#Room641A

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-16

@adisonverlice it's not just re: #Governments (tho #Project2025 explicitly endorses unsactioned comms to twart attempts at #FIOA or any #accountability for that matter), but individuals or any organization:

And if #EncroChat got pwned, who's gonna guarantee @signalapp won't if it's actually secure or isn't an #InsideJob like #ANØM.

After all, both #Signal's Organization and key people like @Mer__edith are known to the authorities by more than just their legal name.

  • What's gonna prevent #Trump from doing a "bag&drag" on her or getting his goons to put a gun on,the developers' heads and force them to,#d0x all users and #backdoor everything (if they didn't already got forced to have some "#LafwulInterception" gear in a closet like #Room641A...

After all, Signal can't pull the 5th and refuse to comply!

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-27

@Andromxda @pixelcode How can you claim something you can't evidence?

It makes you look like one of those folks shilling #VPN|s that ain't logless after all...

  • I don't believe in #marketing #lies and #Signal can't (and won't) be able to evidence that they don't log shit.

At least they should be honest about things and not claim bs, cuz demanding a #PhoneNumber is just #KYC with extra steps like demanding any #SSN or other #PII. Makes them look like chinese MMORPGs that demand ID card numbers for account signups, thus #paywalling the ability to use their service anonymously...

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-27

@pixelcode @taylan @signalapp the #centralization, espechally without means to hide it's traffic via @torproject / #Tor makes it trivial to detect and track @signalapp / #Signal users.

  • Add to that the fact that Signal has #PhoneNumbers = #PII on them and the fact they are incorporated in the #USA, thus subject to #CloudAct and it's not a matter if they snitch on users but how many thousands if not millions got subopena'd to this day.

And with no self-custody of keys it's trivial to #Room641A the users if the devs get "motivated" under threat of spending the rest of theor lives in jail.

Martin SchmiedeckerFr333k@infosec.exchange
2025-03-14

To this day, I still wonder what exactly is/was behind that door #room641a

Orange door in a AT&T facility in San Francisco with room number 641A on it
Doc Edward Morbius ⭕​dredmorbius@toot.cat
2025-03-12

In Memoriam: Mark Klein, AT&T Whistleblower Who Revealed NSA Mass Spying

[W]hat Mark told us changed everything. Through his work, Mark had learned that the National Security Agency (NSA) had installed a secret, secure room at AT&T’s central office in San Francisco, called Room 641A. Mark was assigned to connect circuits carrying Internet data to optical “splitters” that sat just outside of the secret NSA room but were hardwired into it. Those splitters—as well as similar ones in cities around the U.S.—made a copy of all data going through those circuits and delivered it into the secret room.

eff.org/deeplinks/2025/03/memo

Klein provided one of the pre-Snowden disclosures of massive communications surveillance in the United States. I'd included him in an earlier toot from May 2021: toot.cat/@dredmorbius/10625139

His story also demonstrates that "surveillance state" and "surveillance capitalism" aren't separate things, but part of the same larger surveillance octopus.

#MarkKlein #Room641a #ATT #MassSurveillance #SurveillanceState #SurveillanceCapitalism

Kevin Karhan :verified:kkarhan@infosec.space
2025-01-02

@ginaintheburg could be.

#Room641A is everywhere...

#CloudAct

2024-01-29

@tek Makes me wonder if #Room641a and the likelihood of many more of them in existence, combined with centralization of HTTPS certificate control (Let's Encrypt), means that all of our traffic has been recorded for the better part of 20 years. Not to mention most web searches include URL attributes which are inherently insecure. Perhaps it's just paranoia, but I don't think the true nature of those bifurcated fiber pipes is completely understood.

Kevin Karhan :verified:kkarhan@mstdn.social
2023-10-08
Kevin Karhan :verified:kkarhan@mstdn.social
2023-08-24

@Brainclean I mean if you choose the highest end Xilinx FPGAs you can get realtime dreamcast emulation clock-cycle perfect.

It's just that you can expect to pay 5 digits per piece if you buy a roll of 500+ ...

Those things are otherwise used for realtime 100GBit/s fiber interception...

So if you'd ever get your hands on a #Glimmerglass #FiberSplitter out of #Room641A-Style facilities that is fried except said FPGA, you might get lucky.

en.wikipedia.org/wiki/Room_641

Kevin Karhan :verified:kkarhan@mstdn.social
2023-01-27

#FriendlyReminder: #Room641A is still up and running - as is the #PRISM program - to this very day.

en.wikipedia.org/wiki/Room_641

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst