4 ms·
Does using a VPN prevent any of these? EDIT: And I guess Google servers have most of Android users' home Wi-fi passwords. Which means NSA could pretty access an
by enlightenedfool 11y ago
Does using a VPN prevent any of these?
EDIT: And I guess Google servers have most of Android users' home Wi-fi passwords. Which means NSA could pretty access any devices in those homes?
- psykovsky 11y agoAnd most of those routers can be configured remotely by the ISP's who own them... Turtles all the way down.
- auganov 11y agoOnly if the traffic from your VPN host to the target host isn't routed through NSA capture sites. Say China-China traffic is probably out of reach. It generally seems like their captures sites are located where international traffic is routed. One strategy could be to always have a VPN host close to the target host. But still - it doesn't stop them from logging your strange VPN usage.
- dokument 11y agoWhy bother accessing the network via wifi when your chrome browser could provide the same access, or google drive app, or chromecast.
- fnordfnordfnord 11y agoI'll just assume that most home routers have backdoors baked in; a number of those have been found by various folks.
- lazaroclapp 11y agoThey don't even need to have intentional backdoors (as in, designed for spy agencies/law enforcement). The chances of a random home internet appliance not designed with serious cybersecurity considerations in mind (as opposed to "good enough to stop the average snooper/criminal") not having root-worthy vulnerabilities that can be exploited from the upstream provider is close to nil. Remember, most of these things have as their only threat model someone trying to gain access from the Wi-Fi side before authentication. I doubt many vendors seriously consider questions like "can the cable connection to the ISP be used to take over the router?" or take steps to prevent it. For many devices, that sort of access could be considered as a potentially legitimate feature (think, customer support and remote diagnostics).
- jlgaddis 11y agoAnd cable modems download their configuration from the ISP's CMTS when they're powered on.
- psykovsky 11y agoI could almost bet that they don't even validate certificates, IF they use any kind of encryption at all...
- fnordfnordfnord 11y agoNope. https://defcon.org/images/defcon-18/dc-18-presentations/Blake-bitemytaco/DEFCON-18-Blake-bitemytaco-Hacking-DOCSIS.pdf https://defcon.org/images/defcon-18/dc-18-presentations/Blak...
- jlgaddis 11y agoTFTP
- rqebmm 11y agoNo, but it will raise your XKEYSCORE profile! http://www.slate.com/blogs/future_tense/2013/07/31/xkeyscore_nsa_targets_internet_users_who_search_for_suspicious_stuff.html http://www.slate.com/blogs/future_tense/2013/07/31/xkeyscore...
- MichaelGG 11y agoThere isn't evidence that the NSA has access to Google servers, apart from the unencrypted fiber issue (which Google has since fixed, they say). However most users probably have shitty routers that can be remotely pwnd by anyone so yeah... It's also more efficient to just tap the connections of the users' ISPs, rather than tap each home. And since they're tapping backbones, a VPN will only help some. It'll limit the ability for them to easily search you via IP - they'll need to try to distinguish your traffic from the other users on the proxy/VPN. I didn't see anything about correlating timing information, and it'd seem like that'd be a much more difficult thing to analyze versus indexing HTTP requests. But if you read the slides, the instructions to operates are VERY clear to never use this data (passwords and such), but only pass it on to TAO. I'd guess they'd want to be really certain before doing something active/noticeable which might involve spending some sort of identity.