"EDITOR'S NOTE: Since this story was published, The Guardian has reported that the UK intelligence gathering organisation GCHQ has had access to the PRISM system since at least June 2010 and has generated 197 intelligence reports." So other governments have a backdoor to our government's backdoor... What stops China among others from being able to access this? On the other hand, what is the truth if Larry Page is say…
> So other governments have a backdoor to our government's backdoor And we have a backdoor to their backdoor. It's fairly easy to assume that they -- state-sponsored intelligence agencies -- collude with each-other by offering access to each-other's data stores. In a sense we are all foreign to each-other, and the USG may access American data through requests acting as foreign agencies.
White House admits it has 'access' to Facebook, Google
61–70 of 95 posts
Re: White House admits it has 'access' to Facebook, Google
#62Facebook: "We do not provide any government organization with direct access to Facebook servers." Yahoo: "We do not provide the government with direct access to our servers" AOL: "nor do we provide any government agency with access to our servers." Paltalk: "Paltalk does not provide any government agency with direct access to its servers" Apple: "We do not provide any government agency with direct access to our serve…
And if they didn't say that, everyone on HN would be whining about why they didn't deny "direct access" when that was the headline accusation. Can't win with you guys.
"Can't win with you guys."
I mean, not much more you can do than just laugh at shit like this. Yeah man, everyone here is so unreasonable with their standard of "I don't like when companies blatantly lie" how hypocritical of them?
Re: White House admits it has 'access' to Facebook, Google
#63The presentation makes it seem they are harvesting the data. That would resolve any apparent contradiction. The biggest question is how? Surely google has noticed these man in the middle attacks. I think the guardian misinterpreted the word "provider". Edit: it appears the NSA has google's ssl keys. That would explain all the talk about "direct access".
Why would the government choose to use this route to get data from Google/Facebook/etc? This would require them to have to know, and be kept up-to-date, with how every one of their applications sends data across the wire.
Re: White House admits it has 'access' to Facebook, Google
#64Facebook: "We do not provide any government organization with direct access to Facebook servers." Yahoo: "We do not provide the government with direct access to our servers" AOL: "nor do we provide any government agency with access to our servers." Paltalk: "Paltalk does not provide any government agency with direct access to its servers" Apple: "We do not provide any government agency with direct access to our serve…
Re: White House admits it has 'access' to Facebook, Google
#65Earlier quoted context omitted.
How do you resolve the the fact the presentation is real, and Larry Page's statements? This is the only explanation that makes sense. Some secret court compels Google to provide their TLS keys, which is a a few kb of data. No one at Google has to know, and no one at Google can accidentally detect the leak. Also, can you clarify for me why you think giving someone access to eavesdrop overlaps with "direct access to se…
Could it be that the presentation describes targeted surveillance? PRISM may just be a program to standardize a process and the type and format of information returned.
The slide about how traffic is routed through the US is really telling. This program works because there is access to the packets.
Re: White House admits it has 'access' to Facebook, Google
#66The presentation makes it seem they are harvesting the data. That would resolve any apparent contradiction. The biggest question is how? Surely google has noticed these man in the middle attacks. I think the guardian misinterpreted the word "provider". Edit: it appears the NSA has google's ssl keys. That would explain all the talk about "direct access".
Re: White House admits it has 'access' to Facebook, Google
#67The presentation makes it seem they are harvesting the data. That would resolve any apparent contradiction. The biggest question is how? Surely google has noticed these man in the middle attacks. I think the guardian misinterpreted the word "provider". Edit: it appears the NSA has google's ssl keys. That would explain all the talk about "direct access".
Network dumps would seem unreasonably difficult to deal with considering that the provider has structured data and tools to deal with it.
All you have to do is read session cookies. Once you have that, you are done.
Re: White House admits it has 'access' to Facebook, Google
#68Facebook: "We do not provide any government organization with direct access to Facebook servers." Yahoo: "We do not provide the government with direct access to our servers" AOL: "nor do we provide any government agency with access to our servers." Paltalk: "Paltalk does not provide any government agency with direct access to its servers" Apple: "We do not provide any government agency with direct access to our serve…
Those statements are probably true. The NSA has probably subcontracted the operation out to a private corporation. So Facebook, Google, et al, don't deal directly with the government, they deal with the private company.
and don't tell me that hasn't happened before.
Re: White House admits it has 'access' to Facebook, Google
#69The presentation makes it seem they are harvesting the data. That would resolve any apparent contradiction. The biggest question is how? Surely google has noticed these man in the middle attacks. I think the guardian misinterpreted the word "provider". Edit: it appears the NSA has google's ssl keys. That would explain all the talk about "direct access".
Why would the government choose to use this route to get data from Google/Facebook/etc? This would require them to have to know, and be kept up-to-date, with how every one of their applications sends data across the wire.
It is the only way to get access to the data without requiring a vast conspiracy. If they had direct access, thousands of employees would know something was up. If they MITM, then lots of people would notice. If they had a way to actually break TLS, then there would be no slide about "providers".