← Back to context

Comment by OutOfHere

8 hours ago

Huh. When you don't use a man-in-the-middle service, you don't have this problem. When you host on a cloud vendor, you don't have this problem because you control the HTTPS certificate and don't leak it to the MITM. The assumption as such seems silly to me.

Your DNS lookups and IPs in use provide a lot of info. It's not always the data inside an encryption layer that is the most important.

That said, these are US companies subject to FISA court orders and NSLs or National Security Letters. If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to. Any idea that your data is protected because you're not even using a provider WAF or doing TLS termination for load balancing is a fantasy.

  • > Your DNS lookups

    I control which DNS server I use. It is not relevant to the matter at hand.

    > If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to.

    You're confusing bulk data collection with highly selective court-ordered data collection. The two are not alike. Attempting to equate them is a dumb attempt at deception on your part. There is no obligation for a firm to share bulk web data with the NSA.

    • > Please. I control which DNS server I use.

      Which is easily sniffable, re-routable, and spoofable unless using DoH/DoT. Those lookups are plaintext. Keep in mind I'm talking about your cloud endpoint.

      > It is not relevant to the matter at hand.

      Metadata is relevant enough for the US government to drone strike, and relevant enough to issue a collection warrant if one were... desired.

      > You're confusing bulk data collection with selective court-ordered data collection.

      This is both bafflingly naive and dangerously arrogant.

      Just one example, look up FISA Section 702. It does not require a traditional warrant to intercept data. To further this avenue for you, look up the 2024 congressional expansion of Section 702 (via RISAA). This was explicitly done to allow a much broader scope of classification and forced compliance with US intelligence, with extremely limited oversight, and a far reach (they were getting audit fatigue from submitting 702 requests, so why not just do the search and collection and have the courts deal with it later if it's a Real Problem(tm)). This collection doesn't just apply to the datacenter providers, landlords, etc now, it also applies to hardware vendors.