Hacker Newsnew | past | comments | ask | show | jobs | submit | mixmastamyk's commentslogin

Yes, I don't feel like the top comments have actually read it. It was a bit too long unfortunately. They seem to be discussing their own ideas on FOSS funding.

He was a sysadmin who built a system that gathered the documents. Why do you think that SQL is not capable of searching email? Also an anonymizing system already existed before 2001. The safeguards were dropped afterwards.

> He was a sysadmin who built a system

can you elaborate on this ? what were his responsibilities and what role did he have in setting up the system?

He seemed to imply that he helped deploy these systems (though he never authored them), but from his interviews & the evidence provided, I don't even think that was the case. I got the impression he was sort of a backup & storage manager.


Sysadmin with root who does some scripting. From memory it was something like a number of cron jobs to download from rss-like feeds to a central location, and maybe index them too. Show results on a web page.

Until that time it was difficult to get updates and folks were out of touch because info was too compartmentalized. Later something made him take a peek above his clearance, as the data was there.

He explained it in detail in the book Permanent Record, which is available at the library and/or ingested into a model by now.


That sounds believable.

What's your overall take? do you think evidence was presented to confirm these systems were active around his tenure e.g. 2012? I'm maybe 20% confident they were active.


https://en.wikipedia.org/wiki/ThinThread

https://en.wikipedia.org/wiki/Trailblazer_Project

https://en.wikipedia.org/wiki/XKeyscore

The first one existed from the 90s. The second was built in response to 9-11, removing privacy protections early 2000s. The third is an interface for searching. As far as I know no one tried to deny XKeyscore exists, then or now.

Snowden built none of these. His document retrieval system allowed him to find out that the programs above were not following the law.


I mean about the historiography, and your personal verdict on whether those systems were active, based on the evidence Snowden provided.

A wiki is a summary, of the available evidence, but from what I've seen, I'm not 100% confident the systems were active and deployed to the claimed maturity level.


I wasn't there and have never had a security clearance. But I doubt Dick Cheney would have been satisfied with a non-functional query system during the war on terror, many years after giving direct orders to build one. Yes, I believe they were active.

I highly recommend the documentary "The United States of Secrets" by PBS Frontline, it digs into this time period and government motivations after 9/11. Usually free on Kanopy.


Star Wars was non functional. It was effective strategically (and led to the USSR's demise, partially) , but totally impotent technically.

It's just as likely that XKeyscore was a strategic public relations effort to intimidate the enemy .


SQL alone is just a query language. the MySQL design docs Snowden shared were primitive installations that did not meet the claimed capability of their surveillance system.

There's this weird dichotomy where people think the folks that work in government are either evil geniuses or drooling cavemen. They are neither. I assure you that the NSA (with unlimited funding) is capable of running a MySQL cluster to index email and keep it up, most of the time anyway.

Also, Snowden didn't build the query system, he just used it. He built a document gathering system, which I described in my other response. These are different services.


I’m talking about the evidence presented and whether it met the extraordinary claims.

The amount of compute and indexing needed was extraordinary, and the evidence presented didn’t meet that bar.

Yes I believe that the NSA, in theory, had the budget to complete this task, and to a lesser degree, the competence. . But I only believe claims with complete evidence.


I don't think the compute/indexing were extraordinary, what may have been was the storage required. There was a large NSA facility built for purpose early in the century, and the cost of storage dropped significantly at the time.

Google had already demonstrated such a system by the late 90s, using off the shelf technology.


that's an interesting perspective thanks for sharing

Did good work, but haven’t had any since the last contract ended two years ago. What would you suggest?

Does your browser have the email password saved?

I don't know, the article mentions having to deal with brine. Let it evaporate in a pool and you've got plenty.

I did, and the original dev of the component fixed it within a few days. It was straightforward, a backwards reading of a spec, reordered.

The fix is still sitting unmerged many months later.

This surprised me since I thought the project was in heavy bugfix/compat mode. I won’t touch it until I see some velocity on open bugs.


Fork Ubuntu and threaten their business model, that’ll get their attention.

Only half joking.


Ubuntu is the fork; just use Debian.

There's very little incentive to switch. When people release for Linux they almost always first/only test it works on Ubuntu - hence it's going to be the least buggy. (ex: GOG only seemingly tested games on Ubuntu)

So the switching cost is buggy software. You'd need something radically different that brings enough new features to the table to make it worth it the switch and dealing with bad/non-existant support.

I think something like Nix/Guix but with stable library versions that matches Ubuntu/Debian LTS ones 1-to-1 could get traction


Embrace the lock-in.

If you still have toes, take some morphine and reload.

Then you would have to embrace their bad decisions, such as this one, and if you do, what’s the point?

Everything just needs to run from a container with their expected runtime environment.


My solution was to stop using Ubuntu and move to Debian.

And in that debian install rust unix coreutils as default

There are plenty of Ubuntu forks?

Fights for the user and against the MCP!

Electronics recycling exists, plus a few dollars for the aluminum case.

In general I agree, but recycling old power hungry gear may be better for the environment in the long term.

So discard a working and perfectly good Macbook to be replaced by a new one manufactured by the World’s #1 CO2 emitter and transported probably halfway around the world in a container ship burning dirty bunker fuel.

Per unit costs are pretty low, and old Intel gear particularly energy guzzling.

Cable ISPs such as Spectrum sell capacity on their customers routers for such situations, including ‘smart’ appliances.

Xfinity (Comcast) does the same, and the LG TV data leak demonstrated it joining these open “xfinitywifi” SSIDs to transmit telemetry home (edit: retracted, see below subthread).

You can see a map of these nodes with https://wigle.net/


Please provide a source for this claim.

While LG TVs send a lot of private data when connected to the internet, I'm not aware of any credible reports that they automatically connect to open or partner-provided wifi networks without a user choosing to do so.

It's certainly a threat to keep an eye open for, but it seems manufacturers haven't quite stooped to that low yet.


I stand corrected and misremembered comment https://news.ycombinator.com/item?id=49604765 and thread https://news.ycombinator.com/item?id=49592375

It has not been demonstrated actively in use, only that it is possible and trivial to implement. Statement with regards to it being demonstrated retracted.

I stand by the concept that any consumer IoT device could join these networks, and the end user would never know. The only legal solution to this problem statement is to physically disable the radio on the device if assurance is desired.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: