NSA Encryption Bypass

Comments debate the NSA's ability to intercept, decrypt, or circumvent SSL/HTTPS encryption on traffic from companies like Google and Facebook, including methods like cable tapping, key theft, and man-in-the-middle attacks, often referencing Snowden leaks.

➡️ Stable 0.7x Security
2,654
Comments
20
Years Active
5
Top Authors
#9678
Topic ID

Activity Over Time

2007
1
2008
2
2009
6
2010
30
2011
42
2012
63
2013
824
2014
223
2015
216
2016
177
2017
132
2018
95
2019
146
2020
146
2021
112
2022
83
2023
113
2024
103
2025
131
2026
9

Keywords

e.g US CPU MITM E2E CEO LEO DNSSEC arstechnica.com ECDHE nsa ssl traffic encryption decrypt keys data encrypted google mitm

Sample Comments

sillysaurusx Dec 19, 2019 View on HN

Most governments don't, but even the NSA taps into unencrypted or weak links along the pipe. https://www.newyorker.com/news/amy-davidson/tech-companies-s..."SSL added and removed here! :)"

zetafunction Jun 20, 2013 View on HN

Google is using SSL with ECDHE which provides perfect forward secrecy. Having a copy of the SSL certificate won't do the NSA any good.

voidlogic Jun 8, 2013 View on HN

Possibly no direct access because the NSA has copies of Facebook, Google and Apple SSL private keys? Just sniffing the backbone...

PhilipRoman Apr 27, 2024 View on HN

They already tap into every cable, no matter whether they own it or not. See NSA breaking into Google datacenters and wiretapping cables. Granted, they were only able to do this because the internal traffic was not encrypted. Still, global traffic analysis is nothing to scoff at, and with enough surveilance points privacy becomes almost nonexistent, even in the presence of encryption.

zby Jul 3, 2013 View on HN

The journalist forgets that tapping into the cables only works for unencrypted traffic - this is actually the reason that NSA bothered Google and others in the first place.

dvmmh Jun 21, 2013 View on HN

The NSA pulls all data going in and out of Google without their permission. Being the man-in-the-middle, they intercept all communications even if encrypted.

njharman Jan 23, 2016 View on HN

Probably because NSa can break most encryption.

JoachimSchipper Jun 17, 2013 View on HN

Pretty much nil. The NSA isn't stupid; even in the (exceptionally unlikely) case that they can just MITM any SSL connection without arousing suspicion in even a well-monitored network, why would they reveal that? Much easier to just hack your computer/telephone/...

eliotte Apr 26, 2023 View on HN

If it is not E2E encrypted, 3-letter agencies can put their tap somewhere in the Google infrastructure.

Hobotron1 May 2, 2015 View on HN

Wouldn't the NSA be able to capture the data on the way out anyways?