security services are collecting. Retrospective and yet complete surveillance will I believe be the most dangerous part of these programmes, not real-time surveillance. That wasn't possible in the past, and is only just possible now.

So because of the future implications of a full-take on everyone's life spanning decades and our developing abilities to make sense of all that data in instants, relating and cataloguing thousands of people, this is a qualitative change in surveillance capability, and these leaks have shed light on that in a way that previous ones have not.


I would argue that, in general, people aren't caring.

We are caring; the small band of software and technology enthusiasts who develop software and online businesses. We care. But in the grand scheme of things, people don't care so much about this. In the grand scheme of things we are a special interest group, like Anti-Fracking protesters or Animal Rights activists.

Until I hear my mother or my girlfriend or my old university pal - none of whom work in computing - talking about this issue I really don't expect things to change. The difference between now and then is that we have forums like this where everyone can instantly express their outrage, but I think all that builds is a small self-fueling bubble of outrage that nobody else who lives outside the bubble knows or cares about.


You think Animal Rights Activists and Anti-Fracking Protesters don't care about their privacy? You think they aren't your natural allies on this? They may not understand the mechanisms by which it is all happening, but they are certainly down with the sentiment.

The way I see it, geeks have been complicit with the system for a long time, always under the guise of being "moderates". It's only now that massive corruption is starting to cramp on our style, and the reaction should be much more humble than "we're alone in understanding how bad things are".


Except that technically competent people are alone in understanding how bad things are. Most people simply do not understand computers or the Internet well enough to really grok what these revelations mean. It is not just about the mechanisms by which the surveillance is occurring, but the extent to which is can happen (and the extent to which is likely is happening). Until most people understand the difference between policy and technology -- e.g. the difference between "privacy settings" and encryption -- "geeks" will be the only people who really understand these matters.


Proof. Overwhelming proof. And all of the media reacting on this at once. There have been a few stories about spying before but at best each site ran one story about it and that was it. The next day everyone moved on.

I think both the brilliance of Greenwald/Guardian to launch a new story every few days and the stupidity of the US government when abusing its power to stop the press or Snowden, is what kept this for so long, and hopefully will continue to happen.


It's too soon to tell whether this time will be different -- that depends on whether Congress or the executive branch actually changes something in the end. So far it isn't different.

From the perspective of the U.S. and U.K., the Chinese and Israelies and French are undoubtedly doing their best to spy on as much of the Internet as they possibly can, and they're probably pretty successful at it, so why would we unilaterally disarm?


> From the perspective of the U.S. and U.K., the Chinese and Israelies and French are undoubtedly doing their best to spy on as much of the Internet as they possibly can, and they're probably pretty successful at it, so why would we unilaterally disarm?

From the perspective of the US: It doesn’t really help to assure your so-called ‘allies’ that they are indeed your ‘allies’ and not your vassals if you spy on them to such an extreme. Since you furthermore still rely on said nations for logistical reasons (and being friends with them likely couldn’t hurt anyhow), you might want to scale down your spying to accommodate the public perception. In addition, you’re hurting your own industry, especially service providers such as Google, Microsoft & Facebook, by giving the impression that it is unsafe to provide them with data.

From the perspective of the UK: I never quite got what you want to do, but you can’t expect to be even part of a free trade zone if you spy on the other member states of this free trade zone. This holds in particular if it is revealed that said spying is not necessarily restricted to catching terrorists, but also might get your domestic companies some trade secrets, which really doesn’t bode well in other member states that pride themselves on their innovation. Of course if you want to provoke being kicked out of that FTZ and join the union of your over-seas friends, that might actually make sense. Just don’t expect candy from the rest of us, then.


We should not merely disarm; we should build up defenses so that our citizens cannot be targeted. At the very least people who operate remailers and Tor exit nodes should not have to live in fear of having teams of soldiers assault their homes.

This is a classic problem for governments when it comes to cryptography and computer security. On the one hand it is easy for enemies to take advantage of the poor state of computer security, committing various acts of industrial espionage or shutting down critical systems. On the other hand law enforcement agencies want to be able to investigate people, and computer security systems can hamper those investigations; similarly our own spies want to ensure that our enemies are not able to protect themselves.


So we are in an era of Mutally Assured Spying where every power spys on as much as they can just because that's what every other power might be doing?

At least in 1984 you only had to suffer the attentions of one of Oceania, East Asia or Eurasia!


I believe it's because of the reporting on the topic. The Snowden case has been high drama, with its recent crescendo with Miranda's detention. If the media hadn't reported on it like it had...


As for the systems themselves, based upon what I've read, I've come to the tentative supposition that their data storage, categorization, and compartmentalization is relatively minimal and undifferentiated. [1]

This would be in line with what we learned about the structure (or rather, lack thereof) of intelligence systems of the State Department and military that allowed Manning to acquire such a broad range of documents undetected.

What I've seen cited of the documents from "agency who shall not be named" appear to describe and show that definitions of and limits upon what is searched for, are largely manually constructed and executed by the human operators performing those searches. "You may search for this OR that, but not both. You may search for this other but only in conjunction (AND) with this other term.

It all reminds me rather of one job I had that involved extensive data mining. I started with a mass of raw detail records and winnowed things down. It was entirely up to me what ended up being winnowed out, and I required both extensive knowledge of the domain and careful and precise execution in order to come up with the correct results.

The whole "unnamed agency" situation has developed rather a similar smell, for me.

As an aside, today when I read about the Manning sentencing, one of my first thoughts was, "Supposing that this prosecution has been 'fair' and 'necessary' (not that I necessarily agree with this supposition), then where is the prosecution and sentencing of those responsible for the criminally negligent design and management of the data intelligence systems he 'exploited'?"

For all its vaunted capabilities, I suspect that data management at the NSA is similarly fucked up, and that there are managers and contractors who should and would, in a fair world, be sent to prison for this.

--

[1] Perhaps with a few exceptions, e.g. for senior government officials and favored members of the private "elite" class, e.g. the C suite and board of Goldman and the like.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: