Greenwald: Snowden Has Provided ‘Thousands’ Of Docs, ‘Dozens’ Are Newsworthy
livewire.talkingpointsmemo.com
livewire.talkingpointsmemo.com
http://www.zdnet.com/blog/btl/wikileaks-insurance-file-decry...
EDIT: Didn't see the Twitter update at the bottom, my apologies.
I'd imagine it wouldn't be hard to predict their responses to each type of revelation.
They try to downplay the scope of the snooping? Retort with documents showing the number of collaborating service providers and types of materials gathered.
They try to downplay the impact of this on innocent Americans? Release documents showing specific abuses.
etc. and ad nauseaum until the hypocrites, phonies, and apologists are exposed for exactly what they are.
I suppose only time will tell, but I know a lot of people that are getting more and more interested in this.
Its not like Brook's facile drivel takes all that much effort; its not like its designed to stand up to scrutiny by anyone thinking deeply, its just to give people an excuse not to think deeply.
That's why companies often need PR consultants. Because they are tempted to try to keep stuff under wraps, even when it's slowly trickling out. They need an adult to tell them "people will find out anyway, so just dump the whole thing in a press release on a Friday, so you get it all out in one headline". Plus, reporters will be reporting your spin on it, and you look like you've made an honest mistake and are coming clean.
The NSA should probably figure out what's getting leaked, then spoil the PR attack by coming clean. Somehow, I can't see them doing it.
They release some tantalizing tidbits (they are tidbits, aren't they? we already had heard about the metadata in 2006, didn't we?), and at the peak of interest (where did this come from?!?) release Snowden's identity in a carefully crafted video. They maximize control over his story before the government even has any idea who he is, before they can even think how to paint a picture of him in a negative light. Once the media has spent its powder covering Snowden (letting him speak for himself in a gorgeous HD video), there is little the government can do to add to the story; Snowden's identity is largely frozen in the picture that Greenwald et al have painted, while the government PR machine is struggling to come up with a cohesive strategy, let alone a response.
Then, after the Snowden story has run its course (at the point where talking about Snowden any more will mean losing viewers), they drop the big disclosures. At least that's my prediction. So what might the next disclosures be? This is pure paranoid speculation, but I think Snowden hinted at it in the video: the government is recording all telephone conversations, but storing it according to a legal theory that says that as long as no one actually listens to the recordings, they don't need a warrant. They obtain a warrant that is individual-specific, but instead of using that warrant to capture evidence of current actions, they use that warrant to retrieve all of the target's past activities.
99.99% of Americans will see their local TV news slamming the guy on any character assassination angles they can come up with.
Sure, a majority of Americans won't have seen it, but a majority don't give a crap about this kind of thing at all. I would say that for most people who were paying attention, the video had an impact.
http://www.mpopost.com/most-americans-rely-on-television-for...
[1] that the person died and the vehicle crashed are well-reported facts. Most people don't question causality after this - and enough entropy can be introduced to prevent questions also.
And besides, based on this theory, the stream of information being released should speed up, as once you have the worlds attention, they will pay attention to more. But we tend to see an initial release of explosive information, followed by a gradually diminishing stream of information - I am thinking back to Cablegate in particular - until it basically switches off and you never hear anything again.
I'm almost disappointed by this leak because of how it might affect the diversity of mr greenwald's tweets.
Isn't the role of narrator an incredibly important enough part of every tale?
Reporters are now protagonists since states spy on them and use dirty tactics to prevent them from doing their jobs. I don't think many of them wanted that role when they started.
[0] http://www.wired.com/threatlevel/2013/06/snowden-powerpoint/
[1] http://www.guardian.co.uk/world/2013/jun/08/nsa-prism-server...
[2] https://twitter.com/ggreenwald/status/343410562245480449
The slice deck already looks like someone was presenting to non-technical management - why would they have put highly technical details in there too?
Greenwald presumably has plenty of access to technical advisors at the Guardian and elsewhere who can help sift through.
So then it's all about the quality of the advisors they have access to, but given the nature of the materials, I suspect few people have been able to see them.
We just won't know till the whole thing gets released, if ever.
And to the second point, obviously I couldn't know for sure, not having seen it, but it's very very common with these types of presentations within government agencies and defense contractors to have 5-10 overview slides, the conclusion, and then behind that 20 reference slides that are more of an information dump. The idea is that the first set of slides is enough for most people, but if you want to dig deeper, there's additional detail.
You simply can't build the system that does what Greenwald claims for $20 million. You can build a drop box + FISA API for that amount though, but that would mean Greenwald is incorrect (or lying, take your pick) and the companies + NSA were telling the truth about that aspect.
But he doesn't, either because he is obstinate or because he doesn't understand the technical nuances.
Whether or not that would stand up to Supreme Court scrutiny is, I think, an open question.
Suffice it to say, this is a very complicated question. I'm inclined to believe that any attempts to prevent journalists from publishing additional documents like the ones now in question will be quashed. But it's not a sure thing.
I found it really hard to get angry at the PRISM stuff considering that pretty much every major article went through major revisions over the following 48 hours. Also, the "direct access to servers" meme that was categorically false doesn't help to take it seriously.
When the people behind the scandal can spend the entire news cycle raising legitimate criticisms and contradictions to the published articles, it's hard to get mad.
I don't think this was ever determined. The documents specifically stated that access to the servers is "direct," and Glenn Greenwald seems to be sticking to his guns on that point.
Remember that each company has its own homegrown user-data data storage format, homegrown distributed data storage system, homegrown datacenters(!), and firewalls. These companies aren't running MySQL or Oracle, and these systems are constantly being updated with new features and data model migrations.
Does that seem plausible? Contrast against what has been freely admitted since NSLs started appearing:
Each company sets up a "safe-deposit" server for delivering specific one-off subsets of subpoena'd data, and the company's engineers deliver data to that server upon demand.
But when it's been shown that a single subpoena can be "all phone data for three months for every customer", then describing that as "direct access" doesn't seem completely unreasonable to me.
It's clear that there are crucial and important technical details missing. But it's also clear that the NSA has much more fluid access than one-user-per-approved-subpoena-at-one-point-in-time. Depending upon the target audience of the leaked PRISM slides, the description "direct access" may be quite prudent.
In general the stuff coming out of PRISM seemed to me to just be the general name for how the NSA hands out the NSLs(which are awful in their own right) to all these comapnies. A good side-effect of all this hype is people are looking at those. But PRISM doesn't seem to bring anything "new" to the table. Correct me if I'm wrong
Not that I think this is the case - I suspect your scenario is what at least Google is doing. But if it's set up as an API (they submit a search query, Google approves it or even rubber stamps it in many cases, the query is run, the results sent to the dropbox), then the PRISM description is pretty accurate.
I could just up-vote you anonymously but I would rather say in person that this quotation tickles me pink and that I am going to steal it.
The existence of the has_fisa_approval checkbox allows the companies to (dubiously) claim "no direct access" even though it is all but equivalent in practice.
1: http://uncrunched.com/2013/06/11/connecting-the-prism-dots-m...
Somehow I doubt it'd be all that much more technically challenging elsewhere.
It's not a hard problem if there's people complicit at the right levels in these organisations. If there are no people complicit, then it would be difficult, yes. But we don't have enough information to determine whether "direct access" would involve a handful of people for a few days or weeks to get a feed or API set up, or if it would require covert interception of data and people sneaking around at night.
In this case the data comes directly from the company holding the data. There is no wiretap, no cypher breaking, no MITM attack, no bugs planted on suspect computers, no TEMPEST intercepts, no HUMINT concerns, none of that.
The data gets delivered by a secure channel over a point-to-point connection straight to an NSA server, where PRISM goes and makes magic happen from there.
But! Although the data's provenance is direct, there is still the intermediary that delivers it (or not): the company itself, which gets to determine whether or not they will make that SFTP (or equivalent) transfer occur. So the companies can all claim that NSA is not tromping around in their datacenters because the NSA is not. The NSA is asking the company to do the tromping for them.
I realize that sounds disingenuous, but that's the time-honored technique that's also used in OOP: Wrap access to data members around a getter function as part of a defined interface, to allow for modifying the getter later.
NSA may still be able to ask for information on anyone if a FISA warrant is only required after 7 days, and it's not as if many FISA warrants have been disapproved, so that's not to say that there are inherent limits to PRISM's ability to capture data on someone.
But at the same time it's also not like NSA has the ability to do rsync facebook.com:/users nsa.gov:/"$(date)", which is essentially what Greenwald has been claiming this whole time, and what Greenwald refuses to acknowledge even the possibility he might be wrong on.