Wikimedia v. NSA: Wikimedia Foundation files suit against NSA
blog.wikimedia.org
blog.wikimedia.org
They might be becoming increasingly disillusioned with their chosen life and/or unable to change course. Perhaps the money is too good, perhaps their contracts too restrictive. They might have inside knowledge and believe that the NSA is in the right, but they would not be able to voice that belief to us, their friends and colleagues. Unable or unwilling to change course if they believe their country is in the wrong and unable or unwilling to speak up in defence if they think it is in the right. I'd certainly like to talk (in private) to those I knew who at the start of the Snowden affair openly said that he was a traitor and hear what they now think.
There is also the possibility that they have been deluded by nationalism or propaganda in order to believe that a panopticon is acceptable in a democracy, but there isn't much we can do to help these people connect the dots between the panopticon they are helping to build and Orwellian thoughtcrime-- we simply don't have access to them that we could use to be persuasive, as you mentioned. I think this population of people is actually pretty large among the government contractors.
Finally, though you are correct that NSA employees would probably mention this, for the purposes of agencies operating in the public interest in a democracy, the concept of "insider knowledge" is not permissible. I say this not to suggest that we make all the operations of our clandestine groups transparent, but rather to suggest that the complete ignorance the American public has found itself to be in is a byproduct of intentional grooming along the lines of "national security secrets" which really are intentionally crafted backdoors to the process of informed democracy. The citizens not involved in agency day-to-day have a firm need to know the methods and rationales used, and they need to have direct and powerful oversight.
We don't have any of these things, currently.
Do we currently have the ideal balance between the need to protect our citizens and national interests, and the need to protect the rights of our citizens that our Constitution guarantees? Hell no, we obviously don't have it. Is that something most NSA employees have control over? No. You may be the one who is deluded if you think someone can just raise their hand at the NSA and say, what?, "I think we should re-think how we're doing business, because we might be infringing on the rights of everyday Americans." It's a bureaucracy. To address these issues, we need to be suggesting solutions instead of perpetually yelling at each other like opposing fans at a football game.
I don't want to live in a panopticon anymore than you do. My point is that we don't live in a perfect world, and that none of us are perfect (I hold myself up as a prime example). We need to recognize the difficult situation we've put the people who serve our country through the intelligence community; we've asked them to protect us from our enemies, but we expect them to accomplish their mission without encroaching on our privacy or violating our rights. And WE SHOULD expect them to do both; that's the nature of the job. I'm just pointing out that we should recognize and acknowledge the position this puts them in and stop demonizing them. It's counter-productive at best.
I do not accept that all of the communications of every American must be surveilled and stored in order to accomplish the mission. We need to find the right balance between security and citizens' rights. But that's not something that can be accomplished by software engineers at the NSA, nor even by the head of the NSA. We need to elect political leaders who we trust to work towards finding that balance. And we need to recognize that not only will it be an uphill battle, but a long one: we will always struggle to find the right balance between privacy and security. It's been going on since the Declaration of Independence, and I'd bet my money it'll still be going on at the quinticentennial.
Probably best to stop showing up to work at the panopticon then, you know, if you actually believe what you write. Lots of scientists fled Nazi Germany, the Manhattan project may not have happened without such people leaving.
Now lawyers argue about 'law' and due process and separation of powers yet the US government lies, spies, tortures, and murders without conscience.
I just wanted to say that people who support the NSA aren't hiding in fear. Only a small minority of people who work for the government, directly or as contractors, are ashamed of their employer or having a crisis of conscience. In general, nothing polarizes people and brings them together like an external threat. If everyone is shouting that you're bad, the most basic human instinct is to shout back even louder.
This whole thing has been a delight for management in the intelligence services. Some employees and contractors are much more motivated now. And many of those who support Snowden are still indifferent about the issues that he raised. It's either "go team!" or "eh, a job's a job." Only a minority are racked with self-doubt because of what's being posted about their employer on hackernews and reddit. Most will gladly tell you what they think, openly or in private, with no fear of criticism or backlash.
- only the "good guys" do it
- No one ever abuses it.
- Even if someone abuses it they would never just get a slap on the wrist (maybe just fired, and security clearance revoked) rather than criminal charges.
- The disincentive for abuse is "patriotism" and no one has ever decided not to be a "patriot"... ever.
- Absolutely zero people in government seek out power, or have weird ideas about controlling what other people can do or think.
- No one in the intelligence "community" would ever abuse surveillance to (e.g.) blackmail politicians for funding/votes/more power. Because every single one of them always make 100% perfect moral choices.
- It's only used for "threats to national security"... except when it isn't, but the winning the "War on Drugs"/spying on animal rights activists/making sure US companies win bids for foreign contracts/making sure that the correct politicians are re-elected really all fall under the umbrella of "National Security" if you think about it...
/s
Unfortunately, that doesn't appear to be backed by evidence. Every single lawsuit challenging mass surveillance has been resisted by the Executive on the basis of state secrets and lack of standing. The Executive is using a judicial tactic to avoid having to answer the question of whether these programs are constitutional. When that question is asked, it usually ends in the programs being illegal[1][2][3].
So if you're not afraid, would you mind answering some questions? One of the biggest problems I have right now is that your side simply stonewalls or deflects core questions thrown by my side. I would love to be convinced that what you're doing is right.
1) How are broad secret court[4] and non-court[5] orders constitutional? The 4th Amendment appears to only allow targeted warrants, so from where does the government draw this broad surveillance power? So far, the only legal defense been invoking the state secrets privilege[6], which prevents the core question from being addressed.
2) How is the DEA's parallel construction program[7] constitutional? This seems as if the DEA is not allowing a fair trail by withholding evidence from the defendant.
3) If you think the above are unconstitutional, why should they be allowed to exist? How can the rule of law persist with unclear or secret exceptions? Are there things that are more important than the rule of law? What possible impacts does this prioritization have?
I thought we should strive to live under a rule-of-law, and I feel like the Executive and their workers (including you) don't mind having a rule-of-man system. Please convince me otherwise.
[1]: http://arstechnica.com/tech-policy/2014/12/cops-illegally-na...
[2]: https://en.wikipedia.org/wiki/Kyllo_v._United_States
[3]: http://www.nytimes.com/2015/02/07/world/europe/electronic-su...
[4]: https://www.eff.org/deeplinks/2013/06/what-we-need-to-know-a...
[5]: https://www.eff.org/issues/national-security-letters
[6]: https://www.eff.org/nsa-spying/state-secrets-privilege
[7]: https://www.eff.org/deeplinks/2013/08/dea-and-nsa-team-intel...
What we should focus on is whether a government should be allowed to operate in secrecy, without any public oversight or knowledge, and whether the government can be morally justified in surveilling citizens without probable cause.
Actually, it is the problem for precisely that reason. What it boils down to is the Rule of Law. If the people at the top can do anything they want and never face any sort of prosecution, it not only sets precedent for the rest of the big wigs to act the same way (banking crisis anyone?) but it also reveals the farce in a more public way than has been true in the past.
The rule of law has never been perfect, and certainly so in America, but I feel like before the internet only the most egregious violations came to light, whereas now the farcical nature of the system is being revealed across the board. When there is an undermining of the rule of law, people will begin to completely disrespect it, and society will actually become more lawless (in the sense that people break laws willingly).
This is beyond the three felonies a day rhetoric. I think the inner city is a perfect microcosm of this.
Clapper lied to congress bluntly. He should be facing prosecution. Why isn't he? Because DOJ or whatever DA doesn't have the balls. Why don't they have the balls? Good ol boy system? Corruption? Blackmail? (you know NSA has the dirt on the entire SCOTUS and DOJ) Take your pick, the point is that the branches of government are compromised. (including the fourth estate).
If you want things to change, the very first thing that we need to do is prosecute and jail those who are undermining the Constitution and doing so in blatantly illegal ways.
Without justice there can be no peace.
Then at least it's on the books as a choice our society has made. OP's issue is there's currently no clear legal chain of certain programs back to a democratic decision.
I wonder if the system will stand uo though. The addiction to bigbdata is strong once tasted, and spy agencies actually enjoy getting away with stuff.
A handful of elites handing responsibility to a handful of FISA judges in closed/secret court is far, far a choice "society" has made.
From the norms and practices of the USG, I imagine almost everything the NSA does is perfectly legal. SCOTUS will respect the Executive in terms of its state secrets argument and Congress's leadership in handing responsibility to managing these things to FISA will also be deemed lawful.
There are two broad concepts these rest on.
First, is that many of the NSA's activities do not require court oversight in the first place, because they rest on the executive's broad powers in foreign affairs. By and large, the Constitution does not apply on foreign soil, and so the NSA does not need a court order to spy on e.g. Angela Merkel. The crucial thing to understand about the FISA Court is that it's not an attempt to take something that previously required a warrant from a regular court and make it a secret proceeding. That would be unconstitutional. Instead, its an attempt to take a process that Constitutionally requires no court oversight and inject some court oversight to ensure that the NSA stays within its foreign mission.
The second broad principle is Smith v. Maryland plus the broad subpoena power. Smith v. Maryland says that information you put in the hands of a third party is not protected by the 4th amendment. The subpoena power says that you can always be compelled to turn over information pursuant to a valid investigation. The subpoena power is very old. It predates the Constitution by hundreds of years.
The anti-NSA side generally misunderstands the context of the 4th and 5th amendments. The background rule is that the government is entitled to evidence relevant to an investigation. Heck, even private litigants are so entitled. If you're suing a company, you can serve a subpoena on a third party obligating them to turn over documents relevant to the lawsuit. The 4th and 5th amendments are exceptions to those broad powers. And in an age where everyone's information is floating around in the "cloud" where third parties have access to it, Smith v. Maryland gives the NSA a very wide latitude in which they can operate and still in good faith say their programs are legal.
The EFF, ACLU, and now Wikipedia have a whole bunch of lawyers who strongly disagree with your assessment, but they have been unable to argue these points in an adversarial court because the Executive has resisted even addressing the question. If the Executive's opinions are backed in strong legal precedent, it would save everyone a whole lot of time if they just got to those points.
1) The short version is that there is a difference between collecting information and looking at it. The NSA doesn't look at or act upon any metadata it collects without first obtaining a warrant from a judge. It just sits there on a server until government lawyers can convince a judge that evidence shows that the data is relevant to a time sensitive security matter. You may not personally believe the government when they say that, or trust that they will always get a warrant to look at information that's already in their possession. But, that's the process. As of right now, the judicial system takes them at their word. That's why the 4th amendment isn't being violated. They still need a warrant.
2) Evidence collected via parallel construction is not withheld from the defendant, just the method of obtaining it. If the DEA says "We have a tape of the accused discussing drug trafficking", that defense will be notified of that tape's existence during discovery and will be able to hear it and prepare for it before trial. It's just that the DEA won't have to say exactly how they got the tape, as not to reveal the full extent of surveillance programs. This may or may not be an unfair advantage for the prosecution, depending on the details of the case. That's why we have judges, who are in fact specialists at deciding what's fair or not fair to present as evidence during a trial.
3) The Executive, Legislative and Judicial branches of government have all weighed in on these programs and approved them in some form. That's the bottom line. You may disagree vehemently with their judgement, but this is how the American system of government works. If all three branches of the government agree that something is legal, then it's legal. Everyone is allowed to interpret the language of the constitution in their own way, but that has nothing to do with the rule of law. If you have a different interpretation than the government, vote as many of them out of office as you can and encourage others to do so as well.
I don't agree with you, but I fully support your use of the democratic process to change public policy to suit your beliefs.
That being said, we do seem to have a significantly different interpretation of the Fourth and Sixth Amendments. Hooray! We've identified a big root cause of our disagreement! It's a start.
Additionally, I do not agree that the Legislative has been sufficiently informed of mass surveillance programs, and sometimes they have even been knowingly misinformed[1][2][3].
Finally, I do not agree that the Judiciary have signed off on these programs. For the public-facing Judiciary, they haven't even been able to get to the point where they can address the legality of these programs because the Executive have always blocked with standing and state secrets claims[4][5][6]. For the secret Judiciary, it seems that the Executive has also misled them[7][8]. Also, these courts are not adversarial, which opens them up to severe bias and capture[9][10].
Thanks again for your response. Would mind giving some citations to support your positions? I've tried to cite evidence for all of my positions.
Normally, the next step is to try to think of a set of criteria that would settle the differences. Here's mine:
1. The Supreme Court rules that mass collection of domestic information by the Executive does not require a warrant (thus confirming your interpretation of the Fourth Amendment).
2. The Supreme Court rules that parallel construction is constitutional (thus confirming you interpretation of the Sixth Amendment).
What are yours? What criteria would change your position?
[1]: http://www.forbes.com/sites/andygreenberg/2013/06/06/watch-t...
[2]: http://www.theguardian.com/commentisfree/2013/aug/04/congres...
[3]: http://www.usatoday.com/story/news/nation/2014/01/14/sanders...
[4]: https://www.eff.org/deeplinks/2013/02/supreme-court-dismisse...
[5]: https://en.wikipedia.org/wiki/American_Civil_Liberties_Union...
[6]: http://arstechnica.com/tech-policy/2015/02/fbi-really-doesnt...
[7]: https://www.techdirt.com/articles/20130821/16331524274/decla...
[8]: http://www.slate.com/blogs/future_tense/2013/06/17/governmen...
[9]: http://www.theguardian.com/world/2013/jun/20/fisa-court-nsa-...
[10]: http://www.washingtonpost.com/2014/07/05/8139adf8-045a-11e4-...
rayiner is the one to go to for citations and case law. If you think that something in particular that I've said is factually incorrect, then I will gladly stand corrected. After going through your citations, there seems to be a lot of differing opinion and blame shifting regarding who said what and when. I'm not surprised that politicians and judges would say "The NSA never told me about X or Y" if the programs appear to be unpopular. If the Legislative branch is really unhappy with the NSA, they can propose a budget that cuts their funding. The Executive can threaten to veto a budget unless NSA funding is reduced. The Supreme Court can take up any number of cases, including Wikimedia's, at any time.
I'm glad that we were able to exchange ideas, but the decision is ultimately up to the political process. We'll see how it turns out.
2) Seems to be a clear violation of the sixth amendment to me.
3) You seem to be a little to black and white to me. It is possible to think that they have done the wrong thing in some cases and need to be brought back in to line but not think that we need to completely destroy the government's ability to function.
Would you care to litigate it somewhere else ?
Citation needed. Even if this is the case, then it is lucky that we developed cognitive tools that allow us to reflect on our actions and try to comprehend why those people are shouting at us in a civilised society.
It's all about the way how to have a decent discussion. If you first acknowledge that the other party has some good points (for example, acknowledge the need for the government to acquire intelligence), and use that as a basis for further discussion, you have a much better chance to get rid of that instinct and have a reasonable discussion.
Right now, as we did/do with the people of wallstreet, it's a kind of "you are either with us, or against us" discussion. No good ever comes from that.
The discussions I'm having are not with members of the NSA, they're with other people who might potentially be able to help at least prevent further criminal activity by the NSA.
It also doesn't help that most anti-Wall Street rhetoric has much in common, either intentionally or unintentionally, with antisemitic dogwhistles.
Enough of Wall Street's population is Jewish that they recognize the dogwhistling and tune out.
How can we make it so security talent has a better career working somewhere else? It could be multi-pronged. A combination of increasing private sector jobs and pay, decreasing public sector funding, and a healthy dose of public shaming might drain spying organizations of some more talent. Other thoughts?
You're never going to get open publishing / access to NSA research / infrastructure. So it's always going to be an interesting place to work.
Of the options, I think public shaming is the most viable. It's ridiculous IETF / IEEE / {insert org here} doesn't throw people out (to my knowledge?).
Given the way classified work is compartmentalized, I think any such belief would be either very narrow and heavily qualified or - more likely - mostly a matter of faith, emotion, and ego.
No grunt knows what all the grunts are doing.
In all seriousness, you can support the Federal Government and still have constructive debates.
EDIT: My point is no person is getting $75 billion just to shut up and have their opinion swayed. Being loyal to the Federal Government does not bar you from using its processes to improve its processes.
This script has already played out in the sphere of Nuclear Disarmament.
The day I take the defense and intelligence communities opinions seriously is the day they drastically change their goalposts. Spend the same amounts on world peace or just take the cash and prey on people's fear of the next ISIS or Boston bomber. Everybody knows what the easy choice is.
The National Association of Criminal Defense Lawyers, Human Rights Watch, Amnesty International USA, Pen American Center, Global Fund for Women, The Nation Magazine, The Rutherford Institute, and Washington Office on Latin America.
From: https://blog.wikimedia.org/2015/03/10/wikimedia-v-nsa/#cite_...
https://www.eff.org/deeplinks/2015/02/jewel-v-nsa-making-sen...
I'd like to see the NSA under fire from many opponents rather than just one.
As listed above, it's probably because they're already in the middle of their own[0] (assuming that they will appeal, which I'd imagine is almost certain assuming they can fund it).
The EFF has been fighting this battle long before the Snowden revelations, so it's certainly not for lack of interest that they're not a claimant in the Wikimedia case.
[0] https://www.eff.org/deeplinks/2015/02/jewel-v-nsa-making-sen...
I see the Wikimedia Foundation has a rationale for its suit based partly on United States law. It writes, "Our aim in filing this suit is to end this mass surveillance program in order to protect the rights of our users around the world." Because I edit Wikipedia in languages other than English, crucially including Chinese, I am painfully aware that there are a lot of restrictions of the rights of users of Wikipedia all over the world, evidently some of them not within the reach of the United States legal system. There seems to be no prospect, for example, of the Wikimedia Foundation suing the Russian or Chinese central governments (not even to mention north Korea's regime or the ISIS self-styled regime) to protect the rights of users of Wikipedia. That's too bad. If the NSA surveillance programs ceased later today, there would still be a lot of places around the world where Wikipedia would be inaccessible or Wikipedia users would be harassed by agents of other governments.
The land of the free should be ashamed of its mass surveillance no matter what. Even if Russia and China and whatnot continue to do it. And, the USA has much more grip on critical internet infrastructure. Therefore it makes a difference if they care.
Knowing how unpopular this opinion is here, I still feel the need to share... Lawsuits like these strike me as either incredibly naive or a cynical public relations stunt. I don't enjoy my donations supporting either kind of effort and unfortunately, will likely cease future contributions.
The NSA does not surveil domestic communications without a court ordered warrant and I have heard no arguments to convince me that this is not a legitimate use of authority. If there was a single change to the NSA that I could advocate, it would be stronger and harsher mandatory minimums for anyone found in violation of the existing prohibitions on domestic surveillance.
Oh what faith you have...
<snowden> How are things over there?
<poitras> I'm at the Guardian. They’re publishing TEMPORA today.
They are very nervous about an injunction.
<snowden> The NSA love that program.
<poitras> Why?
<snowden> Because they aren't allowed to do it in the US.
The UK lets us query it all day long.I wouldn't give up hope yet, for the anti-surveillance movement.
Basically securing against the NSA is the same as securing against hackers, it should be treated as a security threat like any other.
The NSA also holds a trump card: the law and the US government. I assume at some point that Congress will pass laws, or the secret court will authorize, compelling every American company to essentially open itself to unfettered access and surveillance. US companies already are subject to NSLs, and the Law of Boiling Frogs suggests that it's only a matter of time until surveillance is openly and explicitly compulsory.
The only long term effective way to cut this off is to cut off the NSA's budget and scale back their efforts. But I also believe that will not happen until the first ski resort opens in hell.
We're burning our own village to save it.
Regarding the weakening of crypto standards, this is why I think everyone is wrong when they tell you not to roll your own. Even William Binney (NSA whistleblower) has been saying so recently.
One of the problems is that certain countries block HTTPS (e.g. China), should wikimedia effectively block all chinese users from free knowledge that wikimedia aims to provide? https://en.wikipedia.org/wiki/Censorship_of_Wikipedia
About china, maybe only the IPs from china can use HTTP, maybe only zh.wikipedia.org can use HTTP, ...
I think legal solutions are just temporary fixes, technical ones fix the root of the problem in a more generic way.
HTTPS everywhere is a good start, but it it does a poor job of defending against the NSA. Certificate authorities are fundamentally broken and users don't have the background knowledge to understand certs or why they are necessary.
Even technical people don't understand this. The last time I saw a post about certificate authorities on hacker news, the top comment was about how most people don't want authentication, they just want encryption. You can't have encryption without authentication: unauthenticated encryption is fundamentally broken. But the user who posted the comment was ignorant of this, and enough other people were ignorant of this that they upvoted his comment to the top.
The solutions proposed also don't address the problem that popular centralized services are bound to be compromised. Even if you're sure you're connecting to Google or Facebook services over a secure connection, Google and Facebook are such high-value targets that they will be compromised by an entity with as much money as the NSA. The defense against this is also technical, but it requires a fundamental shift from centralized to decentralized technologies, and I don't think that's easy or at all ready.
> Basically securing against the NSA is the same as securing against hackers, it should be treated as a security threat like any other.
This drastically understates the attacking power of the NSA.
Even discounting that, you cannot trust your firmware, because very few people are running libreboot or equivalently free firmware. Again, backdoors galore for state agencies.
But you solve those and then you need to trust your operating system. Firstly, the vast majority of people use proprietary operating systems. Secondly, even if you use a free operating system (and I mean pathologically free like Trisquel or Parabola) you get a set of security keys included you are meant to be able to trust.
The problem is that the international governmental muscle and influence of the US Fed means it is unlikely you can protect any of these private keys. They are all held by sufficiently large organizations that the US can strongarm them into giving them up, without even resorting to immediate violence.
But I'd feel more comfortable trusting the Arch master keys or the Debian councils keys, because both organizations are multinational collaborations of individuals where the majority can blacklist a compromised member. It sure beats key management by one vulnerable company. So that might work.
It is like how people talk about all this security mumbo-jumbo but all it takes is five minutes with some brass knuckles to get you to spill every password you have ever made. With the knowledge we have and the technology at our disposal the best I can at least do is pray that my OTR conversations over XMPP are secure, given that I have tried to minimize my attack surface on all these fronts, but there is no one solution that I can say "this machine guarantees me my security" because how can I know that the proprietary firmware on my hard drive is not somehow circumventing my dm-crypt layer (it would need some kind of collaboration with the chipset, though, since the keys never touch the disk raw)? I certainly know I cannot trust any hardware encryption at the least, but I don't see anything stopping proprietary motherboards from caching the keys used during hardware SIMD encryption routines (most Intel cpus support hardware accelerated AES 128, for example) in some unseen ROM the user never touches so the NSA can crack the hard drive.
I think that the relevant essay is George Orwell, "You and the Atomic Bomb." Just as the 2nd amendment is obsolete due to modern military hardware, privacy is dead if an APT wants in.
Not that I know.
1. remain undetected over a long period of time, 2. in the face of detection they wish to preserve their anonymity, 3. not be fooled by misinformation, 4. not reveal anything of greater value to them than the value of the file, 5. not open themselves up to reprisals.
This is much harder. While the defender doesn't win short term, a resourceful defender can make the costs to the attacker high enough that future attacks are deterred, the attacker loses, or even that the defender gains more from the attack than they lose. For instance Google in responding to Chinese penetrations via technical, economic, governmental and diplomatic avenues has increased Google's credible deterrence, punished some of the people responsible and increased Google's reputation in the realm of security.
If we go all HTTPS, the NSA will just step up its pressure. Because the warrants can come with gag orders, we'll never know who's giving our data up. Hardware makers, SSL providers, data carriers, and destination servers can all be compelled by the U.S. as long as we allow it to operate as a legitimate authority over our personal data.
They're always going to have more resources until we rip up the roots they use-- government funding provided by a heavily-surveilled and terrified of blackmail political body.
Firstly - you compare securing against the NSA to securing against "hackers". This massively underestimates the reach and resources of the NSA (or any nation-state actor). You can, to a point, keep out all but the most determined and skilled individuals. You almost certainly cannot keep out the NSA if they really want to target you. Even a physical airgap may not be enough (see: stuxnet).
Your example mentioned HTTPS specifically - how does this help if they can force/compromise the host to give up their TLS keys and MiTM your connection?
Secondly - all this does is encrypt the contents of your communication - it doesn't hide who you are, it doesn't hide who you're talking to, and other metadata besides this (yes, I know metadata is at this point a painfully overused term - sadly I can't think of a good synonym right now). You significantly undervalue how important it is to hide this information from an adversary.
Right now, if a major nation state targets you specifically, you have almost no chance. You'd need perfect operational security to anonymise yourself, encryption that can't be broken by forcing a local entity to surrender the key, and to implement this every time without making a mistake. Some people have managed this, but not very many.
If you're just looking to avoid dragnet surveillance, you're in a bad place too. The information we have suggests that it's the metadata, not the content of the communications, that is stored - and very little of that is hidden by using HTTPS rather than HTTP.
None of that should suggest that HTTPS isn't worthwhile - it very much is. And there's little reason not use use HTTPS everywhere these days. But it won't on it's own protect you very much from the NSA - that's why court cases like this are being raised (though I doubt it'll achieve anything in practice).
All we have to do is convince people to use them, keeping in mind 95 percent of users use IMs such as Skype, Hangouts, iMessage, Whatsapp and Facebook Chat. Now all we have to do is get those companies to implement that encryption right? Oh wait, doing that for those companies would be illegal because the law wouldn't be on our side. Now what? Do we go back to convincing people to use obscure "darknet/used by criminals" tools that the government will do its best to denigrate? How much of a chance do you think we have to make those tools used by 80 percent of the population within 5-10 years?
The builders of technologies decided not to go that route. I wish they did, but we can't put all our eggs on the assumption that they will fix the situation for us.
Also, HTTP/2 is a horrible mess already. Encrypted channels should not be part of it. They are something separate and should be specified separately.
Wikimedia: http://m.wikimediafoundation.org/wiki/Ways_to_Give
PJ also refused on principle (AFAIU) to use PGP or other encryption on the basis that those made her (and her informants) more likely to be surveilled. I don't agree with her reasoning on this point.
Still, it's a tremendous loss.
Basically, they think that the NSA has the ability to index anonymous readers with pages visited, and anonymous editors with pages changed. Then if the NSA is sending that data to a bunch of governments around the word (Egypt, Israel, the Five Eyes, whoever else), dissidents around the world are at risk of being caught for browsing/editing Wikipedia for the crime of being opposed to the government in power.
[1] http://www.nytimes.com/2015/03/10/opinion/stop-spying-on-wik...
That's a big IF and one that will be almost impossible to prove. I don't see how the case holds any merit if they can't prove this happens.
I really doubt any legal action will change anything what the NSA does. The future is digital, they cannot and will not step down while other countries, basically everyone that is capable to do it, will do it. It's such a big power factor that it cannot be ignored.
The arms race in cyberspace has begun long ago, and there's just no way it will simply stop.
All we can do is decide how we handle it personally and whom we trust to keep our data safe. And if we really need to create certain kinds of data in the first place (with many kinds we have no choice).
This is not about you. This is not about your data. This is about our society's collective ability to think and act for itself. Blanket acceptance of surveillance is a dangerous attitude and shockingly common.
Political efforts, technological efforts, societal changes are all required to keep democracy alive. And that's what's at stake here, not your personal files. Nobody cares if you can keep those safe - I want my democracy to be safe, please.
It's also about the future of our society, that which our children have to grow up in and deal with.
I don't know how we'll be able to turn to our children in the coming decades and tell them "the government is monitoring everything you say through voice and text on your phone, every keystroke you make on your tablet or computer, every purchase you make on your phone or through your card in this inevitably cashless society, every connection you make on a connected device, everywhere your devices check in, connect to GPS or triangulate... oh and every camera you see out and about is recording you and facial recognition software is tagging it as you" with the justification for their complete lack of privacy being "there were some guys in the middle east riding around in pickup trucks with AK47s so we needed this to protect us".
We're at a pivotal point now and it's very much up to us which way it goes. Our governments are supposed to serve us but instead we live in a society where we are very much ruled, where our rulers are the elite and their ruling mechanism is the complete charade of representative democracy.
We'll all be dead before it gets too bad, thankfully, but our apathy will condemn our children and their descendants to a life under tyranny which we ushered in through theatrical politics, fear mongering and a bizarrely held belief of There Is No Alternative.
But after Snowden's leaks? It's simply something we have to accept.
Amazing how quick some people are to dismiss already acknowledged issues:
https://en.wikipedia.org/wiki/Tyranny_of_the_majority
Amongst the anti-surveillance faction, I think that a major gripe is that the feedback loops put in place to prevent a tyranny of the majority situation are being subverted, if not in the letter of the law, then in the spirit of the law.
How can elected officials have an even discussion regarding state surveillance when imperfect information abounds, and they themselves are kept in the dark from what is actually happening? That is to say nothing about the general population having a more direct say on what their government does on their behalf.
Also while the US is a formal republic, it does often emulate a democracy. Based on common belives the constitution is reinterpreted, or simply ignored. This has been well documented by legal scholars such as Richard Epstein.
I don't think you quite understand the point of anarchy.
We have historical examples of milions of people living this way.
Democracy means that your fellow citizens get a vote too. If you and those that agree with you can't craft a message that appeals to them and their day-to-day concerns, the grandparent comment will continue to be quite correct.
The citizens never asked for this intrusion and would likely have resisted if they had been, so it was executed in secret, and would have remained a complete secret if not for Snowden.
Nobody has even tried to "craft a message that appeals to the public" until AFTER the fact, when their overreach had been exposed.
A democracy generally works by citizens' issue A going to politicians B and being passed after debate to agency C which effects action D; in our situation currently the NSA has decided that it is in the best interest of itself to effect surveillance. It isn't democracy in action no matter how you attempt to spin it.
The suppression of the minority factions by the majority is always popular, which is exactly why the bill of rights exists.
they cannot and will not step down while other
countries, basically everyone that is capable
to do it, will do it
It's true that even if the NSA stopped tapping undersea cables, that wouldn't stop China doing it.But there are plenty of other things they could do. Instead of weakening encryption standards, they could work to strengthen them. Instead of trying to get software vendors to install backdoors, they could get them to use deterministic builds with release checksum transparency. Instead of developing hardware backdoors, they could develop inspection systems to find them.
With sufficient know-how and sophistication you can keep your messages private anyways no? If that's the case, then isn't it really just the average joe using off the shelf tech that's screwed?
Edit: That sounded combative, but it wasn't meant to be.
Yes, the future is digital. And yes, there will be dangers from several global parties. But why does the NSA chose to effectively weaken public communication by discovering and using security issues in known protocols instead of making sure those get fixed (if the NSA can find it, who's to say no one else can?).
With their proven effort to make everyone's communication interceptable (and effectively weakening crypto systems in all possible manners) they aren't protecting anyone, but instead putting US companies, US citizens and all global users of the web at an even higher risk.
I haven't even started on the effects on civil rights and freedom of speech of a global surveillance apparatus that is acting in secret and not under democratic control.
If it would be about an arms race, why not enforce secure crypto standards and help the industry in that regard? Clearly it's not about having more "cyber power" than China, North Korea and what have you. Instead, it's about having power on individuals, no matter where they're from.
Different technologies, but the actions changed and were addressed via politics mainly. Technologies might be here to stay, but we shouldn't expect that the way we use them as societies stay the same.
I can't disagree more. Just a few centuries ago slavery was not only ubiquitous but it was widely regarded as a god given right. Free man power was also a massive boost to economy but we abolished that just fine.
Naysayers will be proven wrong.
"Ethics and Power in the Long War" https://noisysquare.com/ethics-and-power-in-the-long-war-ele...
You're right that stopping it politically is hard:
If you look at the historical record of surveillance structures, you have never, we’ve never seen a modern state without going through a revolution or something similar, roll back deployed and operational and technical capabilities.
You can though tweak the economic cost (and I'd guess that legal process is part of that, technical measures are too):
The economics of spying is the structure that controls whether or not spying is done. The notion of return of investment is very germane here. How much intelligence product are you going to get for a given investment. That is what determines which intelligence methods are used.
That is more an issue of unflagging https://en.wikipedia.org/wiki/Wikipedia:Trust_network than worrying about who is the alpha agent. We can count fine against secret traumatic wars if we each log action, community action (with secure, stable, distributed tools like http://www.matrix.org/alpha and https://www.getaether.net), and begin to self-determine our social systems and safety issues.
[1]: http://www.welivesecurity.com/2013/10/29/survey-says-77-of-a...
Don't be an apologist for immorality just because it's accepted as the status quo. We can do better.
My argument has many parallels with existing statements by the Supreme Court that lawyers representing terror suspects could they themselves be tried under the 'material support' law for simply filing paperwork with the state to clear their client.
Remember Wikipedia's blackout against SOPA!
please post if so
But they do love to know what inspired a particular donation. So I would suggest dropping a few bucks to the ACLU and WMF's general contribution addresses, but including a note that this is why :-)
4th Amendment cases are usually litigated in the context of a criminal appeal; obviously a defendant is facing real jeopardy in a prosecution, and therefore has standing.
Civil lawsuits exist to make plaintiffs whole after suffering a harm. But the court might find that being surveilled, alone and by itself, is not harm. The court could say that nothing has been removed, destroyed, prevented, or altered in Wikimedia's servers, so they have no harm to make whole.
The court could say that merely copying data does no harm to the original data creator or holder. (This argument might sound familiar here on HN, as it is sometimes used to argue that file sharing does no legal harm to publishers.)
It would be great to start from scratch and build things without the expectation of any trustability from anyone, but I don't see that happening ever!
Sad to see that the people elected by other people like us to do good for all the people tend to do everything other than that.
> Almost all of our communication protocols and technologies are built on trust on those who run various services.
That is why we need to build and use de-centralized systems like Bitcoin, Tor and physical mesh networks to share and communicate. These evolve around people, not service providers. Of course, there's a huge difference between trusting people and trusting corporations.
> It would be great to start from scratch and build things without the expectation of any trustability from anyone, but I don't see that happening ever!
Too bad that you're not too bright about the future. A lot of people are working on fixing it. Maybe these links will inspire you to think about it differently?
I have come across these things that you have pointed out and yes they are steps in the right direction. But if you ask me if any of those will become the mainstream de-facto thing that everyone will use some time in the future? Based on the evidence available at the moment, I would still stick to what I said and maintain that it is highly unlikely given the current state of affairs. Yes, I would be very glad to be proven wrong but not enough atm to feel optimism. :)
I hope that more organizations come forward with similar suits so that we can get back on the right path.
(cross-posted to reddit because I could provide links there)
In any case, both technical and legal approaches are appropriate. And you know as well as I do that everyone at WMF desperately wants SSL for everything, and that this is a thing they are specifically working toward (but it turns out to be a bit more complicated than just switching everyone to SSL) - there is no way in which the legal approach precludes the technical approach.
I mean, you're right, this has been a problem for ages and you personally yelled really loudly and quite appropriately at them for it, and I really wish WMF had moved forward sooner. But if yesterday was the best day to act, then today is the next-best day.
Not really, -- it pushes the monitoring into active interception, which is much more costly (and thus does not work as well to hoover up everyone's data) and it is incredibly risky because it is detectable and if detected leaves cryptographic proof of the attack (and which CA was compromised or complicit with it.)
I'm all for other tools as well, which can provide protections that SSL cannot; but shuffling all the readers through Tor isn't practical today while HTTPS _is_ (as demonstrated by most of the other large web properties) and provides pretty decent protection against pervasive surveillance.
> In any case, both technical and legal approaches are appropriate.
Sure. I wanted to litigate about this in the past as well. But I am concerned that the complete failure to take the issue seriously historically weakens the claim of damages here.
> And you know as well as I do that everyone at WMF desperately wants SSL for everything
I don't know what to believe on that front anymore.
There is a simple clear metric for "want" in an institution, whats the funding level? This project has not been raised to a level of importance where its receiving line item disclosed funding, as far as I can tell. There was a plan for deployment in 2013 which hasn't been completed, https://blog.wikimedia.org/2013/08/01/future-https-wikimedia... ... and in the time since then Wikimedia has received another hundred million in funding from the public-- with fundraising running something like 17% ahead of expenditures.
> but it turns out to be a bit more complicated
Yes, it's complicated. Don't forget that I contributed to making it possible too. I'm not waxing away the technical details.
> But if yesterday was the best day to act, then today is the next-best day.
Similar things were said when I raised a similar complaint when Wikimedia posted denying providing any assistance to prism in 2013. (A position that I consider to be a lie by omission)
Continuing to deny that there is a problem here will not result in the problem being resolved.
Simply by obtaining private keys for Google/Facebook/YouTube/Yahoo/Baidu, the NSA can passively decrypt a HUGE percentage of the world's traffic. Any server encrypting for Google will need to have these keys so it's quite difficult to keep all these servers secure, and given the keys' values, the NSA would have no trouble budgeting infiltrating companies to get them.