4 ms·
> "it’s no big secret that the NSA is listening in on the node/isp level" The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pr
by strictnein 1mo ago
> "it’s no big secret that the NSA is listening in on the node/isp level"
The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?
- milkshakes 1mo agosee https://en.wikipedia.org/wiki/XKeyscore https://en.wikipedia.org/wiki/XKeyscore for the sota from 20 years ago
- strictnein 1mo agoYes, I'm well aware of XKeyscore. If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed? Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it. Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
- DANmode 1mo agoYou’re talking about two different things. One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of. > how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed? ISP taps globally, undersea cable taps, the list goes on.
- leonidasrup 1mo agoMost Tier 1 network owners are U.S. companies or U.S. friendly companies, tapping undersea cables is not necessary in many cases, just ask the owner.
- axus 1mo agoYou think the politicians are going to say "The career employees made some convincing arguments about why this is impractical / immoral, guess we'll give up our unregulated power/omniscience"? Or, they will raise the military budgets and continue skipping the audits.
- junofan 1mo agoIsn’t their whole thing supposed to be spying on foreigners? They seem to be quite successful. There aren’t that many exchanges [1]. Could probably manage with cash, guns, and some know-how. [1]: https://en.wikipedia.org/wiki/List_of_Internet_exchange_points_by_size https://en.wikipedia.org/wiki/List_of_Internet_exchange_poin...
- strictnein 1mo agoIf you just look at the largest 4 of those, you'd have 100Tbps of traffic to monitor, with an average throughput of roughly half of that. That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site. If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.
- mitxela 1mo agoThat's nothing a rack full of fast switches can't handle. A rack full of fast switches already does handle it - where do you think the original copy came from? They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.
- strictnein 1mo agoSwitches handle data at far faster rate than any hardware can actually inspect it, store it, process it, etc. But yeah, just a rack of "fast switches" is all it takes to route hundreds of petabytes of data each day. You should let the data center operators know. They'd save billions.
- mitxela 1mo agoSwitches do inspect it. They also have a feature designed for wiretapping, which copies a percentage of traffic to another port. They may have a feature to copy 100% of traffic matching a certain filter. Managed switch ASICs have this feature even though it's usually not exposed in the CLI.