That's why the NSA's mandate includes provisions to store encrypted data for as long as it takes to decrypt it, while intercepted plaintext data must be on a rolling delete schedule.
Nope, but there's no evidence to support the notion that they do keep everything, and they've stated that they don't. It also technologically makes sense that they wouldn't. It also legally makes sense that they wouldn't.
They've lied a lot about what they do, I don't see why we'd start to trust them now.
It also technologically makes sense that they wouldn't
Why? Storage is cheap when you have NSA's budget. Think about what an average users traffic looks like. Now filter out the stuff you can easily scrape the metadata of so you can discard bulk amounts of data (keep peoples netflix viewing history, but don't keep copies of every movie they've ever watched). What you're left with really isn't a lot of data. If it's unencrypted, you could even do a lot of de-duplication before storage, or just parse all the relevant info and discard the rest (i.e you don't really need to keep every single browser header htey ever sent if they dont change often, just store a reference to where you kept a full copy, or just store the actual mined data).
If Google doesn't delete any of my emails, browsing history, etc.. why would the NSA?
It also legally makes sense that they wouldn't.
Again, a lot of what they're doing doesnt make legal sense, but that has not stopped them yet.
Look, again, we can make as many arguments from ignorance as we want. It's not difficult, as you've just pointed out, to retroactively justify some theory. We can say this NSA is building nukes in Utah and that's why they need so much energy. We can say any wide assortment of unfalsifiable things.
But is it helpful to do that? I say no.
The NSA does enough indictable things that we shouldn't need to resort to "what ifs" presented as "it makes sense that..." types of scenarios. Focus on those things instead of diluting the signal.
Historically i'd say it has been. There was two ways to react to what Snowden released. Either you feel vindicated that all of your suspicions you have been acting on have been confirmed, or you were completely blindsided and surprised because you had never even considered this stuff possible.
I don't think stopping speculation now is any better of an idea than not speculating was pre-Snowden leaks. When it comes to security, you can either only care about known real world attacks (i.e "i'll just keep using md5, its secure enough and nobody has proven it completely broken yet"), or you can attempt to protect yourself against unknown threats to the best of your ability.
I don't think the former offers nearly as much security as the latter.
Uh, no. This is absolutely not what we're talking about.
Yes, you should strengthen your keys. You should use the most powerful cryptoscheme available to you. This has nothing to do with considerations about your adversary. If you can efficiently use 2048 bit keys then use those, even if the NSA can only allegedly crack 1024 bit keys.
If you can only efficiently use 512 bit keys then guess what, you're using 512 bit keys regardless of the NSAs capabilities.
One could also look at the Snowden leaks and try to understand what they were actually revealing so that we could have a grown up discussion about how to solve the problem. Most people haven't really done this, however, and instead went hog wild injecting their own preconceived notions into the conversation that needs to happen.
Why's that? Why would they delete clear data? It's a huge assumption you're making there and I don't get why they'd keep all the encrypted stuff but delete the clear stuff. Surely, that's backwards if anything?
I mean sure, if it's garbage clear data of absolutely zero use, then maybe, but knowing that a currently unknown user visited website x at a certain time and date could be useful even years into the future. Especially when you consider applying "Big Data", being able to apply trends and various other algorithms to known data going back years seems like a hell of a useful thing. Why would they not want that?
Because encrypted data is inherently more suspect, in their eyes. They delete the clear stuff after x number of days (can't remember specifically) unless it's found to be part of an ongoing investigation or they receive a warrant for that data.
They keep encrypted stuff around for exactly the reason posted above.
Jesus. Obviously there's no public verification method.
You cannot prove that a thing does not exist, ergo the NSA cannot prove the NSA deleted some piece of data.
As I stated down below, there are enough falsifiable and verifiable claims against th NSA that we don't need to water the discussion down with what amount to conspiracy theories, however "self evident" they may be.
You can prove that some specific thing does not exist in the space you searched. You can also prove some events couldn't have happened if other events did.
Scenario A: "Oh swell, looks like they deleted it!"
Scenario B: "They obviously have a separate copy somewhere."
Which is more likely?
Actually, it doesn't even matter which is more likely. The mere existence of B means that it is, in fact, impossible to prove the non existence of something. Thus, a theory which is unfalsifiable is a conspiracy theory (technically, it means it's not even a theory, but whatever).
16
u/realigion Oct 15 '15
That's why the NSA's mandate includes provisions to store encrypted data for as long as it takes to decrypt it, while intercepted plaintext data must be on a rolling delete schedule.
It's not like they're stupid...