NSA E-Mail Eavesdropping
schneier.com
schneier.com
I would very much like, now more than ever, for services to build on encryption in a way that allows it to be used by everyone, with little to no barrier to entry.
I've wanted to encrypt all my email for a very long time, but the logistics of doing so when you interact with normal people are... rough, at best.
[1] http://www.huffingtonpost.com/2013/06/29/glenn-greenwald-nsa...
I doubt it. Google/Apple/Facebook/AWS/AWS customers/Microsoft have more non-US customers than US customers, and while the US population might not care, all of those "foreign entities" that Obama explained are targeted without warrants aren't going to put their high-value confidential data into those services now that this is common knowledge.
These companies had better get their asses in gear and get this whole surveillance architecture shut down, or it's curtains for the US internet industry.
If this isn't visibly and loudly fixed, nobody (the 6.5+bn nobodies that don't get 4th amendment protections) will trust US-based companies with high value data ever again. (It may already be too late, if only because if they shut down this one, their track record of dishonesty and evasion suggests they'd just build another and lie about its existence like they did this time 'round.)
There are already European municipalities banning the use of Google Apps on security grounds, for instance. This is just the beginning.
I would be very surprised if the NSA didn't already have the means to crack most, if not all, current practical encryption schemes...
Also, do you encrypt meta-data as well? Isn't that what the whole PRISM thing is?
https://www.eff.org/deeplinks/2013/07/restore-fourth-campaig...
I think most people are well aware and in agreement with the fact that the government not only have but should have a much broader scope to work within.
The question is how far that scope should be stretched.
This is one of the major purposes of having a government in society - to delegate tasks to them that the overall group/society does not feel comfortable allowing individuals to take.
Just because you can do something _legally_, doesn't mean it's a good idea.
Just because you can do something _illegally_, doesn't mean it's a bad idea.
FTFY
Probably because of the widespread belief that laws are handed down from the heavens. The idea that the law could be wrong is nearly heresy.
If I don't like the actions the NSA is taking, and those actions are legal, then I should push for laws making it illegal.
If I don't like the actions the NSA is taking, and those actions are illegal, then I should push for punishment of those violating the laws, better oversight, &c.
Pushing for laws banning already illegal behavior is a waste of time. Pushing for (criminal) punishment of people who weren't breaking any laws is not appropriate.
You are right that the present illegality or legality should not substantially affect our assessments of what the laws should be (except perhaps through a weak preference for the status quo motivated out of conservative principles - more ways to break things than fix them).
That's the theory. We're fucked when the govt turns around and subjectively interprets objective law to do whatever the fuck they want.
However, wouldn't it be easier for the NSA to get data directly off your phone rather than requesting your data from all the online companies individually?
It's probably trivial for the NSA to remotely access the data on your phone or even turn it into a remote listening device when you're not using it. Snowden intimated this when he recommended to all the people he was meeting to put their phones in the icebox because its insulation blocks reception.
Whereas doing the same scale of info copying by individually accessing users' computers/phones would be WAY WAY more detectable.
Typing in a hurry, sorry if the point isn't clear.
Regarding detectability, I'm sure they have methods for downloading phone data that are hard to detect and would look like malware if someone happened to detect it.
You may continue to hold that opinion, but I see no reason to trust denials by either the gov't or by Google/Facebook/et al. "Unfettered access" is easy to deny, but it may be the case that what the gov't has amounts to the same thing, or is effectively unfettered access. The gov't officials involved have little incentive to tell the truth, and a large incentive to conceal their activities. The corporate parties may be compelled to lie, or at least be unable to tell the truth (under duress).
>Dragnet surveillance techniques such as tapping fiber is a different issue.
A single program of many. Don't confuse gov't denials concerning one activity under one program, as proof that the gov't isn't conducting that activity under some other program by another name. Also, gov't officials have been caught in outright lies James Clapper, for example.
>I'm sure they have methods for downloading phone data that are hard to detect and would look like malware if someone happened to detect it.
Phones report their users' every activity, this has been discussed here and on the internet at large, at length, several times over the past few years. Most recently was the disclosure related to Motorola phones which is still on the front page. https://news.ycombinator.com/item?id=5973282
I'm not ruling out any scenario -- just pointing out that even if Google/Facebook refuse to comply with the NSA or you decide to stop storing data in the cloud, it may not do much to protect your privacy because your phone is not a safe haven.
In their terms, nothing is off limits, correct?