Live data from Hacker News

Mark Zuckerberg addresses PRISM

facebook.com

151–160 of 298 posts

Re: Mark Zuckerberg addresses PRISM

#151
post #80

I would like to believe these reports from Google [1] and Facebook [2], but someone is not telling the truth. There is evidence that directly contradicts their stories (i.e. The Guardian has verified the authenticity of the document, a 41-slide PowerPoint presentation – classified as top secret with no distribution to foreign allies – which was apparently used to train intelligence operatives on the capabilities of t…

One thing that has bothered me is that neither the Guardian or the Washington Post (someone kindly post the link if I've missed it) has posted more than just a few slides of this 41-slide presentation. I understand the leaker may want as few of slides as possible shown due to the danger of them being watermarked, but the few slides posted so far alone seem to lack important context. Secondly, in defense of the compan…

Implicit confirmation that the programs described in the press are real and as described goes all of the way to Obama himself. For example he responded to a reporter today by saying, "With respect to the Internet and emails, this does not apply to U.S. citizens and it does not apply to people living in the United States."

If the programs were not as described, Obama would have certainly said so. Instead he confirmed their existence without disagreeing with what was said in the Washington Post about it.

Given that, there is good reason to believe the substance of the leak, even though we don't know who leaked it or exactly what is in that presentation.

Re: Mark Zuckerberg addresses PRISM

#152

Earlier quoted context omitted.

We see Eglin's sockpuppets all the time on reddit, they are actually pretty easy to spot.

The airforce base has sock puppets?

I think he's talking about this: http://www.guardian.co.uk/technology/2011/mar/17/us-spy-oper...

and citing this http://blog.reddit.com/2013/05/get-ready-for-global-reddit-m...

where it shows:

Most addicted city (over 100k visits total) Eglin Air Force Base, FL

Re: Mark Zuckerberg addresses PRISM

#153
post #75
post #65

Earlier quoted context omitted.

Google's statement was strong enough to rule out the possibility that either the CEO or chief legal counsel was aware of the existence of NSLs or warrants that are nearly as broad as what Verizon received. Therefore, while they can't say one way or the other whether they receive NSLs, it is a safe inference that Google has not received broad NSLs.

Yeah, I'm wondering if "someone down the chain in Gmail got NSL'd" is a possibility or not. I'm not familiar with Google's org chart nor do I know if NSLs are even flexible enough to accomplish such a thing. If it is possible though, there could perhaps be an NSL that covers "just gmail" that is otherwise as broad as the Verizon one. The notion that a CEO could be unaware of something like that happening is incredibl…

It's not uncommon for an NDA to name specific individuals in company A which could use proprietary information from company B to add features which would be useful to B into company A's product.

The covered persons in A would be just enough to appropriate the necessary budget and deliver the features.

When the VP of Engineering or CEO asked, 'why did we add this particular feature, what's the use case?' the answer was, "If it's business critical that you need to know, we would need to document that and see if you can be added to an NDA."

"An NDA with who?"

"I can't say."

NSLs take this to an entirely different level. Page and Zuck don't have a clue. As soon as the databases were large enough to be useful, the data was in the hands of the NSA. That much should be taken for granted. The more important question has always been "if and how can it be used against you?"

With Obama claiming it's legal and approved by 3 branches, and how widely outside the NSA the data will be shared, the reality of "show me the man, I'll show you the crime" has never been truer.

Re: Mark Zuckerberg addresses PRISM

#154
post #123

Look at the two writeups (Zuckerberg's and Page's) side by side. Each has 4 paragraphs. Each of the pairs of paragraphs addresses the same thing. 1st paragraph: we wanted to respond to these claims. 2nd paragraph: never heard of PRISM, don't give direct access. 3rd paragraph: each request goes through legal channels. 4th paragraph: encourage governments to be more transparent. Terrifying. EDIT: It gets worse. Here's…

The implication that there is some central figure behind this giving these companies scripts to read meets the most common flaw of governmental conspiracy theories. It requires the government to be simultaneously incredibly competent and incompetent. If the NSA was able to keep this project under wraps for so long with the number of people involved, I think they would be smart enough to at least slightly alter the wo…

>The implication that there is some central figure behind this giving these companies scripts to read meets the most common flaw of governmental conspiracy theories. It requires the government to be simultaneously incredibly competent and incompetent.

Which is exactly what governments are.

Extreme resources, very smart people, and very idiot people, incompetent bureaucrats, messy cover-ups, all co-exist, all the time.

What did you thought they were? Incredibly competent XOR incredibly incompetent? (Only the first would be a conspiracy theory, whereas only the second would be gross underestimation).

>If the NSA was able to keep this project under wraps for so long with the number of people involved, I think they would be smart enough to at least slightly alter the words of their puppets, after all this is supposed to be the area of their expertise.

You've never seen badly (or too fast) done spin work?

Not to mention, why would the NSA care to spend too much effort to how those things were phrased?

If you think it matters, I'm afraid, you give the American public too much credit. It's not like it's gonna get suspicious by such small and peripheral signs. Listening to and accepting bad arguments, BS excuses, fake promises, and shit from politicians if what people are doing all their life.

And it's not even like they're gonna do anything about the core situation with regards to privacy. It's just the "hot topic" of the day, to be forgotten for some BS next week. You surely don't expect some kind of revolt of anything? If that was to be, it would have been at the other 20 similar media expositions or against the horrible laws that have been passed openly.

Re: Mark Zuckerberg addresses PRISM

#156

Earlier quoted context omitted.

If the NSA was MITMing SSL communications on a wide scale, presumably the companies would notice that the cert fingerprints were not what the companies expected.

I didn't say MITM. I said redirecting/copying traffic to spy on it.

That would mean they've broken TLS which, whatever powers the NSA supposedly has, seems unlikely.

I don't think they would be intercepting SSL traffic either, because Google has a hard enough time legitimately updating their certificates [1] that I imagine if the government were doing it on a wide scale people would definitely notice.

[1]: http://googleonlinesecurity.blogspot.com.au/2013/05/changes-...

Re: Mark Zuckerberg addresses PRISM

#158
post #134

Earlier quoted context omitted.

>>..another possibility is that they want people to notice the similarities and become more upset about PRISM. Ah, that makes sense, if they are under a gag order, but yet want to subtly convey that they are under a gag order! It would be a brilliant way of circumventing it.

Someone correct me if I'm wrong, but you can admit to a gag order being placed on you. As in, FB and Google would be totally entitled to say "there is a gag order preventing us from going into this". So they don't need to convey anything.

No, they can't admit if there's a gag order in place by the NSA.

Re: Mark Zuckerberg addresses PRISM

#159
post #114
post #41

Earlier quoted context omitted.

There is no contradiction if you accept the suggestion from http://financialcryptography.com/mt/archives/001431.html that the NSA got access to this information by planting moles at target companies who then created back doors for the NSA to use. This would be reasonably easy for the NSA to do, relatively hard for companies to catch, and perfectly explains all published facts.

If moles are involved, they might have simply leaked the private SSL keys. If used together with MITM this would be almost impossible to catch.

This. I imagine that an agency with the resources of the NSA could probably work out a couple of ways to obtain almost any private key they want.

Re: Mark Zuckerberg addresses PRISM

#160
post #67

Earlier quoted context omitted.

Every single official corporate response in this story so far was formulated using the exact same terms, and did not constitute an actual, categorical denial of the claims. We have not giving "direct access". We are providing the government with our data through "legal channels".

Like someone in the other thread about Pages blogpost asked: What could Zuck say more to convince you otherwise? He says explicitly Facebook is not providing information or metadata "in bulk", which seems to contradict the Guardian article ("direct access").

He says:

  We have never received a blanket request or court order from 
  any government agency asking for information or metadata in bulk
Not that they don't provide information in bulk. The next paragraph comes closer:

  When governments ask Facebook for data, we review each request
  carefully to make sure they always follow the correct processes
  and all applicable laws, and then only provide the information 
  if is required by law.
Which in an ungenerous reading leaves plenty of wiggle room. eg, "When governments ask", not "When governments order us".

Personally, I believe Larry and Zuck, but the statements themselves are really weird.

Post reply on HN