Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
SubG
Aug 19, 2004

It's a hard world for little things.

ShadowHawk posted:

And they are low-hanging fruit in part because the NSA doesn't care about its mission to help secure the internet. I don't think we can attribute this particular incident to North Korea exploiting the same holes the NSA ripped open due to sabotage of security standards, but it's only a matter of time before someone does.
I agree that the US should devote more government resources to securing both the large-scale infrastructure of the internet as well as reaching out to individual corporate entities to improve standards and practices at that level. I don't think it's within the NSA's mission to do that however. Maybe the FBI. Part of the problem is that we've got a whole shitload of agencies and assets tasked with getting into poo poo, but very little devoted to improving security.

And I'm not even sure what a workable solution to this sort of thing would look like. If the problem is loving SQL injection and spear phishing then that's not exactly elaborate superspy hacking the Gibson poo poo. It's Sony crapping out on information security 101. And how do you put together a group inside a government agency that can fix that. Like I'd be willing to bet that somewhere in Sony some sysadmins/SREs/whatever the fucks knew about the problems and knew how to fix them and just lacked the corporate will and resources to actually do anything about it. Sony's a publicly-traded company. That means that they've, by legal requirement, had auditors go over all this poo poo with them. What can we imagine a government agency could have done that the auditors failed to?

Adbot
ADBOT LOVES YOU

Spergin Morlock
Aug 8, 2009

ShadowHawk posted:

And they are low-hanging fruit in part because the NSA doesn't care about its mission to help secure the internet. I don't think we can attribute this particular incident to North Korea exploiting the same holes the NSA ripped open due to sabotage of security standards, but it's only a matter of time before someone does.

It's not the NSA's fault that some dimwit at Sony gathered so many credentials together, in plaintext, and stored them all in the same directory. That's on Sony and their people.

Snak
Oct 10, 2005

I myself will carry you to the Gates of Valhalla...
You will ride eternal,
shiny and chrome.
Grimey Drawer

Chadderbox posted:

It's not the NSA's fault that some dimwit at Sony gathered so many credentials together, in plaintext, and stored them all in the same directory. That's on Sony and their people.

Based on previous Sony breaches, it's common practice for Sony.

ShadowHawk
Jun 25, 2000

CERTIFIED PRE OWNED TESLA OWNER

SubG posted:

I agree that the US should devote more government resources to securing both the large-scale infrastructure of the internet as well as reaching out to individual corporate entities to improve standards and practices at that level. I don't think it's within the NSA's mission to do that however. Maybe the FBI. Part of the problem is that we've got a whole shitload of agencies and assets tasked with getting into poo poo, but very little devoted to improving security.
It's within the NSA's purview. Stuff like SE Linux originally came out of the NSA. Imagine what could happen if some of the literal billions of dollars that went into the NSAs budget went into improving the usability of actual security rather than for attacking American firms to steal data about "49%-probability" citizens.

SubG
Aug 19, 2004

It's a hard world for little things.

ShadowHawk posted:

It's within the NSA's purview. Stuff like SE Linux originally came out of the NSA.
And the design of the DES s-boxes and Dual_EC_DRBG.

But whatever. If you want to hold up SELinux you're talking about something that started as an internal initiative back in the early '90s (about as old as and originally independent of the linux kernel). If you want to see what a newer NSA project pursuant to their nominal information assurance goals you get something like the Perfect Citizen/Einstein programme. Which is essentially indistinguishable from all the other creepy surveillance state NSA poo poo that's been discussed in the thread. This shouldn't be surprising; nearly everything that used to be in the NSA devoted to traditional nuts-and-bolts information assurance got re-org'd into Homeland Security. Where a director of the new NSCS (National Cybersecurity Center, not the National Computer Security Center which used to be part of the NSA and developed the rainbow books and so on) resigned because he felt NSA interference made accomplishing the NSCS's goals impossible (and constituted a `threat to our democratic process', in his words).

The NSA is a spy agency. Its solution to all problems is getting more of its eyes up in your poo poo. But I mean don't rely on my word for it. Take a look at the 2012-2016 strategy/mission statement document in the Snowden leaks. Except for a token bullet item about fostering an environment that rewards diversity, all of the mission goals involve target acquisition and data analysis.

I don't think this is a point you're fundamentally trying to argue (I mean you were the one arguing that they're an `outlaw agency' earlier). So I don't know why you'd suddenly want to start relying on them for fixing poo poo like the Sony hack(s). I mean I think it would be great if someone did help improve general information security. I just really don't see why you suddenly like the loving NSA for the job.

ShadowHawk
Jun 25, 2000

CERTIFIED PRE OWNED TESLA OWNER

SubG posted:

And the design of the DES s-boxes and Dual_EC_DRBG.

But whatever. If you want to hold up SELinux you're talking about something that started as an internal initiative back in the early '90s (about as old as and originally independent of the linux kernel). If you want to see what a newer NSA project pursuant to their nominal information assurance goals you get something like the Perfect Citizen/Einstein programme. Which is essentially indistinguishable from all the other creepy surveillance state NSA poo poo that's been discussed in the thread. This shouldn't be surprising; nearly everything that used to be in the NSA devoted to traditional nuts-and-bolts information assurance got re-org'd into Homeland Security. Where a director of the new NSCS (National Cybersecurity Center, not the National Computer Security Center which used to be part of the NSA and developed the rainbow books and so on) resigned because he felt NSA interference made accomplishing the NSCS's goals impossible (and constituted a `threat to our democratic process', in his words).

The NSA is a spy agency. Its solution to all problems is getting more of its eyes up in your poo poo. But I mean don't rely on my word for it. Take a look at the 2012-2016 strategy/mission statement document in the Snowden leaks. Except for a token bullet item about fostering an environment that rewards diversity, all of the mission goals involve target acquisition and data analysis.

I don't think this is a point you're fundamentally trying to argue (I mean you were the one arguing that they're an `outlaw agency' earlier). So I don't know why you'd suddenly want to start relying on them for fixing poo poo like the Sony hack(s). I mean I think it would be great if someone did help improve general information security. I just really don't see why you suddenly like the loving NSA for the job.
Oh organizationally I don't think they're capable of it at all given how far they've gone and the culture. The larger point I'm making is that it's just a huge misappropriation of resources and that, in principle, that same amount of resources directed towards actually promoting information security would place us in an entirely different security environment.

Such exercises are a bit like comparing public health or safety issues to the war on terror, though.

hepatizon
Oct 27, 2010

SubG posted:

The NSA is a spy agency. Its solution to all problems is getting more of its eyes up in your poo poo. But I mean don't rely on my word for it. Take a look at the 2012-2016 strategy/mission statement document in the Snowden leaks. Except for a token bullet item about fostering an environment that rewards diversity, all of the mission goals involve target acquisition and data analysis.

I don't think this is a point you're fundamentally trying to argue (I mean you were the one arguing that they're an `outlaw agency' earlier). So I don't know why you'd suddenly want to start relying on them for fixing poo poo like the Sony hack(s). I mean I think it would be great if someone did help improve general information security. I just really don't see why you suddenly like the loving NSA for the job.

The NSA's page claims that "Information Assurance", basically network security, is one of their two primary missions.

SubG
Aug 19, 2004

It's a hard world for little things.

hepatizon posted:

The NSA's page claims that "Information Assurance", basically network security, is one of their two primary missions.
I know. That's why I talked about it, in those terms, in the paragraph immediately above the ones you quoted. The big headline NSA information assurance project is running Nessus and nmap against domestic networks. Included: collecting and analysing a shitload of data on everyone. Not included: any remediation whatsoever.

Not, incidentally, that anyone should rationally want the NSA to be responsible for remediation efforts because, if the historical record is any indication, their goals would not be to prevent any potential compromises, but rather to prevent compromises by anyone other than the NSA.

So, yes. Information assurance is nominally one of the NSA's missions. But when they use that phrase it does not mean what you think it means.

ShadowHawk posted:

Oh organizationally I don't think they're capable of it at all given how far they've gone and the culture. The larger point I'm making is that it's just a huge misappropriation of resources and that, in principle, that same amount of resources directed towards actually promoting information security would place us in an entirely different security environment.
It's a stretch to call it misappropriation when it's part of explicit executive policy. I mean at this point I think it would be a net win for both American interests and everyone else's interests to scrap more or less the entire US intelligence community and rebuild it from scratch (which is very nearly what has happened since 9/11, to its and our detriment on nearly every level). But the NSA didn't write NSPD-54/HSPD-23 or orchestrate the political trainwreck behind it; that's pure executive action.

i am harry
Oct 14, 2003

http://www.theguardian.com/theobserver/2015/jan/04/nico-sell-wickr-secure-messaging-app-internet-security-nsa-edward-snowden

Interview with founder of some messaging thing. This stood out to me:

quote:

You describe yourself as “properly paranoid”. Is that what we should all be?
If people really understood what was going on, they would be. To me, the NSA and Snowden are just the tip of the iceberg. I don’t have personal conversations that I wouldn’t want to read in a newspaper on email and SMS, nor a phone call unless it’s encrypted with Wickr. I assume all those are public conversations. I’m very careful with Google searches. I wouldn’t do any healthcare search without using a VPN [virtual private network] and a small search engine such as Blekko. And if I’m buying booze for a party I’ll put it on cash instead of a credit card. I think the health insurance companies are very much looking at everything you do and buy. It’s all being watched.

That last sentence...is that just insanity/trying to make the software they're selling seem important?

Elysiume
Aug 13, 2009

Alone, she fights.
I find it hard to believe that insurance companies have access to the full credit card records of everyone they insure and use that information to adjust premiums or whatever.

KillHour
Oct 28, 2007


I don't. I've had jobs pull my credit report before hiring me.

FlamingLiberal
Jan 18, 2009

Would you like to play a game?



Yeah a lot of jobs run credit reports even if it's really irrelevant to the position.

KillHour
Oct 28, 2007


They want to see if you're "responsible" and make sure you're not "a high risk for theft" (poor).

The MUMPSorceress
Jan 6, 2012


^SHTPSTS

Gary’s Answer
My wife has been screwed out of several jobs and promotions at her current job because of a bankruptcy on her credit report. It's absurd what employers hold over your head. "You were the first person in your family to go to college, you say, and your parents aren't financially literate and didn't teach you how to manage your money and credit? Too bad, you're not eligible to advance from a junior position until all past indiscretions are removed from your report."

vxsarin
Oct 29, 2004


ASK ME ABOUT MY AP WIRE PHOTOS

LeftistMuslimObama posted:

My wife has been screwed out of several jobs and promotions at her current job because of a bankruptcy on her credit report. It's absurd what employers hold over your head. "You were the first person in your family to go to college, you say, and your parents aren't financially literate and didn't teach you how to manage your money and credit? Too bad, you're not eligible to advance from a junior position until all past indiscretions are removed from your report."

Yeah, it's a bit silly. Also, if you get a bankruptcy while you are employed with them and doing a good job, are they going to fire you? No.

i am harry
Oct 14, 2003


This is a little off-topic, and I don't want to come off sounding shrill, but I think we should avoid using little terms like this when discussing the power wielded over a person like that with little to no base or ground. That attitude is why server positions in this country are less than minimum wage jobs before tips. The boardrooms of hundreds of powerful, interested (not benevolently in us) parties teleconferenced their wants through a lobbying institution with a deceptively authentic name like "Chamber of Commerce", and everyone just shrugs like it's a god damned given.
see also: myers-briggs testing, drug testing

Kafka Esq.
Jan 1, 2005

"If you ever even think about calling me anything but 'The Crab' I will go so fucking crab on your ass you won't even see what crab'd your crab" -The Crab(TM)
Edit: what the gently caress happened here :psyduck:

Kafka Esq. fucked around with this message at 04:58 on Feb 2, 2015

Maluco Marinero
Jan 18, 2001

Damn that's a
fine elephant.

Kafka Esq. posted:

On the other hand, we don't exactly advertise SomethingAwful's Canadian Politics thread as a safe space, so while we shouldn't be dicks about things, do we have to get into long tangents about semiotics?

I'd hardly call a paragraph about the data-mining approach businesses take to granting/denying jobs to everyday people in the Surveillance in the 21st Century thread a long tangent.

User0015
Nov 24, 2007

Please don't talk about your sexuality unless it serves the ~narrative~!

Elysiume posted:

I find it hard to believe that insurance companies have access to the full credit card records of everyone they insure and use that information to adjust premiums or whatever.

While it's extremely unlikely an insurance company has access to any individuals credit card records, every insurance company is rather friendly with at least one big bank. I'm certain they have mountains of statistics they can analyze and sift through thanks to the data available through the bank. The (sad?) fact is that any specific individual really doesn't matter to something like a large insurance company. You, personally, are not important. It's the aggregate that matters, and how they base their premiums. So while he individually might be paranoid enough to hide his information, it's really the group that they're concerned with.

Malloc Voidstar
May 7, 2007

Fuck the cowboys. Unf. Fuck em hard.
http://www.telegraph.co.uk/technolo...id-Cameron.html

David Cameron posted:

The Security Services will be given the powers to read all messages sent over the internet, if the Conservatives win the general election.

David Cameron, the Prime Minister, made the pledge at a campaign event attended by up to 100 Conservative activists in Nottingham.

The police and the intelligence agencies have expressed concerns that they are not able to access the content of some of the new ways to communicate over the internet.

The Prime Minister - who on Monday morning chaired a meeting of the Security Services to discuss lessons that be learned from last week's terrorist attacks on Paris - said a Tory Government would pass a law in the next Parliament to ensure that the police and Security Services can read internet messages.

[...]

“That is the key principle: do we allow terrorists safer spaces for them to talk to each other. I say no we don’t – and we should legislate accordingly. And if I am in Government that is what you will get.”

He added: “I have a very simple principle which will be the heart of the new legislation that will be necessary. In our country, do we want to allow a means of communication between people which even in extremis, with a signed warrant from the home secretary personally, that we cannot read? “Up until now, governments have said: ‘No, we must not’.

“That is why in extremis it has been possible to read someone’s letter, to listen to someone's telephone, to mobile communications.

“But the question remains: are we going to allow a means of communications which it simply isn’t possible to read. My answer to that question is: ‘No we must not’.
David Cameron appears to be planning to ban crypto.

Broken Machine
Oct 22, 2010

Aleksei Vasiliev posted:

http://www.telegraph.co.uk/technolo...id-Cameron.html
David Cameron appears to be planning to ban crypto.

i am harry
Oct 14, 2003

User0015 posted:

You, personally, are not important. It's the aggregate that matters, and how they base their premiums.
This sounds a bit like an extension of the "they'll never have enough people to look at the individual person," thing I used to tell myself.
Then they made software that could make both the aggregate and the individual viewable, traceable...so again, I don't want to sound too crazy but...Well that article about the car insurance company mentioning that everyone with their little plug-in monitor installed regularly sped and they could-but-couldn't report everyone to the police seems to be down the same line.

Nintendo Kid
Aug 4, 2011

by Smythe

KillHour posted:

I don't. I've had jobs pull my credit report before hiring me.

A credit report is a significantly different thing than full credit card records.

ComradeCosmobot
Dec 4, 2004

USPOL July
Well, I think it's time to close the thread. The NSA has been rehabilitated, as over half of Americans view the NSA favorably, and only seniors view it more unfavorably than favorably. Millennials are the most approving, with 3 in 5 approving of the job the agency is doing.

Warcabbit
Apr 26, 2008

Wedge Regret

Aleksei Vasiliev posted:

http://www.telegraph.co.uk/technolo...id-Cameron.html
David Cameron appears to be planning to ban crypto.

This will have no negative effect on people's bank accounts.

Nektu
Jul 4, 2007

FUKKEN FUUUUUUCK
Cybernetic Crumb

ComradeCosmobot posted:

Well, I think it's time to close the thread. The NSA has been rehabilitated, as over half of Americans view the NSA favorably, and only seniors view it more unfavorably than favorably. Millennials are the most approving, with 3 in 5 approving of the job the agency is doing.
Goodbye free world, you will be missed.

Warcabbit posted:

This will have no negative effect on people's bank accounts.
... and B2B communication. How the gently caress can a crypto-ban even work without hurting businesses?

Nektu fucked around with this message at 22:12 on Jan 31, 2015

Snak
Oct 10, 2005

I myself will carry you to the Gates of Valhalla...
You will ride eternal,
shiny and chrome.
Grimey Drawer
How can they even prove you're using encryption? What if you're just sending strings of garbage data around for fun?

sat on my keys!
Oct 2, 2014

Snak posted:

How can they even prove you're using encryption? What if you're just sending strings of garbage data around for fun?

"Your Honor, although it may appear that I was using public key encryption to send messages about sweet bong hits, I was in fact merely shitposting."

Snak
Oct 10, 2005

I myself will carry you to the Gates of Valhalla...
You will ride eternal,
shiny and chrome.
Grimey Drawer

bartlebyshop posted:

"Your Honor, although it may appear that I was using public key encryption to send messages about sweet bong hits, I was in fact merely shitposting."

But for real, how could they prove it if they can't break your encryption? Like, a number's station is just the word's worst radio show, and definitely isn't transmitting encrypted information...

Kobayashi
Aug 13, 2004

by Nyc_Tattoo

Snak posted:

But for real, how could they prove it if they can't break your encryption? Like, a number's station is just the word's worst radio show, and definitely isn't transmitting encrypted information...

They don't care if "you" use encryption. They care if Google or Apple or Microsoft do.

mila kunis
Jun 10, 2011
A super long read, but interesting:

https://medium.com/@NafeezAhmed/how-the-cia-made-google-e836451a959e

BeanpolePeckerwood
May 4, 2004

I MAY LOOK LIKE SHIT BUT IM ALSO DUMB AS FUCK



This is sort of a crosspost, but here is The Baffler's talk with Cade Crockford and Noam Chomsky about terrorism and the surveillance state. It covers a ton of ground on other topics, too.

http://www.thebaffler.com/videos/crockford-chomsky-full/

Main Paineframe
Oct 27, 2010

Aleksei Vasiliev posted:

http://www.telegraph.co.uk/technolo...id-Cameron.html
David Cameron appears to be planning to ban crypto.

He's almost certainly referring to requiring that all communication services in Canada's jurisdiction provide encryption keys, a backdoor "god view" functionality, or some other way to allow government officials to view the contents of communications transmitted via those services. It's fun to joke about "haha dumb politician wants to ban talking in code, isn't he dumb and stupid" but honestly, who the hell uses their own offline encryption these days when chatting or emailing? Hardly anyone does; most people use a "secure" chat or messaging or email service to communicate, and those communications are all somehow subject to a central authority that the government can attack or pressure. It's not like the NSA is furiously analyzing Skype communications for encryption keys or something like that - they just went to Microsoft and asked for a backdoor, and Harper no doubt intends to follow much the same strategy. Targeting communication services would happily bag almost all "secure" communications...if all chat, messaging, and email services were under Canadian jurisdiction, anyway. The limits of the ability of the Canadian government to police foreign chat clients means that only those who decide to willingly compromise their service in response to a government request would comply, giving the Canadian government access to only most "secure" communications rather than all.

Spergin Morlock
Aug 8, 2009

Main Paineframe posted:

He's almost certainly referring to requiring that all communication services in Canada's jurisdiction provide encryption keys, a backdoor "god view" functionality, or some other way to allow government officials to view the contents of communications transmitted via those services. It's fun to joke about "haha dumb politician wants to ban talking in code, isn't he dumb and stupid" but honestly, who the hell uses their own offline encryption these days when chatting or emailing? Hardly anyone does; most people use a "secure" chat or messaging or email service to communicate, and those communications are all somehow subject to a central authority that the government can attack or pressure. It's not like the NSA is furiously analyzing Skype communications for encryption keys or something like that - they just went to Microsoft and asked for a backdoor, and Harper no doubt intends to follow much the same strategy. Targeting communication services would happily bag almost all "secure" communications...if all chat, messaging, and email services were under Canadian jurisdiction, anyway. The limits of the ability of the Canadian government to police foreign chat clients means that only those who decide to willingly compromise their service in response to a government request would comply, giving the Canadian government access to only most "secure" communications rather than all.

You do realize that article was about David Cameron in the UK and not Stephen Harper in Canada, right?

Main Paineframe
Oct 27, 2010

Chadderbox posted:

You do realize that article was about David Cameron in the UK and not Stephen Harper in Canada, right?

I'm an American, he could be the King of France for all I care. The overall point still applies regardless of where he is.

Spergin Morlock
Aug 8, 2009

Main Paineframe posted:

I'm an American, he could be the King of France for all I care. The overall point still applies regardless of where he is.

Main Paineframe posted:

He's almost certainly referring to

When you said "he" without specifying that you were talking about a subject not listed in the comment you were replying to, it made it look like you were more interested in sharing your opinion than even appearing to have read the article linked by the person you were replying to. After I pointed this out you made a comment about how you don't care where "he" is located because your opinion is still your opinion. Does it matter to you that the article/post you responded to is NOT about the same person at all?

Main Paineframe
Oct 27, 2010

Chadderbox posted:

When you said "he" without specifying that you were talking about a subject not listed in the comment you were replying to, it made it look like you were more interested in sharing your opinion than even appearing to have read the article linked by the person you were replying to. After I pointed this out you made a comment about how you don't care where "he" is located because your opinion is still your opinion. Does it matter to you that the article/post you responded to is NOT about the same person at all?

No, because I wasn't responding to the article, I was calling out the tendency in this thread to trivialize calls to backdoor and subvert communication services as "ha ha dumb politician thinks he can ban encryption, he is so dumb and stupid and funny and harmlessly naive".

Spergin Morlock
Aug 8, 2009

Main Paineframe posted:

No, because I wasn't responding to the article, I was calling out the tendency in this thread to trivialize calls to backdoor and subvert communication services as "ha ha dumb politician thinks he can ban encryption, he is so dumb and stupid and funny and harmlessly naive".

I'm just saying if you weren't replying to the comment or the article quoted in it... ugh never mind. Out of curiosity, who in this thread do you think has been trivializing those things? I've been reading it for a while and haven't seen that at all.

snorch
Jul 27, 2009
UK-US surveillance regime was unlawful ‘for seven years’

quote:

The regime that governs the sharing between Britain and the US of electronic communications intercepted in bulk was unlawful until last year, a secretive UK tribunal has ruled.

The Investigatory Powers Tribunal (IPT) declared on Friday that regulations covering access by Britain’s GCHQ to emails and phone records intercepted by the US National Security Agency (NSA) breached human rights law.
Liberty v GCHQ: read the judgment of the tribunal
Read more

Advocacy groups said the decision raised questions about the legality of intelligence-sharing operations between the UK and the US. The ruling appears to suggest that aspects of the operations were illegal for at least seven years – between 2007, when the Prism intercept programme was introduced, and 2014.

The critical judgment marks the first time since the IPT was established in 2000 that it has upheld a complaint relating to any of the UK’s intelligence agencies. It said that the government’s regulations were illegal because the public were unaware of safeguards that were in place. Details of those safeguards were only revealed during the legal challenge at the IPT. [...]

http://www.theguardian.com/uk-news/2015/feb/06/gchq-mass-internet-surveillance-unlawful-court-nsa

Looks like they're going to do jack poo poo in response.

Adbot
ADBOT LOVES YOU

Tezzor
Jul 29, 2013
Probation
Can't post for 3 years!
Well, of course. The court's argument was "if you had told us it would have been legal, but you didn't so it wasn't, but you did now so we're not going to do anything." You would think that courts would, if nothing else, try to uphold their own power and relevance.

  • Locked thread