Live data from Hacker News

An Apology to my European IT Team

fredlybrand.com

41–50 of 97 posts

Re: An Apology to my European IT Team

#41
post #39

While OP's apology is appreciable, there was more than enough information available in 2008 to understand that his Czech colleagues were right. The Prism scandal may have come as a surprise to US citizens, but the US has been spying foreign nationals and companies for years, and we've long known about it - haven't you heard of Echelon? It was also well known that these systems were used for industrial espionage.

Agreed. From September 7, 2001, on CNN:

European Parliament adopts 'Echelon' report

(...) the document lists several examples in which intelligence officers are believed to have interfered in a commercial contract. The report claims that European aircraft maker Airbus Industrie had its lines tapped in 1994 while negotiating a $6 billion contract with the Saudi Arabian government and national airline.

http://archives.cnn.com/2001/TECH/internet/09/07/echelon.rep...

Re: An Apology to my European IT Team

#42
post #39

While OP's apology is appreciable, there was more than enough information available in 2008 to understand that his Czech colleagues were right. The Prism scandal may have come as a surprise to US citizens, but the US has been spying foreign nationals and companies for years, and we've long known about it - haven't you heard of Echelon? It was also well known that these systems were used for industrial espionage.

Huh. How is "You should've known!" a useful response to an apology? Of course he should've known, that's why he's apologizing.

Re: An Apology to my European IT Team

#43

I just wonder why telcos I've been dealing with have always required to encrypt all information which is not classified as public information. All customer, project, system, configuration, documentation, contracts etc. must be encrypted before transit. - Surely they must have known about this. So if telcos won't trust privacy of telecommunication, why should anyone else think that telcos are trustworthy?

[deleted]

Re: An Apology to my European IT Team

#44
post #38

Sadly the NSA programs are strongly anti-business as it is based on 'trust in me'. American businesses could and should lobby Congress to fight this and to find ways to protect US stored data, I know I wouldn't trust a Chinese cloud company not to snoop or steal business/corporate ideas and trade secrets. But if there were assurances for US cloud businesses that this doesn't affect their business ideas accidentally o…

But what protection of stored data do you mean should Congress find, by introducing some Laws? Because, well, if the data are not encrypted on the server, then someone could still take them... that's how Internet works. For now, the only solution I can think of is that you encrypt the data locally, and upload only the encrypted data - but this way, the cloud provider will not able to provide any additional value. Or…

Not necessarily talking about encryption or security of data, that should already be an inherent part of cloud systems.

I am talking about protections on unauthorized access by agencies (even for national security) meaning no more blanket access to all email/files/etc rather explicit machine read systems that only access data that has a warranted access and useful to the investigations.

Human access should not be allowed unless the data has already been warranted, filtered by the system and useful in the investigation that the NSA/DOJ/ etc might be using.

A big problem right now with it is blanket access and collecting content in bulk to sift through. There should be no way a human can go into an email box or cloud files and read everything for instance unless the person themselves is under investigation, email communication with that person can only be pulled from other innocent people's boxes that are part of the investigation, not everything. As is it right now they just collect everything and store it. It should also have heavy encryption and 3-5 approvals/logs/access audits per individual human access so there is a minimized threat of people searching business ideas for personal gain. This would prevent the one time email or document share with someone that they allows access to all their data. Explicit access and heavily verified across judicial, audits and multiple users 3-5 at least approving or seeing the access within the security organization.

NSA and CIA etc are patriots and like their freedoms as well, I am sure they don't want colleagues stealing ideas, business plans and random people's personal info when they go civilian. It is currently too sweeping and broad due to terrorism threats that have yet to take away as many freedoms as our own internal legal overreaches.

For example, right now let's say I am some crooked agent or politician, I could have one email or call to a person and justify looking at all their data. This might be someone who is in a competitive company or business information they want to find out. Steps like the above would minimize those abuses which are bound to happen. Take for instance oil mining or product plans, these types of competitive environments are very susceptible to snooping and corporate espionage without heavy controls on access to data.

Protection for international users in the same as US persons. Noone will trust storing data on our servers and cloud systems if they know all their data is being filtered and easily accessible by a single agent.

Also, extremely fast audits, judicial warranting. There is no reason it should take a long time with today's tools. I imagine the NSA and others are collecting all this data because the bureaucracy makes it difficult to get approvals in time, so they go in bulk as a fail safe. I dont' envy them the work is very hard and it is justified when true threats exist, these people typically aren't evil and most have the best intentions. But with great access to information comes a power that is hard to contain if not verified.

Timed release/removal of information that is not needed now, not indefinite storage. Will this make us less safe? Maybe but freedoms are not easy, it takes work to be free. Authoritarian is easy.

Maybe something like a Bill of Data Rights that also applies to international people in addition to the US. We would really revolutionize rights and data rights in the world, it would attract alot of business to data storage in the US. However currently data is free-er in other places sadly.

Re: An Apology to my European IT Team

#45
post #22

Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…

This kind of work isn't informal. Economic espionage is a big part of what intelligence agencies are doing all day. http://www.commondreams.org/headlines/070200-02.htm

One unintended consequence of the Snowden leak is to advertise this service to US businesses. My guess is that the discreet inquiries are already winging their way towards Congressmen.

Re: An Apology to my European IT Team

#46
post #37

Earlier quoted context omitted.

Exactly, except for the logging part: It would appear that either Snowden was able to circumvent the logging policies via his admin privs or they were not in place. When I was head of an IT division within lockheed (non-classified) I could have accessed anything - with admin accounts i was the sole owner of. I was ethically precluded from doing so... At a company where there is "open access" with "logging the shit ou…

Snowden didn't circumvent anything, because he hasn't released anything. Snowden has made a lot of grandiose claims which he can't actually back up, because beyond a few slides and some very common knowledge stuff (NSA hacking China) which he could've outright made up he hasn't been able to show he could do any of the stuff he claims. If you were aware of any notable hacking incidents in China, and could claim to hav…

Snowden didn't circumvent anything, because he hasn't released anything.

He clearly has released top secret documents; your assertion that he "hasn't released anything" is simply untrue. If you truly feel this isn't a leak, you obviously think the top secret classification is irrelevant and disagree with the US gov. on this. Some examples of his assertions verified by documents:

    NSA keeping daily phone records for every American
    NSA receiving data from US internet companies
    GCHQ (and thus NSA) keeping 3 days complete internet traffic passing through UK
    GCHQ (and thus NSA) keeping the content of all UK text messages
Re access controls at the NSA, I find it telling that an analyst was able to look at Bill Clinton's emails and only be reprimanded afterward - if proper legal controls on each target of surveillance were in place, or even perfunctory control by supervisors, that could never have happened.

Re: An Apology to my European IT Team

#47
post #37

Earlier quoted context omitted.

Snowden didn't circumvent anything, because he hasn't released anything. Snowden has made a lot of grandiose claims which he can't actually back up, because beyond a few slides and some very common knowledge stuff (NSA hacking China) which he could've outright made up he hasn't been able to show he could do any of the stuff he claims. If you were aware of any notable hacking incidents in China, and could claim to hav…

Snowden didn't circumvent anything, because he hasn't released anything. He clearly has released top secret documents; your assertion that he "hasn't released anything" is simply untrue. If you truly feel this isn't a leak, you obviously think the top secret classification is irrelevant and disagree with the US gov. on this. Some examples of his assertions verified by documents: NSA keeping daily phone records for ev…

He's released - again - a powerpoint presentation. The NSA phone record stuff? That was public knowledge in 2007. The GCHQ stuff seems like it was a powerpoint presentation too - no one's claimed anything more.

It's a leak, yes. He should be prosecuted for it, yes. But it's also widely disseminated internal data by nature of being a presentation.

Everything else is him claiming to have knowledge of things, without providing specific details beyond "his word". There's no reason to think he had the powers he claims to have and he's been leaking the NSAs foreign survieillance programs in broad-strokes like a sieve, but American specific stuff? Mysteriously quiet. With equally quiet walkbacks of the claims by the Washington Post and Guardian.

Re: An Apology to my European IT Team

#49
post #8
post #4

Earlier quoted context omitted.

Is there any way to tell if a particular email is spam, without knowing the content or the sender of said email?

It could be a crowd-sourced effort -- e-mails that are spam you mark as spam and upload to some repo that is maintained by someone (a la Adblock). You keep your filters updated, and run your e-mail against the filters file.

That would be trivially defeated by sending everyone a slightly different spam email. (And if your encryption doesn't produce totally different files for slight changes in plaintext, it doesn't deserve that name.)

Re: An Apology to my European IT Team

#50
post #47

Earlier quoted context omitted.

Snowden didn't circumvent anything, because he hasn't released anything. He clearly has released top secret documents; your assertion that he "hasn't released anything" is simply untrue. If you truly feel this isn't a leak, you obviously think the top secret classification is irrelevant and disagree with the US gov. on this. Some examples of his assertions verified by documents: NSA keeping daily phone records for ev…

He's released - again - a powerpoint presentation. The NSA phone record stuff? That was public knowledge in 2007. The GCHQ stuff seems like it was a powerpoint presentation too - no one's claimed anything more. It's a leak, yes. He should be prosecuted for it, yes. But it's also widely disseminated internal data by nature of being a presentation. Everything else is him claiming to have knowledge of things, without pr…

He's released more than 'a powerpoint presentation'.

http://www.guardian.co.uk/world/interactive/2013/jun/06/veri...

http://www.guardian.co.uk/law/interactive/2013/jun/21/fisa-c...

http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi...

QED. That's not all of course, but gives the lie to your claims.

This is not counting the thousands of documents submitted to journalists, who have only published a selection, at his insistence.

Post reply on HN