6 ms·
Jamming XKeyScore
- aburan28 12y agoThis is funny because Robert Graham is very likely a GCHQ asset.
- crimcrom 12y agobased on even just his last few blog posts i can see "blowhard" or "shill" but intelligence asset? what's your reason for saying this?
- aburan28 12y agoAt the bottom at this page is part of the evidence http://cryptome.org/2014/06/wl-harrison-hoax.htm http://cryptome.org/2014/06/wl-harrison-hoax.htm . Every single time a anti-NSA story comes out he is first to try to defend the actions of the NSA. He is a provocateur and clearly biased.
- eli 12y agoSomeone consistently disagreeing with you is NOT evidence they are acting maliciously or are part of a conspiracy against your viewpoint.
- rdtsc 12y agoEven if you don't like Slavoj Žižek, he has a funny story related to this: https://www.youtube.com/watch?v=PIPjmmmh_os#t=1614 https://www.youtube.com/watch?v=PIPjmmmh_os#t=1614 He talks about how he and his associates were dissidents and had meetings and they agreed on a protocol to talk gibberish at the end. Fake, military sounding code words and stuff. It was a fun thing to do. Years later they discovered the amount of head-aches and resource drain they caused on the secret police who tried in vain to discover the meaning in this nonsense, thinking that perhaps there was some serious stuff going on. That is why I hope one good thing comes out of it, and that is people might start taking cryptography slightly more seriously and they'll also start actively fighting back. This is one way and it is fun too. (for some strange value of "fun").
- nmrm 12y agoAnother great Žižek story/parable about surveillance is the red ink one, which I think is also relevant here: So what are we doing here? Let me tell you a wonderful, old joke from Communist times. A guy was sent from East Germany to work in Siberia. He knew his mail would be read by censors, so he told his friends: “Let’s establish a code. If a letter you get from me is written in blue ink, it is true what I say. If it is written in red ink, it is false.” After a month, his friends get the first letter. Everything is in blue. It says, this letter: “Everything is wonderful here. Stores are full of good food. Movie theatres show good films from the west. Apartments are large and luxurious. The only thing you cannot buy is red ink.” This is how we live. We have all the freedoms we want. But what we are missing is red ink: the language to articulate our non-freedom. The way we are taught to speak about freedom— war on terror and so on—falsifies freedom.
- nfkesnflkesnf 12y agoHmm, I may have to update my project to include this sort of junk data in the response body of its API calls. It sure would be amusing if most of HN did this. Everybody has to do their part, right?
- snorrah 12y agoNope
- quasque 12y agoYou'd be wasting your time as there is no feedback as to whether your attempts have worked to frustrate their targeting, and that's the best case scenario. The worst case is that someone picks up on your efforts and casually flags you to make your life more difficult - extra searches at borders, no fly list, and so on.
- michael_storm 12y agoContinue this for megabytes worth of bridges (xks-0001), and it'll totally mess up XKeyScore. It has no defense against getting flooded with information like this, as far as I can see. Yet it would be trivial to defend against trivial attacks like this. They just need to set a length limit on ingested messages, clean up those regexes, and they're done. A clever NSA developer (of which I'm sure they have several) might implement a garden-variety spam filter. We're trying to inject noise, but this noise is obvious. It's like a nation-state playing Cold War-era radio games by broadcasting "DOUBLE AGENT X COME HOME, DOUBLE AGENT Y COME HOME", etc. Sure it's noise, and it might distract them for five minutes, but it doesn't win the war. Want to fight XKeyscore? Make the noise impossible to distinguish. Set up free email accounts that bounce randomly-generated "interesting" messages among themselves, in between notes to Mom about the World Cup. Get open source software that uses network communication to piggyback some keyword-laden (though non-incriminating) text onto messages it would send anyway. Run a Tor exit node that blocks illegal activity in your country (so you don't go to jail). Or someone else should, at least. I'm busy. And now, I'm on a list.
- rcthompson 12y agoWe need to use the world's best anti-anti-spam technology. The stuff that generates random spam message texts to sneak past spam filters. Maybe combine something like SCIgen [1] with a corpus of "interesting" texts? [1] http://pdos.csail.mit.edu/scigen/ http://pdos.csail.mit.edu/scigen/
- wisty 12y agoI'm guessing they care a lot about the network, not just the content. They'll realise you work in IT, tag you as "linux using trouble maker", then mostly ignore you. Unless you work for the NSA, then they'll kick you out, and maybe send some people over to search your home.
- alttab 12y agoYou seem rather comfortable in your knowledge of this.
- jdong 12y agoThis article is based around the source that author claims to be faked in another article, http://blog.erratasec.com/2014/07/validating-xkeyscore-code.html http://blog.erratasec.com/2014/07/validating-xkeyscore-code.... edit: fixed link
- csandreasen 12y agoI think you mean this one: http://blog.erratasec.com/2014/07/validating-xkeyscore-code.html http://blog.erratasec.com/2014/07/validating-xkeyscore-code....
- jdong 12y agoThanks, clipboard wasn't syncing properly.
- dobbsbob 12y agothat article: "The filename xkeyscorerules100.txt is implausible. Source files do not end in ".txt" and the term "rules" is an odd choice." Looks to me like a typical sample config file that you rename xkeyscorerules100 after editing just like how you would create /etc/udev/rules.d/51-android.rules or SELinux custom module policy before compiling.
- Torgo 12y agoYeah, there are so many reasons it could have a .txt extension the criticism is not plausible. The first thing I thought of was, somebody nontechnical in the reporting pipeline changed the extension to .txt so it would open automatically in a text editor on their OS. Or, they pasted the contents in notepad and saved it, which would automatically append the .txt extension.
- jgalt212 12y agoFor all their illegal spying on American citizens, can the NSA point to one attack* they have stopped? I, for one, am not aware of any. And that's the real big problem here. They all this sh1t, invade everyone's privacy, and to what ends? *I am not talking about the NSA spying on non-US citizens.
- quasque 12y agoAbsence of evidence is not evidence of absence. They may have stopped attacks but not revealed any information about this publicly, or engaged in misdirection as to their role using parallel construction.
- wnoise 12y agoAbsence of evidence is indeed evidence of absence. It's absence of proof that is not proof of absence. It may or may not be strong evidence, depending on how likely evidence is, but it is evidence.
- deciplex 12y agoThen, the governing body of the United States, which is to say (nominally, anyway) the people of the United States are utterly unable to determine the effectiveness of this organization under their charge. Close it down.
- fnordfnordfnord 12y agoIt's a bit like an elephant whistle.
- pkinsky 12y agoThey produced a list of 50 to justify themselves before congress, but only one, a taxi driver sending 10k to Somalia, was deemed valid.
- zaroth 12y agoI guess NSA owes Robert a beer for the helpful QA service!
- nikcub 12y agoThe NSA will see this post, write more rules with regexs to catch anybody doing any of these things, and then tag them as terrorists in XKeyScore. edit not to mention that the source of these rules is from a non-verified document that is at least 2 years old and woefully incomplete.
- keithpeter 12y agoTagging a bunch of harmless HNers as terrorists is going to get them nowhere. The key is real, effective, targeting of that tiny minority who actually organise terrorist acts. Unless this is just some huge job creation scheme/security theatre for politicians.
- leaveyou 12y ago"The key is real, effective, targeting of that tiny minority who..." that's what they want you to believe, bahahahaha :D. Ok, ok I'm not paranoid. But can "we" (common people) really know what "they" (elected and unelected officials) really want ? They have the power, they have the information, they define and pursue the "national interest", they keep it classified, they create secret tribunals, they pick the "national threats", they whack them because terrorists, they make the "no fly" lists, they pick the "extremists"...
- keithpeter 12y agoSo is this basically Catch-22 for the 21st Century or just a bureaucracy that grew and became self-perpetuating?
- mike_hearn 12y agoI think encryption will remain a better way of jamming XKeyScore for the forseeable future.
- fnordfnordfnord 12y agoSo, if they're using a standard regex parser, and not cleaning the input, maybe some regex wizard can come up with some interesting Bobby Tables type fun.
- fapjacks 12y agoThis is a similar idea to something I've been working on for quite a long time (since June of last year, actually)[1]. I have experience with graph-generating software used by Five Eyes governments to map relationships, and I've been developing software that will dilute the effectiveness of those graphs by generating tons of noise across the system. Now it's a half-finished Chrome extension, but my hope was to build a complete set of browser extensions, and then bleed the design to Android/iOS to help dilute the graphs of people's phone behavior. [1] https://github.com/shroudproject https://github.com/shroudproject