Hacker Newsnew | past | comments | ask | show | jobs | submit | strictnein's commentslogin

> "it’s no big secret that the NSA is listening in on the node/isp level"

The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?


see https://en.wikipedia.org/wiki/XKeyscore for the sota from 20 years ago

Yes, I'm well aware of XKeyscore.

If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?

Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it.

Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.


You think the politicians are going to say "The career employees made some convincing arguments about why this is impractical / immoral, guess we'll give up our unregulated power/omniscience"? Or, they will raise the military budgets and continue skipping the audits.

You’re talking about two different things.

One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of.

> how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?

ISP taps globally, undersea cable taps, the list goes on.


Most Tier 1 network owners are U.S. companies or U.S. friendly companies, tapping undersea cables is not necessary in many cases, just ask the owner.

Isn’t their whole thing supposed to be spying on foreigners? They seem to be quite successful. There aren’t that many exchanges [1]. Could probably manage with cash, guns, and some know-how.

[1]: https://en.wikipedia.org/wiki/List_of_Internet_exchange_poin...


If you just look at the largest 4 of those, you'd have 100Tbps of traffic to monitor, with an average throughput of roughly half of that.

That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site.

If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.


That's nothing a rack full of fast switches can't handle. A rack full of fast switches already does handle it - where do you think the original copy came from?

They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.


The NSA couldn't care less about you and your customers, nor do they have any interest whatsoever in the megaton of worthless internet traffic that goes through Cloudflare.

This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta.

https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking...


There's a lot of important data that runs through Cloudflare, so I think it's a bit naive to think that there's nothing interesting for the NSA there.

Of course, but the comment I was replying to stated:

"the NSA learns everything there is to know about you and your customers"

Which implies that they are looking at it all and records it.

The vast, vast majority of Cloudflare's traffic is worthless to an intelligence agency.


They are actively scanning all of it, looking for interesting stuff.

I'm more concerned about crimeflare's own incentive to analyze our traffic that people already willingly let them MITM, and somehow sell it to the highest bidder.

If I was the director of an agency of the size of the NSA and was evaluating the options purely from that perspective, I'd aim at creating a file on every living citizen on earth, including their social network topology and their activities. Basically a Google search engine that includes information not publicly accessible. I'd create much larger files for persons of interest and authorize targeted surveillance of them, of course, but with today's means to collect data a complete world database on every living and many dead persons is well within the technical capabilities. It also makes sense and is rational, if you put aside moral considerations.

That's how I evaluate these things. If it makes sense and can be useful, it's likely going to be done. Notice that there is no law against this in the US if you exclude US citizens. It's perfectly legal and within their mission parameters to do it for non-US citizens. I used to think my judgments were a bit too much on the paranoid side but when Snowden published his leaks it turned out that I was roughly right about every capability the NSA had except for their internal security.


Yeah, I'm sure some system like that exists, although I'd assume that would be more in the CIA's purview. I'd be surprised if they kept a broad swath of data for most people though as the tech companies already do it and it's constantly up to date. If needed, a fed lawyer can work through the FISA court and the tech companies are obliged to provide the records.

According to the information I have, the CIA is unlikely to be involved with SIGINT of that type. It's just not their role. I agree that most of the information the NSA might collect will come from publicly available sources like data brokers, particularly if US citizens are involved. However, what I was talking about concerns real-time capabilities and predictive power, it's very different from targeted surveillance and anything involving courts.

Isnt that basically Palantirs business model?

I always enjoyed Kim Zetter's work. Well written and researched, and she doesn't put herself in the story, unlike some other authors. She highlights the practitioners who are actually the ones doing the work.

You might also enjoy "Command and Control" by Eric Schlosser.

i really enjoyed that one

Hizballah and Hezbollah are different spellings of the same thing, with Hizballah probably being more accurate and the one regularly used by the US government.

Oh...the US government. That clarifies a lot...

It clarifies what, exactly? That there are a myriad of spellings for a group whose name is originally in Arabic and couldn't care at all about how we spell it? I was just correcting the person who thought it was inaccurate to use the spelling "Hizballah".

Are the Dutch more clarifying for you?

https://pt.icct.nl/article/hizballah-africa

Or how about the Brits?

https://search-uk-sanctions-list.service.gov.uk/designations...

A worldview of "America dumb" is a boring way to go through life, especially with topics about which you clearly have a very limited understanding.


> "They claim that anyone who does not align with their policies is a member of this organization"

No one is claiming that Amy Klobuchar or Gavin Newsom is a member of antifa.


You're just not confronting reality, man. The President of the United States personally called for Gavin Newsom to be arrested in June 2025. In September of that year, in response to Newsom's post calling Gestapo chief Stephen Miller a fascist, Miller went on TV to complain that nobody is allowed to call him a fascist and Newsom was encouraging violence by doing so.

that's what a call a straw-man. NSPM-7 exists and is providing funding and direction for LEOs to target ideologically leftist organizations as tame as BLM or 50501 [0]

this, in combination with the rise of Flock, Clearview, Axon, and other mass-surveillance programs is leading us down an incredibly dark and Orwellian state - something that feels almost ludicrous given how anti-Big-Brother your average person is

[0] https://www.aclu.org/news/national-security/how-nspm-7-seeks...


It’s mesmerizing to see how easy it has been to transform the USA into what was decried China to become about 5 years ago.

You see some form of resistance (the guy that was caught with a truck full of cut Flock cameras) but it seems the population is resigned.


They say "every accusation is a confession" yet I'm still continually surprised by accusations that I never thought would turn out to be confessions, turning out to be confessions. Like the Chinese surveillance state.

It seems to be a type of psychological projection - someone harbors an ideal like a surveillance state and assumes everyone else is harboring the same ideal so they accuse them.

I hope the Uyghur genocide accusation doesn't turn out to be a confession.


Well, the Chinese surveillance state in the US took off 25 years ago, give or take a few days.

it's been around for quite a lot longer than that. 1984 was written in 1949 and wasn't strictly inspired by only fascist regimes - there were and still are a lot of similarities (eg ethnosupremaccy, nativism, etc) that have deep roots elsewhere

https://en.wikipedia.org/wiki/Mass_surveillance_in_the_Unite...

>With the end of World War II, Project SHAMROCK was established in 1945. The organization was created to accumulate telegraphic data entering and exiting from the United States.[4][22] Major communication companies such as Western Union, RCA Global and ITT World Communications actively aided the project, allowing American intelligence officials to gain access to international message traffic.[23] Under the project, and many subsequent programs, no precedent had been established for judicial authorization, and no warrants were issued for surveillance activities. The project was terminated in 1975.[4]


What? That's not a "straw-man" in the slightest.

I was responding to the comment that said "Everyone who disagrees with the GOP is labeled antifa" with two of the many prominent Democrat politicians who haven't been. Should I have listed 50 of them or 100?



If this would have included a full RCE chain with Sandbox escape Google would have paid significantly more.

Having just a Sandbox RCE is neat, I've got some on my laptop currently, but it's just a piece of the puzzle.


That sounds like a dumb strategy because if non-evil people sit on individual pieces of the puzzle waiting to solve it in full google loses most of the advantage of having a multi-layer system…

Read the article. It doesn't match the title. OpenAI says it was a boring reason: a routing issue.

What does having a "well trusted TLS cert" enable for them in this case, exactly?

Having a magical cert doesn't mean you can just intercept everything.


On the contrary, it lets you MITM encrypted communications by swapping the website's original certificate for the "well trusted TLS cert"

No, it doesn't. HSTS and other methods prevent this from happening.

HSTS doesn't protect you from this at all. It only requires HTTPS, which a spoofed-but-trusted cert passes just fine.

No mainstream browser (or any browser?) is doing cert pinning.

What "other methods" are there that are deployed and actually in use?


Transparency logs. It's mandatory for a cert to be in CT logs for browsers to trust it. Those are public, if this was happening, someone would have noticed already.

OpenAI and Anthropic have their systems in dozens of data centers, including using compute from the major cloud providers. Are you implying that all of these data centers (and many of their employees) are involved in helping the the US government secretly tap every single AI conversation by routing them through some unknown network/device?

Or did a couple of companies with poor uptime records happen to have overlapping downtime?

Occam's Razor heavily, heavily points us towards the latter.


Normally there are only a handful of employees on the payroll at each major company that exposes the US or US government to risk.

It is not often the Executives or Legal even know, but sometimes they did. AT&T bent over backwards to help.

This is standard behavior by the CIA and NSA, and has been for a long time.

https://www.propublica.org/article/nsa-documents-suggest-clo...

https://www.nytimes.com/2015/08/16/us/politics/att-helped-ns...

https://www.theguardian.com/world/2014/mar/19/us-tech-giants...

https://theintercept.com/2018/06/25/att-internet-nsa-spy-hub...


What makes you think they'd need to touch every datacenter? All of these endpoints use existing providers with decades-long history at this point, and network monitoring is already a proven 'feature' of the agencies they'd need to co-exist with over their lifetimes.

If anything, Occam's Razor would point to a common denominator with all of them, given it wasn't network-wide, as far as i know.


Explain the system in which you could capture all of these chats with no knowledge of anyone in these data centers. How are they routed to this NSA system or through some NSA device when these companies' compute are spread over hundreds of data centers?

> All of these endpoints use existing providers with decades-long history at this point

That is just factually inaccurate. Their data centers aren't old and they lease a lot of compute from companies that didn't exist 5 years ago.


>Explain the system in which you could capture all of these chats with no knowledge of anyone in these data centers.

They all transit the same wires as all other traffic. Copy them at any regional bottleneck. https://en.wikipedia.org/wiki/Room_641A. Additionally, i'd admit that maybe someone(s) at these companies knows. But if we think there isn't any person who would agree to do this then I think we're being naive.

> Their data centers aren't old and they lease a lot of compute...

Again, they transit the same wires as everyone else. Here i'll also add that these companies have been actively courting government relationships (and Anthropic attempting to repair damaged ones), why would they stand on principles here and not any of the other many frontlines they've visibly acquiesced?

I just think it's easier to re-route their traffic than, as you say, touch every single datacenter and its employees in some way.


> They all transit the same wires as all other traffic. Copy them at any regional bottleneck.

Oh, is that all?

> Again, they transit the same wires as everyone else

Which shared wires does Google's traffic go across? Do they share that network with others or do they not function as a Tier 1 network? How about Amazon? And the NSA is doing deep packet inspection of all the traffic going to these places to pull out the data they are interested in? What systems allow them to do this at the scale that would be necessary to accomplish this task? Anthropic, OpenAI, etc have their models hosted and provided by these and other Internet giants. So you now have to be able to somehow also get access to every "regional bottleneck" that those places have. Google has 40+ regions alone, as does Amazon. And each of these regions don't just have a single point of inbound/outbound traffic, so now you're over 200-300 points of interception that you would need just to grab the data you're suggesting they are.

And that's just the start of it. When I use Vertex or the Bedrock, my AI API requests from my instances doesn't leave their networks. So where does that traffic get intercepted?

> I just think it's easier to re-route their traffic than, as you say, touch every single datacenter and its employees in some way.

That would be really, really loud and really obvious. Messing with routes like that is very easily detectable.

Or, maybe, they don't care about this traffic at all and doing all of the huge amount of work necessary to accomplish what you're proposing isn't worth 0.1% of the effort it would require.

If the government needs the chat messages, the companies are already saving them. They can just request them through a variety of legal means. None of this vast conspiracy nonsense is needed. Just a couple lawyers and a willing judge. The NSA stopped their collection of phone metadata because they can just request what they need from the telecoms directly.


Ok, then where's the report? Don't they usually release a retrospective report after outages?

It happened yesterday.

I'd say Occam's Razor leans easily to the former as well, given the history of projects that Snowden revealed and were never shut down, plus all of the cooperation with the federal government that's being touted in recent announcements from both companies.

I don't think you're a sysadmin - because what you're saying really doesn't matter. It can still all fail at a single point.

I'm confused by your statement. Are you suggesting that these companies that have invested tens of billions in their networks and datacenters decided to create a shared single point of failure?

Sharepoint is the cause of the outages?

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: