On Confirmed Assumptions or, Not Trusting Google is a Good Idea
anarchism.is
anarchism.is
Well, he's going to want to punch me, but here's what I think(?) the answer is:
(a) He's not a US person, but instead a well-known citizen of Iceland, living abroad, and is thus not protected by the Fourth Amendment, at least to the extent that anything in the Fourth Amendment conflicts with any interest of the US.
(b) He's a person of interest in the investigation of one of the most significant leaks of national security information in US history.
It applies to actions of the United States government. It is a list of things they may not do.
In 1957, the court changed its position, overturning decades of precedent to declare that American citizens are in fact protected against U.S. government misbehavior by the Bill of Rights even outside the country. Unfortunately for the rest of the world, the court limited its ruling to U.S. citizens. Foreigners remained stuck with the old rule that the Bill of Rights doesn't apply abroad.[0]
So US citizens are protected whether they are within US borders or abroad. And foreigners are protected if they are within US borders... but once they leave, it no longer applies.
[0]. http://articles.latimes.com/2005/dec/16/opinion/oe-raustiala...
If a foreigner is protected while in the US, is accountable to the US if he/she breaks US law from abroad, and accountable if he/she breaks US law while visiting the US in the form of visiting a US web-server, (we foreigners are said to have visited US jurisdiction if we use US based services, there for we can be extradited) why then, if a foreigner's data is on US servers or systems, is his/her data and privacy not also protected under US law, if a foreigner is protected while in the US.
If we are said to have visited the US and there for come under US law if we use US services, then surely it must also apply that the data we leave behind is also protected.
I wonder if a panel of lawmakers were given all of this to make recommendations on, without secrecy, gag orders or political prejudice, if we'd have very different situation today.
To consider the judges as the ultimate arbiters of all constitutional
questions is a very dangerous doctrine indeed and one which would
place us under the despotism of an oligarchy. - Thomas Jefferson,1820
I will also note that the data in question was within the United States, where all property, whether owned by foreigners or not, is protected from unlawful search and seizure.Marbury v. Madison created a remarkable legal instrument: the Court can strike down a law, but it cannot write a new one (deplorable Costa Rican abortion jurisprudence notwithstanding). It is a check on government power that errs on the side of liberty.
However, relying on the Court to strike down every bad law is like relying on the compiler to catch logic errors. A sufficiently intelligent compiler can perform some remarkable analysis of code, but that is not the function of a compiler. We continue to elect bad Congressmen who pass bad laws signed by a bad President, and then we have the gall to blame the Supreme Court. It's ridiculous.
If you want to make a difference in politics, you have to actually get involved in politics, at the party and primary level, because that is just how shit gets done. It is critical to elect good candidates, not just to throw out bad ones.
The reckless interpretation of the U.S. bill of rights is already precariously close to violating the Geneva Conventions (on many cases, it probably has already been violated. I.E. Guantanamo Bay). The idea that you're somehow exempt from what is commonly regarded as decent and fair treatment of another human being based on a narrow (and arguable) technicality is appalling.
Ron Paul arguably holds the same views now (with his various attempts to make state actions immune from federal judicial review).
For both of them, history furnishes examples of why -- even if we hold that the Supreme Court and federal judicial review was a bad idea -- this is also a bad idea.
Congress has the power to declare war, but (a) that power doesn't require any particular language, and any authorization of military action, as contained in the various statutes Congress adopted after the Tripoli declared war, can have the effect of a declaration of war (and a declaration of war may be limited or conditional), and (b) Congressional declaration of war is sufficient to create war, but not necessary; an enemy declaring, or initiating without declaring, war is also sufficient to create war.
See, among other cases, Bas v. Tingy, 4 U.S. 37 (1800); The Prize Cases, 67 U.S. 635 (1862); The Protector, 79 U.S. 700 (1871).
http://en.wikipedia.org/wiki/Reid_v._Covert
http://www.law.cornell.edu/supct/html/historics/USSC_CR_0354...
So when, in 1880, American diplomats in Japan "tried" and convicted one American for killing another in Yokohama Bay, they did not need a jury to convict. When the defendant asserted that his 6th Amendment right to a jury trial had been violated, the Supreme Court declared "the Constitution has no operation in another country."
This is becoming abundantly obvious from where I sit, outside the US as a non-US citizen.
I wonder just how long it's going to take for non US businesses and governments to realise the consequences of that?
I look forward to the startup opportunities in what are currently considered "major player consolidated verticals" for non US based disruption?
Who's currently planning an ad network or web analytics service or auction site or microblogging service or social network or online retail conglomerate - all marketed to national government and non-US based businesses as "all data stored outside US jurisdiction, all data SSL/TLS with PFS on the wire to minimise consequences of interception", then lobby governments to advice citizens to switch away from "US monitored services" and for corporations to forbid use of "US monitored service" via corporate networks.
It's all but impossible to break into markets dominated by Google/eBay/Amazon/Facebook/Twitter - but what if the Australian government started recommending people use a secure local alternative, and big companies started blocking those services at the firewall?
I don't understand this notion that you don't really understand something like the 4th amendment without understanding the whole history of case law interpreting said amendment.
The amendment is short and simple. It says what it says. It is part of the supreme law of the land (the constitution) and thus supersedes any lesser laws which may conflict with it. Any interpretation of it is just that.
If I were to put it in software terms, I'd call interpretations “derived artifacts” and the amendment the “source”. If I start getting weird conflicts and unexpected behavior, as any developer knows, I should “make clean” (clear out all derived artifacts) followed by “make” (rebuild from source).
[1]: http://caselaw.lp.findlaw.com/scripts/getcase.pl?court=us&vo...
[2]: https://supreme.justia.com/cases/federal/us/140/453/case.htm...
The concept that the Bill of Rights and other constitutional protections against
arbitrary government are inoperative when they become inconvenient or when
expediency dictates otherwise is a very dangerous doctrine and, if allowed to
flourish, would destroy the benefit of a written Constitution and undermine the
basis of our Government.
That sentence basically sums up my entire viewpoint on warrantless government dragnets.[1]: http://www.law.cornell.edu/supct/html/historics/USSC_CR_0354...
That's why Reid v. Covert was such a landmark case, it completely overturned the precedent. IANAL either, however :)
[1] http://www.thegreatcourses.com/tgc/courses/course_detail.asp...
Hah. Yeah, sure.
So why do we allow societies to impose a vaccination regimen on people, by even minor coercion?
It only took ten seconds on google to note that the NSA apparently doesn't agree with you.
http://www.nsa.gov/sigint/faqs.shtml#sigint4
Federal law and executive order define a U.S. Person as:
a citizen of the United States;
an alien lawfully admitted for permanent residence;
an unincorporated association with a substantial number
of members who are citizens of the U.S. or are
aliens lawfully admitted for permanent residence; or
a corporation that is incorporated in the U.S.
I doubt that "permanent residence" includes H1-b workers, or other work visas, and I very strongly doubt that it includes people on business or pleasure trips.The NSA's language seems to derive very closely from FISA (the law itself, title 50 chapter 36),
http://uscode.house.gov/download/pls/50C36.txt
..which in 1801 (i) has similar language, though it clarifies that the definition of "lawfully admitted for permanent residence" should be taken from "section 1101(a)(20) of title 8"
According to http://www.law.cornell.edu/uscode/text/8/1101 , here is that section:
(20) The term “lawfully admitted for permanent residence” means the status of having been lawfully accorded the privilege of residing permanently in the United States as an immigrant in accordance with the immigration laws, such status not having changed.
I don't feel enlightened.
The EFF, in a surprising turn, claims that any legal resident is a US Person... normally I expect the EFF to (a) do their research correctly, and then (b) point out the worst-case scenario. This appears to be neither. https://ssd.eff.org/foreign/fisa
IANAL (though sometimes I play one on HN), TINLA.
Who is "the people"? Well, the Constitution starts out like so:
We the people of the United States
[1] http://en.wikipedia.org/wiki/Universal_Declaration_of_Human_...
[2] http://en.wikipedia.org/wiki/International_Covenant_on_Civil...
Again, that actually isn't particularly obvious in this kind of situation. The US property of non-resident aliens enjoys constitutional protection against (for example) expropriation. But there's no equivalent protection for their US cloud data? Oh Well.
On the other hand, as far as I can tell (IANAL) the fellow just got served a warrant, or at least a pretty ordinary court order of the kind that isn't related to foreign-intelligence loopholes or restricted to non-USPERSes. That's roughly the kind of thing that will happen to you in any jurisdiction if prosecutors have good evidence that you have information material to a huge criminal investigation. Maybe the secrecy or the breadth of the order was dubious. (I think it's also very likely that his GMail was scoped out with a FAA702 before the government decided to re-request the information using a means that would allow it to be introduced by the prosecution in a US court case.) But fundamentally it seems </sunglasses> he just got served ... I'll get my coat.
If the US insists on waiving the rights of non-citizens, despite the constitution, then it should also accept that it cannot prosecute any non-citizen for non compliance with its laws because they were not afforded the same rights.
Gotta have both sides of the coin.
You'll get little argument from most 'Mericans for your statement that these rights are human rights. The argument you will get is the rationality of transference. The difference between the OP and any American is citizenship and history.
US citizens of today are beneficiary to a Constitution that was crafted and bled for, over 200 years ago, with nasty war for our independence and claim to self governance. I didn't fight this battle. My father didn't fight this battle. Neither did his father. But one of the dumb-luck results of not only being born in the US to American citizens, are the benefits bestowed upon me by the war that was fought for the benefit of future generations (i.e. ME).
Now... this is going to sound really pointed and "f* y", but there's no other way to say it. Those 200+ year old men and women didn't fight this war for people in other countries, they did it for their own sons, daughters, and many generations that would come.
I agree! Those rights that were fought for should be universal human rights for every single person on the planet. But that's why you have to fight whatever government collects your taxes for those very rights on your own.
Respectfully.
Why? It's not the government collecting my taxes that is reading my emails and generally spying on my communications, it's the US'. How does fighting it help me?
I do agree that there needs to be a framework for how "data privacy" works in the Cloud Era, but it's important to keep in mind that it's not as if the law was meant to be that uneven toward foreigners, the law is essentially still from a time when there was no such thing as a Cloud, and "search & seizure" actually meant something physically present was found and seized.
The law doesn't (in general) permit taking property in the U.S. belonging foreigners abroad, for instance, so it was not as if the legislators all had their "FUCK U EUROPE" pens out when they were drafting the laws.
What we need are bilateral treaties that cover this situation. Perhaps something like a Most Favored Nation status between nations that specifies what kind of warrant requirements would exist for a given foreign national.
But then again, how do you determine the nationality of the user behind a given IP address in the modern world?? :-/
I realize this is a crappy response, but the only solution is to not use the services of countries whose laws do not explicitly protect you. As a US citizen, I refuse to use any services that can avoid that are provided by China for this very reason. (aside from the fact that I can't read Chinese.)
But... it's really, really important you understand something else here... The rights and protections you are correctly suggesting are NOT granted to you because of the limited scope and application of our Constitution, are the exact same rights and protections of mine, as a US citizen, that are currently being violated. Were I a citizen of another country, I would be just as, if not more, incensed about what has been claimed about the privacy rights of my data recently. But imagine what it's like to have grown up in a country where the guarantee of these rights is so ingrained in our minds that they are barely (almost NEVER) questioned, to find out that they are being violated at will and without the legal right to challenge or even the right to know what those violations are.
I can not even begin to articulate to you the degree of uncontainable rage I and many, many people I know have regarding what is going on right now. I can't recall a single time in my entire life, which is not an insignificant number, that I have been more angry or concerned about anything. NOT F!*&%$ ONCE!
A grand jury subpoena can get at your communications without any showing of probable cause, whether you are a U.S. person or a foreigner.
So Google was allowed, not required. Looks like they did the right thing by at least telling OP what they were forced to do. Shouldn't the title be "Not trusting your Government"?
(With the exception of things like tarsnap).
The chain of trust still extends to them. You're trusting that they're actually doing everything they say they're doing.
If you don't own the hardware and the building where the hardware is, you have to trust that they're doing everything you want them to be doing.
> The chain of trust still extends to them. You're
> trusting that they're actually doing everything
> they say they're doing.
Tarsnap performs encryption in the client, which is distributed only as source code. If you audit the client sufficiently to believe it is properly encrypting your data, then there is no need to trust the server or the hosting provider.If you have a sufficiently fast network connection (or enough local disk cache and the ability to predict what you will need before you drop off your high speed network access), that can work. But there will be a lot of things that you may have gotten accustomed to if you operate in such a paradigm.
Also, all the crypto in the world doesn't keep a service from logging (ip, timestamp) tuples each time you access them. You can do a lot with metadata.
With GMail metadata, yes; with Tarsnap metadata, much less so.
The source is open, and signed with PGP.
The data ends up being stored on S3, but the location doesn't matter.
FWIW I agree completely with that viewpoint, so this is not a criticism.
Speak for yourself.
But doing so, it handles so much data about so much people that even with good will, it's a danger. How secret services and cops could not be interested in the huge amount of data magically made available by google services ? The aggregation itself is the danger - and the feature we all love.
I search through Bing. My email is through Hotmail/Outlook. My online cloud sync is through Skydrive. Why am I cowering from Google any more than MS or anyone else that I give huge amounts of my data too?
It doesn't take much to imagine what kind of dossier could be constructed on an individual from that data. Quite likely they do know more about many people than those people know about themselves. Of course this can be used beneficially, but it's also the exact information needed to manipulate people.
That is far more than any other service is able to aggregate, and Google's business is fundamentally about mining that data in a way that is not for other corporations.
But yes, the others are a problem too - just on an orders of magnitude lower scale than Google.
> It could create the exact private service that you are looking for, but it intentionally does not.
Most of Google's products are "webapp" equivalents to traditional desktop software. It is not possible to create webapps which are private against the webapp's host.What you are essentially arguing is that Google ought to shut down its current business in favor of writing security-conscious desktop apps. The result would be that users would all jump ship to another provider, and then Google would go out of business and people on HN would be complaining that $NEW_COMPANY doesn't respect user privacy.
If you want to suggest a course of action that will improve user privacy, it must be one that users will actually be willing to support.
All you are really saying is that Google exposes data to the government because its business model dictates that it put privacy below behavioral profiling it its list of priorities. That is not in dispute.
You are arguing that Google is incapable of solving this problem, whereas I think that a group of people as talented and resourceful as Google could solve it if they wanted to, but they aren't trying because they think their value is tied to the amount of personal data they collect, rather than what problems they solve for society.
Right now, this privacy problem is a serious one for society, and who is better positioned than Google to solve it?
> Google was perfectly capable of creating a secure
> browser and propagating it through all manner of
> mechanisms.
Google could easily create a secure email client. There's no need to, since Thunderbird already exists, but they could if they wanted to. That wouldn't help at all with the problem of email security. > There is no reason they couldn't do the same with a
> secure mail system, for that matter they could just
> deliver it as a chrome update and smoothly redirect
> people into it if they wanted to.
What you're asking for is for Google to create its own proprietary communication protocol, then force all Chrome users to have it, then force Gmail users to use it. Can you imagine the reaction? Apart from flagrantly violating "don't be evil", it would lock out every alternative browser and prevent Gmail users from communicating with non-Gmail users. It would be XMPP->Hangouts all over again, except even worse because people actually use email.And consider how the implementation would have to work. First, it would be available for only a handful of browsers, possibly even only Chrome. Obviously it would need to be equivalent-ish to POP3, so that no data remains on Google's servers, which means that users would only be able to check their mail from a single device. If they bought a smartphone, they'd have to choose which device to read mail on. If they bought a new computer, they'd lose access to their previously received mail.
There is no technical reason why Google could not create a secure messaging system. There are many many many social reasons.
> All you are really saying is that Google exposes data
> to the government because its business model dictates
> that it put privacy below behavioral profiling it its
> list of priorities. That is not in dispute.
Google exposes data to the government because it is headquartered in a country where laws require compliance with search warrants. In theory Google could choose to relocate all of its employees to Somalia to avoid warrants, but that seems impractical.If a user wants their data to be truly private, then the implementation of that requires much more stringent privacy measures than most users are willing to put up with.
Your position appears to be that companies should not provide communication products for people who don't mind giving up a bit of privacy in exchange for a lot of convenience. That's not a reasonable position.
> whereas I think that a group of people as talented and
> resourceful as Google could solve it if they wanted to
This problem is not a technical problem, so no amount of technical expertise could solve it. You could set every single programmer in the world at solving this, but if their solution involves a user having to understand encryption keys then it would never be adopted. Google could easily create a secure email client. There's no need to, since Thunderbird already exists, but they could if they wanted to. That wouldn't help at all with the problem of email security.
False. The problem is not whether or not secure email clients exist. The problem is that people don't use them. Google has massive strength in both marketing and usability that existing secure email clients do not have. What you're asking for is for Google to create its own proprietary communication protocol, then force all Chrome users to have it, then force Gmail users to use it. Can you imagine the reaction? Apart from flagrantly violating "don't be evil", it would lock out every alternative browser and prevent Gmail users from communicating with non-Gmail users. It would be XMPP->Hangouts all over again, except even worse because people actually use email.
False. Nobody said that the protocol had to be proprietary. Nobody said Google couldn't also release it as an open source module that anyone could incorporate to their clients. Indeed these would be prerequisites for the security of the system to be audited. Your position appears to be that companies should not provide communication products for people who don't mind giving up a bit of privacy in exchange for a lot of convenience. That's not a reasonable position.
Why not? If it's unreasonable, you should easily be able to say why. I think it's a question of priorities. After our collective experience with cigarettes, we no longer think it's reasonable for companies to peddle addictive substances. Why shouldn't our attitudes to corporate responsibility for privacy also develop? Google exposes data to the government because it is headquartered in a country where laws require compliance with search warrants. In theory Google could choose to relocate all of its employees to Somalia to avoid warrants, but that seems impractical.
False. Google exposes data because of the law and because it has engineered systems to collect the data for it's own business purposes. Google can't control the first but it can control the second, therefore it is responsible for the outcome (as are the lawmakers and enforcers). This problem is not a technical problem, so no amount of technical expertise could solve it. You could set every single programmer in the world at solving this, but if their solution involves a user having to understand encryption keys then it would never be adopted.
False. Usability and marketing problems can be solved with technical solitions. This is a large part of what Google does. There is no need for users to need to understand encryption keys in order to use encryption, otherwise we wouldn't have ecommerce today.This has been obvious for a long time.
Most other "free" web services aren't much better.
It's sad that it's taken so long for people to start realizing and caring about this, but better late than never.
Most non-free web services are equally happy giving away your data to the government. Apple, MS and all the other companies are no better than Google.
And Google is not the problem -- it is just a symptom. The problem is the government that does not respect the rights of people.
I used the term to highlight that what most people consider "free" web services actually have a price.
That price is usually your privacy.
When you don't pay for a service in money, the company providing that service has to find some other way of generating money.
Often they do this by collecting and selling data about you.
Now, that doesn't mean that just because you paid for a service they won't do the same thing. But they'll will have more incentive to protect their paying customers than some service which consider you and your data as the commodity.
Also, Google does not sell information about their users. They target ads. The difference is huge.
Compare this to Apple's iMessage or FaceTime - Apple cannot decrypt the contents of the messages, and therefore cannot give the contents to the government.
They designed the service this way because their users pay for the service as part of the cost of the devices they sell so they don't require access to the data for behavioral profiling.
> Compare this to Apple's iMessage or FaceTime - Apple
> cannot decrypt the contents of the messages, and
> therefore cannot give the contents to the government.
This is not correct.First, when you buy a new iPhone, the way you authenticate yourself is by entering your Apple ID and password. Once entered, your new device will begin receiving iMessage data. This means that Apple is capable of provisioning a virtual device with your credentials, which will receive your messages. From there, they can be either stored or forwarded to third parties.
Second, your iPhone runs binaries distributed by Apple. There is no technical reason why these binaries could not contain code to forward historical messages to Apple or to a third party. Even if they don't now, a future update to iOS (which you won't be able to audit) could introduce such code.
The only way to have private communication is for all parties to run open-source clients. Each party must have the technical skill to audit the source code, or there must be at least one (preferably multiple) trusted third-party auditor. They must distribute encryption keys through a separate channel which does not depend on the communication host.
In other words, the standard Thunderbird+GPG+keyparty system that is popular among nerds but has seen no uptake among the general population.
Wrong. As others who have examined the protocol have noted, your password is used to unlock a keybag on the device itself. Apple doesn't have your password (only a secure hash) and therefore can't unlock the keybag. The security depends on the strength of your password, which is a weakness, but it is in your control, not Apples.
Yes, the binaries of any system can contain arbitrary spyware or be infected with such at any stage from development through to decommissioning. Open source is no absolute protection against that.
At the moment we are trusting that companies are not baldly lying to us, even Google.
> As others who have examined the protocol have noted,
> your password is used to unlock a keybag on the device
> itself. Apple doesn't have your password (only a secure
> hash) and therefore can't unlock the keybag.
Re-read what I wrote, and think about what it means.Setting up iMessage on a new iPhone does not involve copying a "keybag" (sic), inputting a private key, or any other form of strong client-side authentication. All you have to do is sign into the device using your Apple ID, and you can then receive iMessage messages.
If there were any additional barrier preventing Apple from provisioning iMessage entpoints, iPhone users would not be able to activate iMessage with only their Apple ID.
Do you understand now?
> Yes, the binaries of any system can contain arbitrary
> spyware or be infected with such at any stage from
> development through to decommissioning. Open source is
> no absolute protection against that.
It's not an absolute protection, but it is very good protection.Staying inside your house is not absolute protection against being eaten by bears, but your chances of being eaten by bears are much much lower than if you walk around Yellowstone dressed in steak.
Re-read what I wrote, and think about what it means.
I think it means you have a false belief about the limits of the system. If there were any additional barrier preventing Apple from provisioning iMessage entpoints, iPhone users would not be able to activate iMessage with only their Apple ID.
Wrong. Apple doesn't have your password. Only a hash. Verifying against the hash allows apple to add another device to the backend but does not unlock the keys to the message history. Only the password does that.There is some understanding about how the protocol works here: https://news.ycombinator.com/item?id=5493514
There are other sources around the net that you can refer to to understand more about how such a protocol can be built, but I don't have a lot of faith in you as a conversation partner now that you've demonstrated that you can't be bothered to inform yourself before responding incorrectly with condescending certainty.
> Verifying against the hash allows apple to add another
> device to the backend but does not unlock the keys to
> the message history
Isn't this what I've been claiming? If Apple can provision additional endpoints, they can provision a virtual endpoint which receives messages and forwards them to third parties.The point we are discussing is not whether iMessage provides perfect security. The point is that iMessage doesn't give Apple a stockpile of personal data that can be indiscriminately targeted at any time the way GMail can.
I'm not saying it's a panacea or arguing in favor of Apple. iMessage proves that Google could engineer a system to protect users privacy by not stockpiling data if they wanted to, which you have incorrectly denied.
> iMessage proves that Google could engineer a system
> to protect users privacy
iMessage does not protect privacy, because Apple is capable of intercepting your messages messages and sending them to third parties. To be a private communications medium, it should be considered impossible for messages to be intercepted.The only thing worse than a product that doesn't offer privacy is a product which claims to, but actually doesn't.
IMO, Apple's claim that iMessage is private is irresponsible because it endangers people who take that claim at face value.
Your argument is the equivalent of 'we can't trust any corporation'. It's a coherent position to take but it is extreme and doesn't lead to meaningful discussions about what is possible.
> Therefore no communication system can exist that meets
> your criteria. (E.g. Because the CPU could be compromised)
For the purposes of this discussion it's reasonable to assume that consumer hardware does not contain backdoors, because such extensive compromise of the computing infrastructure would require conspiracy on a massive scale (approximately every electronics manufacturer in the world). IMO, Apple's claim that iMessage is private is irresponsible because it endangers people who take that claim at face value.
By this logic, your claims are irresponsible. Apple's claim is true and you are misleading people into not taking advantage of the privacy they offer.Short version: Users can enable iMessage on their devices by signing in to their Apple account. Therefore, Apple is capable by themselves of configuring which devices receive messages from particular accounts. Therefore, Apple is capable of configuring a device you do not control to receive your messages.
When a new device is added to the keybag, the other devices report the change - this isn't controlled by the server and isn't optional. Apple can control the transport infrastructure, but they cannot enrol new devices into the cryptographic session without the user being involved.
Therefore although Apple could add another device to the communication protocol, without the password another device cannot be added to the encryption session, or without alerting the end user.
Your conclusion does not follow.
This doesn't affect the conclusion - Apple can make services that don't compromise user privacy because they aren't driven by their business model to collect personal data for behavioral profiling. Google has a vested interest in collecting this data, and persuading us to accept this as normal, that Apple just doesn't have.
Maybe you were looking for "Most other web services not in Iceland aren't much better"?
See http://www.daemonology.net/blog/2012-01-19-playing-chicken-w...
Meanwhile, some of the objections in this thread seem kind of selective. With a search warrant, the FBI can tap your phones and record your conversations, they can tap your internet connection and watch every IP address you connect to and record all the unencrypted connections you make, they can place tails on you that record every word they can pick up with a microphone, they can track every financial activity you engage in and every person you meet with; they can go into your house and take everything you own. If Colin was in the US, they could certainly go into his house and install a keylogger.
If you just want an online backup system, definitely use tarsnap or the like. I have an offsite backup that's locally encrypted. If you want a web service, though, with all the tradeoffs that implies, that's what you're going to be subject to. For US citizens, search warrants are actually good things; probable cause is a high bar to meet. It's the bullshit lack of disclosure/secrecy culture that the judiciary accepts so often that is the problem here (as well as the problems of if you're not a US citizen...). If we ensure that warrant disclosure policies are reformed, at least we can be informed that our data has been seized and defend ourselves.
LastPass is a webservice and stil encrypts the data locally; they use an extension, but Google controls the most popular browser today. They could add encryption capabilities to it and use it on Calendar, Contacts and others. Even email could be auto-encrypted on arrival.
LOL, you really think people have started caring about this? Nobody but a handful of techies and tech writers gives a shit.
So basically the authorities will have access to your e-mails anyway. It's just that they won't get them in the first 180 days. And of course this just applies to police/FBI, as NSA can get them from the day you sent them.
http://video.foxbusiness.com/v/3899047/google-ceo-recession-...
It's a non-trivial engineering task. If you want an email service which can readily delete your email, you need to find one with non-redundant, completely un-mirrored databases, fragile filesystems, and no backups. But that is not what most people are clamoring for in a service provider.
Each of them believe they are doing nothing wrong.
I wouldn't be surprised if the NSA didn't have the e-mail captured, sorted, and analyzed before it's processed on the receiving end and shows up in the user's mailbox.
How is this not the wide assumption being made right now? How is there ANY question remaining of whether or not they have such access?
Just as the Syrian government is unlikely to be able to get Google to give them information on particular dissidents, it would be wise for American activists to choose a email provider that is not located in the United States.
Right now that doesn't exist.
Let's say you sent such an e-mail. It was noticed by the NSA and triggered... whatever and now they've decided that they want to monitor you. How much difficulty is involved?
From what I've read recently, it seems that it's fairly trivial to start monitoring an individual and continue to do so for a period of time. I would imagine that the easier it is, the higher the chances are of it happening.
If it's a matter of hitting a few keystrokes to begin the monitoring, there's little cost involved so why not? They could monitor you for a while, analyze the data, and then decide if they need to keep monitoring you.
If it's extremely difficult, costly, or time-consuming to begin the process, well, I'd imagine they would be less likely to do so (by how much I won't begin to guess).
Basically, if they can start monitoring you and gathering data on you with little effort or cost required, it's probably a given that they would keep an eye on you. If there's a bunch of paperwork, warrants, etc., involved, the chances would be lower, I think.
It's hard to imagine anything more interesting to the NSA, but for not just the obvious reason.
Wikileaks set itself up as a nexus of exchange for state secrets of a great many states. Any state with an intelligence operation would want to penetrate that organization to have access to raw data and advance notice of anything interesting about to go down.
I've often wondered if such organizations (not naming names) ever wondered why they get approximately one volunteer from each European nation.
And, well, if you don't want to run to Hong Kong, you're pretty much the government's bitch in that circumstance...
If he doesn't believe organizations have a right to secrecy, then why does he believe that he is entitled to secrecy. Privacy and secrecy are the same thing, claiming to be pro-privacy but against secrecy is dishonest.
No, they aren't (e.g. that I want to be alone when going to the bathroom doesn't mean it's a secret what I am doing there). Even if they were, persons and organizations are not the same thing either.
"No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks." -- International Bill of Human Rights, article 12.
I also found interesting to read the "CCPR General Comment No. 16" [1] on the right to privacy.
[1] http://www.unhchr.ch/tbs/doc.nsf/(Symbol)/23378a8724595410c1...
For users who are willing to give up the web interface, there are many open-source email clients that provide strong encryption (e.g. Thunderbird + GPG).
Google's business relies on them being able to examine your personal data. That's how Gmail is paid for.
Perhaps someone who has a different business model e.g. Samsung, Microsoft, or Apple should do this.
Trusting "someone" on a distributed network to store information for you long term isn't a good idea. They disappear and your data is gone too.
Also, if you can find them to request the data, a search warrant can find them to request it, too.
Also, crypto doesn't help. It would be foolish to assume gmail messages aren't encrypted on disk. The keys have to be stored somewhere. End users can't and won't securely store key material. Store them on the server, and it's subject to the warrant.
If you dont want to use Gmail for some or all messages, just don't use Gmail.
But I agree with you that it's very different from anything they do. Also, too vulnerable to piracy or cloning. Aaand it may not be feasible to run their bots in a weak machine.
Gmail ad targeting isn't a bit of JavaScript that can run in real time in the background. It's a series of huge map reduces touching data sets larger than any client computer could store. Just indexing a pre-prepared list of mothership ads would result in a horrible user experience (far poorer ad targeting).
Google has a vested interest in only showing you ads you might be interested in; it doesn't work as well as it should, but it works magnitudes better than the state of the art 10 years ago.
And if the protocol is sufficiently closed to prevent open-source clients, why would anyone use it at all? Wouldn't that be the same as the XMPP->Hangouts transition that infuriated everyone a few weeks ago?
When the provider can't access your data, if you lose your password, all of your data is gone forever. If you are willing to live with that, alternatives already exist, as others pointed out.
Imagine a Google Glass wearer and a NSA order to record everything he sees?
In theory you can get this reversed, but it is common for courts to uphold the government's interest in keeping investigations secret well beyond normal disclosure dates, in a few cases even up to and during the trial against the person who was served the warrant.
As to your second sentence, I think it's very reductionist. I see a FISC warrant as functioning like a subpoena. Say the SEC subpoena's your company's financial records from your accountant, and finds in there evidence that is sufficient to get a proper warrant to get documents from your company's premises. Does that mean there is no protection or purpose to the SEC not just being able to give itself Article III warrants?
https://www.dropbox.com/s/602d01t8ahqw1km/Screenshot%202013-...
Deleted comment
So try things like blocking analytics at host level, using either gmail or search etc etc. Makes it harder for NSA. Can you imagine yourself in a trial trying to explain why you visited certain sites or searched for certain keywords 3 years ago? Were you really researching what you saw on CSI or were you preparing the perfect murder of your wife?
I should be able to give whatever data I want to Google without worrying that the government is going to take it from Google in secret.
If it chose to, Google could protect users by developing services that do not rely on Google itself examining their personal data.
Google understands the risks better than its users but chooses to expose them because doing so is aligned with its business model and philosophy whereas protecting them is not.
It's a bit like recommending someone travel through a war zone on a bicycle when a tank is an available alternative, because the bike carries advertising you profit from and the tank does not.
The way I see it, the problem is that mass cooperation just isn't going to happen. Incentives and benefits must be found at the individual level (altruism counts as a weak incentive), and drawbacks must be dealt with, starting with the gazillion trivial inconveniences that an otherwise privacy aware citizen would have to put up with.
There's a reason why I don't encrypt my hard drive: my OS doesn't do it by default, and taking the time to set it up is just such a drag.
The inconveniences can be removed by engineering - that's what we do. It's a matter of priorities and Google's are conflicted in this area.
I'm perplexed that you'd call me idealistic for not wanting a coercive third party secretly taking a company's data by force, and in the next sentence suggest that a company should provide services to me in exchange for nothing.
I give my data to Google. In exchange, I get their services and they get to serve me advertisements. I am happy with this arrangement. Wanting my government to have some semblance of the checks and balances encoded in our founding document is neither unreasonable nor idealistic.
I'm calling you idealistic because you are putting your hopes in an idealistic solution when Google could provide you with a technical solution now. One type of check and balance against untrustworthy governments is robust civil institutions. Technology companies could be helping to provide those.
It seems to me that in the presence of an untrustworthy government, a state of affairs that had existed throughout history, you prefer ad-supported free email to privacy.
In a perfect world we wouldn't need locks at all, either on our cars or our houses. But when the world is not perfect then sometimes it becomes more reasonable to abate the risk ourselves than to shout at the whole world to stop being imperfect.
The comment I was responding to was using "shoulds", which I took as an invitation to an ethical comment rather than a pragmatic one.
(a) They're the Internet's foremost adopter and proponent of DHE ciphersuites, which drastically reduce the impact of losing the RSA key that underpins most site's TLS security, and, just as importantly, forces adversaries to actively MITM every connection in order to decrypt them.
(b) They're a pioneer in key pinning, which bakes the identity of their key into the Chrome browser binary, meaning that when your Chrome browser talks to Google's mail service, it's unlikely to trust any otherwise- valid- looking certificate presented by a MITM attacker.
Google's mail service is better encrypted than most banks.
But it's also engineered to give Google itself access to your data so they can improve their behavioral profile of you.
I think what people are suggesting is that if end user privacy was Google's priority rather than gaining access to user data for their own use, they could engineer a service that didn't place themselves as a man-in-the middle.
Chrome doesn't pin actual certificates, just public keys of CAs. If some organization had access to Verisign, Equifax or Geotrust keys, they could just create new certificates for *.google.com, which Chrome would accept.
Actually if someone sends an email to my Gmail account using his ISP SMTP server, is the connection between the two SMTP servers likely to be encrypted?
Google has a financial interest in having access to the content of mail messages, but (a) it's an interest "in the large", not in any specific account, and (b) it's a nonrivalrous interest.
You can't solve a legal problem with engineering. We're talking about the same agencies who had the ability to get all of the major phone carriers to install wiretapping services – there's no reason to believe they wouldn't do the same to anyone else of interest.
Google doesn't want the profile to be stored privately in your browser because then they can't use it to target you in other situations.
They are constantly pushing for access to more of your personal information, not less.