Yahoo Announces Public Disclosure of National Security Letters
yahoopolicy.tumblr.com
yahoopolicy.tumblr.com
I wonder how the exchange takes place? There's no mention of encrypted mail or anything just an additional note that regular mail and non-secure fax are not secure enough.
They also seem to have a template of sorts as indicated by the day(s) and the phrasing when it comes to accounting periods vs. 1st to 1st.
I wonder if you can forge (or possibly man in the middle) such a request (there's no digital signature of the letter I suppose). You'd need to set up a fake agent persona with phone number and fake signature. For a criminal organization that doesn't seem to be an unreasonable afford.
Using fake subpoenas to dox people on IRC seems to be a regular thing, I don't see why not NSLs. (Besides the fact that NSLs might actually receive some scrutiny, so they're probably the inferior choice there)
Most people will just comply straight away.
https://www.eff.org/cases/archive-v-mukasey
https://www.eff.org/document/national-security-letter-intern...
Yahoo's claiming "This marks the first time any company has been able to publicly acknowledge receiving an NSL as a result of the reforms of the USA Freedom Act." -- which is kind of true, in that IA got one released before the reforms!
This is entirely too pedantic though, and it rather upsets me that people feel the need to down vote this.
So apparently the same people, who gag you, sometimes at their discretion may remove the gag. The only thing the law requires is for them to consider doing that.
I'm not sure if they have to be reapproved by a judge each time. If that's the case, then on average it seems like you'd have greater churn on the letters. And even if there's a near-100% approval rate while investigating, it seems harder to argue to a judge as the years go on.
It won't help if Edward Snowden was the target of your letters, of course.
Rule of law can help as well as hinder.
Maybe there's some sort of cooperation with the two in Charlotte as well.
Yes.
Am I correct in assuming that if done improperly the content underneath can be reconstructed?
All you have to do in your initial transparency report (before receiving any NSLs) is to just straight-up say "We have received zero NSLs. If in the future we only indicate that we have received a possible range of NSLs, that means we have recieved at least one NSL".
It's already obvious to most people, but would explicitly stating that to your users (before actually receiving any NSLs) be "pre-contempt"?
There's no problem with the proper statement though, the problem is when you follow through with it.
Anyway, typewriter is not a bad idea, probably more secure than any computer with internet connection or USB port ;)
reminds me of Special Agent Force. :P
Just disclose it already.
This is not an act of civil disobedience, FBI let them release this information.
> Note: The letters we released have been redacted to protect the identities of the FBI agents involved in the investigations, our own personnel, and the Yahoo users affected by the NSLs. The affected users received notice of the NSLs directly from us under our User Notice Policy.