Slashdot Mirror


The NSA and Snowden: Securing the All-Seeing Eye

First time accepted submitter ChelleChelle2 (2908449) writes "Edward Snowden's release of classified material exposing the existence of numerous global surveillance programs (obtained while working as an NSA contractor at Booz Allen Hamilton) has been referred to as 'the most damaging breach of secrets in U.S. history.' Regardless of whether one choses to champion or condemn Snowden's actions, it is apparent that the NSA needs to dramatically rework its security measures. In this article Bob Toxen, renown author of several books and articles on Linux Security, discusses the security practices that could have stopped Snowden. Equally interesting, he weighs in on the constitutionality and morality of the NSA's spying on all Americans."

97 comments

  1. That's only what we know yet by Hamsterdan · · Score: 4, Insightful

    With all the leaks, corruption scandals (quite a show here in Montreal), and all the law-breaking from those agencies and governments, I wish there were more like Snowden. That's only the tip of the iceberg boys & girls,

    --
    I've got better things to do tonight than die.
    1. Re:That's only what we know yet by loony · · Score: 3, Insightful

      Its too easy for people to trust the government. They promise to take care of you, keep you safe and fed and all the other things. Its easier to trust them than to have a mind on your own, to have to think, plan, and work. It usually all goes well for a while until corruption creeps in and politicians think they know better than you how you should live your life...

      The US had an amazing run and I wish I could somehow know what future generations will define as the point in time where the US government turned sour. The current NSA affair? What about the creating of a for-profit, private bank that's put in charge of ruining the dollar value? I'm sure some racists will point to the 13th amendment but I bet 9/11 would be a much more likely choice. Maybe the Nixon years with Watergate and the removal of the gold standard? Oh so many choices... I personally pick the day the southern states seceded. While the North was right and slavery had to go, I still can't find a legal reason that prohibited the South to withdraw from the United States...

      Peter.

    2. Re:That's only what we know yet by AmiMoJo · · Score: 2

      Which is why I think doing anything to help the NSA/GCHQ is immoral.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    3. Re:That's only what we know yet by Anonymous Coward · · Score: 0

      The sour started way way back with the birth of the federal reserve.

    4. Re:That's only what we know yet by SpzToid · · Score: 1

      Montreal is scandalous? Who knew? All I ever hear about from Canada these days is how the Toronto mayor manages to surpass a former Washington DC mayor for being able to overcome his disabilities.

      --
      You can't be ahead of the curve, if you're stuck in a loop.
    5. Re:That's only what we know yet by gweihir · · Score: 2

      People seem to have entirely forgotten the last few catastrophes, like the 3rd Reich, the USSR, etc. But then, people are stupid and usually deserve all the pain they help bring their way.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    6. Re:That's only what we know yet by Anonymous Coward · · Score: 0

      The problem isn't just politicians thinking they know better than you how you should live your life.

      It's politicians abusing their position of power to make themselves, and their old-boys-club members, filthy rich at your expense.

      Anyone who believes that the NSA spying serves primarily to protect us, and is not abused to give economic advantages to specific well-connected rich old-boys-club members, is being injuriously naive.

    7. Re:That's only what we know yet by s.petry · · Score: 1

      All I ever hear ah-boot from Canada these days is how the Crack Smokin Mayor manages to surpass a former Washington DC mayor for being able to overcome his disabilities. Eh!

      FTFY! Living in Detroit made me fluent in Canadian!!

      --

      -The wise argue that there are few absolutes, the fool argues that there are no probabilities.

    8. Re:That's only what we know yet by gmuslera · · Score: 1

      And with that security measures, they could happily anounce and promise that they will be well behaved, stop spying and so on, and keep doing the same or even far worse things. What stops you from lying if you won't get caught anyway?

    9. Re:That's only what we know yet by davester666 · · Score: 1

      It would be, but Canada's press is terrible, as CSIS and CSEC are both taking it up the ass from the NSA and CIA, in order to give them whatever they want.

      --
      Sleep your way to a whiter smile...date a dentist!
    10. Re:That's only what we know yet by Sabriel · · Score: 1

      Why would you need to be a racist to point at the 13th amendment? It doesn't forbid slavery, it monopolises it. The 13th says the government can enslave anyone convicted of a crime, and it's not a coincidence that the US has a ludicrously high incarceration rate and a for-profit prison industry.

    11. Re:That's only what we know yet by Anonymous Coward · · Score: 0

      I personally pick the day the southern states seceded. While the North was right and slavery had to go, I still can't find a legal reason that prohibited the South to withdraw from the United States...

      There was no legal reason the South could not withdraw from the United States. Everybody knew perfectly well that, at the time the Constitution was approved, in practice the approval was conditional and it was neither politically nor militarily feasible to force a state to stay in the Union.

      However, the issue of the right to withdraw is complicated by the fact that there were many human beings in the South who had a right to protection from the federal government under the Bill of Rights.

      Recall that Madison's original text of the Bill of Rights (look it up) specifically limited not just the federal government, but also the state governments. The often heard claim that the Bill of Rights did not apply to the states prior to the 14th Amendment is a myth. In the final version, only the 1st and 7th Amendments specifically limited the federal government, the others were left open to application at both the federal and state level.

      Recall also that the Bill of Rights was written to be open-ended ("rights retained to the people", 9th Amendment) in response to the assertion by the Anti-Federalists that any Bill of Rights would be incomplete.

      Hence, the US federal government of 1861 had the legal authority (and responsibility) to act on the behalf of the large body of people who had many rights arising under the 9th Amendment that were being violated in the Southern states, namely the slaves.

      If the South wanted to withdraw, it would have had to free the slaves, and give them the opportunity to leave, to avoid the responsibility of the federal government to uphold the Bill of Rights. The failure to do this was the critical mistake made by the South.

      To be practical, this would have probably involved compensating the slave owners. Ironically, that was proposed by Gouverneur Morris during his famous anti-slavery speech at the Constitutional Convention of 1787, the better part of a century before the Civil War.

      In short, the conclusion is that a right to secede exists, but the actual process of seceding has to be handled carefully to make sure that it is fair to everyone living in the region wishing to secede (and sometimes those outside).

    12. Re:That's only what we know yet by WindBourne · · Score: 1

      There are plenty like him:
      1) John Walker
      2) Vidkum Quisling
      3) Aldrich Ames
      4) Philby, Donald Maclean and Guy Burgess
      5) William Joyce
      6) Marcus Brutus
      7) and Judas

      There are plenty like him.

      Had he stayed on track about the spying on just America, or even just the west, he would ONLY be a hero. Now, he is both hero and traitor, just like many of the above.

      --
      I prefer the "u" in honour as it seems to be missing these days.
  2. Bad logic by DoofusOfDeath · · Score: 0

    Regardless of whether one choses to champion or condemn Snowden's actions, it is apparent that the NSA needs to dramatically rework its security measures.

    No, their lax security measures are achieving exactly the right results for our democracy at the moment. I am completely against them reworking them, unless you mean subjecting them all to potential veto by a select group of thoughtful small-government patriots.

    1. Re:Bad logic by Anonymous Coward · · Score: 0

      And you are exactly, who?

    2. Re:Bad logic by Anonymous Coward · · Score: 0, Funny

      He's just another one of those damn Republicans that don't give a damn about the Internet or privacy.

    3. Re:Bad logic by Anonymous Coward · · Score: 0

      Except there is also the fact that some of the NSA's main goals, despite its draconian and probably unconstitutional methods, are still counterterrorism and counterintelligence. When a friend or family member is killed in a terrorist attack because the NSA's security wasn't adequate you can be proud you encouraged it.

    4. Re:Bad logic by ThatAblaze · · Score: 3, Insightful

      That's like saying when aliens attack you'll be glad you bought UFO insurance. Just because you can imagine a scenario does not make it likely. I have seen no compelling evidence that terrorism is a battle worth giving up my privacy and freedom for.

    5. Re:Bad logic by Anonymous Coward · · Score: 0

      Yes, that's exactly what it's like if aliens had already attacked the earth thousands of times already. Your analogy is absurd.

      And clearly you didn't actually want to read my post, just make your horrible analogy (been thinking that one up for a while or just a spontaneous fit of stupidity?) but I don't agree with the NSA's methods at all. Still doesn't mean I think they shouldn't fix their security for the sake of the useful work they do (and if you don't think they do *anything* useful you are even more of a conspiracy theory whack job than your post suggests).

    6. Re:Bad logic by Anonymous Coward · · Score: 0

      Too right, I'm outraged.,br> What if my wife or daughter slipped and fell in the bath.
      I demand the government place an agent in every bathroom. It's happened before, It will happen again. To do nothing would be to let the wet floors win.

    7. Re:Bad logic by Anonymous Coward · · Score: 0

      Yes, that's exactly what it's like if aliens had already attacked the earth thousands of times already.

      The U.S. has been attacked by terrorists thousands of times? Really? Huh. Wonder where I've been, I seem to have missed all that. And quoting your previous blithering idiocy...

      When a friend or family member is killed in a terrorist attack

      You know what's interesting about those of you who keep trotting out this kind of BS? You completely ignore that, for instance, more people are killed in automobile accidents every year in the U.S., by a large margin, than have been killed in terrorist attacks in the entire history of the nation. Being so worried about the safety of your friends and family I'm sure you never let them get in a car, right?

      Of course you do. Even you aren't that stupid. But you'll trot out that terrorism boogey-man every time... guess it's better than admitting that you have no actual idea what you're talking about.

      Someday maybe you'll grow up and get a clue, but right now you're so far up your own ass you couldn't find your way out with a map and a flashlight. It's really a shame so many people seem to share your affliction.

    8. Re:Bad logic by BiIl_the_Engineer · · Score: 1

      Risking death to have freedom is more than worth it. Even if the NSA is effective, it should've thought of that before violating the highest law of the land and everyone's fundamental liberties; then they could've carried on with their actual goals.

      --
      These comments are my own and do not necessarily reflect the views or opinions of my employer or colleagues...
    9. Re:Bad logic by BradMajors · · Score: 1

      The NSA does not work for us. I don't care about their security.

    10. Re:Bad logic by flyneye · · Score: 0

      I like to think their fuck ups are what is good for our REPUBLIC.
      Democracy is a bad thing, I prefer to accentuate the positive.

      Taking a cue from the so called consultant field, I would combine the NSA, CIA and Secret service, fire half of them and make them WORK for a living.
      Then I would put the FBI to work at the borders helping to fulfill the Constitutional duty of the Government. Hey, while Im at it, I would put all the other junk agencies on the same detail, but not before firing half of them to begin with, just so the rest appreciate their jobs and get over their pride. THEN, I would cut their wages down to private sector size. WOOHOO, Im on a roll, VOTE for FLY! President FLYNEYE, YAH BAYBEE!

      --
      *Repent!Quit Your Job!Slack Off!The World Ends Tomorrow and You May Die!
    11. Re:Bad logic by Anonymous Coward · · Score: 0

      I like to think their fuck ups are what is good for our REPUBLIC.
      Democracy is a bad thing, I prefer to accentuate the positive.

      You're an idiot! A republic merely means you don't have a hereditary monarchy, nothing else. I really would like to know, who you think is supposed to make the decisions in your non-democratic republic (and by whom they were legitimised to do so), moron.

    12. Re:Bad logic by rtb61 · · Score: 5, Insightful

      In the light let's correct the the heading. Edward Snowden did not cause the 'the most damaging breach of secrets in U.S. history.', he exposed the 'the most damaging breach of secrets in U.S. history.'. Let's be clear on this, it was the NSA that was conducting the illegal breach of secrets of people from all over the globe, no one was safe and no countries laws were respected, not the US not anyones. It was the NSA that was the completely unrepentant criminally insane computer network hacker, hacks not in the hundreds or thousands but very likely in the millions. This had nothing to do with securing anything for the US but everything to do with empowering the insane head of the NSA and his backers in their grab for power. He is now protected status by the secrets he holds, he knows more about the criminal activity of politicians from all over the globe than any other person in US history. As the the puppet president Uncle Tom Obama the choom gang coward, well, he runs nothing and has not done so for years, he just does as he is told to do and smile when he reads his instructions in front of the public on the teleprompter, the puppet prompter, what a way to go no in history, really lame.

      --
      Chaos - everything, everywhere, everywhen
    13. Re:Bad logic by cffrost · · Score: 3, Insightful

      Except there is also the fact that some of the NSA's main goals, despite its draconian and probably unconstitutional methods, are still counterterrorism and counterintelligence. When a friend or family member is killed in a terrorist attack because the NSA's security wasn't adequate you can be proud you encouraged it.

      The NSA's mass-surveillance techniques have not been proven effective for counter-terrorism, nor do those techniques represent a cost-effective method of lowering the overall US death rate, nor are they worth (in my opinion) the egregious violation of our Constitutional rights.

      I believe that a cursory glance at global affairs — in particular, which entities commit terror attacks upon which nations; the attackers' motives; and attacked nations' foreign policies — suggest that the most effective counter-terrorism results come from not interfering in the sovereignty or affairs of foreign governments, and not violating the human/civil rights of foreign and domestic populaces.

      Were a friend or family member killed in a terror attack, I'd be upset they died even though their Constitutional rights were being violated, and I'd be upset that they likely died as a result of blowback from unilateral US action abroad intended to increase or maintain the power and wealth of US oligarchs, likely in violation of international law. If mass-surveillance were ended and a friend or family member were killed in a terror attack, I would take solace in death(s) as free people.

      --
      Thank you, Edward Snowden.

      "Arguments from authority are worthless." —Carl Sagan
    14. Re:Bad logic by Anonymous Coward · · Score: 0

      Except there is also the fact that some of the NSA's main goals, despite its draconian and probably unconstitutional methods, are still counterterrorism and counterintelligence. When a friend or family member is killed in a terrorist attack because the NSA's security wasn't adequate you can be proud you encouraged it.

      Fuck you and your fear mongering.

      If you were in front of me now I'd bitch slap you into the next time zone, motherfucker.

    15. Re:Bad logic by gweihir · · Score: 1

      Indeed. Best summary so far. The NSA seems to be turning more and more into a GeStaPo. On the plus side, they usually kill people outright (or help to do so), instead of torturing them first. So maybe they are still a bit better than the GeStaPo.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    16. Re:Bad logic by Anonymous Coward · · Score: 0

      Nice rant.

    17. Re:Bad logic by Nehmo · · Score: 1

      In the light let's correct the the heading. Edward Snowden did not cause the 'the most damaging breach of secrets in U.S. history.', he exposed the 'the most damaging breach of secrets in U.S. history.'. ....

      Agreed. It's amazing how people mindlessly parrot the government slant.
      Pretty much if the government states something, the opposite is true. The "corrections" department does not correct people; it punishes them. The "defense" department is for offense. The Division of Family Services breaks up families. The Patriot Act is unpatriotic. The ones who "serve and protect" really take your money and your freedom. Etc.

      --
      (||) Nehmo (||)
    18. Re:Bad logic by Blue+Stone · · Score: 1

      I have no more mod points, but would like to say that this entirely, and eloquently, sums up my views on this matter. Well said.

      --
      Corporation, n. An ingenious device for obtaining individual profit without individual responsibility. - Ambrose Bierce
    19. Re:Bad logic by Anonymous Coward · · Score: 0

      How can we vote for you if there is no democracy?

    20. Re:Bad logic by Anonymous Coward · · Score: 0

      Your stupid. Yes people like you seem to think that the NSA can only stop terrorists stupid enough to call their friends on the phone and discuss some terrorist plot. However you are wrong and ill informed! You see with new quantum technology the NSA is now capable of listening in on phone calls that never took place, they can read a text message that was never sent and they can download info from a computer that was never entered. I would explain it to you but it is just too complicated. It has to do with a cat that is both dead and alive at the same time. ;)

    21. Re:Bad logic by ATMAvatar · · Score: 1

      A 9/11 event would have to happen twice a week or more to crack the top 5 causes of death in the US. Why is it so important to give up on fundamental freedoms (i.e. the 4th Amendment)? Does it seem more or less important to you after considering that by the NSA's own admission, not a single terrorist has been caught or a citizen's life saved by this surveillance?

      --
      "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
    22. Re:Bad logic by flyneye · · Score: 1

      Dumbass, we were a Republic less than a century ago. So far Democrazy has done nothing good for us. ESAD

      --
      *Repent!Quit Your Job!Slack Off!The World Ends Tomorrow and You May Die!
    23. Re:Bad logic by flyneye · · Score: 1

      How did we vote before we were a Democrazy? This was less than a century ago.

      --
      *Repent!Quit Your Job!Slack Off!The World Ends Tomorrow and You May Die!
    24. Re:Bad logic by Anonymous Coward · · Score: 0

      This just in: In the REAL world, I am far more likely to be harassed, oppressed, muzzled, audited, or killed by my own government than I am by any terrorists, even the ordinary bloodthirsty Mohammedan variety. Don't try to tell me that the terrorists are a bigger threat than a Gestapo with powers and capabilities that Hitler and Stalin wished they had...

  3. CIA Head: We Will Spy On Americans Through [..] by Anonymous Coward · · Score: 0

    CIA Head: We Will Spy On Americans Through Electrical Appliances

    Global information surveillance grid being constructed; willing Americans embrace gadgets used to spy on them

    Steve Watson | Prisonplanet.com | March 16, 2012

    http://www.prisonplanet.com/ci...

    "CIA director David Petraeus has said that the rise of new "smart" gadgets means that Americans are effectively bugging their own homes, saving US spy agencies a job when it identifies any "persons of interest".

    Speaking at a summit for In-Q-Tel, the CIA's technology investment operation, Petraeus made the comments when discussing new technologies which aim to add processors and web connections to previously 'dumb' home appliances such as fridges, ovens and lighting systems.

    Wired reports the details via its Danger Room Blog[1]:

    "'Transformational' is an overused word, but I do believe it properly applies to these technologies," Petraeus enthused, "particularly to their effect on clandestine tradecraft."

    "Items of interest will be located, identified, monitored, and remotely controlled through technologies such as radio-frequency identification, sensor networks, tiny embedded servers, and energy harvesters - all connected to the next-generation internet using abundant, low-cost, and high-power computing," Petraeus said.

  4. Memorable quotes for 2014 and beyond by Anonymous Coward · · Score: 0

    Looker (1981)
    http://www.imdb.com/title/tt00...

    "John Reston: Television can control public opinion more effectively than armies of secret police, because television is entirely voluntary. The American government forces our children to attend school, but nobody forces them to watch T.V. Americans of all ages *submit* to television. Television is the American ideal. Persuasion without coercion. Nobody makes us watch. Who could have predicted that a *free* people would voluntarily spend one fifth of their lives sitting in front of a *box* with pictures? Fifteen years sitting in prison is punishment. But 15 years sitting in front of a television set is entertainment. And the average American now spends more than one and a half years of his life just watching television commercials. Fifty minutes, every day of his life, watching commercials. Now, that's power."

    ##

    "The United States has it's own propaganda, but it's very effective because people don't realize that it's propaganda. And it's subtle, but it's actually a much stronger propaganda machine than the Nazis had but it's funded in a different way. With the Nazis it was funded by the government, but in the United States, it's funded by corporations and corporations they only want things to happen that will make people want to buy stuff. So whatever that is, then that is considered okay and good, but that doesn't necessarily mean it really serves people's thinking - it can stupify and make not very good things happen."
    - Crispin Glover: http://www.imdb.com/name/nm000...

    ##

    "It's only logical to assume that conspiracies are everywhere, because that's what people do. They conspire. If you can't get the message, get the man." - Mel Gibson (from an interview)

    ##

    "We'll know our disinformation program is complete when everything the American public believes is false." - William Casey, CIA Director

    ##

    "The real reason for the official secrecy, in most instances, is not to keep the opposition (the CIA's euphemistic term for the enemy) from knowing what is going on; the enemy usually does know. The basic reason for governmental secrecy is to keep you, the American public, from knowing - for you, too, are considered the opposition, or enemy - so that you cannot interfere. When the public does not know what the government or the CIA is doing, it cannot voice its approval or disapproval of their actions. In fact, they can even lie to your about what they are doing or have done, and you will not know it. As for the second advantage, despite frequent suggestion that the CIA is a rogue elephant, the truth is that the agency functions at the direction of and in response to the office of the president. All of its major clandestine operations are carried out with the direct approval of or on direct orders from the White House. The CIA is a secret tool of the president - every president. And every president since Truman has lied to the American people in order to protect the agency. When lies have failed, it has been the duty of the CIA to take the blame for the president, thus protecting him. This is known in the business as "plausible denial." The CIA, functioning as a secret instrument of the U.S. government and the presidency, has long misused and abused history and continues to do so."
    - Victor Marchetti, Propaganda and Disinformation: How the CIA Manufactures History

    ##

    George Carlin:

    "The real owners are the big wealthy business interests that control things and make all the important decisions. Forget the politicians, they're an irrelevancy. The politicians are put there to give you the idea that you have freedom of choice. You don't. You have no choice. You have owners. They own you. They own everything. They own all the important land. They own and control the corporations. They've long since bought and paid for the Senate, the Congress, the statehouses, the city halls. They've got the ju

  5. Windows - they've got you by the balls! by Anonymous Coward · · Score: 1

    "People are aware that Windows has bad security but they are underestimating the problem because they are thinking about third parties. What about security against Microsoft? Every non-free program is a 'just trust me program'. 'Trust me, we're a big corporation. Big corporations would never mistreat anybody, would we?' Of course they would! They do all the time, that's what they are known for. So basically you mustn't trust a non free programme."

    "There are three kinds: those that spy on the user, those that restrict the user, and back doors. Windows has all three. Microsoft can install software changes without asking permission. Flash Player has malicious features, as do most mobile phones."

    "Digital handcuffs are the most common malicious features. They restrict what you can do with the data in your own computer. Apple certainly has the digital handcuffs that are the tightest in history. The i-things, well, people found two spy features and Apple says it removed them and there might be more""

    From:

    Richard Stallman: 'Apple has tightest digital handcuffs in history'
    www.newint.org/features/web-exclusive/2012/12/05/richard-stallman-interview/

  6. Well, if it was easy to stop him by fustakrakich · · Score: 1

    Then maybe the whole thing is intentional. After all, the voters, in their conditioned helplessness, aren't going to elect anybody to stop it, so what "damage" is the NSA going to suffer? Smooth everything over with a little PR, and it's back to business as usual. In fact nothing has changed except increased chatter on the internet.

    --
    “He’s not deformed, he’s just drunk!”
    1. Re:Well, if it was easy to stop him by Anonymous Coward · · Score: 0

      And now we have ukraine to bitch about. Go figure

  7. Oversight by Anonymous Coward · · Score: 0

    Without transparency, we can't find their flaws. If you want the NSA to work robustly, and resist internal threats (misuse of their data, leaks etc), its going to have to be more transparent. You can't have oversight without transparency: We gotta at least know what program exist so we can question how their oversight works. Otherwise each internal team has a free for all.

    Personally I'd rather have the whole thing fail, but not the way it has been failing. Unconstrained fragmented secret groups misusing data as they please and immune to laws is not the kind of failure I want...

    1. Re:Oversight by gweihir · · Score: 1

      The whole idea of the NSA is deeply flawed. But, judging from how things are going with the human race, maybe entirely deserved.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  8. Re:Microsoft Kinect Spy System & More by JockTroll · · Score: 1, Funny

    TLDRBIPIOAWMAWI (Too Long Didn't Read But I Printed It Out And Wiped My Ass With It).

    --
    Geeks are so full of shit that "beating the crap out of them" takes a whole new meaning.
  9. The sidebar was the most interesting part... by loony · · Score: 4, Insightful

    I started reading but soon moved on to just skimming the article. It read like a very logical but basic security primer... Until I hit the sidebar. Wow, I've never seen a better laid out, yet brief, history lesson that got straight to the point. Our government needs to remember that its "For the People, by the People" not "For those people, by these people"

    Peter.

    1. Re:The sidebar was the most interesting part... by gweihir · · Score: 1

      That is the old slogan. Today those in power have banded together against the people. It has been quite a while since any US government though it was "for the people".

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    2. Re:The sidebar was the most interesting part... by TubeSteak · · Score: 1

      I started reading but soon moved on to just skimming the article.

      So did I, but I didn't find the 1 fact that would be most relevant to this conversation:
      http://www.nytimes.com/2013/12/15/us/officials-say-us-may-never-know-extent-of-snowdens-leaks.html

      Officials said Mr. Snowden, who had an intimate understanding of the N.S.A.â(TM)s computer architecture, would have known that the Hawaii facility was behind other agency outposts in installing monitoring software.

      According to a former government official who spoke recently with Gen. Keith B. Alexander, the N.S.A. director, the general said that at the time Mr. Snowden was downloading the documents, the spy agency was several months away from having systems in place to catch the activity.

      The Hawaii network that Snowden was assigned to had not yet had its security upgraded as part of the fallout from Manning's massive leak.
      Most, if not all, of the security measures mentioned in this book summary had already been implemented elsewhere and Snowden intentionally picked Hawaii because of this.

      I hope the book goes into more detail, since it has been reported that the Snowden leaks have forced the NSA to consider further security measures beyond what they were already putting into place because of Manning.

      --
      [Fuck Beta]
      o0t!
    3. Re:The sidebar was the most interesting part... by ComputersKai · · Score: 1

      Well, the NSA can claim their security is "for the people", but not necessarily "by the people"

  10. Re: Microsoft Kinect Spy System & More by Anonymous Coward · · Score: 0

    You are fucking insane, even for /.

  11. Inevitable by dbIII · · Score: 3, Informative

    Personally I see using outside contractors such as Booz Allen Hamilton as the massive security breach.

    1. Re:Inevitable by Anonymous Coward · · Score: 0

      can they get around teh constitution by using contractors?

      "oh it wasn't us that did that, the contractor did it. we imposed a penalty on them according to the contract for doing that".

      later in private: 'here is your bonus for the great work you've been doing! keep it up!"

    2. Re:Inevitable by Anonymous Coward · · Score: 0

      At least you can fire contractors who screw up.

    3. Re:Inevitable by Anonymous Coward · · Score: 0

      Contractors go through the same background checks government employee's do. The funny thing though? Office of Personnel Management hires contractors to do investigations as well. There have been plenty of whistle blowers both contractor and government employed.

  12. Rename USA to North American Korea by Anonymous Coward · · Score: 1

    Never in history North Korea and USA were so close. It is true love between regimes of two countries.
    Anyone arriving in USA is terrified by the large number of security forces and STASI type lifestyle so much prevalent.

    Kim Jong Un blesses USA

    1. Re:Rename USA to North American Korea by zedaroca · · Score: 1

      Except that North Korea is not disrespecting every other nation's laws and people. As a Latin American, I don't feel any threats from North Korea. My constitutional rights and my human rights (from the international agreement) are not being violated by North Korea, only by the US.

    2. Re:Rename USA to North American Korea by Anonymous Coward · · Score: 0

      As a Latin American, I don't feel any threats from North Korea.

      You're not within range - yet.

  13. easy by Charliemopps · · Score: 4, Insightful

    The easiest fix would be to stop violating our constitutional rights. Snowden would have never leaked anything had the NSA been acting within the bounds of the constitution. Violate the constitution and everyone working for you that is a patriot is bound by honor to thwart you. Righteous anger is a SOB.

    1. Re:easy by Anonymous Coward · · Score: 0

      The funny thing about the situation is Snowden is being accused of "treason" when he's a hero. The one's doing the mass spying -- in gross violation of the US constitution -- are the criminals.

      That said, we shouldn't hold our breath for charges to be laid. The same people supposed upholding the law, are the same ones violating it.

    2. Re:easy by Sqr(twg) · · Score: 1

      This is especially true, since the security measures suggested by TFA are only designed to stop the lone rouge sysadmin. Even with all those measures in place, it would still be possible for two sysadmins working together to extract top secret documents.

    3. Re:easy by ZouPrime · · Score: 1

      Well, maybe that's true for Snowden, but it's just him. In practice, disclosure of sensitive information happens whether "constitutional rights" are respected or not, and the security controls that can be used to secure this information don't change.

    4. Re:easy by Charliemopps · · Score: 1

      Well, maybe that's true for Snowden, but it's just him. In practice, disclosure of sensitive information happens whether "constitutional rights" are respected or not, and the security controls that can be used to secure this information don't change.

      Yes, but how many people work for the NSA and would commit treason for profit or evil?

      Violate the constitution and now everyone that works there and cares about their country are against you as well. The point is, illegal acts raise the number of adversaries they need to deal with my orders of magnitude.

    5. Re:easy by ZouPrime · · Score: 1

      The unauthorized disclosure of sensible US information has happened regularly in the 20th century. Act of spying are motivated differently depending of the individual. Interestingly enough, it's rarely a question of ideology.

      Sure, illegal acts, or perceived as illegals, can motivate some people in doing what Snowden did. And yes, I guess stopping to do these acts will remove the incentive. But it doesn't mean that it's a solution for the actual security problem. And it certainly how the NSA will see it too.

    6. Re:easy by gweihir · · Score: 1

      Are you kidding? The very purpose of government is to oppress its population and tell them everything is "fine" as long as they are docile little sheep. You thing the Constitution has any value today? Think again.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    7. Re:easy by s.petry · · Score: 1

      Considering that the US Government hid Operation Mockingbird and COINTELPRO for decades (and is still hiding information on those programs), many people see no choice but to leak when the situation seems dire. In these situations it's not the whistle blower that's to blame. Those are just 2 of thousands of examples.

      --

      -The wise argue that there are few absolutes, the fool argues that there are no probabilities.

    8. Re:easy by ZouPrime · · Score: 1

      Well... sure... but how is this related to what I wrote?

    9. Re:easy by s.petry · · Score: 1

      Sure, illegal acts, or perceived as illegals, can motivate some people in doing what Snowden did

      I based my comment on that statement. Also read what whistle blowers themselves state, which is usually along the lines of "there was no choice because leadership is complicit"

      More of a correction that it's not a matter of just being motivated by something illegal. It isalso a belief that the only way to make corrections is to be a whistle blower.

      --

      -The wise argue that there are few absolutes, the fool argues that there are no probabilities.

  14. Permanent solution by Anonymous Coward · · Score: 0

    "Breach" all the secrets. Keep none. We have the deterrent of enough nukes to destroy anything and anyone. We have the fact that any large-scale conflict would only harm the aggressor in trade alone than they could hope to gain.

    The net "damage" to U.S. citizens, worst-case, would be vastly less than the economic and political damage the NSA has itself caused, and continues to cause, to the citizens.

    "National security" nowadays just means "security of the national security apparatus", and has little to do with security of the nation.

  15. Editors! by Anonymous Coward · · Score: 0

    Get thy to the editing!

  16. The Absolutist King Is Back by Anonymous Coward · · Score: 0

    ...and his name is Barak Obama.

    His predecessor was George W. Bush and his sucker abolutist King-lets are David Cameron, Angela Merkel and all the other sucker kinglets of Pax Americana.

    They all give a shit about "unreasonable search and seizuire" - spitting on their respective national constitutions or constitutional scriptures.

  17. That is also why by Anonymous Coward · · Score: 0

    ...they hate Putin. This man is kind of a patriot who sometimes cares about the average Russian, not just the Kleptocracy. Putin dared to lock up at least one of the most greedy Kleptocrats for a couple of years. The Kleoptocratic International hates Putin for this very badly.

    Consequently, they will try to sow all the hatred they can against Putin into Anglosaxon (and other Pax Americana) brains. Thank god there is the internet and we can call out this shit.

    @NSA, CIA: Question yourself whether you like the Kleptocrats or whether you like the government to care about the people. Discharging your duties properly means clamping down on the New York Kleptocracy and their friends. If you fail, well, have a replay of 1933 with Adolph Cromwell, a U.S. Army Corporal who turned himself into the Divine Leader of America.

  18. My 2 cents by JimSadler · · Score: 1

    I think that the degree of spying by the US government and the availability of computers and the net are locked hip to hip. Computers and somewhat open communication are powerful tools and the US government equates paranoia with responsibility.

  19. Securing that global database by AHuxley · · Score: 2

    1. Take control of your own networks via your own staff again.
    No contractors, no private sector, no ex gov staff moving around, people without exhaustive gov staff real world full family tree, education, friends interviewed background results.
    2. Drive the private sector contractors out of the gov networks. Fancy 3rd party network wide security software will not stop a trusted system admin, it will just give the security software bosses a nice gov contract bonus.
    3. Go back to finding all your staff from top universities after watching them in the wild for a few years. When ready, offer them a great job, for life with academic freedoms and an above great wage. Make sure they feel invited in.
    a) Interview them in person using gov staff only staff.
    b) If accepted as useful to the gov:
    Interview their extended family in person using only gov staff. Interview their recent academic staff in person using gov staff. Drive out to their local community and find friends, cops, ex cops, sealed court records, all teachers at every stage of schooling.... in person using gov only staff.
    Look at generations of book lists, magazines, newspapers, payments, gambling, faith with links to other nations, cults with links to other nations, holidays, charities, political causes, the probability of placing another nation/faith/cash/cult interests above all gov security levels.
    Build up a real world life story with real world contact with every close person or event and keep looking.
    Note: a database search is not a real world interview. A database search by a 3rd party private sector security cleared person is not a real world interview.
    Some data on a random gov computer about past good work been seen by a 3rd party private sector security cleared person is not a real world interview.
    Keep interviewing, testing, profiling your new staff using trusted gov staff - in house staff, not a 3rd party private sector security cleared person invited in with a new 'system' to rent.
    4. The file systems need to be kept air gapped and back to best practice compartmentalization. No new 3rd party cloud, no outside big brand private sector 'helpers' beyond installs.
    5.. Dont trust any paperwork from any other sector of the gov/private sector on an individual. If they have great paperwork and want to move jobs, something interesting might be missing from that great 'story'.
    6. Stop political suggestions over 'sharing' the cloud and other ways into what should be a sealed gov network.
    Some better ways to alter public perception:
    Hint at a limited hangout, or partial hangout, the idea that the material was baited provides endless speculation and academic busy work on web 2.0 and beyond.
    Drop hints via trusted cutouts to the 'alternative media' that will take years to work out.
    A sockpuppet is not a useful cutout.
    The hardware and software, junk encryption was for domestic use by 'others' in the wider US legal system. The results of a splitter, tame corporate/academic decryption ended up with any number of diverse ongoing very legal domestic criminal probes is a great talking point.
    Hint at a political culture for weakening once strong gov only security clearance levels.
    8. Talk the the UK about decades of tell all books, newspapers, interviews and 'documents' ie the magical "why" nothing ever got much traction beyond academic history books and obscure university level history papers.
    9.. As all this is now in the open and telco immunity is/was in place move forward with a domestic locked box for all telco metadata. Move in front of "damaging breach" to a post telco immunity budget and gov security expansion needs.

    --
    Domestic spying is now "Benign Information Gathering"
  20. Bob Toxen is a fascist by Anonymous Coward · · Score: 0

    Bob Toxen is a fascist who has his fist up the ass of the NSA.

    "The vast majority of NSA employees and contractors are eminently talented law-abiding dedicated patriots."

    No, they are fascists, like Bob, who got a hard one when they read 1984 and are now living the dream. They are the enemy of the people, and the enablers of our overlords. They are guilty.

    1. Re:Bob Toxen is a fascist by gweihir · · Score: 1

      And they are not very talented either. I now personally that they have to outsource critical stuff because they just cannot hack it themselves...

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    2. Re:Bob Toxen is a fascist by Anonymous Coward · · Score: 0

      No, they are fascists, like Bob, who got a hard one when they read 1984 and are now living the dream.

      Bullshit. I loathe the fact that I live in what has passed the tipping point and is now inexorably sliding towards being a police state, but don't blame the messenger. Security through obscurity isn't secure. NSA's got every right to secure themselves against internal and external threats as private businesses and private individuals do. Most of his suggestions are common sense, something of which the government is in short supply.

  21. Discussing how to help the guilty by Anonymous Coward · · Score: 0

    Discussing how to better secure systems against people like Snowden is like discussing how to ensure a thief or a murderer succeeds.

  22. Shay's Rebellion by Anonymous Coward · · Score: 0, Interesting

    Sure it was during the ORIGINAL Confederacy, but it WAS post-Revolution. What did it teach us? The people in charge will shit all over the veterans even if they just busted their ass to set you free. Combine that with the Whiskey Rebellion and this country was sunk before it even got started.

    But it's not like they bother to teach those little tidbits to gradeschool classes, where the less conditioned children might ask 'How is that any different than what the revolution set out to resolve?' or perhaps 'This sounds just like that children's book about the farm of animals!' :)

    1. Re:Shay's Rebellion by StevenMaurer · · Score: 2

      Um, no. The Whiskey Rebellion had nothing to do with "shitting on veterans". Veterans rallied around George Washington to put down the rebels.

      George Washington was a millionaire at the time because he owned some extremely popular Whiskey distilleries, so when he imposed the first taxes of the nation (largely to pay our war debts), the first thing he did was put on a tax that hit himself hardest. This was considered fair. Even in those days, it was well known that alcohol came with severe social consequences, so this Sin Tax was generally accepted as the best way to raise national funds.

      So what drove the Whiskey Rebellion? Largely it was early Borderlander (Scott/Irish) culture, one of the american nations, which simply wanted all the benefits of living the United States without having to pay a dime for its upkeep. This attitude, by the way, still completely dominates in these regions 200 years later, driving much of our politics: right wingers who pretend to "speak for the veterans" while at the same time refusing to pay for their benefits. Clyde Bundy is a poster child for borderlander culture

      Thinking about it, I suppose you could say that "shitting on veterans" was the point of the revolution - it was just the rebels who were trying to do the shitting.

  23. Re:Microsoft Kinect Spy System & More by cffrost · · Score: 1

    You don't seriously expect people to spend the day plowing through this without a summary, do you? Where's the abstract for this report, book, manifesto, or whatever it is?

    --
    Thank you, Edward Snowden.

    "Arguments from authority are worthless." —Carl Sagan
  24. Amoral by Anonymous Coward · · Score: 0

    I suppose it would be more accurate to sat they are amoral, but the results are the same.

  25. Why have secrets? by Anonymous Coward · · Score: 0

    We need to change our policy on secrets - nothing is secret past a year. The year is enough for tactical security, but not enough to hide embarrassments. Then the state will have to be answerable to its bosses - the citizens.

  26. Re:Bad logic (on logic) by Nehmo · · Score: 1

    Except there is also the fact that some of the NSA's main goals, despite its draconian and probably unconstitutional methods, are still counterterrorism and counterintelligence. When a friend or family member is killed in a terrorist attack because the NSA's security wasn't adequate you can be proud you encouraged it.

    Whatever the "claimed" goals of government are, its real actions are the things that count, and nowadays, in terms of something resulting from NSA intrusions, an American is more likely to be harmed by her or his own government than harmed by a "terrorist attack". The NSA has not been very successful in citing successes in its protecting of Americans.

    If you could guarantee the goals of the NSA were always noble, then I would favor granting them far-reaching authority. But, in reality, the government, and elements of the government such as the NSA in particular, are often not noble; thus, *government authority must be limited*. This is a concept enshrined in The Constitution, and it's also a concept widely accepted by people everywhere the modem civilized world.

    --
    (||) Nehmo (||)
  27. What the author seems to be missing.... by Rick+Zeman · · Score: 2

    ...is somewhere along the line SOMEONE has to be trusted. That secure program that transfers files? How do you know it doesn't have a back door/hidden features? You audit that source code..do you trust the auditor? How do you know he's not in collusion with the programmer? Hmm, better get someone or someones to audit them. And so on....
    Technical restrictions are good, but they're not the be-all. Technically, the best locked down systems aren't usable (any geezers here remember C2 [orange book] Windows NT 4 systems? Very secure (especially for NT in the day)...and wholly unusable).

    His comments about securing ssh are just common sense and best practices (for once they coincide). As he pointed out, metal detectors would have caught the egress of the thumb drives. Just as locks on reinforced cockpit doors would have prevented 9/11, sometimes the low-tech scalable solution is the best solution.

  28. It's "renowned" not "renown" by wytcld · · Score: 1

    If you are of renown, you are renowned. You'd think folks sensitive to the exacting demands of various languages would be more respectful of English. Sheesh.

    --
    "with their freedom lost all virtue lose" - Milton
  29. Re:Microsoft Kinect Spy System & More by Rick+Zeman · · Score: 1

    You don't seriously expect people to spend the day plowing through this without a summary, do you? Where's the abstract for this report, book, manifesto, or whatever it is?

    The video game generation strikes again.

  30. Doing anything to an American by Anonymous Coward · · Score: 0

    With law enforcement intent ,should get you life in prison if there is no probable cause.

  31. NSA say if you're "clean", you don't need to worry by Anonymous Coward · · Score: 0

    ... so, why they're worried about people investigating them?

  32. Versus -- increasing Cognitive Diversity... by Paul+Fernhout · · Score: 1

    My essay: http://www.phibetaiota.net/201...
    "This essay discusses how the USA's security clearance process (mainly related to ensuring secrecy) may have a counter-productive negative effect on the USA's national security by reducing "cognitive diversity" among security professionals."

    An example I have there:
    ----
    Let us contrast two candidates with different very backgrounds and ask which one would get a security clearance. Which of the two would be hired to create the social and technical systems to define US National Security?

    The first candidate is a woman performance artist currently couchsurfing near New York City's Greenwich Village. She has a messed up credit history, suffers from depression, has been on psychological medication, had a terrible childhood, and has had multiple friendships and has slept with people from a variety of foreign nations who she met in NYC. She even spent a few months living in the Middle East protesting various US-related policies. She was arrested once for smoking marijuana in public outside a nightclub. She is outraged by domestic violations of privacy rights in the USA and would never submit to a security clearance screening involving lots of prying questions (if only to protect her friends). Still, she has "been there" and understands what it means to be poor and also understands what it means to see the world from multiple points of view (including the downtrodden). To her, the invasion of Iraq was an obviously stupid thing to do and she was arrested for protesting before the invasion, too. Well, it does not take much imagination to assume she would be denied a security clearance, not that she would probably ever consider a job that requires applying for one.

    The second candidate is a woman with a PhD in mathematics and a master's and bachelors degree in public policy from an Ivy League university (paid for by her professional parents). She has never known a day of hunger or homelessness in her life, has excellent credit, is very emotionally stable in the past (although the limits of that have never really been tested), has never felt a need to escape from her life using drugs, and has married a reliable accountant (himself a third generation American). She thinks that a job working at the Pentagon is worth just about any sacrifice to preserve a superior US way of life (plus, she feels she and her family and friends have nothing to hide). Well, it would seem there is probably a good chance such a person would get a security clearance, even if her polygraph readings jumped when she confessed that she has in the past purchased "fair trade" coffee that came from South America and also drives a Toyota Prius that her parents gave her as a birthday present last year.

    Ten years go by and our successful second candidate has risen to a position where she is assisting in using highly mathematical Operations Research to define US defense policy and weapons systems priorities to protect against those she sincerely feels "hate us because we are free". Do you feel safer as a result? Do you really think she could do as effective a job in thinking about security threats and opportunities relative to general US interests as the other woman who would never qualify for a security clearance?

    As for our first candidate, perhaps she becomes a Volvo-driving soccer mom with three kids in Portland, Oregon, a successful author, and married to an organic grocery store manager, to give her story a reasonably happy ending in mainstream terms? :-)

    But here is a deep question implicitly raised by Scott Page's writings. Do you think the two women, working together, along with others, might be able to do a better job at improving US national security out of their diversity of skills and experiences than either one working alone? What sort of social environment or workplace setting would it take to make that possible?

    --
    A 21st century issue: the irony of technologies of abundance in the hands of those still thinking in terms of scarcity.
    1. Re:Versus -- increasing Cognitive Diversity... by AHuxley · · Score: 1

      Both exhibit what any intelligence service would desire. The ability to work in the community facing interesting events, languages, rapidly changing slang, people, cultures, locations and living with habits that are not without constant risk.
      They are the classic butterfly collectors or anthropologist with deep cover in distant lands as used over generations.
      You have very smart people with the ability to hide their needs. One event may have pulled them very close to the security/mil sector.
      What happens when the security/mil sector moves on from their only reason for joining? New people, other skills, new languages. How does that person react, cope, who can they talk to?
      Thats always the problem when skilling up fast with the poor or rich, people with needed skills. What are you inviting in long term and how will they react when their cause is not getting instant, top priority?
      ie historically a vast number of new people with one event skills does not end well on average. Other groups, countries, faiths, cults start to look and befriend offering the positive feeling about the past.
      You have a person who is trusted, has moved up, is sneaky and has new friends... too many people with too many rushed clearances gets hard to track and then confront..

      --
      Domestic spying is now "Benign Information Gathering"
  33. "Most damaging". Yeah. Right. by Anonymous Coward · · Score: 0

    More damaging than that committed by the Rosenbergs, which only taught the Soviets how to make nuclear weapons and started the nuke-fueled Cold War.

    Hyperbole much?