FBI wants real-time Gmail, Dropbox spying power
slate.com
slate.com
That includes unencrypted email and any unencrypted data stored on a server not under your control.
Even your encrypted communication might be compromised at some point in the future, given the odds that it has probably been logged by someone as it travelled from hop to hop through the Internet.
Once encrypted data leaves your control, anyone intercepting and logging it can attempt to crack that data at their leisure, virtually indefinitely.
Laws may stop some law-abiding entities from trying. But I wouldn't count on it.
Encryption that is out of your control is encryption in a specific, meaningful sense. I believe to effectively use encryption, you have to understand the trade-offs involved and limitations of the technology.
So, Google's encryption is terrific in terms of protecting you from war-drivers. But it won't protect you from the focused attention of the FBI. That doesn't make it good or bad, it's a tool with specific uses and limitations.
I think that lesson needs to be absorbed with all forms of encryption. It's a particularly dangerous area to pop-sci oversimplify.
What I haven't seen is a comprehensive security review of these alternatives. There could be bugs, flaws, or they could outright not be doing what they claim to do.
Pick your battles.
Historically, intelligence monitoring of communications providers was done extra-legally (by employees at the communications providers who either worked directly for or were compensated or politically-motivated agents of intelligence agencies). When it doesn't need to be used in court, there are a lot more options. Stuff as simple as an employee providing copies of the day's tapes.
Later, intelligence agencies got smart (particularly the Israelis) and ran cut-rate service providers for support services (VoIP termination, billing reconciliation, etc.), selling to existing consumer-facing providers, primarily for information.
Just because FBI is talking about this for law enforcement purposes (implying they don't have it now) doesn't mean they don't necessarily have various types of existing access for their dual role as a counterintelligence agency, or that other organizations (US and foreign) don't have access.
ECHELON did it by having 5 nations involved. If the US wanted information on a US citizen they'd pass that name onto the 4 other countries who would do the spying for them.
ECHELON was also used for industrial espionage, providing lots of information to US aerospace.
For the record, I dont mean that in a 'government is bad' tone. That is a different discussion. I mean that in an objective 'you'd think the people who run the country and have access to more resources then we ever will would just find a way to do it in the first place' kind of way.
They can send machines to mars, have laser guided devices fly to the other side of the world and hit a target, (insert more technically difficult feats here)... but they cant get access to all our data on the wires and networks they govern in their own country? i really doubt that.
If you look at history and the kind of surveillance powers governments had compared to the general population, it isn't unreasonable to assume that they can "monitor" everything. In fact you can find several YouTube videos of people who claim they created just such a system after 9/11 for the NSA.
The question is not if the NSA are sweeping every piece of electronic communications, the question is: "how much are they storing?"
If they're just building communications trees then that is a lot less invasive than even automated e-mail scanning. However it is very likely they're looking at content too, because historically (e.g. cold war) they always did keyword/phase monitoring.
If I had to guess, I would guess they're building large communication trees and giving everyone in them a "score" (think: credit score). This score raises based on things like the language used, perceived threat, and similar.
Then when someone's score is high enough or they talk to the "wrong people" you have human analysts who go over their profile with a fine tooth comb...
None of this is impossible with our current technology. In fact it isn't even technically that difficult - just expensive.
Now if you want to get really conspiratorial then let's talk about the public SSL certificate oligopoly. The five or six companies generating the majority of the world's SSL keys are likely handing them straight over to the NSA and in exchange the NSA keeps those companies in power/control of that market.
That's really a very scary thought and I wouldn't be at all surprised if it were true. At least the first part.
It creates a lot of grey space. First, can the data be used to train up various search agents? After you die can they then analyze your data? Among other things.. and just the general safety of the data.
As for ssl, they shouldn't have yor keys, they just sign them and vouch. If NSA compromises the ca authorities they could man in the middle ssl but not feat your keys.
(Although there's ANOTHER 3 company oligarchy in SSL -- probably Apple and Google and Microsoft actually do generate on their hardware or software the majority of SSL keypairs used. If you compromised there, you could get access to everything, either at generation time, or later through a backdoor. This is unlikely as a pervasive thing since it would be eventually detected, but highly plausible for targeted attacks. If nothing else, government 0-day focused on those platforms to get access to keys would be enough, and wouldn't require cooperation of the vendors.)
The net is exact opposite of private, and that's that. And really it always has been. What is actually weird is that people ever thought otherwise. Bits can be made private, but even then its clear to an observer that something private is going on, and then they do everything possible to break it open. Its like a big old, hey, investigate me flag.
To widen the scope a bit, I find it 'funny' that so many people seem to negate the plausible idea that people with tons of money and tons of power don't use those tools for doing bad things. I'd guess that most people, as long as they can keep work/play, earn/spend cycles going, don't truly care what else is happening.
What they're trying to do here is make more of it admissible in court.
(You are not alone ;)
I don't know whether to point the finger at writers of fiction for our lowered expectations or not, but I'm sure it contributes.
My unscientific observation (I don't watch these but my SO used to) is that major (USA) network "crime drama" TV shows (fictional) such as NCIS* depict, in every episode, a fully omniscient surveillance state in action [edit: and as a perfectly normal state of affairs]. My suspicion is that the underlying purpose of same is to condition the viewing citizenry of the fact that such exists and is a normal state of affairs, so there will be no problem with the preconditioned citizenry when such becomes real (if it hasn't already).
Just because they don't currently have any methods they can base a court case on and put on public record doesn't mean they don't have other interception methodologies (whether through cryptographic weaknesses, CA attacks, compromising servers at Google / DropBox, cooperation from / insider double agents at Google / Dropbox / CAs, backdoors installed on clients, compromising user or employee login credentials and so on).
http://www.computerworld.com/s/article/print/9235260/Rogue_G...
and
http://www.computerworld.com/s/article/9219606/Hackers_stole...
Fortunately that attack is only possible if you're a despotic nation-state who controls your entire countries internet connection - or perhaps a three letter agency who'd only have to lean on half a dozen or so major internet backbone company CEOs - so you can MITM pretty much _all_ the traffic...
Yes, let's. For non-critical public services like blogs and videos, cloud providers like AWS and VPS hosts are great. But for things that matter significantly, like corporate e-mail, let's abandon the cloud and regain some of the decentralization that the earlier Internet protocols like SMTP exemplify.
Every service already says they'll cooperate with law enforcement. Even if it was in-house, you'd have to obey a court order to turn records over. This is more about real-time access.
ADD: What we're probably going to need is a new way for users to universally encrypt data deep in the OSI layer instead of continuing to tack it on top of the stack with downloaded apps. Need to think through that some more.
I took a flyer on how my idea would work as a PC program. https://news.ycombinator.com/item?id=5449049
Not sure I made any progress, but that's the fun part about being a hacker and doing this from your armchair (and Pi/packet radio board) -- anything you can imagine you can begin to realize.
I honestly believe all of this surveillance news is going to result in many more technological solutions, although probably no long-term "wins"
Reading the terms of service and privacy policy of each site you visit daily is a good exercise. Nearly all will contain some ambiguous catch-all provision that they can use your data to "improve [their] services." Then, if they're sued, the question is whether they have the resources to hire a law firm that can convince a court that selling data to the FBI/CIA/etc. improves their services. They do.
Can, but apparently aren't, if the FBI is making a fuss about not liking how things work at the moment. If Google were giving them everyone's Gmail, one assumes they'd just stay quiet about it.
If any precedent or piece of legislation disproportionately and negatively affects a certain demographic of a population (let's say those with the means to form their own opinions), while they argue "well it's for everyone's safety", the reality is that it's unjust no matter how you try to spin it.
1: http://en.wikipedia.org/wiki/Hushmail#Compromises_to_email_p...
I don't use Tormail cause it's painfully slow at times (at least for me) and since I figured they're probably not interested in my plaintext gmail anyway. Stories like this may change my mind.
It's not that (mostly) anything I send is PGP worthy; it's just the principle of it.
Somehow, I doubt that the FBI is terribly concerned about that:
If Dropbox starts to let a foreign government (In this case the USA) to watch our files, I must cancel all accounts and will advise all my friends and family to shut down all Dropbox accounts immediately.
Can someone comment as to the truth of this article? If true that means we can never trust a US company again. Please someone tell me this is scaremongering and FUD and has no substance.
Something I can perhaps just throw up on an S3 instance and pay a few bucks for it every month?
Even if we are just talking about e-Mail frontends: Horde is one of the more popular ones and is just awful UX wise. I don't know of any mature free solution which at least tries to match GMail in this regard.
This was made clear in a 1957 Supreme Court ruling, Reid v. Covert:
"At the beginning, we reject the idea that, when the United States acts against citizens abroad, it can do so free of the Bill of Rights. The United States is entirely a creature of the Constitution. Its power and authority have no other source. It can only act in accordance with all the limitations imposed by the Constitution. When the Government reaches out to punish a citizen who is abroad, the shield which the Bill of Rights and other parts of the Constitution provide to protect his life and liberty should not be stripped away just because he happens to be in another land."
"This Court and other federal courts have held or asserted that various constitutional limitations apply to the Government when it acts outside the continental United States. While it has been suggested that only those constitutional rights which are 'fundamental' protect Americans abroad, we can find no warrant, in logic or otherwise, for picking and choosing among the remarkable collection of 'Thou shalt nots' which were explicitly fastened on all departments and agencies of the Federal Government by the Constitution and its Amendments."
http://www.law.cornell.edu/supct/html/historics/USSC_CR_0354... http://www.guardian.co.uk/commentisfree/2013/mar/15/charles-...
http://www.reddit.com/r/technology/comments/1b2m4l/fbi_pursu...
However, as long as Gmail supports IMAP, it's pretty easy to set up PGP encryption/signing with Thunderbird or Mutt or the like. Thunderbird has a plugin/extension for integrating support, and Mutt provides it natively.
If you already use Thunderbird or Mutt, it'll take maybe 15 minutes to set up, and then you don't have to think twice about it.
Running your own mail server[1] is the "must be at least this tall to ride" threshold for even having an opinion.
[1] and possibly providing your own dialtone, which isn't that tough these days ...