Former NSA chief Keith Alexander has joined Amazon’s board of directors
theverge.com
theverge.com
This sounds tinfoil hat crazy, but here we are. Not so crazy now.
Man in a position to have reams of compromising intel on the current president hired by a man in an ongoing battle with the president.
It stinks no matter how you look at it. Actual criminal getting rich post crimes while Snowden who let us all know what a crook he is, is stuck in exile.
The rule of law and equality before it needs to be established.
"Bezos Taps Criminal To Strengthen Bid For Government Work"
Is about the kindest possible spin you can put on a headline for this story, right?
Either is possible.
The USA badly, badly needs a way to get better candidates for both parties. Is there anyone who thinks this is the best the Republicans have to do the job for the american people? Is ther anyone who thinks this is the best the Democrats have to do the job for the american people?
Without being able to falsify the claim, and by deferring to a claim that isn't the simplest possible explanation (he's got nothing), it makes me wonder whether other HN commentators will come to defend my "Bezos is a dirtmonger" conspiracy theory as well.
Do we feel better about that now?
It's not reasonable to assume anything about the Intel Bezos has without evidence. Could be none. Could have hard evidence of crimes of the president and many senior politicians and public servants. Could be something in between those two. All are possible and there is no reason to discount any of it in the absence of evidence.
Good on you sticking up for the world's richest man who just hired a criminal though. It's important to maintian principle regardless of the optics.
For example, here's reporting on an interview with Martin Baron, the paper’s executive editor:
Mr. Bezos holds conference calls with The Post’s leadership every other week to discuss the paper’s business strategy but has no involvement in its news coverage, Mr. Baron said. During his occasional appearances at The Post’s building, Mr. Bezos sometimes stops by a news meeting “just to thank everybody,” Mr. Baron said.
“I can’t say more emphatically he’s never suggested a story to anybody here, he’s never critiqued a story, he’s never suppressed a story,” the editor said.
“Frankly, in a newsroom of 800 journalists, if that had occurred, I guarantee you, you would have heard about it,” he added. “Newsrooms tend not to like those kinds of interventions, particularly a newsroom that’s as proud as The Washington Post.
“If he had been involved in our news coverage, you can be sure that you would have heard about it by now,” Mr. Baron added. “It hasn’t happened. Period.”
Source: https://www.nytimes.com/2018/04/02/business/media/to-trump-i...
(edited for formatting)
The advertisers react to "wrong" coverage by withdrawing support, the chief editor is very attuned so he assigns the right people to the right jobs before trouble starts, and the journalists so assigned naturally work quite sincerely. No actual orders to publish or withdraw articles need to happen.
There's got to be a natural law that, for any given situation, one can compose a scheme whereby no proof of anything would actually exist, but evil would still be done.
Easily attributable to business decisions / climate.
> the chief editor is very attuned so he assigns the right people to the right jobs before trouble starts
Staff assignment as a smoking gun? That's going to be a stretch.
> and the journalists so assigned naturally work quite sincerely
Indeed, just people doing their jobs.
Who, pray tell, is going to leak what?
In this frame, "business decisions / climate" are exactly the driving forces which perpetuate such structures and outcomes.
The banality of evil doesn't forgive laziness in the construction of hypotheses, unless you're Fox News.
To spell it out, what leak / disclosure would constitute proof of GP's belief? A memo from the WaPo editorial staff which says "Pursuant to Mr. Bezo's comments on X, please assign Y to story Z, so that reporting will be more favorable"?
And barring a plausible method of provability / falsifiability, we're in "just asking the question" rumor territory with regards to the original assertions of malice. Which, personally, seems below the level of discourse I expect from HN.
This is the extent of the "conspiracy" in Chomsky's opinion. When things like the Amazon firing of a union organizer happen, the reporter set to cover it is going to have more connections to the corporate side and a be accustomed to writing stories that will please corporate sponsors.
If a reporter is overly critical, the story will likely get a less favorable placement and that reporter won't get similar assignments in the future. There is no overt conspiracy, but there is editorial pressure.
Just being the owner taints their coverage even with no direct influence (again, we can't just pick on Wapo here either). "So Joe, want to spend our time on researching this piece critical of Amazon or one the other hundred stories?"
When you saw that happening, did you just let it slide? Where did it happen? Was the story originally about Amazon or was it just an off-topic side remark that didn't really fit in?
Why should I stop sawing this branch I am sitting on, I havent fallen yet ?
Your argument is that we can't prove the absence of a conspiracy.
Hence, a better analogy would be
"why should i stop sawing this branch? just because gravity has never left me suspended in thin air doesn't mean it can't or won't happen in the future"
Right?
Right, your news company is the only one that doesn't smell. Maybe you should adopt the motto "fair and balanced" to reflect how editorially independent and objective you are.
> Martin Baron, the paper’s executive editor:
The newspaper's editor says that he is objective? Zuckerburg also says facebook is all about user privacy. So it must be true.
Worth nothing that those reams of compromising intel on the current president only exist because the current president...
has, himself, generated reams of compromising intel.
They already publish a ton of heavyweight criticism... and I think there is no new information that could persuade those that still support Trump.
1. The CIA illegally collected intelligence on Donald Trump prior to his election to the Presidency
2. This intelligence was specifically of a compromising nature to President Trump
3. This intelligence was retained and can be retrieved at a moments notice
4. The retired DCI, who is no longer a government employee, somehow retains his read ins, Need to Know or accesses or...
5. Has personnel working within the IC who do have access to this information that would give it to him.
6. That the DCI has provided the existence of this information to Jeff Bezos
7. Bezos then provides a PUBLIC position for this person on the Amazon board as a way to pay for access to this information that Jeff will then ostensibly have as a "secret weapon" to blackmail a sitting President
This type of conjecture is on par with other conspiracy theories which are so far from realistic that they defy logic to believe. I'd love to see the combined probability estimate for something like this.
Others have said it better - Hayden knows the DoD and IC process for IT basically better than anyone, and can help Amazon win more business.
The end.
Pretty simple.
Yeah, that made me laugh.
At some point we need to just say it
some of the largest tech companies are basically NSA+CIA partners and we're well on our way to having
Big Tech completely integrated into NSA and CIA and DoD
https://steveblank.com/2009/04/20/the-secret-history-of-sili...
https://steveblank.com/2009/04/06/story-behind-%E2%80%9Cthe-...
Technology is power.
I am pretty sure USA government buy's plenty of stuff from Chinese companies like everbody else does. Doesn't mean Chinese companies are working with it.
The other government has less power over me because they are thousands of miles away and don't control the institutions that I need to function as a citizen.
That being said, the foreign government might be less afraid of using my information against me, since they would be less afraid of blowback.
I guess I'm not sure. Both suck.
Better use TAILS.
If your country's software industry is comprised mostly of 10-200 person web shops and consultancies there's no real gain for the Goverment agencies to be in bed with them.
Billion, trillion, shmillion, lose some, win some, it's all virtual. Not backed by anything real. I mean, you can see the house of cards falling down because of a sneeze right now :-)
It may suit national interest, but it bodes poorly for the public interest.
Where the public suffers is that it's their tax money that funds this rather than going towards education, health, essential services, better wages, social and economic mobility - the list goes on.
Except now one of the ways the companies can help the government is with readymade worldwide surveillance. That is much scarier than anything Dole could offer.
That's a strangely Aristotelian view of organizations. It is as if you are suggesting that the 3-letter agencies have a fundamental essence outside of the intentions of the people who work there.
Typically it goes like this: lobbyist meets with policy maker, policy maker decides objectives for [a-z]{3}, [a-z]{3} undertakes missions in support of lobbyist's objectives.
I have no evidence other than the sheer obviousness of it, but the ties still continue to this day. I have no doubt it is kept hidden from most employees due to the general political leanings of most Valley engineers. For instance, my work does a ton of work for the DoE and you hear them mentioned all the time. The DoD is also a customer and you never hear their name.
Maps was caught wardriving [2] with Google Streetview, linking Wifi access point names to physical locations early on. After getting caught, they settled for $13 Million last year.
Now Google Maps and even location services on all Android devices uses wifi scanning and bluetooth scanning as part of location triangulation. This is a constantly updating map of every SSID in existance, including unique radio devices in a given location.
Eric Schmidt, former CEO of Google, now heads up the DoD's advisory board on new technology [3]
[1] https://medium.com/insurge-intelligence/how-the-cia-made-goo...
[2] https://www.cnn.com/2019/07/22/tech/google-street-view-priva...
[3] https://www.defensenews.com/industry/techwatch/2016/03/02/go... ||| https://innovation.defense.gov/Media/Biographies/Bio-Display...
The statement also linked to a third-party analysis of the relevant code which concluded: [2]
“Gslite is an executable program that captures, parses, and writes to disk 802.11 wireless frame data. In particular, it parses all frame header data and associates it with its GPS coordinates for easy storage and use in mapping network locations. The program does not analyze or parse the body of Data frames, which contain user content. The data in the Data frame body passes through memory and is written to disk in unparsed format if the frame is sent over an unencrypted wireless network, and is discarded if the frame is sent over an encrypted network.”
[1]: https://googleblog.blogspot.com/2010/05/wifi-data-collection...
[2]: https://static.googleusercontent.com/media/www.google.com/en...
This was the moment I got afraid of every single Android device that's already on the market, sniffing around for everything they can find.
If private people do this, they get jailed. If google does it, nobody gives a damn about it.
There is no privacy, as everybody around you is compromising it without themselves knowing.
https://en.wikipedia.org/wiki/Google_Earth#History
Google Maps stems from an Australian company called Where2, which AFAIK was not funded by spooks.
The issue was that they captured data from open APs, and that collection of data was deemed illegal wiretapping.
The mapping of WiFi networks to physical locations was not.
The government didn't create Silicon Valley, Robert Noyce and the rest of the Traitorous 8 did. They did however bankroll semiconductor fabs here and in Texas for a few years but the world is better for it.
I mean, there are several books about it such as Surveillance Valley, or these two sister pieces
https://medium.com/insurge-intelligence/how-the-cia-made-goo...
https://medium.com/insurge-intelligence/why-google-made-the-...
No we do need to say that because is patently untrue.
- Checking out on Amazon was always encrypted.
- Browsing on Amazon was not encrypted until quite recently. Add To Cart wasn't encrypted.
- High end network equipment includes support for monitoring your browsing on the guest wifi to send URLs from you browsing Amazon to price-compare or buy. See, for instance, Cisco Analytics for Retail.
What do you mean by this? HTTPS has always been supported for browsing and adding to cart.
HTTPS was only experimentally supported by one browser when Amazon launched so this is clearly not the case, is it?
Where did you get that nonsense?
https://www.thenewatlantis.com/publications/we-all-wear-tinf...
I like the way you included just 'Americans', may be because it's just the domestic spying which is against U.S. law, may be because you thought 'spied on Americans' hits harder for an American reader than just 'spied on everyone'.
But, for someone outside USA or China; there's absolutely no difference between U.S. tech or Chinese Tech w.r.t Privacy, what U.S. does privately, China does openly and that's not limited to just spying.
Can you say for sure, that the phone will not be seized, imaged and/or bugged at the airport/border?
Anyways you are talking about differences in what they do with the data or the person to whom that data belongs and not contending the fact that tech companies from both the countries spy internationally.
See, that's what I'm trying to tell, What about 'Not in America'?
Before I proceed further, I want to categorically state that I don't intend to come off as supporting privacy violations by one country vs another; My argument over this entire thread has been that it sucks for someone not in any of these countries as they all spy on us and it's taken for granted in this kind of discussions.
That said,
>use a VPN. The NSA can't stop you if you really want privacy.
Because they have 'No logs' policy? Come on, don't be naive. Even the trillion dollar fruit company has been part of the program according to documents which hasn't been disputed.
>This is illegal in China, where every VPN must be state sponsored and monitored.
So you do agree that the Amercian VPN companies or any American company have double standards when it comes to China? Btw, almost every outsider in China installs a VPN to access content outside Great Firewall once they arrive, several U.S. services work without a VPN e.g. iMessage, Skype etc. I have heard of targeted deportation/arrests at airport, but never heard of random phone seizures at Airports.
Same advice, buy a VPN if you want the services that it provides.
>Because they have 'No logs' policy? Come on, don't be naive.
Contract with a VPN that is audited and resides in a legally favorable country. I hesitate to endorse any particular company, but they're out there. Maybe privacy just isn't convenient enough for you.
>So you do agree that the Amercian VPN companies or any American company have double standards when it comes to China?
What are you talking about?
>very outsider in China installs a VPN to access content outside Great Firewall once they arrive
You are allowed to do this at their law enforcement's mercy.
> several U.S. services work without a VPN
Surveillance wouldn't work very well if it made people quit using the services and network.
> I have heard of targeted deportation/arrests at airport, but never heard of random phone seizures at Airports.
I wonder why they don't feel the need to seize phones at airports. As an aside, I recall reading that the PRC forces Uighurs to install spying apps directly to their phones. That is, all the Uighurs who aren't in "Vocational Educational Camps" and have yet to flee to America, where the supposedly oppressive American surveillance state is a breath of fresh air.
This - >
>Same advice, buy a VPN if you want the services that it provides.
>You are allowed to do this at their law enforcement's mercy.
Do you consider secret courts to be in scope of this discussion.
Then there is this That and this https://en.wikipedia.org/wiki/Disposition_Matrix
Yes. Secret courts are reasonable due process. Do you have an alternative method that wouldn't release damaging information?
Are you interested in talking about surveillance specifically or every talking point of the usual anti-American tirades?
You said
> If they wanted to intentionally examine your network traffic, that would require a court order.
I just gave you an example when that did not matter.
> Are you interested in talking about surveillance specifically or every talking point of the usual anti-American tirades?
Whenever you are willing to have an honest discussion rather than a blinkered and intentionally misleading cheerleading
Prove it.
Yes, independent review by a board or committee separate from the defense intelligence complex who will help determine if the information is actually damaging or if it's just some bullshit a midlevel staffer at the Pentagon determined is 'damaging.'
As an American, I am deeply disturbed by the complete absence of transparency of these programs to Congress and the American people. And honestly I'm not convinced that the people running these programs have any ability to see the forest for the trees, or if they're not just some D.C. automaton skilled enough at groupthink and not asking questions to get the tippity-top security clearance.
Is it a drooling idiot running the program? Dunno. Classified.
Their spying on Americans is reviewed by judges and courts. They get warrants for every american they spy on.
The senate intelligence committee may (behind closed doors and under the oath of secrecy) inquire about just about anything the intelligence community does.
The president may at his or her sole discretion declassify any information.
Haven't you heard, the first rule of conflict is "all warfare is deception"? Try running a state with zero secrets and see how far you get.
Those judges, and the members of the senate intelligence committee are most definitely not an independent committee. That's like calling the police commission an independent committee. Even if they were, how would we even know if they're not just rubberstamping stuff?
Congress is in the dark. Remember Niger?
"We don't know exactly where we're at in the world, militarily, and what we're doing. So John McCain is going to try to create a new system to make sure that we can answer the question (about) why we were there," he said. "We'll know how many soldiers are there, and if somebody gets killed there, that we won't find out about it in the paper." When Senate Minority Leader Chuck Schumer was asked later on "Meet the Press" about knowing whether there were troops in Niger, he responded, "No, I did not."
https://www.cnn.com/2017/10/23/politics/niger-troops-lawmake...
If they don't even know where we have troops doing mildly classified stuff, how much do you think they know about black programs that are totally off the books?
The president has thus far decided things like, 'huh, the Coronavirus is a lot worse than everyone thinks...in February...better not tell anyone about it and we should do absolutely nothing to prepare' classified. Great guy to have in charge of that.
Think about the people we're actually fighting wars against? Do you think elaborate deception has made a sliver of difference in any conflict fought by the United States in the past 60 years?
We need transparency and civilian oversight. I'm not afraid of an Afghan Taliban fighter knowing our super secret plan to spy on the planet. I am afraid of a defense intelligence complex that has shown zero hesitancy in the past to spy on Americans and is increasingly operating in the shadows with little oversight outside of the White House.
This whole system is not engineered for the benefit of the American people. It's a juggernaut of bureaucracy and secrecy that serves a defense and intelligence community that is pursuing god knows what.
Source on this?
>Those judges, and the members of the senate intelligence committee are most definitely not an independent committee.
What does independent committee mean to you? They are from entirely different branches of government. That's as independent as it gets.
The post you linked is from the Senate Armed Services committee which is not the legislative oversight for the NSA. Different people, different processes. Geriatric senators probably forgot we had troops in Nigeria because America has troops in untold dozens of countries. No one remembers the whole list.
If you think the Taliban is our biggest threat you should leave national security to the people who do it for a living.
I can say that there are only 11 judges listed as being on the FISA court, and I don't believe that 11 people can personally oversee every instance of the NSA conducting surveillance on all potential Americans of interest around the planet. Maybe they can. Who knows, it's classified.
Congress is a different branch than the presidency, doesn't mean Mitch McConnell is an independent check-and-balance on the authority of the president.
It's literally their job to be aware of that. They have a staff whose entire job it is to keep them aware of that. If they can't keep track, what's the difference between them and the congressional committee that's supposed to be keeping tabs on the NSA?
The people who do national security for a living are in a bubble that facilitates the construction of boogeymen. And if they can't give me any credible evidence as to the existence of said boogeymen without saying 'sorry, that's all classified,' then why should I believe otherwise?
Right now I'm supposed to be scared of China, but I personally see no evidence that I should be more worried about them than my own president who covered-up the threat from Coronavirus in February, and then tried to blame it all on the Chinese as a diversion. Looks to me like the Chinese were actually trying to warn us in February, while the President was trying to cover it up:
Clinical features of patients infected with 2019 novel coronavirus in Wuhan, China - January 24, 2020 https://www.thelancet.com/journals/lancet/article/PIIS0140-6...
Clinical course and outcomes of critically ill patients with SARS-CoV-2 pneumonia in Wuhan, China: a single-centered, retrospective, observational study - February 24, 2020 https://www.thelancet.com/journals/lanres/article/PIIS2213-2...
If the Taliban aren't a threat to U.S. national security, then why was the longest war in American history fought on Afghan soil? Isn't that where all those 9/11 hijackers were from, and the country that bankrolled them? If they weren't from Afghanistan why didn't we sanction or invade the country they were actually from, and that gladly bankrolled the operation? Is that classified too?
https://www.npr.org/2020/05/13/855611173/fbi-accidentally-re...
Oops... I guess it isn't anymore.
Regardless of legality.
> I'm very sure that you're wrong. Do you have any evidence that the NSA kidnaps and tortures people?
that NSA can get people tortured or killed without much difficulty.
You started with the claim that unlike China an US citizen is unlikely to get his/her privacy encroached on quoting all sorts of processes. I just gave examples where these processes didnt do much in preventing breaches of such encroachments. Add to that what we know is just a clouded view into the tip of the iceberg because of provisions of secrecy. If the clouded tip of the iceberg looks the way it does, it is not hard for someone not so deluded, or not so deprived of a full deck, to fill in what the rest of the iceberg could look like.
If you disagree show me the proof of
> Americans who are overseas plotting imminent terrorist attacks
Show me the oversight over Anwar Awlaki's assasination that went ahead despite the fact that he had never been charged with (let alone convicted of) any crime. Proof of oversight, if you please over the killing of his 16 year old son.
I can play the same game that you have been playing in asking nothing less than irrefutable proof that will stand in a public court. Hope you believe in upholding the same standards over yourself that seek in others.
If you cannot, then how is it different from other places where such proofs are not forthcoming after killings or incarcerations ?
It also links to another similar account a few days before that. And why would Egyptian activists make that up?
Plus, even if the NSA isn't regularly doing the kidnapping, torture, and killing themselves, they certainly help our other organizations do these things. Things like the disposition matrix, black sites, and locally with parallel construction all rely on their surveillance.
Too many unanswered questions. It's more likely she made it up because it gets people angry and that's what activists need to do.
If you have problems with other parts of our government, by all means criticize them and be an activist. Speak your mind and vote. Making up stuff about the NSA is intellectually lazy.
Personally, I agree with the other poster and view the NSA's collaboration as enough evidence, but had remembered seeing the Egypt thing last year.
One popular quote by Upton Sinclair comes to me mind.
You can say, as a US citizen, that all this stuff doesn't affect you much. But I can tell you, from considerable first hand experience, that the average Chinese citizen says the same about China.
I can say that the surveillance doesn't affect me because it's almost unheard of for Americans to get arrested with evidence that the NSA collected. The NSA is not a law enforcement agency. In China arresting people based on data from surveillance is the norm.
Edit: I am mostly addressing the organize against it part. USA has far better free speech protections than China
Do you ? As an outsider it doesn't really look that way. After watching events and protest around BLM, suddenly all those rights have gotchas in them.
Watching USA protesters and Honkong protesters, and goverment respones to them, there were far more similarities than differences. (Well china was still worse, but not by as much as most USA people seem to think).
The biggest difference in USA and china at the moments is that in USA some Politicians still listen to people (if only mostly out of self interest)
Ask those who wanted to protest against recent disproportionate police actions and those who did and became targets.
"All the stuff" that was either started or expanded while he was VP. Yeah, sure he wants to tear it down.
Biden is not going to change anything NSA-related, do not delude yourself and do not mistake electioneering frenzy for policy.
He seems consistent on this issue. Prior to his stint as VP, he complained about metadata collection by the GWB administration. https://youtu.be/h2qgU8kJt-0
So the question is not whether Joe Biden ever grandstanded on the topic - I'm sure he did, as every politician would. The question is what he had done about it when he was Senator and VP - specific actions attributable to him? Because if he has been consistent to paying lip service to the issue while not doing anything in practice - it is prudent to expect the same consistency to extend into the future.
I told you in the GP post. The email metadata program was shut down, and the phone metadata collection was reduced.
> PRISM still exists,
PRISM does not collect Americans' data.
> The question is what he had done about it when he was Senator and VP - specific actions attributable to him?
Again, I told that to you.
You haven't told me anything in fact except that some things supposedly happened while Biden was a VP.
There was only one in the leaks. That one.
> how do you know there's no other programs
If there were any, Snowden would have leaked those instead of a program that had already been shut down.
> how do we know it actually was reduced and not just changed codename?
Because laws were changed, and oversight was added that showed how many metadata records the NSA requested from the telcos.
> how you know Biden personally had anything to do with shutting it down
Does it matter if he was personally in charge or if he delegated? Collection of Americans'metadata shrunk while he was VP.
Living in Europe I have the pleasure of hearing these kinds of naive comparisons on a regular basis. Somehow it's always "the US is basically China and/or Saudi Arabia".
It's exhausting having to explain to people who are seemingly only capable of operating with a binary black and white worldview that there is a massive difference between certain shades of grey.
https://en.wikipedia.org/wiki/Anwar_al-Awlaki
The difference between 'recruiter' and a guy who sent some emails to some people is unfortunately a distinction that is up to some dweeb with more top-secret security clearances than medals on a North Korean general.
I assume it's the same thing in China, they just have more dweebs that can disappear people.
>"According to U.S. government officials, as well as being a senior recruiter and motivator, he was centrally involved in planning terrorist operations for the Islamist militant group al-Qaeda"
We are better off with him dead. He was American, but his allegiance was to al Qaeda and he was planning to murder civilians.
Does your sense of morality and ethics end at the border, shouldn't these types of values be a bit more universal?
You and I have no evidence that he was anything other than a loudmouth who bagged on the U.S. on the web and responded to emails from anyone who sent them.
Remember when Saddam had those tractor-trailer biological weapons factories driving around Iraq ready to release clouds of Anthrax on American civilians? That was also based on classified information from a US government official.
https://www.abc.net.au/news/2003-05-29/cia-confident-iraq-tr...
Completely fabricated.
"not enough evidence for me to believe it" said someone on HN with your handle.
Show us the evidence (a demand you seem to be fond of) and prove that in a public court, that's called due process. I will believe it then.
America won't even let you enter the country if you, or somebody on your feeds, criticized it on social media [0]
People who are too vocal in their opposition to the US government, or just been in the wrong places at the wrong times, have been plenty known to be abducted into torture black sites [1], if not straight up killed by a drone strike because literal SKYNET [2] interpreted their meta-data [3] as that of a terrorist.
And none of that is even accounting for the reality that the US has the highest incarceration rate on the planet, so if there's a place you will most likely be arrested during your vacation, then that's gonna be the US.
But I guess it's easy to forget about these parts of US hegemony while pointing at China over "social credit scores" putting people on no-fly lists.
[0] https://techcrunch.com/2019/08/27/border-deny-entry-united-s...
[1] https://en.wikipedia.org/wiki/Extraordinary_rendition
[2] https://arstechnica.com/information-technology/2016/02/the-n...
[3] https://www.nybooks.com/daily/2014/05/10/we-kill-people-base...
The moral criticism here is that he violated the law he swore to uphold by also spying on his own citizens, and then lied about it.
Maybe for someone outside the US and China who doesn't travel and never intends on traveling. On the flip side if you ever plan on visiting either country there is a pacific-ocean sized gap in what you'll face visiting the two countries. I can't recall the last time someone was "disappeared" for criticizing Trump on twitter. The same can't be said for those who criticize Xi on Weibo.
And this guy lied to Congress about it. And unlike plain folks who would have been prosecuted and jailed for this, he wasn't even indicted.
When? James Clapper is not one of Keith Alexander's aliases.
Also http://www.allgov.com/news/controversies/nsa-director-alexan...
In an exchange from March 2012, Johnson had an opportunity to question NSA Director Keith Alexander about precisely the kind of concerns that the exposé of PRISM confirms — that the signals intel agency can spy on content coming through American Internet servers.
I think it's pretty accurate description of what PRISM and other NSA programs allow NSA to do. Also:
Alexander categorically denied more than once in this clip that NSA even had the capability to conduct surveillance in the manner Wired reported
We now know not only they have the capability, they are actively using it. If claiming such capability does not exist is not a lie, then what it is?
The part you quoted is correct, but he didn't claim otherwise. He said that they could not get Americans' data in that manner, which is true. Reread his exchange with Johnson in the article. ("Does the NSA intercept Americans’ cell phone conversations?") In other words, he did not lie.
Nothing about Amazon hiring a former NSA director to its board is "tinfoil hat crazy". It's in fact perfectly rational, since Amazon is literally in the business of selling services to the federal government.
I want the NSA to know everything a US President does while in office. I want the NSA to know everything a candidate for US President does while they are running for office.
The President of the US is not a regular citizen. The cost of being handed almost unlimited power is that you forfeit the assumption that you will use that power always and only to the benefit of the country.
If Alexander has compromising intel on the current president there is only one man to blame for that - the man who put himself in compromising situations.
Neglecting the fact that, according to Snowden, they already have that power, are you aware what power this gives the intelligence community and, by implication, the sitting president over elections and up-and-coming presidential candidates? Yes, Donald Trump is dangerous. But this doesn't mean we should employ even more dangerous tactics to control him.
That's an explosive claim. If Snowden knows that they have that power, why didn't he leak documents that show they do?
Just because we (Germans, Europeans) are culturally closer to Americans and share certain values does not mean that we should have a double standard on our external affairs.
We are kicking out Huawei. When will we kick out Amazon, Google, Apple and Cisco?
This law, still on the books, theoretically allows the president to order military action against the ICC in Den Haag (The Hague) should they ever try an American Service Member.
> The act also prohibits U.S. military aid to countries that are party to the court. However, exceptions are allowed for aid to NATO members, major non-NATO allies, Taiwan, and countries that have entered into "Article 98 agreements", agreeing not to hand over U.S. nationals to the court.
[1]: https://en.wikipedia.org/wiki/American_Service-Members%27_Pr...
Nonetheless that does not make the US forces in Germany an occupational force.
A stick is a stick regardless of whether it has been used to thrash someone lately.
Maybe Germany (and the EU as a whole) should start paying for its own defense, and paying their agreed to share of GDP into NATO while they are at it
Huh, and here I thought it was 2020 and not 2024. Weird.
> Allies whose current proportion of GDP spent on defence is below this level [2% of GDP] will […] aim to move towards the 2% guideline within a decade.
From the 2014 NATO summit: https://www.gov.uk/government/uploads/system/uploads/attachm...
It works the other way around. We cannot have an European industry meanwhile USA government backed-up companies are competing with our startups.
> collection of small countries
Europe is bigger than the USA. And the division within the USA is as big or bigger than Europe. And, we cannot talk about China.
OK, on some metrics. But I think nobody questions which country is still leading the world.
> And the division within the USA is as big or bigger than Europe. And, we cannot talk about China.
I don't agree with this or we're talking about different things.
The grip of Washington DC on the states of the USA is much stronger than Brussels' on the countries of the EU. The degree of sovereignty is very different. No matter the internal divisions inside the USA, first of all there is one USA. On the other side of the ocean first of all there are multiple competing EU countries, each of them trying to exploit the others and the EU and with different economics and foreign policy goals. About that, do (random picks among large states) California, Texas and New York have a foreign policy worth talking about?
If you're in a security alliance with countries you share values and goals with, how can you not apply different standards in terms of data sharing? And how can you not react somewhat differently to any transgressions, mistakes and imperfections?
I know Trump has made this very difficult by making his personal whims indistinguishable from the interests and commitments of his country. In my view this is a form of corruption that does massive damage to the U.S. And yes, democratic control over security services has been rather tenuous at the best of times.
But I still see many good reasons not to impose broad economic sanctions on allied democracies. And I do see good reasons to side with them against completely illegitimate regimes that use their security services to keep themselves in power without a democratic mandate.
Of course there are many grey areas and a lot of valid criticism. But asking for Europe to officially impose economic sanctions on the U.S is not a proportionate reaction to that. The economic damage would far outweigh any additional freedom or security.
If you refuse to apply a degree of pragmatism and proportionality, other countries would then have to impose economic sanctions on Germany for their use of Staatstrojaner. Essentially, all cross border trade in digital goods and services would have to end globally. That can't be a good idea.
Is the "spying" by the US on Germany as damaging to Germany's future as spying by the Chinese?
If you answer these questions honestly, you'll understand why you're making a false equivalence.
And honestly moving to these tools from slack, confluence, etc. has been awesome.
Zulip threading model is great. So much better than slack.
And using markdown and jupyter notebooks for documentation on gitlab? Damn awesome.
- Is your company mainly a software company?
- How much time do you spend on a week on maintaining your servers?
- How do you make sure that your servers are secure? Maybe you are being hacked every night, does your company have the means to check if there has been a security breach?
- Do you follow/apply the security patches for the OS you are using on the server and all the software you are using on the server?
- Do you have regular offline backups? What would happen if there is a fire in your offices?
These are some of the reasons to go for a cloud solution, especially when you are not a software company (hence you don't have many people who have the knowledge for setting up/maintaining such stuff) or when you don't have the resources to hire dedicated sysadmins.
Mostly yes. We obviously have sales, marketing, etc. as well.
> - How much time do you spend on a week on maintaining your servers?
I don't do devops. There is a team of people that works full-time on IT infrastructure. No idea how time they spend. Gitlab and Zulip servers are updated every couple of weeks. No idea how much time these cost.
> - How do you make sure that your servers are secure? Maybe you are being hacked every night, does your company have the means to check if there has been a security breach?
There is a team of people that work on cybersecurity monitoring. No idea what they do. Normal IT people just make sure that everyone's computer is encrypted, setting up people's credentials, etc.
> Do you follow/apply the security patches for the OS you are using on the server and all the software you are using on the server?
I don't do anything, somebody does this for me.
> Do you have regular offline backups? What would happen if there is a fire in your offices?
We have multiple locations and the backups are replicated across our own locations.
Obviously we're not all going to build our own CPUs from sand at a local beach. So there is a balance between DIY and vetted suppliers
We have a gitlab server, and connecting requires being on VPN, which requires 2FA, and then ssh, which requires your keys to be properly set up.
Good luck finding one. The world is divided in 3 spheres of influence: US, China and Russia. To make business you must obey one of them.
For most practical purposes, the EU is nested within the US sphere of influence.
As long as you have decent hardware (cpu/ram mostly) and reliable storage (netapp or something similar) you can get stuff done very easily.
Also, most people seems to not have noticed how fast computers and disks got recently and how resources you can pack into a single physical machine: you can nowadays fill a 2u, 2socket machine with 128c/256t (2x amd epyc) and literally terabytes of ram...
Thats not a insignificant cost.
Nobody attacks code repositories of non-software companies anyway, people are after CRM and ERP data. There is the occasional issue with malware from mails and special users, but a backup solution with 15min snapshots solves that issue. Although the latter can cost a bit and might be too expensive for smaller companies.
It's done on a budget as well so we're kinda forced to use open source software.
Weirdly enough we use Skype for work chat and Zoom for video meetings, so it feels a bit inconsistent.
It's like as if somehow, in many eyes, that's impossible now. Depending on your scale, it may be impractical given external hosting options but it's certainly not impossible. Lots of data centers rose and started automated processes of shared hosting and co-locating hardware which was a step forward. I remember working with Rackspace, Equinix, The Planet, etc. which further automated quicker server deployment, had applications for UPS resets/interrupts, etc. The more you moved towards a specific business's automation services, the less portable your infrastructure was outside that environment.
That continued on until you now have more sophisticated hosting like what AWS and GC provide. Now, abstractions exist for about everything in a data center and the trade off is that you now have to manage all that complexity through proprietary APIs, consoles, and so forth.
In addition, the tradeoff here is the more complex the infrastructure, the less easy it is to shift it to another provider. That may be fine for you, it may also not be. It's all definitely possible though.
Exactly! I'm a sysadmin (sometimes a Dev), but sysadmin is what i'm really good at. The most important thing is to see a solution from another perspective.
Sometimes, and sometimes we have to ask the developer of that exact OS-subsystem/driver/firmware(AARGH!!) because it fails us too...and here we have a closed circle ;)
I was in ops for 13 years, and if you were to talk to any of my former coworkers they would bury you with praise for the quality of my work. Yet, I eventually chose to move into a management track because I had peaked my career about 7 years in and didn't realize it until later. There was nowhere I could go up, because I wasn't a software developer. Now I'm a manager that has technology understanding, which has a high value prop for many orgs all on its own, but I do sometimes miss "getting my hands dirty".
I've worked with a lot of software developers over the years, and while there are a handful who are really incredible, the majority of people are just mediocre. That's expected and okay. The same is true for Ops folks, as it happens, although generally it takes more competence to rise to "Senior" on the Ops side vs software. The thing is, "Senior" is as high as it goes for Ops folks. So you might meet really stellar Ops folks who are effectively titled and paid the same as a mediocre developer with 3 years of work experience. It's simply not sustainable, and the push towards moving everything to the cloud and off-premise is probably a symptom of this (not enough quality Ops folks to keep things on-prem) and exacerbates this (reducing need for quality Ops folks, driving down market demand, unless you want to work at a cloud provider).
Pretty much all of the other Ops people I've respected and admired over the years have moved into different career paths. I find the same is not true for software developers. So when younger people ask me about career paths, I always recommend software over Ops, if they are adamant they never want to go into management.
It's kind of sad, I suppose, but that's the way of it. I appreciate that there's a subthread on HN where folks recognize and respect the value of competent Ops folks, but I think you'll find that most are being pushed out of that career path.
If your business involves any amount of low priority bulk compute, this gets much much easier. You simply let the low priority stuff fall behind while your order to Dell for new servers is being delivered...
Also, if you have compute that could be on-prem or could be in the cloud, you can set up a kubernetes cluster spanning both and let non-privacy-sensitive overflow to GCP as needed.
All of the above rarely comes out cost-effective though, because while the raw compute is cheaper to DIY-it, when you factor in the staff time to build, maintain, and deal with the shortcomings of your bodged-together on-site solution, it's going to come out much more expensive.
We've built out something homebrew like this using cheap compute desktops but you're still going to pay a lot upfront.
As soon as you start using the full suite of cloud tools, it's impossible to not give the provider the encryption key...
I'll be honest - you guys need to find a new technology partner then. Creating a private cloud that's reliable and offers the basic services that the major providers have is not difficult in 2020. Some of the aaS stuff can get tricky but is still entirely do-able.
Regardless, if they found a way to make your infrastructure MORE expensive than the public clouds they either have no idea how to negotiate or are really, really bad at their jobs. The public cloud is a lot of things - but cheap isn't one of them.
Meaning, e.g. there are specific, rigid rules regarding how Postman can be used while developing backend services, to avoid that customer info is inadvertently transmitted during testing.
Of course, it’s a PITA, but it serves its purpose.
But the idea that Postman is actually git in that analogy is hogwash and a way to wrest data out of people.
I mean I like to think the data has no value to e.g. the US or competitors, and that the sheer volume makes it worthless, but I suspect that's just a lack of imagination on my part.
Never trusted Bezos and the Amazon offerings are too expensive anyway.
There is an AWS Region in Germany. Your data will stay in Germany unless you specifically decide to move it elsewhere.
AWS also provide you with the tools to encrypt everything and if done correctly means that Amazon no matter how "evil" they are cannot decrypt the data. Not only that, there is such a huge separation in access and rigour around governance that there is no way anyone within Amazon can simply login and see your data even if unencrypted.
Every single case of data being leaked from AWS is because the people working for the company that manage the data literally checked a box to make the contents public. Contrast this to "on-prem" where physical security can get compromised or the vendors of the physical hardware/software leave gaping holes or maintenance backdoors that get exploited.
Honestly these types of views are no more grounded in reality that flat earth conspiracy type views.
Prove it
They say "We are sorry", give you some free credit, and that's it ?
"Sorry not sorry" and no credit.
The measures you've enumerated (EU zones, encryption, etc) are mitigations for working with a potentially compromised vendor and should be done anyway. Not using the vendor is such a blindingly obvious countermeasure that one has to be either unprofessional or have a hidden interest to dismiss out of hand.
I personally choose not to believe a company which puts on its board of directors a well-known perjurer [1].
[1] https://www.theguardian.com/commentisfree/2013/sep/25/nsa-re...
The problem I see with the DIY-attitude is that security is easy to get wrong and is moving target. The other opinion here is "keep it in the country". If someone really wants your data, the locale won't save you. And yet, if there is a breach, I could see an foreign company like AWS trying to hush it, where a German company would make a bigger fuss (diplomatic issue).
Cloud Act and National Security Letters really fuck things up for American cloud providers with regard to doing business with European customers.
It feels like the rampant capitalism in the United States, and lack of regulations, fuels the VC economy. Making startups like Google, Amazon and others possible.
I can't imagine a company running on hundreds of millions in dollars of VC money with no real profit coming in, just hoping for an exit.
That's a very strange phenomenon, sort of like the .com bubble never burst but just got bigger.
I'm afraid that in order to see the same rapid development of cloud companies here in Europe we'd have to adopt the lax corporate regulations of the US. Which in turn would lead to other issues like workers losing rights.
Google, Apple, Amazon, ... are not startups, they are behemoths backed up by the USA government. Europe has many very good startups that are just purchased with USA dollars once they are successful.
> we'd have to adopt the lax corporate regulations of the US
That would only ruin Europe standards of living and open us more to be purchased by USA companies. The other way around is the way. It worked for China. Forbid non-European companies to purchase key software companies.
USA is not successful because capitalism, USA is successful were the government puts a lot of money: Military, I+D.
This is incorrect. The current big tech companies became successful and massive without any special government deals. Google dominated search, Microsoft dominated all business and home PCs for decades, Apple and Google dominated mobile for consumers and businesses, Amazon beat them all to cloud and ate online retail with free fast shipping.
It’s only recently with JEDI that Amazon/Microsoft tried to attach directly to the government’s wallet in a big way. And even with losing that, it will be a drop in the bucket for either of them.
These companies were successful because they were allowed to move quickly and beat out competitors. The entire Internet industry blossomed and gave birth to these companies before the government even took the Internet very seriously.
Where did their finance came from: previous SF companies and angel investors
Where did these companies get their funding from: US government
The current companies are only the "daughters and granddaughters" of massively government funded companies in Silicon Valley
Very good point. Many people forgets how much money the state invest, as it should, on technology and to create an industry. From ARPANET to the WWII computers (or NASA), technology needs a level of investment that only states can afford.
What I meant was that they were startups at one point.
I could have given other examples but there are so many that it's hard to decide. Dropbox, Reddit, imgur just to name a few. This site should know plenty of VC fueled startups.
The point was not which startups to name as examples, the point was that lack of regulations make this whole VC system go around.
I could never see that system working here because bureaucracy slows everything down and forces corporations to do things like care for employees and pay taxes.
But with that said, recent news shows that Sweden has given tax exemptions to Facebook and Amazon just like everyone else. To curry their favor. It's frankly disgusting.
Again, you are getting it the other way around. Taxes to invest in education and Development and Research and high qualified citizens is what allows innovation and good companies.
What are the realistic odds that someone internally at Amazon is going to break into your instances to look at your data if you're just a regular business?
If you're in a German cloud, those risks are probably higher since your business has local competition, and if you're self-hosting, then your overall security risks are even higher.
This seems like a emotional choice, not based on realistic business or security sense.
Perhaps Amazon did this on an abstract level to understand video streaming and the Netflix business to create Amazon Video but I doubt Amazon would have cared for the tiny startup I worked at here in Hamburg.
But the hysteria and the “but what if?” thinking is real and it was really codified in bank contracts. So much so that BaFin stipulated that the tech stacks could be audited and there was no way that Amazon was going to allow anyone in to look at it and such.
On the whole if it can be afforded my team is so much more productive being able to build on AWS than to spend all that time both building our product and the infrastructure to go with it. I’m just not that smart.
It's hard to imagine that this includes the code within a Cloud provider. If you're using a Windows server, are they expecting Microsoft to fork over MS source code?
This just sounds like an overly-conservative interpretation of the rules.
It basically rules out ANY cloud solutions - which is unreasonable and wouldn't ever hold up under scrutiny even if the Bank or regulators explicitly asked for it.
I'm pretty sure you can think of stronger business cases against Amazon/US-Milspec involvement in a non-American business.
Amazon, in the hands of Americas spooks, can do a lot of damage to the world of non-Americans; i.e. anyone the spooks decide to hate/target for usurpation. You think Germany is inured from such attention?
I run a simply mid-level business. Amazon doesn't give a crap about my data - that, above all, is what keeps it safe. I'm just not important enough to bother.
Well, you should understand this a little better, then.
Okay try this scenario: lets say I work for a German company that is kicking ass in a market that a spook-at-Amazon has heavily invested in - lets just say "personal transportation system X".
Because its Germany, the tech is amazing and consequently I'm going to sell this tech to Africa, because I like doing that, and not in America - because fuck America, that's why. Also, maybe China, maybe Kazakhstan. My tech, my choice.
Should I succeed in this endeavour, I'm immediately under threat of being NSA'ed by the provider of service I'd rely on, ordinarily, to render my research.
This isn't paranoia, it is due diligence.
Yeah, no thanks, Amazon. This heralds a watershed moment: a return to local services.
Just better to avoid the American spook-o'-sphere entirely, and play a local hand. Maybe even take the data centre guys out for grünkohl and senf some time, whatever.
Look - to understand why the hate for all the spook/control paranoia, Americans/Brits/5-eyes/et al., all you have to do is try to see it from the other side of the national identity for a second.
Germans are very, very rightly on the side of data protection.
The holes in the ground that used to be Gestapo buildings are not all parking lots! Some of them are memorials.
Also not paranoia: diligence.
(^WThis comment brought to you by the ACME-HNnnn-comment-slowdown-negotiator-system™ .. time wasted, is creativity! Disclaimer: Not German, am applying hypotheticals. Still not paranoia!)
I mean, there's this: https://www.wsj.com/articles/amazon-scooped-up-data-from-its...
> The online retailing giant has long asserted, including to Congress, that when it makes and sells its own products, it doesn’t use information it collects from the site’s individual third-party sellers—data those sellers view as proprietary.
> Yet interviews with more than 20 former employees of Amazon’s private-label business and documents reviewed by The Wall Street Journal reveal that employees did just that. Such information can help Amazon decide how to price an item, which features to copy or whether to enter a product segment based on its earning potential, according to people familiar with the practice, including a current employee and some former employees who participated in it.
If you're a regular business and Amazon doesn't want to launch a new hosted product competing with you, then maybe you're safe. But if they want your data, why not just take it while repeatedly insisting that they don't?
It is wildly different to scoop up data from your own Amazon.com platform vs BREAKING IN to a private AWS instance. They aren't even the same divisions in Amazon Inc, so it would be extremely obvious to everyone, very inappropriate, and most likely get leaked that it was happening.
Going to go out on a limb and say that the NSA is going to have an easier time breaking into your on-prem servers.
Hiring a retired General for influence is as old as this town. People are reading too much into this. This doesn't make it more or less likely for Amazon/NSA/CIA/whatever to steal your data.
There is a LOT of money in the government defense sector. AWS is in an excellent position to capture a lot of that money, but their primary competitor in this space, Microsoft, has been preventing a complete domination and monopoly by Amazon.
With Alexander on the board, this will ultimately lead to different/better insights for how Amazon positions itself in this government sector. Alexander can bring a ton of value, just with his contacts and networking alone, let alone the insight into how security and data operations work in the intelligence community.
Ultimately, this isn't a step towards more government surveillance. The government can't coerce Amazon any more with Alexander on the board or not; the rules are still the same. This is fundamentally about Amazon's desire to get in on the lucrative big dollar contracts that would otherwise end up going to traditional defense contractors like Lockheed, Boeing, Northrop.
Architect of (illegal) government surveillance gets influential role in a major Internet company.
I do not expect him to strongly criticize Amazon's privacy violations or questionable data collection. I fully expect him to be supportive of Amazon initiatives that will make for an easier government surveillance (even if only for improving their chances at getting government contracts).
Of course the US government cannot coerce Amazon any more with Alexander on board. Yet having powerful, government surveillance supporting, well versed in building systems of government surveillance, individuals on the board will surely have a very different impact than having a privacy rights activists on the board.
[1]: https://www.drop-dropbox.com/
[2]: https://www.nytimes.com/2020/07/31/technology/blocking-the-t...
They should atleast provide an option
I understand this is all too incestuous, but I also can’t really say it’s a bad move.
[1] https://www.theguardian.com/commentisfree/2013/sep/25/nsa-re...
I mean he could just said that he cant't answer that question because its't highly classified and this hearing is televised to entire planet, instead of lying
A far more adequate analogy would be a company spying on all of its customers and employees, and then lie when asked about it.
Well ... I just searched and it seems they are available there. I did not know that.
The real question is why is an ex-NSA agent working at a place that sells dragon dildos?
In all seriousness though, if Amazon can predict what consumers want, they will make more sales. An ex-NSA should have at least some experience in analyzing behavioral data and predicting what large numbers of people do.
If you thought selling cheap junk to people was profitable, wait until you see what selling mass surveillance to the government pays. Everyone that said, it's an Orwell problem to have pervasive "assistant" devices was right. Look how many billions NSA poured into scanning and indexing everyone's mails and calls in Utah. Now you have OP and a few days ago Amazon PR objected calling Echo a "microphone": all these dumbasses paid for these things and now it's really here.
https://news.ycombinator.com/item?id=24418854
We already know Eric Schmidt's Google is tight with the government, and look, they make home assistants also.
https://theintercept.com/2016/04/22/googles-remarkably-close...
So, are there sanctions on the table for the US? /s
When all that happened, you can bet it wasn't as publicly visible as Alexander joining their board.
Every president betrays us here. Every damn one.
Amazon is far from essential; they can be beaten handily on price, quality, and sustainability by hand-picked suppliers, and frankly in many cases I prefer the experience of buying things from humans. I went to a local hardware store the other day (I live in Los Angeles) and when shopping I asked about some pallets outside and was invited to take them, saving me easily $40 in lumber and making me feel more valued as a customer than Amazon “guaranteed [except not really and with no consequences for failure] 2-day shipping” has ever made me feel.
For people who value the feeling of connection to their community and their supply chains, Amazon doesn’t make sense. For those who would prefer to disconnect from the environment and humans that supply them with what they need and want, Amazon is competitive but not unbeatable.
walmart's checkout process and delivery/order history experience is silky, i was totally surprised by it when i started using them a few months ago.
I don't own Alexas either, but it's obvious why 'normal folk' would like the convenience.
Lol that's me.
I also use it to set timers while cooking, and play music (I think the sound of Alexa is quite good). But that's basically it.
A wireless speaker that can set timers / arams, and maybe control music, would allow me to replace Alexa. Is there something like this ?
Granted I do walk around with a smartphone.
Is his expertise for which he is being hired to help Amazon get away with committing crimes on a massive scale which he clearly has expertise?
Is it reasonable to assume that Amazon, pushing their "Amazon Microphone" are embracing criminal practise and believe criminal activity is ok?
The good news/bad news reality is Alexander is looking for a big payday after years in government service -- not assist the government is using Amazon for its own surveillance purposes, or assist Amazon in becoming better at surveillance.
To avoid concerns about ethics, many high-level government employees retire and join either investment groups or boards of directors. This puts them once removed from the money chain, but still allows them to line their pockets by leveraging the power they accrued while working for the government.
Amazon does business to secure pentagon/etc. information. It is useful to have someone on the board who thinks about nation-state level cyber threats in this context.
Amazon likes government contracts. Amazon probably wants this guy on-board to help them get more contracts.
No, they don’t. It’s a choice people make, and most aren’t buying Kindle, Echo or other near useless spying device like that.
Not that it matters though - phones are [already a vector](https://www.wired.com/2014/06/nsa-bug-iphone/) for the government to listen to you. I'm not sure this news really changes anything - the government already works with large US companies to spy on people, and then makes sure they're not allowed to disclose it to the public.
Also, I think Kindle is a great product, and wouldn't consider it a useless spying device. Each to their own though.
Are we assuming that all the individuals who purchased the devices live completely alone? There are only 128 million households in the US. [0]
[0]: https://www.statista.com/statistics/183635/number-of-househo...
sarcasm.
Or perhaps affect Amazon's procurement with non-transparent motives. Suppose these is a certain microarchitectural vulnerability in one vendor's hardware but not another's. If Amazon could be induced to buy the vulnerable hardware over the non-vulnerable hardware, that could help people who knew about the vulnerability spy on AWS customers. Or if there were a company to be rewarded or punished for its decision to cooperate or not to cooperate with some covert activity, the reward or punishment could be done through procurement decisions.
Or perhaps affect Amazon's lobbying at home or abroad about privacy legislation or something.
(It's not obvious to me whether the danger is particularly greater from a former DIRNSA than from someone with undisclosed connections to a spy agency. Maybe Alexander's recommendations would get extra scrutiny!)
After WWII ended and in amidst a “space race” with Russia, German scientists and other high ranking officials were recruited and placed into well paid positions within the government - most notably NASA. Records of any war crimes they may have committed during WWII were wiped away/ignored.
I just hope technology and IT evolves so that online retail is decentralized.