They use network taps[robust ones] to sift thru the unencrypted traffic[most email traffic and regular net traffic]...and most likely a close relationship with the SSL cert-auth roots to scrutinize the 'secure' stuff.
Anything else encrypted in place is most likely sent to Oak Ridge or there own HPC clusters and bf'd.
Defense?
AES 256 with loooooooong and strong passphrases and keyfiles. and generate your own SSL certs[4096 min]....and use VPN's which terminate out of country and don't keep logs.
I suppose that good people can make a[singular and non-violent] mistake or error in judgement which can run them a foul of the law. These people don't require reform. They are typically leaniently sentenced, pay for their mistake and move on.
I also suppose that others are more habitually and fundamentally anti-social. These people are not worth the effort of trying to 'save'. The brains have literally been wired for this behavior[over the course of many years]. They must be removed from society.
There are also those somewhere in between natural-born killer and 'busted for pot'. These people are responsible for their own personal choices. If they keep making bad choices of their own volition I have no compassion for them. [I say this from first hand experience dealing with a close relative who is a lifelong fuck-up.]
Prison is society's recourse for anti-social behavior. Does it have to be a violent and horrible place? No. The residents tend to make it that. In addition, I am against pampering in anyway, with my tax dollars, people whom I've had to remove from proper society...for anti-social behavior.
Prison is supposed to be a deterrent. My biggest gripe is that I have to pay for it at all. I support banishment or death.
It's not strange at all. If the AP's sources just disappeared, the word would be out to any future sources/marks that the AP gives up sources...but if the big bad government did this rare, but effective overreach...the spooks can still terminate the leak and the AP has plausible denial.
The CIA wants to maintain the AP's ability to lure in more leaks in the future.
This is something I've seen before, and expect more of.
Municipalities[taxpayers] paying to build out infrastructure, "mismanaging it"[then usually underfunding the administration because everyone wants 'small government', and then having the infrastructure scooped up for peanuts by a private company who makes a killing.
It's actually happening right now in slow motion in my hometown.
Physical access is god access. Admin/root is god access.
Guard them both with your life.
I fail to see how handing over control of your boot to some 3rd party who clearly doesn't have the same interests that you do is anything but a horrible idea.
Just physically secure your boxes(or VDI them) and use permissions and ACLs to do what they were designed to do[control and delegate authority].
A good first step for Microsoft, if it cares so much about security, is to stop making its users automagically admin for fogging a mirror, during new PC setup.
They use network taps[robust ones] to sift thru the unencrypted traffic[most email traffic and regular net traffic]...and most likely a close relationship with the SSL cert-auth roots to scrutinize the 'secure' stuff.
Anything else encrypted in place is most likely sent to Oak Ridge or there own HPC clusters and bf'd.
Defense?
AES 256 with loooooooong and strong passphrases and keyfiles. and generate your own SSL certs[4096 min]....and use VPN's which terminate out of country and don't keep logs.