NSA Broke Into Links Between Google, Yahoo Datacenters
barlevg writes "The Washington Post reports that, according to documents obtained from Edward Snowden, through their so-called 'MUSCULAR' initiative, the National Security Agency has exploited a weakness in the transfers between data centers, which Google and others pay a premium to send over secure fiber optic cables. The leaked documents include a post-it note as part of an internal NSA Powerpoint presentation showing a diagram of Google network traffic, an arrow pointing to the Google front-end server with text reading, 'SSL Added and Removed Here' with a smiley face. When shown the sketch by The Post and asked for comment, two engineers with close ties to Google responded with strings of profanity." The Washington Post report is also summarized at SlashBI. Also in can't-trust-the-government-not-to-spy news, an anonymous reader writes: "According to recent reports, the National Security Agency collects 'one-end foreign' Internet metadata as it passes through the United States. The notion is that purely domestic communications should receive greater protection, and that ordinary Americans won't send much personal information outside the country. A researcher at Stanford put this hypothesis to the test... and found that popular U.S. websites routinely pass browsing activity to international servers. Even the House of Representatives website was sending traffic to London. When the NSA vacuums up international Internet metadata, then, it's also snooping on domestic web browsing by millions of Americans."
... and I hope that "string of profanity" was directed at the NSA who put it there.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
Fucking traitors.
Slashdotters seem pretty appalled at these revelations, but when will the general public reach the point of disgust? In theory the people of the USA still have the power to change these behaviors through the ballot box. The news just goes on and on. but the outrage seems slow to reach the surface.
Nothing is "secure" any more. "Secure" is now a one word oxymoron.
Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
This news is very serious, but sometimes humor is the only possible reaction to bad news.
This is a violation of Google's Terms of Service. I hope Google cuts off all access from .gov and .mil domains.
Don't mess with The Phone Company. Piss them off and you'll be using two tin cans and a piece of string.
http://www.businessweek.com/news/2013-10-30/alexander-denies-nsa-infiltrated-google-to-yahoo-servers
That's for the illegal wiretapping.
Google (and the others) shrugged and played nice with the NSA, to what extent we don't know. They should have realized that the NSA didn't need their permission to get that data... they were getting it anyway. And a lot more.
I wonder if Google can sue? And if they can, will they?
Occasionally living proof of the Ballmer peak.
No one knows how many terrorist plots that have been adverted due to this. Just think back at the Boston marathon event. We should be grateful that we have not had more of them for the past decade. A lot of people forget this.
You forgot your <sarc> tags.
An enigma, wrapped in a riddle, shrouded in bacon and cheese
There are some obvious reasons: The operations take place overseas, where many statutory restriction on surveillance don't apply -- and where the Foreign Surveillance Intelligence Court (FISC) has no jurisdiction. In fact, the FISC ruled a similar, smaller scale program involving cables on U.S. territory illegal in 2011. So if the NSA decides to harvest that data on foreign soil, it can skip most of the oversight mechanisms.
Americans and us dangerous foreigners, expect no sympathy. One does not have to believe in Karma to know that you deserve the domestic spying.
By that same line of thinking, one could also say that you deserve to be spied upon and drone-striked, due to your blanket, wholly uninformed generalizations about Americans.
I wouldn't say that, because I'm not an egocentric dick... but someone could, and it would be just as invalid and moronic as your hypothesis.
An enigma, wrapped in a riddle, shrouded in bacon and cheese
Is there some reason the NSA is still around?
Yes. They have a file on everyone in Congress.
NSA = Nothing Sacred Anymore
There are some obvious reasons: The operations take place overseas, where many statutory restriction on surveillance don't apply -- and where the Foreign Surveillance Intelligence Court (FISC) has no jurisdiction. In fact, the FISC ruled a similar, smaller scale program involving cables on U.S. territory illegal in 2011. So if the NSA decides to harvest that data on foreign soil, it can skip most of the oversight mechanisms.
We've seen a lot of articles recently about people demanding companies not host their data in the US so that they're not subject to PRISM. But if PRISM has more oversight than MUSCULAR, and MUSCULAR is only allowed to be used OFF of US soil, then it seems like the safest place for your data is in the US, after all.
I'm pretty sure they have all known about this for some time. This isn't a new thing.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
Hello, NSA shill! Let's be honest here. That's quite right. Exactly: no one knows how many. You know something else? It doesn't even MATTER how many: the ends DO NOT justify the means!
This, what you're doing here? This is state-sponsored terrorism! This is completely off limits. You're way, way out of line. You need to look in the mirror and realise that Snowden has more integrity in his big toe than you have in your whole body. Stop making excuses. Shut these operations down. Publish details of any vulnerabilities you know about, including ones you've created or discovered. It's unethical not to: and it's quite frankly extremely damaging to national and international security not to. And we'll fix them, because we can't trust you to.
At this point I'm not worried about blithering crazy idiots waging "war" on us with half-assed bombs: I'm worried about our own governments waging "cyber-war" on us with billion-dollar budgets. It's obvious with a moment's thought which one the greater threat is, and I'm sorry, but it's not the frothy-mouthed jihadist who's actively sabotaging efforts to secure critical internet and other infrastructure. It's YOU.
People should not have to be afraid of their governments. But they do. We're not interested in your feeble justifications. Freedom IS worth human lives: it always has been. Operations like this make the sacrifices of those who gave their lives in years long past to ensure you have at least the promise of freedom utterly meaningless, and turn our own governments - quite literally - into our adversaries. You should be ashamed of yourselves. That has to stop. It has to stop now. And it has to stop no matter what the cost, no matter what the trade-off.
Given the hard choice between anybody having privacy and nobody having privacy, even if it means sitting down and redesigning baseline security protocols and the internet at large, I'd rather make the right choice than the easy choice. It's time to roll up our sleeves and start fixing this mess, and you're not invited to the party.
Is there some reason the NSA is still around?
Yes. They have a file on everyone in Congress.
Not to mention that most of my fellow Americans are too poopy-pants afraid of teh terroristz to ever allow that to happen. If anybody in Congress tried to dismantle the NSA, you'd better believe that their next opponent would label them "soft on national security". That could be enough to swing many elections, thus you'll never see it done.
"Never let your sense of morals prevent you from doing what is right" - Salvor Hardin
A lot of the NSA's pretense of innocence regarding metadata collection has been about expectation of privacy. They get information posessed by the telephone companies, not by private citizens. Since the information is already being given to the company by the citizen, the citizen has no reasonable expectation of privacy, and bulk metadata raises no 4th amendment issue.
This case defies that excuse. Those fiber optic cables are leased lines, over which Google and Yahoo have very reasonable expectations of privacy. So, if challenged, the government will either have to publish a different legal pretense or give Google and Yahoo some sort of sweetheart contract as hush money.
Perhaps I should go buy some GOOG and YHOO.
Stop-Prism.org: Opt Out of Surveillance
Yes exactly look back to the Boston bombing.
At the Boston bombing we had two countries telling us to watch the bomber that he was radical and potential terrorist, his youtube channel was full of sermons by Muslim extremist clerics.
And what happened... Big Brother did nothing.
Meanwhile the NSA agents are using their dragnet of all of the worlds communications to do what? Loveint, the NSA agents are using their wiretaps to spy on their loved ones, neighbors, crushes, and anyone they want.
So we are left with two options the Government let it happen or the are to incompatent/preoccupied getting their rocks off to be allowed near their own dragnet.
---Saying gnome 3 is better than windows 8 not so much a compliment as it is damning with light praise.
...When Google itself seems to believe you don't deserve to have certain kinds of privacy? (In regards to Schmidt and Gundotra's perspective that the service they are pushing, Google Plus, is supposed to be an identification service used to make sure that real user information is being used). Yes, this makes Google look bad, but it's also proof as to why not anonymizing yourself on the internet is stupid. (And yes, I realize that anonymization doesn't protect you from the NSA, but it is at least one additional layer of obfuscation, which apparently even Google should realize at this point is important).
There is a third option. The NSA is not looking for terrorists. They are doing all this monitoring for other purposes.
There's a "conspiracy theory" detail getting lost in all this discussion: the person who wrote the post-it note the Washington Post is featuring put a smiley face on the Google front-end server next to "SSL Added and Removed Here." To me, that says that they think that SSL encryption is just adorbs, implying they have a way to break it.
I have a theory, based on absolutely nothing.
I think a mathematician working for NSA solved Riemann's years ago and, consequently, NSA can break any internet encryption.
I'm actually okay with this. But it seems awfully cruel to keep the proof secret from the poor mathematicians who've spent their lives trying to solve it.
Meanwhile the NSA agents are using their dragnet of all of the worlds communications to do what? Loveint, the NSA agents are using their wiretaps to spy on their loved ones, neighbors, crushes, and anyone they want.
About 1 person per year has been caught doing that if you read the reports. I'm not going to mark that down as a major threat.
much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
That could be enough to swing many elections, thus you'll never see it done.
So long as the majority of people maintain that there are only 2 political parties to choose from, you will continue to be correct in this regard.
An enigma, wrapped in a riddle, shrouded in bacon and cheese
we had two countries telling us to watch the bomber
They should have e-mailed eachother. Then we would have caught it.
For all intensive purposes, "whom" is no longer a word. That begs the question, "who cares"?
"In fact, the FISC ruled a similar, smaller scale program involving cables on U.S. territory illegal in 2011."
Exactly. The defenders of this nonsense want that little bit to get skipped and forgotten.
There is no question this is illegal, they dont even have a tiny fig leaf of being able to argue they thought it might be legal. It's illegal, even the FISA "court" refused to agree to this.
So they just did it anyway. Sounds to me like despite all the noise about 'oversight' adult supervision is exactly what has been missing.
=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Friends don't let friends enable ecmascript.
Terrorists?
Why would they try to stop terrorists? The sooner there is another successful attack the sooner their budget gets doubled.
=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Friends don't let friends enable ecmascript.
No, all the terrorist plots that never were are thanks to my Anti-Terrorist Rock. It protects against terrorists within a 1,000 mile radius with a 90% accuracy rate. I got it when my Anti-Tiger rock so effectively protected me against tiger attacks (in New York). Sadly, I lost my Anti-Government-Overreach-Of-Power rock. I really could have used that one.
My sci-fi novel, Ghost Thief, is now available from Amazon.com.
Technically the NSA has been downloading copyrighted material, and very likely has more than a few MP3s of popular songs filed away in their datacenters.
I suggest we lobby the RIAA to sue the NSA for $10,000,000,000,000,000 because that's what 50 or so songs are worth, so they say.
The only trouble with this strategy of course, is that I don't know who to root for. The enemy of my enemy is my friend? No, the enemy of my enemy is still my enemy dammit.
If telephones are outlawed, then only outlaws will have telephones.
1 person per year has been caught. We also know that the analysts are nearly totally unsupervised. How many do you think were not caught? 100? 1000? It's certainly a lot more than have been caught.
Our politicians can't even agree on who our foes are so they consider everyone to be one.
I would rather have freedom than a reduction in terrorist attacks.
However, it doesn't matter how I feel, it matters how the people feel, because this is a democracy.
But a democracy doesn't work when the government makes decisions in secrecy; that's the real problem.
Beyond forgetting your sarcasm ( as pointed out below),
I'd guess we've had infinity terrorist plots foiled, then. Guess which one we didn't? The Boston Marathon. So yes, think back to Boston Marathon, where we are taught that more information does absolutely nothing except obfuscate facts. How long did it take to identify the bomber? Long enough for him to be successful.
WP has to be the worst rag going with some of the stupidest journalists possible.
Says someone who has clearly never read the Washington Times.
In this case, NSA is NOT doing anywhere near the spying that WP implies. NSA has said that they as a group are not spying on Americans the way that WP and others imply.
But they refuse to talk about the spying they are conducting on Americans -- spying that clearly violates Americans' Constitutional rights.
!#@%*)anks for hanging up the phone, dear.
How is the well known, and obvious fact that most of the media are Democrats a lie?
Look it up from any source you care. This fact is undeniable. My 90% is in fact a very conservative estimate because I like to give some slack, but poll after poll reports this result.
You can also verify this in the core story at hand - outage over the NSA. It is mentioned in the press but not very much. Or what about drone strikes, or the embassy killings, or any other story you can name⦠all of it gets short attention in the media, nothing like what you see with any Republican wrongdoing.
As the original poster said the two parties are currently very much the same. So the only thing that makes sense to do is to vote for the party the press actually reports wrongdoing on.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Meanwhile the NSA agents are using their dragnet of all of the worlds communications to do what? Loveint, the NSA agents are using their wiretaps to spy on their loved ones, neighbors, crushes, and anyone they want.
About 1 person per year has been caught doing that if you read the reports.
You're right, NSA's internal oversight catches very few abuses. If only they hadn't confessed, they wouldn't have gotten "caught." Instead, they're subject to a very stern reprimand (on the merits on not getting caught), and for the most egregious offenders, the possibility of paid vacation and/or reassignment.
I'm not going to mark that down as a major threat.
So, this shouldn't affect NSA's budget or ability to continue business-as-usual, in other words. No wonder they released that report — it wasn't a major threat, it was limited hangout.
Thank you, Edward Snowden.
"Arguments from authority are worthless." —Carl Sagan
So I heard - but by the time the police arrived not only were they gone, but the entire coffee shop was missing.
The Supreme Court is really clear on this. If you tap a land line without a warrant, you violate the Constitution.
I often hear people say this on slashdot. Americans about American government, whenever somebody mentions "a plot". This can be one of those plots.
5 years ago, everybody would say it's impossible this conspiracy plot is happening because they're stupid morons who can't do sh.t, and I should go buy me self a tinfoil hat somewhere.
What we heard in the last 5 months invalidates opinions of 90 % of people visiting this site. They're obviously efficient and capable at having plots and god only knows (maybe Snowden too) what they did/are doing and will continue to do in the future, but anybody who can think without getting his emotions involved, will naturally assume that whatever they're doing - is not good.
Here's another conspiracy plot. Make Americans think they Government is not capable of doing anything so they (the Americans thinking like this) discredit and label everybody who figures out the truth.
If it's not on the TV/Newspapers it's not happening mentality will ruin you. They are and were just tools for the same Gov that is doing this to all of us to misinform you and control what you know and not know.
Thanks to the internet, blogs, mistake made by booze allen or whatever is the name of that company, we now getting more and more informed. While we getting more and more informed, we're also getting more and more disgusted which we weren't before... naturally. Since we didn't kknow any better, we just knew what they told us.
I know i know... it's a plot again, but i don't expect any better from your, or any other Gov anyway.
There are other, far greater dangers than a Boston, 9/11, or even "mushroom cloud". Namely, collapse of freedom in the US via decades-long slippery slope. Once the tools of a 1984-like tyranny are built, with nothing but "you are supposed to get a warrant" stopping G. Gordon Liddy types from spying on political opponents, it's all over.
It's the lack of real, detailed oversight, uncorruptible, reviewed logging of all queries, and so on, which we need, and which will bring an end to the need to "trust us".
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
It's not that hard or expensive for Google to use end-to-end encryption on these links. Adding more layers for the NSA to have to deal with is always good!
Hopefully Google's network engineers also think this way and are in a meeting right now planning it!
Maybe they simply believe when the government says that "Twerk shall set you free."
Momentarily, the need for the construction of new light will no longer exist.
And the patriot act conceived and produced by the neo-cons, allows the NSA to have a warrant that allows them to follow the leads quickly and find the terrorists.
Sadly, under W, it was abused (stats showed that more than 95% of these warrants were NOT used on terrorists but simple local criminals). However, in 2008, the GOP forced this to be a closed issue. So, we do not know what has happened under O, but considering that neo-cons/tea* have been on the intelligence committee to review this, I would guess that things improved.
I prefer the "u" in honour as it seems to be missing these days.
You lost me at
by law the NSA can't
Oh my goodness. How can someone entirely miss the whole point of the Kang/Kodos election, or Douglas Adams' lizards? The point, which you appear to have somehow totally missed, is to highlight the folly of a two-party system.
The problem is not people voting for the wrong lizard, it is people voting for one of the two lizards IN THE FIRST PLACE.
So long as Democrats and Republicans continue to be rife with corruption, your civic duty is to vote third party.
Otherwise you really are throwing your vote away.
"Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife
NOT 'man in the middle', and no direct compromise of the Google Frontend Server (GFE) is being described here. MUSCULAR is passive taps on presently unencrypted private links between the companies' global data centers. In theory these would be sited on the borders of the United States or (safely) within foreign space.
This cooperation between the Brits and the Gits is ESCHELON in action. Your tax (and drug) dollars at work. I see that the latest Snowden revelation identifies an interception point that is magically distant from Kansas. All the better to take our minds off what NSA is doing in Kansas.
Frankly (and sadly) I do not believe that NSA has ever sited any of their communications taps to avoid gathering domestic traffic. I believe full disclosure would reveal this.
Okay, maybe during the Cold War -- but If there ever were any NSA folk who'd be aghast at the idea of vacuuming their neighbors' telephone calls and private emails, where desk analysts can issue flags that key ancillary targets automatically derived from social networks and phone logs... including their own sons and daughters... those people are not objecting now. They are are gone to grave or recently retired in comfortable surroundings, watching these goings-on with growing discomfort and distaste.
Or long retired. I may have met some of them in the islands as a kid, grim and reserved with little to say about current events. I really wish they would speak up now while there is still time. Especially the ones who witnessed first-hand how the KGB ran Eastern Europe, how Chairman Mao 'purified' China, how Hitler first captured Germany with promises to lead them out of inflationary ruin.
To do these things right it would be a great help to have good intel on all your citizens. Do they realize how incredibly stupid this all is?
Under massive domestic surveillance EVERYONE in the entire country is subject to direct blackmail. NO ONE IS EXEMPT. This is because everyone has a loved one, child, friend relative that has actionable events in their past. This means they get to choose who leads the country by eliminating all opposition. Scandals will just keep coming to light. For more on that see my post about blackmail and 'duress'
Under massive surveillance EVERY ONE of the classic and hallowed checks and balances which keep our Republic together and human traditions that civilization on track is subject to TOTAL CORRUPTION and outright NULLIFICATION.
No human judge is exempt, no jury safe from side-channel tampering. With private communications intercepts it is possible to select or disqualify jurors based on a pretty complete profile of their views. No more Twelve Angry Men.
Under massive surveillance every possible terrorist scenario that hurts us is avoided. Give thanks and praise. But more chillingly, every scenario could benefit the intelligence community will inevitably become a reality, if not in your time then your children's. All they need to do is contact people, ignore people and prepare to capitalize on the event. No more 'acts of God' or tragedies that galvanize honest people into surprising yet dignified ways to some surprising yet triumphant end.
History becomes a script written by the most ruthless and least inhibited who happen have access to the secrets. We see seeds of this in our own time.
Under total surveillance financial markets are relegated to sideshows for the programmed accumulation of wealth (and targeted ruin). By forming an alliance with entities that emit High Frequency Trades, a shadow government can maintain a presence that is unlikely to be detectable or discernible, and in any case, when manipulation begins real humans will react predictably, helplessly.
There is a reason we have evolved so quickly as a species. Not just intelligence, but applied freedom to think, act,
<blink>down the rabbit hole</blink>
No wonder Dianne Feinstein finally came out sort of against the NSA. When they piss off one of her biggest clients it gets serious.
Google is a less restrained than government. Google can limit your life a lot more than the NSA can.
I suppose, hypothetically, if Google execs really wanted to make me disappear, they have enough money to hire people to make it happen, but you have to be pretty far out there to think that Google founders have it in for you personally. If Google isn't making a profit from me, they could terminate all my accounts and sell all my data, but to do anything more would dig into their profits, so they won't.
On the other hand, The US Gov has put away several people I know for drugs, frequently after investigating them on totally bogus, unrelated charges. So I've seen people's data abused by the government for more than the targeted adds Google would have sent them. And this is not even mentioning all the time and money non-convict people I know have had to sink in defending themselves from damning scraps of data.
The NSA, by law, can't even enforce laws in the US
Yeah, they wouldn't enforce anything, they can just turn over their data to agencies that could enforce within the US borders. E.g.: http://www.washingtonpost.com/blogs/the-switch/wp/2013/08/05/the-nsa-is-giving-your-phone-records-to-the-dea-and-the-dea-is-covering-it-up/
the NSA could only tap foreign data centers
1) I accidentally made the horribly unpatriotic blunder of meeting and making friends with some of the six and a half billion people who live outside the US. Some in a public high-school no less!
2) Unfortunately for the good patriots, who did a better job of shunning the dirty foreigners, the internet is pretty fuzzy on borders and as the summary points out, data is often sent to information centers outside the US even if it is just returned unaltered, back inside.
3) I have never paid attention to the geographic location of my web-surfing before and I suspect neither have you. Are we sure even Slashdot has all it's data centers in the US? Many of the liked articles aren't, so I'm sure they got some good meta data on the two of us accessing leaked documents published by foreign agencies.
Really, in the side of Government vs. Corporation, the only side that represents YOU is Government.
Depends what the conflict was. Normally, yes, in healthcare, employment rights, unconscionable EULAs, etc, these are situations where the government needs to kick corporate ass on my behalf. This situation on the other hand, the government is not protecting me from the corporations; the government is coming after me. Even if the corporations only want to protect me to ensure their profits, I don't care. Right now they are on my side.
Now, if Google was caught tapping the NSA to get my personal info, then I'd be pissed at Google, not the NSA.
Without government, Corporations would, literally, have you as slaves.
This is true, but from here on out, you really left the situation at hand to talk about political movements I'm not familiar enough with to comment on but I'm thinking 30% chance you are going to reply to my post with "Sarcasm, moron: learn to detect it!"
A Kickstarter campaign to put up billboards alongside the top 25 rush hour arteries across the USA with stark black letters on white background:
The NSA knows what you did.
And one day they will expose you.
Stop Them and save yourself.
Here's what gets me about the Boston incident: We know the government has basically been intercepting and monitoring all domestic communications since at least 2006, right? And we also know that the Russian government warned our government that these Tsarnesev (not going to bother looking up the spelling) brothers were coming here and up to no good, right?
So, the government is monitoring the communications of these guys who came to this country to blow shit up... and they never came across any information that would have allowed them to prevent the attack? I don't buy that shit for a second - you can't honestly tell me that in the, what, 3-4 years these assholes were here, they never, ever, not even once, said something over an electronic communications line that would warrant further scrutiny. Especially considering the warning we received from the Ruskies.
Something fishy about that.
An enigma, wrapped in a riddle, shrouded in bacon and cheese