In Silicon Valley, a new emphasis on barriers to government requests for data
washingtonpost.com
washingtonpost.com
I've been trying to get Chicago's mayor's office's phone records for a while now. 1.5 years, 4 FOIAs to two different city departments, state's attorney FOIA request for review, redactions left and right, a fight for AG anonymity, and a lawsuit later, I got a list of phone numbers and created [0].
The amount of pushback and bad interpretation of FOIA that prevented me, or anyone else, in getting that data was shameful. And after all of that, the judge didn't give me the FOIA suit payout since the city eventually "complied".
It's no wonder nobody actually tries to make positive change - it's just so damn hard.
[0] https://docs.google.com/spreadsheets/d/1hgG79eIr8MbkjYrCvcTR...
edit: cleaned up a wee. Also, that link's for the whole office suite, not just the room the mayor calls his office. Please don't try to come to any direct conclusions.
The first design feature of the panopticon is that any inmate can be seen by the guards at any time without his knowledge. The second equally important design feature is that the inmate can never see the guard, can never see what he's up to or who he is looking at. Or even if he's around.
In the present context this manifests itself in the above hilarious obstructionism against FOIA and open government, and more ominously in Obama's war against whistle blowers.
The judge eventually just told them to just Google the phone numbers as a check if they're public numbers. They followed with other checks, and a longish list of numbers was the result. There was one government phone redacted, but we got the name of the person a bit later, with just a name, no number.
I submitted two requests earlier to get that info and hopefully more. "Unduly burdensome" is a lame, so it has to be done in piecemeal. We'll see.
I was curious to see if your request (or anything to do with phone calls) was in the published FOIA log [0] by the mayor's office...maybe it is/isn't (I don't know who you are)...but it seems that they've been slow to update the log, with no new records since August 2015. Other FOIA logs, such as the 311 requests [1] (though not the police), seem to still be updated.
[0] https://data.cityofchicago.org/FOIA/FOIA-Request-Log-Office-...
[1] https://data.cityofchicago.org/FOIA/FOIA-Request-Log-311/j2p...
I actually got the records by a request to their IT Dept for the mayor's office's VoIP logs. They ended up getting me info from the phone's billing system, but redacted. It took six months or so of waiting for AG to agree with my arguments to unredact the records.
Chicago's lawyer then swooped in and called a technical foul... since they don't use VoIP, so the request was invalidated.
A nearly identical request later (without "VoIP") and they sent me the exact same PDF as before along with a claim of unduly burdensome to discover if the numbers were releasable or not. So then we sued.
Chicago's FOIA officers seem to be pretty good with not giving too much information out, but they slip sometimes. Some other data I have includes all of Chicago's parking tickets, including license plates, but the only reason I was able to get that was because of a slipup that resulted in the tribune getting all red light camera ticket's license plate info.
If they'd followed foia properly there, I wouldn't have been able to get license plates. That, and it would've been within reason if they rejected my request for plate info, so I'd've just moved on.
Definitely slippery slope territory, though.
If you replace "encryption" with "secure encryption", that's absolutely what's being proposed.
I've held my tongue about this through dozens of stories, and I won't harp on it again, but after the third time in this article I'm sort of snapping.
The average person is becoming increasingly security conscious, and so are small and medium sized businesses. I seem to remember that Azure was having a really hard time selling to an international audience because foreigners thought the data would be vulnerable in the hands of the US government.
As someone who doesn't live in the US and works in consulting the few years post Snowden were quite curious, with clients who previously didn't mind using cloud solutions like Amazon S3 actively refusing any architecture choices which would lead to having their data stored in the US, even if it meant greater expense.
I really do believe that not taking an approach similar to this where we use End to End encryption and companies minimise their access over their customers data as much as humanly possible can and does lead to lost business.
I thought they communicated using burner phones and not encryption [1].
[1] http://arstechnica.com/tech-policy/2016/03/paris-terrorist-a...
ps -- remember the san bernardino attacks? The attackers destroyed their personal cells and left a work cell behind. It's pretty obvious there never was anything on it. And had the fbi found anything germane, they would have trumpeted it.
http://www.cnn.com/2015/12/17/politics/paris-attacks-terrori...
https://www.washingtonpost.com/world/europe/paris-attack-pla...
If more services start to avoid storing data altogether (or at least only encrypted in a way that prevents them from accessing the data), there will be less food so to speak for the various creatures that might gravitate towards the trough.
[1] NB that the choice of words is not mine - the irony of a supreme court judge calling law enforcement and intelligence agencies pigs is kind of nice, though. ;-)
Worst part is that I currently live in Texas, and not the cool parts :p
Looks like McCarthyism is alive and well in the United States.
What’s driving Silicon Valley to become ‘radicalized’It completely removes the need to waste person-hours attempting to fulfill a "wiretrap" request, whether from a warrant or FISA-court type thing, if the request is impossible due to lack of crypto keys. And at least at present completely legal unless the US passes laws outlawing crypto.
There are precedents for that kind of thing here and there already, in Bittorrent, Bitcoin, Ethereum, Freenet, TOR... and as [1] said, SMTP.
At some point that mail has to go into storage somewhere so it can be accessed by a user/client via IMAP, and that's where the subpoena/national security letter/warrant/FISA court request will go. To whatever location the disk storage resides at.
His name is Joel Chandler and he lives in Lakeland, FL. You can Google him for more details on some of the requests he has made and lawsuits he has filed to get information.
"Heavy" encryption? Srsly?
Companies are merely doing what they need to, to be relevant outside the US