Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

111–120 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#111
post #35

Earlier quoted context omitted.

My perspective on this is going to sound weird to you. 1. I am very irritated at inaccurate and sensationalized reporting. 2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens. 3. I think leaking details of signals intelligence programs should be a crime. 4. I hope Goog…

3. I think leaking details of signals intelligence programs should be a crime. I think dealing in absolutes, anywhere, should be a crime.

by saying "anywhere", aren't you dealing in absolutes?

Re: Asking the U.S. to allow Google to publish more national security request data

#112
post #51

Earlier quoted context omitted.

> 3. I think leaking details of signals intelligence programs should be a crime. This one surprised me. Wouldn't the strongest signals intelligence program be one that doesn't need to depend on obfuscation?

Can you expand on this idea? I would think that one of the main points of signals intelligence and their efficacy is if the emitter is not aware that you are collecting their signal.

Then you run the risk (as it just happened) of having the program losing efficacy if knowledge about it is leaked. Compared to a hypothetical program where knowing of its existence doesn't weaken it. Whether such a system can be built is debatable (something like the universal eavesdropping in 1984), but not a priori impossible.

Re: Asking the U.S. to allow Google to publish more national security request data

#114
Please also request tagging for each of the requests. e.g.

    2013-07-12
        Foreign National
        Drug Related - Cocaine
    2013-07-18 
        US Citizen 
        Drug Related - Marijuana
        Request from FBI
    2013-07-22 
        Foreign National
        Terrorism Related
    2013-08-01
        Foreign National
        Industrial Espionage
I think it's really important that we know how many of the requests have to do with the existential threat of terrorism, since that is the example the administration and Congress keep using to justify these actions.

The more metadata the better. If they want our metadata, it's only fair that we get their metadata too, to be able to keep tabs on their actions.

Re: Asking the U.S. to allow Google to publish more national security request data

#115
post #67

Ok, so its a bit snarky, but I wish Google would invest as much cleverness in evading the letter of these non-disclosure rules as they do in evading the letter of the tax laws in their various jurisdictions. Perhaps they could create Google Panama Ltd which is the official entity to petition for all FISA and NSL requests which is an independently operating subsidiary based in Panama and outside the jurisdiction of th…

It's not just snarky, it's preposterously unreasonable. How much work do you, personally, put into making money? At least 40 hours a week, I'm guessing, plus the time you spend on managing your investments, doing your taxes, and so on? How much work do you put into maintaining your own privacy? Is it even 1 hour per week, on average? Really? Note that Google has, allegedly, already put a LOT of work into pushing back…

Not precisely a rebuttal (you missed my point) but an interesting point in it's own right which I read was "Can you evaluate dollar value of privacy using the dollar value of your income stream?" And doing a sort of solve for X thing where you end up with hours invested in maintaining privacy becoming valued at hours invested in generating income. If I misunderstood please let me know, but assuming that I got the gist of it...

For me, I don't believe there is even a piece wise approximation between time investment and privacy value because the tools are so much different and the available actions being constrained. To illustrate where I get hung up on that reasoning, if you build a phishing page setup and contract a botnet to spam few hundred million people with phone phish-spam, you might get a lot of "income" for a relatively small time investment, similarly you can get greatly increase your privacy by investing in forged identity documents. So at the least we would have to constrain the hours invested in legitimate ways to enhance ones privacy and legitimate ways to enhance one's income.

Next there is an issue of facilitating the effort, so when company A sells me raw materials at a modest markup they facilitate my ability to make a living using them to provide said raw materials.If instead they were to charge an extortionate mark up, I might still be able to make a living but I might find the effort to do so requiring many many more hours of time investment. So at what point do the actions of my raw materials supplier work for or against my efforts at generating income. Similarly the provider of my tools can make it easier or less easy for me to maintain my privacy, so for example a Google Drive plugin which let me keep everything on their servers encrypted. If Google provides that then its a small number of hours invested to enhance my privacy, but if I have to rely on a third party who is acting without support from Google, then it takes many more hours for the same level of enhancement.

Given these built in and essentially intractable forces which affect the efficiency of hours invested needed to achieve the desired result, I am not persuaded by your claim that I can evaluate the 'worth' of privacy using your proposed reasoning.

Google can, and apparently does, to things like warrant notices where if you are suddenly asked to reconfirm your acceptance of their terms of service it's a signal that a warrant was served to them that they had to turn over your data. I think these sorts of things help them in the eyes of their users and are not illegal. They meet the letter of the law and so are not actionable, just as their transferring of rights around amongst their national subsidiaries is a completely legal way of not paying more tax.

My call to action was to try to think of ways that would make things like the PRISM data not useful to the NSA and yet meet their obligations under the law. I mentioned one (in cloud encryption with client side decryption) but I am sure there are others.

Re: Asking the U.S. to allow Google to publish more national security request data

#116
I would also like to see Google and other companies specifically fund counter-surveillance technologies, like end-to-end human friendly encryption.

I would love it if Chrome came with a GPG chrome extension that worked with Yahoo Mail, Gmail and other popular webmail clients right out of the box. Mozilla should also have a plugin that comes preinstalled for this.

The limiting factor in adopting end-to-end encryption in email is network effects. Preinstalling GPG support in browsers is half the battle.

Re: Asking the U.S. to allow Google to publish more national security request data

#118
post #109

While I'd like to know how many secret requests are being made to whom, why should I ever believe any numbers? We're living in crazy-town, maybe we always were. What is to stop the A.G. from publicly saying "Yes, disclose away!" and then to privately send one of those magic-do-anything-we-say requests saying, "Don't disclose X, Y, and Z."? Or if we are given an accurate count today, what is to prevent the government…

Good point. If they can force companies to lie about the existence of FISA requests, why wouldn't they force them to lie about the number of such?

What lies have companies told?

Re: Asking the U.S. to allow Google to publish more national security request data

#119
post #54

Earlier quoted context omitted.

I agree with your perspective, with the exception of a slight modification to #3. I believe that leaking should be a crime, but I also believe that if the court of public opinion judges the original secret worse than the leak, that it should become politically out-of-bounds to actually prosecute the case. I think there's a world of difference between Bradley Manning and Edward Snowden. And while I think Manning's tre…

I don't know enough about what happened with Snowden to have an opinion about him one way or another; I'm just not of the opinion that leaks are by default heroic.

What if one of Kim Jung Un's subordinates leaks details on "abuses" in the prison camp system? Technically he's breaking the law - North Korea's law - but I think it would be difficult to say that it would be the wrong thing to do. Also, if these reports are accurate, then I wouldn't necessarily consider that analogy too hyperbolic.
Post reply on HN