White House admits it has 'access' to Facebook, Google
theweek.co.uk
theweek.co.uk
Yahoo: "We do not provide the government with direct access to our servers"
AOL: "nor do we provide any government agency with access to our servers."
Paltalk: "Paltalk does not provide any government agency with direct access to its servers"
Apple: "We do not provide any government agency with direct access to our servers"
Can't win with you guys.
There are millions of ways you could phrase the response (Dropbox and Microsoft used completely different language), the chance that these five came up with the phrasing used independently seems fairly low. Especially as the statements weren't all given to a single reporter (who could have phrased the question in a particular way) but rather to a variety of different news sources.
It could still be completely innocent, they could all have cribbed off whoever did the first denial or they could have discussed it beforehand and co-ordinated messages without there having been any government involvement.
It is however something that needs explaining.
These are after all companies several (all?) of whom have co-ordinated illegal no-hire compacts in the past: it's not far-fetched to think they'd work together on a PR response to this. Which isn't necessarily to rule out a more sinister explanation of course.
This is the most clear and direct way
I accused you of doing X
You could say "you know, my brother and I, we once, 30 years ago blah blah blah blah blah blah but X, X never happened".
Most people, however, will just say "No, i don't do X".
They were accused, point blank, of providing direct access to their servers. They said "we do not provide direct access to their servers".
But please, see a conspiracy here because people are trying to be as direct and clear.
You see, people don't want to know if government has direct access(ok, they want, but it is not their primary concern), they want to know what happened.
It simply doesn't matter if google uploads data to government servers or government gets data from google servers by "directly accessing" them. I would even guess that the latter is simpler to implement and maintain.
I don't mean that google is happy to hand user data to government - they probably aren't - I want to know how many data governments gets.
The companies are saying they have no idea. They literally said "we've never heard of this program". What more do you want?
The claim the newspapers made, in line 1, was, "the government has direct access". The denial made was "the government does not have direct access".
If they want to publish a different claim, i'm sure a different denial will be written.
If you want to know what happened, why are you asking GOogle? Go ask the NSA
For example why do they all use the word "provide" there are hundreds of synonyms that work just as well ("given", "enabled", "allowed", "have", etc.). They weren't accused of "providing" the access, it's a word they've chosen to use.
The specific accusation was about the NSA, why are the denials using "government agencies" or synonyms rather than NSA. There might be perfectly valid reasons, but the chance that they'd all make the same decision to use it independently ?
Why are they all in current tense rather than "we have never x" ?
If there were on or two similarities it might be coincidence, but we're talking about dozens of grammatically and phrasing choices.
Amdocs (http://en.wikipedia.org/wiki/Amdocs) provides billing services and customer support for most of the major phone companies so it has access to all of the transactional data on your billing statement. If a government agency had access to the Amdocs data, it would have access to the phone data through an indirect channel.
And it is kind of true: "We do not provide any government agency with direct access to our servers" is the clearest construction I can imagine for denying involvement, but they get called out for it anyway.
"Can't win with you guys."
I mean, not much more you can do than just laugh at shit like this. Yeah man, everyone here is so unreasonable with their standard of "I don't like when companies blatantly lie" how hypocritical of them?
Wish I had been a fly on the wall when they where instructed on what to say and how to phrase it. It is certainly no accident that they came out on the same day, with the same phrasing, etc
and don't tell me that hasn't happened before.
There's also shit ton of papers on Chines academia on how to reconstruct and rapid classify packets from raw IP dumps
Edit: THIS -> https://news.ycombinator.com/item?id=5843442 Beam splitters, or 分光 as called in Chinese.
http://www.nytimes.com/2013/06/08/technology/tech-companies-...
Here is what Obama said: http://www.whitehouse.gov/the-press-office/2013/06/07/statem...
Here are the statements from the DNI:
http://www.dni.gov/index.php/newsroom/press-releases/191-pre... http://www.dni.gov/index.php/newsroom/press-releases/191-pre...
Nowhere in those do I see any confirmation that there is direct or unlimited access to the servers of the companies mentioned.
So other governments have a backdoor to our government's backdoor... What stops China among others from being able to access this?
On the other hand, what is the truth if Larry Page is saying that Google does not allow 'direct' access but the White House is saying that it does have access? This just looks like a giant finger pointing and blame game now.
And we have a backdoor to their backdoor. It's fairly easy to assume that they -- state-sponsored intelligence agencies -- collude with each-other by offering access to each-other's data stores.
In a sense we are all foreign to each-other, and the USG may access American data through requests acting as foreign agencies.
Nothing, and that's exactly what China was doing during Aurora and similar operations.
It's worth noting that Google posted incorrect/misleading information on their blog at the time of that incident as well. They claimed that the intrusions were motivated by China wanting to target human rights and freedom of speech activists, positioning them as a villain.[1] It ended with the same crap about pushing for freedom and transparency.
A few months ago it was leaked that the actual motivations behind Aurora were that China was using it to see which of China's spies were being monitored by the US government through the PRISM-like interface[2]:
""What we found was the attackers were actually looking for the accounts that we had lawful wiretap orders on," Aucsmith says. "So if you think about this, this is brilliant counter-intelligence. You have two choices: If you want to find out if your agents, if you will, have been discovered, you can try to break into the FBI to find out that way. Presumably that's difficult. Or you can break into the people that the courts have served paper on and see if you can find it that way."
[3]:
"As Google was responding to the breach, its technicians made another startling discovery: its database with years of information on surveillance orders had been hacked. ...
The most sensitive orders, however, came from a federal court that approves surveillance of foreign targets such as spies, diplomats, suspected terrorists and agents of other governments. Those orders, issued under the Foreign Intelligence Surveillance Act, are classified.
Google did not disclose that breach publicly, but soon after detecting it, the company alerted the FBI, former officials said."
[1] http://googleblog.blogspot.com/2010/01/new-approach-to-china...
[2] www.cio.com/article/732122/_Aurora_Cyber_Attackers_Were_Really_Running_Counter_Intelligence
[3] http://www.washingtonpost.com/world/national-security/chines...
Edit: it appears the NSA has google's ssl keys. That would explain all the talk about "direct access".
It is also possible they just got the keys from spies. In my company, anyone with sudo access to front end machines can get the keys. I have no idea how to keep these keys secure from the NSA.
[1] http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-se...
Sure it could. First, it would be accurate: TLS keys give you the ability to decrypt communications, which is distinct from direct access to the servers (though, obviously, it can easily substitute for it.) Second, even if it wasn't an accurate distinction, people can (and do) argue positions on unsound bases, and Google doesn't seem to be especially incapacitated in that regard.
This is the only explanation that makes sense. Some secret court compels Google to provide their TLS keys, which is a a few kb of data. No one at Google has to know, and no one at Google can accidentally detect the leak.
Also, can you clarify for me why you think giving someone access to eavesdrop overlaps with "direct access to servers"?
If what I say is correct, Larry Page's statement is 100% defensible.
The slide about how traffic is routed through the US is really telling. This program works because there is access to the packets.
This would require them to have to know, and be kept up-to-date, with how every one of their applications sends data across the wire.
It is the only way to get access to the data without requiring a vast conspiracy. If they had direct access, thousands of employees would know something was up. If they MITM, then lots of people would notice. If they had a way to actually break TLS, then there would be no slide about "providers".
All you have to do is read session cookies. Once you have that, you are done.
Now go read the slides, and you'll know exactly what is going on.
And how are we supposed to believe this? We were already blatantly lied to.
"Now, with respect to the Internet and emails [...], the FISA Court has to authorize it." [1]
1. http://blogs.wsj.com/washwire/2013/06/07/transcript-what-oba...
Google says "No".
However, Google has not denied giving government access to user data: in fact, Google for a few years has been publishing a report of how many times governments ask it for user data:
http://www.google.com/transparencyreport/userdatarequests&#x...;
> But if you really need that kind of privacy, the reality is that search engines, including Google, do retain this information for some time. And [...] we're all subject, in the US, to the Patriot Act, and it is possible that that information could be made available to the authorities.
Only regular citizens will be caught by this and... the whitehouse knows it. I only wish the general public could see HN now. Someone with lots of money,looks-at-Google, should buy like 2mins of commercial-time during the Super-bowl to talk about stuff like this.
More likely you already have suspects, and your suspects have acquaintances , family etc.
You would be more interested in looking at these people, who do they network with on social media, what are they interested in? Might they be knowingly or unknowingly be providing material support?
You would probably use this information to build up a broader profile and see which avenues are worth investigation.
If the American gov wanted to kill the cloud, then good job ! I want to clarify that I do not trust my own gov neither ...
These software corps better be persuasive because a whole economic part of USA will be endangered then !
True theater!!!
PR 101, mang
http://www.theonion.com/video/cias-facebook-program-dramatic...;
Without their keys having it over the wire won't get them what they want.
EDIT: poor wording.
I just assume Barack is LOLing everytime I crack a funny on twitter.