Google, Apple and Facebook Deny Participating In Alleged NSA “PRISM” Program
marketingland.com
marketingland.com
Email : GPG/PGP (The End!)
Web : Tor (Browser bundle)
Voice/Txt : RedPhone, Silent Circle, Cellcrypt, TrustCall, TextSecure
Data : TrueCrypt, Scramdisk, PGPDisk
We can all pretend this is still a Democracy (it's not and never has been; it's a Representative Republic and our representatives are mostly evil and/or stupid) and think those who have power will relinquish it voluntarily or you can actually do something about your own privacy.Edit: Dear God, I feel like I'm turning into Stallman! (Which, on closer inspection, may be a good thing)
Email: PGP-encryped.
Browsing Traffic: Routed through Tor
Voice/Text: Encrypyed.
Other Sensitive Data: TrueCrypt Hidden Partition
Seeing your interrogator pull out a rubber hose,
and realize that none of that matters: Priceless
---- | think those who have power will relinquish
| it voluntarily
Yea. It was pretty crazy when the Secret Service sided with GW Bush and the Marines sided with Obama, and Bush made his last stand to retain the Presidency at the Oval Office. I don't look forward to when/if Obama is voted out of office...I feel stupid. What are you talking about? Or is this a joke scenario or something? Sorry if I'm being daft.
If the people in office get voted out, they leave. If they didn't, we might have a problem.
This is dangerous that after they and someone replaces them the story repeats like a record player in a lop, only with louder volume. (I wish I could think of a better analogy)
I think that's a bit of a (very large) stretch. I think the "President" and the military are separate enough in this country that we don't run a huge risk of "THE GOVERNMENT" (ie, a "leader" and militia to empower them) could or would act as a cohesive force against the US.
Usually when you see this, you see fractioned militia that support the next successor or what not.
> If the people in office get voted out, they leave. If they didn't, we might have a problem.
No, as evidenced by the our current situation, we still have a problem.
Seriously, I don't really care how people take their privacy into their own hands (as long as they don't harm anyone), but this ridiculous theme of "you have nothing to hide and/or [insert bit of data] isn't really private anyway" is starting to become a real bore.
BTW... I understand the shortcomings of OTPs (and pigeons; I live in New York), but I don't see why it's not used more often. I mean secure distribution of pads is starting to look like the least vulnerable link in the chain at this point.
Besides, generating an OTP is fairly trivial.
http://eksith.wordpress.com/2011/12/26/cryptographically-sec...
* OTR * Works on iOS & Android * Is Free * Works well (doesn't crash) * Does push notifications
Hopefully cryptocat will be that soon.
Regardless, they are purposefully missing the point. The average citizen isn't upset by the means of the private information sharing, but that it is going on in the first place. It is that 'providing only information required by law' sounds limiting, but if the law makes clever use of language to access a huge amount of data then that phrase doesn't mean anything.
Just think about the teams they have to put together to build even reasonably useful tools.
I think you give it too little credit.
The government does a bad job with citizen-facing software engineering. It's not clear that the same is true for defense and intelligence applications.
Take a look at successful teams that already work with "big data" like at Wolfram Alpha or IBM's Watson. It is not at all easy to build such teams today. There aren't enough PhD's around, unless you are outsourcing to China. And then to step it up a level to Google's requirements we enter personal chefs and segway territory. I cant find the quote but Eric Schmidt has said multiple time what is hampering progress is not the lack of cash or infrastructure but talent.
More than the privacy issues I have to wonder about the waste. Cause getting the data and the infrastructure to handle it is the "easy" part. Extracting actionable intelligence I doubt highly they will succeed. Will turn into a big cash sink, that no one will talk about as the costs need to be justified...until they cant be.
People with the skills to do the data mining needed at this scale already have better jobs at Google or on Wall Street. Are they really going to take a pay cut, worse benefits and "government job" bureaucracy for the privilege of spying on their friends and family?
I have family in military intelligence and the situation they are in right now is their branch of the armed service thinks they are just going to send their officers of below average mathematical talent to big data boot camp and expect them to just pick this stuff up, as if it's the same thing as learning Russian or flying a drone. Although the I'm as disappointed as everyone in that so many in the government seem think domestic spying is the wave of the future, I'm skeptical that the real motivations are anything beyond business as usual defense sector pork.
But even if this is the case it's irrelevant to whether or not the government should even be engaged in this practice.
Every single person I have dealt with at a three letter agency is that caliber of smart. They have entire buildings full of them. Sure you have tons of other mid-grade government paper pushers, but the sheer scale of smart people was overwhelming.
They have 10 Bram Cohen's to our one.
Once you are on the inside, you have daily interactions with technology that is 10 years ahead of anything on the outside, which is really hard to walk away from. Not to mention you probably married someone else with a clearance along the way.
If you do want to leave... all your accomplishments, achievements, and awards are locked up in an ISR (internal staffing resume), and you end up sending potential employers a half page CV listing something stupid like "Senior Computer Operator, Defense Department, Ft. Meade" that no recruiter is smart enough to parse.
I understand the feeling of purpose but starting at half the salary and having a cap of 155K (assuming you move into senior management (GS-15 step 10)) vs somewhere like Google where you start at ~100K and the limit for technical people seems like its the 400K+ range seems like a tough sell. Also maybe its just stereotypes, but it seems like antisocial behavior which seems somewhat prevalent in excellent technical types wouldn't really mesh with the command structure there.
On a side note do the top tier/brilliant software engineers at Lockheed/et al make Google level salaries? Actual technical people, not those who have moved into management that is.
A lot of people like myself just don't want to work for Google, regardless of price.
The people I know at defense contractors in the Bay Area all make more than what you would at Google.
Could you talk/link about what that means, exactly? In what ways, which areas? How do you compare these things? Thanks!
1. They can read all the publicly available journals, so they are not going to be any worse
2. They hire top researchers in CS and math, and have internal, classified journals on their cutting edge work
That doesn't make it sound like these are smart people to me. Being easily manipulated by bullshit is usually for the simple.
Not when you spend your first 20 years of life in school, being trained to follow instructions and being punished for questioning authority. Even very intelligent people can be turned into obedient workers.
These communications people are playing word games. These companies turn over and give access to whatever they are legally required to.
Lest people think this is a joke, this is EXACTLY what the telecoms did under Bush that lead to Congress passing retroactive telecom immunity. Predictable outrage this time looks to me like outrage then, and I have no reason to believe that we won't see a similar legislative response.
That said, in Google's case I believe them. This is the company that is going to court to stop the government from trying to get information about Google users with warrantless national security letters.
FB on the other hand, I would expect to see providing technical support to the FBI about how to use their in house tools to more quickly analyze the dumps...
| FB on the other hand, I would expect to see
| providing technical support to the FBI about
| how to use their in house tools to more quickly
| analyze the dumps...
According to Mark Zuckerberg: "Having two identities for yourself is an example
of a lack of integrity"
I'm surprised that he didn't beg the government to peruse his data to weed out all these 'phonies' that are polluting his perfect system.[Only half-joking]
A very telling fact was that Obama was one of those voting for it as well. That told me at least who Obama was. I was never fooled by his hope and change rhetoric, that one action said all I wanted to know before he even started running for pres.
Here is Sen Obama's 2008 reason for flip flopping on the issue:
http://www.huffingtonpost.com/2008/06/20/obama-backs-bill-gi...
--- "Under this compromise legislation, an important tool in the fight against terrorism will continue, but the President's illegal program of warrantless surveillance will be over. It restores FISA and existing criminal wiretap statutes as the exclusive means to conduct surveillance - making it clear that the President cannot circumvent the law and disregard the civil liberties of the American people. ---
But what was the alternative? McCain missed that vote, but had been strongly for telecom immunity all along, and was much more vocal about it than Obama. Hillary Clinton's husband Bill ran Echelon and Carnivore, the odds she would be different were low to nil.
Incidentally in this case it is worth noting that Obama stayed in the letter of his promise. There was a warrant. Whether that warrant was properly obtained, or should be legal is a different question. But there actually was a warrant from the rubber-stamp FISA court.
Yap, it seems as if they got a set of "talking points". They can use certain words and phrases and still given some technicality get away with telling "truth" while effectively also telling lies.
Some say how NSL (national security letters) are pretty draconian and imply personal liability for disclosure. And that is true perhaps but at the same time these agencies do want to get some cooperation and are perhaps willing to "help out" their co-conspirators so PR departments I imagine get a cheat-sheet -- "use these phrases as responses".
It's individual criminal liability for disclosing. They are literally required to dodge under federal law to stay out of jail.
http://en.wikipedia.org/wiki/National_security_letter#Doe_v....
At the same time the govt probably does want them to cooperate, and doesn't want it to be a completely adversarial situation. I can see them buttering these companies up and offering "talking points" on how to specifically dodge these kind of questions. For example Dept. of State have media training, they set up adversarial training situations with fake role playing journalists asking "tough" questions then train employees to dodge them successfully. Very useful.
Same here I can see maybe PR spokespeople are urged maybe to say "we are not spying" because maybe the word "spying" has a specific meaning and given some technicality what they are doing is not "spying", stuff like that. Kind of like NSA has been saying they are not looking at everyone's emails. Well they are not people doing that, it all gets archived and stored probably based on some pattern. So they can clearly and proudly say they are not "reading" our information.
That would only come into play if they're partly immunized and compelled to testify, in the Congress or a grand jury; otherwise they could plead the 5th.
I'm not sure that PRISM==NSLs but I'm sure you're absolutely right that PRISM involves a gag.
Besides, these are largely non-statements by these companies. "No direct access" != "No access", etc.
2) Moreover, if the alleged companies were knowingly providing user data to the US government as members of the PRISM program, they would be unable to confirm or deny this fact because it would be illegal for them to do so. The orders for compliance are accompanied with gag orders.
"The Guardian and The Washington Post articles refer to collection of communications pursuant to Section 702 of the Foreign Intelligence Surveillance Act. They contain numerous inaccuracies.
Section 702 is a provision of FISA that is designed to facilitate the acquisition of foreign intelligence information concerning non-U.S. persons located outside the United States. It cannot be used to intentionally target any U.S. citizen, any other U.S. person, or anyone located within the United States.
Activities authorized by Section 702 are subject to oversight by the Foreign Intelligence Surveillance Court, the Executive Branch, and Congress. They involve extensive procedures, specifically approved by the court, to ensure that only non-U.S. persons outside the U.S. are targeted, and that minimize the acquisition, retention and dissemination of incidentally acquired information about U.S. persons.
Section 702 was recently reauthorized by Congress after extensive hearings and debate.
Information collected under this program is among the most important and valuable foreign intelligence information we collect, and is used to protect our nation from a wide variety of threats.
The unauthorized disclosure of information about this important and entirely legal program is reprehensible and risks important protections for the security of Americans."
In any event, each of these denials were just refuted by the man in charge of the program. So much for trusting anything any of these companies say ever again.
That said, the only way I can square his statement with the facts is that when you collect information on EVERYONE, then you haven't targeted ANYONE in particular. Which is exactly what this warrant enables the FBI to do.
Also it should be noted that all denials have included the admission that companies are forced to comply with lawful requests. A request that comes complete with a warrant from a judge will be usually seen as lawful, even though there might be issues with the warrant. Thus a company could "only comply with lawful requests" and also turn over all of their data under a warrant like this.
That said, Google has been vocal enough in protesting government attempts to troll through its data that I am inclined to give them the benefit of the doubt on this one. But I think that we'll soon have more details.
The conspiracy theorist in me wonders how much PRISM had to do with the acquisition of Skype...
Getting access to it "voluntarily" makes thing so much easier. It says in the slides the PRISM program only costs them $20 million a year.
Now there is a system that can be used for example. That system is once NSA identifies the list of suspects they forward that record to a another agency (FBI?) who then is in charge of finding other evidence, which could have plausibly be found anyway, and prosecute based on that. They can never release the initial reason why they got "interested" in someone as that might reveal the abilities of the NSA.