The FBI's internal guide for getting data from AT&T, T-Mobile, Verizon
vice.com
vice.com
I think it would be interesting to know how people really feel about this. I would love to see a survey that actually truly explained the trade-offs and see how people felt about it, eg avoiding the “ should government be able to subpoena records from private business” but actually ask questions like “is it OK with you that with a subpoena that the government can get a list every website that you have visited?” And then present the trade offs and abuse cases. I really think that we’ve allowed the surveillance state to form without actually having a meaningful public debate about it.
Let's face the truth: none of us is safe. Everything we do, even if we are just oedinary 9-5 office workers and not politicians or activists, is ending up recorded somewhere.
The only way out would be a nation-state effort of open source: everything from the VHDL of the chips over firmware to the OS, and enough money to fund audits of all components. At least, users could then somewhat trust at least their clients, and treat the network as a dumb leaky network of pipes.
Do you think US intelligence don't also have the same? We've already seen a sitting US president hire intelligence agents to bug his enemies and political rivals, it's not like there's any reason to suspect that was a one time occurrence.
Do you have a source for this claim?
We kept the concepts separated, and weren’t paying attention.
Then why is capitalism being killed and replaced with corporatism? Why is everything industry consolidating having one or few very big players and no medium and small businesses?
This has been going on for a long time. A decade ago, Microsoft purchased Skype and converted it from secure peer-to-peer[0][1] to sending all user data unencrypted through their servers while giving the government access to everything. "The 2013 mass surveillance disclosures revealed that Microsoft had granted intelligence agencies unfettered access to supernodes and Skype communication content."[2]
[0] https://arxiv.org/abs/cs/0412017 (2004)
[1] https://www.reuters.com/article/us-security-internet-germany... (2007)
[2] https://en.wikipedia.org/w/index.php?title=Skype&oldid=10314... (2021)
There was never a real problem for law enforcement to solve. All we ever needed were reinforced cockpit doors.
/s
Sword of Damocles is hanging over our heads
The US system is superior to China because we have checks and balances that actually: 1) uncover this stuff, 2) share it with the public, 3) have a system to provide feedback, 4) courts to uphold rights.
The US system isn't perfect and it isn't always fast, but the point is there is a system of checks and balances that hopefully bring it back to what the people intend it to be.
1) surveillance of citizens in China it is public, no need to uncover anything 2) in China their government already shared it with the citizens since it's official policy 3) since when the feedback started to matter? 4) that it's very naive to assume that the laws and the courts will always be free of abuse and will always protect the freedoms of the citizens, protect their interests and protect the innocent, we are far from living in a perfect world: the only way to make someone can't abuse his power is to not give him that power. And they have courts in China too, if that matters.
"we are far from living in a perfect world" well yes. And we never will live in a perfect world where privacy is never violated. There will always be people willing to break the rules to benefit themselves.
And since when has feedback mattered? It matters all the time? I mean the Democrats won an election and are now proposing a massive spending bill taking the country in a very different direction, just as one example.
- with secret FISA courts whose cases and rulings are unknown
- that will imprison recipients from even saying they got a security letter
- threaten to imprison the very people who exposed the NSA spying on you.
- etc. etc.
Come now, some perspective and humility.
What good is it when the fundamental principes arising from those assumptions are constantly being eroded? It appears some american states restrict even the bearing of arms now. If the founders of the USA were to resurrect today, I wonder what they would think about the nation they created.
I don't understand the fetishisation of the US "founding fathers". What does it matter what a bunch of people who lived 200 years ago thought and wanted and how they would feel about today's version of that? Considering some of the things that were normal in their time, like slavery, the subservient role of women in society, power only in the aristocracy or rich people ( even the "bastion of democracy" US wasn't a popular democracy where everyone had a vote until after WWI), segregation, etc. of course they'd disagree. And so would Louis XVI, Franz Josef, Queen Victoria, Hitler, etc.. so what?
Who cares what those people would theoretically think and why?
The advent of smartphones, social media, search engines, pervasive online shopping are all absolute boons for surveillance entities.
And the best part is that the users/public just gives all of this info up willingly and for free.
The only way to avoid this would have been to design the Internet as something Tor-like from the beginning, which would have been impractical from an efficiency standpoint.
If you are in the US: Should you support Israel?
If you are in the UK: Should you vote to leave the EU?
If you are in Germany: Should you support US troops in Asia?
If you are in Australia: Should you support economic treaties with China?
Advertising techniques can sway you - and large portions of the population - into supporting or not supporting many facets of policy. If the Arab states want to destroy the Jewish state today, they would not send troops. They would fund influence of opinion of the American and European population.
Actually, they already do.
Unfortunately, the average person's intelligence has remained constant.
Especially since it's been happening for awhile now and nothing outright bad has happened to most individuals. They just enjoy using Instagram. They see a targeted ad and are like "oo scary... they know me" and then continue on.
Well, yes, that's essentially the whole point of silicon valley. The government and military fund the creation of startups that have tactical value. Those businesses become self-funding and improve the US economy, which also has military value since a robust economy is harder to attack. This has been explored in a few places, e.g. [0], [1].
But it's not like any of this was secret. The off-loading of government operations to private industry, combined with the lobbying for reduced regulations on private industry effectively gives the government carte blanche with the added bonus of plausible deniability.
Whether or not these trends are good has been debated for half a century in the US.
[0] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...
The government can't take it by force without a warrant. But the company is free to give it to them if they ask nicely or otherwise.
The issue is that they (i.e. government) have always done this. I'm only 35, but I remember this being very clear immediately after 9/11. You just say the boogeyman is terrorism, and that is used to justify end-runs around the constitution via the "PATRIOT" Act, etc. etc. Before terrorism, the excuse was communism. Maybe I'm just cynical now or read too much "1984" as a teenager, but I feel like there will always be a new boogeyman that they use to justify more authority, more powers, and all the while saying it's for our own good and to 'protect' us.
Our current electoral system: https://m.youtube.com/watch?v=s7tWHJfhiyo
What about the patriot act?
There are tons of other examples about how this isn't a partisan issue, and getting people to think of it as partisan only helps their goal in getting it through.
However, a lot of current surveillance is more about snooping. That's where it crosses the line for me. I guess it comes down to ownership. I should own the text messages and call logs because I have access to them. AT&T can own the cell tower logs because they own the cell towers.
https://apnews.com/article/artificial-intelligence-algorithm...
> Employees can and do modify the location or number of shots fired at the request of police, according to court records.
You will find yourself on the short list of suspects because you were in the area of a crime. If you actually read some news you will also find that it is often because one of the law enforcement decided their "gut" feeling was you are most guilty loooking and now they have a solid starting piece of evidence to use against you.
How long until the government finish outsourcing of all its attributions to private entities and corporations take ownership of governance? Then instead of voting, the citizens can manifest their interests through buying shares.
Isn't this sort of how it already works? Although only a few (very rich) citizens hold enough shares to actually have any clout.
Isn't it for the "Greater Good™", as always? :D
There's a rather innocuous sounding name for this - "public private partnership" [1]. If you've ever experienced this scenario first hand, you'd truly be surprised how much government is run in partnership with private enterprise.
[1] https://en.wikipedia.org/wiki/Public%E2%80%93private_partner...
>A ministry supervising state companies, the State-owned Assets Supervision and Administration Commission, is mapping plans to set up more government-controlled providers of cloud services for data storage, people familiar with the agency’s workings say. Such services have been dominated by private companies, including Alibaba and Tencent.
>The city of Tianjin has ordered companies it supervises to migrate data from private-sector cloud platforms to state-owned ones within two months of the expiration of existing contracts, and by September 2022 at the latest, according to an official notice dated Aug. 12. More localities are expected to follow suit, the people say.
>Government-controlled entities are acquiring stakes and filling board seats in more companies to make sure they fall in line with the state’s goals. ByteDance Ltd., owner of the video-sharing app TikTok, and Weibo Corp. , which runs Twitter-like microblogging platforms, recently have sold stakes to state-backed companies.
https://www.wsj.com/articles/xi-jinping-aims-to-rein-in-chin...
How would you vote to get to this meaningful debate in the first place?
When I did it, I could see they recorded IP addresses, time stamps and data transfer volume of every web site that I visited over their network, along with cell tower connections. It was fascinating.
I suspect a VPN user would show up in the Verizon data file with many large TCP sessions to a very small number of IPs.
Just curious, how many captchas do you solve with this setup daily? Or even IP bans?
I did exactly the same thing once and it was so annoying.
I set up a VPN on a Digital Ocean instance and got captchas all the time on various websites, especially ones using CloudFlare etc (I’m aware of Privacy Pass but didn’t bother setting it up as it was a temporary thing)
That said, if you're using your own EC2/lightsail instance you won't see as many CAPTCHAs as, say, using a commodity VPN service.
Given you can't detect a VPN per-se (if configured properly) usually the way it works is that the destination node knows you're coming from a source IP from a known VPN-supplier's well-known IP-block.
If you go for this kind of setup (running your own VPN on AWS) you're simply changing your ISP to Amazon. They still might (and probably will) be monitoring egress traffic at the very least to perform any kind of incident analysis.
Lightsail costs $3.50/mo with 1tb transfer bundled or $5/mo with 2tb.
If your setup is scripted then it probably makes sense to switch over to save a bit of cash. Others following the same path could save some money by using Lightsail as opposed to EC2.
I personally use lightsail for most always on things and then just use ec2 for on demand workloads, because it works out far cheaper (these are just random personal projects so I'm heavily optimising for low cost)
You can't configure the lightsail instances as much as an EC2 instance, but otherwise it's essentially the same product (both operated by AWS).
Generally speaking, this makes me feel a better when using mobile data or any foreign network (public, friends, work, etc) since I know all of my outbound requests are coming from "one location".
I can reroute outbound access to an external VPN if/when needed, but it's really a crapshoot for who you trust to keep track of your outbound requests. I don't trust any VPN out there to be strong enough to say "NO" to an intrusive 3rd-party like the US gov. No more than my own ISP at least.
For someone overly paranoid about tracking, I would probably suggest just using Tor, but for basic consolidation of internet access, routing through a self-hosted VPN at home works great.
I'm curious if other have done the same.
This stuff is barely scratching the surface of the data those companies collect and maintain, likely for long periods of time, just to analyze and improve customer experience.
> data transfer volume of every web site that I visited over their network
Aggregate data usage is one thing, but retaining any kind of detailed logs on where one goes or how much data was used on a specific site is unnecessary for the base provisioning of network connectivity.
Heh, just to analyze and improve customer experience? Nothing else a bit more unsavory?
> Heh, just to analyze and improve customer experience? Nothing else a bit more unsavory?
The point is this data would get captured regardless, surveillance or no. Mass surveillance (at least in this matter) often isn't so much about what gets captured, but how long it gets retained and who gets access to it.
I found this article [0] describing the situation in various countries, with the following info for the United States:
> Data Retention Period = 1 Year for Internet metadata, email, phone records
> Authorization required to access the data = Various United States agencies leverage the (voluntary) data retention practiced by many U.S. commercial organizations like Amazon through programs such as Prism and Muscular.
> Status Of Data Retention Regime = No mandatory data retention regime
I'm guessing the above means that metdata (user ip and also user web and email destinations) are held for a year, but retaining actual user data (email contents, etc) is not mandated.
4.4 trillion database entries in a year
Meaning, the cost to record everything a person does all day, every day of the year for literally forever is not very much at all.
Please see my answer here https://news.ycombinator.com/item?id=29003198
Very helpful when filling out the time report if you are reporting time on many different customers.
If a company force installed it on your PC it is probably not a good place to work at.
It is not uncommon for me to have 15-30 different time tracker entries for things I worked on in a single day. This is not an exaggeration. Then other days I will work on a single task for entire day.
So all of this unscheduled stuff gets lost pretty easily. Calls scheduled for an hour run only 30 minutes. Client A needed 10 minutes of support here, 20 minutes there, 5 minutes there. I want to be as fair as possible to our clients.
And related to client support, there is often the question of "who owns this bug" and who pays for the call. So I can use screenshots of the client environment to relate to the team and get more information about whether we should really be billing for the call or if that's something that needs to be improved in our software.
Also I support other developers. Skype calls with developers tend to be short. But boy can they add up. If I'm spending 3 hours a day on support overall, I really need to track that. That time needs to go into the right project at the very least.
So that's where the screenshots come in. This is not something the company asked for or have ever requested access to. They know I do this. So when I say I spent two hours supporting a client, they feel confident sending out that bill.
It actually started as one of those experiments into time lapse video. But I multitask way too much for these to be usable videos. Though I have hand picked select days and turned them into something very cool.
do you know what this “cloud storage internet/web browsing” data looks like?
What about android?
probably doesn't matter because regular dns is performed in the clear. There's nothing preventing them from logging/intercepting your requests even if you changed them.
>Odd that iPhones let you change it for wifi, but not cellular.
>What about android?
AFAIK on both changing DNS can be done by using an app that acts like a VPN, and intercepts the DNS requests.
The latter could be construed as necessary logging while the former is spying for the sake of spying.
Network Settings -> Advanced -> Private DNS
Enter one.one.one.one (or substitute your favorite DoH-supporting resolver)
- Cloud Storage
- Internet/Web Browsing
In the big picture it’s probably fine to conflate them but the technical aspects of each are going to be very different.
> Ping: The network sends a message to the phones internal GPS receiver to report it's location (must see min. of 4 satellites. GPS coordinates of device and suspected radius from tower e-mailed(or through L-Site website) every 15 minutes for 30 days. Can be done manually every 5 minutes.
I wonder if this is facilitated by one of those infamous "carrier app" backdoors included in stock OS but not e.g. in GrapheneOS:
https://grapheneos.org/faq#cellular-tracking
https://gist.github.com/thestinger/171b5ffdc54a50ee44497028a...
https://github.com/dan-v/rattlesnakeos-stack/issues/69#issue...
There's Enhanced 9-1-1 but its GPS access should be mediated by the OS? Hopefully?
They can query location remotely using GPS and likely turn on microphone too.
They also have the longest and deepest history of working with the government on surveillance.
AT&T lost iPhone exclusivity a decade ago.
I've long considered ATT to be an extension of the US intelligence apparatus. Ownership doesn't matter, it is who they answer to.
What's the arrest funnel? Do they use Salesforce to store all their leads as well?
Sprint may be able to translate IPV6 addresses (ex. 001:0db8:0000:0042:0000:8a2e:0370:7334) to a phone number.
Interesting, anyone know which aspect of the IPV6 protocol allows for this?
The main difference is whether the subscriber side uses an IPv6 or private IPv4 address, but on the internet side they are equivalent.
Establishing a best practice for public/private sector communication keeps the govt in check and helps companies ensure compliance & transparency.
An ethical and transparent way to handle such subpoenas would include:
1. If possible, not being a US company so you might be able to avoid the subpoena in the first place.
2. Have a policy of not keeping user data at all, or keeping it with a third party that is not legally bound by US government subpoenas, so that it can't (?) be subpoenaed.
3. Publish any subpoena you get from the government.
4. Moreover, arrange it so that subpoenas are published before being read, so that if you get a National Security Letter, you would not be able to comply with the non-disclosure requirement. Another way to go about this may be to only open subpoenas in a public forum, preferably with journalists present. Try to consult ACLU/EFF lawyers about this particular issue.
5. If the government somehow gets its hands on user data, inform the users immediately.
You appear to be passionate about the issue at hand, but your knowledge on this process seems to be limited.
1. Not being a US company doesn't matter - international agencies send subpoenas just like the US agencies. US govt can send subpoenas to international companies just the same.
2. Not having PII or user data doesn't prevent subpoenas (i.e. Reddit, 4chan, Whisper, etc.)
3. Subpoena’s often come with Non-Disclosure Orders (NDO). Even without NDOs, publication of the actual subpoena is arguably more irresponsible just by the shear fact you could be publicizing PII, and subjecting this user to unfair, and non-contextualized public opinion. Big tech has adopted transparency reports for this reason. User notice is the goal - not publicly shaming your user just to make a point to the government.
4. Non-compliance and willful disregard for the legal order will not change the overall problem. Ironically, you're right that the best way to prevent data requests from the govt might be non-compliance...then the company would get shut down for said non-compliance...so there would be no company for the government to subpoena.
5. User notice is obviously a legal department best practice, but if there is a NDO it puts legal repercussions on a company for disclosing such info. Keeping this process clunky/messy/disorganized hurts the user, and the company. You say this company is not ethical, yet Kodex automatically informs users about data requests pertinent to them, and if there is an NDO, the user is notified immediately upon expiration rather than relying on a legal department employee to remember to manually do it months or years later. Would it be more ethical to keep the process unchanged and prone to human error?
These guides for Law Enforcement (LE) to get data are actually meant to streamline the process for the company, so companies don’t have to deal with non-valid subpoenas. The subpoena is coming regardless…why waste time/resources dealing with non-valid subpoenas when educating LE will help streamline things. Obfuscation is never going to prevent these legal orders…if the FBI wants to send your company a subpoena they are going to whether you tell them how to do it properly or not. Kodex is a best practice that standardizes how the govt can interact with companies, to keep the govt in check, while keeping companies compliant, transparent, and accountable about the process.
As the writer said: “There is a lot that can be fixed in government. This process is one of them. The goal is not to ‘help the FBI do their job more easily’… making the process easier for the company, forces the government to do their job BETTER, and helps society move forward.”
2. Not having PII or user data may not prevent a subpoena, but if you're subpoenaed for data you don't have, then you just write back saying you don't have such data.
3. If your process of handling mail is transparent to begin with, the order is (probably, hopefully) moot. I had assumed only NSL's can have such non-disclosure orders, but I guess the USA has a slightly more repressive regime than I had assumed... as for subpoenas containing PII - do you mean about the people the government wants to spy on? It's morally necessary to publish who the government is spying on. I hope (though, again, not a US lawyer) that such publicizing this is protected by the first amendment anyways.
"You say this company is not ethical, yet Kodex ... informs users about ... an NDO ... immediately upon expiration"
So, the Kodex+its client would hide a subpoena from the user while it is in effect. This is most likely unethical, and certainly immoral.
4. Mass circumvention (or disregard) of government orders will most certainly change the overall problem. Just like general disregard of copyright infringement of file sharing platforms and applications has had significant effects on music distribution, academic publishing etc.
5. The process doesn't need to be clunky, messy, or disorganized - but certainly, a primary concern must be preventing the government from secretly spying on people.
1. “I doubt they [international agencies] send the kind of subpoenas…” - It’s a gross display of willful ignorance to assume things just so it agrees with your opinion. This is Facebook’s Transparency report (https://transparency.fb.com/data/government-data-requests/co...) They are just one example, with hundreds of thousands of requests coming from outside of the United States. There are 195 countries in the world…170 of them have sent them to Facebook alone.
2. You are literally proving the point of why those data guides were created…so no one asks a company for data that they don’t have and waste everyones time/energy. The reality is that every company has some form of data…if a company didn’t have any sort of data how in the world would they be able to display any information, or do literally anything ever? There is always something to ask for.
3. Lol so many absurdities going on with this bullet so buckle in:
3.1 - “If your process of handling mail…” - So do you not use email? Most people graduated from mailing addresses to email addresses because it was a better way of doing things and easier than mail…most companies use emails to deal with subpoenas…a tool like Kodex is easier than email and takes the burdens away from this legal obligation…keeping the process difficult only makes it difficult on the company, not the govt.
3.2 - “USA has a slightly more repressive regime than [you] assumed…” - NDOs are used so the subject of a case isn’t tipped off. For example, would you prefer pedophiles to be told “the FBI just asked for the CSAM on your google drive” and have the pedophile go dark/get away, and continue to abuse innocent children as a result? Is that “repressive” towards the pedophile? Or a necessary legal vehicle to protect the innocent? Would you rather the USA take the unfortunate approach that some countries do, and not do anything about heinous crimes like that?
3.3 - “Who the government is spying on…” - “Spying” and “investigating” are two very different things. Choosing to use the language “spying” for a subpoena is either ignorance, or a determined effort to fit the narrative you want and demonize what is actually going on. Subpoena’s are legal documents that go through a court. Spying does not. That NSA/Snowden scandal had nothing to do with subpoenas…that was all Top Secret spy programs that did not involve courts, or legal documents…Subpoenas are all unclassified information used for investigations, not on-going spy programs.
3.4 - “Publicizing…Protected by first amendment…” - You can’t yell fire in a crowded movie theater. Aka Free speech is moot when it is “a clear and present danger that they will bring about the substantive evils that Congress has a right to prevent.” You have a right to express your opinions, desire’s etc, but not to put others in harms way. These investigations are to prevent harms.
3.5 - “Hide a subpoena from the user while it is in effect…” - Kodex makes it easier for the client to follow the law, and allows them to ethically follow up with the user once the law no longer prohibits the company from doing so. Would you rather hope the company just remembers to go back to the mail room and fish through a file cabinet to see which user should be notified each day when that isn’t a priority for the company’s bottom line? Or would you want the company to be automatically reminded when such a date comes? Keeping this process more disorganized than it needs to be just for the sake of silently convincing yourself you live on a higher moral plane is what is more unethical.
4. “Mass circumvention…” - You seem to be willfully ignoring the fact that consequences exist, once again. You know copyright infringement/file sharing pioneers like Napster were ultimately shut down…right? You know, because it was illegal and the consequence was…being shut down? If you try to say that changed the music industry to help the onset of streaming/Spotify you might be right, but then why would you ignore that something like Kodex can be the same type disruption to subpoena processing that streaming was to music…making it easier and more accesible? Moreover, it wasn’t the general disregard for the rules that created Spotify, it was the realization of the desire for instant access to every song, rather than pay $1.29 for some songs.5. “The process doesn’t need to be clunky, messy, or disorganized” - Thank you, I agree!
I’d encourage you to learn more about this topic, because you seem to have put little effort into understanding what’s really going on, and instead have chosen to just yell at the sky/internet about what you think is going on - simply for the sake of yelling.
I can't imagine this working more than once, the goverment can just verbally inform you of the non-disclosure requirement when they deliver any future documents in person.
In Jujitsu, that's the way it works. You create a new technique, or rediscover it, you get one free shot at Sensei, and then it doesn't work the same anymore.
You might do this once, and "win" the battle. The federal government will come for revenge.
This is all great, but does this mean that the local provider has no access to my traffic? I guess DNS is all resolved overseas too? How does the tunnelling work?
https://www.firstnet.com/power-of-firstnet/firstnet-advantag...
>FirstNet is designed with a defense-in-depth security strategy that goes well beyond standard commercial network security measures, providing protection without sacrificing usability. And now, we’ve gone farther than anyone in the industry to secure public safety communications. FirstNet will be the first-ever network with comprehensive, tower-to-core encryption based on open industry standards.
Which implies every other network doesn't encrypt that traffic (or does it with some proprietary scheme... which wouldn't give me a lot of confidence)
Like, if your eNB is a picocell or feeding a DAS, it probably is doing backhaul over IPSec over internet or dedicated circuit, but if it's normal carrier network, likely not.
ref Page 37 of https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
Under the "Location Based Services" chart, US Cellular is listed "No. However, you can force a call without a ring to the target device to determine tower/sector"
It appears to be possible to do quite a bit of location tracking/location verification without any help at all from the telcos. The calls they are referring to seems to mean calling a phone and hanging up quickly. This causes the cell network to issue a high priority RRC paging request (someone is calling you!) which causes your handset to wake up and begin broadcasting to the cell network.
This enables passive eavesdropping and coarse location detection via monitoring the RF lansdcape for TSMI/IMSI collection and correlation. It is then possible to narrow down a large area to the specific cell, ~2km area, from there you can use another beacon or maybe regular direction finding and trilateration to pinpoint a signal. This sounds like an operation which requires 3-5 operators, but I don't know about the procedures.
Some cell network packets contain GPS location and other subscriber data, which could be intercepted and analyzed by this advanced threat.
With the aid of a Cell Site Simulator/Stingray, it seems to be possible to use this method to sense the handset and then use the CSS to hijack a handset's tower association turning coarse location data into a normal MITM. There are many other location sensing techniques such as a GSM Tripwire device or packet analysis.
Interesting stuff. The cell phones are rather evil.
[0] - https://www.eff.org/ro/wp/gotta-catch-em-all-understanding-h...
It doesn't have to be a no-ring call, it can be anybody at all with a legit call, text message, etc. Its favorable for the operator to do so in a way that will not alert the user, hence the no-ring call stuff.
In my experience some handsets will report fast hang-ups as a missed call, and others won't.
You can probably enable airplane mode/rfkill to shut down this threat from the less spooky nerds who would use it. No GSM radio = no GSM packets.
Including a table that listed which providers would hand over data without a subpoena and what the retention period was for each provider.
One of the interesting things I remember seeing was that it was noted that T-Mobile had never been able to supply such information to LEO.
I have seen it before but never had direct access to it.
I never thought before that ISPs would really keep track of every user's browsing history, but apparently as cheap as the disks are today, this has become true. Can't think of any use of this data other than for mass surveillance.
Perhaps that's what you mean by "mass surveillance", but I took that to mean specifically government surveillance.
These leaks seem... like they would get someone indicted...
I'm not talking about heat-of-the-moment things, but literally anything requiring any sort of planning or organisation (kidnapping, gangsterism, etc) should be solvable with this. So why isn't it?
*Note, I don't want an uber-surveillance state - my point is that we already have one, and any feeble excuses from law enforcement about solving 10s of thousands of crimes with "ooops we can't figure it out" seems utterly hollow and untrue.
My guess is that this looks like training material for low-level desk jockeys to help do all of the legwork gathering evidence that would be presented in court cases.
Stingrays you would think would be more of a targeted operation and likely handled by a different group of people.
The second slide seems rather suspicous in its placement of "CAST members are not qualified to testify after reading this"; almost as if they were not speaking to an audience of CAST members, but rather, the public.
Perhaps a decoy? to draw attention away from STINGRAY and other intricacies?
Sounds like they are doing advance witness tampering by trying to get CAST members to evade calls to testify on material facts known to them should they receive such, not lobbying the public via anticipated future leak.
(I’m not even sure how the statement about testimony would be expected to manipulate the public.)
If you’ve ever had to testify as an expert, it’s an art and a science. You need a lot of training to be able to respond to the traps attorneys will set for you.
I did some work on their compliance team in 2010/2011 and the merger was one of the reasons why I left.
Funny enough, US Cellular divested their Chicago holdings back in 2012 to Sprint but never moved their HQ. None of their HQ employees have cell service through them.
If you aren't careful, your target could become aware of their presence.
If you are pulling data from the carrier, there's less logistics involved and your target shouldn't notice unless someone screws up.
In the EU people are more pro-government and anti-company so the government is more likely to have access.
The US process for access is sometimes tied to FISA.
I'm not an expert on this stuff, but I think I'd generally prefer companies handling retention and government having to request access rather than the other way around. Assuming (probably a big assumption) that the companies do it securely and don't fuck it up.
The chart does make me pretty happy with T-Mobile though, and their 5GUC speeds are wild! https://twitter.com/zachalberico/status/1449049818857459718?...
It's pretty efficient, if the government announced they would save some files on all citizens, it would be widely unpopular. So let the people use the services they consent to use, let the businesses collect as much data as possible, the more, the merrier.
And when the need for these resources arises, subpoena the business, they'll even do the search for them.
As far as I understand, there are 3 mobile networks in the US (Verizon, ATT, T-Mobile), and the MVNO’s are just a mechanism to price discriminate. Different customers are sliced into various priorities and willingness/ability to pay, so the 3 mobile networks can most accurately collect the most money according to each individual’s ability and willingness to pay for a certain level of priority on the network.
And bonus question for what they do when they need to pull put bank statements.
> Do nothing, we already have this data loaded and indexed.
https://www.businessinsider.com/the-story-of-joseph-nacchio-...
https://www.denverpost.com/2014/03/27/former-qwest-ceo-nacch...
https://en.wikipedia.org/wiki/Joseph_Nacchio
And let's not forget the number of people put the jail without the government disclosing the use of stingrays to the defense attorneys:
https://en.wikipedia.org/wiki/Stingray_use_in_United_States_...
https://theintercept.com/2020/07/31/protests-surveillance-st...
From the wiki page:
>On March 15, 2005, Nacchio and six other former Qwest executives were sued by the U.S. Securities and Exchange Commission. They were accused of a $3 billion financial fraud between 1999 and 2002 and of benefiting from an inflated stock price.
Interesting that Nacchio was prosecuted for this but almost no one else is.
There's nothing noteworthy here.
You are literally presenting an opinion at face value ...
That seems like a colossal Catch-22.
As to the selling of shares - prima facie, that's likely criminal (insider selling) but I don't know the details of his case.
You do not need to acknowledge that you received an NSL in order to acknowledge you are no longer providing services to the NSA. You do not need to reference the NSA or NSL at all in order to correctly state revenue, because you are not required to show all of the entities with which you're doing business.
It is fully possible to pretend you simply lost the NSA contract for non-NSL related reasons. His fraud is his own doing
And this is the guy I'm supposed to be sympathetic of?
These kinds of stories get 'forgotten' very quickly.
I’m not defending the sedition act, but it’s quite important that it was implemented during a quasi-war and was still barely passed. There’s also a reason that two hundred years later it’s constantly held up as a paragon of bad law and there’s no way it would pass judicial review at any point since then (it didn’t at the time either, because it expired 2 years after it was passed and before judicial review was established).
Now, it turned out that "meddling" amounted to buying facebook ads. Not really a huge deal.
But more importantly, since you brought up the founders - what would they say about the fact that we apparently have at least 17 federal agencies dedicated to spying.
https://www.mountvernon.org/george-washington/the-revolution...
> Among other honorifics, George Washington—known as Agent 711 in the Culper Spy Ring—is often heralded as a great “spymaster,” and indeed, he was. Under Washington’s astute watch, several networks of spies operated in both close-knit circles and far-reaching societies.
> Washington recognized the need for an organized approach to espionage.
https://en.wikipedia.org/wiki/Intelligence_in_the_American_R...
> The original Committee members—America's first foreign intelligence agency—were Benjamin Franklin, Benjamin Harrison, Thomas Johnson and subsequently included James Lovell, who became the Congress' expert on codes and ciphers and has been called the father of American cryptanalysis.
> On June 5, 1776, the Congress appointed John Adams, Thomas Jefferson, Edward Rutledge, James Wilson, and Robert Livingston "to consider what is proper to be done with persons giving intelligence to the enemy or supplying them with provisions." They were charged with revising the Articles of War in regard to espionage directed against the American forces. The problem was an urgent one: Dr. Benjamin Church, chief physician of the Continental Army, had already been seized and imprisoned as a British agent, but there was no civilian espionage act, and George Washington thought the existing military law did not provide punishment severe enough to afford a deterrent.
That's three right from the start.
If you look at the fate of people like Aaron Burr, I think it’s quite clear that the founders were not supermen, but humans who dealt with similar problems that we do today. Likewise, the post-revolution treatment of tories wasn’t exactly magnanimous either.