The NSA Is Collecting Lots of Spam
wiredog writes "One side effect of the NSA's surveillance program is that a great deal of spam is getting swept up along with the actual communications data. Overwhelming amounts, perhaps. From The Washington Post: '[W]hen one Iranian e-mail address of interest got taken over by spammers ... the Iranian account began sending out bogus messages to its entire address book. ... the spam that wasn't deleted by those recipients kept getting scooped up every time the NSA's gaze passed over them. And as some people had marked the Iranian account as a safe account, additional spam messages continued to stream in, and the NSA likely picked those up, too....Every day from Sept. 11, 2011 to Sept. 24, 2011, the NSA collected somewhere between 2 GB and 117 GB of data concerning this Iranian address."
LOL This was something that should be expected!
Linux is for people who don't mind RTFM.
Patriotism is the last refuge of a spammer?
If they are gathering spam or not, there is still a violation of the Constitution involved. Yeah, I'm a stodgy old prick with a memory like an Elephant! If they were not acting illegally this would not be a story now would it?
-The wise argue that there are few absolutes, the fool argues that there are no probabilities.
But the posting software seems to have wrapped the whole thing in blockquotes.
Best Slashdot Co
So if I want to do terrorist stuff - I should probably hide my communications inside emails about ch3ap V!agr@. Eventually the NSA will have to get a mail washer to help filter out the crap and my criminal activity will go un-noticed.
---- "Logoff! That cookie shit makes me nervous!" - A. Soprano
What could they possibly do about this? Let me think...
I've got it: expand the budget by $2 billion.
(If you haven't figured out by now that money is at the end of this rainbow -- not power -- then you're falling straight into the trap.)
Inside those seemingly banal Nigerian wire transfer scams are steganographically hidden instructions to sleeper cells. It just takes a particularly clever analyst to see the data for the noise.
My God, it's Full of Source!
OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
and you never know if the SPAM are actually a broadcast messages with certain keywords carrying the instructions for their coordinated attacks. May be the typos contains letters to form hidden words too?
It's a clever spy technique called obfuscation. Each one of those pill or account transfer messages contains a vital enemy secret that could mean the downfall of our nation. I encourage the NSA to carefully look over each one with exacting attention. You never know....
I'm not a math major however if 2GB to 117GB estimate is a result of rounding error NSA storage capacity must be huge.
"somewhere between 2 GB and 117 GB" ... can't narrow it down any more than that? Are you sure it was an Iranian email address, or was it just somewhere between Israel and Yemen?
Think of the spam filter they could build with that amount of spam to train it with...
One thing about using Yahoo, and Google mail, is that their spam filters have scale. Because so many virtually identical emails will be sent to hundreds or thousands of inboxes, they can say that it's either spam or a newsletter. If it looks like spam, or if enough people mark it as spam, than it probably is. Bang.
And the NSA is getting not just the email going to one company, but to all of them. And to those weirdos (like me) who don't trust advertising supported email and either pay someone or run their own email.
Wow. If they were doing good, they could distribute a set of rules so that anyone could implement an almost perfect spam filter...
HELP MY ACCOUNT HAS BEEN HACKED BY AN ILLIBERAL ART STUDENT SET TO DESTROY THE INTERWEBZ!
...as soon as they hear back from that Nigerian Prince.
If we colonize Mars, it won't be the World Wide Web anymore. UWW?
Between 2 and 117 GB
I guess this is that "are they really collecting just metadata like they're telling us, or the whole message to analyze" thing.
They can't even filter it out like we can, because:
"Get ready HUGE P3n1s for the HERBAL V1@gra attack next week."
Now I have to whitelist spammers and blacklist my friends.
They're the ones with the biggest penises and/or breasts.
In SOVIET RUSSIA... erm...NSA AMERICA, the Internet logs onto YOU!
Everyone loves spammers.
Now if the NSA actually did something useful and targeted those creating all this spam perhaps they could get a little positive press and goodwill... or maybe not
Spam is actually doing something useful. Enemy of my enemy and all that.
If you're gonna go snooping through people's stuff, you're bound to find a lot of garbage.
Laughter is the Spackle of the Soul.
Sure, but with deduplication, they could easily filter that down to very little to save. Yeah it takes some processing power, but isn't that why they have these fancy buildings?
Maybe with a bit more processing power, they will be able to remove the duplicated slashdot posts.
The Storage industry wins here. Hands down.
Fuck infosec, losing battle. APTs, NSA, shitty budgets, the money is in STORAGE.
Where else do they store all this shit? Time to buy some EMC, Netapp and fujitsu baby
Can the NSA waterboard the spammers? If so, they could redeem themsleves.
"I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
One of the more immediate consequences of snooping (even if were only metadata, and is far more than that), was that "normal" americans getting spam (or other kinds of unsolicited email) from elsewhere could be put into watch lists, with the collateral effects of getting all their mail inspected and backdoors installed in their PCs/cellphones just in case, and more "real world" consequences with the TSA or others in the present or future (maybe exaggerating, i liked a lot this story, but reality seem to be stranger than fiction). That they can't tell that it is spam before triggering all those actions should be worrysome.
If it's true that the NSA has a hard time dealing with even "real" (?) spam, a great project would be a browser / mail client plugin that automatically added "terror" words to (a subset of) your outgoing mail. Make it one-click easy for people to express their opposition to our out-of-control security state.
Yeah, I know - good luck getting people to be the first to start using it. But if it was super easy & there were no adverse consequences for 99.99% of users, eventually it would spread. (c.f. music piracy, etc.) There are a lot more of us (citizens) than there are of them (spooks and their political cohorts), even accounting for the fact that most of us can't be bothered to get off the couch.
So after sorting out all that spam, the NSA is now busy creating files on people such as miss Wumi Abdul, the only Daughter of late Mr and Mrs George Abdul, whose father was a very wealthy cocoa merchant in Abidjan, the economic capital of Ivory Coast before he was poisoned to death by his business associates on one of their outing to discus on a business deal.
So Miss Wumi Abdul, if that's your real name, wherever you are, the NSA's on to you now.
The implicit message here being: "NSA is really, really needed to counter that evil, evil Iran!!! Now ignore the fact we also snoop on everybody else..."
Never mind Iran has a sizeable Jewish population and is not at all engaged in Sunni Extremism. Your nice "ally" Saudi-Arabia is both the ideological source and the financier of Islamic terror.
But you are so dumb you hanged Saddam when the Wahabists hit your towers instead of bombing Mecca.
To heck with spending, we're borrowing half an aircraft carrier's worth of money per day. A few dozen servers a week with a hundred terabyte drives? Hehehehehehehehe.
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
They're the ones with the biggest penises and/or breasts.
*shudders*
If enough spam turns into effective crypto (doesn't matter who uses it, just so that it's effective), the spam problem with end ASAP.
Actually, I kind of want this to happen. I don't like spammers or our ridiculous defense budget, but watching the cage match would be fun.
Everyone knows they're behind it so it makes it difficult for anyone else to run their own email services.
for all the atta-boys for the NSA, I've yet to see them doing anything with the data. We know they are spying on us. And there is nothing we can do about that till the next election. I think they may want to stay in business. They lid to us enough to make you think that.
Why not do something with the data. Like there are missing people in real time, they collect our data in real time, we lose someone let them help, the courts/cops say you have to be missing for 24 hours, but they are listening in real time, why not send a hint.....
I'm guessing everyone working at the NSA has an enormous penis. Even the women. And they're probably erect ALL THE TIME. They probably fund their entire operation with the resource given to them by those guys trying to get all their shit out of Nigeria. No doubt none of their credit cards are blocked at Bank of Aemerica, and they probably supplement their income with lottery winnings from the UK (Nigel seems like such a nice young lad) and working from home for a thousand dollars a day.
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
I suspect a lot of their collection of contacts is centred around people carelessly leaving whole gobs of people in the To or CC lines (instead of BCC) when doing forwards.
If they are going to invade our privacy on a massive scale, the least they could do is use the evidence of this spam to crack down hard on the spammers. It would make it easier to find the terrorists by eliminating a lot of the communications noise, and might be good PR, giving something tangible back to society instead of being just takers for all anyone can tell. And they'd have less data to store, which would be cheaper and faster.
This is what I have been saying all along for the last 10 years. Fighting privacy by making yourself more private is not the solution. The current premise of all surveillance programs that are being operated today assumes that it is generated by a human being. The easiest way to counter this assumption we can go back to the Aesop's Fable "The boy who cried wolf".
What did the boy do? The boy cried wolf so many times that in the end when he told the truth, no one believed him. If that boy was alive today and wanted personal privacy, he would be crying wolf all the time. How would that work?
Automate the process and make it easy that everyone else can do it, too. If everyone cried wolf, who would you believe? We change the assumption and accept the fact that surveillance isn't going away. However, by burying the would-be listener with unlimited content and for someone/something to groom through all that data to figure out what is relevant, what is the truth and un-truth, it is a daunting task and it opens a new set of problems. How can you assess the threat if everyone was saying the same thing all the time, became friends with everyone else? Do you really know that person? Or is everyone really friends with Timothy McVeigh because he is such a cool guy until he pull that crazy stunt in OKC in 1995. What if sleeper cells weren't so sleepy but were outright public being a sleeper cell?
They collect spam? Let's make them fucking cry blood over it.
1. Get botnet
2. Make seemingly-terrorist spam
3. Watch the fireworks
You want to really nuke them? Forge each "from" field by outputting a random line from a directory of your officials.
You know. For the lulz.