Ask HN: Suppose that the PRISM slides are made up. Why does the gov play along?
2 comments
http://www.nytimes.com/2013/06/08/technology/tech-companies-...
New York Times tries to explain the difference between the Washington Post's report and the companies' denials
New York Times tries to explain the difference between the Washington Post's report and the companies' denials
My theory is that the slides will eventually turn out to be a hoax, and they are just trying to raise the ppls' privacy-invasion tolerance levels, so that they can actually implement it later on.
The other scenario is passive listening on the backbone, and working from the captured data. Nowadays everyone uses SSL, so they would need to decrypt it. Let's suppose that they have no magic, and they play by the same rules as us. In that case the only feasible way is somehow obtaining the private keys of the companies and using that to decrypt the traffic, however for example in google's case the private keys won't do any good, because (if I understand everything correctly) Google uses the Diffie-Hellman key exchange algorithm for its SSL connections which makes passive mitm impossible: https://news.ycombinator.com/item?id=5843223
Active mitm is very unlikely, because that could be detected.
And I have ran out of possible scenarios. The only remaining scenario is that all this is made up for some reason. My question is: What could be that reason?