Hacker Newsnew | past | comments | ask | show | jobs | submit | monocasa's commentslogin

> Ex-NSA Chief: 'We Kill People Based on Metadata'

> Hayden made the remark after saying he agreed with the idea that metadata - the information collected by the NSA about phone calls and other communications that does not include content - can tell the government "everything" about anyone it's targeting for surveillance, often making the actual content of the communication unnecessary.

https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-...


If I was the NSA, I would be using the fact that signal uses AWS for their backend combined with the cudgel that .us.gov has with the AWS govcloud contract to mandate that all traffic to and from signal's backend also gets routed to NSA traffic analysis servers, which could then be correlated with other sources like ISP data to get a pretty complete record of all Signal message metadata.

To be clear, I use signal pretty heavily, but that's because my threat model doesn't really include competent .us.gov actors. I don't think that they'd either prove they're doing this or go through the trouble of parallel construction over anything in my messages or who I'm talking to.


'Apple' was a metaphor to Newton. 'Open'AI was meant as a promise; one that they've since broke both to some of their founders as well to the general populace. Reminding people of that broken promise doesn't seem that wild.

> They don't sniff all the packets to find anything useful. Snowden showed that they intercept certain packets flowing between particular sources and destinations that might contain useful information

Their legal argument was that it was actually ok for them to grab and store all packets, and that it wasn't a search until they ran an actual search that matched against that stored traffic.

> In Snowden's leaks, one such application was email inbox backup transfers for big Internet companies that did not (at that time) encrypt their WAN traffic, from which they mined the sender and recipient to build a social graph, a program that the leaks said had already been shut down.

That was private fiber they had spliced into, not anything routed across public Internet. That's why the DCs weren't encrypting it to begin with.


> Their legal argument was that it was actually ok for them to grab and store all packets, and that it wasn't a search until they ran an actual search that matched against that stored traffic.

No, they never made that argument because they don't grab and store all packets. Instead, they stored the metadata extracted from these packets (the sender and receiver). This program has ended prior to Snowden's leaks according to his documents, but the telephone pen register collection was still ongoing.

> That was private fiber they had spliced into,

No, this was public Internet, at places like Room 641A. There was nothing in the leaks suggesting they had spliced private fiber.


> No, they never made that argument because they don't grab and store all packets. Instead, they stored the metadata extracted from these packets (the sender and receiver). This program has ended prior to Snowden's leaks according to his documents, but the telephone pen register collection was still ongoing.

The utah data center is their buffer. And they were storing large amounts of traffic because they had their diffie-helman hack.

> No, this was public Internet, at places like Room 641A. There was nothing in the leaks suggesting they had spliced private fiber.

I've talked to Google engineers about this. They spliced private fiber. Google was smart enough to encrypt anything routed over public internet, but thought that their private WAN was safe until the disclosures.


> The utah data center is their buffer.

The Utah data center hadn't even been constructed at the time of Snowden's leaks, so obviously there was no evidence for that in the leaks.

> And they were storing large amounts of traffic because they had their diffie-helman hack.

Again, there was no evidence that they were doing this in the leaks. The leaks said that they did full take data collection only in a specific set of regions like Afghanistan.

> I've talked to Google engineers about this. They spliced private fiber.

Those engineers simply misread the leaks. What they did was insert their network analyzers in places like Room 641A, next door to an IX where subsea cables connect to private routers. These cables pass through that room first. No splicing required. If you look at the third slide in the PRISM/US-984XN deck, you can see that this happens only on international infrastructure like these subsea cables, not on purely domestic DC to DC links.


Please, just stop.

The engineers I've talked to did not misread the leaks and found non public information confirming it. The diffie-hellman stuff has explicit evidence in the leaks. Yes, the Utah data center is newer than the leaks. It was created because total traffic was expanding and they required more storage.


> Please, just stop.

I will stop correcting you when you stop posting falsehoods. The conspiracy theories that people spread following the Snowden leaks that were contradicted by the leaks themselves helped lead to a the government we have today, so this is not some minor issue that I will let rest.

> The diffie-hellman stuff has explicit evidence in the leaks.

Nothing in the leaks says they were exploiting a Diffie-Helman weakness. That was hypothesized years after the leaks. I didn't address this because it was irrelevant compared to the larger lie that they "grab and store all packets" in the US instead of in some small set of regions with little Internet traffic and extreme national security interest as said in the leaks.

> It was created because total traffic was expanding and they required more storage.

Again, not because they were storing full take US data. That is not in the leaks.


Eh, they call TypeScript a tier 1 language too.

It's also only 45 frames uncompressed at 4k. It's remarkably easy to hit that if your base assets are mostly raster rather than vector for a dynamic scene.

Obviously, they should try harder, and this is an explanation rather than an excuse, but the graphics assets are mostly why.


Why would you need that kind of resolution for a weather app? What are you even going to depict with all those pixels?

Because people are looking at it on 4k screens.

I mean, I usually check the weather by putting "weather" into a search engine. And this will show me little SVG icons that take up a tiny fraction of my low-resolution screen and probably involve like less than a kilobyte of path description. And I think this looks perfectly fine and I can hardly even fathom why anyone would want it to be fancier than that. I think that even animating them would make the display actively worse.

Microsoft explicitly de-emphasized Java in favor of C# after their J++ lawsuit. That's why they created C# in fact.

Python for windows application development never really got there and is kind of a technically runs if you want to run python kind of situation.


I think there's a chain of trust. The sensor signs raws, and the private cloud takes signed raws, does minimal processing so they're at least coherent, and re signs that output (maybe even including the original signed raw as well in the image file).

Any model can be expressed as a database.

Kolmogorov looks at this with a ‘duh’ face

Calling everything "whatabouting" when someone is just responding and expanding context to an existing comparison is what's actually last decade.

Last decade is so last decade

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: