Skip to content

Comment on What If China Hacks the NSA's Massive Data Trove?

Comments

That's part of the reason for the Utah datacenter. Consolidating several NSA datacenters around the country into one super-secure fortress.

First, separate offline networks and the most advanced network security ever conceived will be put in place at this new datacenter.

If you're thinking that a reverse engineered Stuxnet might be able to hop over to the secure network, I doubt it, and even if it does then what will it do to transmit the data out?

It is slightly insulting to the engineers and security experts whose full-time job is to keep the NSA secure, but I suppose this scenario is worth discussing just in-case someone thinks of a clever way which the NSA has not.

The most vulnerable aspect is any remote access either to company servers or to the NSA search tools. I would hope that a data dump or unrestricted access to the NSAs "database" would be completely impossible. Even with extensive insider knowledge of the Utah datacenters systems, an ex-employee would have zero chance of gaining unauthorized access.

"No worry, it's impossible to break/hack/destroy/do !" is the start of so many disasters.

Especially funny (in a way) at a time where leaks of secret/classified data and informations is becoming endemic.

Whistle-blowing does not equal hacking.

Yes, but it still means the data finds a way out.

The leaked materials were not solely housed at an NSA datacenter.

Yes, and water is wet, that doesn't change anything to my two previous messages.

You can whistle blow a lot now-a-days...

Maybe at a private company, but it is not wise to disclose classified information about the US government if you are or were employed by them.

This isn't a blockbuster action film, it's a data center. I think this sort of thing is interesting but I write software. I wouldn't bet any amount of money that everyone along the PRISM chain of decision making is as impressed with the idea of a super-fortress data center. Corners get cut, work is pushed towards those with connections instead of the ones who can best do the job. Compromises are made, money goes here instead of there.

I find the idea of a super-fortress of data a bit far-fetched to begin with, that such a place would be goverment run seems even more ridiculous.

The Utah data center is more of a consolidating effort than some new spy program. It's suppose to save money and increase security (and storage ability).

The NSA has computer security technology that the public and other government do not. They also have an unfathomable amount of processing power without the Utah data center (Tordella).

What congress in their right mind would slash the NSAs budget and put the entire nation at risk?

Also, it isn't a set fact of life that all government agencies / programs are inefficient and incompetent.

Yeah and the Titanic was too big to sink.

Humanity can often get it wrong.

Insulting? Really?

It's a truism in computing that the only really secure computer is one that has been disconnected from the network, turned off, encased in solid concrete, and sunk to the bottom of the ocean.

Even then, better hope James Cameron doesn't want what's inside.

I'm sure NSA's security people are aware of this. If they are not, then they're not very good at their job.

Why doesn't simply being disconnected from the internet and located in the middle of nowhere Utah locked in a super-secure fortress with the best network engineers, computer experts, and cryptologists suffice?

And yes, it is insulting. The NSA has been at the forefront of encryption and network security for the past 60 years.

Am I giving the NSA too much undeserved credit?

Why doesn't simply being disconnected from the internet and located in the middle of nowhere Utah locked in a super-secure fortress with the best network engineers, computer experts, and cryptologists suffice?

Because nobody can use it there. You might as well put it at the bottom of the ocean -- or not collect it in the first place. At some point you have to give agents in the outside world a way to use the data or it's totally worthless, and then you have an exploitation vector.

Am I giving the NSA too much undeserved credit?

There is always a difference between best-in-class and infallible. And the problem is that you only have to be wrong once.

Also, this: https://news.ycombinator.com/item?id=5848148

Not to mention they have to get the data to the top secret offline location and it can be intercepted before it gets there.

Encryption? They're pretty good at it.

Cryptographers have a saying. Encryption is like a single fence post which is a thousand miles high. You're not likely to break the encryption, but it doesn't do you any good if the attacker can just go around it. Find a weaker link in the chain: Poor passwords, social engineering, bribery, good ol' fashion espionage, etc.

Yes you are giving them too much undeserved credit. You're asking us to have faith in a government agency being able to keep an enormous amount of digital data (and growing fast) when we've already seen that fail plenty of times.

So the NSA is special? What happens when the political winds change and they experience budget cutbacks, and some of the really talented employees move to the private sector? Or when they bring in outside private sector contractors.

The slip up doesn't even have to be monumental in itself, but the consequences are. The real terrorism (the one that will actually affect a large number of people) is and will be cyber based. You're basically stockpiling weapons.

If it's disconnected from the internet, how is it going to get any new data? If there's a way for it to get new data, then, well... isn't that exactly how Stuxnet happened?

An intermediary system. Sure, there will be internet access at the Utah facility, but the networks will be separated. Stuxnet was physically delivered on a USB drive. Stuxnet didn't have the requirement of sending back massive amounts of data (or any really).

That's a good point.

Having said that, I guess it just comes back to the fact that the intermediary is the real target then. So we hope the NSA has had it's crack team in there. Which means that we hope that it's disconnected etc. as well... I mean, at some point there needs to a source that is connected to the internet and I guess that source is the real target.

If it's not connected to the internet, how are you going to get terabytes of data per day in there? If it's not connected to the internet, how are you going to get the "interesting™" stills that it has extracted from millions of hours of CCTV to the Pentagon? There is almost no point in not having it connected to the internet.

Separate networks at the Utah data center. One would be connected to the internet and very highly monitored for intrusion or unauthorized access.

Maybe even turn off the power for data over X years old. Then it would be impossible to steal that data without physical access to one of the most secure buildings on the planet.

No, the most vulnerable aspect is almost always users. Human, fallible, greedy, lazy, sloppy, mismanaged users.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.