Internet Giants Erect Barriers to Spy Agencies
nytimes.com
nytimes.com
> Telecommunications companies say they are denying requests to volunteer data not covered by existing law.
Existing law covers (and will cover) bulk collection. The USA Freedom Act, from my understanding, actually strengthens the legality of bulk collection without the pesky need to renew the PATRIOT Act every few years (collection queries can be based on devices, for instance... so you could collect based on iPhone, Android, or browser user agent).
I am happy that Google and other companies recognize it's in their interests to protect privacy. But until substantive legislation protects the public, we have no reason to celebrate.
(edited for typos)
But actually, even imperfect, these measures by Google in particular are very useful and important, and are laudable. These measures stop the surreptitious acquisition of data, and so at least force data-acquisition activity into the open, and make it slightly more expensive to get.
Good! The US spy agencies are too reliant on technology! The bad guys can only really be found before they strike through face-to-face social interactions, which is inherently slow and doesn't scale. Good! Justice is a human problem and deserves to be executed at human scale. If it isn't then we risk a whole raft of moral hazards, which we are already seeing.
As far as the government relying on technology, I doubt that is a battle that can be won. Laws were written with inefficiency as an obvious countermeasure for abuse. Now that inefficiency is disappearing, the laws need to be revisited and countermeasures directly written in. This will be difficult.
Google's roadblock is laudable and good, but perhaps a bit overdue. They were knowingly transmitting user data in plaintext outside of their physical control.
Google's roadblock is laudable and good,
but perhaps a bit overdue. They were
knowingly transmitting user data in
plaintext outside of their physical control.
I dunno about that.Imagine you're the engineer reviewing the design doc for the system that does cross-colo data transfers on company owned fiber. Do you really expect to see a detailed encryption system in there? Or even any discussion? I'm not sure I'd have said yes even now, much less a year ago.
I may be a minority and sound hyperbolic in saying this, but in many ways Snowden feels like something of a "9/11" for our industry: innocent assumptions we made prior (the company-internal network is safe; no terrorist would go down with the plane) just aren't true anymore..
http://www.nytimes.com/2005/12/16/politics/16program.html?pa...
Those with innocent assumptions last year had their heads in the sand, and if we're talking about Google, Apple, et al, who claim to hire the best of the best, then that's a sad situation indeed. The simpler explanation is that it wasn't a problem to them until their customers found out.
The connection runs outside your control, why would you think it would be safe? Maybe they didn't think it likely, but the threat was always present and available for anyone with the desire and resources to exploit.
Too bad those expenses are ultimately paid for by the taxpayer.
Eh? Tapping a wire is one of the easiest ways to listen in to communications. It's not like Google or MS or anyone was unaware of this threat vector, they just decided they didn't want to spend the time and money to deploy crypto on all their networks (I don't blame them, making it all work is a pain, and troubleshooting becomes more difficult, too).
And on top of that, AT&T was revealed to be splitting fibre for intelligence agencies in 2006. So in 2013 for Google or anyone to be caught unaware or call this "brilliant" is really overstating things.
What next, revelations on how Google is shocked that someone setup acoustic eavesdropping and keylogging? How this was "brilliant"?
NYT shouldn't give the NSA credit for being more than thugs on this particular thing. They've got a huge budget and apparently a fairly free legal reign. Of course they can go listen to other people.
It is significant because large companies like Google are beginning to view their relationship with agencies like the NSA as adversarial instead of cooperative. Your comparison of AT&T and Google illustrates how this has begun to change in the last decade or so.
Yet splicing into fiber-optics, especially undetected, is not the same thing at all. The americans have special-forces submarines that help them with this. Not exactly rookie stuff.
see, eg >https://en.wikipedia.org/wiki/USS_Jimmy_Carter_%28SSN-23%29
logically.
Google becoming an ISP for customers is well known, but where did they get the massive capital required to setup transoceanic fiber? (And why don't they just rent dedicated fibers on existing lines)
Advertising in internet is bound to fall due to ad blockers, it's just sensible for them to spread their knowledge and ubiquity... so if Adword profits vanish, they'll still be a profitable ISP/megacorp.
I wouldn't be surprised if some Google people came to the conclusion that ad-blocking is prevalent in affluent demographics (namely people with non-trivial technical skill) whereas 'the next 1 billion' coming online are predominantly simply not installing ad-blocking software (browser extensions/plug-ins, desktop applications, etc).
It stands to reason that this would certainly drive Google's interest in being on the forefront of 'the next 1 billion' coming online.
We already know that the NSA has the power to barge into Google's server stacks and install their little black boxes wherever they please. Ergo, if Google has your plaintext, nothing Google does really matters. When Gmail starts to use public key encryption to encode my emails at my own computer and automagically decrypts them at my friends' computers, I'll start to trust Google. That's never going to happen though, because Google needs my plaintext so they can serve me targeted ads. That is their lifeblood.
If you fear the NSA, you should still fear Google.
Please do point out how we know that.
> When Gmail starts to use public key encryption to encode my emails at my own computer and automagically decrypts them at my friends' computers, I'll start to trust Google. That's never going to happen though
So you didn't read the end of the article or see the news from earlier this week.
They have agents that work for Google. Either employees' or people who are paid very large sums of money to do the NSA's bidding.
Anyway, I don't want to make the NSA to seem like the boogie man, but from the leaked documents, they've shown that they pretty much at-will can access secure data and systems.
I believe Google has a lot of resources, and has very smart people, but the NSA is no slouch either.
Add to that, security/threat prevention is very much a game of Cat and Mouse.
Prefacing a post with "Pure speculation" especially on HN, invites a negative response by default. I would recommend providing a bit more "meat" in support of your argument, or at least provide enough detail so that commenters can assume good faith. These are only my opinions, however.
In response to your argument, I would suggest you investigate some of the specific vulnerabilities, such as in DUAL_EC_DRBG. There is evidence that particular components of certain encryption schemes have been compromised, but at least to my knowledge, use of appropriate libraries with common schemes like AES are still considered secure.
I worked for a small security startup, and our main security engineer would mention that he believed that at MSFT, there were groups that secretly worked with the government to install government backdoors in various software. He had no proof, but it seemed plausible.
Not only are there technical barriers being set-up but now a lot of companies have started to grow a spine and challenge the Govt..
Plus that "smiley" on the leaked NSA slide bragging about hacking all the big companies has VERY seriously ticked off some of the bright folks at these companies :)
I hadn't realized that Asia and Europe are countries now. I suppose the EU is at least a step in that direction.
Especially as long stretches of dark fiber tend to need repeaters, which tend to be in easily locatable places....
What would prevent the NSA from going into the ocean and tapping direct?
Forgive my ignorance, but I thought the revelation was that the NSA can routinely break encryption schemes.
Also, I thought it was against US export law to use certain types of encryption for data leaving the US.
> Or the relative difficulty of needing to use a submarine of some sort
They overcame that difficulty. The USS Jimmy Carter was specifically outfitted to be able to tap into undersea cables.
I find myself unbothered by these NSA "revelations", and I feel most are just pretending to be. It's all far from unexpected, and other governments have cynically latched onto these leaks to further their interests.
I don't care about for the heightened focus on privacy tech and policy, it's boring.
The NSA did bring it on itself though by allowing this stuff to leak out, which is the only difference between it and other nations' intelligence bodies.
There isn't much that comes out of these mass shootings that indicate a series of coordinated digital events, that typically occur for foreign groups looking to attack US interests. Instead it's the work of a single, mentally disturbed person.
Europe has a problem of citizens leaving to travel to Syria who become more radicalized. Terrorists are not all foreigners.
There's a reason why we don't replace the police forces across the USA with undeployed units from the US Army, even though it would dramatically cut costs and probably wouldn't have any immediate terrible effects. Similarly, there's a reason why you should care that the NSA is expanding their jurisdiction. In fact, their loud protests that (contrary to released evidence) they are doing nothing of the sort should be evidence enough that it's a troubling direction for them to be moving in.
> the heightened focus on privacy tech and policy, it's boring
That's your complaint? You know what else is boring? Health care policy, campaign finance reform, gerrymeandering, lobbying, and every other major administrative pathology of our society. You are correct that these things are boring but they are also the most important things to care about and to try to get other people to care about.
> The NSA did bring it on itself though by allowing this stuff to leak out, which is the only difference between it and other nations' intelligence bodies.
That, ~~~SCALE~~~, the extent to which they exert overt and underhanded influence over our political system, the extent to which they impose a chilling effect by expanding into US law enforcement, and the extent to which they can use secret courts and gag orders to order you to do god knows what.
Can you elaborate on this? I'm curious.
Governments tax, imprison, and kill. Businesses serve ads.
So when a government gets your data, they look for reasons to imprison or kill you. When Google gets your data, they try to find more relevant ads for you.
It sounds good to the rubes and may provide some protection against non-governmental interceptors, but otherwise, it won't have an effect.