Feds tell web firms to turn over user passwords
m.cnet.com
m.cnet.com
In the current state, some big companies have the means to fight such requests, some big companies are very willing to cooperate, and small companies rarely have the means to go into a legal battle.
Because of the current fragmentation and secrecy surrounding feds' requests with software companies, users do not have the possibility of knowing what they're in for with which company. Also, the divide and conquer tactics used by the Feds really allow them to extract much more information than what would otherwise be the case. Ideally there should be a union for software companies, which makes agreements with the feds concerning their access rights; agreements which then apply to all members of the union.
Currently I have two rules of thumb: 1) for critical services, avoid companies located or significantly involved in the US or UK and 2) at all costs, stay away from Microsoft.
Also: You can encrypt the server hard drives.
Hey, it sounded good on paper.
Corporations (or any large centralized power base) will optimize for the most exploitable customer or user base, culturing this base if possible. To help broaden a target user base corporations need strong centralized governments more than they need even sizable (but less "culturable") segments of their market base.
Upshot: mature corporations (political parties / religions / etc) will not typically stand up to a centralized government on behalf of a rights-demanding fraction of their market... indeed, typically, they will do the opposite.
To me this is the prime definition of "too big to fail". It would only require a small percentage of these companies uniting "for the greater good" to produce meaningful results. Not cowing to the NSA is not treason in this instance so I can't even possibly understand why complying with "laws that aren't on any books so are they really laws?" has any positive merit.
If so, are there any viable, offline alternatives?
http://en.wikipedia.org/wiki/Comparison_of_accounting_softwa...
http://www.motherjones.com/kevin-drum/2013/06/wsj-nsa-progra...
But as far as I know, my bank can't look at my accounts that are with other financial companies.
The entire premise is personal finance software that learns your habits to make it easier to use :)
An open source service sounds interesting, but I don't think I'll ever be willing to post all my financial data to a web service again. It would be great to have a locally installed application that could keep track of all those accounts. Having some algorithms run to help me save would be great, but it would take some demonstrated assurances to get me to provide even anonymous data for the machine learning process.
The policies (or location) of online budgeting tools are entirely irrelevant. Hiding financial data from the government involves well established trades dating to long before the internet (or PRISM): money laundering and tax evasion.
Everyone needs to reconsider their worldview and a few important definitions they hold. One of those is privacy.
My definition of privacy: anything I relay to ANY one person is no longer private. What's the old saying about three people keeping a secret? Information wants to be free and privacy is not its natural state. It's always been this way, but the physical barriers to diffusion have been completely decimated in the past two decades.
This is not a mere blip in a long term trend, it is fundamental, IMO.
That being said, I believe there are new values we can all embrace to make the most of the state of the human experience today. Perhaps someone should can a thread on Internet values for the 21st century and beyond.
PS - Anyone ever wonder how MSFT got an anti-trust pass in the US, but not in the EU?
"In the interest of national security..."
In what ways is it in a different category to their phone company handing over their call logs and getting someone to impersonate their voice (or send a text message) to an associate?
A single password, in an active situation, with oversight [2], is a totally different proposition from something like Prism or handing over SSL private keys.
[1] Not sure about US law on entrapment, but "bring the kit, we're doing it tonight, rendezvous is XYZ" and then seeing who turns up with what doesn't sound like entrapment to me.
[2] I have no idea what oversight might or might not be applied. "No comment" from the government is admittedly not an encouraging sign.
And even then, a password should be encrypted. If there is a court order to reveal information, then there has to be a way to get this information rather than sending unencrypted passwords to the government so they can snoop through your mail without even being proven that you are guilty.
I must point out, "snooping through your mail" requires probable cause, not proof of guilt (that's for a court to decide).
Going to the companies who have to validate user passwords to get a password a user is unwilling or unable to divulge is wrong. Going beyond that in asking for details on how passwords are salted, hashed, what the salts are, etc. ... more wrong still.
That the practice has been revealed should be all any internet startup/company/organization should need to never, ever store a user's password again. Ever.
Where compelled disclosure of a password falls on that spectrum is, indeed, a matter of debate.
However, this is not the same. This is compelling a company to turn over either a user's password (which the user [debatably] could not be forced to turn over without potential infringement of 5A) or specific technical details necessary to business, security, and privacy operations to help them decrypt an encrypted password.
My examples were specifically not about compelling a person criminally charged or investigated to divulge combinations or produce keys. It was about compelling the safe-makers and key-makers to do the job as an end run around users being unwilling or unable to provide the demanded result.
Tangentially, this revelation makes me think a bit more about the CISPA requirements that were discussed regarding protecting employees from being forced to surrender passwords to their employers. Can't help but wonder if backdoor conversations on that proposal were engineered by executive wishes to be able to compel employers to turn over employee passwords because they haven't been successful with service providers directly.
[edit: mixed up my former/latter statement. added last comment. fixed spelling/grammar mistakes.]
If not, then to me it would seem that the only password that could be compelled is something like a hard drive firmware boot password, where the contents may not be encrypted but can't be accessed (through normal means) without the password.
Saying "turn over the physical object used to commit crime" makes turning it over testimonial! But saying "turn over the rifle with the serial number 98980843" is not testimony.
This is the most important story for this country since 9/11. Third rate journalism won't be part of the solution.
His main sources are "...one internet industry source" and "...a person who has worked at a large Silicon Valley Company."
That's about as vague and unverifiable as you can get for the foundation of a story like this.
What the hell is wrong with the government, is it really their business to interfere with personal life? It's their job to facilitate the community, to find solutions for peoples lives, this is not a solution, they are creating overly complex problems, unnecessary spent money. We need less government, less people there with less money, it seems they have too much of it and way too much time.
I don't expect a quick resolution to this problem and others. Political philosophy and legal theory have not kept up with technical advancements in society.
I'm learning the hard way just how much the user is the one ultimately screwed when it comes to account access. My father just recently died very unexpectedly and tragically. He was generally retired but still doing a dozen or so small tech consulting projects here and there and using his personal accounts on Gmail/Facebook/etc. for everything.
Facebook simply will not give any family member access to a deceased person's account. Google will consider it after you fill out a form and send them a bunch of documentation. Then they will consider and may possibly end up sending you off to get a court order and the like, but you're entirely subject to their own decision about whether you can get access to your deceased family member's main form of personal and business communication. You do not own your Gmail account, regardless of the shit they spout about you being able to download your data using takeout. If your estate can't get "your" data, you didn't really own it.
Yes, I know there are steps that could have been taken to have given access to others on the event of one's death, but realistically what percentage of Gmail/Facebook users have taken those steps? And why should those accounts be different from normal digital accounts like bank accounts where a standard court estate document is enough?
So you expect them to accept any old paper that looks like a court order without a vetting and verification process?
>If your estate can't get "your" data, you didn't really own it.
If you can't legally prove that you are part of "your" estate, then you're SOL. And getting anything done legally takes time. Sometimes lots of it.
It looks like you are SOL no matter what you prove.
Honestly, I kind of like the way that's handled. Whatever I put on facebook is private to me (and me alone, not whoever survives me) plus whatever I allowed that information to be shared with either on site or with legal documents.
No pre authoriation, no sharing.
Let's say a request is made for Google give over loads of Gmail passwords. Could they not silently implement an extremely strong password encryption on the affected accounts, and hand over these passwords, knowing that the feds wouldn't be able to crack them without a significant amount of time.
Also, are the feds likely to check to see if these passwords are legitimate? If my password was 12345 and Google simply told them that my password was 54321 then how could the feds possibly know that the passwords sent over are real?
EDIT: Obviously, I know this is highly illegal, and would land any company in trouble. I'm just wondering whether, theoretically, this is possible for a firm to do to circumvent any action from the feds.
By them NOT WORKING?
A lot of people have already stated that one way around this would be to change your password before the feds have had a chance to crack the provided hashes. This would surely be a similar system.
Of course, I don't know if this would work at all. I was basically thinking aloud to see if this idea would have some merit.
It's just not worth a company risking this kind of tampering. They could go to jail for that.
By all means, companies should fight back legally, and it sounds like they all are. I applaud them for that. But I think it's unreasonable to expect them to break the law for you.
It's morally wrong, and obviously I'm not saying it's the way to go. It's just a theory that I had, and I wanted to know if it was feasible for a company to do this.
It won't solve the problem, but it'll certainly help a bit.
EDIT after a few comments :
This will not make it impossible to steal identity. But this will cost us almost nothing and imply high cost for spooks : if you have a user password, you can use it on many website, for common users, without the related company even knowing it. If you implement last login timestamp, it's something you can do within hours, without any need for heavy architectural changes, and it will cost a lot to spooks to try to fake it on every websites, for a large amount of users.
Cheap to us, costly to them. That's the way to go for me.
What is a problem is mass surveillance. A simple measure like that could make it very costly to achieve mass operations.
EDIT : also, please note that the problem with password is that once you get one, for common people, you can hope they used it on many other sites. This allow feds to access website without the company even knowing it. If you have to fake login timestamp, all related companies must be aware of your action.
Facebook also provides access to all recent/active sessions and their last accessed time under Settings -> Security. They've got all kinds of other good security features that are worth enabling too.
I suspect a better long-term approach here is going to be something like Mozilla Persona (with the option of easily using your own domain for auth & auth if you like). Then the service doesn't have your password. They could still give the Feds access to your data, but at least the Feds won't be able to leverage your password against other services (greater adoption of password managers would also help this scenario).
And of course, enable two-factor auth on any site that supports it.
But as I say, we need something that everyone can implement right now and that makes mass surveillance cost too expensive to be realistic. Log history and 2 steps login (for example) are something that need heavy architectural changes, while showing the last log can be done at no cost.
But the cost to apply this to every single website they want to spook on will be prohibitively high to implement massive use.
LastPass say that all your details are encrypted client-side via your master password, so they cannot access anything of yours.
There's nothing to stop Apple doing the same - but I suspect they won't.
I hope they are, anyway.
EDIT: It's OX Text I'm most after (https://www.ox.io/ox_text)
I'm considering setting up my own e-mail system, but haven't gotten around to it yet.
EDIT: Actually, I forgot I installed Piwik for web analytics. Not that it's in any way needed for what I do, but I wanted to see what it's like. I was impressed, but haven't pushed it yet.
https://prism-break.org/#cloud-storage
I'm using rsync for backup and Seafile for file sync myself.
Two key aspects crucial to a functioning democracy. Two things they wont have to do if you have your data in a US-controlled cloud.
Possible point of interest: I don't live in the US.
Hahahahaha. No.
If anyone wants to come to my house and take a look at my server, I will know. Unless the global internet-police suddenly gained magical fairy-powers.
Hosting your own OwnCloud is 10000000% more secure than relying on third parties, things like Dropbox, where people can go behind your back.
In that case they can easily sniff passwords as they are used.
> A 2009 paper (PDF) by computer scientist Colin Percival estimated that it would cost a mere $4 to crack, in an average of one year, an 8-character bcrypt password composed only of letters.
Yet the linked paper by cpercival specifically states that a 8 _letter_ password would only take $4 per year to crack, but a 8 _character_ password would jump to $130k. Also, these numbers, as quoted from the paper, are referenced from 2002 dollars, including dollar costs of hardware from 2002, but do not include hardware other than the CPU, such as power supplies.
Along with all these jokers — http://plaintextoffenders.com/
Most instances of plain-text or weak password hashing are due to incompetence or laziness, not malice.
How hard can it be? It can already log in by itself, now it just needs to know the page where you can change your password.
Really, the only solution to this kind of thing is offshore corps.
1Password is a local, encrypted store of known passwords. Nothing is generated, except for the original passphrases themselves, which are completely random (not from a seed).
Still, if 1password made scraping work for the biggest sites out there (google, microsoft, etc) then that in itself would already be worthwhile.
The only reason any of this is an issue is because we have our data and communication in the internet. That's what makes mass surveillance possible.
If you keep your data off the internet, then you're only at risk of individual surveillance. But even that's difficult; stuxnet demonstrated that even air gapped computers are at risk, because we move data around on usb sticks and the like.
So, speech and paper, or human memory, are the only really secure media.
As for all the apps we carry around in our pockets ... do you really need instant online access to your bank balance over the internet on the bus? We used to carry around checkbooks and make entries in the register. If you really need to know your balance 24/7, carry a register booklet, or a moleskin. Then you don't have to wonder if Mint et al. are giving up your passwords.
Opt out.
The main issue is; scraping is hard and breaks at the drop of a hat. Sure you could script hourly password changes if you wanted to, but as soon as the host service modifies their forms a little, the whole system breaks and you could possibly be locked out of your account.
Operating directly on the database means either :
* requesting a dump that get quickly deprecated
* having a direct access to database, which can be traced
Using common interface, you can use it without rising any flags, except if companies specifically implement warning feature for known NSA/feds/whatever ips.
The best of that is that many people use the same password for several websites. So, having one, you may access data on an other website without the company knowing it.
As it becomes more and more clear big companies are fighting agencies here, decyphering passwords and using them abroad makes perfect sense.
I mean, isn't the article about the gov't asking the companies for user passwords? How is asking for direct db access any different than this?
Also, if there is an automated system for sending new passwords to your local clandestine operations agency then you're simply speeding up the process of them hoovering your data.
[1] http://asset2.cbsistatic.com/cnwk.1d/i/tim2/2013/07/25/bcryp... [2] http://instacod.es