Rackspace Response to PRISM
community.rackspace.com
community.rackspace.com
If the Govt/NSA wanted access to certain metadata and a company refused (like some claim Twitter did), what's to stop them from going to Amazon or Rackspace and throwing their weight around to get access that way? Or, if that didn't work, they could just keep going up the OSI layers (or tier 1 providers) until they get the access they want OR can force it be threatening to disrupt service.
My point is, even awesome companies like Rackspace are dependent on less-than-awesome companies for some types of infrastructure.
Any company that doesn't comply and hand the data by API will have it's links scraped. Sure it's more costly. That's why they go through the arm twisting.
Regardless of my earlier posts, I'm actually inclined to believe these service providers.
I'm curious, has anyone seen/heard anything from CA's? I imagine it would be much easier to just create a split network route at the ISP layer and decrypt all traffic.
Wouldn't be that crazy if you had all of the root keys.
All the CA does is cryptographically certify "this is the public key that the Company (eg. Google) gave me"; they never see the corresponding private key.
Cooperation from the CA might give the NSA their own certificates for Google, which would allow for an active man-in-the-middle attack. Certificate pinning would defeat that, and doing that on the fly in the Internet at large would be a serious undertaking.
But if they want to decrypt traffic passively and they don't know about serious SSL vulnerabilities, they would have to have Google's private key. And with Perfect Forward Secrecy, even that is not sufficient. (PFS requires an active attack because the session key can only be determined if you're actually one of the two doing the handshake, or you know how to factor very large numbers.)
Furthermore, this would be easily reproducible evidence that they are actively intercepting (and proxying) traffic. Never happen.
Actually, it's quite common for CAs to do the site admins a favor and generate the keypair for them. The admin then downloads the private key and installs it on his server.
On TLS connections where the client and server do not negotiate the use of Ephemeral Diffie-Hellman (EC)DHE (sometimes called EDH), then the CA could have retained the private key data which could be used to decrypt the packet capture after-the-fact.
Google should be applauded for configuring their servers to prefer (EC)DHE on their TLS services. It also means they can fight a law enforcement subpoena for their private key.
The social media company presumably-NSA-supplied denial script says "no direct access to servers".[1] I wonder just how few bits of networking gear (or switch OSs) you'd need to root - gear that sits between the SSL termination and the servers - to not even need to ask for "direct access"?
[1] In fairness - perhaps that turn-of-phrase only appeared in every CEO denial because it was a direct quite from the WaPo article.
How about a blanket FISA order?
"We have never been served with a blanket warrant, or anything close to it, that requires us to give data owned by multiple customers."
Those are the words that need to be examined for loopholes.
Nothing stopping NSA from splitting their transit fibers on the (3), Telia, and Qwest sides though.
What's going to be really interesting is how PRISM integrates with AWS, once some brave Amazon soul decides to self-immolate for our own intellectual curiosity.
See, that's part of the problem in terms of economic calculation when dealing with a surveillance society -> since it's largely impossible to quantify the amount of lost business due to various surveillance / justice actions, as the methods and individual events in which such actions took place may never see the light of day, a society could be going bankrupt due to an overly large security division, and never know it.
Let's consider a real-life plausible scenario: a DEA agent gets a tip from a questionable source about a large shipment of Molly coming in tonight on the docks (cliche, but let's roll with it). The information isn't good enough to get a warrant, but the DEA hasn't had a bust in a while, and the agents are being pressured to find something to justify their jobs. This DEA agent figures that it wouldn't hurt to have a look around (nothing illegal there, right?), and spotting nothing immediately out on the docks, begins to think that it's a bust. The agent notices that an upper window is open on one of the warehouses, and that there are voices being heard within; it would take a little effort, shimmying up the side, but the agent could peak through the window (questionable)...and maybe even climb inside if the agent sees something. The agent climbs up, and hears rising voices from within. Not seeing anyone, the agent climbs in.
The agent, walking on top of some crates, sees the owners of the voices, and after listening for several moments, realizes that it's just a typical worker's spat. The agent goes to leave, not seeing anything of interest...but as the agent moves, one of the crates topples, pushing the one in front of it, and so on in a domino fashion. The agent manages to leave undiscovered, but not before $30 million in Lowe's Italian Chandeliers are dropped three stories onto a hard concrete floor.
The workers will be blamed for not stacking the crates correctly, and the owner of the warehouse cited. The insurance company will, of course, cover the costs of the damaged merchandise. However, the cost to society, for this overstep, was more than a minor civil rights violation...it was more than those workers make in a decade, possibly their lives.
And that's kind of at the heart of these infringements...when the intelligence agencies screw up, when the police screw up, it's not like they're shouldered with that debt; it's charged to society as the cost of doing business...no different from what the bankers did recently when they 'privatized the gains, and socialized the losses.'
HBGary's leak included a subcontract involving development of a USB kernel driver exploit to inject a rootkit into kernel memory. Just saying ;)
Not to engage in the spergy one-upmanship that usually happens now, but one of the best hackers I know got me building kernels without loadable module support of any kind in the 90s after demoing a similar attack. I build my colo machine kernels without most hardware drivers outside of disk and ethernet. (n.b. that you must also patch to deny writes to /dev/mem and /dev/kmem (even for uid0), as you can use these to insert code into a running kernel even without module support.)
There are ways to resist, still.
See: http://www.cisco.com/en/US/docs/routers/7600/ios/12.2SR/conf...
and: http://en.wikipedia.org/wiki/Communications_Assistance_for_L...
So how are we to interpret
"Based on our interpretation of the Fourth Amendment and ECPA, we are of the view that Rackspace is prohibited from accessing and turning over customer data stored on a customer’s server or other storage device in a U.S. data center without a properly issued, lawful request ( e.g. search warrants, court orders, Foreign Intelligence Surveillance Orders) from a U.S. court with appropriate jurisdiction over Rackspace and the data sought."
? Coming right after the recitation of the Fourth Amendment, this gives the impression that Rackspace will only hand out your data in response to a warrant (or warrant-like-thing) that demonstrates probable cause. But in fact, when the customer is a non-resident alien, the order is a FISA 702 order, and the court is the FISC, probable cause never comes into it: the US can (completely properly and lawfully!) get such an order for no stated reason at all. Imagine the following conversation in 1860:
Q: I hear that you have slaves on your Virginia cotton plantation. Is this really true?
A: The Fifth Amendment to the US Constitution states that 'No person shall [...] be deprived of life, liberty, or property, without due process of law'. No-one is forcibly detained on this plantation except fully in accordance with the law and the Fifth Amendment.
This answer seeks to suggest that the only prisoners on the plantation are convicted criminals, which is false - the plantation is worked by slaves. But in fact the answer is precisely true though devious: slaves have no rights under the law, while the Fifth Amendment does not apply to slaves. I really hope this isn't the correct way to interpret Rackspace's statement as well.
And further - it's not just "US-based cloud", it's almost certainly "cloud resources physically based _anywhere_ if it's owned/operated by a US based company". I'm pretty sure Rackspace[1] would consider any data that I (a non-US resident/citizen) store on a Rackspace instance intentionally provisioned in their Sydney Australia datacenter to be subject to US law instead of local Australian law[2] - and would most likely hand over any and all of my data with no need for a warrant.
[1] for completeness/fairness, I'm pretty sure Amazon would treat and Sydney AZ instances I spin up exactly the same way. [2] actually, I suspect I'd get the worst-case scenario of the least protection available under either US or Australian law - if push ever came to shove...
Totally. These points completely nail it for me (A non-US consumer of US based services).
Anyone who was concerned about "the subpoena risk" [1] before, but was satisfied if their data resides in (eg) Australian data centres will now be forced to think again.
I see this as a huge opportunity for non-US domestic PAAS / IAAS providers who keep everything in a single juristiction.
[1] http://www.cisco.com/web/about/doing_business/legal/privacy_...
When you see just how far the New Zealand law enforcement rolled over and violated national law at the request of US copyright enforcement in their shoddily executed raid on Kim Dot Com, I have very little doubt that in spite of Ninefold's marketing using legal jurisdiction nightmares if you use their major competitors AWS or Rackspace - if the NSA showed up even without local law enforcement on their side, me and my data would likley get "thrown under the bus" (especially in the light of stories like this: https://mailman.stanford.edu/pipermail/liberationtech/2013-J... )
Something needs to change. What do you think are the chances of Senator Scott Ludlum's "Get a Warrant" bill [1] making it through before the election?
[1] http://www.guardian.co.uk/world/2013/jun/11/greens-warrant-p...
If some nation can step up and provide some guarantee that your data is not subject to law enforcement without rigorousness due process, they might be able to attract substantial investment.
So for my personal situation - there are two juridictions I have citizenship in (Australia and The UK), neither of which I have much confidence in the amount of resistance they'd provide at a policy or law enforcement level to requests for my personal data from US agencies - and both places where I suspect that companies capable of storing data for me reliably and availably enough probably all have enough of a US presence that they'd be easily "leaned on" by agencies as powerful as the NSA (and probably even the MPAA) in such a way that it'd be "the right thing for them to do" to give up my data rather than incur the costs to the company of fighting.
My current "solution" is increase my (and as many people as I work and communicate with as possible) use of encryption (and hope that as well as "not doing anything wrong, so I've got nothing to fear", that things like AES & PBKDF2 with strong passphrases and tools like EncFS, TrueCrypt, 1Password, OpenSSL are still viable options even against the NSA).
I m not saying PRISM is lawful (that remains to be seen?), but i think many non-US citizens are feeling too entitled to the protection of US law.
What you have to realize is that 4th Amendment law is largely tied to searches for prosecution reasons and so usually the issue is "well, the 4th Amendment is violated and so to punish the government and give them the right incentives, we won't let them use the following set of evidence in their prosecution." It's really hard to make such rules effective regarding surveillance of foreigners conducted overseas.
Non-citizens in the US for whatever reason do have relevant liberties. This does not extend to say buying tv advertisements for candidates in elections, but it does extend to unreasonable searches and seizures. Non-citizens with no real ties to the US, and not in the US are different.
But their US property is still protected. If I'm a Russian orthodontist in Minsk and I buy 500 shares of Google, the Fifth Amendment protects me having them expropriated by the US government even if I never go near the States. (IANAL, but I did check this one.) However if I open a Google Mail account then apparently (under current interpretations) I have no similar protections.
I can't say if this apparent discrepancy is actually legally justified, or not. Without even getting into the question of whether it's morally justified, it is going to come as a significant surprise to a lot of people, who have got used to the idea that they're largely protected by the US rule of law when they do business with the US. And one way or the other, it's reasonable to point out that Rackspace's Fourth Amendment-based reassurances seem to be (no doubt accidentally) crucially misleading to many or most of its customers.
It's seems stupid that given recent events that the uproar over whether the US government is reading your Facebook posts has rammed the point home to many people but I guess this is just the final prod that woke a lot of people up.
*Purely from the perspective of the government. I've nothing but admiration (mostly) for large parts of the culture, attitude and hard work of the good citizens of the 50 states.
There have been at least four or five major epochs for the US, which saw fairly substantial changes (good or bad) to the rule of law and social cohesion. We started as a constitutional republic and nearly laissez-faire capitalism; then we had a massive federal explosion post civil war, that saw the power of the states greatly diminished; we shifted to a mixed economy, welfare state with a heavy bent toward democracy; now we're speeding toward police state socialism with oligarchs, the facade of property rights, and blended government-corporations, aka fascism (or as some call it in our incarnation, corporatism).
The question of whether to migrate to other cloud services, or to host my own private cloud is up in the air.
If you read these (I noted them in order from most recent to oldest) and read/carefully count votes on concurring and dissenting opinions (after having read Smith v. Maryland), I think you could be pardoned for thinking the Supreme Court had said a bunch of things about this, much in conflict with a bunch of other things.
I don't give a fuck what SCOTUS said in 1979. They could have gotten it wrong. Their interpretation could disagree with a plain reading of the Constitution, or they could have based their decision on inaccurate or incomplete data. Even if neither of those things are true, times have changed; issues at hand are wildly different than would ever have been conceivable in 1979.
Going "SHUT UP, SCOTUS DECIDED THIS ALREADY" does nothing for the discussion, and it comes out every single time there's an ECPA or 4th Amendment thread.
I responded to one point in the Rackspace response I thought was a bit off-base, specifically that their general counsel thinks the fourth amendment applies to them ... "Based on our interpretation of the Fourth Amendment ". It does not.
You may not give a * about what the SCOTUS decided in 1979 but the SCOTUS does, it is called legal precedent.
Times may have changed, but Smith v Maryland is still controlling law.
Please try to be more civil.
So I am questioning as to whether Smith controls the Verizon order as it is. I am not sure a simple "yes" is possible.
Precedence can be handled a few ways:
1. They can be narrowed. "Gathering data from all customers regarding where and where they called from and who they called is fundamentally different under the 4th Amendment than what was decided under Smith."
2. They can be expanded, "Cell site location information is no different than what a pen register collects under the Constitution."
3. They can be overruled by the Supreme Court ("We hold we were wrong when we decided Smith v. Maryland.") This is the last choice for obvious practical reasons, and it involves more scrutiny.
I don't think this will cause the third party doctrine to be reconsidered as it was decided in the past (in the context of narrow investigations). I think it is far more likely that courts (from circuit courts to the Supreme Court) will merely hold that it is Constitutionally different to do this to everyone without individualized suspicion than to do it to a specific individual already under investigation, just as it would be Constitutionally different to issue a search warrant for all apartments in a high-rise apartment building than it is to issue a search warrant on an individual's home. I don't think California Bankers Association will be overruled either and if they feel compelled to differentiate, they may say that rules do not require routine disclosure of all financial records, only the few big ones.
With that out of the way, the best discussion of this topic and all the nuances that I've found is a "debate" between two law professors on the initial issue I raised: the third party doctrine.
http://www.abajournal.com/magazine/article/the_data_question...
Like you, they argue what they think the law should be. In contrast, I'm stating simply what it is.
I stand by my original assertion that Rackspace is not bound by the fourth amendment. This may be a technical point but an important one. Shaky though Smith v. Maryland may be, it remains the law of the land. Users have no "reasonable expectation of privacy" in data they store on Rackspace servers.
Again, thanks for your comments.
However I am not certain that this is the only way to look at the existing precedents. If you look at Rhenquist's majority opinion in Knotts, for example, he is quite clear that whether widescale tracking is under the same rules is not a question the court was deciding. Knotts is important for the Verizon order because I think one can argue that beeper cases are closer to cell site location information (also disclosed under the Verizon order) than they are to pen registers.
Since Knotts leaves explicitly open the question of whether widespread location tracking is under different rules, I think it is premature to just say that Smith and California Bankers Association control on their face. Additionally it is anything but clear what the Supreme Court said about this in Jones v. United States because it isn't clear how to count the votes. I would argue that Sotomayor and Alito do not control, but the fact that you have 5 justices clearly edgy about such things in their separate opinions (Alito concurring in judgement joined by Breyer, Ginsberg, and Kagan, Sotomayor concurring with Scalia but endorsing Alito's views).
If I had to say what the law is in this case I would say this:
The law is currently unclear. There is, however, a bunch of Supreme Court opinion which seems to give permission to circuit courts to figure this issue out.
Edit: I would also like to point out that the third circuit has held that historical cell site location information is at least potentially protected under the 4th Amendment, and that magistrates have the power to deny ordering disclosure of such on the basis of such 4th Amendment concerns. I don't think the Third Circuit could do this if it was clearly established that these third party business records were outside the purview of the 4th Amendment.
1. The information was willingly shared with a third party.
2. The individual relied on the sharing for many other services including being able to trace harassing phone calls, and the like, and
3. The information was not deeply revealing.
The much more important case regarding 3rd Party Doctrine is California Bankers Association v. Shultz (1974), which established that there is no reasonable expectation to privacy in routine surveillance of bank records of transactions above a certain amount (set at $10k under the statute then as now). The thing is that the dissent was worried specifically about dragnet surveillance and the majority more or less swept that one under the rug.
However, this is not the 1970's any more and there are reasons to think the dragnet surveillance concerns that were ignored in 1974 carry more weight today. In 1983, the Supreme Court, in United States v. Knotts included clear dicta differentiating the case of following a car with a beeper installed in something that was sold with suspicion that it would be used illegally, from the dragnet surveillance case. Rhenquist, writing for the majority, said:
But the fact is that the "reality hardly suggests
abuse," Zurcher v. Stanford [460 U.S. 276, 284] Daily,
436 U.S. 547, 566 (1978); if such dragnet-type law
enforcement practices as respondent envisions should
eventually occur, there will be time enough then to
determine whether different constitutional principles
may be applicable.
The court further narrowed beeper tracking in Karo v. United States to hold it was a search when law enforcement officers determined that a barrel of ether (suspected of being used in making of narcotics) was traced to someone's home. Given that even without GPS, our cell phones are effectively beepers have lead some courts to start pushing back on subpoenas for historical cell site location data.More recently, you have the 5 concurring justices in Antoine Jones v. United States, opining that long-term surveillance by virtue of time and amount of data collected may well violate the 4th Amendment even if individual pieces may not. I say "opining" rather than "ruling" because Sotomayor refused to rule on that ground, but instead chose Scalia's more narrow rule, while at the same time endorsing Alito's much broader rule. While not the "Opinion of the Court" it is still "an opinion of the majority of the court" and I think this has a certain amount of force on courts below.
We must be confronted that we are at a point where Rhenquist's insistence that dragnet surveillance must be considered separately now mandates that we confront that. A clear majority on the Supreme Court seems to believe that this can violate the Constitution with the other four justices merely having declined to comment on it.
I hope this clarifies both what the court said and what confusions there currently are as this area develops. No I am not a lawyer but I read Supreme Court cases for fun.
They'd still do it today, IMO:
> we are of the view that Rackspace is prohibited from accessing and turning over customer data stored on a customer’s server or other storage device in a U.S. data center without a properly issued, lawful request ( e.g. search warrants, court orders, Foreign Intelligence Surveillance Orders)
> without a properly issued, lawful request
> lawful request
When you write the laws, anything is lawful.
Their training and expertise ranges from glorified security guards to para-military.
[1] http://en.wikipedia.org/wiki/Federal_law_enforcement_in_the_...
---
vertis 29 minutes ago I am an Australian (i.e. Non-US-Resident Non-US-Citizen). While I have nothing of particular interest on my servers, the revelations of the last week have concerned me for multiple reasons.
The Guardian story about the PRISM program suggests there is extensive surveillance and interception of foreign citizens' data without a court order. Do I need to move my servers to a provider that is based in a country that respects my rights to not be surveilled?
lmatos 18 minutes ago Hello,
As an American citizen, I completely understand. With that said, we have to comply with all US law as we are a US based company.
If there is anything else that we can do to help, please do not hesitate to ask.
Regards, Lee M
Rackspace buys service from somewhere. Those fibers are suspect.
There was a fight (which was won) to get the gag-order provisions of PATRIOT NSLs lifted, at least for speaking to one's own lawyer, which is a protected right (spouses and coworkers are still out, tho). Who knows if those rights extend to FISA orders, though we've seen how they interpret other constitutionally protected rights.
It's not their fault that they don't want jail time. Blame your government. Support courageous people like Snowden. Tell your friends.
Although then again they could stick a physical intercept in a box.