Risk
7/31/2013
06:47 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

NSA Surveillance Can Penetrate VPNs

National Security Agency's XKeyscore system can collect just about everything that happens online, even things encrypted by VPNs, according to Edward Snowden.

The National Security Agency has a system that allows it to collect pretty much everything a user does on the Internet, according to a report published by The Guardian on Wednesday, apparently even when those activities are done under the presumed protection of a virtual private network (VPN).

The Guardian's information comes from whistleblower Edward Snowden, the former NSA contractor now seeking asylum in Russia from U.S. authorities for revealing classified documents about the NSA's intelligence-gathering capabilities to the media. The news organization's report suggests that Snowden's claim that he could wiretap anyone from his desk, dismissed by U.S. lawmakers as false, was essentially accurate.

Described in a 2008 presentation, the system, called XKeyscore, can reportedly track email addresses, logins, phone numbers, IP addresses and online activities — files, email contents, Facebook chats, for example — and can cross-reference this information with other metadata.

Even after weeks of revelations about the scope and breadth of NSA data gathering, news that XKeyscore can penetrate VPNs comes as a something of a shock.

"This is huge: XKeyscore slides also suggest NSA regularly decrypts encrypted VPN traffic," said security researcher Ashkan Soltani via Twitter.

[ Want to be a Web photographer? Read Google's Photo Sphere Community Wants You. ]

Responding to Soltani, CDT senior staff technologist Joseph Lorenzo Hall expressed skepticism that the NSA can break all VPN encryption. But Soltani contends the NSA at least has the capability to crack weak cipher implementations on Windows machines common in the Middle East, such as PPTP and MS-Chap. He points to a 2012 post from security researcher Moxie Marlinspike that states, "PPTP traffic should be considered unencrypted."

Whether or not the NSA is able to crack more robust implementations remains to be seen. Given the resources available to the NSA, the issue may be how much the NSA wants to break a given code rather than its ability to do so. After all, in cases where codes cannot be broken, people can be. As Danish developer Poul-Henning Kamp argues in ACM Queue, politics trumps cryptography.

The White House, trying to contain discontent with its surveillance programs, chose Wednesday to release formerly classified documents about the NSA's domestic phone surveillance program as a Senate Judiciary Committee meeting convened to address the oversight of Foreign Intelligence Surveillance Act programs.

The documents, published by the Office of the Director of National Intelligence, detail the collection of telephone metadata under Section 215 of the Patriot Act.

Senate Judiciary Committee chair Sen. Patrick J. Leahy (D-Vt.) said in a statement that if the government's collection of phone records is not effective, the program should be discontinued. He suggested that NSA chief Gen. Keith Alexander's prior claim that Section 215 surveillance programs have led to the disruption of 54 terrorist plots is not supported by the classified documentation he was provided.

A 2008 presentation states, "Over 300 terrorists [have been] captured using intelligence generated from XKeyscore."

Gen. Alexander contended with skeptical hecklers Wednesday at the Black Hat USA 2013 security conference in Las Vegas, where he defended NSA surveillance as necessary for national security.

In prepared remarks presented during the Judiciary Committee meeting, Stewart A. Baker, a partner in the Washington office of Steptoe & Johnson, LLP, and former assistant secretary for policy at the Department of Homeland Security, dismissed worries about civil liberties concerns.

"[I]t appears that law enforcement has been gaining access to our call metadata for as long as billing records have existed — nearly a century," he said. "If this were the road to Orwell's 1984, surely we'd be there by now, and without any help from NSA's 300 searches."

Baker advocates protecting privacy by, paradoxically, embracing big data and subjecting government employees to more effective surveillance.

"We need systems that audit for data misuse, that flag questionable searches, and that require employees to explain why they are seeking unusual data access," he said. "That's far more likely to provide effective protection against misuse of private data than trying to keep cheap data out of government hands. ... A proper system for auditing access to restricted data would not just improve privacy enforcement, it likely would have flagged both Bradley Manning and Edward Snowden for their unusual network browsing habits."

Jameel Jaffer, deputy legal director of the American Civil Liberties Union Foundation, offered testimony in the opposite direction. He called for Congress to amend the Foreign Intelligence Surveillance Act "to prohibit suspicionless, 'dragnet' monitoring or tracking of Americans' communications," to require more disclosure about Foreign Intelligence Surveillance Court opinions, and to ensure that government surveillance activities are subject to reasonable judicial scrutiny.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
AmmarNaeem
50%
50%
AmmarNaeem,
User Rank: Apprentice
2/12/2014 | 6:30:26 AM
re: NSA Surveillance Can Penetrate VPNs
To judge any intelligence organisation by the national law is pretty tricky. An intelligence organisation always will go against it political masters. So when you come up against the so called crimes of any intelligence organisation go to the top, it does not matter in what state you are if it is Israel, Russia or China.

The only point here is that BO should have put more support against the NSA as he has directed them. If you want to reform any of this you should look at the legislative and that is where in the USA I see little coherence. Even Snowden does not blame the NSA as an organisation, but many pro-Snowden activist do not get that either.

But how can we cover ourselve from recent NSA activation to distroy privacy laws? I setup VPN to some what and some how secure my online privacy as it provides encryption and changes my ip to cover my online identity and provide me online anonymity and freedom.

Though theer are many top VPN services but i recommend you to check out this a comprehensive list of best encrypted vpn services that also do not keep logs and provide advacnced protocol to ensure your online privacy 
mykiralspirelli
50%
50%
mykiralspirelli,
User Rank: Apprentice
8/1/2013 | 6:56:47 PM
re: NSA Surveillance Can Penetrate VPNs
Does this really come as a shock to most people??

Its obvious that anything you do on pretty much any form of technology is traceable and leaves a digital paper trail.
With that said do you really think the government has the resources to listen/read everyone's facebook chats or emails?

I feel sorry for whoever reads my chats LOL...Perhaps i should be more dramatic in my text to put on a show and give that poor government employee more excitement.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3587
Published: 2014-08-22
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists bec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.