Live data from Hacker News

Larry Page addresses PRISM

googleblog.blogspot.com

391–400 of 482 posts

Re: Larry Page addresses PRISM

#392

Earlier quoted context omitted.

Of course it's weaseling. Maybe they disclosed such information on a slightly lesser scale. That passage doesn't say. They all said stuff about "direct access", without discussing what would and wouldn't qualify as "indirect". They didn't deny doing all kinds of different access that could be called indirect in some way.

Of course they don't deny indirect because that would be a lie. Everyone provides data indirectly via a thing called "warrants". Google publishes how many indirect requests they comply with right here: http://www.google.com/transparencyreport/userdatarequests

The thing is we can't trust any statement by anyone because of the gagging component of NSLs. I've heard it said that the above information is for FBI requests under the patriot act and doesn't include NSLs. For all we know NSL gags could explicitly forbid that kind of reporting and may even compel the recipients to lie if asked.

The last sentence he made, that the government needs to be far more transparent about what they're doing is the only sentence I can really trust as honest, especially given that the alternative to lying could be being thrown into Guantanamo for 'assisting terrorists'.

Re: Larry Page addresses PRISM

#393

Earlier quoted context omitted.

Matt - Many of us believe that many of the people at Google are doing their best, however in this instance you're not doing the right thing.

Hey teawithcarl, I appreciate that. I'd be interested in hearing what you think the right thing is. I suspect that we're actually in agreement on most points. If there's something you think we should be doing differently (and I agree with you :), I'm more than happy to lobby for that within Google. I do think Google is working hard to protect our users from unwarranted government requests. Just speaking for me person…

Hey Matt.

While I honestly think _you_ believe Google is doing "the right thing" - there's a nagging suspicion that there's some NSL-style legal (or possibly extra-legal) compulsion being used at the very top levels. Even if I believe that Larry is 100% "on my side" against the government - I'm also under no doubt that Larry and Google are effectively powerless against the pressure the various US government agencies could apply if they so chose.

While explanations of the similarity between Larry's and Mark Z's posts based on direct rebuttal of the WaPo article are plausible, when combined with Apple's, AOL's, and Yahoo's suspiciously similar structure and wording - cynical-me can't help but wonder if all 5 CEO's are being compelled to disseminate the same government supplied message (and are possibly intentionally using almost word-for-word similar language as a plausibly deniable way of telling people that).

I'm not sure if there's much Google can say or do - given the depth and seriousness of the seeds of suspicion that've already been sown… (Having said that, I was pleased to read Yonatan's G+ post earlier today…)

Re: Larry Page addresses PRISM

#394
post #34

Earlier quoted context omitted.

Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. I'm not sure how much more strongly you'd like t…

There's 2 different things going on, under different legal authorities and Google is confusing them. Verizon was given a Patriot Act order for business records, metadata; no names; no content, but all citizens or foreigner. Google and other tech companies are said to have gotten orders under section 702 of the FISA Amendments Act of 2008. That allows the government to compel communications companies to furnish lots o…

I don't see how they could have gotten an order under the Patriot Act. The section that deals with this is section 215, which amended section 501 of FISA.

It specifically states that such an order can be made "provided that such investigation of a United States person is not conducted solely upon the basis of activities protected by the first amendment to the Constitution".

If they have been violated, then there are a number of members of Congress and the Senate who are falling down on their job - the Attorney General must inform the Permanent Select Committee on Intelligence of the House of Representatives and the Select Committee on Intelligence of the Senate. On top of this, every 6 months the Attorney General must also provide a report to the Committee on the Judiciary of the House of Representatives and the Senate which details the total number of applications made for orders approving requests for the production of tangible things and the total number of such orders either granted, modified, or denied.

I've read and documented the USA PATRIOT Act on Wikipedia incidentally. Took me two years to read and understand the thing. Possibly things after the Patriot Act changed FISA, I wasn't going to spend any more time on writing up about this subject. I'm an Australian citizen, after all.

I should note that I'm not thrilled about the fact that the U.S. government can read my communications. Not that I have anything to hide, nor am I of any interest to them, but hardly the point.

The two parts to read on Wikipedia, incidentally are:

* http://en.wikipedia.org/wiki/Patriot_Act,_Title_II#Overview

* http://en.wikipedia.org/wiki/Detailed_breakdown_of_USA_PATRI...

Re: Larry Page addresses PRISM

#396

Earlier quoted context omitted.

It's exactly the kind of denial you'd expect them to issue if they were legally required to deny any involvement.

I've never heard it said that anyone was required to deny involvement. Did you mean that exactly as you wrote? I think there's a world of difference between a gag order where you are not allowed to confirm, and an order to explicitly deny involvement. I'm not saying the former is "good", but there's a difference.

OK, I'll say it.

I think there's a non-zero probability that there are US government agencies who can and have compelled people to explicitly deny something that they know is true.

Realistically, it would boggle my mind to discover they'd done that to all the founders/CEOs/legal departments of all the companies involved here (at least Google/Facebook/Apple/Yahoo/AOL), but given the stakes in this game - I have no doubt that it _could_ be done.

Re: Larry Page addresses PRISM

#397
post #189

Earlier quoted context omitted.

There are cases in which you can't even confirm the existence of a gag order. I can not believe it's constitutional... but they do it.

What about the strategy you hear about of getting around this? Where they say "we're not under a gag order" (or whatever) each day until they are, until they go under a gag order, at which point it reveals they are. Now, I'm not so naive to think that if someone tried this, the government and courts would just say "Herp, derp, you sure outfoxed us there!" But has that strategy ever been tested in court?

Rsync.net does this:

http://www.rsync.net/resources/notices/canary.txt

And they note:

This scheme is not infallible. Although signing the declaration makes it impossible for a third party to produce arbitrary declarations, it does not prevent them from using force to coerce rsync.net to produce false declarations. The news clip in the signed message serves to demonstrate that that update could not have been created prior to that date. It shows that a series of these updates were not created in advance and posted on this page.

Re: Larry Page addresses PRISM

#398

Earlier quoted context omitted.

I disagree with your definition of papers. And that is why we have Judges.

Your disagreement isn't with my definition of "papers" (we both probably agree that "papers" can easily be read to encompass both physical and digital documents). Your disagreement is with my assertion that handing your "papers" over to a third party robs you of any 4th amendment interest you might have had in those documents.

What happens with safety deposit boxes?

Re: Larry Page addresses PRISM

#399
post #284

Earlier quoted context omitted.

There's 2 different things going on, under different legal authorities and Google is confusing them. Verizon was given a Patriot Act order for business records, metadata; no names; no content, but all citizens or foreigner. Google and other tech companies are said to have gotten orders under section 702 of the FISA Amendments Act of 2008. That allows the government to compel communications companies to furnish lots o…

I don't buy it. What I quoted above doesn't say anything about US persons or non-US persons, about content or metadata, about this law or that one. It just says, Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. Now, Page may well be lying , but he definitely isn't weaseling. I'm pretty sure that denial covers both of the possibilities you're…

>>Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false.

If you consider that PRISM is not a 'dragnet' but rather an automated system that processes FISA warrants on company premises then the denial wouldn't be wrong. There is no 'scale' that you wouldn't be able to get using regular data requests to internet companies. PRISM could just make the process a lot easier for everyone involved.

So instead of sending a warrant over, having the company verify and send the data to the NSA, then finally transforming the data into a reportable format PRISM automates the whole process.

If you read some of the media descriptions it almost looks like PRISM is more of a data aggregation and portal system that sits on top of a data source and allows analysts to explore content.

Re: Larry Page addresses PRISM

#400
post #389

Earlier quoted context omitted.

Is that even possible if Google's SSL certs have Extended Validation? They'd have to have cooperation all the way down to the browser vendors and I can't see Mozilla caving that easily.

There are several governments (Spain, France, Netherlands, Japan) who publicly have Root CAs in the trusted browser list[1]. It seems pretty likely (cf say, Prism) that the NSA has a CA cert where they can generate whatever certificates they want in order to MITM browser SSL communications... [1] http://www.mozilla.org/projects/security/certs&#x2F ;

Can we remove Root CAs from our browser?

Edit: Found the answer: https://wiki.mozilla.org/CA:UserCertDB

Post reply on HN