Eric Schmidt: CNET gets it right on the NSA/Google issue
plus.google.com
plus.google.com
He's well-known for basically claiming that we're not entitled to any privacy ("if you don't want anyone to know blah blah ... ") and for later being a vindictive fool when CNET published some of his personal details found through Google.
Besides, he's not even CEO anymore, why would he know anything about highly confidential dealings with the NSA?
Would you like Larry Page to detail this for you? or Matt Cutts? Who will you believe?
Inferring he is no longer CEO and might not know about these matters is just an informal fallacy and has zero to do with whether or not Google, Facebook, etc. is telling the truth on the matter. FWIW, I believe them when they say they aren't giving direct access to their servers to the government. That doesn't mean they aren't, and I'm willing to listen to any substantial claims that they are.
I don't trust the government to always do the right thing when poking around in our business, but I'm also not going to run around like a chicken with my head cut off when everyone gets their underwear in a knot over leaks like these.
What have they done to earn your trust so that you believe them?
In matters of espionage and mass surveillance, I expect lying to be the default response for the government and corporate players involved.
They're saying PRISM gets them access to Google/Facebook/etc.'s data with no other middleman. That's not always the case; when working with international partners NSA might obtain intel from other (foreign) intelligence agencies, or their HUMINT might report data that is itself hearsay.
So the source/provenance of data is very important for an intelligence agency. NSA is saying this (with PRISM) is the best case as far as the source of intel goes, there is no better primary source.
That still doesn't mean NSA has embedded backdoors or that the company doesn't control access to the data though. Data Access is a separate concept from Data Source in intel.
We can still say that having this kind of access to data is above the capabilities NSA needs to have (it certainly seems ripe for abuse) but it's sounding like the reality is not quite as sinister as Greenwald or WaPo had been led to believe.
"But if you really need that kind of privacy, the reality is that search engines, including Google, do retain this information for some time. And it’s important, for example, that we are all subject in the United States to the Patriot Act. It is possible that that information could be made available to the authorities."
Allow me to quote from the NSA document we just
published defining PRISM: "COLLECTION DIRECTLY
FROM THE SERVERS"
Our story was written *from the start* to say NSA
claimed this, telecoms deny-we wanted them to have
to work it out *in public* what they do
We reported - accurately - what the NSA claims. We
reported - accurately - what the companies claim. It
conflicts. That's why we reported it
Just one more time: NSA on PRISM: "Collection directly
from the servers of these US service providers:
Microsoft, Yahoo, Google, Facebook.."The lede on Greenwald's story:
The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants, according to a top secret document obtained by the Guardian.
Then, just 1 graf later:
The Guardian has verified the authenticity of the document [...]
Later:
The NSA access was enabled by changes to US surveillance law introduced under President Bush and renewed under Obama in December 2012.
The access. Was enabled. No qualifications given.
Next graf:
The program facilitates extensive, in-depth surveillance on live communications and stored information.
The program now exists. The article no longer reports on the contents of a document, but rather on "the program" itself. Is he talking about PRISM, or about the change to FISA law? It's not clear. But it's clear here:
The participation of the internet companies in Prism will add to the debate, ignited by the Verizon revelation, about the scale of surveillance by the intelligence services.
Greenwald has now reified the program and the participation of the listed service providers.
He seems to go back to reporting on the document here:
Some of the world's largest internet brands are claimed to be part of the information-sharing program since its introduction in 2007.
But in fact, the "claim" he's referring to is the calendar date of the start of participation. Next graf:
It was followed by Yahoo in 2008; Google, Facebook and PalTalk in 2009; YouTube in 2010; Skype and AOL in 2011; and finally Apple, which joined the program in 2012. The program is continuing to expand, with other providers due to come online.
It is followed. It is continuing to expand. Not, "the document claims". Words mean things, as Greenwald knows very well.
The extent and nature of the data collected from each company varies.
Again: by this point in the article, the collection is happening, the way his interpretation of the leaked slide deck says it is.
A chart prepared by the NSA, contained within the top-secret document obtained by the Guardian, underscores the breadth of the data it is able to obtain: email, video and voice chat, videos, photos, voice-over-IP (Skype, for example) chats, file transfers, social networking details, and more.
It is able to obtain. Not "claims" to be able to obtain.
Greenwald can't now hide from what he actually wrote, and his attempt to do so is telling.
There's no substantive difference between "It was followed by Yahoo in 2008" and "The document claims it was followed by Yahoo in 2008." The furor of the past 72 hours has given no reason to question the document's authenticity nor the existence of the program the document entails. The president himself has alluded to the existence of the PRISM program and attempted to assure us all that it was only to keep an eye on foreigners and not citizens.
http://theweek.com/article/index/245360/solving-the-mystery-...
On another topic, oh to be a fly in the wall when Mr US Citizen Greenwald passes through JFK customs.
edit: It's just one new slide (http://static.guim.co.uk/sys-images/Guardian/Pix/pictures/20...) which says "directly from the servers"...but since Google is ostensibly arguing that the slides are poorly worded, hopefully the Guardian believes the other unreleased slides elaborate? The blog post ends with "A far fuller picture of the exact operation of Prism, and the other surveillance operations brought to light, is expected to emerge in the coming weeks and months...", which means that they will be releasing bombshell by bombshell, or that they think other revelations will be independently reported?
(original comment below:)
I immensely respect Greenwald, but he's setting up presumptions for his reporting that make it unassailable, no matter what the facts are.
1. Our reporting is accurate.
2. The fact that the companies involved deny it is proof that our reporting is accurate, because our reporting said that they would deny the report.
3. Therefore, our reporting is accurate.
It's possible that the reporting is accurate on its face, but the most relevant details (i.e. the ones that would separate this from, egregiously and surprisingly evil to, well, just more of the same) were not reported correctly. Has either the Guardian or the WaPo released the entire slide set?
He explicitly states in those tweets that he reported the claims of both sides, which he was fully aware were in conflict, in the hopes that the truth of the reality would come out.
> The slide, below, details different methods of data collection under the FISA Amendment Act of 2008 (which was renewed in December 2012). It clearly distinguishes Prism, which involves data collection from servers, as distinct from four different programs involving data collection from "fiber cables and infrastructure as data flows past"...Essentially, the slide suggests that the NSA also collects some information under FAA702 from cable intercepts, but that process is distinct from Prism.
This specific paragraph seems like a non-sequitur...did the counter-argument that Google made rely on claim that the news reports conflated fiber optic tapping and PRISM? I thought the argument was:
1. The Guardian has slides claiming that the NSA has direct access to our servers
2. Those slides, according to Google, are wrong.
Presumably, the Guardian is in possession of the full 41 page powerpoint. They'll likely release pieces of it at a time. Nice to see they're waiting for everyone to trip all over themselves first. I can't wait to see how this plays out in the coming weeks.
Funny. When Wikileaks did the same thing people said it was inappropriate and editorializing and dishonest. It seems that the Guardian and Wikileaks strategies for maximizing impact are on the same frequency.
My guess was that the source feared that one or all of the slides have some kind of identifying tag, if not as a meta-watermark but as something tell-tale in the content...and so had requested the Guardian and the Post to release as little as possible.
NSA says that they can use PRISM to get information directly from a company's servers. That's true, but it happens through an intermediary (the company itself). But even with the intermediary the data being sent did come directly from the company.
In other words intelligence agencies like NSA are concerned with the source of intel and in this case there's no middle man. Access to intel is also important to NSA and in this case there is a middle man. "Access to" and "provenance of" intel are separate concepts though and it does Greenwald little credit to allow himself to be confused by it.
Edit: If I was Greenwald I would clarify quickly as well as otherwise he's going to allow the National Intelligence community to turn the debate into technical sticking points that Greenwald is going to lose on, while at the same time turning the debate away from the transparency of these types of intelligence gathering schemes and whether they're necessary at all.
If true, that means there's no direct panopticon access, only an expedited, direct, digital means of getting the data, once retrieved, into the government's hands.
Ignoring whether I think a government should be able to ask for this information at all, I think the existence of such direct means is probably on the whole a good thing, because if the british government's repeated losses of laptops and DVDs full on private information are anything to go on, governments really suck at secure data transfer and I'd rather only a government had it than a government -and- whoever managed to steal the thing en route.
I still hope google will continue to challenge the NSL process etc. in court, but I can't say I mind them arranging things in the meantime so as to minimise the odds of the government screwing up the execution of said process.
declan submitted his story https://news.ycombinator.com/item?id=5844091 but it languished.
It's a shame, because it's the first responsible piece of reporting I've seen on this mess. The media has been trolled by a Powerpoint brief from self-important USG bureaucrats.
Surveillance is tricky business and technology makes the boundaries of what's acceptable to reveal even trickier. It's true that the muddling of the Verizon/AT&T stories is being interwoven with this, which may not have helped. And the scope of the information requested falls well within acceptable procedure for "traditional" investigations I.E. who contacted whom at what hour on which day. But this isn't a traditional investigation anymore.
In essence, they tried to automate police footwork, which still doesn't fly with a lot of us.
"the government does not have access to Google servers—not directly, or via a back door, or a so-called drop box" https://plus.google.com/+google/posts/TMh6gUVrwMq
I'm not sure what is rumored or not, or what is true or not. My point is that they deny involvement in PRISM, and by PRISM I mean the program that alleges access to company servers.
What are you talking about? Almost every story reporting on this originally said that. The Washington Post backed down, but the originating reporter is still quoting some NSA source(s) as saying it:
'Just one more time: NSA on PRISM: "Collection directly from the servers of these US service providers: Microsoft, Yahoo, Google, Facebook.."'[1]
[1] https://twitter.com/ggreenwald/status/343423727066824705
This seems unfair. There was a specific accusation or suggestion of direct access, so it's not (or at least not necessarily) misdirection for Google and friends to specifically deny it. It certainly doesn't answer all questions about PRISM, but between the denial of direct access, and the denial of any Verizon-scale order which would amount to direct access in all but name, you get a pretty forthright statement limiting the possible extent of the NSA data-gathering.
[1] http://static.guim.co.uk/sys-images/Guardian/Pix/pictures/20...
Greenwald pisses me off and I don't trust him. We know there are 41 slides. They are putting out 1 new slide per day it seems. Just release all of it and get it over with. This seems designed to maximize the Guardian's traffic by doling out the information piecemeal.
Today they released a slide (http://www.guardian.co.uk/world/2013/jun/08/nsa-surveillance...) that shows NSA upstream fiber-interception (outside company datacenters) + PRISM, but again, it is vague as to what PRISM is.
If the slide definitely said "Data from internal datacenter taps or backdoors" it would be clear and inarguable. All that would need to be discussed is whether they did this with HUMINT moles, or whether the companies knowingly cooperated.
As it stands now, PRISM could be anything from "Google Takeout NSA Edition" that lets the NSA get a ZIP file of account data after it's been requested via a warrant/NSA, or it could be a hack into Google's servers that somehow allows them to slurp up and intercept data and it flows around the data center.
We don't know, but if Greenwald has other slides that clarify this, just release them, the speculation right now is irresponsible and based on lack of knowledge.
I would call it 'directly from the servers'. It's likely used to distinguish client vs server side. Not the actual technical mechanism.
Which puts everyone on all sides on notice that they should step carefully with their statements.
1. What is the process.
What requests come from the government. What government entities make those requests. What entities within the internet companies process those requests. What parts of the request handling are done by humans with decision-making authority vs what parts are handled by machines or by humans following a rigid script. In either case, what policy drives those decisions. What proportion of the requested information is given or denied.
2. What is the speed and scale of the process
How quickly are these requests fulfilled. How much data comes back from a request. What proportion of this data is relevant to the target and the investigation vs “incidental”. How many requests are there per month or per year. How much data is gathered per month or per year.
Side-issues not covered above:
Is the access “direct”. Is there a “back door”. Is access given to “servers”. Is access given to a “network”. Is there a “beam splitter”. Is the government provided with a private or secret “key”.
There are many ways to construct such a system, and there are many ways to describe it (nevermind flat-out lie about it) by carefully parsing these side-issues. What matters is not the implementation details but the effect.
The PPS lists various types of data the NSA gets from various companies. For some reason most commenters here chose to interpret this to mean the NSA has a direct pipe feeding it all of these companies data. The fact the PPS mentions it's a $20m program should inform that this is obviously not the case. Is it just a matter of wanting to believe the more outrageous version?
Does any government, US or otherwise, their agents, representatives, contractors or NGO's have access, directly or indirectly, through any means, to <insert company name here> DATA, FILES, COMMUNICATIONS, LOGS or any other information having any relationship whatsoever to <insert company name here> users?
This could be, and probably should be, refined, IANAL.
The point is simple: We don't care about "direct access to servers". We care about access to data. And this can be provided through many channels, direct and indirect. It can even be provided via daily tape backup dumps. Of course, it can be provided to organizations peripherally working for or with a government yet not directly to a government agency. And, finally, it could be provided to another government that, in turn, can pipe it back to US governnment agencies or collaborators.
Anyone can say "The US government does not have direct access to our servers" while still feeding them a firehose of information through alternative means.
Now, could you suggest better language?
I think the shocking part was that the NSA might have been able to essentially run grep themselves on a company's servers (though apparently it's not that simple), but that's not the question you're asking.
Provided you're of sound mind, you're the only person who can't let you down.
The order has to be for account information or an intercept directed at a specific foreign person, and "you can't say everyone in Pakistan who searched for 'X'... It still has to be particularized."
This seems to contradict the NYT's claim http://www.nytimes.com/2013/06/08/technology/tech-companies-... that
FISA orders can range from inquiries about specific people to a broad sweep for intelligence, like logs of certain search terms, lawyers who work with the orders said.
. Maybe it's specifically there to contradict the NYT claim.
https://twitter.com/ggreenwald/status/343421926057861121
And what about the FISA requests Google cannot legally talk about?
I'm not angry about my details leaking to governments, what I'm angry about is how manipulative the media is and how much stupid they assume we are.
I rather trust Mark Zuckerberg than CNET. Their tech reviews are mostly biased sponsored ads, why would I trust them with something serious like this?
I'm not sure what you mean by "every single possibility." Do you just mean "it's possible"?
"It's not as described in the histrionics in the Washington Post or the
Guardian," the person said. "None of it's true. It's a very formalized
legal process that companies are obliged to do."
Please, please can we know about this "formalized legal process"?Strategically placed traffic monitoring at major ISPs is enough to build a pretty complete picture. I can imagine SSL traffic doesn't even pose much of a hurdle to a well funded project. You don't need the data in real time.
We cannot say this more clearly—the government does not have access to Google servers—not directly, or via a back door, or a so-called drop box. Nor have we received blanket orders of the kind being discussed in the media. It is quite wrong to insinuate otherwise. We provide user data to governments only in accordance with the law. Our legal team reviews each and every request, and frequently pushes back when requests are overly broad or don’t follow the correct process. And we have taken the lead in being as transparent as possible about government requests for user information.