6 ms·
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers You're replying to a comment talking about migrat
by esperent 9d ago
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers
You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?
If so, what's your source for that claim?
- 9864325789976 9d ago[dead]
- icantevenhold 9d agoHeck the NSA backdoored our head of states phones - if “NSA wants my data” is your threat model you are pretty much cooked everywhere. Even if you host on your own server and operate everything yourself it’s no big secret that the NSA is listening in on the node/isp level
- strictnein 9d ago> "it’s no big secret that the NSA is listening in on the node/isp level" The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?
- milkshakes 9d agosee https://en.wikipedia.org/wiki/XKeyscore https://en.wikipedia.org/wiki/XKeyscore for the sota from 20 years ago
- strictnein 8d agoYes, I'm well aware of XKeyscore. If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed? Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it. Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
- DANmode 8d agoYou’re talking about two different things. One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of. > how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed? ISP taps globally, undersea cable taps, the list goes on.
- leonidasrup 8d agoMost Tier 1 network owners are U.S. companies or U.S. friendly companies, tapping undersea cables is not necessary in many cases, just ask the owner.
- axus 8d agoYou think the politicians are going to say "The career employees made some convincing arguments about why this is impractical / immoral, guess we'll give up our unregulated power/omniscience"? Or, they will raise the military budgets and continue skipping the audits.
- junofan 8d agoIsn’t their whole thing supposed to be spying on foreigners? They seem to be quite successful. There aren’t that many exchanges [1]. Could probably manage with cash, guns, and some know-how. [1]: https://en.wikipedia.org/wiki/List_of_Internet_exchange_points_by_size https://en.wikipedia.org/wiki/List_of_Internet_exchange_poin...
- strictnein 8d agoIf you just look at the largest 4 of those, you'd have 100Tbps of traffic to monitor, with an average throughput of roughly half of that. That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site. If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.
- mitxela 8d agoThat's nothing a rack full of fast switches can't handle. A rack full of fast switches already does handle it - where do you think the original copy came from? They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.
- strictnein 7d agoSwitches handle data at far faster rate than any hardware can actually inspect it, store it, process it, etc. But yeah, just a rack of "fast switches" is all it takes to route hundreds of petabytes of data each day. You should let the data center operators know. They'd save billions.
- mitxela 7d agoSwitches do inspect it. They also have a feature designed for wiretapping, which copies a percentage of traffic to another port. They may have a feature to copy 100% of traffic matching a certain filter. Managed switch ASICs have this feature even though it's usually not exposed in the CLI.
- TallGuyShort 8d ago"The “threat model” section of a security paper resembles the script for a telenovela that was written by a paranoid schizophrenic: there are elaborate narratives and grand conspiracy theories, and there are heroes and villains with fantastic (yet oddly constrained) powers that necessitate a grinding battle of emotional and technical attrition. In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them." -- James Mickens
- mitxela 8d agoYeah but like, they still have to do that, we don't put our own uranium lumps in our cellphones like we do with cloudflare.
- giancarlostoro 8d agoMan, can I get that as a telenovela? I want to hear my mother in law explain the plot. I remember my mom watching novelas in the 2000s they were something else, nowadays they're all over the place.
- fr2029 8d agol2paragraph, aint nobody reading dat
- mitxela 8d agoYou may as well make them work hard to get it. The NSA can only get metadata from your ISP.
- ARandomerDude 8d agoThis is a joke. If it's electronic the NSA can hack it with impunity, including your ISP. And that's assuming your ISP won't just give them whatever they ask for (unlikely).
- whh 8d agoI did once theorise that Cloudflare would be a fantastic NSA front.
- mitxela 8d agoThat's why it is one.
- leonidasrup 8d agoThere is nothing magical about these NSA hacks: NSA putting implants into Cisco equipment before delivery to the customer. https://www.certificationkits.com/nsa-upgrade-process-cisco-equipment-pictures/ https://www.certificationkits.com/nsa-upgrade-process-cisco-... ANT catalogue from 2008 with hacking equipment: https://dcssproject.net/ant-catalogue/index.html https://dcssproject.net/ant-catalogue/index.html