Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers

You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?

If so, what's your source for that claim?

 help



Heck the NSA backdoored our head of states phones - if “NSA wants my data” is your threat model you are pretty much cooked everywhere. Even if you host on your own server and operate everything yourself it’s no big secret that the NSA is listening in on the node/isp level

"The “threat model” section of a security paper resembles the script for a telenovela that was written by a paranoid schizophrenic: there are elaborate narratives and grand conspiracy theories, and there are heroes and villains with fantastic (yet oddly constrained) powers that necessitate a grinding battle of emotional and technical attrition. In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from [email protected]. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them." -- James Mickens

Man, can I get that as a telenovela? I want to hear my mother in law explain the plot.

I remember my mom watching novelas in the 2000s they were something else, nowadays they're all over the place.


Yeah but like, they still have to do that, we don't put our own uranium lumps in our cellphones like we do with cloudflare.

l2paragraph, aint nobody reading dat

> "it’s no big secret that the NSA is listening in on the node/isp level"

The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?


Isn’t their whole thing supposed to be spying on foreigners? They seem to be quite successful. There aren’t that many exchanges [1]. Could probably manage with cash, guns, and some know-how.

[1]: https://en.wikipedia.org/wiki/List_of_Internet_exchange_poin...


If you just look at the largest 4 of those, you'd have 100Tbps of traffic to monitor, with an average throughput of roughly half of that.

That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site.

If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.


That's nothing a rack full of fast switches can't handle. A rack full of fast switches already does handle it - where do you think the original copy came from?

They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.


Switches handle data at far faster rate than any hardware can actually inspect it, store it, process it, etc.

But yeah, just a rack of "fast switches" is all it takes to route hundreds of petabytes of data each day. You should let the data center operators know. They'd save billions.


Switches do inspect it. They also have a feature designed for wiretapping, which copies a percentage of traffic to another port. They may have a feature to copy 100% of traffic matching a certain filter. Managed switch ASICs have this feature even though it's usually not exposed in the CLI.

see https://en.wikipedia.org/wiki/XKeyscore for the sota from 20 years ago

Yes, I'm well aware of XKeyscore.

If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?

Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it.

Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.


You’re talking about two different things.

One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of.

> how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?

ISP taps globally, undersea cable taps, the list goes on.


Most Tier 1 network owners are U.S. companies or U.S. friendly companies, tapping undersea cables is not necessary in many cases, just ask the owner.

You think the politicians are going to say "The career employees made some convincing arguments about why this is impractical / immoral, guess we'll give up our unregulated power/omniscience"? Or, they will raise the military budgets and continue skipping the audits.

You may as well make them work hard to get it. The NSA can only get metadata from your ISP.

This is a joke. If it's electronic the NSA can hack it with impunity, including your ISP. And that's assuming your ISP won't just give them whatever they ask for (unlikely).

There is nothing magical about these NSA hacks:

NSA putting implants into Cisco equipment before delivery to the customer.

https://www.certificationkits.com/nsa-upgrade-process-cisco-...

ANT catalogue from 2008 with hacking equipment:

https://dcssproject.net/ant-catalogue/index.html


I did once theorise that Cloudflare would be a fantastic NSA front.

That's why it is one.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: