Facebook, LinkedIn, Yahoo, Google, Microsoft disclose data about NSA requests
thenextweb.com
thenextweb.com
Watch this hand, which is issuing specific requests for data.
Ignore the other hand that was snooping on (until Google started encrypting last year) Google's inter-datacenter links, almost all Yahoo! traffic since they only enabled ssl for non-premium accounts last year, most Hotmail/Outlook.com traffic since their defaults had ssl disabled until recently (last year?), and anything else we can (everything of interest that's not encrypted or that we can break[1]).
Ignore that restrictions on spying on our own citizens are weakened since they're not citizens to the other 4 "5 eyes" countries, and in some situations they can share back that data or they can query it for us.
Ignore that we don't consider collecting metadata on phone calls to be a 4th amendment violation. Because knowing if you called Bill Ayers or an abortion clinic or an HIV clinic is not private personal data at all.
Ignore that the data we collect, although nominally for national security purposes, is being used in criminal prosecutions having nothing to do with national security, and that we encourage law enforcement agencies to use "parallel construction" to avoid revealing the true source of the data that jumpstarted their investigations. Since we've been caught doing this, the Dept of Justice is now revealing in court when this occurs, but please ignore that these domestic criminal cases may not have been possible at all without the mass data collection we do for "national security" purposes.
Ignore our attempts to compromise internet infrastructure and subvert public cryptographic standards.
Ignore that the DNI lied to Congress. Ignore, ignore, ignore.
[1] RC4 maybe; see https://twitter.com/ioerror/status/398059565947699200
It's reached the point where Google defenders on HN need to state their employer, given the evidence we now know it's ridiculous.
I wouldn't believe this statement anymore than I'd believe the one of any other common criminal. Everything they say fits some kind of agenda.
OTOH, I'm surprised Google, after being the victim of known hacking by an intelligence agency (in pursuit of a religious extremist group, presumably), consisting of malware, targeted malware/spearphishing, attacks on staff (presumably inserting trusted staff into Google in various roles), etc., didn't include bulk encryption within its network as a way to compartmentalize things.
They certainly pulled out of the world's largest Internet market, locked down their employee workstations across the board (essentially banning Windows, IIRC), adopted 2FA internally, and generally have better internal security than banks or virtually any large enterprises. On the customer-facing side, they're leading in cert pinning, "ssl everywhere", etc. So not doing bulk encryption between datacenters was an oversight -- it's technically expensive to implement, which was probably a major factor.
(In case it's not obvious, this isn't Google v NSA)
You mean this?
http://www.washingtonpost.com/business/technology/google-enc...
The USgov/NSA thinks we're fools. This range tells me nothing. I can assume the worse and conclude they send 999 requests every 6 months, but then I'd be a conspiracy-nutcase. They know what they're doing. Ed Snowden's data is more valuable to the public than this PR stunt. If there are anymore of you people out there with info like Snowden considering doing a leak, please do it. I understand it's a very personal decision to kinda ruin your life and be unable to support loved ones around you; that's something only you can decide.
But if what's holding you back is "duty to your country", look to Ed Snowden. His actions gave true duty to the country... and the world.
These reports are useful only in that they show how much the company is in bed with the government versus how much they're just getting abused. You don't see these types of reports from the phone companies, for example, because they've been helping the government snoop for years.
And yet, so far, nothing, not an announcement, a rumor, a hiring ad, nothing, nothing, nothing.
Arguing that {Google,Yahoo,Facebook,LinkedIn} should implement secure communication is equivalent to arguing that they should shut down their existing products in favor of secure client-side implementations. The moment they do this, the resulting product gap will be filled by some other company and nothing will have changed.
The corollary is that any web-based service that claims to offer secure communication is almost certainly not doing anything of the sort, and should be treated with great suspicion.
Web software is convenient, for sure, but it isn't so difficult to run ad-supported services with client-side software.
It's trivially easy to configure a local Gmail client. Install Thunderbird, type in your username and password, and you're good to go. The result is a Gmail experience with an excellent UI, no ads, and the user is running only open-source software.
Installing the Enigmail extension, GPG, and generating a GPG key provides a secured communication channel. The user need only tick a checkbox to send emails that are impervious to known interception methods.
Thus it's already possible to use Gmail for secure communications. No changes on Google's part are required to enable secure emails in Gmail. So what are you actually asking for?
It sounds like what you're saying is that Google ought to shut down the Gmail web UI because you don't think hosted services are sufficiently secure. But the thing is, almost nobody (excluding HN) actually cares. If Gmail moved to a secure model tomorrow, it would be effectively the same as shutting down the service because the userbase would migrate to Yahoo or Hotmail overnight. What benefit has the new "secure" Gmail then achieved?
You are setting up some straw men for demolition. As Skype showed, before it was nerfed, there is no need for a client interface, especially a mobile client interface not to support security that is so easy that it is equivalent to an unsecured product.
> If Google or any of the other services had their own
> client that properly integrated with back-end services
> like key exchange, key signing, etc. you would not have
> to understand and implement identity verification yourself.
If key exchange and verification were handled by a third-party service, then a compromise of that service would threaten the security of all communications. To be secure, key exchange and verification must be handled offline at the level of individual users.Pre-acquisition Skype was not a secure communications system, any more than iMessage or Hangouts are today. If you believe it was, then you have not spent sufficient time considering how to compromise such a system.
Also, Skype in unlike iMessage or Hangouts in that messages traversed nodes that could capture and attack traffic. Skype had security requirements these other services did not have. A modern, verifiable service could be built that, to end users, resembled Skype in simplicity. Or, for that matter, Hangouts could open source their client and enable verifiable security that, to the end-user, would be no more complicated than using Hangouts is currently.
So with 1%, they mean that over 10 freaking million Facebook users were under surveillance?
Let me try it: Let me run code to sieve through every politician mailbox. I won't go after all of them, so only a handful will be "impacted" on.
And this is only first-order of impact. What happens with second order impacts when a mail account by a person like Jacob Appelbaum is "impacted"? Is every dissident that emailed in danger, and what if their organization is not in favor of current US politics?
Given the number of virtual servers they have in the cloud right now, the amount of corporate data stored and passing through those, and the NSA's interest in SSL, I would REALLY like to know where Amazon stands.
This is PR stunt..
Btw: How can I boycott NSA and still use the Internet?