FBI May Not Have Had Access To Instapaper Hard Drive Data After All
blog.instapaper.com
blog.instapaper.com
People really have to understand that "the government" isn't after you and that Western society has generally had a really good track record of not abusing their power as compared to most places around the world. The FBI simply doesn't walk into data centers or your homes and try to disrupt things. There are real American people who work in the government and police agencies who do good work. You have to realize that when they do something they shouldn't be doing, they have to answer to the court of law just like you and I with presented evidence.
I'm sorry if you disagree with me. But I don't think it's fair to assume corruption on part of the police.
Whether or not they looked at or did anything with the data on his servers is irrelevant to the fact that they violated constitutional provisions against unreasonable search and seizure.
But remember, let's not confuse direct violation of constitutional rights with mistakes.
Off the top of my head: Communist registration, mail censorship, Japanese internment, McCarthy, Nixon, J. Edgar Hoover and/or COINTELPRO, warrantless wiretapping, PATRIOT Act, Guantanamo Bay, the current crusade against whistleblowers. These are just some of the biggies I'm familiar with.
I've never seen any evidence that the US government as a whole cares about rights until the courts and people MAKE them, and I've seen plenty of politicians and law enforcement officers sounding off in the press about how some big new threat necessitates the completely unconstitutional and usually unethical and immoral conduct they are about to engage in.
BTW -- the Government is made up of people. Citizens. People become politicians because they are voted in by other people. I find it unusual that people talk about "government" as if it is something that is detached from the citizens. People are the Government. People determine the direction of Government.
If you forget that people are the Government then you've pretty much given up on democracy.
Government is a mob -- it is up to those outside the mob to keep it aimed in the correct direction, because it won't do so on its own.
My suspicion is that the FBI had a warrant for somebodies "server", without any consideration given to what "a server" means in terms of physically removable equipment compared to what someone like Marco actually gets when he leases "a server".
I'll bet no one tried to explain to the judge signing the warrant that the "server" they wanted to seize was actually a blade card sitting in a chassis with a bunch of other blades (that were _other_ people's "servers" (on which they were running their businesses), and that the "disks" for the servers they wanted to seize were actually virtual disks sitting on another piece of shared hardware...
And I wonder what we'll be deploying on when the law catches up with today's standard hosting practices?
It's also possible the FBI just took a rackful of diskless blade servers, and have no evidence at all, target related or not...
What would be odd is if the FBI pulled out only the blades they were interested in at the data center and left everything else intact. What's much more likely is they took the entire chassis as it is in working condition so they could do their analysis. If they missed something or their warrant didn't include additional enclosures or equipment then they'll probably be back with a second warrant to collect the enclosure with all the storage arrays.
I'm definitely not an apologist for the post-9/11 police state, but that's a pretty silly conspiracy theory.
For example, if they think they may have imaged too much, do they promptly and irreversibly wipe the extra? Or keep it, just in case their assessment of its relation to the current investigation changes again? Could current or future automated criminal-activity-analysis engines be run against every old disk image in their possession, ignoring the details of how/why they were collected?
As problematic as that is, it's a drop in the bucket compared to things like Echelon. I think people should be realistic about their paranoia.
Physical access to systems is far more problematic. Even if the data is nominally encrypted on-disk, the key must be in RAM to make use of the data, rendering it vulnerable at the time of seizure. (You can partially mitigate the risk, but you can't make it 100%, and it's very likely you'll have issues with cost, performance, and user-friendliness along the way.)