The PRISM letter Google, Yahoo, Apple, Facebook, Microsoft are sending Congress
venturebeat.com
venturebeat.com
I don't understand the tone of the comments here. I see lots of pitchforks out and pointed at these companies, but I don't get why. Yes, it appears that companies released data to the US government. That seriously sucks.
But as far as I can tell, the affected companies are the victims here. They were forced into doing this by the US government. There's no "cooperation" when the US government says "we are legally compelling you to do this".
If it wasn't by force, why would any of these companies do it? What's the upside for Microsoft of Twitter to send user data to the government? If it's cooperation, what do they get out of it?
I think this letter is a good thing because, even if the US government doesn't respond to it, it communicates that the companies involved are apparently releasing less information than people think. Why would they ask to show the numbers if they were large?
The companies here are asking to be more transparent. I can't see how anyone can argue that it isn't a step in the right direction.
Trust is necessary for Google's business model. This letter represents a truly minimal attempt at self-preservation. If you truly want to regain you users' trust then you need to be transparent. Who at Google failed to tell the truth until it served their own interests? Who decided to meekly comply rather than taking a stand? Name names. What is going on that we still don't know about? Silence is support.
This directly contradicts what he is mentioning above. When you are compelled to do something, it doesn't mean you are facilitating. It means you are being forced.
> Who at Google failed to tell the truth until it served their own interests?
Has anyone up until the last month when the press decided to take up the Snowden case 24x7 actually asked Google if this was going on? Books about this subject and the NSA goings on have been published for 5+ years now. Maybe no one cared enough to pay attention? Or it was known and ignored until now because no one thought it newsworthy? That doesn't mean Google was keeping it secret.
Especially for a company that big, you'd expect some backbone.
http://www.wired.com/threatlevel/2013/04/google-fights-nsl/ for example.
Just because not every fight is public doesn't mean they aren't happening.
Yahoo fought for 5 years before their fight became public.
Could you please elaborate what it means to be "forced" in a democratic, free, law-abiding country?
Do you mean CEO of Google had a gun at their face? Do you mean they were treated to get electricity cut off? Internet cut off? Engineers thrown in jail without fair trial? Please kindly tell me what it means where a free democratic government is "forcing" you to comply with a secret unethical, most likely unlawful and surely unconstitutional request?
You can be compelled by the US government to do things you might not like to do. Google can either comply since they are a US based company, or not. The benefits of compliance outweigh the downsides of not complying.
>secret unethical, most likely unlawful and surely unconstitutional request?
There has been no evidence that what the NSA is doing is illegal. It has congressional oversight and approval.
I'm thinking that the US Government would have a much harder time prosecuting a high-profile, wealthy CEO over a systems administrator no one had heard of until a month ago. And the media attention would be harder to derail.
I'm thinking that the US Government would have a much
harder time prosecuting a high-profile, wealthy CEO
http://www.businessinsider.com/the-story-of-joseph-nacchio-a... "Only One Big Telecom CEO Refused To Cave To The NSA ...
And He's Been In Jail For 4 Years
https://mailman.stanford.edu/pipermail/liberationtech/2013-J... We know what happened in the case of QWest before 9/11.
They contacted the CEO/Chairman asking to wiretap all the
customers. After he consulted with Legal, he refused. As
a result, NSA canceled a bunch of unrelated billion dollar
contracts that QWest was the top bidder for. And then the
DoJ targeted him and prosecuted him and put him in prison
for insider trading -- on the theory that he knew of
anticipated income from secret programs that QWest was
planning for the government, while the public didn't
because it was classified and he couldn't legally tell
them, and then he bought or sold QWest stock
knowing those things.
This CEO's name is Joseph P. Nacchio and TODAY he's still
serving a trumped-up 6-year federal prison sentence today
for quietly refusing an NSA demand to massively wiretap
his customers.He would go to jail. And then, instead of being a powerful executive in a strong position to push the government to do the right thing, he would be powerless.
Microsoft is an even worse offender here, with their recent marketing campaigns slamming Google for privacy while they themselves were apparently being 'forced' to disrespect their users privacy.
Don't claim something that you know that you cannot provide, even if you want to provide it.
Trusted...how? I guess we need to define trusted.
Google isn't selling your email history to the highest 3rd party bidder for extra money. They are complying with the law, handing over specific info for specific legal requests from the US government.
That's what I'd expect any company which espouses a "do no evil" policy to do. Literally, if you are doing evil, especially if you are being compelled to do so, take whatever action is necessary to prevent further evil from being done.
As for the letter in the article, I find it completely insufficient. Asking for the ability to disclose how many secret compulsions are made against these companies isn't useful information for us. Further, it doesn't actually fix the problem. There shouldn't be secret requests being made. It should all be done under normal warrants, with exceptional cases that actually require secrecy decided by a judge, not the NSA. In this way, when your information is collected but isn't pertinent to national security, Google can actually inform you.
But let's not be intentionally naive or ignorant. Google should have prefaced their "Don't Be Evil" mantra with a small-print "Unless a secretive Total Information Awareness-esque system of massive surveillance of raw and curated data is demanded of us in the form of a secretive judicial court in FISC whose base intentions were corrupted, that we are totally unable to challenge because the consortium of all 3 major branches of government are preventing us from seeking legal recourse"????
Right. As you were saying about models of trust and all that nebulous nonsense... Carry on.
Google didn't fail to tell the truth here, they (and others) were legally prohibited from doing so. You have to understand if Google were to simply put up a page saying, "We've complied with 1234 NSA requests", people will be thrown in prison.
And frankly, this entire scandal is in part these companies having their chickens come home to roost. Google and Facebook have for years been pushing the culture into accepting that private entities will store and analyze your personal information for profit. How many times has Eric Schmidt publicly said that people need to get over their ideas of personal privacy? Google has played a direct role in changing the expectation of privacy on the internet into one with which the present spying programs are legally defensible. We should demand the government stay out of our business while private corporations are using our data for their own gain and without transparency? You work for a mild-mannered spy agency.
>How many times has Eric Schmidt publicly said that people need to get over their ideas of personal privacy?
And now we know definitively WHY Eric was saying this BS -- because he knew it was ALREADY compromised, deliberately, by Goog and NSA!!
And besides, if what you say is true, how do we know that these companies weren't legally compelled to write this letter to brainwash everyone? It's a drop in the bucket compared to what they were legally compelled to do before. How would we ever know if they will be legally compelled to report wrong numbers?
Do Google allow NSA to run computer code on google's servers? More specific, do NSA supply database queries when demanding data? Do NSA ever provide Google with tracking code like JS or links to NSA webbugs (1px imgs) that Google later put in targeted ads? Do Google ever provide physical (or remote) access to servers, hard drives (like backups) or network devices to NSA?
Having NSA supplied querries running over all of googles databases are indirect full access to googles servers. That as bad as direct access/backdoor, and would likely be called as such by NSA. Same goes for trackers inside google's adnetwork, or if they got physical access to any backups.
I could be wrong, but I believe Google has been pushing the government to be able to make this public since well before the PRISM story broke.
> It's a drop in the bucket compared to what they were legally compelled to do before.
Actually, we don't know if there is a bucket or not, which is precisely what Google and others are trying to remedy here. We simply have no data on the scope of what information the government is receiving.
These companies allowed people with a perverted sense of morality and the law to root through the most private details of our personal lives and our company's. Then they release the most weaselly denial ever contrived, and now this weak excuse for action.
If one man can stand up to the US Gov. risking liberty and life, big businesses certainly can. Google stood by and let it happen. Too often does the world hinges on the actions of one man, in spite of the cowardice of the organised, resourceful and powerful.
As a result, I am disgusted by google, and the others. Yahoo tried, and still try. Why not the all mighty do no evil google?
Remember people, it only takes one man. One single, principled, brave, man. (I am reminded of the central message of Babylon 5)
What are the govt gonna do, throw Tim Cook, Eric Schmidt, Larry and Sergey into jail? Disappear them?
The absolute best lawyers in America available to them, massive public opinion likely to be on their side, unlimited funds to defend lengthy legal action. If THEY won't and don't feel able to say 'no this is wrong' and stand up to the NSA mission creep then that is a very scary thought and makes Snowden's actions even more brave.
If people can give up their lives or parts of it to do the right thing, why can't a company? (I would add that if you have a good reason for it, that's also a reason to re-think companies, and not to simply accept that they can't do the right thing because that's how they are)
I could see a CEO not wanting to see his employees out of a job, or being afraid of his shareholders caring more about the share value than what they see when they look in the mirror; but that doesn't automatically justify anything. Especially since even if Google "died", just for refusing and resisting a little (which I doubt, but I'm willing to assume it and argue from there anyway), something else would have to replace at least parts of it, and former Googlers would be the first hired for any and all of that.
But considering Erich Schmidt says stuff like "If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place.", it kinda seems like the issue sits deeper. It's not (just) cowardice, it's lack of awareness.
If you're working at one of these companies that handles millions of peoples data, you'd better learn more empathy for your customers.
The fact that you work at Google and can't understand this is frightening to me.
This is a convenient position to take, which clears Google of any responsibility.
There were companies, smaller than Google, that stood up against government requests to spy on their customers. Quest is one of them. But Google agreed to the terms, "signed papers", and has been cooperating ever since.
More so, Google et al. deliberately lied about commitment to user privacy, which all of the PRISM participants reiterated in their press-releases after Snowden revealed the program.
> I think this letter is a good thing
This letter is a good thing, but little more than good PR.
Releasing statistics on government requests has no implications on the PRISM program, which gives intelligence agencies unhindered access to our data.
I think it's a little unfair to pride oneself as a privacy activist, while spying on your users.
http://www.google.com/transparencyreport/
http://googleblog.blogspot.com/2013/03/transparency-report-s...
Google has ALWAYS pushed for more transparency in government data requests. The government only allowed reporting on NSL's earlier this year (and even then only in aggregate). FISA actions were and are still a harder fight.
Google, Apple, Yahoo, Facebook, etc. have lost trust because of this whole spying thing. To say that these companies were somehow "victims" is troubling to me. As far as I can tell the Constitution of the U.S.A is the law. Anything introduced to purposely subvert the constitution is illegal and should be challenged.
With companies like Google who have a lot of weight (money) to just hand over anything private to the NSA without actually calling them on it, is disturbing. These NSA programs have been going on for a very long time; collecting everyone's (american AND their allies) private communications. I'm sorry, but victim? No way. Instead of keeping to the "cloud" mentality there could have been more work on protecting users with proper encryption techniques. No body has done this. Yes, Yahoo may have lost in secret, but they also didn't fight the NSA's spying by creating technologies or build upon current technologies to protect their users.
I trusted Google to keep my gmail/youtube/etc. information private for me and those whom I talk to. Advertisements bothered me, yes, so I stopped communicating about confidential things to do with business, etc. I have been a Google user since a week after gmail was introduced.
I have deleted all my connections to Google thanks to these revelations.
In order for Google, Facebook or Microsoft to gain my trust again, there needs to be innovation in the encryption world where I can seamlessly encrypt ON THE CLIENT and decrypt ON THE CLIENT machine with out storing anything to do with the private keys on the cloud or trust Google with the private keys. Would this ever happen? Probably not. Google is an Ad company. Privacy isn't exactly their biggest strong point. Same goes for the others.
If I get to run a quarry on the Gmail servers, scanning through every personal email to find a subset of say 100 people, the statistic that Google want to publish will state that only a 100 peoples account was violated. In truth however, all customers was violated to create the list of the 100 people which account contents got sent over.
Second, Microsoft or Twitter do gain privilege by cooperate with governments. They become less likely a target for lawsuits directed at violations of competition laws. they also get a easier time lobbying politicians for lower taxes if they at the same time are helping out with spying at the local population.
* a helping hand when foreign governments want to close loopholes that allow these companies to dodge local taxes
* useful information about foreign competitors that comes out of the snooping
* government contracts
* ...and much more...
Google on the other hand makes it's money out of analyzing people's communication and online behavior. Why would you expect it to protect people's privacy from itself?
As for Google, I expect them to charge a fee to make up for lost ad revenue. I already pay for several Google services.
Think about other instances in which the U.S. government "forces" companies into doing things: say a new EPA reg or a new SEC reg. Every such activity is met with a flood of litigation from the companies affected. But here, apparently only Yahoo put up a fight.
It might seem like the DOJ is omnipotent, but really, it's a very budget-constrained and capacity-constrained entity (it's too busy fighting Nancy Reagan's drug war). People need to get their stories consistent on this point: if the government is owned by big evil corporations with lots of money, well the tech industry has plenty of those that can throw their weight and money around.
To be fair, I don't know all of the details, but my gut feeling is that if these companies had wanted to, they could have at least forced the DOJ to spend a lot of money and time getting their cooperation. As a practical matter, not doing so might have been the wrong move even from a business standpoint--each company possibly stands to lose a lot more than they would have had to spend on enough litigation to ruin the DOJ's day.
It's really not comparable though... It took Yahoo six years to earn the right to communicate about one particular lawsuit[1]. We have no idea how many legal challenges Google, Apple, and others are involved in but prevented from talking about.
[1] https://www.eff.org/deeplinks/2013/07/yahoo-fight-for-users-...
a) If a company is approached by any spooky three-letter agency, the higher-ups of that company could possibly interpret that as a validation that they've made it 'big' -- and furthermore, they could see in that offer a security that three-letter agencies then have an interest in seeing the company continue to scale up and succeed (because of limited funds, three-lettered agencies can't just go merrily creating tools that work properly with the 'next facebook' every other 9 months... and furthermore, there's no knowing if they'll come across resistance when they solicit 'direct access' to the next company. Also, NSA would have just loved it if China and Russia was a big user of Facebook... so I can even imagine them doing something subtle to try to make that a reality).
b) I have worked in the defense industry, but what I worked on was pretty unremarkable (and not at all weird). Most of my coworkers and bosses were pretty liberal. I remember once I asked my boss (with whom I was pretty close and friendly with) how he felt that he was working for the defense given his political beliefs... and he had a 'meh, gotta put food on the plate for my kids somehow' answer. Then he further reaffirmed that what we were doing wasn't anything special, it's the folks in the NSA who're doing crazy Stuxnet-type shit. If we weren't doing what we were doing, someone else would have. So, my point in saying this is, for all the rage you see on HN I really just can't help but wonder if these folks would deny an offer from a company who's working for the American defense. I really think the only reason there was a lot of commotion (finally) over this issue was that it had just the right PR elements: a good looking guy, leaving the country in a coolass way, humiliating the world power by escaping arrest, etc. I mean, anyone who knew anything about anything already knew about these programs -- this was the cover of Wired last year: http://i.imgur.com/3Rjh1la.jpg
Lastly, I think folks who're pretty made at the top leading will just acquiesce to requests from NSA for reasons mentioned in point a, and because folks at the top are usually the sort of people who care about succeeding and making a company profit as much as it can, they generally don't give a damn about anyone's privacy:
Zuck: Yeah so if you ever need info about anyone at Harvard
Zuck: Just ask.
Zuck: I have over 4,000 emails, pictures, addresses, SNS
[Redacted Friend's Name]: What? How'd you manage that one?
Zuck: People just submitted it.
Zuck: I don't know why.
Zuck: They "trust me"
Zuck: Dumb fucks.
http://www.businessinsider.com/well-these-new-zuckerberg-ims...
I'm sure the number of people like Snowden is much less than the number of programs like PRISM. I ask myself frequently, why did I trust these company in the first place, why did I trust them again and again. I guess Snowden is just a flag for "it's time for a change", but when I see your comment, I see no hope, 'cause guys like you, the potential whistleblowers, need these companies to be trusted. I wonder if you've known anything about these before Snowden reveals, if you have, why were you being quiet, if you haven't, how the hell can you trust your employer now?
I see the future, people are willing to sell themselves for a 'better life' based on their privacy. Why? Because some of us are selling it already. But I don't want to be one of them, even I ended up with starving to death.
that's because i can imagine situations (e.g., FBI identify a child trafficker) where i am okay with his privacy being compromised. but I can't for the life of me come up with a scenario where it benefits society to hide these statistics. for crying out loud, tell us how much data you're looking at!
I totally agree this is (belatedly) a step in the right direction, and I'm pleased Google are getting together with other SV companies to question the right of government to extract data at will from their servers, but we don't really know if PRISM was a voluntary program or not at this point, or even what the extent of the surveillance is, because no-one is willing to tell us. So it's hard as a customer to decide where Google stands on this.
Are other companies like Twitter and Amazon cooperating with PRISM? As far as I understand it some companies are cooperating, and some are not, and some like Apple only agreed relatively recently, unlike say Microsoft, Yahoo or Google. The response to the news that they had been cooperating was also a bit odd because rather than siding with their customers and asking for more transparency at that point, the non-denial denials issued told us nothing about what exactly Google have been doing, but lots about what they're not doing in quite specific terms.
The real focus of people's anger should of course be the government which has insisted these companies take part, and refuses to allow any transparency on numbers and methods, but there are lingering suspicions about whether the practices are legal, and whether companies were actually obliged to take part on pain of sanctions, or just strongly encouraged to do so.
But there's a whole different discussion to be had around:
>If it's cooperation, what do they get out of it?
I'm just spit balling here, but tax breaks and favorable legislation are a reasonable first guess. Keep in mind that just like the legal justification for these user data requests, the meetings of the parties involved here (congressmen and company representatives) are not public knowledge. We don't know what benefits are or may be offered.
In fact, we don't know what benefits could be offered. Most of the public--HN included--can't even guess or imagine the benefits that a company would seek in an instance like this. Most of us simply don't have business knowledge at that level, let alone knowledge of the business interests and goals of an individual company as large as Facebook.
So the absence of any of us being able to give a good answer to 'what do they get out of it' is not a good reason to believe that they're not getting something out of it.
We all like to believe in the good of people. But it's our responsibility as the governed, in order to protect our liberty and the liberty of those who follow us, to challenge the actions of the government especially actions on this scale of importance--because we're effectively questioning if the government is already using telecommunications as telescreens.
What do you think of this: https://news.ycombinator.com/item?id=6054532
I don't care about "Section 215" and "Section 702" specifically. We've seen the government has had no problem with coming up with their own secret "interpretations" of these laws, what's stopping them from using other laws to secretly justify programs?
It's like a "blacklist" rather than a "whitelist" approach. I want companies to categorically state with no wiggle room the only circumstances under which they provide data to government/law enforcement before I even begin to think about trusting them again.
And I'm not actually sure about their market share since their stock is remarkably steady over 5 years and has been steadily climbing since the middle of 2012.
Yahoo's commendation: https://www.eff.org/deeplinks/2013/07/yahoo-fight-for-users-...
Yahoo's stock: http://finance.yahoo.com/echarts?s=YHOO+Interactive#symbol=y...
I know look at the max length of Yahoo's stock and yes, it seems they have dropped quite a bit at points. Dec 1999 being their highest at 108 and change (dot com bust I'd imagine came shortly after), and as high as 39 in 2006 up from a low of 4.45 in Sep 2001. Currently 29 though so they've been putting in work since they dropped to 11.51 in Nov 2008.
1. Unless I've missed some crucial evidence
Why aren't these companies, and people in general, demanding that operations like PRISM are terminated entirely? Why are people prepared to accept this sort of intrusion into their private lives at all?
If a peeping tom kept bothering me I would not accept his presence as long as he called me up before he started watching my house.
The major issue here isn't the way the government snoops on its citizens, it's that it happens at all.
As a sidenote, think about how efficient copyright advocates have been with this strategy: slowly pushing through seemingly innocent changes.
However, in this case we are not dealing with business law or economic policy and such. We're dealing with something insidious and socially toxic. To me the correct course is to outright object to mass personal surveillance from the outset. We should not allow tyranny to edge its way into our society, it should be stamped out and named to be the rotten cancer that it is.
But that reminds me of one of my favourite series: http://www.amazon.com/Traveler-Fourth-Realm-Trilogy-Book/dp/...
On the other hand, competitors have a chance to catch up now. Which is great news for consumers.
Companies like Google, Apple, Facebook and others don't have time to do a lot of research and development unless it's directly related to the product they sell. So Google hires a lot of programmers who figure out how to deal with a lot of data, Apple hires a lot of software and hardware people who design beautiful integrated computing experiences...but their success depends on so much more than those narrow fields.
For example I read recently about some really high-tech networking switches that Google uses which allow their data centers to run that much more efficiently. Does Google have time to invent new kinds of networking equipment? Probably not. Maybe to build and deploy them... but not to invent. So they make a deal with DARPA, NSA or whoever. The government will trickle down any technological breakthroughs they've made using tax-payer money to the corporate sector, and the corporations will in exchange be VERY compliant and VERY quiet when it comes to feeding the NSA user data it hungers for.
Now shit's hit the fan, and the companies are attempting to simulate their dislike for the NSA.
Hah. If they have time to invent self-driving cars, balloon powered internet, and wearable computing devices I'm pretty sure they can spare a few people to invent networking equipment that would save them millions.
http://www.nethosting.com/buzz/blog/a-rare-look-at-google-cu...
That one about "non-denial denials" still seems popular though.
Once someone has failed on this scale, they should never be trusted again.
I understand sticking by your morals, but literally every big companies has turned over data to PRISM. Not using any of these products because of morals is silly.
Edit: The title has since been updated.
http://www.theatlanticwire.com/politics/2013/07/nsa-admits-i...
Although I won't agree with it, I can understand that Google (and crew) were prevented from DISCLOSING that they're being tapped. Fine, gun to the head and all that. But what prevented them from saying "we receive requests, we fight them", and even providing information on the process of fighting a request.