PRISM: "Collection directly from the servers"
twitter.com
twitter.com
http://www.guardian.co.uk/world/2013/jun/08/nsa-surveillance...
Could it be that the slides were made by a non-technical person who was over-selling this? "direct access" could mean "straight from the source".
If the most powerful country in the world is getting trolled with one pdf and five powerpoint slides, this is a masterwork. It would appear that the phone tapping is real, or functionally real, based on the reaction of the Senate and the telecoms. The internet companies replies, especially Google's, are quite different. Simply causing FUD is sufficient to disrupt a lot of US companies' dominance in the internet market.
A lot of countries stand to benefit from a crippled United States position in internet architecture. One of them is holding an internet security summit with the President today. All of them have powerpoint, and many of them have active intelligence programs of their own.
Skepticism is warranted... The long term effects of this hubbub should act to strengthen privacy and security worldwide.
Start ~2:00. http://www.washingtonpost.com/video/thefold/nsa-leak-source-...
The order, signed by Judge Roger Vinson, compels Verizon to produce to the NSA electronic copies of "all call detail records or 'telephony metadata' created by Verizon for communications between the United States and abroad" or "wholly within the United States, including local telephone calls".
The order directs Verizon to "continue production on an ongoing daily basis thereafter for the duration of this order". It specifies that the records to be produced include "session identifying information", such as "originating and terminating number", the duration of each call, telephone calling card numbers, trunk identifiers, International Mobile Subscriber Identity (IMSI) number, and "comprehensive communication routing information".
This court order and the extremely wide net makes me believe the worst for the rest.
In which case, they could claim to be lawfully complying with information requests that are "not as broad", even if the system as designed makes it as easy for the NSA as hitting a "monitor this person" button.
It also wouldn't take vast systemic corporate knowledge. All centralized systems have centralized administrative control that allow for in-depth view and analysis of user accounts and data, and most large-scale systems have relatively powerful and easy-to-use tooling (especially to support customer service, sales, etc).
Complete access to those systems is generally restricted due to the likelihood for abuse, but there remain valid internal management reasons for such access.
Adding to those systems to allow the NSA unfettered (or barely fettered) access could be done without having to alert the entire organization that their internal management systems, which they built knowingly, and have no reason to distrust, have been subverted to allow for on-demand government spying.
It puts any conspiracies I've heard involving the US government to shame. You may not like the Chinese governments, but you need to look at the facts here: the slides were released by the Western media, the US has not denied their legitimacy or the existence of PRISM, and there is zero evidence for Chinese involvement.
http://techcrunch.com/2010/09/14/google-engineer-spying-fire...;
That was three years ago though...a lot may have changed about Google's infrastructure...I'm thinking, for example, whatever work has been done to unify login systems between Google Apps, GMail, Youtube, and of course, Google Plus. Presumably, as complexity has arisen, so has the need for better access-control infrastructure, which would (hopefully) prevent someone even at Eric Schmidt's level to lose his wits and trample around in the system without many, many flags going off first.
So with that said, that's why I'm skeptical (in the layman sense of, this is all more complicated than I can dream of) that this surveillance alleged in the PRISM reports could occur with just a few dedicated employees in the know (or a few moles).
It's not just the data transfer that has to go unnoticed, but the successful navigating of the access control infrastructure. And even if Google were to be completely in cahoots with the NSA and built a backdoor, wouldn't there have to be a testing suite that would make sure whatever normal changes to Google's code base also didn't inadvertently restrict (or reveal) the back door logic? And then wouldn't there also have to be at least one layer of oversight to make sure that that testing suite itself was maintained but otherwise unnoticed?
But I'm speaking as a layperson here who thinks that the kind of infrastructure Google has would require a framework that would make backdoor access awkward to implement. Just so many things could break across all of Google's servers, otherwise...like this fun incident that most people probably still remember, if you happened to be awake early one morning 3 years ago:
http://googleblog.blogspot.com/2009/01/this-site-may-harm-yo...
> If you did a Google search between 6:30 a.m. PST and 7:25 a.m. PST this morning, you likely saw that the message "This site may harm your computer" accompanied each and every search result. This was clearly an error, and we are very sorry for the inconvenience caused to our users. > > We periodically update that list and released one such update to the site this morning. Unfortunately (and here's the human error), the URL of '/' was mistakenly checked in as a value to the file and '/' expands to all URLs. Fortunately, our on-call site reliability team found the problem quickly and reverted the file.
In addition, internal analytics systems will have reason to tap into data streams/events, as will content-based advertising systems.
All of these things are often designed to provide general interfaces; locking them down is done through generic privilege levels and access controls. The people managing those access controls are few, and may not even know the true purpose for the controls they've authorized. Indeed, someone could requisition the insertion of a content analysis system that was fed user data, appeared to be a legitimate deployment, and yet was actually a core service used to push data to the government.
PRISM is not system handling common law enforcement issues. Those documents reveal very large scale secret government intelligence collecting tool. If companies are involved, they are forbidden to reveal it and there will be spin, of course.