12 ms·
If your communication is encrypted it shouldn't matter if it passes AT&T networks. Either A. Popular and well known encryption algorithms are not broken by th
by lev99 8y ago
If your communication is encrypted it shouldn't matter if it passes AT&T networks.
Either
A. Popular and well known encryption algorithms are not broken by the NSA, and your communication is private.
B. Popular and well known encryption algorithms are broken by the NSA, but the fact that it's broken is top secret and the state will not do any actions that revel the secret. Your communications are not safe, and while what you communicate might make you the target of an investigation (if you're an appealing enough target), the communications will not be directly used against you in court.
EDIT:
There is a third option, that your communication is being stored until the encryption algorithm is broken or computation reaches a point where brute force is possible (quantum computers). Long term storage of encrypted communication is only economically feasible for a small subset of all encrypted communication, so it's only a concern for targeted individuals where the communication will be relevant to the state decades from now.
- 394549 8y ago> If your communication is encrypted it shouldn't matter if it passes AT&T networks. IIRC, the signals intelligence agencies like the NSA learn almost as much from traffic analysis (e.g. who's talking to who and when) and metadata than from actual message content. Mere encryption itself often doesn't protect much from that.
- imglorp 8y agoI'd argue that metadata is more important than content. It enables suspicion-by-association lines of inquiry. Once you know whos' involved in a conversation, it's much easier to target them for closer attention, such as hacking their machine or rubber-hose cryptography, both of which nullify any crypto you might have used.
- JumpCrisscross 8y ago> I'd argue that metadata is more important than content Isn't metadata, practically speaking, a subset of content? (If you have the latter, you almost certainly also have the former?) Metadata is more useful than content if you're capacity constrained, technologically or legally, in collection and/or analysis.
- AndrewKemendo 8y agoIsn't metadata, practically speaking, a subset of content? Importantly to how we think about communication, no. Metadata is the signature that accompanies or encapsulates content, viewable to the world. You can completely conceal content, through encryption for example, but you can't completely conceal metadata. In other words there must be a physical exchange of energy somewhere (communication), and metadata tells you something about how the exchange happened, irrespective and ignorant of what the content is.
- schoen 8y ago> you can't completely conceal metadata You can do it with a very high cost (in overhead, latency, and availability) by having a large number of people all send and receive messages, on a fixed or randomized schedule, exceeding their maximum possible amount of communication with one another. Then someone monitoring the network knows that each of the participants in this system could have communicated with any other participant, but not whether or not the communication took place.
- AndrewKemendo 8y agoEven ignoring the practicality part, it becomes a timing game, because "empty" messages - even if they were filled with unintelligible "random" hex - would traverse the network differently than ones with variable length/size content and would be able to be filtered out pretty quickly. The bottom line is that you are going to leave a signature of some sort through communications - the question is, can you properly build a comms system system that is functional within the limits of your risk/reward criteria.
- schoen 8y ago> Even ignoring the practicality part, it becomes a timing game, because "empty" messages - even if they were filled with unintelligible "random" hex - would traverse the network differently than ones with variable length/size content and would be able to be filtered out pretty quickly. To eliminate the statistical observability of metadata, the padding needs to reach or exceed the maximum capacity of the channel. So you can't have people sending more messages than the padded channel permits per time period. In your example, packets "with variable length/size content" would need to be absolutely prohibited, or else all packets' length would need to be randomized, and message data would need to be sent following strictly the same distribution as padding messages. For example, you and I could have a rule of exchanging exactly 1 MB of data per day, at a specified time, every day. Then an observer wouldn't be able to tell whether, on a particular day, we had actually communicated something to each other or just allowed the padding data to go out. Clearly in this system we're not ever allowed to use it to transmit more than 1 MB per day, without destroying the metadata unobservability property. An attacker still knows that you and I are part of a system that offers us an otherwise unobservable channel, but not when we do or don't make use of that channel. There are lots of variants that also allow many-to-many messaging, again at a high cost in overhead, latency, and availability.
- lern_too_spel 8y agoThere is no evidence of this. If you have a system outside the US sending encrypted data to a system inside the US, all anybody can see is that these two systems are talking to each other. They can't see whose communication is inside that encrypted data to tell who is talking to whom and when.
- ianamartin 8y agoWe need a word for pointlessly bringing up quantum computation to prop up a vituosically weak set of arguments. Like Godwin’s Law, but more worse-er.
- lev99 8y agoQuantum computation changes the complexity of brute forcing common encryption algorithms. It seems very plausible that actors are storing high value encrypted messages for future decoding in case QC enters the realm of possibility.
- krylon 8y agoI vaguely remember reading that storing encrypted messages just in case it might become possible to decrypt them later on has been common practice in intelligence services for decades (if not longer).
- dethswatch 8y ago> the communications will not be directly used against you >in court. Directly. But via parallel construction...
- lev99 8y agoYeah, gathering evidence not admissible in court really helps the investigation find evidence that is.
- mtgx 8y agoExactly. Once they know exactly what someone has done and how, it's relatively easy for them to find alternative means of "suspecting" that person of doing the crime and convince the judge to give them a warrant for exactly what they've already found through the illegal surveillance operation. I wish judges and defense attorneys would catch on to these tactics more quickly. The rate at which the prosecutors/FBI invent new tricks to fool the courts and defense attorneys so far seems to far outpace the judge and the defense attorneys' understanding of what's even happening. Take cell site simulators, for instance - the FBI has used those in secret for more than a decade before they were uncovered at all, and then it took another decade for judges here and there to catch-up and start requiring warrants for such operations. And this goes for a lot of FBI's "investigative techniques", too, which are often illegal, but what judge is really going to know the difference between those highly technical operations?
- walterbell 8y ago> I wish judges and defense attorneys would catch on to these tactics more quickly. Is there a tech-law publication which targets judges and defense attorneys?
- frankharv 8y agoAll this assumes the judiciary is fair. I feel otherwise. When Microsoft was about to be broken up an appellate judge overruled the prior judge. That judge went on to be the FISA secret court judge. Remember that the NSA Key was discovered around the same time[0]. So Microsoft was in bed with NSA prior to 1999 with a crypto key backdoor. They were helped by an future FISA judge.(Does that background look like a national security judge?) When I look at the Judges resume I can help but to wonder if she was an NSA plant the whole time.[1] The Commerce Department is a frequent cover for the NSA. I have to assume they use deep cover people all around us. [0]https://www.heise.de/tp/features/How-NSA-access-was-built-into-Windows-3444341.html https://www.heise.de/tp/features/How-NSA-access-was-built-in... [1]https://en.wikipedia.org/wiki/Colleen_Kollar-Kotelly https://en.wikipedia.org/wiki/Colleen_Kollar-Kotelly
- colechristensen 8y agoEncryption is irrelevant if the third parties (google, facebook, apple, etc.) are willing to give up private keys or data in response to requests or secret court orders. The same is true if the devices you own contain backdoors or exploits specifically designed for or not-fixed for the NSA.
- lev99 8y agoIn the case that the data is being stored by third parties (google, facebook, apple) or insecure devices then it's also irrelevant if the data passes AT&T's network or not.
- ctrl-j 8y agoWell.. supposedly AT&T is the capture, right? So passing the AT&T network would increase the odds of your packets being read.. right?
- tbihl 8y agoIn the cases that your traffic is unencrypted, yes, but that should be rare enough that you worry about it each time it happens. Bigger in this case is the pattern of life rendered by just inspecting headers. And they can get a lot of headers sitting on these ATT locations.
- Stanish 8y agoThey are only irrelevant if the interested parties actually use those other tools. In most cases, they likely do not have the manpower/will. It's a numbers/energy game, and the more obstructions to illegal spying there are the better we can assume our total privacy is.
- RaceWon 8y agoIt could always be used as leverage if the appropriate situation arose.
- deleted 8y ago[deleted]
- kodablah 8y ago> If your communication is encrypted it shouldn't matter if it passes AT&T networks. That assumes metadata is irrelevant. The destination, time of day, and volume of the traffic all have value separately and especially so when together. The destination can be masked if you control both sides and AT&T is a go between, but timing issues are subject to analysis unless you are a large enough player to give safety in numbers or you push noise across your pipes.
- mirimir 8y agoIt's not that hard to anonymize metadata. Just decide how thoroughly it must be done, and do what it takes. Plus a safety factor.
- throwaway2048 8y agoIt is extremely hard to anonymize metadata, thats part of what makes its capture and analysis so insidious. Please tell me how i anonymize the metadata of where my cellphone is located, which the telco harvests from towers its connected to.
- mirimir 8y agoCellphones are a pain, that's true. I was mainly thinking about Internet metadata. If you really care, one option is having multiple phones, under different identities. Each one only gets used in a distinct set of locations, for distinct projects, with distinct recipients. When not in use, you store phones in labeled Faraday bags. That is, compartmentalization. Another option is to nuke the radio in your phone, use only WiFi and VPNs for internet access, and use hosted cellphones from multiple providers. You can still compartmentalize, but need only carry one phone. But you depend on WiFi access.
- Spooky23 8y agoPut it in a bag, and don’t use it.
- fulafel 8y ago
- bitexploder 8y agoMost traffic is HTTP/S. I would bet a decent amount of dollars the NSA can transparently MiTM any common CA certs. Look at what a mess the trusted roots are.