HomeinetMikko Hypponen How the NSA betrayed the world's trust, time for...

Mikko Hypponen How the NSA betrayed the world's trust, time for action

Mikko HypponenRecent events have highlighted, underlined and written in bold letters the fact that the United States is secretly monitoring every foreigner whose data passes through an American entity – whether or not there is any suspicion of wrongdoing. This means that, in essence, every international internet user is being monitored, says Mikko Hypponen. A significantly angry speech (in TED Talk), wrapped up with a plea: to find alternatives to using American companies for the world’s information needs.

The translation into Greek was done by Chryssa Rapessi and edited by Dimitra Papageorgiou.

Probably the two greatest inventions of our generation are the internet and the mobile phone. They have changed the world. But, to a large extent, to our surprise, they have also turned out to be the perfect tools for the surveillance state. It turns out that this ability to collect data and connections on any and all of us is exactly what we have been hearing about over the summer through revelations and leaks about Western intelligence agencies, mainly US intelligence agencies, monitoring the rest of the world.

We heard about them starting with the revelations of June 6th. Edward Snowden started leaking information, top secret classified information, from U.S. intelligence agencies, and we started learning about things like PRISM and XKeyscore and so on. And these are examples of the kinds of programs that the United States intelligence agencies are running right now, against the entire rest of the world.

If you look at George Orwell's predictions about surveillance, it turns out that George Orwell was optimistic. (Laughter) We're seeing a much larger scale of surveillance of individual citizens right now than he could have ever imagined.

And this is the infamous National Security Agency (NSA) data center in Utah. It's going to open very soon, and it's going to be both a supercomputer center and a data storage center. You can basically imagine that it has a big room full of hard drives that store the data that they collect. And it's a pretty big building. How big? Well, I can give you the numbers -- 140,000 square meters -- but that doesn't tell you much. Maybe it's better to think of it as a comparison. Think of the biggest IKEA store you've ever been to. This is five times bigger. How many hard drives can you fit in an IKEA store? Right? It's pretty big. We estimate that the electric bill alone to run this data center is going to be in the tens of millions of dollars a year. And this kind of mass surveillance means that they can collect our data and basically keep it forever, keep it for long periods of time, keep it for years, keep it for decades. This creates completely new kinds of risks for all of us. And this is mass, generalized surveillance of everyone.

Okay, not exactly everyone, because the U.S. intelligence community is legally allowed to monitor only foreigners. They can monitor foreigners when their data connections end up in or pass through the United States. And monitoring foreigners doesn't sound so bad until you realize that I'm a foreigner and you're a foreigner. In fact, 96 percent of the planet is foreign.

(Laughter)

Isn't that right?

So it's mass surveillance of all of us, all of us who use telecommunications and the internet.

But don't get me wrong: There are indeed types of surveillance that are okay. I love freedom, but even I agree that some surveillance is okay. If the authorities are trying to find a murderer, or trying to catch a drug lord, or trying to prevent a school shooting, and they have evidence and they have suspects, then it's perfectly okay to monitor the suspect's phone, and to intercept their online communications. I don't disagree with that at all, but that's not what programs like PRISM are for. They're not about monitoring people who they have reasonable suspicions of wrongdoing. They're about monitoring people who they know are innocent.

So the four main arguments in favor of this kind of surveillance, the first is that every time you start talking about these revelations, there are going to be deniers who are going to try to downplay the significance of these revelations, saying that we already knew all this, we knew it was happening, it's nothing new. That's not true. Don't let anyone tell you that we already knew this, because we didn't. Our worst fears may have been this, but we didn't know it was happening. Now we know for sure that it's happening. We didn't know this. We didn't know about PRISM. We didn't know about XKeyscore. We didn't know about Cybertrans. We didn't know about DoubleArrow. We didn't know about Skywriter -- all these different programs that the United States intelligence agencies are running. But now we do.

And we didn't know that the United States intelligence agencies were going to the extreme of infiltrating standards organizations to sabotage encryption algorithms on purpose. And that means you take something that's secure, an encryption algorithm that's so secure that when you use it to encrypt a file, nobody can decrypt it. Even if they used every computer on the planet to decrypt that file, it would take millions of years. So it's basically completely secure, it can't be broken. You take something that's so good and then you deliberately weaken it, ultimately making us all less secure. A real-world equivalent would be the intelligence agencies forcing a secret PIN code into every home alarm so that they can get into every home because, you know, the bad guys might have home alarms, but that would make us all less secure as a result. The backdoors in the encryption algorithms are mind-boggling. But of course, these intelligence agencies are doing their jobs. That's what they were told to do: intercept signals, monitor telecommunications, monitor Internet traffic. That's what they're trying to do, and since most of the Internet traffic today is encrypted, they're trying to find ways to bypass the encryption. One way is to sabotage the encryption algorithms, which is a great example of how the United States intelligence agencies have gone wild. They're completely out of control, and we need to get them back under control.

So what do we know about these leaks? They're all based on the files leaked by Mr. Snowden. The first PRISM slides from early June give the details of a collection program where data is collected from service providers, and they can go and name the service providers they have access to. They even have a specific date of when they started collecting the data for each of these service providers. For example, they say that the collection by Microsoft started on September 11, 2007, for Yahoo on March 12, 2008, and then for others: Google, Facebook, Skype, Apple and so on.

And every single one of these companies denies it. They all say that it's just not true, that they're not giving access to their data through the backdoor. But we have these records. So is one of them lying, or is there an alternative explanation? One explanation would be that these parties, these service providers, are not cooperating. Instead, they've been hacked. That would explain it. They're not cooperating. They've been hacked. In this case, they've been hacked by their own government. This may sound strange, but we've seen cases where this has happened before, for example, the case of the Flame malware which we strongly believe was written by the U.S. government, and which, in order to spread, compromised the security of the Windows update network, which in this case means that the company was hacked by its own government. And there's more evidence to support this theory. The German Der Spiegel has leaked more information about the operations run by the elite hacking units that operate within these intelligence agencies. Within the NSA, the unit is called TAO, Tailored Access Operations, and within GCHQ, which is the equivalent in the UK, it is called NAC, Network Analysis Center. These recent leaks of these three slides show in detail an operation run by the UK intelligence agency GCHQ targeting a telecommunications company here in Belgium. What this means in effect is that the intelligence agency of an EU country is breaching the security of a telecommunications company in an EU member state, and they discuss it in their slides quite casually, as business as usual. Here is the primary target, here is the secondary target, here is the grouping. They probably have a Thursday night team building in the pub. They use kitschy PowerPoint clip art images like, you know, "Success," when they access services like this. What the hell?

And then there's the argument that, okay, yes, that might be the case, but then, so do other countries. All countries spy. And maybe that's true. Many countries spy, not all of them, but let's look at an example. Let's take, for example, Sweden. I'm talking about Sweden because Sweden has a somewhat similar law to the United States. When your data traffic passes through Sweden, the intelligence agency has the legal right, by law, to intercept that traffic. Okay, how many Swedish leaders and politicians and business leaders use, every day, U.S.-based services like, you know, running Windows or OSX, or using Facebook or LinkedIn, or storing their data in some cloud like iCloud or Skydrive or DropBox, or maybe using online services like Amazon or sales support? The answer is that every Swedish business leader does that every day. Let's turn it around. How many American leaders use Swedish email and cloud services? The answer is zero. So it's not balanced. It's not balanced at all, not in the slightest.

And when we have the occasional European success story, and even those typically end up being sold to the United States. Like Skype, which was secure. It was end-to-end encrypted. Then it was sold to the United States. Today, it's not secure anymore. So, once again, we're taking something that is secure and making it less secure on purpose, making us all, as a result, less secure.

Then there's the argument that the United States is only fighting terrorists. It's the war on terror. You shouldn't worry about that. Well, it's not the war on terror. Yes, part of it is the war on terror, and yes, there are terrorists, and they kill and maim and we have to fight them, but we know from these leaks that they've used the same techniques to listen to the phone calls of European leaders, to intercept the emails of people in Mexico and Brazil, to read the email traffic inside the UN headquarters and the European Parliament, and I don't think they're trying to find terrorists inside the European Parliament, are they? It's not the war on terror. It may be a part of it, and there are terrorists, but do we really view terrorists as such an existential threat that we are willing to do anything to fight them? Are Americans ready to throw away the Constitution and throw it in the trash just because there are terrorists? The same with the Bill of Rights and all the amendments and the Universal Declaration of Human Rights and the European conventions on human rights and fundamental freedoms and freedom of the press? Do we view terrorism as such an existential threat that we are willing to do anything?

But people are afraid of terrorists and then they think maybe this surveillance is okay because they have nothing to hide. Feel free to research me if that helps. And anyone who tells you they have nothing to hide just hasn't thought it through enough.

(Clap)

Because we have this thing called privacy, and if you really believe you have nothing to hide, please make sure that's the first thing you tell me because then I'll know not to trust you with secrets, because it's obvious that you can't keep a secret. But people are brutally honest with the internet, and when these leaks started, a lot of people were asking me about that. And I have nothing to hide. I'm not doing anything wrong or illegal. But I don't have anything specific that I would like to share with an intelligence agency, especially a foreign intelligence agency. And if we really need a Big Brother, I would much rather have a domestic Big Brother than a foreign Big Brother. When the leaks started, the first thing I tweeted about it was a comment about how, when you use search engines, you're potentially leaking all this to U.S. intelligence agencies. And after two minutes, I got a response from a Kimberly from the United States who was questioning me, why was I worried about this? What am I sending that I should be worried about? Am I sending nude photos or something? My response to Kimberly was that what I'm sending is none of her business, and it shouldn't be any of her government's business. Because that's the point. It's about privacy. Privacy is non-negotiable. It should be built into all the systems that we use.

(Clap)

One thing we all need to understand is that we are ruthlessly honest with search engines. Show me your search history, and I'll find something incriminating or embarrassing in five minutes. We are more honest with search engines than we are with our families. Search engines know more about you than your family members know about you. All of this information that we give, we give to the United States.

And surveillance changes history. We know this from examples of corrupt presidents like Nixon. Imagine if he had the surveillance tools that are available today. And let me quote the president of Brazil, Ms. Dilma Rousseff. She was targeted by the NSA. They were reading her emails, and she spoke at the United Nations and said, "If there is no right to privacy, there can be no true freedom of expression and opinion, and therefore, there can be no effective democracy.".

That's what it's all about. Privacy is the building block of our democracies. And to quote a fellow security researcher, Marcus Rannum, he said that right now the United States is treating the internet like it would one of its colonies. So we're back to the colonial era, and we, the foreign users of the internet, should consider the Americans our masters.

So Mr. Snowden has been accused of many things. Some accuse him of creating problems for the American cloud industry and software companies with these revelations, and blaming Snowden for the problems of the American cloud industry would be like blaming Al Gore for causing global warming.

(Laughter)

(Clap)

So, what can be done? Should we be worried? No, we shouldn't be worried. We should be angry, because this is wrong and it's rude and it shouldn't be happening. But that's not going to really change the situation. What will change the situation for the rest of the world is to try to stay away from systems that are made in the United States. That's a lot easier said than done. How do you do that? One country, any country in Europe, can't replace and build replacements for operating systems and cloud services that are made in the United States.

But maybe you don't have to do it alone. Maybe you can do it with other countries. The solution is open source. By building open, free, secure systems together, we can bypass this surveillance, and then no one country has to solve the problem alone. It just has to solve a small problem. And to quote a fellow security researcher, Harun Mer, it only takes one country to make a small wave, but those small waves together become a tide, and the tide will lift all the boats at once, and the tide that we build with secure, free, open source systems will become the tide that will lift us all above and beyond the surveillance state.

Thank you very much.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS