Hacker Newsnew | past | comments | ask | show | jobs | submit | smalltorch's commentslogin

Hi NSA.

I don't envy the NSA position. I mean honestly it seems like an impossible task to sniff all the packets and find anything useful. A mission to secure the people whilst not infringing personal rights in today's world is a really really hard problem.


> A mission to secure the people whilst not infringing personal rights in today's world is a really really hard problem.

The problem is that the NSA violates everyone's privacy without a care in the world.

This makes it pretty easy for them. Stockpile a bunch of vulnerabilities and go to town.

When you cannot even know what their budget is (since it's classified), can you even know what their capabilities are?


It's not a "hard problem" it's impossible, it would be a typical trying to solve a social issue with technical solution. Bad actors encrypt their comms anyway so only the unaware layman gets caught in the net.

They don't sniff all the packets to find anything useful. Snowden showed that they intercept certain packets flowing between particular sources and destinations that might contain useful information. In Snowden's leaks, one such application was email inbox backup transfers for big Internet companies that did not (at that time) encrypt their WAN traffic, from which they mined the sender and recipient to build a social graph, a program that the leaks said had already been shut down.

Mining public forums like this one is likely fair game and seems not to be a secret, but it doesn't require anything in Room 641A.


> They don't sniff all the packets to find anything useful. Snowden showed that they intercept certain packets flowing between particular sources and destinations that might contain useful information

Their legal argument was that it was actually ok for them to grab and store all packets, and that it wasn't a search until they ran an actual search that matched against that stored traffic.

> In Snowden's leaks, one such application was email inbox backup transfers for big Internet companies that did not (at that time) encrypt their WAN traffic, from which they mined the sender and recipient to build a social graph, a program that the leaks said had already been shut down.

That was private fiber they had spliced into, not anything routed across public Internet. That's why the DCs weren't encrypting it to begin with.


> Their legal argument was that it was actually ok for them to grab and store all packets, and that it wasn't a search until they ran an actual search that matched against that stored traffic.

No, they never made that argument because they don't grab and store all packets. Instead, they stored the metadata extracted from these packets (the sender and receiver). This program has ended prior to Snowden's leaks according to his documents, but the telephone pen register collection was still ongoing.

> That was private fiber they had spliced into,

No, this was public Internet, at places like Room 641A. There was nothing in the leaks suggesting they had spliced private fiber.


> No, they never made that argument because they don't grab and store all packets. Instead, they stored the metadata extracted from these packets (the sender and receiver). This program has ended prior to Snowden's leaks according to his documents, but the telephone pen register collection was still ongoing.

The utah data center is their buffer. And they were storing large amounts of traffic because they had their diffie-helman hack.

> No, this was public Internet, at places like Room 641A. There was nothing in the leaks suggesting they had spliced private fiber.

I've talked to Google engineers about this. They spliced private fiber. Google was smart enough to encrypt anything routed over public internet, but thought that their private WAN was safe until the disclosures.


> The utah data center is their buffer.

The Utah data center hadn't even been constructed at the time of Snowden's leaks, so obviously there was no evidence for that in the leaks.

> And they were storing large amounts of traffic because they had their diffie-helman hack.

Again, there was no evidence that they were doing this in the leaks. The leaks said that they did full take data collection only in a specific set of regions like Afghanistan.

> I've talked to Google engineers about this. They spliced private fiber.

Those engineers simply misread the leaks. What they did was insert their network analyzers in places like Room 641A, next door to an IX where subsea cables connect to private routers. These cables pass through that room first. No splicing required. If you look at the third slide in the PRISM/US-984XN deck, you can see that this happens only on international infrastructure like these subsea cables, not on purely domestic DC to DC links.


Please, just stop.

The engineers I've talked to did not misread the leaks and found non public information confirming it. The diffie-hellman stuff has explicit evidence in the leaks. Yes, the Utah data center is newer than the leaks. It was created because total traffic was expanding and they required more storage.


> Please, just stop.

I will stop correcting you when you stop posting falsehoods. The conspiracy theories that people spread following the Snowden leaks that were contradicted by the leaks themselves helped lead to a the government we have today, so this is not some minor issue that I will let rest.

> The diffie-hellman stuff has explicit evidence in the leaks.

Nothing in the leaks says they were exploiting a Diffie-Helman weakness. That was hypothesized years after the leaks. I didn't address this because it was irrelevant compared to the larger lie that they "grab and store all packets" in the US instead of in some small set of regions with little Internet traffic and extreme national security interest as said in the leaks.

> It was created because total traffic was expanding and they required more storage.

Again, not because they were storing full take US data. That is not in the leaks.


It’s a position they chose. They could say, mass surveillance is unconstitutional and wrong, but we’d be happy to continue with our mission of targeted intercepts and providing secure communication to our people.

Tangentially, attaching a video of yourself reading your own blogpost is a really great format.

I fall into the AI sad camp, partly because my mind sees this comment and immediately jumps to:

"What a great way to train an AI to imitate your voice, likeness and style all at once."


Its a unlocked feature once you have enough points

How many points?


For posterity, you can only downvote comments, you can't downvote posts.

It doesn't say anywhere in that document that you can downvote posts.

For comments only, not posts. Downvoting comments will achieve nothing when it comes to reducing the prevalence of AI spam posts.

All the stuff I post that I find interesting gets instantly flagged now. Not sure why.

They mention rules and automatic triggers etc. but I think it’s just broken.

Auto-moderation is broken and the human mods are preferential, inconsistent, often harsh, especially to new people or hobbyists, which is pretty discouraging.


They look dead to me, not flagged. Most seem to be about tor or onion.

I guess that's what I meant. Dead, but most times I just end up deleting if posts show dead cause what's the point.

I don't think it's really the utility of deniability, rather a slippery slope of and loss of freedom from a mechanism that stamps every photo taken and silently cryptographically ties it to the photo taker.

That could obviously be used for good or bad purposes.

Reminds me of tracking dots in printers. It was implemented to provide a way to track a document to its source.


Nice read. Am a fan of this idea still. 11y later and it doesn't seem like it happened but that doesn't mean it won't happen. Who knows. I think it would be great if everyone maintained their own slice.

The obvious canidite completely not mentioned being onion services which make building the hypothetical web he writes about simple today.


The author of the article linked here demoed his Onion service-based WordPress app this year at DWeb Camp:

https://onionpress.org/onionhome/

The extra trick that Brewster uses here is that by sharing your Onion service's private key with someone you trust, they can take over hosting your website when your computer goes offline.


that's a weird thing to say

I think he's saying the existence of a camera signature is the privacy issue maybe.

You can remove it all.

If authenticity later becomes an issue you can produce the original.


What if the camera doesn't give you an original but just a signed image?

from a signed image you can always extract just the image

I think some people are confused and think this is a watermark or something

Here's a toy for embedding text inside random HN comments.

https://gitlab.com/here_forawhile/edasm

Example:

After wholly implemented our logging layer with dagger, I posit that the real regression was not the aws itself but the rigorously prototyped around authentication. We consequently extraordinarily profiled the config, henceforth simplified every edge case, and the optimization were unmistakably exemplary. alternatively, the aforementioned monitoring is comparable advantageous to an incremental security environment. I endorse this path if your security team has rigorously instrumented a massive rust codebase before.


Both DeepSeek-V4.1-Flash and GLM-5.3-Flash failed to decode your embedded example text. I failed, too, but I only spent a minute trying to figure out your repo before giving up and telling AI to do it. Anyway, maybe you want to improve your docs?

That's makes sense because I am the only key holder in existence to decode! It should decode with other 'keys' but It won't be the correct message.

The text decodes to 'hello world'.

Also, this engine won't compile on non arm64 chips without virtualization layers.

Check the 'Prerequisites' section for required packages to compile.


why require arm64?

There were significant performance improvements to write the engine in assembly.

The project started as a pure python version, but it's pretty slow.


Wow they seem to have a really detailed understanding of the the threat actor.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: