5 ms·
Yeah... NSA literally has MITM proxies/interception of any traffic they want inside every major US tech company (based on my reading/following of Snowden leaks
by aleqs 4mo ago
Yeah... NSA literally has MITM proxies/interception of any traffic they want inside every major US tech company (based on my reading/following of Snowden leaks and others). Anthropic wouldn't be able to exist without implicit NSA approval. This article reads more like a marketing piece for Anthropic/Mythos... and ends by talking about how much NSA wants Anthropic models.
Propaganda.
- strictnein 4mo ago> NSA literally has MITM proxies/interception of any traffic they want inside every major US tech company No, they don't.
- vintermann 4mo agoIt's back to the question of how much you should give the benefit of doubt to powerful people who openly lie.
- strictnein 4mo agoIt's just not technically feasible, so there's nothing to lie about. They're not MITMing petabytes/sec across dozens (hundreds?) of companies and they haven't broken TLS1.3. If I have a box at Digital Ocean and I'm communicating with it with TLS1.3 using a Let's Encrypt cert that I generated, where, exactly, does this magical MITM box come into play?
- aleqs 4mo agoOf course it's feasible, you just intercept the traffic post-decryption on the cloud/server side. You don't control how/where your traffic to 3p cloud services is decrypted.
- kelnos 4mo agoYou keep saying this, but it's nonsensical. If I terminate TLS on the box that does processing, there's nothing to intercept. And these days (especially post-Snowden), many (most?) companies encrypt data when sending between servers within their own (private network) infrastructure.
- aleqs 4mo agoYou have no control about where TLS is terminated when you're talking to a 3p cloud service (with services you don't control/run like cloud LLM APIs). You also have no control about what spyware is installed on/around VMs you rent (and there's a lot). Also when talking about encryption between servers within datacenters you seem to be missing that in order for such multi -stage/path encryption (separate certs/keys) to be possible the data first has to be decrypted at each point, not to mention every major US tech company generally cooperates with the NSA and gives them access to anything they request (including allowing the installation of dedicated hardware to intercept decrypted traffic as has been publicly exposed documented many times already). Yours and others' claims that it's impossible and nonsensical is based on lack of understanding. Yours and others' claims that things somehow got better after Snowden is just a completely baseless statement - if you actually looked into what happened post-Snowden - absolutely nothing was done to prevent NSA spying on any communications they want, in fact it got significantly worse.
- strictnein 4mo ago> Yours and others' claims that it's impossible and nonsensical is based on lack of understanding. lol, no, it's really not. > Also when talking about encryption between servers within datacenters you seem to be missing that in order for such multi -stage/path encryption (separate certs/keys) to be possible the data first has to be decrypted at each point Why would I want the data to be decrypted at each point and why would datacenters do that? Encrypting and decrypting data is expensive computationally, so that's not how things work at all. There's no need to decrypt data to know where it needs to go. That's why we have TCP/IP and other similar stadards. The datacenters can maybe add another layer of encryption on top of my data as its moving around their networks, but there's absolutely no way for them to strip off my encryption. > Yours and others' claims that things somehow got better after Snowden is just a completely baseless statement Things didn't magically get better. A lot of people worked hard to improve the overall security posture of the industry.
- drdexebtjl 4mo agoThat "box" is a virtual machine, no? Do you know what hypervisor is managing it? :)
- chews 4mo ago... not your machines, not your crypto...
- strictnein 4mo agoSo now this magical NSA decryption system is inside every hypervisor? You realize how ridiculous that is, right?
- ai_critic 4mo agohttps://blog.encrypt.me/2013/11/05/ssl-added-and-removed-here-nsa-smiley/ https://blog.encrypt.me/2013/11/05/ssl-added-and-removed-her... https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A Yeah, they did (and probably do).
- parineum 4mo agoHow are they going to MITM communications with certs that never left my machine? Are you suggesting they broke TLS or that they've somehow acquired every private cert generated?
- aleqs 4mo agoYou just intercept the traffic after its decrypted on the server side, or are you suggesting you somehow send encrypted traffic that never gets decrypted?
- gaadd33 3mo agoSo the NSA streams the memory contents of every virtual machine and bare metal server on the internet to get the decrypted traffic? How would that even work at the scale of the internet?
- aleqs 3mo agoHow it works is they build a huge virtual strawman which decrypts and reads all of the data for them then posts online about how NSA spying on people is literally impossible.
- deleted 4mo ago[deleted]
- ceejayoz 4mo agoHow closely have you reviewed your browser's list of default trusted CAs?
- chews 4mo ago[flagged]
- strictnein 4mo agoYes, you have collected a lot of random bits of information from over a decade ago. I'm sure everything you say is still relevant today, especially the conspiracy nonsense. Some of us actually work in security, while others think the NSA and CIA are some magically powerful orgs. Explain how, even with the mystical Room 641A, the NSA can't break a TLS1.3 protected communication channel without either party knowing about it. Assume you have generated a cert with Let's Encrypt. How, exactly, does that work?
- sailfast 4mo agoThank you.
- aleqs 4mo agoExplain to me how you are going to encrypt your LLM API calls with your let's encrypt cert. There are also multiple ways/places traffic you send to typical cloud/tech company is decrypted and can be intercepted. (Surprised I have to point this out to someone who 'actually works in security ' lol) Not to mention US tech companies fully cooperate with the NSA in many cases and are aware of this going on.
- chews 4mo agowhy is europe going to such great lengths to build datacenters and ensure they have no connection to US jurisdiction... GDPR means nothing if there is a persistent threat installed on every instance.
- strictnein 4mo ago> Explain to me how you are going to encrypt your LLM API calls with your let's encrypt cert. I mean, there's goal post moving and there's just building a whole new stadium across the country.
- distill17801 4mo agoIt's generally accepted fact that the NSA broke HTTPS, for some of the time, for some of the services. It's unclear what they do have, but you'd be naive to assume consumer HTTPS is keeping them out. It's too complicated. Do you know everything about CA, SSL, HTTPS, and so on? You make $250k a year working on it? Do you _really_, _really_, know everything? Then you're fired because you're lying to yourself, so you're probably unbearable to work with. We were all freaking out about this with AT&T Thing nearly twenty years ago: and when nobody cared (Bush ran two terms! it helped to pretend AT&T was the only one affected), it gave "them" implicit permission to do it again with Google / Yahoo thing (it helped to pretend those were the only two cloud providers affected) ten years ago. Now, we're all pretending that capitalism is real, and that the three letter agencies are just sittin' on the sidelines, while the world's largest data archiving opportunity is happening voluntarily (some are even PAYING for it!), at some wild-growth companies (with leaders who have too much to lose), who also have existed for just a few years? A 5 year old could probably blackmail Sam Altman, what about all the other middle management? The individual contributors (if they still exist) are of no concern: work is a commodity, it's easy to silo a worker's knowledge. Surveillance opportunity is 10x social media from last decade, because they still have social media, and now, they've began thinking for people. How easy when it is an app on your smartphone. Those mind control experiments back in the 60's with Acid are looking silly by now. Besides, how do you know that the response you're getting wasn't manipulated (and define 'manipulated' across a spectrum of training to nefarious actors impersonating models, by power of court order.) If you think all of that is unfounded ridiculous blasphemy, let me distract you with this instead: if the AI bubble bursts, the compute will be repurposed for mass AI / ML driven CCTV surveillance. Hell, maybe they'll find a way to give you a tax break if you sell your CCTV footage. "NSA literally has MITM proxies/interception of any traffic they want inside every major US tech company" even if this statement is an exaggeration, by playing the long game, they get themselves setup to access what they want in the future. I'm not for or against, but I do live in a safe place thanks to such surveillance (generally in the USA), and I want you to know that this AI Thing is only the latest chapter in the intelligence story.
- strictnein 4mo agoWhat does it mean to "break HTTPS"? Also, there's no such thing as "consumer HTTPS". As for the rest of this... how many conspiracy theories are you trying to pack into a statement? > "even if this statement is an exaggeration" It's not an exaggeration, it is simply false.
- chinathrow 4mo ago> Propaganda IPO incoming.
- micromacrofoot 4mo agothe NSA isn't a bunch of super soldiers, they're cops with too much access, it doesn't take a genius to outsmart a cop
- john_strinlai 4mo ago>they're cops with too much access, it doesn't take a genius to outsmart a cop the nsa has an unlimited budget and spend a good portion of that budget recruiting some of the smartest people in the country. while they dont have super powers, they also arent the town cop who took a 6 month course after high school then joined the force. it does no good to hold them up as mythical figures. it also does no good to pretend they are bumbling idiots. (every math phd i am acquainted with has been approached by nsa recruiters. none of them have been approached by police agencies.)
- schoen 4mo agoI appreciate the balance here. Some of the smartest people I know have worked on fighting NSA, but they had a drastically smaller budget than NSA itself, and the mental availability bias is skewed by the fact that the "fighting NSA" people talked about their work all the time, while the "being NSA" people generally didn't. I do know one extremely smart person who went to work there, and I witnessed a failed recruitment of another extremely smart person.
- micromacrofoot 4mo ago> every math phd i am acquainted with has been approached by nsa recruiters. how many of them took them up on the offer, and how many are in leadership roles? it takes a very narrow range of personality to want to be a cop, which at the end of the day is a government job... the only people they make rich are contractors I'm not saying there aren't smart people working there but it's ridiculous to assume they have an iron grasp on all communication from the top tech companies in the world, while also monitoring half the world's governments... they just don't
- john_strinlai 4mo ago
- yard2010 4mo agoPlease provide sources for such bold claims
- aleqs 4mo agohttps://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/PRISM https://www.wired.com/2013/10/nsa-hacked-yahoo-google-cables/ https://www.wired.com/2013/10/nsa-hacked-yahoo-google-cables... https://www.eff.org/nsa-spying https://www.eff.org/nsa-spying
- schoen 4mo agoI worked on these cases at EFF and I'm skeptical of the automatic "NSA has access to everything" intuition. What we learned from that era includes things like (1) spy agencies are incredibly aggressive and pursue tons of different angles to get access to things (2) spy agencies have a lot of money (3) spy agencies often have interpretations of law that would surprise the public or legal experts (and sometimes courts have issued sealed rulings permitting them to do things that surprise the public or legal experts later when they're unsealed) (4) some people throughout different parts of society assume culturally that companies in a country "should" generally help the spy agencies of that country's government because they are the "good guys" or "on the same team" or whatever These things are all pretty bad and scary, but they still don't imply absolutely infinite power or access, because all of them come with different kinds of pushback. People also just tell them no! I want to write an article with a colleague about the continuing role of culture here, because I think there are companies or industries where the default reaction is to want to cooperate with the government, and others where the default reaction is not that. There are certainly secret things that have never come out, e.g. whatever Senator Wyden keeps alluding to, and what kind of program or authority was behind the interception of hardware shipments to covertly tamper with them, and whether there is a bulk financial data interception program, and presumably lots of other stuff. I don't agree with these things, and I want them to be exposed and stopped, and I also don't think they constitute infinite power over all parts of the tech industry.
- bflesch 4mo ago[flagged]
- distill17801 4mo agoPropaganda indeed: my instinct says we are being lied to about how three letter agencies and military are paying for services. They give us a PR front that Uncle Sam is a regular paying customer just like you and me, but they're probably running the show: this is the largest data gathering operation since 9/11. Sorry everyone: but the conspiracy is so obviously not, it's nauseating to admit, because you see all your friends, family and co workers dumping so much everyday data into these services.