Apple:
> "We have never heard of PRISM", "We do not provide any government agency with direct access to our servers"
https://web.archive.org/web/20130609061546/https://www.culto...
..some things are just not discussed on public forums.
Apple:
> "We have never heard of PRISM", "We do not provide any government agency with direct access to our servers"
https://web.archive.org/web/20130609061546/https://www.culto...
..some things are just not discussed on public forums.
They can essentially conscript anybody in the company to work as a spy using (probably bullshit but still intimidating) legal threats to keep them quiet.
Yes, "evidence for a secret program" is a bit tricky to produce, but the one I know of - Doe v. Ashcroft - the president of the company was compelled to produce data. I'd be very surprised if this wasn't the universal approach.
My immediate reaction to such a letter would be to contact the company legal department regardless of whether the letter said not to, simply because I'd assume unless given very good evidence (and originating from a .gov domain isn't good enough) that it was a scam.
Edit: According to the EFF you can talk to an attorney about an NSL.
An email/phone call to a legal department is much less work and provides all the same protections.
So actually Apple was being honest. They had not heard of PRISM, because that term was only used inside the NSA. And they were not allowing direct government access to their servers, they were responding to FISA warrants.
If we are being pedantic, one can claim that all data, can be very well anything because there is always a "one-time pad" transforming all communication into something malicious.
If the law is not precise, then it is on the government to improve it.
For example, imagine a Login page that said, "Password incorrect," versus "User does not exist." If you have "User does not exist," you could use that to figure out whether a given email address has an account with a service. That could be useful information to PRISM when looking for a target to subpoena or monitor. (This is also why it's now best practice to just say "Login incorrect" or something vague that doesn't say whether the username, or the password, was wrong.)
Though, I could be wrong, I'd love more info.
Direct access to the data was mentioned in the Guardian and other newspapers
It goes further than just the error message. I think the original exploit was based on how quickly Unix would fail to login. (Bad user failed faster than bad password) and that allowed you to enumerate the user names.
I have always associated that period with the discovery of Prism. I would love to hear if anybody knows what I'm talking about.
I don't really mind it either anymore, a lot of people have this hero worship fetish and they can't help painting everything in black and white, even though they're all just different shades of gray.
Apple is definitively brighter on that scale then Google or Meta, but they're all corrupt multinational corporations that will do everything they can get away with to increase their bottom line.
Or do you live and operate like RMS?