Live data from Hacker News

Why didn't tech company leaders blow the whistle?

mailman.stanford.edu

31–40 of 91 posts

Re: Why didn't tech company leaders blow the whistle?

#31
post #26

Earlier quoted context omitted.

Because, outside US, government agencies and companies that considers their communication security critical will choose another provider. They are paying Google Apps, Microsoft 365, etc.

Would anyone (especially from a foreign country) who considers their communication security critical really be using any of those services today?

Yes. Obviously not the most sensitive ones but there are a lot of government operations using their services.

Re: Why didn't tech company leaders blow the whistle?

#32

Blow the whistle on what? The problem with the "conversation" going on in these threads is that no one is defining that first. If we're talking about the first leaked version of PRISM, we still don't even know if it exists or how it works. Subsequent revisions have made it seem that if the NSA doesn't have the immediate ability to query the companies' backends, then they have some kind of carte blanche ability to ask…

[deleted]

Re: Why didn't tech company leaders blow the whistle?

#33
post #9

Earlier quoted context omitted.

... and shareholders who care more about profits than morals I think this issue goes against shareholders because they can lose real customers feeling defrauded. It's realistic to expect legal actions against Google/Microsoft/etc operations outside US, mainly for Government accounts.

What makes you think these companies are going to lose any substantial number of customers? Most of the anger here is directed at the government, and it is only a small minority of people who even are angry about this. Only a very tiny minority of people will actually stop using Google or Facebook because of this incident.

In the short term nothing will change for Google, Facebook etc. But i think you are underestimating the longer term reaction from members of this community. The cloud in its current form is dead. Google's goal of collecting the world's information is a dead end if everything ends up in the hands of the NSA. New user data models with better privacy will eventually be introduced by one or more startups that could be a treat to Google and co.

Re: Why didn't tech company leaders blow the whistle?

#34

Blow the whistle on what? The problem with the "conversation" going on in these threads is that no one is defining that first. If we're talking about the first leaked version of PRISM, we still don't even know if it exists or how it works. Subsequent revisions have made it seem that if the NSA doesn't have the immediate ability to query the companies' backends, then they have some kind of carte blanche ability to ask…

I'm just not sure there are easy answers in any direction here. Should they have the program at all? If they should, did they choose the right parameters? If the parameters are right, is the oversight adequate to both preventing misuse of these undeniably broad powers and making the rest of us feel like it is still, in the end, our government? Who should make each of those decisions? Given democratic uncertainty over whether all the forgoing are within spitting distance of 'correct' (whatever that means), what is any individual actor's responsibility -- even assuming he has full knowledge of the program -- to undermine most of those decisions when he feels it's wrong? How wrong would he have to feel it was, and on what axes?

Re: Why didn't tech company leaders blow the whistle?

#36
post #19

For the post linked in the headline, those seem like shocking accusations, but the kind I'm now accustomed to taking with a grain of salt. It seems perfectly plausible that the guy legitimately deserves a 6 year sentence for reasons unrelated to any of this. As for the subject/headline, which I'm not sure is related to the particular post linked, it seems pretty simple. Tech companies would probably see PRISM with mu…

This whole post is unwarranted assumptions about the extent to which companies illegally violate their privacy policies. Their are plenty of disgruntled ex-SREs like Rachel who would love to blow the whistle if anything close to what you are suggesting ever happened.

Re: Why didn't tech company leaders blow the whistle?

#37
post #16

Earlier quoted context omitted.

Well it's a real (if secret) court, so I assume it would be what normally happens for contempt of court.

It's my understanding that the secret court ruled the primary legal justification for PRISM (FISA Section 702) as unconstitutional. The Justice Department is trying to keep that ruling as secret as possible. [1] So, really, what would they do? [1] https://www.eff.org/deeplinks/2013/06/government-says-secret...

How can they rule the justification as unconstitutiona when the judges were giving court orders under that justification?

More broadly though, I don't understand how you can possibly have secret courts. Justice not only must be done but must be seen to be done, otherwise its not justice.

Re: Why didn't tech company leaders blow the whistle?

#38

Earlier quoted context omitted.

It's my understanding that the secret court ruled the primary legal justification for PRISM (FISA Section 702) as unconstitutional. The Justice Department is trying to keep that ruling as secret as possible. [1] So, really, what would they do? [1] https://www.eff.org/deeplinks/2013/06/government-says-secret...

How can they rule the justification as unconstitutiona when the judges were giving court orders under that justification? More broadly though, I don't understand how you can possibly have secret courts. Justice not only must be done but must be seen to be done, otherwise its not justice.

I'm not a lawyer, but I believe they declared only part of FISA unconstitutional. The part they declared unconstitutional happens to be the primary crux of the legal argument for PRISM.

I don't understand how you can have secret courts either. It's a perversion of what this country was founded upon.

Re: Why didn't tech company leaders blow the whistle?

#39

Blow the whistle on what? The problem with the "conversation" going on in these threads is that no one is defining that first. If we're talking about the first leaked version of PRISM, we still don't even know if it exists or how it works. Subsequent revisions have made it seem that if the NSA doesn't have the immediate ability to query the companies' backends, then they have some kind of carte blanche ability to ask…

>If not, and there's a very real chance that neither of these are true, then the question doesn't make sense. Particularly since every tech company leader (and the NSA) are insisting that neither is true.

This is just it. This time last week it was public knowledge that (for example) Google complied with FISA 702 orders. Now it's public knowledge that Google complies with FISA 702 orders, using a workflow-automation system. There are hints of extra reasons to be more worried than before, but so far it seeems they're all either speculative or disputed:

(I'll keep talking about Google specifically just to narrow things down for now.)

* NYT suggested that FISA orders can be broad and shallow ("a broad sweep for intelligence, like logs of certain search terms") instead of narrow and deep (eg. everything on person or company X), but CNET's source contradicted that https://news.ycombinator.com/item?id=5845878 .

* The Washington Post used language which suggested that Google's lawyers may have been taken out of its FISA-702-order-execution loop altogether, but NYT contradicts that and Google has denied it https://news.ycombinator.com/item?id=5847846 .

* The Verizon mega-warrant suggests that NSA might be gathering data under similarly broad FISA orders, something that (like broad-and-shallow orders) would make "no direct access" a lot less meaningful, but that's been denied by Google https://news.ycombinator.com/item?id=5847959 and the various anonymous sources seem to be contradicting it too.

* The NYT article http://www.nytimes.com/2013/06/08/technology/tech-companies-... seemed to hint at the possiblity that the Google lawyers processing FISA orders could be suffering some kind of reverse regulatory capture or that Larry Page and Chief Legal Officer David Drummond could have lost track of the extent and nature of what they were approving. There doesn't seem to be any specific evidence for that though.

One thing that does seem to be true is that if you make it more convenient for the NSA to get data under FISA 702 orders it will respond by getting a lot more of it. Apparently the NSA's PRISM stack boasts of a 63% increase in the number of communications obtained in 2012 from Google http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-n... (and much larger increases at other companies). Still, it seems the PRISM system hasn't - or at least, hasn't yet! - facilitated an order-of-magnitude or game-changing increase in the scale of FISA 702 snooping. Overall there doesn't seem to be any great change in what we think we know http://www.wired.com/images_blogs/threatlevel/2013/05/fisaca... about that.

So, unless some of those hinted worries are true, there doesn't seem to be anything very big that Larry Page could have brought to our attention that wasn't public knowledge last week already. The biggest news is probably the increase in the scale of the data requested, and if Page cared enough about that he could presumably just have done a Twitter and declined to build a semi-automatic pipeline...

(IANAL or anything else.)

Re: Why didn't tech company leaders blow the whistle?

#40

There are several valid reasons why they didn't blow the whistle: 1. As the NYTimes article leaks[1], the leaders of these tech companies may not actually know the extent of FISA and PRISM within their servers - employees cooperating with the NSA would be forbidden from sharing this even with the CEOs. 2. What are they blowing the whistle on? There are a flurry of competing facts and fragmented stories. It came out a…

The government making a request like this to an employee of a tech company, with a gag order that doesnt let him share that information with the company he is working for is a blatant abuse of power. An employee has no resources to fight something like this if he cant tell the company he works for what he is doing, meaning that any company is vulnerable to this way of operating.
Post reply on HN