NSA: we can warrantlessly grab your data and keep it forever if encrypted
techdirt.com
techdirt.com
Starting today, I am writing email encryption software that, when you send an email to someone else with the software installed, will automatically encrypt it on the way out, and automatically decrypt any encrypted messages on the way in. (A "zero user interface" once installed).
The intention is that this will allow people to encrypt their messages with zero effort on their part.
Initially it will encrypt email and will run on unixlike machines (Linux and Mac). Later it will run on all major platforms (Windows, iOS, Android) and have functionality for VoIP and social networking (the intention is to replace Skype and Facebook with secure alternatives).
Also, checkout OWS: https://whispersystems.org/
It will be open source.
In other words, this will be a long slog where most of the work is product-oriented and feature Xerox'ing, and not whiz-bang cool encryption oriented. Good luck :)
How will they be distributed and replaced?
Who will generate them?
How will they get on my phone?
What happens when my phone is stolen?
How will they get to the people who want to communicate with me?
Hacking out a local client usable by unix nerds punts on these problems, more or less. Solve these problems in a way that fits into the workflow of present day average e-mail users (ie, my mom) and you will have something.
I do. Am I the only one who finds web-based email clients insufferably slow?
What if your standalone client is a website running on your local box with an interface similar to gmail?
> In other words, this will be a long slog where most of the work is product-oriented and feature Xerox'ing, and not whiz-bang cool encryption oriented.
Yes, you're right. The crypto itself isn't that complicated.
And that is ignoring the whole aspect of it that they shouldn't be doing blanket surveillance to begin with, and should only be doing targeted surveillance, whether or not it is against a US citizen.
Servers that store key material are subject to wiretaps.
We're not lacking secure alternatives because this isn't a technical problem.
I believe it is an interface problem. I am surprised Mozilla isn't re-activating Thunderbird with an easier to use encryption procedure and an educational campaign to raise awareness in users instead of making petitions around Firefox.
Rather, the recent issue is a disagreement over what constitutes a violation of privacy, e.g. whether electronic collection of data (without a human listener) constitutes violation.
What if, instead, you had a bedroom camera (maybe for tracking frisky escapades) and it streamed wirelessly to a home server? The more relevant question then becomes whether it's OK for the NSA (or rather, FBI) to sit on the street and capture that WiFi stream from a public road.
As you consider this question, also consider how many open WiFi hotspots you've ever used (or broke the WEP for) in your hacking career. :) The idea that it's OK to hack the stupid because their system was so open to attack might finally die due to PRISM, if people are intellectually honest with themselves.
Wait, there are no "issues", there is no "disagreement", not in any conventional fashion.
From the state, we have seen nothing but the boiler-plate propaganda that comes out when any large bureaucracy faces an embarrassment.
They sort-of say it's OK to invade the privacy of (any vaguely accused) terrorists, they sort-of say they can look at anything and it's not an invasion of privacy and they sort-of say they can collect anything and as long they don't look its not an invasion of privacy. But none of it matters, it's not a "debate", there are no "disagreements" in the sense of a dialogue.
These are just press releases arguments are clearly wrong to everyone but morons, and they are naturally aimed for the mass of the morons out there (or the mass of ignorant and prefer-to-be-ignorant if you want).
If you think accessing private communications should not be allowed except in limited circumstances, you should be very worried by the storing of all this information. The implications are that anyone's privacy can be violated simply because of a policy change by those agencies who store and swap this information across national borders at some unspecified point in the future. In addition to future use by your national agency - your data might be collected in one country, and used in 10 others without control. The only way to stop future abuse is not to collect the data.
The intelligence agencies have arrogated to themselves the right to listen to any communication by using lawyerly arguments like yours over the difference between collection and listening, and denying that they are using all this information they are collecting without proper legal authority (of course for the NSA, that legal authority turns out to be a six-monthly rubber stamp on their procedures, not oversight of their actual work, but oversight of what they say they do).
So I think your distinction between storing and accessing is unimportant and not worth arguing about - storage enables later access, so once it has all been stored, you have no control over the way it will be used (and it will be used).
I don't think that's the kind of clear-cut argument you'd like it to be. To me, for example, if I'm letting AT&T or Verizon see the encrypted bits (as well as any intermediate carriers and backbone operators), I don't really have a privacy expectation on the encrypted bits themselves. I might be persuaded that I have a privacy expectation on the decrypted bits, however.
Why? Because ISPs handle your data, they get to spy on you? If you asked UPS to ship a memory card full of photos, does that give them permission to copy it and use it how they wish?
Also, the government doesn't need a warrant to intercept a UPS package.
[citation needed]
Disclaimers: I am not a customer, and have not used the service, but believe that looking at the security methods used by those actively prosecuted is a decent way to figure out with precautions/security measures work.
*though a quick google of ups open package on warrant will reveal many on dubious forums
The law specifically prevents this for US mail.
They're probably buffered on a Microsoft OS. Do they get a copy too? Can I expect my Dell not to be keylogged? It seems like in a "post 9/11 era" we have no expectation to anything short of getting your balls fondled.
> I don't have any particular expectation of privacy with regards to the bits short of their actually decrypting them
None at all? Would you share your network traffic with me?
Tell this to the people going after Snowden.
What if UPS could scan your package and interpret the bits on a memory stick inside? Would that be reasonable? (They could frame it as "we scanned the bits, transferred it over the internet to another memory stick, and copied and delivered those contents".
A world in which there was truly no privacy is one in which anyone on the planet could log into your bank account, and get an itemized list of every transaction you've run through it. Obviously, that's not the case. Just as obviously, your medical records are not a matter of public record. Nor are your job performance reviews, your tax returns, or the contents of your medicine cabinet.
Indeed, there's a TON of material that people both expect to be private and which, in the normal course of life, IS private. Moreover, the "reasonable expectation of privacy" standard is not based simply on what's technically possible to conceal, but on the boundaries that are socially necessary to maintain a free and open democracy.
And I'm sorry, but this is a VERY clear cut argument. The lines are as straight and as bright and as shining as they've ever been. For the government to search records that a citizen has made a legal effort to shield from public view, it must have specific and articulable cause to suspect that citizen of a specific crime. Whether my correspondence is printed on paper or stored in my smartphone has exactly zero bearing on the fundamental law governing the government itself. None, zero, nada, zip.
Apologies for the caps used as emphasis. I try not to use them unless the comment in question is not just stupid and wrong, but dangerously stupid and wrong. And this comment is about as stupidly dangerous and wrong as asserting "if you've got nothing to hide, you've got nothing to fear."
It is interesting you give the examples that you give, because the government can get, at least Constitutionally, your bank records without a warrant: https://ssd.eff.org/your-computer/govt/privacy, or your medical records: http://www.aclu.org/technology-and-liberty/faq-government-ac.... To the extent that such information is protected, the protections are statutory in nature, not Constitutional.
> For the government to search records that a citizen has made any effort to shield from public view, it much have specific and articulable cause to suspect that citizen of a specific crime
This is "alexqgb's interpretation of what the law should be" not what the framers had in mind when they drafted the 4th amendment.
For instance, the one about medical records is discussing warrants, and whether the government needs one IN ADDITION to clear and articulable suspicion pertaining to a crime, and not just suspicion. Even in cases where the constraints on searches are eased, the reasonable expectation that privacy exists remains very real. Indeed, if there weren't a reasonable expectation of privacy, there wouldn't need to be clear rules describing how and when it can be pierced.
The article goes on to discuss the additional exemptions to the need for warrants pertaining to national security concerns, but as it points out, the existence of these provisions in law IS NOT to be interpreted as a validation of their constitutionality. In fact, the whole point of the link you provided is to underscore how dubious the claims to constitutionality really are.
Here's the crux of it:
Q: Is it Constitutional for the government to get my medical information without a warrant?
A: The ACLU believes that this easy, warrantless access to our medical information violates the U.S. Constitution, especially the Fourth Amendment, which generally bars the government from engaging in unreasonable searches and seizures.[viii] However, because the Patriot Act and the HIPAA regulations have only recently gone into effect, their constitutionality remains largely untested, although at least one legal challenge to the HIPAA rules is underway, and more challenges are likely.
Specifically (from the first article): "Thus, some Supreme Court cases have held that you have no reasonable expectation of privacy in information you have 'knowingly exposed' to a third party — for example, bank records or records of telephone numbers you have dialed — even if you intended for that third party to keep the information secret."
Going on: "Records stored by others. As the Supreme Court has stated, 'The Fourth Amendment does not prohibit the obtaining of information revealed to a third party and conveyed by him to Government authorities, even if the information is revealed on the assumption that it will be used only for a limited purpose and the confidence placed in the third party will not be betrayed.' This means that you will often have no Fourth Amendment protection in the records that others keep about you, because most information that a third party will have about you was either given freely to them by you, thus knowingly exposed, or was collected from other, public sources."
That's the law, that's what the Supreme Court has said, not what the ACLU hopes or believes.
From the second article: "Q: Can the police get my medical information without a warrant?
A: Yes. The HIPAA rules provide a wide variety of circumstances under which medical information can be disclosed for law enforcement-related purposes without explicitly requiring a warrant."
That's the statutory law, at this moment, based on the Congress's reasonable interpretation of the Constitutional basis above.
Of course the ACLU hopes to get the courts to go the other way, but as they tacitly admit: courts have not done so to date. E.g. http://www.law360.com/articles/376791/warrantless-seizure-of... (Warrantless Seizure Of Medical Records OK'd In Drug Case).
At this moment, it's hard to describe 4th amendment protections as applied to medical records anything other than aspirational on the part of the ACLU.
dd if=/dev/urandom of=secret.txt bs=1m count=200
^^^ this should do the trick!
OK, then we will take you house away and you cant have it back until you produce the key.
You're presupposing that capturing data you have flowing over the internet is something that requires a warrant, and the NSA's position is predicated on the idea that it generally does not.
But do know, I find the idea of having nothing to hide absurd, and see far too much of authority actually treating us people as guilty before we have done anything even slightly suspicious.
So, yeah, sarcasm, I suppose, but my intention was to back up the original point.
There's always a chain of trust that you have to follow down. It just gets harder to mess with the deeper you go. Not impossible, just more difficult and less likely to be entirely automated.
Also encrypt everything possible, and encourage others to do that too. It might attract more attention to you, but it's also a strong assertion of your right to privacy. Everyone should use encryption for even the most mundane of things. The government says we have no right to privacy for emails older then 180 days because we are sharing them via someone else's server. If we encrypt them, that argument is invalid, because we are making it clear that only the recipients are intended to read it and it is private from everyone else.
that's why I left your country. whole bunch of Short-of's.
providing endless cover to actual chatter
a crypto tithing