NSA paid millions to cover Prism compliance costs for tech companies
theguardian.com
theguardian.com
You have to assume everything sent over HTTP(S) is insecure. If it cannot be MITMd now, it can be stored and decrypted later.
Even if you connect via more secure means, you cannot trust service providers to tell the truth about the data they collect or store.
In short, you can't trust anyone or anything anymore. Trust is a weakness.
It seems like we should be able to progress on this front, but I haven't seen much work towards it. Trustable computers are necessary but clearly not sufficient to push back against tyranny, which is why I (like everyone else) just assume my computing base is solid (or at least not infecting the software I'm writing), while working on software to help get us out of this VC-fueled "web 2.0" trap.
This is the heuristics I use:
1) You can generally trust network equipment because there are many types of it, produced by many companies all over the world.
2) This means any backdoor in your computer that transmits information over the network would be trivial to detect and therefore useless for NSA et al.
With that in mind, the most dangerous backdoor that could feasibly exist is probably the one that subverts the RNG. Here is a discussion about a hypothetical backdoor in the hardware RNG built into new Intel CPUs: http://crypto.stackexchange.com/questions/9210/technical-fea...
The judgment revealed that the NSA was collecting up to
56,000 wholly US internet communications per year in the
three years until the court intervened. Bates also
rebuked the agency for misrepresenting the true scope of
a major collection program for the third time in three
years.
This "judgement" showed they were only collecting 56,000 emails per year? Give me a break. Even if their system for collecting foreigners' emails was actually trying to only collect foreigners' emails, I would whole-heartedly expect them to nab more than 56k/year accidentally.I think if you dig in, you'll find it's a few orders of magnitude higher.
Based on what? If the goal is just to capture all the wholly domestic communication possible, why engage in this elaborate charade of procedures that are done in secret and not publicly visible anyway?
Common sense and experience with mail servers.
One do wonder what NSA paid good money for if not for a government program which Google participated in.
I wondered if the comments in those slides about these companies "joining the program" were meant to be an internal joke. In other words, this could be internal NSA jargon for "screwed up their security badly enough that we were then able to wholesale intercept data going between their servers".
These latest revelations would seem to imply that no, it's not an internal joke.
"We won't lie to you, but we think this information should be public and if you knew what we know, then you'd be writing and calling your representative urging them to allow us to talk about it."
They could go even farther by passing judgement with the addition "... because what is being done in the name of the average citizen presents an existential threat to democracy and the betterment of a free and open society."
Being paid, combined with them getting immunity for this sort of stuff just makes the companies a whole lot more complacent about it, and much more likely to agree to giving them all the data they need, knowing that almost nothing can happen to them,as long the process is kept secret - and they probably didn't worry too much about that, because secrecy is NSA's job.
Now, when are we going to create backlash against the ISP's and carriers for allowing NSA to scoop up most of the web's traffic? Almost nobody is mentioning them in these stories, even though they play an even bigger role than the companies listed in PRISM.
The NSA could have paid for a lot of things besides "direct access to Google's data", as you claim. There are hundreds of shades of gray here.
Link: http://www.cnn.com/2010/OPINION/01/23/schneier.google.hackin...
Interesting you say that, because in the article you linked, it says this:
> In order to comply with government search warrants on user data
Can you explain this discrepancy?
http://www.wired.com/threatlevel/2011/10/ecpa-turns-twenty-f... http://en.wikipedia.org/wiki/Stored_Communications_Act
See "Perfect Forward Secrecy can block the NSA from secure web pages, but no one uses it" (http://blogs.computerworld.com/encryption/22366/can-nsa-see-...).
For example, government agencies buying "likes" from FB - seems like a perfect way to pay for PRISM participation using kosher looking transactions.
http://thecable.foreignpolicy.com/posts/2013/07/02/omg_state...
Once you've been elected to office, it should be perjury to lie to the citizens that have elected you.
NSA requires gear in a rack, NSA pays some defense contractor-integrator to show-up and install the gear. Pays for whatever telco to install a new demarc etc.
The company just needs to point to the locations and provide badge access to spaces etc.
My best guess is that the monetary loss due to this whole forceful invasion of privacy would be in order of billions (I am just guessing here; would be great if someone could point me to a thoroughly researched number though). This cost is apart from the bazillion sunk money that the US/UK Government put in to get hold data from the trunk, set up data center of NSA etc. All to just get hold of less than 50 so-called potential murderers (Avoiding the T-word!).
Looking at the cost of the whole thing and the stupidity of the presented picture, I think purpose of PRISM is already lot more than just curbing terrorism.
Personally, I think the important lesson here is to see that the barrier to entry to deploy your own cloud, of any size, is extremely low at this point.
Personally, this has galvanized me to figure out a way to help people deploy their own, secure, micro-cloud stacks with the ability to deploy your own services. I'd love to chat with HNers about this - as I believe there is a whole new market, industry opening up at this point; Fractalization of the web.
> as I believe there is a whole new market, industry opening up at this point; Fractalization of the web.
Totally agree. And it could be state-of-the-art, methinks! I'd say decentralization is of extreme importance and also a way for people to converse with static/dynamic IPs (lol).
What stack do you recommend to say a bootstrapping startup of say less than 10 people?
Clearly, any organization can leverage AWS and any number of other cloud providers.
But - if you want to build your own cloud, then I do recommend OpenStack. I also recommend that you bring external consulting to get you launched quickly where your dev-ops folks can get familiar.
go to fuel.mirantis.com to see how to get a tool that allows you to very quickly and easily put up a stack.
Also, read http://ceph.com/docs/master/start/ as this is where most people are going from a storage perspective.
Feel free to email me if you'd like to discuss more.
Thinking that I was proposing "cloud" as some new thing... Maybe you don't understand what I meant?
I've not moved out of a lot of services YET, but people around the world are certainly moving their sticks to provide options, it's now also a market, not just idealism, political positioning.. they'll arrive and I'll certainly and happily go, and maybe try taking the opportunity myself, why not? Think of a good leader, he's respected and followed because people trust him, trust him to that position, but it's a fragile thing and after it's broken, it's broken. There's a vacuum.. and naturally it's got to be filled