Who Has Your Back? Government Data Requests 2015
eff.org
eff.org
Another issue here is that by looking at the past reports you see how quickly one company is the favorite and soon becomes the ugly step child. The columns with stars are also changing to what sound like very vague and lax requirements compared to the year before.
I didn't see any explanation there why. For instance they took out the "requires warrant" column. I wonder if companies are contributing to the EFF and so the EFF feels the pressure to make these companies look good in the face of this new Snowden era. For instance, isn't it great that Apple now has 5 stars as it's starting it's big "we're private" push while Google is now very low compared to previous years? And how about twitter? They used to be a poster child for good behavior as far as companies go.
When we're talking about protection against government data requests, only companies that make sure they have access to the absolute minimum client information they possible can do truly have our backs. Everyone else just has good intentions.
That's why I keep recommending tarsnap to customers.
Obviously there could be a tarsnap option to stream the data to be uploaded through an encryption program of your choice, but doing it just as you suggest would nerf a few of tarsnap's prime advantages.
Tarsnap is a combination client-side application and remote service.
I am suggesting instead to use/recommend one of the existing client-side tools that work similar to the tarsnap client does, but don't lock the user into a single service provider.
By using a client-side tool that just generates archives (and isn't tied to a single storage service provider), you can store them anywhere - AWS, iCloud, Google Drive, Rsync.net, a rented VPS, a friends computer, an external hard drive, all of the above. You name it.
Edit: I used 'specify the storage location' very loosely. I.e., I realise it could mean simply piping the archive data to yet another program in the shell.
Personally, I use git-annex, which isn't exactly a backup tool but a general distributed file manager which can, among other things, automatically make encrypted copies of the files to various places (SSH servers, S3, Google Drive, etc).
Both do dedup and encryption, Attic can also store the data remotely via SSH (either with or without installation on the remote end) and Obnam can handle remote storage to an SFTP server.
It's an almost completely transparent user-space filesystem. Basically you store your files in a given folder, and it automatically stores a parallel encrypted copy in a different folder.
http://www.howtogeek.com/121737/how-to-encrypt-cloud-storage...
Edit: sounds like EncFS has some significant security issues: http://sourceforge.net/p/encfs/mailman/message/31849549/. No recent information in that discussion, so I don't know whether it's all been resolved. Here's an HN discussion of the audit: https://news.ycombinator.com/item?id=7384730
However, until I have reason to dislike tarsnap's archiving or encryption or AWS, it's simply easier to use a single tool.
Not if you make the users password the key.
Seems like the only way.
I'm honestly interested because I'm building a distributed system where only the user has the decryption key, and I've always just assumed that password recovery is a lost cause in such systems.
I'd rather lists like these not be polluted by things like that.
- Condi Rice is on the Board of directors - an avowed supporter of NSA warantless wiretaps
- Users cannot control thier Keys such that it becomes impossible for them handover data to the Govt. even if they complied to the NSL or whatever other BS demand
And they get 5 stars for "Having our Backs" (!)
Edit: (less cheekily)
Inform users about government data demands: "...Google does not commit to providing notice after an emergency has ended or a gag has been lifted"
Disclose data retention policies: "Google publishes some information about log data and deleted data, but it is not complete and representative of all its services and thus does not qualify for a star."
Has Google gotten so much worse in the last year? Or has it perhaps stopped funding the EFF?
Edited to add citation: http://www.theregister.co.uk/2014/10/14/assange_bollocks_goo...
The following companies have gone from at least one star below Google to at least one star above Google, on a 4-6 star rating system, in the last year: Adobe, LinkedIn, Wickr, Wikimedia, Wordpress.
despite no company materially changing their terms in that time.
How is this a robust or meaningful measure, in that case? The exceptionally large variation is not addressed.
Why has this happened? In my opinion, it's because the 2014 report is bogus (two of the categories are "published a report"), and most probably it was just permitted to be bogus because Google were heavily funding the EFF in 2014.
It's perfectly reasonable for the EFF to evolve how they're rating companies as the years go on. After all, the privacy landscape changes and they're trying to push companies to making some changes. That explains the drop in stars. According to the EFF, Google is doing things that are now considered standard, and they're no longer on the forefront of defending privacy.
Your accusations of bias because Google isn't funding the EFF are, frankly, ridiculous.
If that were the only major difference, Google would still have 4 stars with the 5th undecided. Google now have 3 stars.
>Your accusations of bias because Google isn't funding the EFF are, frankly, ridiculous.
To be clear, I am not accusing EFF of bias against Google.
Other privacy organisations have literally accused the EFF of lobbying for Google. From Wikipedia:
"In 2011, the EFF received $1 million from Google as part of a settlement of a class action related to privacy issues involving Google Buzz. EPIC and seven other privacy-focused nonprofits protested that that the plaintiffs lawyers and Google had, in effect, arranged to give the majority of those funds "to organizations that are currently paid by Google to lobby for or to consult for the company.""
Since then, the EFF spoke up loudly against the right to be forgotten (Google Spain v AEPD and Mario Costeja González), even though this is considered a privacy basic by EU data protection principles.
Yes, because, again, the test criteria themselves changed.
I'd suggest your focus on a two-data-point trend and google (at the exclusion of every other company on this list) may just be revealing your own bias rather than the EFF's.
> it's because the 2014 report is bogus (two of the categories are "published a report")
again, I'd suggest actually reading the report. Several of the categories this year also only require a single line in a privacy policy. That's all this report has ever been -- some disclosures, but in many cases, just flat out statements that something will be done with no actual verification that it will be (since in many cases that's not conclusively possible).
https://support.google.com/chrome/answer/2392284?p=mobile_ba...
There's nothing there about privacy considerations. It'd be great if Google started letting users know of there are (or aren't) privacy implications.