10 ms·
NSA spied through Angry Birds, other apps: report (2014)
- simonvc 1y agoWas drinking in a bar in Espoo in 2012 or 2013 and heard this from someone at rovio. At the time they used Riak db and basho were onsite and we asked why they didn't enable inter server encryption. "Because nsa pay us 10m not to". Guess nsa pulled the Riak cluster protocol off the aws fibre.
- fiatpandas 1y agoI’m actually comforted by the fact that NSA needed encryption turned off to spy.
- danielheath 1y agoOr it was simply cheaper than cracking it.
- hx8 1y agoI was comforted by the idea that it is more expensive than $10m to crack encryption, but this was in 2013.
- greenavocado 1y agoEarth's oceans contain approximately 1.35 billion cubic kilometers of water. To raise this entire volume from an average temperature of 3.5C to boiling (100 C), we'd need roughly: 1.35 x 10^21 kg x 4,184 J/(kg C) x 96.5C is approximately 5.45 x 10^25 joules That's 545 million exajoules or about 10,000 times humanity's annual energy consumption. If you tried to brute-force AES-256 with conventional computers, you'd need to check 2^256 possible keys. Even with a billion billion (10^18) attempts per second: 2^256 operations / 10^18 operations/second is approximately 10^59 seconds. You'd need about 2.7 x 10^41 universe lifetimes to crack AES-256 At about 10 watts per computer, this would require approximately 10^60 joules, or roughly 2 x 10^34 times the energy needed to boil the oceans. You could boil the oceans, refill them, and repeat this process 200 trillion trillion trillion times. For RSA-2048, the best classical algorithms would need about 2^112 operations. This would still require around 10^27 joules, or about 20 times what's needed to boil the oceans. ECC with a 256-bit key would need roughly 2^128 operations to crack, requiring approximately 10^31 joules It's enough to boil the oceans about 2,000 times over. Quantum computers could theoretically use Shor's algorithm to break RSA and ECC much faster. But to break RSA-2048, we'd need a fault-tolerant quantum computer with millions of qubits. Current quantum computers have fewer than 1,000 stable qubits. Even with quantum computing, the energy requirements would still be astronomical. Perhaps enough to boil all the oceans once or twice, rather than thousands of times.
- gosub100 1y ago> you'd need to check 2^256 possible keys it's very unlikely you'd have to check the entire keyspace before you found it. On average it would be about half.
- greenavocado 1y agoIs there a more efficient way? What's the state of the art?
- timschmidt 1y agoIDK, let's ask a mathematician. Oh, they all work for NSA.
- aaronbrethorst 1y agoWomp womp. https://therecord.media/nsa-to-cut-up-to-2000-roles-downsizing https://therecord.media/nsa-to-cut-up-to-2000-roles-downsizi...
- timschmidt 1y agoI like to tell myself that everyone at NSA is a fine upstanding patriot, and that the agency only ever does what is in the best interest of the American People, but that does feel naive at times. Like when they infiltrate international standards bodies to introduce backdoors. Is downsizing the NSA something we're upset about?
- akimbostrawman 1y agoIt doesn't even really matter what character most of them have. Most information is on need to know basis for a reason so the one giving the orders can tell a tale about foreign terrorists while the grunts happily surveil the common man.
- 1y ago
- nullc 1y agoWrong assumption. Lets imagine they could costslessly crack the encryption there. But as soon as they use any information gathered that way they risk leaking that they have this incredibly valuable capability. ... valuable and very fragile since people can easily change encryption schemes. Better to pay every party you need to to have boring vulnerabilities and security shortcomings, so that any information leak doesn't need a capabilities revealing explanation. So I think this gives you no information on their capabilities beyond bribing commercial players, which isn't exactly new. In the past (and presumably now) our intelligence apparatus has outright owned crypto/security companies in order to distribute backdoored technology. And of course they have, they're not prohibited, it's highly effective, they'd be incompetent not to.
- bb88 1y agoBut knowing still gives you an advantage, even if you can't use it legally -- because you can still use it illegally. LEO and Prosecutors will use "parallel construction" to construct a narrative about how information was obtained in a legal way even though it was clearly obtained illegally. Or you could choose to only act on 5% (e.g.) of the information gleaned -- and that which could clearly be shown to be leaked by a third party. Or say if you were tapping the information of a mob boss, you could leak the information to a competitor and let justice work it's way through the streets instead of the courts.
- nullc 1y agoIt's tricky, because you run the risk that any use risks disclosing the capability. Targets can even set traps. E.g. I caught irc opers spying on PMs by sending trap URLs where I secretly could see the access logs. Because great care was taken to make sure the URLs existed nowhere else when they got loaded it was a confirmation that the traffic was monitored. Now perhaps a somewhat safer tool is to just use the cracking to determine the best targets to bribe or backdoor, but only allow the group with the cracking power to give the names of services to monitor at any cost.
- bb88 1y ago
- emmelaich 1y agoYou could leak the private key accidentally on purpose but that would be harder to plausibly deny involvement if that fact leaked.
- deafpolygon 1y agoI'm reminded of a certain XKCD comic[1]. The US government probably doesn't need to crack the encryption to get what they want. [1]: https://xkcd.com/538/ https://xkcd.com/538/
- starspangled 1y agoOn the other hand it would be a very cheap counter espionage measure if a small stream of such payments was enough to convince China et al that the NSA had not broken encryption.
- xori 1y ago"How do you get corporate secrets out of a software engineer? Sit them next to another engineer on a plane."
- frollogaston 1y agoIt's elegant. The other person can spill amazing secrets, but there's no way to prove it, so nobody will believe you second-hand.
- arealaccount 1y agoWhy wouldn’t they just give them DB access for the 10m? Id assume NSA would prefer the database to remain encrypted and have an admin account?
- radicaldreamer 1y agoDeniability
- dylan604 1y agoPlausible. You can always deny anything. It just might not be so plausible under scrutiny.
- bb88 1y agoIf you're the NSA, you can tell Amazon, "Hey here's $1B. You're going to get some fiber outages, and we're also going to buy a bunch of compute from you at an exorbitantly high price you'll charge us. It's fine, we're the NSA. So when the outages happen, don't announce it. Also terrorism."
- deleted 1y ago[deleted]
- bb88 1y ago10M sounds like a nice executive bonus. I'm not saying it's a bribe -- I would never, ever do that.
- CrossVR 1y agoI once asked a VP of engineering at a major ISP why they don't add a layer of encryption to their peering and customer connections to prevent spy agencies from tapping their fibre cables. I was expecting him to say it would be too expensive to upgrade all their network hardware given the amount of traffic. Instead he said: "our routers can already do that, but the government regulator stepped in and prevented us from turning it on."
- rdtsc 1y agoThat's pretty wild. Was it an "investment" of some sort, and then the CEO got a hint with a wink, that there is more where it came from if they don't enable any encryption. Anyone from Rovio who got less than $10m in their pocket willing to tell us a story?
- adeon 1y agoIs there any reliable source for NSA paying Rovio other than this random bar discussion? Not that I don't believe you or that I'm naive about NSA and the power of money, but I looked around news in 2014 and the accusations against Rovio specifically are a bit different flavor. It seems that Rovio was oversharing data to ad networks (Millennial Media comes up a lot), and NSA likely slurped data from the advertising companies. This bar banter is suggesting that NSA had some kind of arrangement with Rovio directly instead, and Rovio willingly went along. Or alternatively, do you feel the Rovio employee's blabbering was talking about an actual, real NSA deal with Rovio, or was it more like a bar joke and direct NSA co-operation was not really implied? (e.g. "we know our security is bad, but these ad companies pay us $XX million to not use encryption so it's sorta like NSA pays us to keep it that way sips beer"). I'm interested, because if that is an actual thing that happened, then that's an example of NSA paying a Finnish company $$$ to weaken their security, and the Finnish company willingly agreeing to that. Is it in NSA's Modus Operandi to approach and then pay foreign companies to do this sort of thing? Your comment is describing it in few words, but to me it sounds like it maybe wasn't implying an actual NSA direct co-operation, more like someone doing bar banter and being entirely serious. But that's just me trying to guess tone. (I'm Finnish. I want to know if Rovio has skeletons in their closet. So I can roast them.)
- leftcenterright 1y agofrom an intelligence perspective, this is business as usual. - Rovio sold data to ad companies (ad companies primarily based in the US) - They used AWS (to which of course NSA has legal access) - Data is not end to end encrypted, all metadata sits on servers in plain text and within AWS even moves from server to server in plain text How much insight metadata can grant to someone like NSA is still wildly underrated. - https://www.propublica.org/article/spy-agencies-probe-angry-birds-and-other-apps-for-personal-data https://www.propublica.org/article/spy-agencies-probe-angry-...
- adeon 1y agoAh yeah, I saw the propublica as well, it was one of the first articles I found when looking on the topic. I don't doubt at all that Angry Birds data was used by NSA, doesn't seem controversial. The specific question I am interested in is: Did Rovio knowingly and willingly accept $$$ from NSA (directly or indirectly) to weaken their security? I.e. were they acting as a willing accomplice. Because that part would be unusual for Finland (well, at least as far as I know). For US companies I wouldn't bat an eye at news like this.
- fsckboy 1y ago2014? this is really old news, and there's no smoking gun in here. it's not like they are looking through your camera or listening to your mic, it's just "who is using this app" type stuff, and the NSA denies they target people who they are not seeking for other reasons i'm not saying "believe the NSA" or the Five Eyes, but you already know how you think about that
- greenchair 1y ago[flagged]
- froggertoaster 1y agoThey call them "slippery slopes" for a reason. Why were they collecting this data at all, and why is it constitutional?
- 01HNNWZ0MV43FF 1y ago> old news Vogon detected "There's no point in acting surprised about it. All the planning charts and demolition orders have been on display at your local planning department in Alpha Centauri for 50 of your Earth years, so you've had plenty of time to lodge any formal complaint and it's far too late to start making a fuss about it now."
- alabastervlog 1y agoThey deny they target people they aren’t seeking for other reasons (uh, duh? This basically doesn’t say anything at all) but don’t deny mass collection, nor using your data to try to target others (or you, if “other reasons” come up!) or to build a general spying-on-everyone surveillance system. But sure, I do believe them that they don’t bother to look at it unless they want to. Like… yes, that’s how looking works.
- chrischen 1y agoThis is exactly why adversarial countries like China want to block large multinational social media and technology companies from their market. India saw facebook try to meddle in their elections. This is probably why the US should block TikTok, although there are further repercussions on free speech and the free market (something China ideologically doesn’t care about).
- shadowgovt 1y agoIf the US wants to stop meddling in their elections, they should block Facebook.
- 01HNNWZ0MV43FF 1y agoTBH the US should block Facebook it's just one party doesn't have the voter base and the other party is evil
- alabastervlog 1y agoEngagement-driven personalized “algo” feeds need to be banned in general, by any countries that don’t want to continue swinging rightward. I would feel a lot more confident about the future of liberal democracy if this were under serious discussion in at least some countries, but, afaik, it’s still not even now (it should have been years ago!) which is worrisome.
- _heimdall 1y ago
- MyPasswordSucks 1y ago[flagged]
- bigbuppo 1y agoAnd don't forget that ad tech has grown more pervasive since then. The NSA is the least of your troubles these days.
- OutOfHere 1y agoAd-tech does not put people in prison or deport them. The NSA does, via parallel reconstruction.
- kjkjadksj 1y agoNo it just takes the money out of their pocket and makes them addicted to things so it is Ok.
- OutOfHere 1y agoIt is not okay, but it is not anywhere as bad as what the government does in the name of security.
- Barracoon 1y agoThe NSA does not do either of those things
- OutOfHere 1y agoThey do on occasion pass their intel to other domestic agencies which then do the field work of parallel reconstruction and locking people up. Additionally, the NSA has been silently sabotaging computer security for decades with their exploitable backdoors, making things worse for everyone.
- gruez 1y ago>It wasn't clear precisely what information can be extracted from which apps, but one of the slides gave the example of a user who uploaded a photo using a social media app. Under the words, "Golden Nugget!" it said that the data generated by the app could be examined to determine a phone's settings, where it connected to, which websites it had visited, which documents it had downloaded, and who its users' friends were. Sounds like those apps weren't using SSL, and NSA could eavesdrop on whatever API calls or telemetry it was sending? There's no real evidence that those apps are complicit, even though the article tries to imply that.
- frollogaston 1y agoTikTok's CDNs also don't use SSL, unless that changed.
- mrheosuper 1y agoSSL added and removed here ;-)
- buyucu 1y agonot using SSL means the app devs were either stupid, or they were complicit.
- engels_gibs 1y agoBut remember folks: China is spying you!
- nashashmi 1y ago“And that’s why we need to ban TikTok” but not so they can stop influencing you. “And why we need to stop you from supporting terrorists” but not because we are against your freedom to speak.
- Calliope1 1y ago[flagged]
- areyourllySorry 1y agoEMDASH DETECTED EMDASH SPOTTED ON LINE 3 INITIALIZING GPTZERO.EXE DETECTED STRING: “just a game — or a gateway ” AI CONFIRMED TOO COHERENT DETECTION OFF THE CHARTS OUTPUT: “DON'T EVER USE AI AGAIN.”
- johnisgood 1y agoLibreOffice automatically inserts emdash when I press space after typing "-". :P
- zghst 1y agoDetasking, minimization, FAA/PAA incidents database, etc., yeah right!
- ddxv 1y agoRather than going through 1000s of app companies, why not go directly to the 100s of third party analytic companies? From my research most all apps use some SDK which tracks users. Many apps use 3 or 4 for various marketing / product / business use cases. I've been tracking this on https://appgoblin.info/companies https://appgoblin.info/companies if anyone wants to check. Try looking at the "no analytics" found groups, which are just apps I haven't found evidence of 3rd party trackers, almost certainly they do use them. I would like to see world where Angry Birds data at least stays on Angry Birds servers and have been working on building a part of that with OpenAttribution (https://openattribution.dev https://openattribution.dev) to let app/game companies build their marketing pipeline with at least one less tracker in the app. I think as compute is getting cheaper a lot of this should/can be self-hosted by at least larger companies so they have full control of their BI tools and the data underlying it.
- MartinGAugustin 1y ago[dead]