“The government does not have access to Google servers”
plus.google.com
plus.google.com
10 years from now, people will still be talking about this.
We need to roll back the Patriot Act, period.
1) Access to users when provided with a "warrant" or someother legal instrument. This is where for example a divorce court orders the message history of a person from facebook to confirm/deny infidelity. This is your "Facebook secure room/portal" business. You don't want any tom dick and harry having access to this as its a massive security hole. 2) Snooping. This is where apparatus is placed between the public and a company which allows the interception of all data.
These are two very different mechanisms, 1) is a precision tool for getting information on a small amount of users. 2) is a blunt tool that allow people to stuff themselves full of information, it is also inherently very expensive(both in time, resources and analysis).
both method 1 & 2 have been going on for many years. Its also been fairly well known for many years (schneier and crytptome have been saying this for a very very long time)
So why did the NSA ask verizon (and most likley all the big players) for this list of who phoned whom, if they have all this information kicking around? two reasons: Its dirt cheap, and accurate.
Instead of having to infer who was on what IP at what time, you have the canonical proof.
I'm curious if these orders can be served directly to mere employees that have access to install the monitoring software/hardware, with confidentiality obligations barring them from telling their employer. Another explanation may be that NSA agents simply obtained jobs at each company, and those agents installed the monitoring software/hardware without the knowledge of the companies. This would explain the dismay, and the clear embarrassment of the NSA.
I feel as if so much could be cleared up if they would simply respond line by line to the stories by the NYTimes and Washington Post.
It's ludicrous.
http://www.theonion.com/articles/the-onion-urges-barack-obam...
Thanks, fixed. Looks like HN is over-escaping some values -- click the 'link' link to this post and see how the first line is over-escaped in the title bar?
Which, unfortunately, puts the rest of the denial into question for me as well.
These accusations are seriously getting out of hand. This is also seriously getting so illogical that I've considered whether it's even worth posting a response.
Is accusing someone with a badly created powerpoint presentation now enough for such a massive storm?
Yesterday, Larry gave a thorough point to point denial to the Washington Post article. Conspiracy theorists@HN moved the goalpost and started talking about how if Google isn't doing X they must be providing data to NSA servers. Now that David Drummond has come out and denied that Google's not doing Y, some HNers start complaining that he's lying even though there's no evidence to the contrary.
Google has committed its fair share of mistakes but as employees inside the company we have always stood by our users and a lot of these attacks are indirectly questioning our moral character.
Larry and especially David have created a culture where we push back when the government makes overreaching user data requests. These push backs have been happening for years. Google has even gone to courts questioning the constitutional validity of NSLs. (source: [1]). There are times when courts uphold the Government request. Google publishes these in its Transparency report ([2]). The claim that these guys are willfully lying on this issue is completely out of character with what their actions have been till date.
You say that government has already admitted that they access the data. Where? Do you mean the Verizon CDRs? Or are you using the flimsy PPT as evidence? Maybe your source is one the myriad of articles that have used the powerpoint as their source. Or maybe your source is one of those of another articles that use other badly sourced article as their sources. Maybe you mean Obama's statement that the government does track emails. In that case, being in technology, I hope you realize that being a MITM email snooper is one of the easiest things to do. That's why you never ever use email for secure communication. Maybe you don't understand these "nerd-y" things (yes, I was a shocked too when a HNer threw that at me), but I implore you to logically think about this story.
Yesterday, there were a flurry of posts that were seeing a conspiracy in how Mark Zuckerberg's and Larry's response were similar. Why have we HNers turned into conspiracy theorists now? It was only later when some sane voices pointed out that they were each responding to the specific points raised by the original WaPo article, that that controversy died down. Of course no one seems to mention that the original WaPo post has retracted several claims especially about companies being in the know. [3]
Some conspiracy theorists@HN have even talked about spies infiltrating as Google engineers. Are you guys serious? The level of control/monitoring/logging that happens to employees at Google when accessing any data at Google (even when you're just trying to debug why processing that data is crashing your server) is so huge that this just won't be a feasible strategy for these spies. Also, with all these checks in place it's impossible to get hold of information without a lot of flags being raised. Even if we assume that all US based engineers at Google are somehow government spies (a preposterous claim which I'm sure someone must have made on HN by now), Google has engineers outside US. Engineers who have access to the same alerting/monitoring systems that would alert them if such unauthorized data access was happening. Those engineers would not be bound by any US government imposed gag order that conspiracy theorists here seem to claim.
I've even had someone claim on HN that because Google worked with NSA to protect Chinese human rights activists from spying attempts/hacking attacks, Google's helping NSA spy on US citizens. This is so illogical that it makes no sense to me.
I've had the opportunity to have worked with Yonatan's team and I have immense respect for him. I also completely mirror his feelings [4]. Any massive data sharing/accessing would be really hard to do without this turning up in some shape or form in front of me and if this were happening I would not be at Google. Most of us engineers would not be.
Enough with the personal attacks questioning our values.
Now to the bigger question, if a democratically elected US "government" is making and forcing private individuals and organizations to follow extra-constitutional norms. Shouldn't you actually take this issue up with your local senator/representative? Contact them: http://www.senate.gov/general/contact_information/senators_c... http://www.house.gov/representatives/ Doesn't being in a representative republic mean that that's how you solve the problems you're having with your government. I was one of those who were mystified by the current president's oratory. Yet, I also believe that if something is not right it's time to use the proper channels to have your voice heard. How many of you are US citizens and have written multiple posts here on HN since yesterday but haven't called your local representative yet? Now is the time.
These witch hunts without evidence, all these conspiracy theories, the attempts to find fault with every statement being made; these are not what HN should be about. Let's actually do something to bring about some real change.
Sources: [1] - http://news.cnet.com/8301-13578_3-57587003-38/judge-orders-g...; [2] - https://www.google.com/transparencyreport/ [3] - http://www.forbes.com/sites/jonathanhall/2013/06/07/washingt...; [4] - https://plus.google.com/103389452828130864950/posts/huwQsphB...
The documents provided with the Washington Post and Guardian articles are not no evidence.
And yes if you examine the documents as much as my post you'd have seen that they are indeed based on little to no evidence.
By the way have you called your local rep yet?
but i doubt they'd say that. they already seem to say they get very regular requests (which could be 10 or 100 000 or more) that are just "hey please give us that we need it".
http://techcrunch.com/2013/06/07/doublespeak-denials-and-bro...;
If you're actually interested: the only source of facts on that whole page is the NYTimes piece they link to: http://www.nytimes.com/2013/06/08/technology/tech-companies-...
Here are a few facts:
1. The New York Times article did not specifically cite PRISM, it only cited FISA, which was already largely known by the public. It is true that this could be because PRISM is allegedly justified under Section 702 of FISA, but they are not the same thing.[1] It would be most appropriate to say that one encompasses the other, but they have two separate protocols, and as of right now, only one was discussed by the Times.
2. Let's say the NYTimes article is about PRISM, and they simply didn't mention that acronym for whatever reason. If that is the case, the information leaked therein also makes it very clear that it is entirely possible for CEOs, chief officers, and other high ranking employees to be completely in the dark about it. The only people allowed to know about the requests for information are those who receive and analyze the requests. That's not a conspiracy theory - it's leaked right along with the rest of the information.[2] Mark Zuckerberg, Larry Page, Dave Drummond, Yonaton Zunger, etc. might literally not know the extent of how far the government reaches in their companies.
3. It is unreasonable and unrealistic to expect the leaders of these named companies to stand together in righteous technological might against The Man. Nothing practical would be achieved by having Mark Zuckerberg or Larry Page penalized for what they said on record, in public against a government agency. Nothing would benefit the American people by having them put on trial or their companies sued for violating national security. The NSA designed a Catch-22 gag order that prevents those involved from even acknowledging the existence of government involvement or letter agencies, let alone detailing specific protocols or history.
I've said it before and I'll say it again. Stop getting distracted from the real problem here. The threat to privacy is the NSA. The threat is our government(s). We have the power to fight it if we consolidate our focus with precision. We may feel wronged by the apparent lies of public figures but they had no choice, if they were even in the wrong. We cannot know what pressures were put upon them at this point in time.
Lay down your pitchforks and direct your anger and incredulity to your government, who ordered this - the public entity that made this legal and hidden and nearly impossible to speak out against. That is your real enemy.
[1]: http://www.theverge.com/2013/6/7/4407782/phone-spying-and-pr...
[2]: http://www.nytimes.com/2013/06/08/technology/tech-companies-...
Unfortunately, it is important that all collaborators be punished. Especially since the government is trying to expand its surveillance programs to include a wider range of companies, and per reports many companies are reluctant to sign up out of fear of public backlash. There needs to be that public backlash. There needs to be negative consequences for those companies that participate.
That being said, I'd like to clarify that I don't think all forms of cooperation with government investigations are inappropriate. Very narrow and specific requests in response to explicit subpoenas being an example of something I think must be tolerated. On the other hand, blanket requests and requests for data access that would enable government to independently explore the records of millions of American citizens is something that can't be tolerated. Efforts must be made to change such policies at the same time that efforts are made to penalize the companies that collaborate and make it possible.
It's also important to raise the awareness that our data isn't safe in Google's hands.
Google isn't the internet.
Dump gmail, FB and other spy holes. Use public key crypto. Take your own network back.
Or continue on as usual. Our choice.
The reason I recommend Bitmessage is because after overcoming the friction of installing it, it's frictionless. You don't have to remember passphrases or anything. It also has advantages over PGP-encrypted email like deniability, built-in spam minimization, broadcast messages (like Twitter), chan boards, etc.
My mother doesn't even know what the words "public key crypto" mean.
Your post is well written and presents an interesting viewpoint, but this is completely wrong. A handfull of the most powerful and wealthiest companies in the world standing up to the US government wouldn't achieve anything? What? It would make a HUGE difference. If the people involved won't stand up for what's right due to personal fear, that's understandable. Most people wouldn't. But they shouldn't pretend it's for any other reason. To do so is a huge insult to those who do have enough courage to do the right thing in the face of huge risk--much greater risk than is faced by these frightened SV millionaires and billionaires.
As it takes less resources to obtain information you can bet that there will be more efforts to obtain information. If you want to avoid much of this, you just require hand-delivered documents from accredited agents to accredited agents, manual review of these documents (and perhaps shipping them between corporate offices for such review). Get a review for being thorough, pushing back, and not hurrying. Make sure it takes time, that lawyers go through them one by one, and send to another lawyer (preferably somewhere else) to cross-check. stall for as long as you can on every order you can. You will get fewer.
Google is essentially claiming transparency, while ensuring that the transparency report is increasingly meaningless because it is easier and easier to get info in ways that won't get into it.
Within Google's denials is more or less a confirmation that what the NYT is saying is true.
This means Google (and the other American companies, too) has a problem of loyalty now, and I'd say a huge one. It's only a matter of time before such services arrive, and I'd like to believe people will start quitting it in droves.
I see it much like with the ISP situation in US. People don't really have a choice of ISP's, but they've grown to hate them so much over the years, that as soon as a decent competitor is around, they'll be switching. I believe (and hope) the same will happen to the American companies, including Google - at least until this mess is fixed, and the Patriot Act repealed.
So I do believe the Patriot Act, and the uncovering of what it can really be done with it has caused irreparable damage to US companies. I received a Chrome update yesterday, and now I have to wonder "is it just a coincidence? Or is it to remove some tracking technology they had it until now, so people don't find out about it when all the spotlights are on them now?".
Could be a genuine question, or maybe I'm just too paranoid, but the point is these unveilings made me feel this way (the Google "privacy issues" never bothered me before, and I was actually waiting for Google Glass - not anymore obviously), and I don't think anything Google and others say in the future will make me feel otherwise, until there are concrete steps done, wide in the open, to stop this kind of surveillance.
These are big companies and putting pressure on them like this is both practical (just pick your data-hosting European country carefully, though) and could create economic leverage on Congress, but I think it's kind of bullshit when these transparency reports mention receiving between "0-999" National Security Letters, and Eric Schmidt is telling people about the PATRIOT Act requiring them to hand over information, and now you're saying "what?? they're handing over data because of an order that doesn't require probable cause established in front of a judge?"
I don't want to come off as too harsh here, but, yes, this is what we've been banging the drum on for years about. Jewel v NSA[1] is very nearly 5 years old now, and the executive branch is trying to drag it out even longer. Welcome to the fight; let's try to make our country livable instead of dreaming about jumping ship but doing nothing in the meantime.
But the key thing is to not waste energy on the side issue...the grab for power should always be scrutinized, and it is not an issue as simple as "Vote in a new president and live like Richard Stallman" (though neither of those ideas are bad, either)
Call me jaded...but remember how angry and energized everyone was over Aaron Swartz's death? Just six months later and we hear nary a peep about it, not even a boilerplate response to the White House petition. This is the way it is with so many issues involving the law, people get bored or conflate the wrong things...a few months later, no one really remembers.
The responsible thing to do is to require a physical document, hand delivered to an appropriate corporate agent or officer, with a manual, hard copy review process.
http://www.washingtonpost.com/wp-srv/special/politics/prism-...;
Go on, someone, make it so. Then leak it. Let's do this thing.
Every time NSA, FBI requests user's private info from google they'll [the government] be divulging the identity of a suspect or a potential suspect. This leads to potential leaks or potential reputation damage. Imagine if a congressman or famous CEO is under investigation. So the person/people inside google ought to have the same clearance OR google would need to give a back door access to the government. Which is why I don't believe google.
If google is sincere about their position, they should setup their systems so that no one but the user(owner) would ever be able to access their private data.
But what makes the person who unveiled the PRISM more credible than all of the Tech companies?
Also, I don't think they are playing with words or intending to do so. They are making it quite clear in my opinion.
(I have to admit I do not fully understand PFS and the implications here.)
>employees whose job it is to comply with FISA requests are not allowed to discuss the details even with others at the company
So it is possible that executives are not allowed to know what data their companies are supplying to the government.
Not only are their google+ profile very active, I am going to assume they are still using and most likely will be using google products (or products from other companies who has been implicated) months from now even if nothing changes.
The question is, lets say you are absolutely sure beyond any doubt that all these companies willfully (or unwillingly but now lying to you) shared data with the government. What do you do now?
Do you accept it as it is and carry on? Do you stop using their service? Or do you campaign to stop these companies and government from doing this (seems highly unlikely to be effective or verify)?
The problem, of course, is that some Google services are nearly irreplaceable, especially search. There are alternative search engines, but they simply aren't as good for the technical type searches that a programmer needs. Duck Duck Go is better than some older alternatives have been, but when using it I frequently find myself having to return to Google to actually find what I'm looking for. I wish them luck and hope very much they keep improving, as I'd like to use them, but so far I can't really.
If he is telling the truth, at least about this very specific thing (not having access to "Google's servers"), then it's still possible they are giving them easy access in some other way, such as copying the data to other servers that are "not Google's servers".
So worse case scenario, he's blatantly lying about it. Probably best case scenario, they're still giving them the data wholesale in some way, and he's playing word games and semantics.
I have a very hard time believing none of this is happening, at this point. I hope I'm wrong though, but even then, the NSA probably has direct pipes into the carriers and ISP's, and at the very least have access to all the data going through US pipes that is unencrypted (and the encrypted data is stored for later - i.e. the 5 billion terrabyte Utah data center).
No, the best case scenario is he's telling the truth and Google only gives specific data in response to specific court orders that have been reviewed by their lawyers.
Normally I love reading the comments on HN, but I've just despaired over the last couple of days. People are assuming that out-of-context fragments from a Powerpoint presentation are 100% correct and when every single company gives a flat-out denial, then the companies must be lying or misleading or slippery.
The law does not require these companies to issue denials.
Google has sent us a statement that reads: "As a law abiding company, we comply with valid legal process, and that - as for any US based company - means the data stored outside of the U.S. may be subject to lawful access by the U.S. government."
[1] http://news.softpedia.com/news/Google-Admits-Handing-over-Eu...
No they just have Google's SSL private keys- perhaps...
Does any government, US or otherwise, their agents, representatives, contractors or NGO's have access, directly or indirectly, through any means, to <insert company name here> DATA, FILES, COMMUNICATIONS, LOGS or any other information having any relationship whatsoever to <insert company name here> users?
This could be, and probably should be, refined, IANAL.
The point is simple: We don't care about "direct access to servers". We care about access to data. And this can be provided through many channels, direct and indirect. It can even be provided via daily tape backup dumps. Of course, it can be provided to organizations peripherally working for or with a government yet not directly to a government agency. And, finally, it could be provided to another government that, in turn, can pipe it back to US governnment agencies or collaborators.
The rabbit hole can be very deep.
Some people have correctly pointed out that if Prism is considered 'law' (falling under any number of national security laws), then all Google is doing is complying with the law.
And in that case, what Drummond just said in no way actually denies participation in Prism or a similar program.
The message is loud and clear from Google that we need to know doublespeak when we hear it. Class is in session!