I wish this was true. I don't think it's there yet. I virtually hear nobody outside of tech talking about it. It's really quite remarkable.
I wish this was true. I don't think it's there yet. I virtually hear nobody outside of tech talking about it. It's really quite remarkable.
I'll tell you what, though: young people are absolutely paying attention.
And members of the Judiciary Committee seemed genuinely surprised by the scope of these programs. They were obviously fed a line of bullshit from the past several administrations about what these programs actually do if they were told anything at all. That fact isn't particularly comforting since these programs have been hinted at publicly for years and anyone who has been paying attention understands what the intelligence community is up to.
If you read Hayden's op-ed in CNN last week you'll also see evidence that the tech companies and the backers of TPP are two forces having the big impact on the debate right now since he addressed both issues right up front.
We are a long way from getting meaningful change, but it sure looks more likely now than it did three months ago. And there is more coming on this story. For example, Greenwald says he has NSA training manuals that prove that NSA analysts have the technical ability to tap communications from their desk just like Snowden said they do. Right now the administration is hiding behind the fact that they are restricted by policy from doing that, and many members of the Judiciary Committee seemed to be confused by that. They seem to believe that analysts don't have the technical capability when the admin says "they can't" do it.
Also, even Cheney seemed genuinely mind boggled by the fact that a low level contractor has access to the details of these programs. He insisted that he must have had the help of a higher placed source to get access to the documents he leaked. People really don't understand how computer networks work and what it means to be a system administrator.
I believe the NSA is specifically calculating that it's better to delay and appear to put up a "fight" over releasing this info. Then, when it finally comes out, it will have the psychological effect of making people think that if the NSA is fighting so hard to protect something so "trivial", then maybe there's nothing to worry about. Maybe all of their programs and activities are just as "trivial". So, nothing to see here. Let's keep it moving.
But, of course, the specific number of a certain type of request for a small number of tech companies is only a small part of the picture with respect to this overall issue. So, ultimately, such a limited release would work in the NSA's favor.
I watched the entire Judiciary Committee hearings and they were more than just the normal political posturing. There was a lot of that of course, but there is an undercurrent of deep concern that congress has been had by the executive and judicial branches. That is a good thing. The more documentation that comes out, the more likely there will be real change. Especially if Congress becomes convinced that thousands of analysts across the intelligence community have the technical ability to bypass any legally required procedures and do what Snowden said they can do, and that the technical auditing of that access is less than complete. Looking at the architecture of the system that the NSA has built, and hearing that the number of system administrators with access similar to Snowden's is in the "hundreds", then I suspect the truth is that there are hundreds of people who have total access to all the data the NSA has and that they can access that data in a way that would be very hard to detect unless someone in command was looking for a specific case of abuse. And even then, how could you trust the audit trail when at some level at least some system admins have to have full access to that data too?
But that will not really solve the global problem for the tech community since Congress will never prevent the NSA from monitoring foreign traffic. It will be interesting to see how Google handles encrypting Google Drive. The only hope they have of gaining back the trust of international users in the long term is to make it easy to ensure that this sort of wholesale surveillance is much less likely to bear fruit. Google has conflicting incentives in this area though since they want to be able to read the content to serve relevant ads.
I still think it is highly unlikely that we'll get any real reform. But I have more hope than I have in years, and that is great.
At the end of the day, we need more tech like Tor. And we need the tech community to actively resist restrictions that governments will always want to place on the effectiveness of such systems. I personally would like to see a requirement that data centers in the US must allow users to host Tor relays and exit nodes on their networks without hassle or restriction. That is unlikely to ever happen, but that would go a long way in really protecting users since it would allow users to fund a network that would actually protect their privacy. At a minimum, there needs to be legal protection for users who do choose to host relays and exits. Short of a requirement that all DCs allow Tor exit nodes, as a community we need to actively support companies that allow users to host Tor exit nodes. And we should set up a legal fund to fight any battles that result from the hosting of relays and exits.