Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, particularly given it was against a US telecom company, the NSA would make sense as the source of the implant.


No that would make 0 sense. The NSA doesn't "attack" american companies with covert implants.

They get FISA court orders that force american companies to attach their equipment.



> ...doesn't "attack" american companies with covert implants.

Specific example aside, it's worth talking about why this does happen. "Black bag jobs" can mean "we didn't get a warrant", but they can also mean "we got a warrant and still aren't telling".

Even given a court order, there's still a possibility that employing surveillance by fiat will cause somebody to leak, or modify how they handle data, or simply reveal information about what sort of surveillance tools a given agency employs. Given that a FISA order can be obtained without a defendant, getting a court order and then doing the thing secretly anyway gives a sort of "bowling with bumpers" advantage where the project is approved if it gets revealed, but also done without revealing anything if it isn't.

More disturbingly, there's also substantial evidence that the NSA attacks companies covertly in places where they couldn't get a court order. Taking a specific device out of the supply chain and adding surveillance before it's shipped to the destination is a warrant-worthy project. Setting up systematic physical vulnerabilities with a use case of "turn it on some time in the future to get something interesting" isn't in the purview of a FISA order, so if the NSA did do that it would have to be without an order.


Wasn't PRISM all about attacking American companies with covert implants? For instance tapping into Google region to region data transfers, after which Google started encrypting everything.


I thought PRISM wasn't covert. Companies were compelled to allow them to install their sniffing hardware, it was all above-board. Snowden even leaked an internal slideshow with a nice timeline of when each tech company joined the program.


Parts of that whole expose were covert. In the case of Google we know by tapping fiber connections that they had between data centers (as sseth mentioned, using foreign intelligence peers to do an end run around legal protections), which was on Google owned fiber, theoretically entirely "in-house", so Google transferred it unencrypted. I believe they called this operation "Muscular". After the fiasco Google started assuming everything was hostile.


PRISM was an overt program (to the data stewards, not to the public) for processing FISA warrants and the like.

Other NSA programs that Snowden revealed were covert hacks. https://en.wikipedia.org/wiki/Global_surveillance_disclosure...


My understanding is that the google tapping was done in UK using British intelligence services, thus bypassing the legal constraints.


The program for tapping data center links had the internal code name MUSCULAR and was a partnership with the British GCHQ, who actually did the intercepting.

PRISM was at first reported as some sort of direct access to the servers of certain American companies, but it turned out to be the code name for a joint program with the FBI for using FISA warrants to request data from those companies.


I used to work in engineering at one of the big wireless telecoms. The impression that I got was that many of the outsourced services were compromised. For instance, we had zero control over our voice mail systems, they were outsourced to Amdocs.

You can see how this benefits the NSA; if the voice mail is outsourced to a foreign company, and the NSA buys intel from that company, it's technically not spying on US citizens, particularly if they're getting metadata.


You don't know that. We do know that the USG covertly intercepted fiber communications.

https://www.washingtonpost.com/news/the-switch/wp/2013/11/04...


The story literally quotes the general of the NSA, saying they go though the FBI to get a FISA court order to compel the company..

Additionally, the story quoted talks about how the UK obtained the data and gave it to the NSA.

Nowhere is the NSA installing covert implants. They just don't do that.

The CIA does that :)


> The story literally quotes the general of the NSA

Ah, so he pinky-promised? Well OK then!


What I meant was that you don’t know it isn’t done.

You are taking the word of a spy? Did he say it wittingly?


Sure! It was the least untruthful thing he could say.



"SSL added and removed here ;-)" doesn't sound like a FISA court order.


The NSA has "attacked" internet infrastructure for many years before it became sort of legal (but probably still unconstitutional).


but the NSA has been performing backdoors on hardware for years

PRISM

https://www.schneier.com/blog/archives/2018/08/backdoors_in_...

> Juniper has confirmed that an initial analysis of malware linked to the National Security Agency appears to affect its firewalls.

https://www.zdnet.com/article/juniper-confirms-leaked-nsa-ex...


China is just as interested in US' communications.

Huawei & ZTE have been alleged with these exact type of attacks, by the US government


> the NSA would make sense as the source of the implant.

That doesn't make sense based on the assumption that US telecom companies already cooperate extensively with US inteligence agencies.


"Extensively" is not 100%


The only US Telecom that did not allow NSA direct access to vacuum up transmissions was Qwest, and their CEO was sent to prison.


..for insider trading. You are implying that he went to prison because of the NSA. He went to prison because he sold $52 million in stock after the intelligence community said they would no longer consider Qwest for classified government contracts because of his refusal to cooperate with the NSA.

He went to prison because he sold stock based on insider information. Regardless of the reasons for his trade, it was still insider information.


Everyone breaks laws all the time. The question is whether the Government decides to focus on your activities in order to identify your crimes.


I find these attempts to distinguish between different state sponsored criminals to be a diversion and subterfuge.

Whether China or the US re-allocates your IP, you can expect a competing product made in China. That you might have a relationship with one of them probably doesn't change anything unless they actually think your firm is the best one for the job of maximizing the results on their tax base.

I mean maybe I'm wrong; would it make any sense that these Republics take private corporate property more seriously other parts of their Constitutions they have violated at least until caught?

The US makes the claim China does not and former president and CIA head George Bush floated corporate espionage as THE plan for handling the absurd costs of "intelligence" criminals after the cold war..

I'm always astounded that working in a competitive market seems to blind people to significant stated facts of the environment their market is operating in.

In nature, it might make sense to just outrun the weakest, after all, a bear has a limited appetite. But superpowers have unlimited apetites and will collapse like the USSR if they should ever expand slower than cancer.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: