Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> NSA is good at MITM attacks according to Snowden. Moving outside the USA won't stop them.

If they do MITM attacks, it will probably be on US citizens. Moving Persona out of the US would at least stop the snooping on non-US citizens.



That's only if the traffic does not flow through the US which, given the way our current internet infrastructure is setup, is very possible


If I have my datacenter in Iceland and you connect from France, I really doubt you'er going waste valuable transcontinental bandwidth with high latency and extra hops by routing through NYC first.


If the US decides your France<->Iceland traffic is that valuable, it's a small matter to reach an arrangement with friendly-or-easily-pressured governments, agencies, or companies to have your traffic routed in such a way that the US can see it, whether that's in the US or not, or to just have one of those governments, agencies, or companies to play MITM and pass everything over wholesale.

For that matter, go look up Ivy Bells. Sure, fiber can't be tapped in the same manner, but you can get around that by placing your splice/tap during other outages, especially if you arrange for those too -- "Here's <insert amount> dollars/euros/ducats/doubloons/etc. Drag this across the bottom from point x to point y on your charts on date z, then cut it loose and leave it behind and go on your way."

Now, with a straight face, can you claim that you know, for sure, that your undersea links are pristine and unmolested, either at the end points with the equivalent of the infamous at&t "nsa rooms", or somewhere in the middle? Do you know, for sure, that the people who own the fiber trunks aren't playing ball with the nsa/mi6/dgse/etc?

Unless you own the entire infrastructure, and actively monitor it to be sure of such things, it is best to assume that your communications are vulnerable at some point along the way.


> it is best to assume that your communications are vulnerable at some point along the way.

This claim and the claim of "I'm probably going through the US" are two entirely different claims.

Yes, using encryption helps. Yes, using non-US datacenters help. Security is layers. Its not all hopeless. The US isn't all powerful.


If your communications are vulnerable, and your communications are of interest to governments, then there's very little you can do to avoid it being intercepted.

You may, if you trust your hardware, your encryption software, and your key management, be able to keep that intercepted message from being read for some length of time. That is different than actually intercepting the traffic, which is trivial for the organizations we're talking about, and there is very, very little someone can do to avoid the interception.

Believing that being on a different continent makes you safe is deluding yourself.


You really think the NSA doesn't have overseas datacenters?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: