>As a result we are currently developing new data retention and disclosure policies.
“I guess we don’t actually need that” should have been the idea from the start.
I'd say they followed "I guess we don't actually need that" approach reasonably well so far and good for them if they want to improve that even more.
On top of all of that, it's volunteer run and has been understaffed for basically it's entire life, so sitting down and figuring out a proper data retention policy that takes a holistic view of everything we have just never bubbled up.
In general I think we already do a pretty good job of collecting a minimal amount of data, and hopefully with proper policies we can do an even better job.
While they are transparent the events happened, they are not transparent about which packages and what authors are being flagged, which is unfortunate.
Considering they are admitting they will always obey government commands, including regarding non-disclosure of actions to affected users, it is prudent to assume they are, in fact, not transparent about events; only about those events which the government has let them tell you about. Other events (e.g. National Security Letters) may or may not have occurred.
Which is the most important part.
Edit
I read 'chaps as saying there was an NDA on the subpoena, but apparently there wasn't, so this might just be flatly wrong.
Never made sense to me. Terrorists and other very bad people usually aren't in the business of following laws so I don't know what crimes you'd prevent by weakening the rights of everyone else.
Let's say someone stole your identity and in the process they emailed all your financial documents to example.anon12345(at)gmail. If you contacted the police and the FBI subpoenaed Google to force them to give them the details of whatever they know about that accountholder, is that bad and hurting the rights of somebody, or is it protecting your rights?
Does it change based on the despicableness level of the crime suspected? From one count of copyright infringement of a Taco Bell commercial, to organized retail theft rings, to identity theft, to CSAM, to terrorism?
I'm not saying you're wrong, I'm just curious what the "We hate subpoena power" argument is so I can decide where I stand on it. I feel mildly like I'm not as bothered as you are, but I suspect I'm missing something.
Also, should "online" operate under different rules than offline? If the "feds" have probable cause that some guy is a drug kingpin and they break into his office and his safe to seize evidence, is that equally bad as forcing Google to open up his Gmail account for them?
Surveillance does not reduce crime, tending to people's basics needs so that they don't need to commit crimes reduces crimes.
> the government read everything everyone wrote/texted/read
is this really a relevant analogy for this? And yes, I've heard of the mass surveillance via telco that we did find out (through Snowden) was happening, and do think it seriously crossed the line. I'm just wondering if this kind of case at issue has anything in common with that malfeasance at all.
Is it your belief that they lacked any probable cause and are actually trying to persecute those 5 people for some reason?
Rather than try to argue against a position I'm not fully understanding, I'd like to hear how you think police should solve crimes with a significant "cyber" component.
Child porn and terrorism are the favorite subjects of politicians looking to enact a new law but idk if it's good to follow that thinking and use it as an example as opposed to a serial killer or something