This Internet provider pledges to put your privacy first. Always.
news.cnet.com
news.cnet.com
You can go a reasonably long way with just best practice privacy policy (requiring court orders, keeping minimal records, locking down configs, obfuscating IPs, not intentionally compromising privacy), but there are a couple issues. One, a lot of big ISPs (from what I've read) are only profitable due to selling clickstreams or other privacy-invading things. So a privacy-protecting ISP will cost more for the same service (or, will offer crappier bandwidth).
Second, once you move beyond this level of security, you're trying to defeat traffic analysis, and then targeted attacks. Targeted attacks are probably out of scope (and really expensive to defend against), but defending against traffic analysis usually requires burning a lot of bandwidth, or scheduling or routing communications in strange ways (which adds latency in various ways). This makes things REALLY expensive, and especially for wireless systems, uses up the finite spectrum capacity.
Ultimately the best way to really protect privacy is to structure applications to be message based, tolerant of latency on the order of hours, and basically non-interactive. This is the opposite of how ~everything is done on the web -- email is probably the only widely deployed application which works like this, and that's why email has the best anti-traffic-analysis systems out there (mixmaster/mixminion remailers).
Plus, there's a big problem with declaring yourself "the ISP for people who want to be anonymous" -- it self-selects, especially if it's a small pool of users due to higher cost, into a great target. Either the organization itself is evil and secretly monitoring, or just becomes a hacker/government target (which could involve monitoring on the perimeter/upstream). The best model is some combination of making privacy protection a default feature of protocols, having a bunch of different vendors (which may advertise better privacy) to choose from, and having technical systems which can provably protect your secrets against various kinds of threats.
It's a bunch of medium and hard problems. The biggest problem is that 99.99% of users totally don't care, though.
I'm just glad to see that he decided to be more courageous than most of us and believed that he should be doing the right thing instead of the easy thing by refusing to hand over his client's information.
I, for one, will be keeping my eye out for this guy and will definitely invest into his idea for customer privacy.
http://www.reddit.com/r/technology/comments/s479x/this_inter...
His pseudo-kickstart page is unlikely to generate anywhere near the amount of funding it would on the KS site. I'm wondering why they wouldn't allow it to be funded there.
Is there something dubious about this project that the typical tech blog cheerleaders are ignoring, or is there some reason this kind of project is not allowed on Kickstarter in general?
http://www.indiegogo.com/calyx
--
> A project is not open-ended. Starting a business, for example, does not qualify as a project. No charity or cause funding.
The problem Kickstarter has with this project (and, similarly, when I tried to do the same thing) is that it's not an "artistic" endeavor. That is to say, they don't allow small business projects, unless you plan on producing a short story or documentary about the process as you do it. (Here's an entrepreneur who used this exact loophole: http://kck.st/rtglLo)
I don't like this, but this is what I think will happen.
Not if they accept bitcoin, or some other anonymous currency.
http://en.wikipedia.org/wiki/Competitive_local_exchange_carr...
I find that interesting. Indication of dissension in the ranks of the NSA over how far to take domestic surveillance?
The actual contents of the emails is pretty much irrelevant- I'm pretty sure that international terrorists probably use code.
I'm also pretty sure that having one of these accounts and a series of logs showing your access to online gambling or movie sharing sites or banks in the Caymans is going to trip the same alarm bells.
But you said it: there's still too much identifying information left on the table.
There's another angle that threatens Calyx, too: they're just one rider on a "must-pass" bill away from being shut down and tied up in court. Or worse, made to _silently_ monitor your traffic after all their publicity about their privacy.
National Security Letters make it clear: the gag orders mean even if Nick Merrill wanted to tell you his company had been compromised, he wouldn't be able to.
There does seem to be a technical workaround, known as a "canary," where Nick Merrill posts a daily message far and wide signed from an air-gapped physically-secure private key that basically says, "Today is 11/Apr/2012. Under penalty of perjury, I have not been served with any legal threats."
Thus, the day the "canary" stops appearing, it becomes obvious what has happened; it seems that our current legal climate probably cannot compel him to _commit_ perjury, and his _inaction_ in posting his "canary" does not constitute a violation of any gag order; ironically, he conforms to it and by so doing alerts his customers to the problem.
Problems with this approach include:
• All the sites he has been using for the canary could get shut down simultaneously a la Megaupload
• Compromise of his private key
• Dwindling interest by his customers in checking multiple sits every day, even if the process can be mostly automated
I don't have to reveal the hidden location and password to my air-gapped private key unless I am in court.
I agree that spending the rest of my life at Hotel Guantanamo isn't my favorite, but if he defies the Federal Gov't's established secret wiretapping, surely he has assessed the possibility of this happening already and he's not afraid?
So a three-letter-agency guy turns up with a SWAT team, you only need one of them to decide to reveal the key with a gun at their head - or with the threat that child porn would be found on his laptop/20kg of heroin would be found in his apartment. Chain = weakest link.
Wouldn't be able to legally. If he feels strongly enough about this to start a company, he may feel strongly enough to defy the law.
I hope so.
Under penalty of perjury is a meaningless phrase unless a court or other authorized body is requiring that statement of you. Look: under penalty of perjury, I am Chief Justice John Roberts of the United States Supreme Court.
Well, I'm not Chief Justice John Roberts. I lied about that. Am I in danger of going to jail for contempt of court? No, because nobody with judicial or administrative power required me to make a truthful declaration. Rather I made a statement I wanted you to believe and attached a common legal incantation to it - little different from a religious expression, such as 'God strike me dead if I lie.' In earlier times when people had little understanding of science, the sheer randomness of the world was attributed to mysterious divine provenance, and of course every so often these beliefs are validated in such dramatic fashion that the story is repeated (http://members.tm.net/lapointe/Lawyers3.htm for example, from 1988).
An awful lot of hackers I've met seem to think that law is strictly a matter of form, that if you say certain words in a certain order legal validity (and thus, truth-value of some sort) automatically attaches to them. This is not how law works, this is how magic works - and it's a good example of Arthur C. Clarke's comment that 'any sufficiently advanced form of technology is indistinguishable from magic.' Legal conventions are a form of social technology, and can not be taken at face value this way, any more than nontechnologists can foretell the future from blinkenlights.
That being said, there are magic words that you can say that have very strong legal weight. For example, attaching a GPL licence to a piece of code you wrote has significant legal ramifications.
It's clear that "Under penalty of perjury" doesn't accomplish the intention of giving a canary message greater legal weight. I am, however, curious if there are some other "magic words" that could exist in a canary message which would help to signify its validity. For example, making it illegal for someone to fake the canary message.
Would a 5th Amendment right (not witnessing against herself / self-incrimination) protect the owner of the ISP against a charge of obstruction of justice?
i.e. Owner of ISP refuses to post the canary after a gag order. She is not named as a defendant in the investigation. But she can defend herself against obstruction of justice charges: plead the 5th, and thus she is not compelled to falsely affirm the canary.
It's not clear this would work, either, but there might be some pretty solid precedents that could be used in this way.
http://en.wikipedia.org/wiki/Affidavit
A bit more administrative hassle, but the concept should be sound.
http://en.wikipedia.org/wiki/Perjury
The rules for perjury [apply] even if the person has not been sworn or affirmed as a witness before an appropriate official.
Also relevant:
http://en.wikipedia.org/wiki/Subornation_of_perjury
Subornation of perjury is the crime of persuading a person to commit perjury; and also describes the circumstance wherein an attorney causes or allows another party to lie.
It's pretty clear this, not magic, is the end goal of the original statement.
"Under penalty of perjury" is just a mechanism for substituting a written declaration for an in-person swearing.
If you look at the statute, the governing condition is (paraphrased) "under laws or circumstances requiring or permitting a sworn statement".
IANAL, but 'anigbrowl has some training here.
If they're also a telecom provider who can't comply with wiretaps, that's also huge.
Personally I think this is very exciting. Governments' game has been to make secret deals for surveillance; by announcing openly that they won't cooperate, this company will either succeed or may force the government to state openly the level of surveillance they demand. Citizens should know how out-of-control it's gotten.
Unless they are going to spend a gazzilion $ putting their own cell towers across the country with their own backbone then their partner telcos have your location = so does the NSA.
And unless you are only emailing people/visiting sites in their system then the other telcos have the end points of those links. Calyx could hide the originator of these packets, but in that case they are no different from any other VPN - and I have a lot more security from PATRIOT (or MPAA) requests using a VPN owned by a Liberian company run from a rack in Estonia than I do with one run out of the USA. Ironically your best 'security' at the moment from US wiretaps is to use a VPN owned by the Chinese government.
That's ridiculous. The point of this is not make it easy to evade justice. Remember, we do want the police to be able to gather evidence against criminals when it's warranted. It's to prevent mass surveillance of the population by the state. Having communications companies that minimize the data they gather about their customers and refuse to hand it over to the state without a warrant is a huge step forward in protecting the civil liberties of ordinary citizens. That's the point.
This telco is claiming that they have the technical means to prevent that - while in fact they have no technical difference (other than storing your email encrypted) than any other.
If all they are claiming is that they are good guys and wouldn't hand over your data if ordered then you have no more security than all the other telcos who also said that - either because they were lying or they were ordered to say so.
If your risk model is that the telco will cooperate with the US government then the solution is a telco who has no reason to do so.
That isn't my interpretation.
They seem to be saying that they will do everything technically and legally possible to prevent tracking.
That's a significant difference from the current situation where telcos hand over information whenever the government asks, even if not ordered to do so.
It's not clear to me that we can prevent mass surveillance without making it easier for criminals to evade justice.
I still think we should work to prevent mass surveillance, not because making things tough for law enforcement is not a problem, but because mass surveillance is a much bigger problem.
What if you pay with a prepaid Visa/Mastercard, since those aren't linked to your name? Or in cash (yes, that still exists!), or via money order (since sending cash in the mail is illegal, and money orders can't be reliably linked to an individual).
Or I'm talking nonsense. But a secure ISP that is not capable of eavesdropping is a start.