If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it.
Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
You think the politicians are going to say "The career employees made some convincing arguments about why this is impractical / immoral, guess we'll give up our unregulated power/omniscience"? Or, they will raise the military budgets and continue skipping the audits.
One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of.
> how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
ISP taps globally, undersea cable taps, the list goes on.
Isn’t their whole thing supposed to be spying on foreigners? They seem to be quite successful. There aren’t that many exchanges [1]. Could probably manage with cash, guns, and some know-how.
If you just look at the largest 4 of those, you'd have 100Tbps of traffic to monitor, with an average throughput of roughly half of that.
That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site.
If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.
That's nothing a rack full of fast switches can't handle. A rack full of fast switches already does handle it - where do you think the original copy came from?
They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.
The NSA couldn't care less about you and your customers, nor do they have any interest whatsoever in the megaton of worthless internet traffic that goes through Cloudflare.
This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta.
I'm more concerned about crimeflare's own incentive to analyze our traffic that people already willingly let them MITM, and somehow sell it to the highest bidder.
If I was the director of an agency of the size of the NSA and was evaluating the options purely from that perspective, I'd aim at creating a file on every living citizen on earth, including their social network topology and their activities. Basically a Google search engine that includes information not publicly accessible. I'd create much larger files for persons of interest and authorize targeted surveillance of them, of course, but with today's means to collect data a complete world database on every living and many dead persons is well within the technical capabilities. It also makes sense and is rational, if you put aside moral considerations.
That's how I evaluate these things. If it makes sense and can be useful, it's likely going to be done. Notice that there is no law against this in the US if you exclude US citizens. It's perfectly legal and within their mission parameters to do it for non-US citizens. I used to think my judgments were a bit too much on the paranoid side but when Snowden published his leaks it turned out that I was roughly right about every capability the NSA had except for their internal security.
Yeah, I'm sure some system like that exists, although I'd assume that would be more in the CIA's purview. I'd be surprised if they kept a broad swath of data for most people though as the tech companies already do it and it's constantly up to date. If needed, a fed lawyer can work through the FISA court and the tech companies are obliged to provide the records.
According to the information I have, the CIA is unlikely to be involved with SIGINT of that type. It's just not their role. I agree that most of the information the NSA might collect will come from publicly available sources like data brokers, particularly if US citizens are involved. However, what I was talking about concerns real-time capabilities and predictive power, it's very different from targeted surveillance and anything involving courts.
I always enjoyed Kim Zetter's work. Well written and researched, and she doesn't put herself in the story, unlike some other authors. She highlights the practitioners who are actually the ones doing the work.
Hizballah and Hezbollah are different spellings of the same thing, with Hizballah probably being more accurate and the one regularly used by the US government.
It clarifies what, exactly? That there are a myriad of spellings for a group whose name is originally in Arabic and couldn't care at all about how we spell it? I was just correcting the person who thought it was inaccurate to use the spelling "Hizballah".
You're just not confronting reality, man. The President of the United States personally called for Gavin Newsom to be arrested in June 2025. In September of that year, in response to Newsom's post calling Gestapo chief Stephen Miller a fascist, Miller went on TV to complain that nobody is allowed to call him a fascist and Newsom was encouraging violence by doing so.
that's what a call a straw-man. NSPM-7 exists and is providing funding and direction for LEOs to target ideologically leftist organizations as tame as BLM or 50501 [0]
this, in combination with the rise of Flock, Clearview, Axon, and other mass-surveillance programs is leading us down an incredibly dark and Orwellian state - something that feels almost ludicrous given how anti-Big-Brother your average person is
They say "every accusation is a confession" yet I'm still continually surprised by accusations that I never thought would turn out to be confessions, turning out to be confessions. Like the Chinese surveillance state.
It seems to be a type of psychological projection - someone harbors an ideal like a surveillance state and assumes everyone else is harboring the same ideal so they accuse them.
I hope the Uyghur genocide accusation doesn't turn out to be a confession.
it's been around for quite a lot longer than that. 1984 was written in 1949 and wasn't strictly inspired by only fascist regimes - there were and still are a lot of similarities (eg ethnosupremaccy, nativism, etc) that have deep roots elsewhere
>With the end of World War II, Project SHAMROCK was established in 1945. The organization was created to accumulate telegraphic data entering and exiting from the United States.[4][22] Major communication companies such as Western Union, RCA Global and ITT World Communications actively aided the project, allowing American intelligence officials to gain access to international message traffic.[23] Under the project, and many subsequent programs, no precedent had been established for judicial authorization, and no warrants were issued for surveillance activities. The project was terminated in 1975.[4]
I was responding to the comment that said "Everyone who disagrees with the GOP is labeled antifa" with two of the many prominent Democrat politicians who haven't been. Should I have listed 50 of them or 100?
That sounds like a dumb strategy because if non-evil people sit on individual pieces of the puzzle waiting to solve it in full google loses most of the advantage of having a multi-layer system…
Transparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.
OpenAI and Anthropic have their systems in dozens of data centers, including using compute from the major cloud providers. Are you implying that all of these data centers (and many of their employees) are involved in helping the the US government secretly tap every single AI conversation by routing them through some unknown network/device?
Or did a couple of companies with poor uptime records happen to have overlapping downtime?
Occam's Razor heavily, heavily points us towards the latter.
What makes you think they'd need to touch every datacenter? All of these endpoints use existing providers with decades-long history at this point, and network monitoring is already a proven 'feature' of the agencies they'd need to co-exist with over their lifetimes.
If anything, Occam's Razor would point to a common denominator with all of them, given it wasn't network-wide, as far as i know.
Explain the system in which you could capture all of these chats with no knowledge of anyone in these data centers. How are they routed to this NSA system or through some NSA device when these companies' compute are spread over hundreds of data centers?
> All of these endpoints use existing providers with decades-long history at this point
That is just factually inaccurate. Their data centers aren't old and they lease a lot of compute from companies that didn't exist 5 years ago.
>Explain the system in which you could capture all of these chats with no knowledge of anyone in these data centers.
They all transit the same wires as all other traffic. Copy them at any regional bottleneck. https://en.wikipedia.org/wiki/Room_641A. Additionally, i'd admit that maybe someone(s) at these companies knows. But if we think there isn't any person who would agree to do this then I think we're being naive.
> Their data centers aren't old and they lease a lot of compute...
Again, they transit the same wires as everyone else. Here i'll also add that these companies have been actively courting government relationships (and Anthropic attempting to repair damaged ones), why would they stand on principles here and not any of the other many frontlines they've visibly acquiesced?
I just think it's easier to re-route their traffic than, as you say, touch every single datacenter and its employees in some way.
> They all transit the same wires as all other traffic. Copy them at any regional bottleneck.
Oh, is that all?
> Again, they transit the same wires as everyone else
Which shared wires does Google's traffic go across? Do they share that network with others or do they not function as a Tier 1 network? How about Amazon? And the NSA is doing deep packet inspection of all the traffic going to these places to pull out the data they are interested in? What systems allow them to do this at the scale that would be necessary to accomplish this task? Anthropic, OpenAI, etc have their models hosted and provided by these and other Internet giants. So you now have to be able to somehow also get access to every "regional bottleneck" that those places have. Google has 40+ regions alone, as does Amazon. And each of these regions don't just have a single point of inbound/outbound traffic, so now you're over 200-300 points of interception that you would need just to grab the data you're suggesting they are.
And that's just the start of it. When I use Vertex or the Bedrock, my AI API requests from my instances doesn't leave their networks. So where does that traffic get intercepted?
> I just think it's easier to re-route their traffic than, as you say, touch every single datacenter and its employees in some way.
That would be really, really loud and really obvious. Messing with routes like that is very easily detectable.
Or, maybe, they don't care about this traffic at all and doing all of the huge amount of work necessary to accomplish what you're proposing isn't worth 0.1% of the effort it would require.
If the government needs the chat messages, the companies are already saving them. They can just request them through a variety of legal means. None of this vast conspiracy nonsense is needed. Just a couple lawyers and a willing judge. The NSA stopped their collection of phone metadata because they can just request what they need from the telecoms directly.
I'd say Occam's Razor leans easily to the former as well, given the history of projects that Snowden revealed and were never shut down, plus all of the cooperation with the federal government that's being touted in recent announcements from both companies.
I'm confused by your statement. Are you suggesting that these companies that have invested tens of billions in their networks and datacenters decided to create a shared single point of failure?
The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?
reply