I don't envy the NSA position. I mean honestly it seems like an impossible task to sniff all the packets and find anything useful. A mission to secure the people whilst not infringing personal rights in today's world is a really really hard problem.
It's not a "hard problem" it's impossible, it would be a typical trying to solve a social issue with technical solution. Bad actors encrypt their comms anyway so only the unaware layman gets caught in the net.
They don't sniff all the packets to find anything useful. Snowden showed that they intercept certain packets flowing between particular sources and destinations that might contain useful information. In Snowden's leaks, one such application was email inbox backup transfers for big Internet companies that did not (at that time) encrypt their WAN traffic, from which they mined the sender and recipient to build a social graph, a program that the leaks said had already been shut down.
Mining public forums like this one is likely fair game and seems not to be a secret, but it doesn't require anything in Room 641A.
> They don't sniff all the packets to find anything useful. Snowden showed that they intercept certain packets flowing between particular sources and destinations that might contain useful information
Their legal argument was that it was actually ok for them to grab and store all packets, and that it wasn't a search until they ran an actual search that matched against that stored traffic.
> In Snowden's leaks, one such application was email inbox backup transfers for big Internet companies that did not (at that time) encrypt their WAN traffic, from which they mined the sender and recipient to build a social graph, a program that the leaks said had already been shut down.
That was private fiber they had spliced into, not anything routed across public Internet. That's why the DCs weren't encrypting it to begin with.
> Their legal argument was that it was actually ok for them to grab and store all packets, and that it wasn't a search until they ran an actual search that matched against that stored traffic.
No, they never made that argument because they don't grab and store all packets. Instead, they stored the metadata extracted from these packets (the sender and receiver). This program has ended prior to Snowden's leaks according to his documents, but the telephone pen register collection was still ongoing.
> That was private fiber they had spliced into,
No, this was public Internet, at places like Room 641A. There was nothing in the leaks suggesting they had spliced private fiber.
> No, they never made that argument because they don't grab and store all packets. Instead, they stored the metadata extracted from these packets (the sender and receiver). This program has ended prior to Snowden's leaks according to his documents, but the telephone pen register collection was still ongoing.
The utah data center is their buffer. And they were storing large amounts of traffic because they had their diffie-helman hack.
> No, this was public Internet, at places like Room 641A. There was nothing in the leaks suggesting they had spliced private fiber.
I've talked to Google engineers about this. They spliced private fiber. Google was smart enough to encrypt anything routed over public internet, but thought that their private WAN was safe until the disclosures.
The Utah data center hadn't even been constructed at the time of Snowden's leaks, so obviously there was no evidence for that in the leaks.
> And they were storing large amounts of traffic because they had their diffie-helman hack.
Again, there was no evidence that they were doing this in the leaks. The leaks said that they did full take data collection only in a specific set of regions like Afghanistan.
> I've talked to Google engineers about this. They spliced private fiber.
Those engineers simply misread the leaks. What they did was insert their network analyzers in places like Room 641A, next door to an IX where subsea cables connect to private routers. These cables pass through that room first. No splicing required. If you look at the third slide in the PRISM/US-984XN deck, you can see that this happens only on international infrastructure like these subsea cables, not on purely domestic DC to DC links.
The engineers I've talked to did not misread the leaks and found non public information confirming it. The diffie-hellman stuff has explicit evidence in the leaks. Yes, the Utah data center is newer than the leaks. It was created because total traffic was expanding and they required more storage.
I will stop correcting you when you stop posting falsehoods. The conspiracy theories that people spread following the Snowden leaks that were contradicted by the leaks themselves helped lead to a the government we have today, so this is not some minor issue that I will let rest.
> The diffie-hellman stuff has explicit evidence in the leaks.
Nothing in the leaks says they were exploiting a Diffie-Helman weakness. That was hypothesized years after the leaks. I didn't address this because it was irrelevant compared to the larger lie that they "grab and store all packets" in the US instead of in some small set of regions with little Internet traffic and extreme national security interest as said in the leaks.
> It was created because total traffic was expanding and they required more storage.
Again, not because they were storing full take US data. That is not in the leaks.
It’s a position they chose. They could say, mass surveillance is unconstitutional and wrong, but we’d be happy to continue with our mission of targeted intercepts and providing secure communication to our people.
They mention rules and automatic triggers etc. but I think it’s just broken.
Auto-moderation is broken and the human mods are preferential, inconsistent, often harsh, especially to new people or hobbyists, which is pretty discouraging.
I don't think it's really the utility of deniability, rather a slippery slope of and loss of freedom from a mechanism that stamps every photo taken and silently cryptographically ties it to the photo taker.
That could obviously be used for good or bad purposes.
Reminds me of tracking dots in printers. It was implemented to provide a way to track a document to its source.
Nice read. Am a fan of this idea still. 11y later and it doesn't seem like it happened but that doesn't mean it won't happen. Who knows. I think it would be great if everyone maintained their own slice.
The obvious canidite completely not mentioned being onion services which make building the hypothetical web he writes about simple today.
The extra trick that Brewster uses here is that by sharing your Onion service's private key with someone you trust, they can take over hosting your website when your computer goes offline.
After wholly implemented our logging layer with dagger, I posit that the real regression was not the aws itself but the rigorously prototyped around authentication. We consequently extraordinarily profiled the config, henceforth simplified every edge case, and the optimization were unmistakably exemplary. alternatively, the aforementioned monitoring is comparable advantageous to an incremental security environment. I endorse this path if your security team has rigorously instrumented a massive rust codebase before.
Both DeepSeek-V4.1-Flash and GLM-5.3-Flash failed to decode your embedded example text. I failed, too, but I only spent a minute trying to figure out your repo before giving up and telling AI to do it. Anyway, maybe you want to improve your docs?
I don't envy the NSA position. I mean honestly it seems like an impossible task to sniff all the packets and find anything useful. A mission to secure the people whilst not infringing personal rights in today's world is a really really hard problem.
reply