This would be reasonably easy for the NSA to do, relatively hard for companies to catch, and perfectly explains all published facts.
This would be reasonably easy for the NSA to do, relatively hard for companies to catch, and perfectly explains all published facts.
For that matter, who is the CEO authorized to tell if the CEO got the letter. Obviously they have to be authorized to tell at least enough employees to actually implement the demand.
If it is possible though, there could perhaps be an NSL that covers "just gmail" that is otherwise as broad as the Verizon one.
The notion that a CEO could be unaware of something like that happening is incredibly disturbing though. I hope that is not possible.
I suppose though that whatever part of a NSL that authorizes the CEO to tell developers to make it would likely also authorize the CEO to tell the security guys not to sound alarms about it.. at least not without consulting senior management first.
The covered persons in A would be just enough to appropriate the necessary budget and deliver the features.
When the VP of Engineering or CEO asked, 'why did we add this particular feature, what's the use case?' the answer was, "If it's business critical that you need to know, we would need to document that and see if you can be added to an NDA."
"An NDA with who?"
"I can't say."
NSLs take this to an entirely different level. Page and Zuck don't have a clue. As soon as the databases were large enough to be useful, the data was in the hands of the NSA. That much should be taken for granted. The more important question has always been "if and how can it be used against you?"
With Obama claiming it's legal and approved by 3 branches, and how widely outside the NSA the data will be shared, the reality of "show me the man, I'll show you the crime" has never been truer.
All the companies ruled out is direct access (and Microsoft said is if there's a voluntary program, they're not part of it; they didn't rule out an involuntary program of course).
They did not rule out even something so simple as an API, or another party doing the work for the NSA (which the NSA then taps into, ala the Palantir concept).
Press reports that suggest that Google is providing open-ended access to our users’ data are false, period. Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false.
I mean you still need to deal with private keys but the NSA might have the certificate authorities wrapped around their fingers.
I don't think they would be intercepting SSL traffic either, because Google has a hard enough time legitimately updating their certificates [1] that I imagine if the government were doing it on a wide scale people would definitely notice.
[1]: http://googleonlinesecurity.blogspot.com.au/2013/05/changes-...