The Internet Is a Surveillance State
schneier.com
schneier.com
I think the focus shouldn't be on the unavoidable "information radiation wake" you give off as you move through the world living your life, but on the ways people utilize this information. The government, and private entities, need to be constrained in how this information can be legally used, not in the collection of it, which I think is impossible.
Consider health records, which lots of people are paranoid about. There's a lot of diseases we might be able to treat if people's health records were available to researchers. One might be able to detect correlations in disease from these records of millions of individual cases. But insurance companies and employers could potentially discriminate against you based on these records, so it is in your interest to keep your medical conditions secret. In cases, if you have a communicable disease, it is understandable you'd want privacy too.
Point being, the biggest danger of loss of privacy is abuse by the state or other private entities, and if we could build safeguards against that, the fact that your phone signals give away your location, or your subway card shows where you've been, might not be so threatening.
You clearly describe two options: preventing collection, and limiting utilization. I agree that preventing collection is impossible, but I don't think simply limiting utilization is enough. I think limiting utilization and retention is key. As long as the data exist, it can be utilized in the future.
I think the retention point is valuable. But it also seems sort of impossible in some arenas.
Take Facebook. Say that the government can only retain information it collects for 6 months. Fine; but they could re-request that same data 6 months later.
I suppose there is always a way around this (no extensions without a warrant), but in principle retention seems both critical and a minefield of potential confusion. I'd be interested to hear others' thoughts on the topic.
I think you would've had a very hard time tracking someone through these records.
As an NYer, tapping John Gotti was very traditional compared to the blanket tracking of US citizens that has been granted by FISA.
As for Schneier's link to the Atlantic's article, I think we're moving to a new era where we trust developers and not the popularity or the design of the app itself. I'm sure one will be tracked when you don't have to pay anything for it.
In some cases, organizations simply had to actively file reports with government agencies via snail mail when certain suspicious activity was encountered, sort of an active, HUMINT client-side filter.
Best examples are one-way ticket purchases, or cash transfers at banks over $5000, or Western Union telegrams, these were activity monitored via human labor and dead tree paperwork.
(Technically, "keep" includes "keep until the book is returned", but you mean "keep" in the sense of longer document retention, and I feel it's unfair to lump libraries into the same category as a bank, which has a legal obligation to keep long-term records.)
Nobody would bat an eye about it today though. . .
In addition to efficient, it also made it more convenient and secure to do so. This aspect is huge.
The local video tape rental place may have kept records of every movie you rented, but an agency wasn't going to go in and demand your records from the scumbag owner unless it had a really pressing reason to, as it would potentially blow their investigation/operational security. Scumbag owner would have some guys in dark suits visit him and it'd be all over town in a matter of hours. The end result is that they probably wouldn't sift through your rental records.
Now, with the proliferation of the Internet, the government doesn't even need active participation of the records custodian, they can pull traffic off the wire and warehouse it themselves.
And if it does require active participation from the data custodian, they have nice National Security Letters with highly-threatening gag orders, which have proven to be quite effective.
But they don't need NSL's to get the data. Just as a plain old warrant or subpoena would have been enough to get your local video tape rental place's records of the movies you watch, it's enough to get Netflix's records of those movies.
If you can get Netflix, it suddenly justifies the effort to mine that data and weave it into a larger tapestry.
Now, in the electronic age, they could demand that the phone company keep records of every phone call made by every single customer of theirs, and have it uploaded to the NSA computers for real-time analysis using AI. Different scope entirely.
I feel the same thing goes for all the data we create. That data can be seen as an important tool for law enforcement (which I no doubt think that some of it is), but we cannot let it be use as as reason for subjugation. We need make that unacceptable.
This reminds me of a quote attributed to Joseph Stalin, "Quantity has a quality all its own."
The collection of data is not new. However, the extraordinary amount of data now collected, and the ease with which those data can be cross-referenced or otherwise mined, create a phenomenon that seems qualitatively new.
Modeling each individual in a population the size of America based on a 1000 variables would be the realm of fantasy in the 1990s. The manpower requirements to even gather, organize and group large volumes of data made profiling, or things like Obama's campaign the things of science fiction.
Now the system has shifted dramatically. Not only is such analysis is possible, it is constant. While the models are not perfect, they managed to get Obama to 1.5 % of the final poll numbers.
Practically - this is a difference between bronze age weaponry and Iron age weaponry, and only one side has the ability to use these weapons. Normal citizens will not be able to run similar models on government.
Normal citizens dont have access to databases of such data, nor can they in turn stay one step ahead of the government.
Earlier the barrier for a government to collude against its populace meant that a strong civil rights movement could halt nascent programs because of the runway required for them to take off (Years and large manpower requirements just to record data).
Ideally at this stage, people need to know what is being predicted about them, how the data is being used. People need to be mutually armed and aware.
Disbarring a prosecutor from ever holding elective office is about the only thing I have been able to think of, and it's not hardly enough.
Get rid of the ridiculous laws is more like it. Perhaps our Founders had a point when they were trying to create a limited government? Gerry Ford's best ever quote puts it in the modern context, "A government big enough to give you everything you want is a government big enough to take from you everything you have." (http://en.wikiquote.org/wiki/Gerald_Ford#Address_to_Congress...)
A simple way to decide if a law is bad or not is to look at how many people break it each year. Any law that's broken by more than 1% of the population each year should be removed from the books.
That's one way. I'd go further and say that if the "crime" doesn't have a victim, and involves strictly voluntary / consensual actions & behavior among adults (children may be a bit of a special case) then it is no crime.
I generally agree with Bastiat's[1] sentiments on this:
What Is Law?
What, then, is law? It is the collective organization of the individual right to lawful defense.
Each of us has a natural right — from God — to defend his person, his liberty, and his property. These are the three basic requirements of life, and the preservation of any one of them is completely dependent upon the preservation of the other two. For what are our faculties but the extension of our individuality? And what is property but an extension of our faculties? If every person has the right to defend even by force — his person, his liberty, and his property, then it follows that a group of men have the right to organize and support a common force to protect these rights constantly. Thus the principle of collective right — its reason for existing, its lawfulness — is based on individual right. And the common force that protects this collective right cannot logically have any other purpose or any other mission than that for which it acts as a substitute. Thus, since an individual cannot lawfully use force against the person, liberty, or property of another individual, then the common force — for the same reason — cannot lawfully be used to destroy the person, liberty, or property of individuals or groups.
Such a perversion of force would be, in both cases, contrary to our premise. Force has been given to us to defend our own individual rights. Who will dare to say that force has been given to us to destroy the equal rights of our brothers? Since no individual acting separately can lawfully use force to destroy the rights of others, does it not logically follow that the same principle also applies to the common force that is nothing more than the organized combination of the individual forces?
If this is true, then nothing can be more evident than this: The law is the organization of the natural right of lawful defense. It is the substitution of a common force for individual forces. And this common force is to do only what the individual forces have a natural and lawful right to do: to protect persons, liberties, and properties; to maintain the right of each, and to cause justice to reign over us all.
Where I disagree is the whole "from God" bit, considering that I'm an atheist. I consider the rights he is speaking of, as being a fundamental aspect of being a sovereign individual possessed of self-ownership and agency.
In this context, the issue though, is what rights should "society" in the large recognize and hold as sacrosanct. I argue that the basic essence of being a conscious, self-aware individual, with agency and self-ownership of your body, entails what Bastiat refers to as the "inherent right to self defense". Others are, obviously, free to disagree.
A right that you have is one that cannot be taken away. Traditionally this is limited to things that society has agreed not to take away. However we are slowing entering into an age where a new type of right emerges: a right that you seized and society is powerless to take away.
We don't normally think of "PGP'd email can't be read" as a "right", but that is essentially what it is. A right that has been seized, not granted.
These rights are of course vulnerable, just like rights granted by society. Instead of keeping society convinced that the right must remain granted, you instead have to be careful that you remain in a position where society is powerless. In practice, this is quite difficult.
For that matter, this applies even to granted rights. There are plenty of rights that people have that are outlawed by unenforced (and unenforceable laws). Consider for example laws in less enlightened states that specify what sorts of sex two consenting adults are allowed to have. These laws are not enforced, making them little more than monuments to the ignorance of the past.
Irrelevant; it isn't a right if you can't defend yourself in court if you're caught doing it and detecting someone using encryption is not at all difficult. We're talking about rights here, not "what I can get away with". You position isn't defensible.
In what western country is it a felony?
Also if more than one percent commits fraud you could have a problem.
Yes, it means that the definition of "fraud" is too broad.
Most UK citizens have probably laundered money this year [1]. That does not mean all money laundering should be legalised.
[1][http://en.wikipedia.org/wiki/Money_laundering#United_Kingdom]
Quick question about how it would play out in practice: how would it apply to things like financial regulation? For example, if more than 1% of banks ignore the rules about capital reserves, does that make the law about maintaining capital reserves void?
Or would this type of law only apply to laws enforced against individuals?
The biggest issue I can see here is the "slippery slope" problem. At first parties are a bit louder, but enough people are doing it that we need to set the noise bar a bit higher. Then everyone gets a bit louder, and so on until it's untenable. It's like trying to walk across a street that never has speeding enforcement. People have long ago realized that and now drive much faster as a result. It didn't start like that, it just sort of got that way naturally.
It's not like people will voluntarily admit to crimes on the off chance that it may get the law repealed.
The laws that are important will be passed again; otherwise, they'll fade away into history as society changes.
He spends much of his book complaining (with some justification) that people such as securities traders have so much bureaucracy to deal with that they face a heightened risk of criminality through non-compliance. I think that both our regulatory and litigation systems are extremely unwieldy and that what we need is a bit less mechanistic proceduralism and a bit more bureaucratic autonomy and accountability but that's a far cry from the notion that pretty much everyone is a criminal.
And now, the "hackers" are in disbelief that the US government is actually reading their emails and listening to their phone calls. NSS!
We got what we wanted here, folks. Information is free - free to be created, free to be read, and free to be copied, stored, decrypted and analyzed by anyone with the means and drive to do so.
I don't know who said it, but "Don't put anything online you wouldn't want to appear above the fold of the Wall Stree Journal."
But I do care about the fact that the FBI can pull up information about me and I have no knowledge of it. If they collect information to combat terrorism, fine. But the 99.999 percent of innecent people being tracked have a right to be notified (and given a course of action for recourse) when they've been wrongly targeted, for whatever reason.
I know, it's an idealistic dream, but it is more realistic than combating the inevitable surveillance practices that are just now coming to light.
If anything, being notified that I'm being looked at would freak me out more than not knowing. We've entered this weird world of now needing to avoid appearances.
The thing that troubles me the most about the government accessing ALL of my data is the idea of false positives -- or hell, even purposefully spinning one aspect of my data to mean whatever the hell they want it to mean. If we don't have access to the same information, how are we supposed to defend ourselves against accusations?
1. Broad annual reports containing the number of individuals were investigated, or whose 'file' was pulled, and the number of investigations that resulted in some sort of prosecution. Basically, give me the figures that show me the efficiency of the NSA investigations. This would help combat just broad pulling of records without specific cause and purpose. You could go so far as to say that after passing certain thresholds of efficiency, their actions would be audited. Note that I realize this is not ever likely to happen, but just trying to give an example of how increased transparency could be done.
2. Individual notification. This is obviously much more difficult because they wouldn't want to tip off a legitimate threat to the fact they are under investigation. But the general alternative is not acceptable either. The government can't just investigate people and invade their privacy without good reason. So some how, individuals need to know.
The checks and balances of Executive, Legislative and Judicial branches is an effective mode of government, but there is a second 'check': the one by the people. If I don't know my rights are being violated, how can I hold the government responsible?
So, yes, some form of individual notification is necessary. Maybe the notification happens after the investigation is finished. Maybe I'm notified a year late. But one way or another, I have a right to face my accuser.
Those are my thoughts on it anyhow.
If you're unfamiliar, there was a strong meme in the late eighties through early/mid nineties among a certain set that the perfect storm of public key encryption (still wonderfully unbounded in our minds) and the emerging global network would be a nexus point for personal power in privacy, anonymity and security and in many real ways break down the bonds of the states. It's worth noting that this was about the time that the soviet union fell, and many in the know had gotten a first taste of global presence by hearing about the people in the streets via usenet before it made the news.
It wasn't that I was particularly a hard core believer or activist, at least compared to many I knew. But for those who understood what an immense impact the internet was going to have it seemed to everyone I knew - NSA, hackers, professors, that it was just how it would be. You couldn't hope to spy on pretty much anyone anymore when you could use perfect encryption to scramble a telephone call or an email. Kind of like when you knew everyone was about to have a touch phone.
I was ideologically aligned and mixed in such circles, nerds were still outcasts so not really too big a world, but my life was busy with other things - but I watched from a distance, fascinated with all the ideas and things to come. I'm not sure I've every really been more sure something was going to happen, at least to a very significant degree.
The government was sure too - that was when they came up with CALEA and people got upset but mostly scoffed - there was a real sense that they were just in their death throws.
Things got pretty busy, Internet boom. Company got bought by an agency, every big name anybody needed to be on the Internet yesterday. Was a blast though a bit of a blur - ended up in SF as the whole thing worked itself into a nasty hangover. Can't remember worrying too much about when the cypherpunks were going to win but still knew it had to be coming, err well it's just about adoption.
It really sucks to wake up after a bender and realize that you helped kill the dream that you were just waiting for someone else to make happen.
Working infosec as california recovered put me face to face with reality pretty early in this cycle. Not only was the thing I was so sure of totally not how it went down, with shift from relatively petty financial fraud and wankers to states and srs.bsns abandoning defense to focus solely of offense it's been very hard to square. It's hard to believe many people ever feel so sure about something that turns out so absolutely opposite.
Fuck, at least nobody killed rms.
This is really what the rage on the internet is about. People like to pretend they're mad at the government overstepping its Constitutional boundaries, but what they're really mad about is the failure of their attempt to re-litigate the division of power between government and the people.
It seems Google had a significant number of employees in each camp. But the market logic was pretty firmly in one of those camps and not the other...
Not just easier: we made it possible.
The government couldn't have created Facebook on their own. But now that it exists, it's an intelligence agency's dream come true.
Every time we see another consumer web startup which relies on advertising or mining user data, we see yet another nail in the coffin in freedom and privacy for users. But, that's okay, because we're totally killing it, and that bridge round is coming any time now to keep us in our expensive lofts and designer foods.
Way to go, folks. Hope it was worth selling out the rest of your fucking race.
"And never forget, the internet only knows what you tell it... more or less" --me!
Companies are starting to realize that providing a good experience is the most important thing your company can do to stay relevant. Dreams often die in execution -- but I think we're getting to a point where a group of dedicated individuals focused on creating an exceptional Internet experience built on privacy and encryption really could make something happen.
I used to use GPG on Linux and OS X. I tried so very hard to keep using it. But it was the biggest pain in the ass, so eventually I just gave it up. I pulled up my key not long ago and had totally forgotten my passphrase.
The devil is in the details. Creating something familiar, something usable, and something that the average person would actually want to use is the part we need to get right.
Or so you think until it turns out an amendment to 2000-page farm appropriation bill actually mandated a government backdoor to be installed into any phone legally sold in the US, and 100% of US providers implemented in 5 years ago. And this backdoor is accessible without warrant since you communicate over public airwaves so you have no expectation of privacy.
Not good enough: you have to think of activating it. And even if you do, most traffic will still be unencrypted, making it easier for spies to tell who may have something to hide, and when they do.
To have real good, actual privacy, everything should be encrypted by default, the internet itself should be a giant scrambling overlay network such as Tor, and people should have symmetric bandwidth to encourage decentralization —no more need for YouTube.
I don't see it happen in the following decades.
If its done right, there are only 2 people capable of getting the content of the message: you and the intended recipient.
Regarding phones, this is already the case with iOS. The Full-disk and Full-filesystem encryption mechanisms appear to be fairly/very strong. I believe since Android 4, full filesystem encryption has been supported, but I'm not sure if it's as well-integrated as on iOS.
Apple has made an effort (although an imperfect one) to make text messaging secure by default.
Obviously Apple screwed up pretty badly by making all this stuff closed-source, and it's probably full of vulnerabilities, but the reality is that this seems to be, in practice, enough to thwart LEO attempts to surveil users of iOS devices.
I think we're on the right track.
- that it's implementation secure (for example Android FDE is trivial to crack for us, imagine what a joke it is for the NSA)
- that it's algorithms are secure (gone are the days where the NSA would warn us DES is broken to help US companies)
- that the data is never stored or sent in clear - the system has full access to the data, in clear, when its running.
- that there is no backdoor. each step of the implementation can have relatively hard to spot backdoors. Specially in proprietary code.
What vulnerabilities exist with the full disk encryption on android that make it insecure ?
A really safe internet has to look more like BitTorrent and less like YouTube.
There've been powerful incentives for software on servers; I think the above got in the way of p2p getting much of a foothold to develop its own advantages.
I'm still terrified of a second McCarthyism.
1) Proper anonymity, so they don't know who to beat.
2) Deniable encryption.
3) Steganography.
4) (with 2) Sacrificial data of less significance to "give up" after sufficient beatings.
5) Social norms against beatings and similar coercion, extending to extreme circumstances.
6) Governmental transparency.
Neither individually nor collectively are these perfect security (and some are only relevant to certain circumstances) but they help to limit it.That's not enough. They still know who you talk to, where you are and just about everything except the contents of your conversation.
Oh, that's probably partly because that wouldn't help its detractors any one bit: as a dead martyr, RMS would be more powerful than as a living bitter old figurehead. (Disclaimer: I know nothing about RMS' actual mood.)
Only the monitoring computers have the time and patience to look at as much as they can ... and they can't parse text sentences (let alone voice comms) well enough to do anything but scrutinize for a few common terms ... let alone nuances (seen Google translate?). A couple of back-of-the-envelope calculations will demonstrate that to anyone.
The agencies and the corporations know that but they refuse to cop to it, possibly because it's so obvious that all they can do is -pretend- to be able to monitor a significant fraction of it all. Maybe because pretending is the only hope they've got left.
Secondly, whenever you do need privacy, use the social equivalent of a one-time pad. Never execute the same mechanism twice. For example, you could conceivably use a cantenna to access a distant wi-fi spot. You could buy the wireless cards with cash (and walk to the store where you buy it, preferably in a city that you don't frequent - and get there by car with good mileage so that there's limited trace of you being there), and buy a used laptop on craigslist with cash....
While surveillors can be open-minded, to a certain degree access to enhanced tracking technology will also engender a stronger reliance on the streetlight effect - and complete expurgation of the streetlight effect is impossible.
If only.
No one of power will fight this because they are afraid of becoming its target.
Recommend to use some privacy oriented apps/sites spideroaks, securekeep.com
If the State wants your head, there's not much you can do even if you're innocent.
We should also use peer based grid/mesh networks as much as possible
FTFY
Blah. Ignoring for the moment that he's 6 levels removed from the agents in the field, notoriously the very few of them out there (last time I checked 90% of the CIA is desk bound in the US) are very bad at fundamental trade-craft, with the Camp Chapman attack (http://en.wikipedia.org/wiki/Camp_Chapman_attack) as a telling extreme example.
"Deutch left the CIA on December 15, 1996 and later that year it was revealed that several of his laptop computers contained classified materials designated as unclassified."
Specifically, he took sensitive compartmented information (SCI, http://en.wikipedia.org/wiki/Sensitive_Compartmented_Informa...), stuff which was covered by special access programs (http://en.wikipedia.org/wiki/Special_access_program) that required you to acknowledge each time you accessed it that it was so, and that you not leave the secured area with it, and put it on his personal PCs connected to the Internet, which he used to write up stuff which he emailed, again over that unsecured Internet, to people in the Clinton White House.
It's hard to express just how bad this is, not to mention how this angered the community of people with "tickets" (clearances, which, BTW, I've supplied recommendations for two of my friends, one who went to the NSA, the other with a TS/SCI ... which I know nothing about, except we can and do discuss which technology he's using (e.g. Microsoft)).
I would hope "the average person", after getting the usual training, and signing off on access to SCI, would understand and follow the simple idea that "Don't take it out of this room" means exactly that.
"The average person" would, I think, know he wouldn't be protected from prosecution by political pull if he violated that simple, white line rule....
At first you would want to encrypt the information. Then you would like to have some method of transfer that does not stick out and could hide the intent to transfer encrypted data. Perhaps with the help of some steganography tool. And you would make sure that nobody identifies you in the process by using tools like Tor. This "I hope they don't notice" method is just gambling.
This is nothing different than what the us government is doing by abusing their power and the people that can vote down are doing the same.