As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.
As an aside I am finding it really difficult to delete my iCloud account, in fact it seems that is impossible.
If they haven't cracked your European email provider, then they're not doing what we pay and order them to do.
The difference is that European email providers are not cooperating, because they aren't obliged by your laws, whereas US companies are not only obliged to comply with requests, but they are also coerced to keep it a secret.
> ... then they're not doing what we pay and order them to do
That's a good thing to know, plus this is reason enough to pressure our governments and companies to not buy into US products or services. And in case you haven't noticed, this has tangible effects already, as fear of industrial espionage is spreading in big companies like fire and I've noticed this first hand in the German companies I'm in contact with. On the negative side, the US is positioned as the steward of the Internet and because your government fucked things up so badly, this is the perfect opportunity for the other countries to balkanize the Internet, to build firewalls, etc.
So I hope you're happy about how your taxes are being spent.
The NSA doesn't need cooperation. It can pwn sysadmins, plant covert operatives, and backdoor equipment in transit (including foreign-made equipment, so long as US intelligence can influence the shipping carrier, for example by recruiting employees or hacking ancient legacy software). If it can't, then it can pwn the other side of the conversation, or watch the SMTP in cleartext through a submarine-tapped undersea cable.
Disband the NSA and some other agency, some other country, will do the same thing.
You're bikeshedding. End-to-end encryption with HSMs and trusted execution environments everywhere, always. Verifiable, deterministic builds. A genuinely trustworthy, decentralized PKI. Better software engineering security practices, a professional barrier to entry, and an ethical system (ala the Bar or medical boards) with teeth that will reliably eviscerate people and companies who write and run irresponsibly sloppy code.
The cat's not going back in the bag because you avoid the US. Fighting over which service providers you send cleartext through, whose hard drives your unencrypted data sits on, who has the power to MITM you, is a waste of time and a distraction from the real challenge of developing and adopting security systems and practices that make doing what the NSA is doing actually difficult.
But of course it does. Security is not a black and white issue, but rather a matter of cost. And the fact is US companies are much easier and more cost effective to crack because they can be (legally) coerced and nobody has unlimited resources, not even the NSA.
> Disband the NSA and some other agency, some other country, will do the same thing
This is one of those logical fallacies that keeps popping up. So we should bend over and take it like a man, because if it's not the NSA, then it will be somebody else. Even if you're right, bad actors in society should get punished, otherwise they'll never learn. And indeed, it doesn't seem fair to punish US companies, many of whom really want to be good and faithful for their customers, but I've seen many signals that the american public approves and finances this behavior, which includes the above comment and the US government never apologized (to us, foreigners), therefore avoiding US services and products can become a matter of necessity.
> The cat's not going back in the bag because you avoid the US.
Yeah, but you see, I'm not an US citizen so I don't even get to vote on your laws and your government has made it clear that when it comes to foreigners then everything is allowed. And we do have intelligence agencies and they are cooperating even with the NSA and so on and so forth, but here there is no behemoth like the NSA is. And as an EU citizen at least I would have ways to fight it.
> developing and adopting security systems and practices that make doing what the NSA is doing actually difficult
Only a software developer would end up thinking that all political and social issues can be solved with technology. The world doesn't work that way. You want cryptography? It will eventually get outlawed and there is already precedent in the US.
Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys.
So as long as you trust the company, the country it's in is not relevant, at least for the situations outlined above.
Laws can and have been written that require companies to gather data.
> Similarly, laws cannot force a company to divulge encrypted data if the company does not hold the encryption keys.
Laws can and have been written that require companies to use weaker or broken encryption.
Apple has thus far been steadfast in resisting this sort of activity and in advocating against any such laws.
So for me at least, this is behavior that is worthy of trust.
Court rulings and legal authorisations to conduct surveilance can and have ... you guessed it ... been kept secret
Source? Example? I don't know an example of this. (At least in the US)
https://www.schneier.com/blog/archives/2015/03/can_the_nsa_b...
http://gizmodo.com/nsa-paid-security-firm-10-million-bribe-t...
Not just that. Laws can (and probably have been) written that require companies to gather data and to explicitly lie about it.
Maybe I'm dense or naive, but I don't think there's any precedent for that. A gag order is one thing (and there are certainly places for it), but forcing someone to lie would hopefully violate the First Amendment.
It's well know about.
Trusting the company has nothing to do with it - they could be legally compelled to do so in a secret court, and gagged with a NSL to keep them from revealing such an order. Sadly that's the reality we now live in.
In theory Apple could modify iMessage to MITM the key distribution server and enable eavesdropping. The only way to protect against that is to provide in-person validation mechanisms so users can directly compare keys. I hope they add such a thing, not that 99.99999% of their users would ever use it.
As far as the US legal system goes you'd need positive law to enforce wiretapping requirements. Courts (as a general rule) can't issue orders to force Apple to write new code or modify their silicon design to support something the government wishes it could have. Given the way SCOTUS has been approaching cell phone privacy I'm not sure such a law would pass muster.
Basically, unless they let me see what's happening with my data by allowing me access to the code, I can't and won't trust them.
Infiltrating foreign servers, installing backdoors and such don't require any warrant or court approval.
- allows for "reconnaissance" on external networks, including breaking encryption or forcing targets to divulge keys. This "reconnaissance" apparently includes installing sniffers or data probes.
- allows for untargeted data collection on wired networks (including cell phone towers)
- has provisions for forcing data transit stations (including ISP's, but also AMS-IX) to comply with requests.
Only English source I've been able to find with a quick search is https://blog.cyberwar.nl/2015/07/dutch-intelligence-bill-pro...
At least in theory, the NSA could allow a compliant US business to be secure. If the NSA could not get data from a foreign business the easy way, I'm sure they would get it the hard way.
Ta-da! Both the marketing and the NSA are happy as clams.
I agree, like Lavabit... Lavabit had all the best intentions but in the end the law screwed them over anyway.
Of course Apple has a lot more power than Lavabit, so it's nice they are taking this standpoint and being resistant. Hopefully they can contribute to a positive change.. Anyways at least they are trying, something i haven't seen from other big companies, like Google https://en.wikipedia.org/wiki/Criticism_of_Google#Privacy
Other companies should take this as an example. (Only problem: many other companies likely wouldn't want to tell in plain words how broad they are gathering and aggregating your (my) data)
"We don’t build a profile based on your email content or web browsing habits to sell to advertisers" but we do build profiles (bonus points for insinuating competition sells your information)
"we don’t read your email or your messages to get information to market to you." - but we do read and index your emails and messages, only to make our services and devices 'better' - by our definition
The sentences are built to sound like the italicized parts are not there, yet they totally change (negate) the meaning.
If I were a murderer, I could say "I do not kill men to eat their livers" and it would be 100% true, but it sounds like I'm not into killing at all.
1. Is that the word? Not a native speaker