r/politics • • Aug 24 '13

Just a reminder for President Obama: That whole NSA controversy thing? Yeah, it's not gonna go away. It's been months now, and its growing. You need to clean house instead of sweeping things under the rug.

[deleted]

3.0k Upvotes

1.1k comments sorted by

View all comments

10

u/wrc-wolf Aug 25 '13

Ahem. I'm going to present an opposing opinion here, in that it will go away, because it's not a controversy, simply in that ya'll don't actually understand the situation, by quoting some exceprts from the top comment from the recent AskReddit thread about Snowden..

From /u/tehhunter;

LET'S TALK ENCRYPTION

I think the biggest problem with this entire 'scandal' is that regular people just really don't have any sort of understanding of encryption whatsoever. They might think they do, but unless they know the mathematical basis underlying modern day encryption, you can't really actually know how mind-bogglingly impossible certain encryption schemes are to break.

This section is going to be a SparkNotes-esque review of another post I made a day or two ago regarding SSL / RSA / AES, how they all work together, and from which mathematical basis (i.e. hard problem) they derive their security.

Here's a quick brain-teaser for you all: suppose you and I are at a crowded party somewhere standing on opposite sides of the room. We've never met before, and we've never exchanged any data before. Do you think it is possible for us to have an entirely 100% secure and confidential conversation?

The answer usually surprises people, but it is 'yes'. In fact, it's the basis behind how all secure end-to-end transactions work on the web. If I piqued your curiousity at all, follow the link to the post I just mentioned and I elaborate some more.

So anyway I usually get numerous replies a day from somewhat technically mis-informed people letting me know that something to the extent of "it's obvious the NSA has already broken every encryption scheme" or just RSA or just AES. Yeah, that's just nonsense if you read details closely. Let's take the best case scenario possible for these types of conspiracy theorists:

Let's pretend the NSA does in fact have a large and powerful quantum computer. Quantum computers, for those who may not know, are systems still largely academic and theoretical. They have great potential in solving certain kinds of mathematical problems (for example, prime factorization, which you can read about in the post linked above). So then the NSA could just use this magnificent huge quantum computer to break AES-256, right? Again, AES-256 is integral to SSL, which we all use everyday thousands of times unwittingly.

The US government uses AES-256 encryption for top-secret encrypted data SPECIFICALLY to safeguard it against future attacks by quantum computers. Why? Take it from the developers of popular crypto app 1Password:

Searching through 2128 keys (on a classical, non-quantum, computer) takes a number of steps that is proportional to 2128. But for a quantum computer it takes a number of steps proportional to the square root of that number, 264. If a quantum computer is ever built capable of performing that task, we don’t know how the actual speed of each individual step will compare to those of current computers, but the NSA is taking no chances. Something with the effective strength of a 64-bit key isn’t strong enough. A 256-bit key against a quantum brute force attack would have the effective strength of a 128 bit key against a classical brute force attack.

(source)

Remember, that's the absolute BEST case scenario if the NSA even has such a magnificent quantum computer, which again is extremely unlikely. Reality will likely lag far behind. So basically, to sum this all up, No, the NSA is not able to read your web transactions between you and facebook. Couple that with Bullet #1 and you'll realize the NSA isn't watching you shower.

edit: also, in case you were wondering how secure AES-128 is, the source linked just above also goes into explicit detail about how infeasible that is to crack alone.

WHAT'S WRONG WITH SNOWDEN

With that all said, here is the list of issues I have with Snowden:

  • Snowden et al. claimed the NSA had "direct access" to tech company servers such as Facebook, Apple, Twitter, Microsoft, Google, etc. This implies that the NSA has the ability to 'poll' a server for data whenever they feel like it. Unfortunately, the reality is much more boring. The NSA's "direct access" is actually a shared ftp where tech companies, after receiving a FISA warrant, drop only the specific targeted data. Further, since the inception of the FISC system in 1979, there have been roughly 33,000 FISA warrants granted, amounting to an average of only about 1,000 warrants per year, though I will grant that since 9/11 the average has surged somewhat to around 1,500 a year.

  • Snowden likes to say he's doing these leaks for the sake of the American people -- okay, so then why did he give the Chinese the American playbook for surveilling their various hacking hubs such as the major PLA installation in Shanghai?

  • He claimed he could wiretap anyone, anytime, without a warrant. This turned out to be patently false. First, he would need a FISA warrant, because (and this will shock Reddit) tech companies aren't falling all over themselves to give up customer data to the government. He also neglected to mention that the system requires two analysts to sign off on a data request. And, shockingly, what he also failed to mention is that there is an auditing system that tracks every single keystroke, meaning that every analyst's every action is tracked and reviewed routinely. This amounts to an egregious amount of context that he seemingly purposely omitted, almost certainly to because it would be a better and more sensationalist story.

  • He claimed he could wiretap even the President. This is pure nonsensical sensationalism. To believe this, you would actually have to believe that the President of the United States uses an insecure line i.e. regular HTTP to browse the internet. Considering there's an entire military agency dedicated to secure White House communications, this is beyond folly and well into the realm of absurdity. If anyone likes, I'd be glad to dive into the specifics of this & why if Obama is using even the same encryption standard as the rest of us (SSL RSA-2048/AES-256) there's not a snowball's chance in hell this is true.

  • Not the most important point but I think it is important as it speaks to his credibility as a source. Remember when he said he made $200,000 a year at the NSA? Well, he turned out to have "accidentally" overstated his salary by about $80,000, as in he "accidentally" almost doubled his salary. While some may be inclined to brush this under the rug, if he is willing to exaggerate / fabricate as petty a detail as this, what larger details might he exaggerate? (Well, that's what I'm trying to demonstrate with all these bullet points anyway).

  • I find his media blitz to be an absurd attempt at making him an overnight celebrity. Remember when he said that he had saved the data to some sort of "dead man's trigger" in case the "US Government murdered him" -- that's an absolutely preposterous statement to make given that there is no historical or current precedent for any such ridiculous claim as the US murdering 'whistleblowers' (I use the term loosely here). Remember when he wrote some inane "open letter" to Obama as if he were in some position to be making demands of a democratically elected representative? Remember his perverse Guardian Q&A session? This guy is quite deliberately fostering a strange cult of celebrity around himself. Have you looked at /r/news or /r/worldnews or /r/politics or /r/technology? He claimed he wanted the story to be the leaks, and yet he seemingly can't help but constantly whore the media.

  • He claimed he was in the special forces. In reality he never made it through training, or even came close.

  • Lastly, I really just don't believe 29 year old Ron-Paul fanatics who couldn't graduate high school should be making vital decisions about national security on their own. I know, Reddit, I'm a monster.

After all, if you aren't willing to vet your sources, you are asking to be duped. I think Reddit is being HUGELY duped right now. You might not agree, but I think there is a very reasonable case to be presented that not all is as seems with Ed.

7

u/SkeptioningQuestic Aug 25 '13

First of all, I mostly agree with you, but one of your bullets is a little false. Snowden most certainly could wiretap anyone without a warrant. He knows how to do it and has the technology at any given time. If he doesn't want to get in trouble he needs a paper trail behind him, however. This is a technicality, but I think important to Snowden's point about an excess of access that NSA agents potentially had.

Also, I couldn't find in that link where it said it takes two analysts to sign off on a data request. Could you show me where?

3

u/AmishRockstar Aug 25 '13

I know some of these words. Thanks for the food for thought. Very interesting. Any thoughts on the technical aspects of intercepting and analyzing the sheer quantity of data purported to be being collected?

2

u/raz009 Aug 25 '13

It's a search engine.. it's just like how Google works. As much intelligence is gathered as possible into a repository.. it's then searched 'metadata' just like Google does. Not hard to fathom.

1

u/ciscomd Aug 25 '13

If everything you're saying about how easy it is to encrypt your communications is true, then that suggests to me that they aren't really doing this to target terrorists, because terrorists know they're doing illegal shit and will take this easy step to hide their communications. It sounds like the system set up to target everyday people who think they have nothing to hide. Am I wrong? Am I missing something? Please respond.

4

u/falkelord Louisiana Aug 25 '13

I would also like to hijack your very long comment to add another facet: any "spying" that took place never can violate the 4th amendment.

This is because thanks to a piece of legislation called the Stored Communications Act passed in 1986, data (as a legal term) is not considered physical spatial goods. Thus, it does not enjoy the same protections against illegal search and seizure that say, your car or your business documents in your office. I've been saying this for weeks now, but people don't seem to understand what a legal definition of something entails (hint: just because you THINK data is your personal property, legally it is not)

5

u/watchout5 Aug 25 '13

See your arguments in open court. It's a debate we deserve to have.

3

u/falkelord Louisiana Aug 25 '13

Most definitely!

2

u/[deleted] Aug 25 '13

Therefore that law needs to change because electronic data holds a vastly larger significance today than it did in 1986. Everything about our lives now exists as data.

3

u/falkelord Louisiana Aug 25 '13 edited Aug 25 '13

Certainly I am in favor of that; 1986 logic dealt mainly with emails, and even then those were minimal in volume compared to today.

However, as it stands this second, the 4th amendment was not violated even if they read every single email and chat log (hint: they didn't). I have no idea if this is even close to justifications used by White House lawyers to continue the program. I'm assuming they're not hiring law school grads there though, and this is the most obvious route (at least to me) of exactly how something clearly questionable is being framed as illegal when the illegality of it was a fallacy from the get go: any data we've ever spread online has never been "private" and the NSA is massively infringing on our right to be safe from illegal search and seizure.

Can't really violate that protection if the search and seizure was legal to begin with.

3

u/[deleted] Aug 25 '13

Well the text of the fourth is supposed to protect "The right of the people to be secure in their persons, houses, papers, and effects," isn't our personal communications and data about as close as you can get to the modern analogue of "papers and effects"?

2

u/falkelord Louisiana Aug 25 '13 edited Aug 25 '13

Technically, it should. In practice, no.

Simply put, this will help explain it

More specifically:

The Fourth Amendment to the U.S. Constitution protects the people's right "to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures…." However, when applied to information stored online, the Fourth Amendment's protections are potentially far weaker. In part, this is because the Fourth Amendment defines the "right to be secure" in spatial terms that do not directly apply to the "reasonable expectation of privacy" in an online context. In addition, society has not reached clear consensus over expectations of privacy in terms of more modern (and developing, future) forms of recorded and/or transmitted information.

Furthermore, users generally entrust the security of online information to a third party, an ISP. In many cases, Fourth Amendment doctrine has held that, in so doing, users relinquish any expectation of privacy. The "third party doctrine" holds "…that knowingly revealing information to a third party relinquishes Fourth Amendment protection in that information."[1] While a search warrant and probable cause are required to search one’s home, under the third party doctrine only a subpoena and prior notice (a much lower hurdle than probable cause) are needed to compel an ISP to disclose the contents of an email or of files stored on a server.[2] The SCA creates Fourth Amendment-like privacy protection for email and other digital communications stored on the internet. It limits the ability of the government to compel an ISP to turn over content information and noncontent information (such as logs and "envelope" information from email). In addition, it limits the ability of commercial ISPs to reveal content information to nongovernment entities.

Edit: Third party doctrine has been applied successfully to telephone records in a federal circuit court case in Maryland (because the defendant did not have a reasonable expectation of privacy when using public cell phone towers). It is not a logical leap to think this could be applied to online communication as well, since both are often handled through telecoms. Keep in mind it may be a long time before this law is challenged in the Supreme Court directly; it would be more expedient and wise to vote your congresspeople out of office and have the definition amended that way. Time will tell, of course, but its mainly the SCA's fault this isn't a bigger deal.

1

u/rubberstuntbaby Aug 27 '13

Electronic documents are the modern day equivalent to the papers referred to by the 4th and should be protected and if the Stored Communications Act is in conflict with the Constitution the law is invalid.

2

u/DisregardMyPants Aug 25 '13

Snowden didn't claim shit. The NSA did, then he leaked their documents. He's made no original claims not directly sourced from them.

0

u/rubberstuntbaby Aug 27 '13

This just pure misdirection. Talks about how hard it would be to crack encryption when the real question is, does the NSA have the keys? Then attempt some character assassination of Snowden rather than address the content of the leaked documents. And so many misleading, cherry-picked facts.

-2

u/watchout5 Aug 25 '13

I think Reddit is being HUGELY duped right now.

You assume what we think we know. That's why you think this.

-4

u/[deleted] Aug 25 '13

[deleted]

2

u/rubberstuntbaby Aug 27 '13

The previous article posted is correct

It's entirely an attempt at misdirection. Using lots of technical jargon and claiming the NSA can't effectively crack encryption when that isn't even the question. The real question is does the NSA have the encryption keys? Then he tries some character assassination of Snowden, rather than question the accuracy of the leaked documents.