White House Takes Security Pitch to Silicon Valley
nytimes.com
nytimes.com
Right, because what they're doing in the cyber domain isn't lawful. Naturally they'll fix that retroactively.
> He urged the next generation of software pioneers and entrepreneurs to take a break from developing killer apps and consider a tour of service fending off Chinese, Russian and North Korean hackers...
Yeah, exploitation of vulnerability isn't partisan or nationalistic. While narrowly possible, it isn't really practical to fend off Chinese hackers without also fending off American ones, and vise versa.
> ...even as he acknowledged that the documents leaked by Edward J. Snowden, the former intelligence contractor, "showed there was a difference in view between what we were doing and what people perceived us as doing."
I can't help but picture these hacks that shill for the administration like cheaters who've been caught trying to talk their way out of it.
"Baby, I know I said I was visiting my grandma last night, and while I admit that leaked photograph of me kissing and groping my former lover is authentic, I swear to you it's not like that! The kiss had to be collected in case it was needed in the future but it's not cheating because I wasn't feeling into it at the time. You've got to understand there's a difference in view between what we were doing and what people perceived us as doing. I lied to keep you safe! Think of the greater good baby!!"
That one boggles my mind. On 2013, Mar 12, Clapper lied to congress about NSA spying. The purpose of a lie is so that people perceive something different from reality. So they achieved their goal, they're just sorry they got caught.
Now, you know I love you. I would never do anything behind your back. That's why all of your friends were fully briefed on this encounter. And they all agreed that it was necessary and appropriate. Well, almost everyone. I vow to bring the perpetrator who leaked the photo to justice! And so in light of this, we can have an important debate about who else I deny I have slept with, who else you have proof I sleep with and what other sexual acts I must do with them in order to safeguard our relationship.
But let's not forget what's important. We need to work together to build a framework for a process where I continue to see others I'm attracted to, particularly the Russian and Chinese ones, in a way that respects privacy, by preventing you from finding out, but with proper oversight that is transparent, accountable, and consistent with my unwavering support for monogamy. After all, the security of our relationship depends on it.
and got away with lying to congress.
Everyone should learn from Clapper's example, when they're in front of a judge, court, or other tribunal.
He can't address it beforehand if the admission of its existence is classified. By addressing it beforehand and saying "you can't ask me this question" he indicates its existence.
I don't know if we are permanently moving past the Westphalian nations state, but there does seem to be quite a fluctuation going on. Due to our own government's actions and serious, deep breaches of trust, our own government is becoming a threat to a whole sector of society and the economy.
I thin the question is how the government will react if it gets nothing but the cold shoulder that it should due to its own behaviors. Will it change its ways and learn how to deal with a new reality, a new world; or will it lash out and take an aggressive approach to infiltrate, disrupt, sabotage, and co-opt the tech community and graduates for its deceptive and rather nefarious antiquated and rather fascist intentions? I think history projects that the latter is far more likely than the former without significant civic intervention, but we will see.
People are more connected to each other across the world than before. The government is not the only body with multinational links and multinational information coming is as part of everyday life. The 'othering' of people in other countries no longer so prominent. We care a little less about our own country compared to the wider world.
And yes, the government has totally, thoroughly earned our distrust and disrespect in this field. Almost any new security work assumes not just hackers as its threat model, but pervasive network monitoring and compromised service-providers at every level.
New security systems, created by freedom-minded individuals - not terrorists, not criminals - actually count the government as a direct threat.
This is quite a big thing...
I'd say that the government isn't aware of the postnationalist movement because it's really quite a small group of people overall, and there aren't really any actionable goals or organizational structures that these people have rallied around. If there were post-nationalist groups getting into political advocacy etc, I assume we'd see a strong pushback and propaganda-based reiteration of the good old "American Values" to rile up the proliteriat.
In general, the government doesn't like getting the cold shoulder, and treats its behaviors as always justified. I'd put my money on aggression. After all, they already have JTRIG groups whose purpose is to infiltrate and disrupt political groups.
This is pretty much the EXACT thing that is the problem. Let's be clear and unified on this topic: this is NOT a difference of "perception". This is a fundamental question of whether we're going to live in a democratic republic or not.
I remember when my small private university received its first DOJ request in 2005 to install wire-tapping hardware on our servers. We in the IT department circled up and met, deciding to ignore this letter as a disgrace to the American public, the constitution, and the human values we believed in. Even receiving shamed us, and stirred anger and fear for years after.
When we ignored it, no request came again and no consequence -- because the people who asked us to do wrong would never ask us to do it again by the light of day.
Remember: stand true to what is right for you and those around you, whether in private or in public, and you'll never regret that choice from this day to your last.
This is just an example of how government stupidity when it comes to computer security is leading to MORE vulnerability and insecurity.
You did the right thing if dragged into court you could have rightfully pointed out that you refused for patriotic reasons since the whole thing "smelled" wrong and sounded like an attempt by foreign bodies to infiltrate your network, which would have got you into alot of trouble...
I wonder how the likes of Googles of this world response to similar requests...
If you're big enough fish, you will be caught either with a lure or a net.
[1] http://www.washingtonpost.com/blogs/the-switch/wp/2013/09/30...
http://www.nytimes.com/2002/03/29/business/enron-s-many-stra...
Or why they had to restate $550M in revenue and then take $11 billion in writedowns from overvalued assets..
http://www.deseretnews.com/article/945565/Qwest-plans-to-res...
Good luck with the convincing. Quite a few of us can read, so it will be rather impossible.
> The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized. http://en.wikipedia.org/wiki/Fourth_Amendment_to_the_United_...
> Shortly after the terrorist attacks on Sept. 11, 2001, President George W. Bush secretly told the N.S.A. that it could wiretap Americans’ international phone calls and collect bulk data about their phone calls and emails without obeying the Foreign Intelligence Surveillance Act. http://www.nytimes.com/2015/04/25/us/politics/value-of-nsa-w...
> On July 9, 2012, when asked by a member of the press if a large data center in Utah was used to store data on American citizens, Alexander stated, "No. While I can't go into all the details on the Utah data center, we don't hold data on U.S. citizens."
http://en.wikipedia.org/wiki/Keith_B._Alexander#Statements_t...
Why are these people not in prison for violating the constitution on a mass scale? Their only defense can be that they were simply "following orders."
The USA PATRIOT Act will be viewed by historians as something akin to the Reichstag Fire Decree http://en.wikipedia.org/wiki/Reichstag_Fire_Decree#Backgroun...
None of that matters if the evidence collected is never intended for criminal prosecutions. Either by the FBI or by the NSA.
At least one of Boston's federal judges serves on the FISA court and I have it on the word of Boston's clerk of court that the FISA court judges care deeply about doing a good job and being a check on executive overreach. I believe him. But that doesn't matter at all.
[1] Everyone should read http://lawcomic.net/guide/?p=1585 and actually look at this flowchart for the 4th amendment http://lawcomic.net/guide/?p=2256.
[2] Most warrant requests are granted, not because it is a rubber stamp, but because the conditions for warrant approval are predictable and judges don't like having their time wasted with dumb requests. It's not like the patent office.
No deal. There is another way. I'm sure many in tech would take up the gauntlet of protecting all people if it were to be executed in a way that fits with the ideals of those people - which coincidentally align pretty well with what the US Constitution and Bill of Rights put forth 223 years ago.
If the US wants security they can have it. If they want to continue to expand the military industrial complex, they should go looking elsewhere.
I don't exactly trust the policy positions of the handful of major corporations that rate on the White House's radar to be beneficial to the end user/society in general.
You had one chance and choice on 9/12/2001, government; and you chose to play right into the hands and goals of the tactic of terrorism ... turning on your own people and sacrificing your principles at the cost of vanquishing the tenuous and feeble trust civil society had placed in you.
Maybe you will be successful in steering the massive ship and changing perceptions and molding society as you have before in the past, government. But for now, there is a lot of trust to be made up through apology, action, and prosecuting perpetrators, i.e., showing that your actions are not just more empty promises and lies that any other run of the mill addict uses to avoid accountability for their actions and impacts on those in their lives.
If you're up to not good you're just going to download a non-backdoored encryption toolkit from somewhere else.
Good point. Software is made all around the world and there's no way for USA government to force it's backdoors (call it "golden key" or whatever) into all of it, especially in the age of open source. The purpose of wiretaping consumer grade software is clearly monitoring and controlling of casual citizens, not fighting serious criminals, hackers or enemy cyberarmies.
A law that required the use of "approved" encryption necessarily bans real encryption tools. Anybody that is actually secure is made a criminal, which is one more law that can be enforced arbitrary if someone decides you are a problem.
It should be fairly easy to filter for non-approved encryption with DPI. This gives them a nice map of all the "subversives" that are trying to evade the "monitoring and controlling of casual citizens".
Step 1, make this first point true at least (the second and third points will probably be debated until the heat-death of the universe).
Quite heartened by the rest of the article though; techies standing by their principles.
Funny principles, those.
Ads, privacy violations, more ads, dark patterns, some more ads.
You mean there was a difference in view between what you said you were doing, and what your leaked internal documents SHOWED beyond a shadow of a doubt what you were actually doing and planning on doing.
Do these guys not know their audience?
(at least that's how I read it as a tech guy)
"Expressing sympathy" means absolutely nothing when concrete actions have been taken to undermine privacy and security.
I hope that the tech industry can organize around resisting the government to provide security and privacy for their users.
The more robust anti-spying measures we have, the more secure we'll be from malicious actors who would use our communications against us for their own gain.
It'll break eventually.
For all countries X, the government of X is absolutely untrustworthy.
>The computer industry is seeking to block surveillance, including by the N.S.A., which fears “going dark” on terror threats.
I find something about the use of "the computer industry" to describe Google et al be really quaint. It's understatement. Also, what industry doesn't depend on the computer industry these days?