5 ms·
First off, I don't think anyone except "tinfoil hats" really imagined the scale of NSA spying. Who really thought the NSA would try to subvert the cryptographic
by salient 13y ago
First off, I don't think anyone except "tinfoil hats" really imagined the scale of NSA spying. Who really thought the NSA would try to subvert the cryptographic standards they pretend to create to "secure systems"? Who really thought they'd go to US service and hardware companies and ask them to implement backdoors for them?
Also, there's a big difference between letting NSA protect US against Real Threats - real national security people-are-going-to-die threats, and spying not just on every single citizen on the planet (which includes corporate espionage), but on American citizens and companies, too.
Just like everyone has a little "evil" in them, without all of us being Hitler, the NSA can do a little bit of spying on important targets, without going 10/10 on the scale of evil spying.
So no, I really don't think "this is their job" or that "everyone knew they were doing this". I think the vast majority of people thought NSA would be reasonable with their spying.
I also hate it when people say, "didn't you see when they passed the Patriot Act? You should've expected this." Perhaps, but if you go back to when they passed it, they did it in literally hours, and if you watch Bush speak about it [1], he makes it sound as if they are only going to use it to spy on the terrorists' communications - not everyone's. Going by how fast they passed the bill, and how few details were offered, you can't really blame most people for "not knowing".
Heck, it was even called the "anti-terrorism bill" on TV, so I don't think people imagined that meant all of their communications are going to be swept up, because they were now thinking everyone is a potential terrorist (which is what "collecting it all" means) until proven otherwise by their systems.
[1] - http://www.youtube.com/watch?v=DfRcfTakhFo http://www.youtube.com/watch?v=DfRcfTakhFo
- mgkimsal 13y ago"Going by how fast they passed the bill, and how few details were offered, you can't really blame most people for "not knowing"." True, but perhaps someday we can learn to not advocate the passage of bills in such a short amount of time that representatives themselves do not have a chance to read or digest them, much less have debate about the specific contents. I say perhaps because I suspect we'll continue to see much more of this until there's some sort of mechanical change requiring a X day waiting period on any legislation introduced, and/or something requiring reps to sign a document with real penalties for perjury that they've read the damn things before voting on them.
- leephillips 13y agoThis sounds great in principle, but it would turn the way congress does business upside down (maybe not a bad thing). I've heard stories about hundreds or thousands of pages being added to bills by staff just minutes before a vote. I suspect the way it works is that the legislators tell their staffs what they want the bills to do, rely on them, and have no interest in actually reading the result (and who can blame them - ever read legislation?).
- beagle3 13y ago> I suspect the way it works is that the legislators tell their staffs what they want the bills to do Many bills today (perhaps most) are not written by legislators and their staff, but rather by lobbyists. That might have been the case since forever (if the movie "The Aviator" is not too dramatized, this has been true in the 1930's as well)
- JunkDNA 13y agoBut my issue is that very little in the slides released by Der Spiegel talks about the actual targets where devices were employed. There is the Internet dragnet stuff which is rightly worrisome, but the vast majority of the slides are similar to the one about the iPhone and detail targeted exploits: specific phones, specific servers, specific routers. Targeted spying on real threats requires those capabilities. Unfortunately, if deployed at scale they could be used for large scale spying. But there is no evidence here that these methods are used in this way (in contrast to stuff like PRISM). I think that's what makes me uncomfortable here. There is a bit of sloppiness going on where people are trying to conflate techniques for targeted spying with mass surveillance. I think it's important to be careful to make the distinctions.
- mirkules 13y agoTo me it seems that the underlying issue in these talks isn't that these methods exist or that they can be employed on a large scale. The issue is that these powers are complety secretive and unchecked. I do agree that they could have been more clear on this.
- Zigurd 13y agoSome of these items need to be deployed with "black bag jobs" and that has some natural limits. Still, we know that people like Martin Luther King were the targets of dirty tricks campaigns, and that the treatment of people like Jacob Appelbaum indicate such dirty tricks are still in play. There are enough prominent technology and finance people reading this who back controversial and truly disruptive technologies like bitcoin, biotech hacker spaces, open source crypto, etc. that they may have a reasonable concern about being a target.
- leephillips 13y ago"Who really thought the NSA would try to subvert the cryptographic standards they pretend to create" I first encountered speculation that this was the case in a textbook from 1986, in a chapter discussing encryption algorithms in wide use that were contributed to by the NSA. "Who really thought they'd go to US service and hardware companies and ask them to implement backdoors" The fascinating book The Puzzle Palace, from 1982, describes the precursors to the NSA setting up shop in telegraph offices and copying all traffic with the collusion of the new industry. None of this is new, and none of it is in the least bit surprising.
- el-mapache 13y agoNone of this is surprising to an extremely small subset of the global population, those who have had the means to study computer science and cryptography, and the history(ies) of government sanctioned spy agencies for a long enough period to be able to glean insights into the future behaviour of said agencies. Since not everyone who reads this site meets those criteria, I suspect that it is even a not-insignificant subset on hacker news as well.
- leephillips 13y agoClearly you're right, in the sense that, as a simple statement of fact, the NSA revelations are surprising to a great many people, maybe most people who learn of them. But there is a sense in which, when people say "this is not surprising", it implies "to people who know some things about the subject". I guess this expression, used this way, might come off as elitist or haughty, but I think it's a pretty common usage. Another reason I'm surprised at all the surprise is that I never studied cryptography, computer science, or the history of spy agencies systematically. The Puzzle Palace was a popular book, widely read, and I learned about NSA involvement in academic cryptography research by accident while studying up on numerical algorithms for physics simulations.
- deleted 13y ago[deleted]
- aaronem 13y ago
- tonyb 13y ago"Who really thought they'd go to US service and hardware companies and ask them to implement backdoors" To this point has there been any evidence that a company has add in a "backdoor" at the request of the NSA? The media keeps using the term "backdoor" when they talk about covert access but that doesn't mean that some company added a "NSA Access" feature to their product. It is possible (I would even say probable) that the NSA has exploited unknown vulnerabilities rather than used built in backdoors. Covert access is only effective if it remains covert. If companies are building in these features then a lot more people know about it and it reduces the likely hood of staying covert.