For example, for Facebook, the analyst goes to a special webpage/site at Facebook, then they simply clicks through a "Yep, this person is a terrorist" EULA and they have full access to Facebook's database (eg. full access to user content). I bet they rejoiced when Facebook Graph opened shop.
https://news.ycombinator.com/item?id=5833747
If people don't know something by now it's equally the fault of the services they use for not educating them about the real implications of what they do online.
In regards to battery; please do stop now, you've resorted to using nonsense as argument.
How is this different than saying "if you want privacy don't share over the postal system" or "if you want privacy don't share over the phone"?
I am not good/disciplined enough to maintain my own mail server.
LE requests to FB simply do not work that way. They can make a request online, which is checked for proper authority, etc. The guidelines FB follows can be viewed at https://www.facebook.com/safety/groups/law/guidelines/ and the idea that FB just randomly hands out full read access to user data is either a paranoid delusion or calculated deception. Maybe you can tell us which one you were aiming for.
'With a few clicks and an affirmation that the subject is believed to be engaged in terrorism, espionage or nuclear proliferation, an analyst obtains full access to Facebook’s “extensive search and surveillance capabilities against the variety of online social networking services.”'
Again: Questioning the motives behind an attempt of persuasion argument isn't a personal attack.
I'm pretty sure dropbox can reverse any encryption they use for the files they store. Or do they even encrypt the data?
There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good job of misrepresenting how their security worked for the past ~4 years to mislead people into trusting it, though.
This is mostly why I don't use Dropbox whenever I have a choice.
I would suggest Spider Oak, however, their support is not timely and there's currently a bug in the Windows 8 client that doesn't let it work. But if they get those issues sorted it could be a decent service.
Could someone please tell me why I can't reply to any comments that are below the third level? The reply link simply disappears!
Edit: Now that I've made this statement there's a reply to gknoy, but not the ones below him or to o0-0o. This is really weird.
Edit 2: Upon refreshing, there's now a reply link to o0-0o but not the other ones below gknoy.
(I kind of hate the feature, since most of the time "you suck" "no, you do" "no, you do" only goes on a few levels, so the exponential delay isn't an issue, but an actual technical discussion goes deeper. False positives and false negatives. :( )
The problem is mobile. Due to some questionable decisions made by especially Apple but also earlier with Google, you really need every single app to write to your cloud storage provider's API. Dropbox is unquestionably the leader there; iCloud on iOS seems to do ok for newer apps. Neither provides meaningful encryption. Requiring every app developer to figure out encryption and manage keys on his own and then handle that on top of the Dropbox API is also insane.
Arguably Apple has a lot of ways to pwn iOS users already, so I'd consider trusting Apple and iCloud to not be that much worse than just trusting iOS, but it is still bad (and most of the bad things Apple can do to you either involve signing bad things, then requiring an active step by the user or MITM, or doing things like retaining device keys at manufacture time and subsequently seizing the devices, or having some deeply-buried backdoors which probably require physical access or are exceedingly infrequently used.)
There's really no good solution for mobile now. You could probably build something fairly non-shitty in the Android world, although I don't know enough about how applications share files and interoperate to know if it would need to be a per-user-app integration. On non-jailbroken iOS, it's pretty clear you'd need to develop a new API which did client-side crypto, key management, etc., on top of file sharing. It would be a pain, and even more of a pain if you wanted to avoid fully trusting Apple in the process.
The best solution right now is "no data lives on the phone", rather than trying to sync; use some kind of web or app which just uses transport crypto to interact with a server but never stores anything locally. If you trust the OS a lot, you could do something like what Good Technologies does and try to sandbox your data within a specialized app like that.
If only...
Android devices are unix devices, and (I assume) either have ssh/scp/sftp/rsync in their userland or it can easily be placed there...
If I had a modern phone, which I do not[1], I would probably just load duplicity[2] on it ? But now that I think about it, in the same way that I have zero data on my laptop, I assume I would also have zero data on my phone ?
Please do elaborate.
[1] Motorola F3 ("MOTO FONE")
“Google cares deeply about the security of our users’ data,” a company spokesman said. “We disclose user data to government in accordance with the law, and we review all such requests carefully. From time to time, people allege that we have created a government ‘back door’ into our systems, but Google does not have a ‘back door’ for the government to access private user data.”
We can assume that Cook, who appeared behind Obama during The State of the Union, is probably on the same page. Highly powerful people know they can't fight the tide; and truly, why should they? The normal rules could never apply to them.
Watch this video and listen how many times 'in the United States' is mentioned.