intelligenceå ±æ©é¢ãç§ãã¡ãã¯ããã«äžåã£ãŠãããããæå·åã§èº«ãå®ãã®ã¯æå³ããªããšããä»®å®ã¯ééã£ãŠããŸãã Snowdenã¢ãŒã«ã€ãã®1ã€ã®ããã¥ã¡ã³ãã瀺ãããã«ãå°ãªããšã2012幎ã«ã¯ãNSAã¯å€ãã®éä¿¡ãããã³ã«ã®è§£èªã«æåããŸããã§ããã ãã®å¹Žã®äŒè°ã®ãã¬ãŒã³ããŒã·ã§ã³ã«ã¯ãã¢ã¡ãªã«äººã解èªã§ããªãæå·åããã°ã©ã ã®ãªã¹ããå«ãŸããŠããŸããã æå·è§£èªã®ããã»ã¹ã§ã¯ãNSAæå·åŠè ã¯ãæ»æã®è€éãã®ã¬ãã«ãšããäºçŽ°ãªããããç Žå±çãªããŸã§ã«åŸãããçµæã«åŸã£ãŠãç®æšã5ã€ã®ã¬ãã«ã«åããŸããã
[ åç·š ]
Webäžã®ããã¥ã¡ã³ãã®åããç£èŠããããšã¯ããäºçŽ°ãªãç®æšãšããŠåé¡ãããŸãã Facebookã§ãã£ãããèšé²ããããšã¯ãåçŽãªãã¿ã¹ã¯ã§ããã ãã·ã¢ã®ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ã㌠Mail.ruãä»ããŠéä¿¡ãããæåã解èªããè€éãã®ã¬ãã«ã¯ãäžçšåºŠã®è€éããã®ã¿ã¹ã¯ãšèŠãªãããŸãã ããããããã3ã€ã®åé¡ã¬ãã«ã¯ãã¹ãŠãNSAã«æ·±å»ãªåé¡ãåŒãèµ·ããããšã¯ãããŸããã
第4ã¬ãã«ã§ã¯ããã¹ãŠãããè€éã«ãªããŸãã ãã¬ãŒã³ããŒã·ã§ã³ã«ããã°ãNSAã¯ã ZohoãµãŒãã¹ãªã©ã®åŒ·åãªæå·åæ¹æ³ã䜿çšããŠããŸãã¯å¿åã®Webæ€çŽ¢çšã«éçºãããTorãããã¯ãŒã¯ã®ãŠãŒã¶ãŒãç£èŠãããšãã«ãé»åã¡ãŒã«ã¡ãã»ãŒãžãããã€ããŒãä»ããŠéä¿¡ãããã¡ãã»ãŒãžã埩å·åããããšãããé倧ãªãåé¡ãçµéšããŠããŸãã The Onion RouterãšããŠãç¥ãããTorã¯ãç¡æã®ãªãŒãã³ãœãŒã¹ãœãããŠã§ã¢ã§ããããŠãŒã¶ãŒã¯6,000å°ä»¥äžã®æ¥ç¶ãããèªçºçã«å¯ä»ãããã³ã³ãã¥ãŒã¿ãŒã®ãããã¯ãŒã¯ãéããŠã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããŸãã ãããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒã«ãã¹ãŠã®ãŠãŒã¶ãŒæ å ±ãå«ãŸããªãããã«ããœãããŠã§ã¢ã¯èªåçã«ããŒã¿ãæå·åããŸãã ãããã£ãŠãç£èŠã®å°é家ãç¹å®ã®Webãµã€ãã«ã¢ã¯ã»ã¹ãã人ã®å± å Žæã远跡ããããTorã䜿çšããŠã€ã³ã¿ãŒããããæ€çŽ¢ãã人ãæ»æãããããããšã¯éåžžã«å°é£ã«ãªããŸãã
ã³ã³ãã¥ãŒã¿ãŒäžã®ãã¡ã€ã«ãæå·åããããã°ã©ã ã§ããTruecryptããNSAã«é倧ãªåé¡ãåŒãèµ·ãããŸãã ãã®éçºè ã¯ãæšå¹Ž5æã«ããã°ã©ã ã®éçºãåæ¢ããŸãããããã«ãããå·æ©é¢ããã®å§åã®çããé«ãŸããŸããã ã€ã³ã¹ã¿ã³ãã¡ãã»ãŒãžã®ãšã³ãããŒãšã³ãã®æå·åã®ããã®Off-The-RecordïŒOTRïŒãšåŒã°ãããããã³ã«ããNSAã«é倧ãªåé¡ãåŒãèµ·ããããã§ãã ãããã®äž¡æ¹ã®ããã°ã©ã ã®ã³ãŒãã¯ãèªç±ã«è¡šç€ºãå€æŽãããã³é åžã§ããŸãã å°é家ã¯ãintelligenceå ±æ©é¢ããªãŒãã³ãœãŒã¹ããã°ã©ã ãæäœããããšã¯ãAppleãMicrosoftãªã©ã®äŒæ¥ãéçºããå€ãã®ã¯ããŒãºãã·ã¹ãã ãããã¯ããã«é£ããããšã«åæããŠããŸãã 誰ã§ããã®ãããªãœãããŠã§ã¢ã®ã³ãŒããèŠãããšãã§ãããããæ€åºãããªãããã¯ãã¢ãå®è£ ããããšã¯éåžžã«å°é£ã§ãã GoogleãFacebookãAppleãªã©ã®å°ãªããšã9ã€ã®ç±³åœã®ã€ã³ã¿ãŒãããäŒæ¥ããã®NSAã®ããŒã¿åéããã°ã©ã ã§ããPrismããŒãããŒã代çåºã«æäŸããååOTRãã£ããã®ãã©ã³ã¹ã¯ãªããã¯ããã®å ŽåãNSAã®åªåã倱æããããšã瀺ããŠããŸãã OTRã§æå·åãããã¡ãã»ãŒãžã¯è§£èªã§ããŸãããã ããã¯ãå°ãªããšãOTRãããã³ã«ã䜿çšãããšãNSAã§è¡šç€ºããããã«éä¿¡ã«ã¢ã¯ã»ã¹ã§ããªãããã«ããããšãã§ããããšãæå³ããŸãã
ãšãŒãžã§ã³ã·ãŒã«ãšã£ãŠãç¶æ³ã¯ã5ãã¬ãã«ã§ãå£æ» çãã«ãªããŸããããšãã°ã被éšè ãTorãå¥ã®ãå¿ååããµãŒãã¹ã CSpaceã€ã³ã¹ã¿ã³ãã¡ãã»ãŒãžã³ã°ã·ã¹ãã ãããã³ZRTPãšåŒã°ããã€ã³ã¿ãŒããããã¬ãã©ããŒã·ã¹ãã ïŒVoIPïŒã®çµã¿åããã䜿çšããå Žåã NSAææžã«ç€ºãããŠãããã®ãããªçµã¿åããã¯ããéžæãããæœèšã®å Žæãšéä¿¡ã远跡ããèœåã®ã»ãŒå®å šãªåªå€±ãã«ã€ãªãããŸãã
ZRTPã·ã¹ãã ã¯ãã¢ãã€ã«ããã€ã¹ã§äŒè©±ããã£ãããå®å šã«æå·åããããã«äœ¿çšãããRedPhoneãSignalãªã©ã®ç¡æã®ãªãŒãã³ãœãŒã¹ããã°ã©ã ã§äœ¿çšãããŸãã
ãNSAã¯ãåœç€Ÿã®ãµãŒãã¹ãä»ããéä¿¡ã®æå·åãçã«äžéæã§ãããšèããŠããããšãç¥ã£ãŠããããã§ãããšãMoxie Marlinspikeãšããä»®åã§RedPhoneéçºè ã¯èšããŸãã
ãã©ãŒãããŒãã®ããã«æ»ã¬
ZRTPãšããååã®æåãZãã¯ãã·ã¹ãã ã®éçºè ã®1人ã§ããPhil Zimmermannã«æ¬æãè¡šãããã®ã§ããPhilZimmermannã¯ãPretty Good Privacyã·ã¹ãã ãäœæããŸããã PGPã¯20幎以äžåã«äœæãããŸããããé©ãã¹ãããšã«ãNSAã«ãšã£ãŠã¯äŸç¶ãšããŠãéåžžã«å°é£ãã§ãã ããã®PGPã§æå·åãããã¡ãã»ãŒãžã¯åŸ©å·åã§ããŸãããNSAã®ææžã¯ãYahooçµç±ã§éä¿¡ãããæçŽã«é¢ããŠSpiegelã®æã«æž¡ããŸããã
Phil Zimmermannã¯1991幎ã«PGPãæžããŸããã ç±³åœã®æ žå µåšèšç»ãçµãããã掻å家ã¯ãä»ã®å¿ãåãããã人ã ãšå®å šã«æ å ±ã亀æã§ããæå·åã·ã¹ãã ãäœæããããšèããŠããŸããã 圌ã®ã·ã¹ãã ã¯ãããã«äžçäžã®åäœå¶æŽŸã®éã§éåžžã«äººæ°ãåããŸããã ç±³åœå€ã§ãã®ããã°ã©ã ãåºã䜿çšãããŠããããšãèãããšã1990幎代ã«ç±³åœæ¿åºã¯ãæŠåšèŒžåºç®¡çæ³ã«éåãããšãããZimmermannã起蚎ãå§ããŸããã æ€å¯å®ã¯ããã®ãããªè€éãªæå·åã·ã¹ãã ãäœæããŠåœå€ã«é åžããããšã¯éæ³ã§ããããšã«åæããŸããã ãã£ã³ããŒãã³ã¯ãã·ã¹ãã ã®ãœãŒã¹ã³ãŒããæ¬ã®åœ¢ã§å ¬éããããšã§å¯Ÿå¿ããŸãããããã¯æ²æ³ã«ãã£ãŠä¿è·ãããèšè«ã®èªç±ã®çŸãã§ããã
PGPã¯åŒãç¶ãéçºãããŠãããçŸåšã§ã¯å€ãã®ããŒãžã§ã³ã®ã·ã¹ãã ãå©çšå¯èœã§ãã æãäžè¬çãªã®ã¯ããã€ãã®ããã°ã©ããŒWerner Kochã«ãã£ãŠéçºãããããã°ã©ã ã§ããGNU Privacy GuardïŒGnuPGïŒã§ãã ææžã®1ã€ã¯ãFive Eyesåçã®ä»£è¡šè ãPGPãæã 䜿çšããããšã瀺ããŠããŸãã èªåã®ã»ãã¥ãªãã£ãšç±³åœåœå±ã«åãä»ãããŠããããã«ãŒã¯ãæ³å以äžã«å€ãã®å ±éç¹ãæã£ãŠããããšãããããŸãã åœåãTorãããžã§ã¯ãã¯ç±³åœæµ·è»ç 究æã®æ¯æŽãåããŠéçºãããŸããã
ä»æ¥ãææžã®1ã€ã«ç€ºãããŠããããã«ãNSAãšãã®åçåœã¯ãç±³è»ãäœæããã·ã¹ãã ãç Žå£ããããã«æåãå°œãããŠããŸãã ãå¿ååãTorã¯ãæããã«NSAã®æåªå äºé ã®1ã€ã§ããããã®åéã§ã¯ãšãŒãžã§ã³ã·ãŒã¯ã»ãšãã©æåããŠããŸããã 2011幎ã®ææžã®1ã€ã¯ããã¹ãèªäœãšããŠãæ©é¢èªäœã䜿çšããŠTorã®çµæã解èªããè©Šã¿ã«èšåããŠããŸãã
ã¹ããŒãã³ã®ææžã¯ãããçšåºŠãæ å ±åéã«å¯Ÿããå°œããããšã®ãªãæžãã§NSAãæ¢ããããšã¯ã§ããªããšä¿¡ããŠãã人ã ã«ãããçšåºŠã®å®å¿æãåŒã³èµ·ããã¹ãã§ãã ãŸã å®å šãªéä¿¡ãã£ãã«ãããããã§ãã ãã ãããã®ææžã¯ãintelligenceå ±æ©é¢ãããŒã¿ãä¿åããã³è§£èªããããã«ã©ã®çšåºŠäœæ¥ãé²ããŠãããã瀺ããŠããŸãã
ã€ã³ã¿ãŒãããã»ãã¥ãªãã£ã¯è€æ°ã®ã¬ãã«ã§å®è¡ãããŸããNSAã¯ããã®åçåœãšãšãã«ãæããã«ã䜿çšãïŒã€ãŸãããããã³ã°ãïŒã§ããããšã¯æããã§ãããããŸã§èããããªãã£ãèŠæš¡ã§æãåºã䜿çšãããŠãããã®ã§ãã
ä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ãšå®éã®ãä»®æ³ã
1ã€ã®äŸã¯ä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ïŒVPNïŒã§ããããã¯ãè€æ°ã®ãªãã£ã¹ãå Žæã§éå¶ãããŠããäŒæ¥ãæ©é¢ã§ãã䜿çšãããŸãã çè«çã«ã¯ãVPNã¯Webäžã®2ã€ã®ãã€ã³ãéã«å®å šãªãã³ãã«ãäœæããŸãã æå·ã§ä¿è·ããããã¹ãŠã®ããŒã¿ã¯ããã®ãã³ãã«ã«ã«ãŒãã£ã³ã°ãããŸãã ããããVPNã»ãã¥ãªãã£ã®ã¬ãã«ã«é¢ããŠã¯ããä»®æ³ããšããèšèããã®èª¬æã«æãé©ããŠããŸãã ããã¯ãNSAãVPNã䜿çšããŠå€æ°ã®æ¥ç¶ãã¯ã©ãã¯ãã倧èŠæš¡ãããžã§ã¯ãã«åãçµãã§ããããã§ããããã«ããããšãŒãžã§ã³ã·ãŒã¯ãã®ãªã·ã£æ¿åºã®VPNãããã¯ãŒã¯ãªã©ã®VPNãããã¯ãŒã¯ã§éä¿¡ãããæ å ±ãååã§ããŸãã Spiegelã®æã«æž¡ã£ãææžã«ãããšãã®ãªã·ã£ã®VPNã³ãã¥ãã±ãŒã·ã§ã³ãæ åœããNSAããŒã ã¯12人ã§æ§æãããŠããŸãã
NSAã¯ãã¢ã€ã«ã©ã³ãã®VPNãµãŒãã¹SecurityKissãæšçã«ããŸããã NSAã®ã¬ããŒãã«ããã°ãXkeyscoreã®ä»¥äžã®ãããžã¿ã«ãã£ã³ã¬ãŒããªã³ããã¯åŒ·åãªã¹ãã€ãŠã§ã¢ããã°ã©ã ã§ããããµãŒãã¹ããŒã¿ãæœåºããããã«ãã¹ãããã³äœ¿çšãããŸããã
fingerprint('encryption/securitykiss/x509') = $pkcs and ( ($tcp and from_port(443)) or ($udp and (from_port(123) or from_por (5000) or from_port(5353)) ) ) and (not (ip_subnet('10.0.0.0/8' or '172.16.0.0/12' or '192.168.0.0/16' )) ) and 'RSA Generated Server Certificate'c and 'Dublin1'c and 'GL CA'c;
2009幎ã®NSAææžã«ãããšããšãŒãžã§ã³ã·ãŒã¯VPNæ¥ç¶ããã®1æéããã1,000件ã®ãªã¯ãšã¹ããåŠçããŸããã ãã®æ°ã¯ã2011幎æ«ãŸã§ã«1æéããã100,000ã«å¢å ãããšäºæ³ãããŠããŸããã ã·ã¹ãã ã®ç®çã¯ããããã®èŠæ±ã®ãå°ãªããšã20ïŒ ããå®å šã«åŠçããããšã§ãããã€ãŸããåä¿¡ããããŒã¿ã埩å·åããŠå®å ã«éä¿¡ããå¿ èŠããããŸããã ã€ãŸãã2011幎æ«ãŸã§ã«ãNSAã¯1æéãããæ倧20,000ã®å®å šãªVPNæ¥ç¶ãç¶ç¶çã«ç£èŠããããšãèšç»ããŠããŸããã
VPNæ¥ç¶ã¯ãããŸããŸãªãããã³ã«ã«åºã¥ããŠæ§ç¯ã§ããŸãã æãäžè¬çã«äœ¿çšãããPoint-to-Pointãã³ããªã³ã°ãããã³ã«ïŒPPTPïŒããã³IPsecïŒã€ã³ã¿ãŒããããããã³ã«ã»ãã¥ãªãã£ïŒã ãããã®ãããã³ã«ã¯ãæ¬åœã«æ¥ç¶ãã¯ã©ãã¯ãããå ŽåãNSAã¹ãã€ã«ç¹å®ã®åé¡ãæ瀺ããŸããã å°é家ã¯ãã§ã«PPTPãããã³ã«ãå®å šã§ãªããšåŒãã§ããŸãããå€ãã®åçšã·ã¹ãã ã§äœ¿çšããç¶ããŠããŸãã NSAã®ãã¬ãŒã³ããŒã·ã§ã³ã®ããããã®èè ã¯ãFOURSCOREãšåŒã°ãããããžã§ã¯ããèªã£ãŠããŸããããã®ãããžã§ã¯ãã¯ãPPTPãããã³ã«ãä»ããŠéä¿¡ãããæå·åãããã¡ã¿ããŒã¿ãå«ãæ å ±ãä¿åããŸãã
NSAææžã¯ãå€æ°ã®ç°ãªãããã°ã©ã ã䜿çšããŠã代çåºãµãŒãã¹ãå€ãã®äŒæ¥ãããã¯ãŒã¯ã«äŸµå ¥ãããšè¿°ã¹ãŠããŸãã 远跡察象è ã®äžã«ã¯ããã·ã¢ã®èªç©ºäŒç€ŸTransaeroãRoyal Jordanian Airlinesãã¢ã¹ã¯ã¯ã®ãã¬ã³ã ãããã€ããŒTelematics WorldããããŸãã ãã®ããã°ã©ã ã®ããäžã€ã®ææã¯ãã¢ãã¬ãã¹ã¿ã³ãããã¹ã¿ã³ããã«ã³ã®å€äº€å®ãšå ¬åå¡ã®å éšéä¿¡ã®ç£èŠã®ç¢ºç«ã§ãã
IPsecã¯ãäžèŠãããšã¹ãã€ã«ãšã£ãŠããå€ãã®åé¡ãåŒãèµ·ãããããã³ã«ã§ãã ããããNSAã«ã¯ãæ¥ç¶ãäœæããããã»ã¹ã«é¢äžããã«ãŒã¿ãŒã«å¯ŸããŠå€ãã®æ»æãå®è¡ããããŒãååŸããéä¿¡ãããæ å ±ã解èªããããã解èªããå¯èœæ§ãé«ããªãœãŒã¹ããããŸããããã¯ãNSAéšéããã®Tailored Access Operationsãšããã¡ãã»ãŒãžã«ãã£ãŠèšŒæãããŸãïŒãTAOã¡ã€ã³ãã³ãã³ã°ãã©ãã£ãã¯ãééããã«ãŒã¿ãŒã«ã¢ã¯ã»ã¹ã§ããŸããããšãã¬ãŒã³ããŒã·ã§ã³ããããŸãã
ã»ãã¥ãªãã£ãšã¯é¢ä¿ãããŸãã
éåžžã®ã€ã³ã¿ãŒããããŠãŒã¶ãŒãéèååŒãé»åè³Œå ¥ããŸãã¯é»åã¡ãŒã«ã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹ã«åžžã«äŸåããŠãããšèããããå®å šãªã·ã¹ãã ã¯ãVPNãããå®å šæ§ãäœããªããŸãã äžè¬çãªäººã¯ããã©ãŠã¶ã®ã¢ãã¬ã¹ããŒãèŠããšããããã®ãå®å šãªãæ¥ç¶ãç°¡åã«èªèã§ããŸãããã®æ¥ç¶ã§ã¯ãã¢ãã¬ã¹ã¯ãhttpãã§ã¯ãªããhttpsãã§å§ãŸããŸãã ãã®å Žåã®ãSãã¯ãã»ãã¥ã¢ãããã»ãã¥ã¢ããæå³ããŸãã åé¡ã¯ããããã®ãããã³ã«ãã»ãã¥ãªãã£ãšã¯äœã®é¢ä¿ããªãããšã§ãã
NSAãšãã®åçåœã®ãã®ãããªååç©ã¯ã1æ¥100äžåãç°¡åã«å解ãããŸãã NSAææžã«ãããšããšãŒãžã§ã³ã·ãŒã¯ããããã³ã°ãããhttpsæ¥ç¶ã®éã2012幎æ«ãŸã§ã«1æ¥ããã1,000äžã«å¢ããããšãèšç»ããŸããã ã€ã³ããªãžã§ã³ã¹ãµãŒãã¹ã¯ããŠãŒã¶ãŒãã¹ã¯ãŒãã®åéã«ç¹ã«é¢å¿ããããŸãã 2012幎æ«ãŸã§ã«ãã·ã¹ãã ã¯1ãæã«çŽ20,000å䜿çšãããã³ã«ããæå·åã䜿çšãããã¹ã¯ãŒãã«åºã¥ããŠåäœããå°ãªããšã100åã®ã¢ããªã±ãŒã·ã§ã³ã®ã¹ããŒã¿ã¹ã远跡ãããããšã«ãªã£ãŠããã
ããšãã°ãè±åœæ¿åºéä¿¡ã»ã³ã¿ãŒã¯ãTLSããã³SSLãããã³ã«ïŒãããã¯httpsæ¥ç¶æå·åãããã³ã«ïŒã䜿çšããŠããFLYING PIGããšåŒã°ããããŒã¿ããŒã¹ã§æå·åã«é¢ããæ å ±ãåéããŸãã è±åœã®ã¹ãã€ã¯æ¯é±ãã·ã¹ãã ã®çŸåšã®ç¶æ ã«é¢ããã¬ããŒããçæããŠãã»ãšãã©ã®å ŽåSSLãããã³ã«ã䜿çšãããµãŒãã¹ãã«ã¿ãã°åãããããã®æ¥ç¶ã®è©³çŽ°ãä¿åããŸãã FacebookãTwitterãHotmailãYahooãiCloudãªã©ã®ãµãŒãã¹ã¯ããã®ãããªãããã³ã«ãç¹ã«é »ç¹ã«äœ¿çšããããšã§åºå¥ãããŸããè±åœã®æ¥ç¶ãµãŒãã¹ã§èšé²ãããæ¯é±ã®æ¥ç¶æ°ã¯æ°ååã§ããããã¯ãæã人æ°ã®ãã40ãµã€ãã®ã¿ã§ãã
ããã±ãŒãµã€ãã®ç£èŠ
ã«ããéä¿¡ã»ãã¥ãªãã£ã»ã³ã¿ãŒã¯ãåœââå ã§æã人æ°ã®ãã嚯楜å°çšã®ãµã€ããç£èŠããŠããŸãããããã±ãŒãã£ã¹ã«ãã·ã§ã³ãµã€ãã§ã®ãã£ããã¢ã¯ãã£ããã£ã®å€§å¹ ãªå¢å ã远跡ããŸããã ããã¯ããããããã¬ãŒãªãã·ãŒãºã³ã®éå§ã«ãããã®ã§ãããšãããã¬ãŒã³ããŒã·ã§ã³ã¯è¿°ã¹ãŠããŸãã
NSAã¯ãŸããSSHãããã³ã«ã解èªã§ãããšäž»åŒµããããã°ã©ã ãäœæããŸããã éåžžãäž»ã«ã€ã³ã¿ãŒãããã«ãŒã¿ãŒãããžãã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ã·ã¹ãã ãããã³ãã®ä»ã®åæ§ã®ãµãŒãã¹ã§äœ¿çšããããã«ãã·ã¹ãã 管çè ãåŸæ¥å¡ã®ã³ã³ãã¥ãŒã¿ãŒã«ãªã¢ãŒãã§ã¢ã¯ã»ã¹ããããã«äœ¿çšããŸãã NSAã¯ããã®ããã«ããŠååŸããããŒã¿ãä»ã®æ å ±ãšçµã¿åãããŠãéèŠãªã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããŸãã
匱ãæå·åæšæº
ãããããã¡ã€ãã¢ã€ã¢ã©ã€ã¢ã³ã¹ã¯ã©ã®ããã«ããŠãããã®æšæºãšæå·åã·ã¹ãã ã®ãã¹ãŠã«äŸµå ¥ããã®ã§ããããïŒ ç°¡åãªçãïŒå©çšå¯èœãªãã¹ãŠã®æ©èœã䜿çšããŸãã
ãããã®1ã€ã¯ããã®ãããªã·ã¹ãã ãäœæããããã«äœ¿çšãããæå·åæšæºã®æ·±å»ãªåŒ±äœåã§ãã Spiegelãå©çšã§ããããã«ãªã£ãææžã¯ãNSAãšãŒãžã§ã³ãããã®ãããªæšæºãéçºããæ å ±ãåéããããããäŒè°ã§è¡ãããè°è«ã«åœ±é¿ãäžããããã«ãIETFã®äŒè°ã«åºåžããããšã瀺ããŠããŸãã NSAã®å éšæ å ±ã·ã¹ãã ã§éå¬ãããIETFãµã³ãã£ãšãŽäŒè°ã®ç°¡åãªèª¬æãèªã¿ãŸãã
æå·åæšæºã匱ãããã®ããã»ã¹ã¯ãããªãåããç¶ããŠããŸãã ç¹å®ã®çš®é¡ã®æ©å¯æ å ±ãåé¡ããæ¹æ³ã説æããææžã§ããåé¡åã®å€§èŠã«ã¯ããNSA / Central Security Serviceãåçšããã€ã¹ãŸãã¯ã»ãã¥ãªãã£ã·ã¹ãã ã®æå·åããã®åŸã®äœ¿çšã®ããã«æå·åãããšããäºå®ããšããèŠåºããä»ããŠããŸãã
NSAåé¡åã®ã³ã¬ã¯ã·ã§ã³ïŒãæå·ã®å€æŽã
ãã®ããã«éåžžã«åŒ±ãã誀åäœããŠããæå·ã·ã¹ãã ã¯ãã¹ãŒããŒã³ã³ãã¥ãŒã¿ãŒã䜿çšããŠåŠçãããŸãã NSAã¯LonghaulãšåŒã°ããã·ã¹ãã ãäœæããŸãã-ãããŒã¿ãããã¯ãŒã¯æå·ããã³ããŒã¿ãããã¯ãŒã¯ã»ãã·ã§ã³æå·ãã©ãã£ãã¯çšã®ãšã³ãããŒãšã³ãæ»æããã³ããŒå埩ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãµãŒãã¹ãã å®éãNSAã®Longhaulã¯ãããŸããŸãªã·ã¹ãã ã埩å·åããæ©äŒãæ¢ããœãŒã¹ã§ãã
NSAã«ãããšããã®ã·ã¹ãã ã¯ãã¡ãªãŒã©ã³ãå·ãã©ãŒãããŒãã«ãããã«ãã©ã¹ãŒããŒã³ã³ãã¥ãŒã¿ãŒãšãããã·ãŒå·ãªãŒã¯ãªããžã«ãããªãŒã¯ãªããžããŒã¿ã»ã³ã¿ãŒã®é»åã䜿çšããŠããŸãã ãµãŒãã¹ã¯ãNSAãããŒã¿ãååããããã«äžçäžã«å±éããŠããç§å¯ã®ãããã¯ãŒã¯ã®äžéšã§ããTurmoilãªã©ã®ã·ã¹ãã ã«ã埩å·åãããããŒã¿ãéä¿¡ã§ããŸãã ãã®æ¹åã§ã®éçºã®ã³ãŒãåã¯Valientsurfã§ãã GallantwaveãšåŒã°ããåæ§ã®ããã°ã©ã ã¯ãããã³ãã«ãããã³ã«ãšã»ãã·ã§ã³ãããã³ã«ãã¯ã©ãã¯ãããããã«èšèšãããŠããŸãã
ãã®ä»ã®å Žåãã¹ãã€ã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããŠãã«ãŒã¿ãŒæ§æãã¡ã€ã«ããæå·åããŒãçã¿ãŸãã DiscorouteãšåŒã°ãããªããžããªã«ã¯ããã¢ã¯ãã£ãããã³ããã·ããªæ¹æ³ã§ååŸãããã«ãŒã¿ãŒæ§æããŒã¿ããå«ãŸããŠããŸãã ã¢ã¯ãã£ããªåéãšã¯ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ãžã®ãããã³ã°ãŸãã¯ãã®ä»ã®äŸµå ¥ãæå³ããããã·ããªåéãšã¯ãNSAã«ãã£ãŠå¶åŸ¡ãããç§å¯ã®ã³ã³ãã¥ãŒã¿ãŒãä»ããŠã€ã³ã¿ãŒãããçµç±ã§éä¿¡ãããããŒã¿ãåä¿¡ããããšãæå³ããŸãã
Five Eye Allianceã®åŸ©å·åäœæ¥ã®éèŠãªéšåã¯ãåã«å€§éã®ããŒã¿ãåéããããšã§ãã ããšãã°ãããããSSLãã³ãã·ã§ã€ã¯ã¡ãã»ãŒãž-SSLæ¥ç¶ã確ç«ããããã«ã³ã³ãã¥ãŒã¿ãŒã亀æããæ å ±ãåéããŸãã æ¥ç¶ã¡ã¿ããŒã¿ãšæå·åãããã³ã«ã¡ã¿ããŒã¿ãçµã¿åãããŠããŒãååŸãããšã埩å·åããããã©ãã£ãã¯ã®èªã¿åããŸãã¯æžã蟌ã¿ãå¯èœã«ãªããŸãã
æåŸã«ãä»ã®æ¹æ³ã圹ã«ç«ããªãå ŽåãNSAãšé£ååœã¯ãã«ãŒããã©ãŒã¹ã«äŸåããŸãïŒåœŒãã¯ç§å¯ã®ããŒã¿ãååŸããããã«ã¿ãŒã²ããã³ã³ãã¥ãŒã¿ãŒãŸãã¯ã«ãŒã¿ãŒã§ããã«ãŒæ»æãçµç¹ããŸã-ãŸãã¯é ä¿¡å Žæã«åããéäžã§ã³ã³ãã¥ãŒã¿ãŒèªäœãååããããã«ãã°ãå°å ¥ããŸã-ãã®ããã»ã¹ãæµã®åŠšå®³ããšåŒã°ããŸãã
æ·±å»ãªã»ãã¥ãªãã£ãªã¹ã¯
NSAã«ãšã£ãŠã埩å·åã¯åžžã«å©ççžåã§ãã 代çåºãšãã®åçåœã«ã¯ãå éšäœ¿çšã®ããã®ç¬èªã®ç§å¯æå·åæ¹æ³ããããŸãã ãã ããNSAã¯ãç±³åœåœç«æšæºæè¡ç 究æïŒNISTïŒã«ãä¿¡é Œæ§ã®é«ãæè¡ãéžæããããã®ã¬ã€ãã©ã€ã³ããæäŸããããšãæ±ããããŠããŸãã ã€ãŸããæå·åã·ã¹ãã ã®å質ã確èªããããšã¯ãNSAã®äœæ¥ã®äžéšã§ãã NISTãæšå¥šããæå·åæšæºã®1ã€ã¯ãAdvanced Encryption StandardïŒAESïŒã§ãã éè¡ã«ãŒãã®PINã³ãŒãã®æå·åããã³ã³ãã¥ãŒã¿ãŒã®ããŒããã©ã€ãã®æå·åãŸã§ãããŸããŸãªã·ã¹ãã ã§äœ¿çšãããŠããŸãã
NSAææžã®1ã€ã¯ãIAEAãæšå¥šããæšæºã«äŸµå ¥ããæ¹æ³ãç©æ¥µçã«æ¢ããŠããããšã瀺ããŠããŸã-ãã®ã»ã¯ã·ã§ã³ã«ã¯ãTop SecretããšããèŠåºããä»ããŠããŸãããAdvanced Encryption Standardãªã©ã®é»åã³ãŒãããã¯ã¯åºãæ®åããŠãããæå·æ»æã NSAãææããå éšãããã³ã°ãã¯ããã¯ã¯å°æ°ã§ãã TUNDRAãããžã§ã¯ãã¯ãé»åã³ãŒãããã¯ã®åæã«ããããã®æçšæ§ãå€æããããã®æœåšçã«æ°ããææ³ã暡玢ããŠããŸãã
ã€ã³ã¿ãŒãããã«ããµããèšå€§ãªæ°ã®æå·åã·ã¹ãã ãNSAãšãã®åçã«ãã£ãŠæå³çã«åŒ±äœåãŸãã¯ãããã³ã°ãããŠãããšããäºå®ã¯ãWebã®ã»ãã¥ãªãã£ã«äŸåãããŠãŒã¶ãŒããçµç¹ãäŒæ¥ã«è³ããŸã§ãã€ã³ã¿ãŒãããã«äŸåãããã¹ãŠã®äººã®ã»ãã¥ãªãã£ã«å€§ããªè åšããããããŸãã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã ãããã®ãç©Žãã®å€ãã¯ãNSAã ãã§ãªãããããã«ã€ããŠç¥ã人ãªã誰ã§ã䜿çšã§ããŸãã
ã€ã³ããªãžã§ã³ã¹éšéèªäœããããååã«èªèããŠããŸãã2011幎ã®ææžã«ãããšãæ¿åºéä¿¡ã»ã³ã¿ãŒã®832人ã®åŸæ¥å¡èªèº«ãBULLRUNãããžã§ã¯ãã®åå è ãšãªãããã®ç®æšã¯ã€ã³ã¿ãŒãããã»ãã¥ãªãã£ã«å¯Ÿããåºç¯ãªã¹ãã©ã€ãã§ãã
2人ã®èè ãJacob AppelbaumãšAaron Gibsonã¯Torãããžã§ã¯ãã«åãçµãã§ããŸãã Appelbaumã¯OTRãããžã§ã¯ãã«ãæºãã£ãŠãããä»ã®ããŒã¿æå·åããã°ã©ã ã®äœæã«ãé¢äžããŠããŸãã