U.S. surveillance laws have proven ineffective at countering terrorism
theprivacyissue.com
theprivacyissue.com
tl;dr; Franklin was defending government spending on defense
I'll update the tldr with two quotes
> It is a quotation that defends the authority of a legislature to govern in the interests of collective security. It means, in context, not quite the opposite of what it's almost always quoted as saying but much closer to the opposite than to the thing that people think it means.
> And maybe it doesn't matter so much what Franklin was actually trying to say because the quotation means so much to us in terms of the tension between government power and individual liberties. But I do think it is worth remembering what he was actually trying to say because the actual context is much more sensitive to the problems of real governance than the flip quotation's use is, often.
I think the second quote is important, because sayings change over time and the meaning they hold changes too. That is the progression of language.
Franklin was actually supporting the authority of government to act/govern in the interest of collective security. [1]
[1] https://www.npr.org/2015/03/02/390245038/ben-franklins-famou...
But bureaucracy is just so evolves that it perpetuates the problem it was created to solve. Trivially, those agencies which reliably have achieved their goal get disbanded as no more needed, the only remaining in the long term are such whose goals are elusive.
This is how well-intentioned, honest people try to grab more power for their agency, because it seems to help achieve that elusive goal.
(To say nothing of people with less integrity in a position of power.)
Or maybe just saying "as the commonly used phrase goes" is better.
Of course, blatant misattribution is also so dang common that it seems better to me in general to cite some kind of context or whatever. Plus (for me, a prior editor) use of quote marks typically implies verbatim, citable quotation, so that's a factor whether the attribution is "safe", as you suggest.
Not to criticize anything here at all; I just wanted to throw in some of that sweet sweet context!
Meanwhile the vast majority of what the TSA and a significant-enough chunk of what security agencies do is pure theater, in exchange for a significant headaches and loss of privacy/dignity/time/etc of citizens who fund and technically support such organizations - and everyone else visiting the country as it deters plenty of tourism and business travel.
The FAA still systematically pulls medicals for mental health issues rather than allowing treatment. If your livelihood and a couple hundred thousand dollars of debt depend on it, you'll conceal extreme depression just fine. Pilots are terrified of getting help and an absurd proportion of the community is suffering from depression as a result.
because that seems ridiculous
Well, no, actually it was impossible to get into the cabin from outside long before 9/11 (in fact, I think since the 70’s). The hijackers smuggled box-cutters on board and used the box cutters to kill stewardesses until the pilot agreed to open the door - after which they had full access to the plane.
That's the problem -- that there was a door that could be opened. It seems to me that there shouldn't be. The pilots should have their own separate entrance from the exterior of the aircraft.
Also, the pilots occasionally need to be able to get back to the cabin for troubleshooting in emergencies and to use the toilet/crew rest.
Toilet, crew rest, and meals can be provided in the pilot's cabin. Troubleshooting may be a good point, but perhaps it would suffice to have a tech in the non-cabin portion of the plane.
In any case, it was just a thought. This is not an issue that I actually have a strong opinion about either way.
I don't mean to come across as condescending, I believe that as long as we spend our time talking about possible "solutions" to what-if, abstract problems, without addressing the real issues, we are just going to waste our time.
Also, we do spend an enormous amount of money on safety in the US. Why do you think the absolute cheapest new cars in the US are two to four times as expensive as new cars in countries that don’t have the same kind of safety standards (e.g. Mexico or India)? And because of the tort system, businesses spend untold amounts of money making their facilities and products safer in general.
It would be a bit distracted to worry about chemical X when there are way more pressing issues on where to shine the limited spotlight of attention. Let those who are concerned with health speak to the spending of precious attention, and let those who are concerned with X discuss the loss of focus on X. Somewhere people will switch sides and a meta conversation will form in terms of resource allocation and framing.
I think they have to be able to get in and out to use the bathroom, though. And get some food.
Also, they don't forbid you from bringing an abrasive stone through with which you can make a shiv out of LITERALLY ANYTHING.
What's changed is twofold. Physical access to the cabin, and the knowledge that no pilot will ever let another soul onto the flight deck no matter how many people they can shiv to death.
Ugh. It's a fine article, but I worry the VPN industry's constant mis-selling of services under the banner of privacy will eventually taint the message.
There are a lot of VPNs with really bogus claims on their websites but I didn't notice anything appalling about this.
One can argue that IPs and ports matter, but if all the IPs you visit are in AWS (and their ilk) over 443 (including real time communication protocols), it becomes meaningless.
> Between TLS and DNS over HTTPS, the number of things an ISP can reliably discern from your traffic is becoming vanishingly small.
A) While encryption is commonplace, not everything on the web is encrypted. The most recent stats I can find[0] say that about 3-10% of common web traffic is still not encrypted. If you're browsing more interesting parts of the web (ie, old forums and independent sites, and not just Facebook/CNN) your stats are probably worse.
B) Even if all of the websites you visit are fine, a nontrivial portion of native apps also don't use encrypted endpoints, because unlike on the web there were never native warnings or lock icons in a URL bar to force them to make the change.
C) Even if the server is using TLS, there are numerous attacks based around measuring packet delivery times and request sizes to figure out exactly which static pages of a domain you're visiting. This is why Linux package managers have widely dismissed HTTPS -- it provides no privacy for their specific use-case, because anyone can figure out what you're downloading just by counting how many bytes get sent to you.
D) So you just turn on DNS over HTTPS, right? Sounds good, except pretty much none of your native apps or dedicated devices like game consoles, e-readers, and smart-home appliances support it unless you're handling it on the network level. Even if you are doing DOH on your router, it's not uncommon for dedicated devices to bypass your DNS settings entirely. Even Google is guilty of this, for a long time you could not set a Chromecast to use a custom DNS server.
E) Even if you have DNS over HTTPS, you still need to worry about SNI, and encrypted SNI still has relatively low adoption on the web outside of industry-leaders like Cloudflare.
----
But let's assume that none of the above applies to you. You're connecting to a site that's using TLS 1.3 and supports encrypted SNI. You're using DNS over HTTPS. In that scenario, knowing the IP/port of the server you're connecting to can still be good enough to unmask the domain.
You do bring up this point, but then you kind of just skip over it.
> One can argue that IPs and ports matter, but if all the IPs you visit are in AWS (and their ilk)
But they're not. Yes, if every single site I visited had the same IP, I'd be fine leaking that information. But they don't all have the same IP. I visit plenty of sites that are being hosted on independent hardware, on Linode servers, and so on. Servers with unique, static IPs are not uncommon.
Not only is this bad advice in the sense that it just isn't true, it's also bad advice because it's tying security/privacy to centralization. We want people to host their own stuff online, we don't want everyone to be on AWS and Google Cloud. We want diversity of hosting.
----
Finally, although I understand you're only talking about ISPs above, it's also worth noting that the point of a VPN is not just to obscure your traffic from your ISP, it's also to obscure your IP address from the sites you visit. That's also an idea that gets regularly dismissed by a vocal subgroup on HN, who are apparently of the opinion that the entire TOR project is just a waste of time because IP addresses don't actually matter.
VPNs are not a perfect solution. They're arguably not a even a good solution. But the problem that they're trying to solve does exist. There are reasonable, strong arguments to make against VPNs: that they aren't magic, that they're deceptively marketed, that shifting trust can be problematic. "IP addresses aren't worth protecting", or "DNS is fine already", are not reasonable arguments.
Perhaps, but what about all the traffic that doesn't go to AWS or use port 443? The vast majority of my traffic doesn't do those things, and very probably won't within my lifetime.
> I tried to write a more honest VPN commercial. The sponsor wasn't happy about it.
So you've transferred the lack of privacy from one company (your ISP) to another (your VPN vendor). Heck - look what happened to Onavo - facebook bought them and reaped a treasure trove of private browsing habits.
I've used self-hosted VPNs running on AWS LightSail to have privacy from wifi operators I didn't trust, but it doesn't work for higher levels of surveillance than that.
For example, if your VPN runs on a server with a dedicated or at least relatively persistent IP and you're the only one using it an upsteam of the server like an ISP or a network of sites could track you cross-site and use that data to deanonymize.
I would of course prefer a zero-trust solution, but absent that, can I at least avoid giving my data the companies that are openly spying on me right now? At least until we figure out how to make Tor scale better for normal usage like streaming/games?
Transferring trust is definitely problematic, but it's also a thing that we do basically every single day all the time, and it's only in the context of VPNs where I see people suddenly advocating that anything less than a zero-trust solution is useless. Zero-trust solutions are the exception when we deal with companies. Most of the time we're just moving/centralizing trust.
I never really saw that as a VPN's main purpose. Far from cutting out the ISP, you now have 2 ISPs. One that can see "everything" and another that can make inferences about your habits by analyzing your encrypted traffic.
The job a VPN actually does really well is hide your IP from sites and services that you visit which reduces the information they have available with which to track you.
The problem is the lack of heavy-weight counter-balance, always demanding more privacy, fewer laws, and less firepower. The best we've got is "the status quo" and a few non-profits (that thankfully are punching way above their weight class).
Without such a counterbalancing agency, each small gain by law enforcement rarely reverts, so rather than oscillating between a bit too much freedom and a bit too much policing we have an arrow moving us steadily toward a police state.
If you support anything but paying lip service to checks and balances then you would support restricting US government's surveillance powers and requiring a warrant in many more instances than it is required today (almost never when it comes to the NSA, and now the FBI and other agencies can warrantless look at your data before going to court, too, thanks to the latest FISA extension).
Britain and France had geopolitical and business interests in the Middle East since the 18-19th century. America since the 20th, when oil suddenly had all the spotlight.
Fundamentalists are convinced that "the West" is the Devil on Earth. No political force can pacify fundamentalists nor avoid future generations.
Most of the problems in the Middle East, at least with regards to them hating the US, are because the US did something to directly make them hate the US. Iran, Iraq, and Afghanistan - at least in their current iterations - are all problems the US created. This is barely even beginning to describe the list of atrocities the US has committed against other countries.
The US has terrorists because the US creates terrorists, sometimes from us terrorizing other countries that are too insignificant for the world to take notice.
If you think I'm being hyperbolic, look into the history of US drone strikes just for a very recent example of the US leveraging its military superiority to decimate other countries. What's interesting is it gets worse regardless of the president.
On a grand historical scale, the Powers That May at any given point in time become the main offender against those having something of value. Next time it'll probably be China (beginning with the "Security Theater" [1] in Xinjiang).
[1] https://www.schneier.com/essays/archives/2009/11/beyond_secu...
What change? Why don't you let them effect those changes?
The article: Surveillance fails to catch terrorist.
Your argument: Without surveillance we cannot catch terrorist.
My question: How are we catching them now? How did we catch bad actors and saboteurs before surveillance?
https://en.wikipedia.org/wiki/Terrorism_in_the_United_States...
After September 11, the typical number of deaths from terrorism in a given year was...0, give or take a few, with a disconcerting uptick since 2013. Great, our efforts to curb terrorism are working!
From 1975-2001, the typical number of deaths from terrorism in a given year was...2. Wait, the massive surveillance state has saved 2 lives a year? What? We saved more lives by posting a guard at the Caltrain tracks in Palo Alto to keep people from killing themselves.
By the numbers, terrorism just wasn't a problem, because rational people don't blow themselves up to make a point. Mentally ill people do, and a significant number of mass shootings are not counted in the terrorism statistics but actually kill far more people. But by making terrorism into a big bogeyman that's going to kill you, it feeds into the interests of the media, of the state, and of the military-industrial complex, and so there are a lot of powerful forces shaping the discourse around terrorism that aren't necessarily reflective of reality.
Suppose I told you that taking bazookas away from people that live in the city prevents bear attacks? You might say that there aren't bear attacks in the city anyway, which would be true, but you couldn't prove it one way or another. Who knows, maybe there would have been one bear attack if people ran around with bazookas shooting up the nearby forest.
Now add in the complexity that terrorism is more like a rate than a yes/no question. What if I told you that taking away bazookas in the city reduced the crime rate? Well, the crime rate in many cities has decreased, but how are those two related? Once again, we're left with a statement that might sound good to some and bad to others -- and no way to reasonably discuss it.
The only thing we can say with certainty is that no matter what we do, terrorism will continue exist. We can never eliminate it no matter how hard we try. So unless we want each new terrorist act to wreak havoc with massive changes on our societies, we're really talking about trade-offs here. How much stuff do you want to give away for a 50% reduction in terrorism? And once you come up with that answer, how would you know if your giving those things actually was the thing that reduced it?
It's one thing when a pubic discussion has reasonable people talking about the various sides. It's another thing entirely when we start injecting these semantic landmines into our conversations. I'm not saying you're wrong or right; I'm saying there is no way to know.
When Sept 11 happened the popular meme for why we were attacked was "Because they hate our freedom." On a strategic level, they're doing a dramatically good job at winning: look at how much our freedom has been curtailed since then. And they can do it without touching an American; rather, the fear of what they might do provokes the U.S. government into destroying our freedom for them.
(A secondary goal for Osama bin Laden was to bankrupt America, something they are also winning at: since 2001 the U.S. national debt has grown from $6T to $23T.)
You are totally right of course, but the public "debate" around these kind of issues is so emotion-driven that this line of questioning is never explored. Humans generally want someone in power over them that will grant them safety and security, and a sense of certainty that nothing bad will happen to them. Any argument that relies on probability and the idea of trade-offs will never be effective in the public square of a democratic society
Personally, I'm willing to accept a level of risk from terrorism and crime if it means that I get to live my life the way I want to without being constantly monitored by government.
Regarding checks and balances, it's extremely hard to have robust authorization when the group calibrating and performing the authorizations is the same group or adjacent to the group who wants to look at the data. To do it well you need true, apolitical, independence between gatekeepers and users, and users can never be in possession of the actual data because access control can be easily bypassed if this is the case. We have never had that in this country, countermeasures against misuse always seem to be non-transparent and policy based rather than technical (ie secret courts and warrants that no one can actually audit), and data is repeatedly misused over and over with no consequences (eg parallel reconstruction, people spying on partners, people spying on celebs, etc).
I can embed standard EXIF metadata into an image and send it to someone's facebook wall. You think NSA is looking at that?
It's not that hard.
The reason is simple: terrorists and bad actors assume they're being surveiled, and take countermeasures, and those countermeasures are far more effective than the surveillance. Anyone with moderate technical knowledge can use GPG and Tor. It's not rocket surgery.
The people caught by surveillance are for the most part uneducated young men of color who are driven into low-level drug dealing by poverty, and anyone who thinks that putting these people in jail is an effective measure against drug addiction is willfully ignoring the evidence.
There are alternatives:
Not that other countries couldn't also look to Germany's example, but that would require trans-national empathy so LOLno.
It's about control.
Security is just how it's sold to the public, the politicians, etc.
This article links to a report that gives a number for terror incidents and how many were foiled.
You can see a map here: https://www.typeinvestigations.org/domesticterror/ which talks about the incident, and in the case of foiled incidents, links to something like court proceedings. This doesn't necessarily show clandestine operations led to foiling them vs regular police work, though...
Seems to say that surveillance does work, but that we're perhaps surveilling the wrong people/in the wrong proportions. It could be consequence of homegrown terrorism being, errr, homegrown, which therefore entails the much more legally tricky surveillance of American citizens. Islamic terrorism tends to be funded/trained/orchestrated abroad, where collaborators don't enjoy the same freedoms from surveillance.
> "The patchwork of U.S. surveillance laws has proven ineffective at countering terrorism"
Where is the proof? I can not find it in the article.
The claim is that "sacrificing liberty is providing us more safety" __not__ "our sacrifice of liberty has been ineffective at providing more safety." The latter statement comes from the lack of proof from those that carry the requisite burden. The former claims were made when liberty was initially eroded. Now that we have had time and calmed down people are asking "was it worth it?" and no one has provided a compelling "yes, here's (with evidence) why".
The problem is that this article, and the resopnses to it, are focusing on the wrong thing: The efficacy of violating ones consitiutional rights should have no bearing on wether or not that violation is legal.
Also, nobody is born a terrorist. They're overly fixated on catching terrorists instead of preventing terrorism altogether. Domestic crime, including terrorism, is the result of a broken education system. If you want to fix domestic terrorism, fix education, fix mental health, fix life in general for US citizens, and a lot of problems will quite literally magically disappear.
- Number of gun deaths in the US in 2019: 15381
- Number of mass shooting incidents in the US in 2019: 434
- Number of deaths actually reported as being due to "terrorists" in the US in 2019: 0
For instance: The government goes after Islamic terrorists and Mexican illegal immigrants. So what to complain about? Mix cause and effect to pose the illegal immigrants as targeting based on race. Or pose the extremist religious as vulnerable Muslims, targeted on religion. Remove their status as far away from the cold-hard reality, so you can claim racism and prejudice and use that to cripple surveillance. But the suspect is a "citizen"! All weasel words to stay away from the real dirt. Let's go after the atheists for counter terrorism, so we don't discriminate in the eyes of the ACLU...
Then the "ineffective against terrorism"-claim. This can't be supported, because no clear numbers/cases are known. Then conflate laws against terrorism with actual actions against terrorism: Sure, no law directly contributed against countering terrorists, but the surveillance certainly did. Thanks NSA for passing along information to my country many times, so we could capture really dangerous people before they could strike.
Anti-terrorism is also a red herring for surveillance efficiency. Surveillance predominantly used for other national security purposes, such as counter intelligence, foreign intelligence, border safety, crime fighting, and even economic espionage.
Sure, posing any immigrant as a bad hombre, potential MS-13 gang member, selling your children fentanyl-laced drugs, is ridiculous. But the other side of that same coin is posing bad people as vulnerable undocumented citizens who are being targeted on race. It does not do justice to the situation on the ground.
The cold-hard reality is that states who have established a system of domestic surveillance have sent millions of their own citizens to crematoriums.
Sane nations have destroyed your political faction back in sixties.
Pro-communist, race chauvinists who look up to Mao for inspiration were thrown in the garbage bin of history, and thank god for that.
Very fortunately, America of today is not Cambodia, nor Laos, and you all have to thank Rockefeller commission for grinding the legacy of Allen Dullest to dust
It is intellectually dishonest to pose the effort of governments to combat illegal immigration as a targeting of people based on race. It is a sensitivity trap that shuts down our rational faculties. Yes... all religious extremists are also religious. Most immigrants have a different race. Yes, being an undocumented immigrant makes you vulnerable. But deserving of coddling, because they happen to also share a protected variable? No.