4 ms·
I can confirm much of this article. (A couple years ago I provided some comments here https://news.ycombinator.com/item?id=3296691 https://news.ycombinator.com/
by secthrowaway 13y ago
I can confirm much of this article. (A couple years ago I provided some comments here https://news.ycombinator.com/item?id=3296691 https://news.ycombinator.com/item?id=3296691)
There's lots of condemnation of the poster, and the NSA practices and some of the murkier parts of this article. I thought I'd tip in with some explanations as possible while staying outside of anything classified or naughty.
jonknee: https://news.ycombinator.com/item?id=6910978 https://news.ycombinator.com/item?id=6910978
- "It's compartmentalized enough that the individual actors can justify their actions by the assumed competence and benevolence of the others."
It's compartmentalized a bit more than the OP lets on for mostly security/separation of concerns/need-to-know reasons. For example, a Air Force analyst who is cleared to view TS//SI material won't have access to the NSA systems directly. Some of the NSA systems have external (Intelligence Community (IC)) facing equivalents that omit quite a bit of the information that less scrutinized IC analysts shouldn't have access to. w/r to the information the NSA collects, NSA employees and contractors are held to stricter standards about how that material is used and treated. An analogy, a minor commits a crime and his record is sealed. The local court employees who handle the record, the judge etc. have really nothing that prevents them from leaking that information to an overzealous cop or lawyer or some such other than the standard to which their held for their job. It's more or less the same thing with the NSA.
> The mental leap here is subtle, but substantial. Since I have been told I can't use US selectors , I assume the system enforces this.
Actually, one of the higher standards the NSA employees are held to, and I believe they sign something to effect is that it's outright illegal for them to do so and even one misuse could result in loss of employment, clearance (a death sentence in IC heavy employment areas) and possibly time in prison as a felon. This is taken very seriously and I've never known an NSA employee to not treat this rule and US citizen data as radioactive to them.
https://news.ycombinator.com/item?id=6911054 https://news.ycombinator.com/item?id=6911054
> Definitely a bizarre mix, I thought it was a parody a couple of times. To combat the threat of nuclear war with the completely isolated totalitarian state of North Korea we must create and store copies of all global communication...
It's easy to generalize, and if the world worked as simply as the model you propose here, then things would be much better for everybody, but it simply doesn't. For example, to uphold various sanctions regimes, by law, the U.S. must know if a business has connections two hops out that are linked to any bad activity. For example, how did Kim Jong Il buy all his whiskey? It's outright illegal for a U.S. company to sell to the North Korean government. Okay, so they sell to an overseas distributor who then sells to the North Korean government. Turns out that's illegal as well and the government must take action to not allow the U.S. whiskey maker or the distributor to operate in the U.S. any longer. Okay, so the whiskey make checks out their distributors finds one who doesn't sell to NK, but one of their customers does. Same deal, it's illegal for anybody in that chain to operate in the U.S. After that, the chain becomes so long it's not worth looking into and Kim Jong Il was eventually able to get his whiskey.
Just talking whiskey and North Korea here, but you can guess it goes for all kinds of goods and countries under various sanction regimes. So how do you propose things should be collected? Collecting only on North Korea gets you nowhere, it's everybody else who may or may not be supplying whiskey to the Norks that makes things much harder and requires a much larger collection apparatus.
https://news.ycombinator.com/item?id=6911216 https://news.ycombinator.com/item?id=6911216
> It's helping diplomats illegally snoop on our allies.
Good! Our allies are most definitely snooping on us! Spying and espionage is sometimes called the second oldest profession for a reason. There's been no time in history that two countries aren't doing a bit of spying on each other, most especially at the diplomatic level.
rst: https://news.ycombinator.com/item?id=6911150 https://news.ycombinator.com/item?id=6911150
> In fact, it's been known for months that the DEA receives intercepts from the NSA in such volume that they have an office devoted to handling them (the DEA's "Special Operations Division").
This is a problem. In general, the work the IC does in collection does not hold up to LE scrutiny. Having worked on both sides of the fence, LE is both more difficult in some cases and easier in others to work in. For example, you need a warrant to gather phone records in LE, but you can share those records more freely once you have them. In the IC the opposite is true, you can pretty much get whatever you need, but it's virtually useless if a criminal approach is taken. That's why it's often simpler to blow up the target then to arrest and try them. Parallel Construction is an investigative focusing approach that saves LE from getting collection warrants that go nowhere. The IC approach is to find the connections or whatever, then help LE figure out where to focus their warrant-based approach in doing the same collection from their side. Scrubbing U.S. Persons IC data and reusing it directly for LE is highly illegal for all of the participants involved.
revelation: https://news.ycombinator.com/item?id=6911022 https://news.ycombinator.com/item?id=6911022
> Well, following his explanations, you can fail the polygraph and just do it again. The cost of failure is zero, so really just keep trying.
Actually the penalty after enough tries is no clearance which means no job and a permanent record that you were denied a clearance...which pretty much deep sixes any attempt in the future to get one. In some parts of the country, like the Washington D.C. area, that's virtually a career death sentence.
kabdib: https://news.ycombinator.com/item?id=6910969 https://news.ycombinator.com/item?id=6910969
> My best friend's dad was a spy in the CIA
> During the 70s and 80s my dad worked with Russian scientists
> So, how likely is it that my email is read, that my phone records are looked at, and so on? What are the chances that I'll have trouble the next time I cross a border or try to board a plane? One percent? Fifty percent?
Assume it is collected but probably not read, but not for the reasons you gave above. There's just simply not enough manpower to read everybody's email, and it's a useless thing to try to accomplish. Now suppose one of the guys you email also emails somebody who's "nefarious" in some way. Then yeah, maybe your email is read. And if all you talk about in your emails are things that don't involve an armed insurrection against the United States you'll probably be filed into the "don't give a shit" bucket and the analyst will move on.
A common thread here is that everybody who's worried about their email being read seems to assume that whatever they're doing is important enough for it to get read. Trust me, it isn't.
(continued next comment)
- secthrowaway 13y agomd224: https://news.ycombinator.com/item?id=6911261 https://news.ycombinator.com/item?id=6911261 > Anyone who defends the NSA on the grounds that it only targets those who are worthy of targeting needs to convince me that another COINTELPRO will never happen. I would actually welcome such an argument, since it would make me feel a whole lot better about this. You raise a very good point. I don't think there are many in the IC who would have a problem with more (and better) oversight...it helps them feel more legitimacy in what they're doing. All that being said, assume that there will be another COINTELPRO or similar. It sucks, but to be perfectly honest with you, you aren't important enough to convince one way or the other about it or about approving of the various collection programs the NSA is running. If half of the comments here are to be taken at face value, almost nobody on HN knows enough about the issues involved to be consulted or for their opinion to be considered. I'll draw a parallel here to the outcry over technology centered court cases or software patents, an opinion often given here is that engineers or software experts should be involved in deciding those cases because the layman doesn't know enough about it to have an informed opinion. It's just as true with IC issues. What's troubling is that oversight is via Congress, who until the last election were likely laypeople themselves. So the expertise to properly evaluate, oversee and monitor what's going on simply isn't there. sedev: https://news.ycombinator.com/item?id=6911078 https://news.ycombinator.com/item?id=6911078 > This reads like it was penned by someone who's never heard of the Stanford Prison experiment or Milgram's research... You bring up good points. One of the issues with the IC is one of internal monitoring (as we're all now seeing). Who watches the watchers? There's notionally a number of very serious laws, or committees and counter-X professionals who are supposed to be doing this, but to be honest. Once you're cleared and stuck on a project, there's really very little day-to-day oversight of any kind. I personally would welcome a higher level of scrutiny, but I think the equation of "spend manpower watching watchers" vs. "spend manpower looking for bad guys out in the world" has, and will continue to, balance on the later. https://news.ycombinator.com/item?id=6911091 https://news.ycombinator.com/item?id=6911091 > If you'd never heard of parallel construction before today, that seems to powerfully undermine your credibility. He only worked there for two years on a single program. I challenge anybody here who works for any organization larger than 3 people to have perfect knowledge of every single thing their organization is doing. Unless you work on the bits that interface with the LE community you'd probably never have had opportunity to know anything about it. I bet he also doesn't know the details of companies the NSA contracts to do their plumbing or handle their trash. EthanHeilman: https://news.ycombinator.com/item?id=6910896 https://news.ycombinator.com/item?id=6910896 > The NSA has a history of sharing intelligence with LE, to state that the NSA is not a LE agency is extremely misleading, if not an outright lie. I don't think you understand what a LE entity is, the powers and limitations that LE organizations operate under or how they differ from IC organizations. Saying the NSA is LE because they cooperate with LE is like saying the Department of Agriculture or Labor is an LE agency because they sometimes have to cooperate with LE. jjoonathan: https://news.ycombinator.com/item?id=6910922 https://news.ycombinator.com/item?id=6910922 > It's good to hear that many NSA employees take the police/military distinction seriously, but we know for a fact that some higher-ups don't... This is true, and it's particularly vexing to work in the IC and have senior officials asking you to participate in outright illegal activities. It doesn't happen often, but I've seen both people ruin their careers saying no and those that want to keep their job and say yes. It's usually under the auspices of "helping out to stop bad things", and it's very hard to say no when activities are couched that way...despite very many of the people on here talking publicly about their very righteous and moral high ground, placed in the same position, the vast majority of HN users would want to stop bad things from happening even if it meant crossing the line a bit here or there. Because, honestly, if you choice is help stop innocents from getting killed vs. sit on your hands because of some futzy law someplace that ties your hands, most of us would feel like we'd rather take the immediate action to stop the bad guys. "Mission Expediency" is the word of the day when it comes to these matters. mtgentry: https://news.ycombinator.com/item?id=6910911 https://news.ycombinator.com/item?id=6910911 > No offense to OP, but this reads like propaganda to me. I can confirm that this represents the mindset of most of the people I've worked with in the IC. It does take a certain kind of personality to sign-up and go through all the hassles involved with getting employed in the IC and that self-selection seems to attract a certain kind of personality type. > But I wouldn't be surprised if there was some sort of concerted effort by the NSA to encourage a dialogue with hackers on platforms like HN. There really isn't, other than to not discuss classified information. Keeping track of what's classified and not when you spend near a third of your life and half of your waking hours dealing with only classified things is complex enough that most people just don't engage with the "unclean" public. jurjenh: https://news.ycombinator.com/item?id=6911235 https://news.ycombinator.com/item?id=6911235 > What I'd be more interested in is how much this issue is being discussed internally. If these discussions are allowed, or even surreptitiously encouraged, then I'd take that as a possible internal propaganda push, subtle as it may be. Discussions about these issues, in the way that they're being discussed here, are not terribly common. The milieu of working in the IC just doesn't lend itself to these kinds of topics, in these kinds of ways, as focuses of conversation. Mostly what's discussed is the lines you aren't supposed to cross and the penalties for crossing them. But more often then not, casual conversation is about anything other than IC topics. After a hard day of spying, you really want to just engage in something else. Bizarrely, discussing Snowden might be tricky inside of the IC because you might discuss something that was leaked that you technically don't have a need-to-know for. So specific cases like this are not often serious topics of conversation. (continued next comment)