Live data from Hacker News

An Apology to my European IT Team

fredlybrand.com

71–80 of 97 posts

Re: An Apology to my European IT Team

#71
post #68

Earlier quoted context omitted.

If he hasn't released anything of use, why is he being charged with espionage?

Just because you failed to release interesting classified materials doesn't mean you weren't trying to. Just because you didn't kill anybody doesn't mean you don't get charged with attempted murder.

Sorry. I guess I presumed that your very first statement of "Snowden didn't circumvent anything" meant that he had nothing interesting in the first place. Which implies that he has nothing to release even if he wanted to.

So if he's charged with espionage, even if he hasn't released anything, does that mean he has circumvented something? Or that access to that information didn't actually require being circumvented in the first place?

Re: An Apology to my European IT Team

#72
post #38

Earlier quoted context omitted.

But what protection of stored data do you mean should Congress find, by introducing some Laws? Because, well, if the data are not encrypted on the server, then someone could still take them... that's how Internet works. For now, the only solution I can think of is that you encrypt the data locally, and upload only the encrypted data - but this way, the cloud provider will not able to provide any additional value. Or…

Not necessarily talking about encryption or security of data, that should already be an inherent part of cloud systems. I am talking about protections on unauthorized access by agencies (even for national security) meaning no more blanket access to all email/files/etc rather explicit machine read systems that only access data that has a warranted access and useful to the investigations. Human access should not be all…

> Human access should not be allowed unless the data has already been warranted

Access should not be allowed unless the data has already been warranted.

I don't care a fig whether my privacy is being violated by amoral machines or amoral humans.

Re: An Apology to my European IT Team

#73
post #51
post #39

While OP's apology is appreciable, there was more than enough information available in 2008 to understand that his Czech colleagues were right. The Prism scandal may have come as a surprise to US citizens, but the US has been spying foreign nationals and companies for years, and we've long known about it - haven't you heard of Echelon? It was also well known that these systems were used for industrial espionage.

Exactly, AFAIR it's always been sorta known that US intelligence agencies can spy on non-US citizen data held on US servers without a warrent. The PRISM lark is mostly big because it's spying on US citizens.

Even PRISM turned out to not be spying on U.S. citizens though. The NSL or FISA warrant required demonstrating that the target was more likely than not to be a foreigner.

Verizon metadata is different perhaps, as is the idea of 641A-style mass interception of communications. But PRISM itself automated FISA compliance, it didn't actually create more NSA powers than existed before it.

Re: An Apology to my European IT Team

#74
post #49
post #8

Earlier quoted context omitted.

It could be a crowd-sourced effort -- e-mails that are spam you mark as spam and upload to some repo that is maintained by someone (a la Adblock). You keep your filters updated, and run your e-mail against the filters file.

That would be trivially defeated by sending everyone a slightly different spam email. (And if your encryption doesn't produce totally different files for slight changes in plaintext, it doesn't deserve that name.)

I think you're replying to the wrong comment tree. Spammers already do this today, by including your name and other data in the message, and varying the wording, but that is not enough to fool the spam blockers, and there are diminishing rewards as your addresses/IPs begin to get marked as source of spam regardless of the content.

Re: An Apology to my European IT Team

#75
post #34

Hrm I wonder what are the chances that someone at the NSA or doing contract work for the NSA has a buddy at a company and that person decides to use their NSA powers to get their buddy's competitor's emails from Google Apps and send those emails to their friend. If there are safeguards in place from keeping this from happening how was Snowden able to take so many documents with him when he went to Hong Kong. Ok so ma…

Snowden directly answers this -- he claims NSA analysts can get away with it: http://www.guardian.co.uk/world/2013/jun/17/edward-snowden-n... and http://www.guardian.co.uk/world/2013/jun/17/edward-snowden-n... This is getting overlooked, but a 2009 NYT article claimed an NSA analyst looked through Bill Clinton's email out of curiosity (he was caught). I think this is very revealing. http://www.nytimes.com/2009/06/17/…

Many government and private sector systems share these types of problems.

Think Facebook and the DMV. As controls mature around the process, trolling through the data becomes relatively easy to enforce. My understanding is that in most state DMVs, looking up the driving record of a public figure or similarly flagged individual by some clerk is immediately detected, and "curiosity" lookups on friends and family eventually get caught by audit.

Re: An Apology to my European IT Team

#76
post #68

Earlier quoted context omitted.

If he hasn't released anything of use, why is he being charged with espionage?

Just because you failed to release interesting classified materials doesn't mean you weren't trying to. Just because you didn't kill anybody doesn't mean you don't get charged with attempted murder.

Which of the publicized charges against Snowden deal with attempted espionage, or even an attempted release of classified materials?

Re: An Apology to my European IT Team

#77
post #57

Earlier quoted context omitted.

He's released more than 'a powerpoint presentation'. http://www.guardian.co.uk/world/interactive/2013/jun/06/veri... http://www.guardian.co.uk/law/interactive/2013/jun/21/fisa-c... http://www.guardian.co.uk/world/interactive/2013/jun/20/exhi... QED. That's not all of course, but gives the lie to your claims. This is not counting the thousands of documents submitted to journalists, who have only published a selection,…

Lie to my claims? My question is, what has Snowden released which confirms the idea that he had the type of broad-ranging access which you claim. Nothing you just cited confirms that: the first is Verizon phone records. Again - public knowledge since 2007 if anyone was actually paying attention. The second and third are a warrant of the type used to request surveillance (you know, due process and all that) and a docu…

No you have it wrong. The rules, while explaining how to deal with data, provide loopholes to basically capture and store everybody (US citizens included). The point is that they are writing laws that should be illegal and are interpreting the patriot act in ways it was not supposed to be interpreted.

http://venturebeat.com/2013/06/06/nsa-patriot-act/

It is a very big deal and the US needs to forget about Snowden and concentrate on how to go forward.

Re: An Apology to my European IT Team

#78

Sadly the NSA programs are strongly anti-business as it is based on 'trust in me'. American businesses could and should lobby Congress to fight this and to find ways to protect US stored data, I know I wouldn't trust a Chinese cloud company not to snoop or steal business/corporate ideas and trade secrets. But if there were assurances for US cloud businesses that this doesn't affect their business ideas accidentally o…

I love how business-friendliness is your top concern here.

How about this: only businesses (like Facebook, Google et al.) should be able to say 'trust in me' - to their customers. Privacy regulation is only for the government, this will ensure that the surveillance state is built by corporations, as God intended.

It's obviously a huge risk and embarrassment if the US government looks at data from Europeans. But if American companies sell each other that data, that should be of no concern to Europeans, because private companies are all inherently trustworthy without external oversight.

Re: An Apology to my European IT Team

#79
post #57

Earlier quoted context omitted.

Lie to my claims? My question is, what has Snowden released which confirms the idea that he had the type of broad-ranging access which you claim. Nothing you just cited confirms that: the first is Verizon phone records. Again - public knowledge since 2007 if anyone was actually paying attention. The second and third are a warrant of the type used to request surveillance (you know, due process and all that) and a docu…

No you have it wrong. The rules, while explaining how to deal with data, provide loopholes to basically capture and store everybody (US citizens included). The point is that they are writing laws that should be illegal and are interpreting the patriot act in ways it was not supposed to be interpreted. http://venturebeat.com/2013/06/06/nsa-patriot-act/ It is a very big deal and the US needs to forget about Snowden and…

You think this is not an intended use of the PATRIOT act? That's hilarious. The PATRIOT act explicitly creates and authorizes this monster.

Re: An Apology to my European IT Team

#80

The author is overlooking one major flaw in his discussion: security (and possibly also reliability). His implication is that they can run internal servers more securely than Google and Salesforce. While government collection of encrypted emails is problematic, securing your own server and making it reliable is an entirely different issue. Unless they have an absolutely top notch security team they'd be better off on…

This is perhaps true where budget is severely constrained, or where Windows servers are spec'd, or where developers do systems administration, or where the corporate culture won't pay for capable IT.

Experienced IT staff can typically exceed the uptime of Google and Salesforce on a standard budget with no special accommodation. Perhaps the organization's IP (intellectual property) wasn't really worth that much, or upper management forced their hand? Sounds like that wasn't the case but you never really know.

Post reply on HN