Setting the Record Straight
yahoo.tumblr.com
yahoo.tumblr.com
I trust Google not to share my sensitive information (product strategies, negotiating positions) with competitors on request, I can't trust some random agent who knows he won't be held accountable if he looks up and sends that information to his cousin.
There's the potential here to 'disrupt' the whole of silicon valley.
And Diogenes thought he had it bad when looking for an honest man. That the U.S. did this is completely despicable and I'm furious at my government--especially, the guy I voted for who ran on a platform of stopping this--for continuing to pull these stunts. I look out over the panoply of countries with "modern, well-formed" legal systems, and I keep seeing the same abuses:
http://news.bbc.co.uk/2/hi/science/nature/2027377.stm - "The [United Kingdom] National Technical Assistance Centre (NTAC) will decrypt computer data and intercepted internet and e-mail traffic as part of a drive against cyber-crime..."
http://www.spiegel.de/international/germany/constitutional-c... - "German Intelligence Under Fire For Spying on Parliamentarians..."
http://www.smh.com.au/technology/technology-news/every-click... - "[The] telephone and internet data of every Australian will be retained for up to two years and intelligence agencies would be given increased access to social media sites such as Facebook and Twitter..."
Plus, if you're a foreigner (e.g. an American using Australian services), what incentive does the "other" country have to care about you? No one has complained, in this whole debate, about one country spying on the citizens of another country. This uproar happened because the U.S. NSA admitted to gathering data on domestic people under the guise of doing "foreign" surveillance.
Maybe I'm just getting too cynical.
I'm expecting something in Europe (ThePirateBay crew seem pretty trustworthy), or some self sufficient island? (New Zealand?)
Being European, I'm looking for services which operate in my home country. I prefer to be spied where I'm a citizen, because US clearly only protects the privacy of its own citizen, and because it is illusional that intelligence services be transparent.
However, there is no such thing as a european company running cloud services for email, rss, file storage and social network: Not even talking about dismissing american-funded strat-ups, all the supposedly European services are run under a .com website, and this extension puts them under american trade and penal laws - We've had this example of a piracy UK website run by UK citizen be trialled in US, where the defendant knew no-one, for the domain was in .com.
Note that I would trust a cloud service registered in my ophome country and in .se, because they have proper forms of government.
Who's up to start such a company? I'd give them big money to keep my records home.
They can extrade the person: "As long as a website's address ends in .com or .net, if it is implicated in the spread of pirated US-made films, TV or other media it is a legitimate target to be closed down or targeted for prosecution"
I wouldn't be surprised of a sweeping European law saying "For the safety of European Intellectual properties, it is forbidden for businesses to store their email in Gmail". The game is to explain the WTO that this is not protectionism, and given the present NSA leaks, it only makes it easier.
They look like they were made with MS Paint. CNET and James Clapper says this is all bullshit.
Maybe we should stop drawing conclusions about a story that is developing and extremely foggy until it clears up a little more?
[0]http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter&#x...;
[1] http://www.huffingtonpost.com/2013/05/14/ryan-fogle-cia_n_32...
Even the issues about the slight differences between WaPo and Guardian variants of the slides are easy to explain with different versions of Microsoft Office (or even using LibreOffice to try to open).
Edit:
I am not arguing that foreigners should receive welfare check and benefit from social programs. I am arguing that if they are targeted by the US government, they should be subjected to the same protection. There should be no special exception for anybody, because the special exception was used to justified the NSA spying program.
I don't mean to agree or disagree (though I am inclined to disagree, I admit, which is why I ask the question). By asking, though, I hope to see the advantages and disadvantages in a real-world situation.
Most things that qualify as precedents are predominantly rulings on genocide, crimes against humanity, extrajudicial executions, war crimes, torture and forced disappearances.
The impact of universal jurisdiction is not simple, in fact it flies in the face of Westphalian soverignty[2] in the sense that it destroys it utterly, potentially disrupting over four centuries of precedent and denying nations' inherent right to self-determination.
Nuremberg essentially applied penalties for rights violations to people of a foreign, sovereign nation.
The proposal in the GP comment is for new rights–not new responsibilities–to be granted to people of a foreign, sovereign nation.
So I appreciate the background you have provided, and I want to springboard from there to draw a distinction, and to see if there is any precedent for something even more similar.
The UN Human Rights Council[1] would probably be the highest authority to appeal to, considering they have enshrined many rights as natural human rights that are inviolable and universally applicable -- for example freedom of association and assembly, freedom of expression, freedom of belief, Women's rights, and so forth. Many nations don't recognize these rights (and quite a few don't recognize the UN's authority) and the UN's ability to enforce respect of these rights is quite non-existent, but it's a good place to start.
[1] http://en.wikipedia.org/wiki/United_Nations_Human_Rights_Cou...
Uhhh no. I pay taxes and uphold my civic responsibilities (jury duty, selective service, etc.).
I earn those rights.
Unless those foreigners decide to become US citizens and take on the same responsibilities, no, those rights do not extend to them.
The same works the other way around.
Wouldn't it make sense to have reciprocity so it ends up being a game of citizen collaboration, rather than of competition (as in many other areas of international diplomacy and law)?
Yes, I'd be perfectly happy with that. In fact, I'd be thrilled to have the same protections when travelling abroad. Unfortunately, most countries don't provide such protections for even their own citizens.
There are many non-racket variants of this, including an actor or famous athlete hiring a bodyguard.
Of course it is not accurate to state that the government is running a protection racket because his initial premise from which that follows is stunningly idiotic in the first place. Rights are not given in return for tax money, not even in America. Non-taxpaying non-citizens enjoy basic protection under the law if they happen to be physically located in America; they don't have to "buy" that.
That "physically located" qualification is what needs to be changed. "They don't pay taxes to us" is not an excuse.
May be other governments in other countries are doing the same, we don't know. If that's the case, this is very depressing - pretty soon, everyone will be spying on everyone else (if that is not already happening), and this wouldn't be a nice way to live
Mostly I avoid the issue by not visiting Weibo, etc., but I realize that's not very helpful for those not in the U.S. since there's really only the one Facebook, Google, etc.
Perhaps this kind of thing would lead to either increased federation of website (e.g. there's be a U.S. Google and a E.U. Google and swapping amongst them would not be completely frictionless).
Either that or reciprocal agreements between different nations to increase the privacy rights of their citizens (in fact I thought these already existed). But I don't see a solution that involves not having all these nations intelligence agencies simply skipping out on the collection of intelligence part.
But with that in mind I'm not sure how much you're really asking to be different.
He who lives by the sword...
Unfortunately, there are people that venerate the constitution that ignore its precursor document which states that we believe all men are created equal.
If all men are created equal, then they should be treated as such, unless we want to repeat the "some are more equal than others" line.
Instead people have replaced that justification with circular justifications, blind patriotism, and apathy.
I think in the sense that the rights are human rights, then all humans should get them. But the civil rights in the US Constitution and amendments are, for the most part, meant to protect citizens from the government becoming too powerful and abusing its power. The framers of the constitution, being in the novel position of actually getting to decide what the powers of their own government were to be, were very fearful that it would be too powerful. A fear soon validated by the French Revolution's problems. (The idea that civil rights are somehow "earned" as mentioned in this comment thread is odd... the rights are not a "reward" to be earned, they were put in place as a precursor to any government: no American starts off without them and you do not need to be a taxpayer or even a citizen to enjoy them, you just need to be in US-ruled territory.)
It does not make sense for anyone not residing in the US to be given freedom of speech or the right to bear arms by the US government. These rights are allowed (or not) by whoever governs the place where you are. If the US government is spying on you on your territory, it is up to your government to protect you. Note how the US government reacts when another country is spying on our citizens (well, corporates anyway.)
The fourth amendment was not put in place because "gentlemen do not read each others' mail" but because the Brits used to bust in with general warrants to try and collect taxes and it pissed off the colonists. It was not the principal of the thing, really, but the consequences that got the colonists' goat. Since the US government can't really do anything to people not within the US except as an act of war, their search of your property--while reprehensible--is not meant to have been protected under the 4th.
It does, unfortunately, make perfect sense for any non-American to want their Internet traffic kept from traversing US soil if by so doing it places that communication under US scrutiny. I suspect it would not be hard to set up routing tables that keeps traffic from entering the US unless that's the destination (but I'm talking out of my armpit, I'm not a network engineer.)
> We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness.--That to secure these rights, Governments are instituted among Men, deriving their just powers from the consent of the governed, --That whenever any Form of Government becomes destructive of these ends, it is the Right of the People to alter or to abolish it, and to institute new Government, laying its foundation on such principles and organizing its powers in such form, as to them shall seem most likely to effect their Safety and Happiness.
All men. Rights endowed by their creator - not the government. The way I read that, regardless of government or location of their birth, the basic rights enumerated in the constitution are the birthright of every single human.
My favorite way to battle the stupid bullshit neocon xenophobia is to leverage their own anti-state agenda (which, to be fair, I generally agree with) against them, by pointing out that the false dichotomy of us/them is based upon them labeling someone as "American"/"foreign", which is in turn based upon whether or not they are born within or without an imaginary line drawn by the state.
PS: inb4 "but slaves are people too"
What Google et al didn't take into account, being very short sighted, is the competitive advantage they lost unprotecting their customers information.
Who's lying?
[1] https://twitter.com/ggreenwald/status/343470800784982016
Ninja edit: Also as another commenter pointed out, that $20-million figure could be for just one specific part of the program or what have you.
In fact I'd argue that Glenn's reputation is based more on being a "civil liberties watchdog" and far far less on actually being right in his reporting. So in that regard he's simply padding his rep even further.
This strikes me as pretty implausible; verifying the extent of their access to someone's gmail or facebook account seems like something the NSA should be able to do very easily. I think it's safe to assume that this part of the project is $20M, not that they have $20M worth of access to the internet.
For example, if PRISM is really just an internal NSA tool for interfacing, searching, storing etc information procured from these providers from different means (such as NSLs or FISA warrants), then obviously no company joined it. It's an internal tool! The idea of 'adding' just becomes ensuring normalization of data and other such 'mundane' things.
Note I say, 'for example'. Because amongst all the yelling about, we still don't actually know what the fuck PRISM actually is, and arguments just revolve around how charitable/cynical you are about the parties involved.
* An interface to fuse data received by court order from each site.
* A scraping tool to pull in open source data, possibly with seed accounts (i.e., a facebook account for each university) to give you better access.
* Scraping data on the wire to and from each service, at the level of the internet backbone
The most likely explanation is that PRISM = FISA. The Washington Post article with the slides begins "Through a top-secret program authorized by federal judges working under the Foreign Intelligence Surveillance Act (FISA)..."
Now imagine how this works in practice. The FBI (not NSA, other articles have stated that the NSA works by handing a request off to the FBI to implement on domestic soil) comes to a tech company with a signed court order to hand over the user data for a user suspected of criminal actions. The tech company complies. The data is normalized and assembled on the NSA end, and then a realtime feed goes to the PRISM GUI where an analyst looks it over. At no point does the government ever reveal the name "PRISM" to the tech company - why would the NSA ever reveal top-secret codenames outside of the organization.
When the program is made public, it's the NSA side of the story that hits the papers. The tech companies have never heard of PRISM, they know that the NSA does not have boxes inside their datacenters, and the whole accusation seems ludicrous.
It's a mistake, when you find out that a secret has been kept from you, to assume that other people know about the secret as well, even if they were involved. The NSA is not in the business of telling businesses about confidential national security projects.
On Thursday, James Clapper, the Director of National Intelligence, wrote "The Guardian and The Washington Post articles refer to collection of communications pursuant to Section 702 of the Foreign Intelligence Surveillance Act. They contain numerous inaccuracies."[1]
Today, he released a fact sheet[2] which stated, among other things,
* PRISM is not an undisclosed collection or data mining program. It is an internal government computer system used to facilitate the government’s statutorily authorized collection of foreign intelligence information from electronic communication service providers under court supervision, as authorized by Section 702 of the Foreign Intelligence Surveillance Act (FISA) (50 U.S.C. § 1881a). This authority was created by the Congress and has been widely known and publicly discussed since its inception in 2008.
* Under Section 702 of FISA, the United States Government does not unilaterally obtain information from the servers of U.S. electronic communication service providers. All such information is obtained with FISA Court approval and with the knowledge of the provider based upon a written directive from the Attorney General and the Director of National Intelligence. In short, Section 702 facilitates the targeted acquisition of foreign intelligence information concerning foreign targets located outside the United States under court oversight. Service providers supply information to the Government when they are lawfully required to do so.
* The Government cannot target anyone under the court-approved procedures for Section 702 collection unless there is an appropriate, and documented, foreign intelligence purpose for the acquisition (such as for the prevention of terrorism, hostile cyber activities, or nuclear proliferation) and the foreign target is reasonably believed to be outside the United States. We cannot target even foreign persons overseas without a valid foreign intelligence purpose.
* In addition, Section 702 cannot be used to intentionally target any U.S. citizen, or any other U.S. person, or to intentionally target any person known to be in the United States. Likewise, Section 702 cannot be used to target a person outside the United States if the purpose is to acquire information from a person inside the United States.
[1] http://www.dni.gov/index.php/newsroom/press-releases/191-pre...
[2] http://www.dni.gov/files/documents/Facts%20on%20the%20Collec...
For other statements from the DNI, see http://www.dni.gov/index.php/newsroom/press-releases
| they need to admit that these reports are true
Assume for a moment that the reports aren't true, or are exaggerated. Are they supposed to lie to you in a way the hurts them just to appease you?The PRISM leak started as this dramatic claim that NSA is hoovering up all of the person data of everyone in the cloud. Now this has been mostly retracted to tech companies sending them data on individual accounts as requested by lawful court order, which is what they've been doing, in public view, unclassified, for years, and admitting it -- that they respond to lawful requests on a case by case basis.
What more do you want? The denials are about as vehement as they can get. The NSA denies the "firehose feed" hypothesis as well.
You see, if you don't stand up, you still get counted. "Little Brother is watching you, too"
Seems like a paradox. Mind blown.
Something about this feels like it carries more weight, probably because it comes from the legal department and not from a CEO.
If you qualify it as "any third party", I really doubt the proscriptions over disclosing specific FISC or NSL orders apply. They do receive orders to turn over information for all sorts of reasons, some of which are totally legitimate.
Unless the number is "100%".
This statement definitely carries much higher conviction language that related statements, interesting to note the absence of Marissa Mayer from the statements. I would guess that it just gives a little more PR distance in case things blow up further.
1) Face Value. Don't look into the wording and just see that so many companies "accused," are not involved.
2) Semantics. Look at the wording for hidden meanings, possibility of a gag order, and these companies are (in reference to this article) involuntarily involved.
I think they are general so the person reading it will take it as they want. I posted a "what will you do now," post on here [0], because that's really what this comes down to. I agree with most that I've ALWAYS assumed we were all monitored, but as I've said many times....it's not what they know, it's what they can prove in court (that's why I'm thankful CISPA got blocked...it was kinda like legalizing what was already going on to be able to use what they know in court).
Like the other official/legal postings so far, the verbiage in this post is carefully crafted to mean the opposite of what it says.
Changing a government will take a lot of time; but a business outside the reach of US legislation could pop up tomorrow.