NSA Encryption Bypass

Comments debate the NSA's ability to intercept, decrypt, or circumvent SSL/HTTPS encryption on traffic from companies like Google and Facebook, including methods like cable tapping, key theft, and man-in-the-middle attacks, often referencing Snowden leaks.

➡️ Stable 0.7x Security
2,654
Comments
20
Years Active
5
Top Authors
#9678
Topic ID

Activity Over Time

2007
1
2008
2
2009
6
2010
30
2011
42
2012
63
2013
824
2014
223
2015
216
2016
177
2017
132
2018
95
2019
146
2020
146
2021
112
2022
83
2023
113
2024
103
2025
131
2026
9

Keywords

e.g US CPU MITM E2E CEO LEO DNSSEC arstechnica.com ECDHE nsa ssl traffic encryption decrypt keys data encrypted google mitm

Sample Comments

sillysaurusx • Dec 19, 2019 • View on HN

Most governments don't, but even the NSA taps into unencrypted or weak links along the pipe. https://www.newyorker.com/news/amy-davidson/tech-companies-s..."SSL added and removed here! :)"

zetafunction • Jun 20, 2013 • View on HN

Google is using SSL with ECDHE which provides perfect forward secrecy. Having a copy of the SSL certificate won't do the NSA any good.

voidlogic • Jun 8, 2013 • View on HN

Possibly no direct access because the NSA has copies of Facebook, Google and Apple SSL private keys? Just sniffing the backbone...

PhilipRoman • Apr 27, 2024 • View on HN

They already tap into every cable, no matter whether they own it or not. See NSA breaking into Google datacenters and wiretapping cables. Granted, they were only able to do this because the internal traffic was not encrypted. Still, global traffic analysis is nothing to scoff at, and with enough surveilance points privacy becomes almost nonexistent, even in the presence of encryption.

zby • Jul 3, 2013 • View on HN

The journalist forgets that tapping into the cables only works for unencrypted traffic - this is actually the reason that NSA bothered Google and others in the first place.

dvmmh • Jun 21, 2013 • View on HN

The NSA pulls all data going in and out of Google without their permission. Being the man-in-the-middle, they intercept all communications even if encrypted.

njharman • Jan 23, 2016 • View on HN

Probably because NSa can break most encryption.

JoachimSchipper • Jun 17, 2013 • View on HN

Pretty much nil. The NSA isn't stupid; even in the (exceptionally unlikely) case that they can just MITM any SSL connection without arousing suspicion in even a well-monitored network, why would they reveal that? Much easier to just hack your computer/telephone/...

eliotte • Apr 26, 2023 • View on HN

If it is not E2E encrypted, 3-letter agencies can put their tap somewhere in the Google infrastructure.

Hobotron1 • May 2, 2015 • View on HN

Wouldn't the NSA be able to capture the data on the way out anyways?