An Apology to my European IT Team
21–30 of 97 posts
Re: An Apology to my European IT Team
#22Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…
Economic espionage is a big part of what intelligence agencies are doing all day.
Re: An Apology to my European IT Team
#23Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…
They could probably still get access to a very limited number through some pretext, or with cooperation from other staff (like sysadmins or the reviewers), but it's less of a risk with NSA I think than it is with other agencies.
Re: An Apology to my European IT Team
#24Earlier quoted context omitted.
I think he understood the risks, but basically took it as fact that the US was beholden to decent privacy laws restricting access to private (and encrypted) communications like email. One of the main arguments for using Google apps in the past is the technical level of Google's security, and protection from being hacked. But the NSA/prism leaks have raised a new question in peoples minds, in favour of keeping things…
That's just it though, we've heard of stuff like ECHELON (which involved no warrants whatsoever) since years before this discussion would have taken place. ECPA dates to 1986! FISA dates to 1978 ! The insidiously loose interpretation on 4th Amendment controls for third-party communications dates back for centuries. A lot of this was just a quick Google search away, and would have been just as relevant the very year G…
Re: An Apology to my European IT Team
#25Earlier quoted context omitted.
Is there any way to tell if a particular email is spam, without knowing the content or the sender of said email?
If all your actual email is encrypted then by definition spam is the unencrypted stuff. A long time ago in a different galaxy I built a PGP MTA (based on sendmail at the time) which only forwarded mail that was encrypted, and as expected it was spam free, all though these days spammers just might go to the trouble of sending it encrypted if they thought it would get through.
At this point, I'd consider NOT using START TLS for your MTA to be nearly as irresponsible as not using ssh instead of telnet/rsh, or not using secure passwords. It correctly pushes all the pain onto the sysadmin (and a very tiny amount of pain), rather than end users.
Re: An Apology to my European IT Team
#26Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…
Is no one else paying attention to anything beyond the "slides" in this story?!
Re: An Apology to my European IT Team
#27Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…
According to Google "NSA powers" in their case are restricted to FISA orders, so I'm not sure how a random worker at a government contractor can produce these. Snowden was a sysadmin for a contractor and that is how he got his hands on their internal documents. Is no one else paying attention to anything beyond the "slides" in this story?!
Re: An Apology to my European IT Team
#28Earlier quoted context omitted.
If all your actual email is encrypted then by definition spam is the unencrypted stuff. A long time ago in a different galaxy I built a PGP MTA (based on sendmail at the time) which only forwarded mail that was encrypted, and as expected it was spam free, all though these days spammers just might go to the trouble of sending it encrypted if they thought it would get through.
Even just setting START TLS REQUIRED might solve your spam problem, as long as only a tiny minority of people did it. That would have the added benefit of protecting you from Yahoo Mail users, the FBI, and such. At this point, I'd consider NOT using START TLS for your MTA to be nearly as irresponsible as not using ssh instead of telnet/rsh, or not using secure passwords. It correctly pushes all the pain onto the sysa…
I kinda doubt it - if for some reason your outgoing mail server connects to one of my secondary/relaying MX servers, I don't think there's any way for you to ensure that server bothers trying to set up a TLS session when it relays my mail(which I guess is mostly my problem/fault) - and similarly, if your ISP requires you to send mail via their SMTP servers (blocking port 25 isn't uncommon here) - I don't think you've got any say in whether or not that server requires TLS?
(I know - I really should go and look this up myself…)
Re: An Apology to my European IT Team
#29Earlier quoted context omitted.
According to Google "NSA powers" in their case are restricted to FISA orders, so I'm not sure how a random worker at a government contractor can produce these. Snowden was a sysadmin for a contractor and that is how he got his hands on their internal documents. Is no one else paying attention to anything beyond the "slides" in this story?!
Aren't the NSA claiming they only need a FISA warrant if both ends of the correspondence are (reasonably believed to be) US citizens on US territory? For those of us in "the rest of the world" or any Americans corresponding with us I believe the restrictions on the NSA are "Yeah, do whatever the hell you want!"
Re: An Apology to my European IT Team
#30Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…
This kind of work isn't informal. Economic espionage is a big part of what intelligence agencies are doing all day. http://www.commondreams.org/headlines/070200-02.htm