Live data from Hacker News

Mark Zuckerberg addresses PRISM

facebook.com

101–110 of 298 posts

Re: Mark Zuckerberg addresses PRISM

#101

Look at the two writeups (Zuckerberg's and Page's) side by side. Each has 4 paragraphs. Each of the pairs of paragraphs addresses the same thing. 1st paragraph: we wanted to respond to these claims. 2nd paragraph: never heard of PRISM, don't give direct access. 3rd paragraph: each request goes through legal channels. 4th paragraph: encourage governments to be more transparent. Terrifying. EDIT: It gets worse. Here's…

Lawyer-speak tends to be consistent.

Re: Mark Zuckerberg addresses PRISM

#102
post #62

Earlier quoted context omitted.

PG made a post on Twitter about the Yahoo and Apple quotes being similar, but I initially thought it were probably due to the way the journalist asked the question. The similarity between these two does suggest something else is happening. Many people are going to jump to the conclusion that it's because they were following the same broad script, but another possibility is that they want people to notice the similari…

>>..another possibility is that they want people to notice the similarities and become more upset about PRISM. Ah, that makes sense, if they are under a gag order, but yet want to subtly convey that they are under a gag order! It would be a brilliant way of circumventing it.

That doesn't seem likely to me. If you want to let the truth be known, but you feel so much under the gun that you issue not just a minimum-compliance false statement but a fulsome one under your own name, would you really feel safe contacting a bunch of other Silicon Valley CEOs to co-ordinate such a subtle but intentional secret message?

Re: Mark Zuckerberg addresses PRISM

#103
post #62

Earlier quoted context omitted.

PG made a post on Twitter about the Yahoo and Apple quotes being similar, but I initially thought it were probably due to the way the journalist asked the question. The similarity between these two does suggest something else is happening. Many people are going to jump to the conclusion that it's because they were following the same broad script, but another possibility is that they want people to notice the similari…

>>..another possibility is that they want people to notice the similarities and become more upset about PRISM. Ah, that makes sense, if they are under a gag order, but yet want to subtly convey that they are under a gag order! It would be a brilliant way of circumventing it.

Realistically though, can you imagine there being so many CEOs knowing that this thing is going on and being forced to lie about it, and not one of them spilling the beans?

Even if the gov tries to arrest them for leaking classified information, they'd be near-impossible to convict following the inevitable massive public outcry.

Re: Mark Zuckerberg addresses PRISM

#104
post #70

I'm now just confused. If I understand it correctly, the government has publicly acknowledged the program and tried to explain how it's "limited and legal," but extant nonetheless. Now the companies are all uniformly denying it. The options: - The companies are lying. - The government has infiltrated these companies and developed backdoor access the executive team is unaware of. - The government is intercepting traff…

I may be naive but I have a theory that government officials will defend anything the government does -- regardless of whether the accusations are true.

The NSA PRISM program may not even exist, however the Obama government may be too incensed with the notion of anybody opposing government's encroachment on privacy and civil liberties, and thusly they're hastily defending and deflecting any accusations of wrong-doing.

Re: Mark Zuckerberg addresses PRISM

#105
post #41

Earlier quoted context omitted.

There is no contradiction if you accept the suggestion from http://financialcryptography.com/mt/archives/001431.html that the NSA got access to this information by planting moles at target companies who then created back doors for the NSA to use. This would be reasonably easy for the NSA to do, relatively hard for companies to catch, and perfectly explains all published facts.

Why do you need a mole? Just have someone dig up the street, and intercept the fiber optic cable. I mean you still need to deal with private keys but the NSA might have the certificate authorities wrapped around their fingers.

If the NSA was MITMing SSL communications on a wide scale, presumably the companies would notice that the cert fingerprints were not what the companies expected.

Re: Mark Zuckerberg addresses PRISM

#106
Something fishy is going on... the same message, same exact words being used.

I'm thinking all these companies are legally being forced to give up data and provide direct access to some kind of third party company, which in turn works with the NSA.

It's pretty clear Google, facebook, apple, etc. can't just come out and say they're doing this. They're choosing their words very carefully.

Re: Mark Zuckerberg addresses PRISM

#107

Look at the two writeups (Zuckerberg's and Page's) side by side. Each has 4 paragraphs. Each of the pairs of paragraphs addresses the same thing. 1st paragraph: we wanted to respond to these claims. 2nd paragraph: never heard of PRISM, don't give direct access. 3rd paragraph: each request goes through legal channels. 4th paragraph: encourage governments to be more transparent. Terrifying. EDIT: It gets worse. Here's…

Isn't a possibility just that they are using the same PR template, or that one looked at the other as they were responding? They are remarkably similar, but if you were the PR person at a company isn't that exactly what you would say as well?

Re: Mark Zuckerberg addresses PRISM

#108
If read the right way the responses could still allow for direct access to all their users data through a special API. Direct access to the server itself isn't necessary to get at all the data at will.

Re: Mark Zuckerberg addresses PRISM

#109
post #33
post #13

Earlier quoted context omitted.

The NSA have hooks in various data centers and internet backbones. They collect the intel indirectly giving the companies plausible deniability.

Yes, but how would they do this exactly? To collect anything valuable from Google they would need to MITM SSL on a large scale. And Chrome actually ships with a list of pinned certificates, including those for Google, making it difficult to MITM even for the government.

They wouldn’t do that, obviously, even if it was actually feasible. That kind of MITM would be easily detectable (though still effective, in short term)—we know when the Chinese do it.

However the private keys have to deployed, on scale. So if as someone here is suggesting the NSA has infiltrated those companies, they could have got those keys and just decrypt the stream.

I wouldn’t bet my money on that… but it’s more likely than breaking the encryption, and if they can get military secrets, I guess they could get the keys.

Also those companies could have just volunteered them—that’s where the emphasis on ‘direct’ access comes in.

Post reply on HN