Asking the U.S. to allow Google to publish more national security request data
googleblog.blogspot.com
googleblog.blogspot.com
I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroad, and lose a ton of business and customers, both small and major.
Maybe then they'll start doing some real lobbying to the government to end the madness, and maybe the government will stop thinking all the spying is worth breaking all international relationships and hurting the US economy in the process.
Until that happens, if Google cares that much about encryption and their users' privacy, they should show me they are willing to implement OTR, ZRTP and PGP in their services. The same goes for Microsoft and Facebook. Otherwise, this press release means nothing except for showing that "they are doing something".
Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.
A non-google-trusting way to do PGP with a better UI/UX would also be a nice feature for gmail. Just indicating "encrypted" at the message-list view or something. I have PGP working quite nicely in mutt, but a lot of people seem to prefer webmail.
2. I'd actually prefer a world where signals intelligence, outside extremely tactical intelligence, were impossible through technical means. I think we'll be there at some point, just because the cost of protection is dropping.
(confidentiality and message integrity should be feasible for any reasonable government defender at this point. traffic analysis/direction finding/etc. burns bandwidth and latency budgets, so that might be harder, but you can do arbitrarily well.)
The US (government and citizens/private industry) probably has more to gain from universally strong COMSEC vs. effective USG SIGINT.
We're doing a pretty good job on mobile of "centralized trust", and also sort of with cloud infrastructure, if not apps.
At least, we'll have secure infrastructure on which people can continue writing insecure applications by 2020-2025. The "people writing insecure applications" won't stop until people stop writing applications, hopefully replaced by non-humans writing applications, maybe in 2050+.
And as you mention, you would still have to trust Google.
I'm not talking about giving the real PGP or S/MIME to Google; just a UI flag saying "this message has special content, click here to download". And some kind of low-assurance S/MIME signature which just says "was downloaded from gmail" to protect from local modification. I'm not sure how mail clients deal with multiple s/mime signatures (or s/mime + PGP inside).
IMAP is already TLS encrypted.
The biggest missing puzzle piece is making it simpler for people to get S/MIME set up (or PGP for that matter), and having it work with all major mail clients (yes, Mail.app is a major mail client).
Right now S/MIME still requires too many steps to get the lay person to set it up, same with PGP, we need something that is secure from the get-go with very minimal effort required on the users part.
The downside is that S/MIME and PGP don't really fit into the online world, no longer will it be simple to open the browser and go look at your email, you will be required to have your keys with you. Securing those keys becomes the second problem, one that has partially been solved with smart cards and other devices that will do signing/encrypting/decrypting on the card without giving up the private key... but loss is still an issue so key escrow becomes a big thing.
It is an interesting problem, with interesting challenges and I look forward to seeing how we as a group of technologists solve them. Once it becomes easy enough for grandma and grandpa to use secure encrypted communication it will become much harder to do wide-scale snooping on data.
Also, the fellow you replied to didn't specify what sort of spying needs to be stopped. He could have no issue with foreign signals intelligence (which presumably means spying on non-US folks).
(Even worse, as the transport security part gets better, you either need to add a bunch of active-attacker MITM or somehow compromise endpoints. At some point, even if you thought purely passive SIGINT collection was fine, the level of prior restraint on service providers/developers becomes absurd and probably no one would support it; witness the key escrow crypto wars of the 1990s.)
Generally NSA seems to put a good amount of effort into minimization post-collection. But, that only works if you trust them to be 1) forever competent and 2) forever equally ethical.
In any case, the argument isn't that webmail is perfect for implementing PGP. The argument is that
1) no one uses PGP now because no on else uses PGP
2) if webmail providers deployed PGP, everyone would be using PGP
3) some use of PGP is better than no use of PGP
It really seems like some people are cutting off their PGP noses to spite their PGP faces. I remember when the assumption with vegetarianism was that you were either a vegetarian (and never ate meat) or you were a meat eater (and ate meat regularly). So people kept eating meat regularly because they "couldn't give up meat", thus believing in a false choice. If vegetarians had been pragmatic, they'd have realized that would have been much easier, and would save more animals, if you convinced 95% of people to give up meat 95% of the time.
Dear privacy advocates: stop wanting everything yesterday, because it's keeping you from getting something tomorrow. Most change takes place gradually. Webmail providers deploying PGP will instantly create millions of PGP users, which will at the very least serve a valuable educational and awareness purpose. These users will gradually become more concerned with the implementation details, triggering a gradual increase in overall privacy and security.
This phrasing seems to suggest that the intended target of FISA 702 - the US cloud data of non-US-resident non-US-citizens - enjoys Fourth Amendment-based protections, such as the probable cause requirement, under FISA 702. But in fact it seems that (IANAL) FISA 702 is compatible with the Fourth Amendment (if it is) only in the sense that slavery was compatible with the Fifth Amendment: simply because the Fifth Amendment does not apply to slaves. If 702 envisaged non-resident aliens' US cloud data as being protected by the Fourth Amendment then it would presumably require the US government to establish probable cause at the FISC (or some other court). But in fact 702 doesn't seem to require the government to claim any kind of cause or suspicion or even state any purpose or motivation for the search to the FISC. The FISA 702 PowerPoints obtained by the ACLU under FOI make it clear that the US government understands FISA 702 as removing the probable cause requirement http://www.aclu.org/files/pdfs/natsec/faafoia20101129/FAAFBI... .
That would only make sense if they wouldn't be required to become your key escrow service (=custodians of your private keys). PGP is also a pretty bad choice for private communication, as it offers no forward-secrecy. Something like client-side OTR implementation would be better.
The NSA just killed the goose that lays the golden egg and not much is going change that.
"Germany's interior minister said that politicians and senior civil servants in government should avoid mobile devices such as the iPhone and the Blackberry, citing security risks and increasing hacker attacks. (...) ministers and senior civil servants have been told to rely on the German-made Simko2 gadgets, on advice from the German federal office for information security (BSI)."
Corporations that have a vested interest in providing security (or the illusion thereof) may reconsider cloud-hosted solutions. But that's probably a relatively small market.
I'd really enjoy hearing Thiel's perspective on this whole issue given that he is a libertarian with a strong business relationship with the NSA and a strong business relationship with facebook.
This leaves a lot of space for speculation, how can somebody possibly know if they didn't request a bulk copy of all Facebook data? Or issue a billion seperate requests when by law nobody can talk about the count and scope of those requests. If I were a journalist, the first thing I would question is if they did exactly this, because they wrote a law that allows exactly this type of behaviour.
I'm sorry, are we now taking the opportunity to blame big evil government for this?
The mistrust of this industry has always existed as a completely separate issue due to the utter lack of respect for privacy and privacy related laws, an attitude of which Google is one the most prominent exponents. This is a company that lobbies governments against privacy protection.
An industry that has for years tried to convince the public that surrendering your privacy to them for profit is perfectly okay has zero credibility in this matter.
*I'm using voluntary here in the most straightforward sense possible. You can switch services if you'd like, or even turn off ad targeting for most services. You cannot, however, go to a an nsa.gov link and click the "Please don't track me" box.
We're living in crazy-town, maybe we always were. What is to stop the A.G. from publicly saying "Yes, disclose away!" and then to privately send one of those magic-do-anything-we-say requests saying, "Don't disclose X, Y, and Z."? Or if we are given an accurate count today, what is to prevent the government from in the future secretly retracting that privilege?
I think in the end we can be satisfied by nothing less than some sort of "Too Many Secrets" Constitutional Amendment, stating clearly that no private citizen can be required or compelled to partake in a "National Security" cover-up, so that everyone currently bound up in the web of lies could speak up without fear of persecution.
That is what galls me as much as anything. If the government wants to gather data and keep secrets, let them gather and keep them themselves. Drafting people against their will into compulsory service in signals-intelligence, forcing them to lie to their loved ones and the world, and persecuting them for honesty, is absolutely amoral.
Which is not to say Google or anyone else is lying about the nature or the scope or anything else about the requests they have received. But the problem is that we can't ever know one way or the other, because we have apparently created a system of secrecy and dishonesty. Once you know someone (in this case, the intelligence community, and those they compel) has a history of lying to you, how do you move past that back into a state of trust?
EDIT: well, technically it says not to 'bear false witness against thy neighbor', but it certainly would not be hard to justify a religious objection to that requirement.
Again, i have seen this in argument after argument. Nobody has yet provided any legal authority that states it is constitutional or legal for the government to compel forced lies. They can compel silence, for sure.
There is plenty of authority in other contexts (IE not national security), that the government cannot compel you to speak misleading or non-truthful information.
I wish this idea that everyone must be lying because the government can legally, force them to, would stop.
I imagine someone started with the NSL gag orders, which compel silence, and then just started saying they compel you to lie instead (which they don't).
In fact, even the compel silence part of the NSL was found unconstitutional.
And don't bother trying to work out how the law allows this, we're not even allowed to know what some of the laws even are.
What laws do you think you can't know of, exactly?
If this whole debacle sets up an epic confrontation between Google and the DoJ, I may have to reevaluate how irritated I am at how "Prism" has been reported. More Greenwald agita! Let's see if we can pick a fight!
1. I am very irritated at inaccurate and sensationalized reporting.
2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens.
3. I think leaking details of signals intelligence programs should be a crime.
4. I hope Google picks a giant fight with the DoJ and wins it.
I think there's a world of difference between Bradley Manning and Edward Snowden. And while I think Manning's treatment has been harsh, I do think he should be prosecuted because he was reckless and untargeted. Snowden clearly has a much more focused goal and surgical approach.
This one surprised me. Wouldn't the strongest signals intelligence program be one that doesn't need to depend on obfuscation?
I would think that one of the main points of signals intelligence and their efficacy is if the emitter is not aware that you are collecting their signal.
I think dealing in absolutes, anywhere, should be a crime.
Leaking should get you fired, of course. Realistically, it will and you'll be blackballed from working in security forever. I think that's more than enough incentive not to leak unless there is real abuse going on.
I have two ideas that are just as well supported by the complete lack of facts that we all have.
First, that Google is setting us up to believe a half-truth related to FISA letter counts. There are such numbers, we will get them, and they will not include all surveillance conducted with Google's data but anyone who says that will be back to being a crank.
Second, that Google perceives an existential threat to their company along two related but separate axis. The first is that their customers will leave, but that is less likely than the second. The second is that their best employees will leave. Googlers will not want to consider themselves as clerks in the Ministry of Truth. If they and their peers began to think about it in that way, then they will leave and the business will eventually die. If their employees have a credible excuse to think of their employer as a noble crusader, then this threat is significantly mitigated.
What does "unfettered access" mean? What are "valid legal requests"?
While there is an implication of spirit in their words, I know deep down that everyone involved is focused on the letter of their words.
This has nothing to do with my personal trust and confidence in Google, but in my trust and confidence in this entire charade. Google is part of it, whether they're on the right side or not. I simply cannot tell.
At least they mention in one sentence "the number of FISA national security requests that Google receives, as well as the number of accounts covered by those requests" which is already much more useful information than only the "number of requests." We saw that in Verizon case one single request was enough to mean "give me all about everything from everybody."
p.s. I'm taking google at their word -- that they are not giving 'direct access' to the NSA. I am assuming they know, that the truth could leak out at some point, where they to lie about it.
Edit: Or is this also including requests for users in other countries? Sorry, English is not my mother tongue, so I might got it wrong.
They also publish non-us government requests as well.
So they release an "open" letter trying to redirect the masses attention, and I'm not a little shocked it's working. People are actually praising Google? WTH? If Google really cared this letter is like 5 years too late doncha think? Google cares about one thing! That they got caught not giving a crap about the privacy/rights of their customers.
News Flash, they still don't give a crap. But hey, if losing gmail, google+, picasa, blogspot, drive etc. would just cause your world to fall apart, then keep using it and just be honest that you don't give a crap about your privacy or rights any more than Google does.
You should read the news occasionally. Google has been publishing a Transparency Report since 2010, and has been expanding it since then. Not quite 5 years, but more than long enough to render your comment paranoid nonsense.
This sort of response from Tech companies is just a distraction from the real issue.
That is the entire story in this case, direct access to the servers.
No it isn't.
For most SSL certs this is probably true, but Google uses perfect forward secrecy which makes this very unlikely if not damn near impossible: http://googleonlinesecurity.blogspot.com/2011/11/protecting-...
> It is a low view of the NSA to think that they do not
> have the ability to real-time decrypt SSL certs from
> every major SSL cert authority.
The technology required to break SSL is sufficiently advanced that any organization possessing it would probably have easier ways to collect data, all of which would grossly outmatch all known security precautions. There would be no need for any of these sneaking-around stuff because breaking SSL is an instant win condition.How much work do you, personally, put into making money? At least 40 hours a week, I'm guessing, plus the time you spend on managing your investments, doing your taxes, and so on? How much work do you put into maintaining your own privacy? Is it even 1 hour per week, on average? Really?
Note that Google has, allegedly, already put a LOT of work into pushing back on ensuring that due process is followed. Many engineers, many lawyers, lots of executive-decision-effort.
Maybe you don't believe anything Drummond or Page say? Maybe you think google.com/transparencyreport is purely fabricated? Maybe you think Google should violate the law and get shut down (that's what you said, actually, with "evade the letter of the law", but I find that position so laughable that I assume I misunderstood you)? Maybe you yourself actually DO spend the same time on privacy that you spend on pecuniary gain, or maybe you expect Google to hew to a higher standard than you yourself do?
For me, I don't believe there is even a piece wise approximation between time investment and privacy value because the tools are so much different and the available actions being constrained. To illustrate where I get hung up on that reasoning, if you build a phishing page setup and contract a botnet to spam few hundred million people with phone phish-spam, you might get a lot of "income" for a relatively small time investment, similarly you can get greatly increase your privacy by investing in forged identity documents. So at the least we would have to constrain the hours invested in legitimate ways to enhance ones privacy and legitimate ways to enhance one's income.
Next there is an issue of facilitating the effort, so when company A sells me raw materials at a modest markup they facilitate my ability to make a living using them to provide said raw materials.If instead they were to charge an extortionate mark up, I might still be able to make a living but I might find the effort to do so requiring many many more hours of time investment. So at what point do the actions of my raw materials supplier work for or against my efforts at generating income. Similarly the provider of my tools can make it easier or less easy for me to maintain my privacy, so for example a Google Drive plugin which let me keep everything on their servers encrypted. If Google provides that then its a small number of hours invested to enhance my privacy, but if I have to rely on a third party who is acting without support from Google, then it takes many more hours for the same level of enhancement.
Given these built in and essentially intractable forces which affect the efficiency of hours invested needed to achieve the desired result, I am not persuaded by your claim that I can evaluate the 'worth' of privacy using your proposed reasoning.
Google can, and apparently does, to things like warrant notices where if you are suddenly asked to reconfirm your acceptance of their terms of service it's a signal that a warrant was served to them that they had to turn over your data. I think these sorts of things help them in the eyes of their users and are not illegal. They meet the letter of the law and so are not actionable, just as their transferring of rights around amongst their national subsidiaries is a completely legal way of not paying more tax.
My call to action was to try to think of ways that would make things like the PRISM data not useful to the NSA and yet meet their obligations under the law. I mentioned one (in cloud encryption with client side decryption) but I am sure there are others.
And I am _highly_ skeptical about this "reconfirm your TOS, as a hint that there's an NSL on you". (I have no inside knowledge of this, and if I did I would lie to you about it.) But if any engineer did that, and got caught, they'd go to jail. Given that 99.9% of users who're NSLed will not have read that blogpost (the crazy tinfoil-hat wild-speculation one that started this rumour), what would be the benefit? No benefit, but one conscientious engineer goes to jail. Yay.
Law, in general, is just as concerned with the spirit of the law as the letter.
My whole reply is that Google is already working harder on privacy, as a fraction of total resources, than nearly anyone you've ever met, and certainly more than nearly any corporation. (Unless Google is lying about basically everything, which I can't/won't prove they/we are not). Your expectations, as originally stated, are unreasonable.
Disclaimer: And yes, I have a vested interest. Hopefully my argument stands on its own merits. Your call to action is insulting.
I am sure that Google is a much different place than when I left it, hell it was different between the time I joined and left. That said ...
The comparison I was trying to make, and I grant you that it is imperfect, is that Google, like Apple, has billions of dollars in free cash flow and in legal testimony lately they have shown great creativity in ways to shuffle that cash around so as to avoid being required to hand it over to various revenue agencies. Google is also has billions of data points about all of the individuals that use its services. If those data points were dollars, and the revenue agencies were intelligence agencies, what creative ways might they come up with to disassociate which data point belongs to which user such that they could still use the data but not be compelled to hand it over. Just like they use those free cash dollars rather than hand some percentage over as tax.
I've got nothing but respect for the smart people at Google, and still have friends that work there (and folks who used to work here and are now working there :-). Perhaps I'm misreading your tone but it sounds like you want to pick a fight.
An API may serve millions of requests per day and return single-integer responses, or it might serve one batch query per day and provide a nested document with many sub-sections.
Let's try and keep the speculation to a minimum.
2013-07-12
Foreign National
Drug Related - Cocaine
2013-07-18
US Citizen
Drug Related - Marijuana
Request from FBI
2013-07-22
Foreign National
Terrorism Related
2013-08-01
Foreign National
Industrial Espionage
I think it's really important that we know how many of the requests have to do with the existential threat of terrorism, since that is the example the administration and Congress keep using to justify these actions.The more metadata the better. If they want our metadata, it's only fair that we get their metadata too, to be able to keep tabs on their actions.
I would love it if Chrome came with a GPG chrome extension that worked with Yahoo Mail, Gmail and other popular webmail clients right out of the box. Mozilla should also have a plugin that comes preinstalled for this.
The limiting factor in adopting end-to-end encryption in email is network effects. Preinstalling GPG support in browsers is half the battle.
Secret partnerships with government agencies is detrimental to free market capitalism and goes against the true spirit of entrepreneurship.
You have the encryption key, the data on our servers is completely useless without that encryption key. We are physically unable to be compelled to comply with any orders to violate your privacy from anyone.
The only example of a cloud service I can think of that matches this off the top of my head is spideroak and tarsnap, perhaps also the new torrent sync? I'm not entirely certain how that works but I do recall a client side crypto key being involved in there somewhere?
The problem is, if the data is opaque to the cloud service, it is very hard for it to do anything other than passively store and retrieve it, at which point it is not really a cloud service at all.
And even then: they can give logs to authorities showing what you accessed when and from where, they probably know your credit card and billing details.
However, you do bring up an interesting point, it is indeed harder to do "useful stuff" when the store is untrusted and has no idea what it's holding, string searches et al become pretty much impossible generally speaking, big bummer there.
Perhaps this will be a good accelerant for the adoption of homomorphic encryption algorithms?
Even without PRISM, the rise of cloud computing is a strong incentive for people to try to develop practical homomorphic encryption. Until there's a practical algorithm adoption will be limited.
What about the non-FISA requests, has any of them given the U.S. government unfettered access to user data?
What does unfettered mean? "You only can access all user data for 2 hours" "You need to specify (through tickboxes?) all the user data you wish to download to PRISM" "You only access all user data of all German users"
But it's saving a whole lot more than that. Much more.
They just put the spotlight on Administration, which of course won't allow it. Smart.
Thanks Google.
Strange phrase to put in there.
This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the NSA would look great on a resume, and put the person in a position to compromise essentially all internal security and data integrity.
- NSA 2013
But the prevailing view seems to be that the whole FISA program is a system of secret laws, which is not in fact the truth.
Source: https://www.eff.org/deeplinks/2013/06/government-says-secret...
Well, so far as we know anyway. There is still, AFAIK, an open question about the existence and/or exact nature of "secret laws" in the US. See John Gilmore's struggle to travel without offering up identity documents[1], for example.
So, there's a pretty good chance that unless its a rogue NSA operation, they are pretty well covered on the whole threat of criminal prosecution front.
(genuinely interested, because I did not know this)
I'm working on the client-side (Chrome) and my knowledge in the server area is therefore limited, but from my understanding this would be really hard.
1. Googlers have access to almost all source code. It would be difficult to hide code that just sends data to an outside entity.
2. Google continually monitors its (internal) bandwidth. This is done to optimize traffic, and detect intruders. A rogue Googler would trigger the same traps that are exist for potential hackers.
3. Google's infrastructure changes. You can't just install a gateway to the NSA and expect it to continue working for a long time. It's not as if user-data was stored in simple text-files.
I think this was the biggest bullshit signal for me (also a Googler, although a recent addition). The high rate of change of Google's infrastructure is astounding when you consider the scale it operates at. The notion of trying to maintain a functional API in secret of the scope they're talking about is laughable without a pretty sizable team.
Impossible? No, probably not, but really ridiculously unlikely.
If you're operating in secret, cooperation is going to be a hard commodity to come by. I also feel like a sizable team of the sort of people who work at Google would inevitably have leaked something about this before now.
Also, forwarding all of everybody's gmail would be a lot of data transiting the network. Unexpected traffic equal to all of gmail's normal traffic could be noticed.
2. The link out to the NSA would need to be massive as well. Would be very difficult to keep that secret. A 4G modem is not going to cut it.
3. Sure, but I imagine the NSA would be happy to put in the maintenance effort required. The data would have high ROI from their perspective.
So what. The world has access to the Linux source code. If I told you there was code in there that sent every byte written to disk to some external entity could you find it? Even if it was clear enough for you to find it, you'd have to be looking for it.
Further, you said yourself that googlers have access to almost all source code. How do you know something else isn't injected in before deployment. Honestly, the vast majority of googlers would have no idea and no way to have any idea if something like this were going on. Especially if people's jobs/freedom depending on no one knowing.
Are all internal Google communications encrypted? Probably not, but even if they are if you work in network security you likely hold the keys to that encryption regardless. You probably have access to their PKI keys as well.
Google is not made of idiots. It is not a startup run in a garage where every the "IT guy" has access to all the private keys.
Curious sarcasm. Network security is a role, and it's one which Google holds in very high esteem. Yes, if someone is configuring IPSec or new load balancers or any other front-end system, they need the Google certs. This is a simple function of the job.
It is not a startup run in a garage where every the "IT guy"
Here you go again. "IT Guy" when I was talking about network security roles (which despite your laughable sarcasm we know is a role at Google) -- the guys in charge of the coop, protecting the chickens. Maybe they wolves.
I have never, ever, in my life seen checks and controls that weren't laughably insecure. I've worked at a multinational bank, a large insurance company, a national telephone company, among other places. There will always be those people who cluck their mouths and wave their arms about how no way this is super advanced controls...in my experience it never, ever is.
There is more than one way to skin a cat. Google employs lots of smart people who are adept at developing cat-skinning algorithms.
Sounds suspiciously like they are going to ruin everyone's nerd rage.
So from a PR perspective I don't see how Google can fix this unless US law substantially changes (or they employ crypto on the users side but that undermines the economics of much of their business).
[1] I'm not convinced that it is legal under EU data protection law and Google does have a presence in the EU, but I'm no lawyer.
This is true, at least in Google's situation. However I think there is an untapped market of people that want to be advertised to, provided the advertising is relevant.
Surprisingly I think traditional print magazines actually have this figured out. The advertisements for designer clothing, watches, and booze get a lot of readership in "gentleman/bachelor/whatever" magazines (not sure what the correct term there is, not trying to refer to porn (well, except Playboy)) and I suspect that removing them would actually damage their subscription rates. Now, these adverts obviously are not targeted to the individual, but I think they nevertheless demonstrate the concept.
I'm sorry but where are you getting this from? Google has categorically stated that they do not share data without court approved mandates. There is no mass "targeting" that is going on, no matter what the nationality.
Nor does his attempt to marginalize an interest imply that the interest is marginalized on HN. It concerns me that you are so eager to misread others' comments, and defend comments that contain no substance, only name-calling.
I'll give you a hint and tell you one of the things it doesn't mean. It doesn't mean "surprises me".
For the facts that do indeed turn out to be true, soapbox away.
If it wasn't for this earth-rattling leak, Google would still be merrily handing over my emails to the NSA. Fail.