Live data from Hacker News

Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

techcrunch.com

71–80 of 124 posts

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#71
post #63

Earlier quoted context omitted.

> Every company that wants to continue to operate in the US has to comply with US government orders, that is just a fact of life. No one in the technology industry is super excited about going to jail or having their equipment seized I understand this and it is not contrary to my point. I'm actually trying to point out that the companies Snowden mentions have been specifically mentioned by NSA slides/documents and I…

It's always hard to be absolutely certain about what goes on at a company, but I'm pretty confident about Dropbox not participating in PRISM (defined as a government system that automatically collects considerable data from within a company's private systems). I haven't been at Dropbox for a year now, but for most of the time I was there I was one of only two SREs that ran the production infrastructure. I knew every…

I'm still not confident. Don't actually answer these questions (NDA and all), but how much traffic do you guys get? Could you possibly inspect it all? Have you inspected the hardware itself? Can you trust the switching equipment?It's reasonable to think that collection happens at the pipes between data centers (like some of the Google collections - which didn't involve any of the hardware present although that collection program wasn't a cooperative one).

Some of the lengths they go for these programs are really impressive. It was revealed that AT&T had secret rooms built that blend into the building infrastructure but MITM every packet that gets sent through (what looks like) normal infrastructure lines.

At some point it feels like you're being asked to prove a negative. That's the thing about discussing secret operations. And it is why the documents are so important.

I wonder now that the Snowden leaks are getting dated about a year old (and it being a few since you've left Dropbox) how much has changed.

Finally, the other companies on Snowden's list are certifiably on the list of already onboarded products, so it's hard to trust them.

> I also doubt that she has any day-to-day authority or responsibilities whatsoever

For example she assigned a new CFO for Dropbox. I doubt she has day-to-day authority (she's a busy woman), but being on the board and selecting upper management is a lot of power.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#72
post #25

Earlier quoted context omitted.

You don't get to determine whether you have something to hide or not. That's not up to you. It's up to whomever is targeting you to decide whether they want to turn something you consider irrelevant, into something that puts you in prison. For example, something not considered a crime today, such as having this conversation, can be a 'thought crime' tomorrow. Oh, I see here film42, that back in 2014, you partook in a…

I agree with your principle, but I'm confident that I don't need to worry about a hard labor sentencing regime.

How about a more mundane example?

A friend who worked for an analytics agency once told me that insurance companies are very interested in having access to the purchasing histories of their subscribers.

We speculated why, and among several possibilities, we figured the most likely and obvious is this: what happens when you get cancer or have a heart attack at 72 and your insurance company denies all your medical claims citing the entire volume of ice cream, pork, beer, coffee and diet coke you've consumed in your life? Or cite all your family and friends that smoke, even though you don't?

I make what I think are quite responsible choices with my health, but that conversation has stuck with me as an example of how information about me, information I'm not trying to 'hide', information that I didn't consider especially 'private', might be used against me at some point in the future.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#73
post #54

Earlier quoted context omitted.

"But it's hard for myself (the consumer) to leave a service (like dropbox) that makes my life easier." That's nonsensical and a strawman. No one is telling you to stop using such services. Just use an alternative that respects your rights. That's all there is to it.

Go ahead and list those alternatives for me. Please make sure they're immune to the power of USgov & NSA. Below is my list of tech companies that are immune to the USgov/NSA: ____

Tech companies can't give up what they've never had, and tech companies choose whether or not they'll store user data centrally.

Here's one for your list: http://syncthing.net/

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#74
post #7

Earlier quoted context omitted.

Dropbox is mentioned in the PRISM slide deck as being a desired participant, not an actual participant. I worked at Dropbox when those slides were released, and none of us on the operations team knew what it could possibly be talking about. Every company that wants to continue to operate in the US has to comply with US government orders, that is just a fact of life. No one in the technology industry is super excited…

So people should just upload unencrypted data willy nilly to 3rd party servers because they aren't mentioned in a leaked document? Sounds like a terrible security plan.

This!

"Don't mind me, just putting important & sensitive personal information on the internet backed by the power of an easily guessible password and hints.

Pre-Encrypt -> [OwnCloud || SpiderOak || AWS S3 || etc.]

And re leaked docs ... I still don't understand the mindset that some people have (maybe someone can help me). When people say, "oh, but the US Gov isn't worried about you" all I can do is roll my eyes.

* How can you verifiably prove that? (they can't)

* How can you verifiably prove other governments aren't?

* How can you verifiably prove chaos agents aren't?

* How can you verifiably prove someone isn't silently watching you?

* etc.

Just because it was or wasn't in a leaked document does not mean that the ability does not exist nor does it mean that such capability is only in the hands of 1 government.

In my eyes, the leaked docs showed "this is the current level" re: security/privacy/surveillance. We have to assume all other governments, corps, & individuals have equally or more powerful systems in place. Why? Because it's the only safe assumption.

That assumption has no bearing on the merits of legality with how the NSA conducts its mission, nor bearing on how others act. The documents merely give evidence and a base-level run down of additional attack vectors. This has absolutely zero to do with a "legal vs. illegal"-action debate and everything to do with technological security and infrastructure.

I encourage everyone to consider RFC 7258 [1] in their future projects. Do it for your users, whomever they may be. Consider RFC 7258 your USSINT 18 (if you're American) ... that is, fucking read it, understand it, and internalize it. Maybe the gov is good, maybe they're bad - that is irrelevant when there is more than just 1 gov in the world.

[1] http://tools.ietf.org/html/rfc7258

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#75

Earlier quoted context omitted.

"The data is also collected and stored and processed by algorithms without any court oversight." This is false. PRISM doesn't get any data that wasn't specifically requested with a court order. It sounds like your understanding is still based on Greenwald's original reporting, which has since been shown to be inaccurate.

"Collected" legally means looked at by a human. I'm talking about sent to the NSA, processed by algorithms and stored. That's not 'collected'. It's a word game they play. My original assertion stands. And be careful of "not under the PRISM program". The "not this program" has been shown to be false over and over (in spirit) as there are many related programs that do joint work on shared datasets. Regarding Greenwald'…

This is the actual legal definition of collected per DoDD 5240.1-R[1]:

"C2.2.1. Collection. Information shall be considered as "collected" only when it has been received for use by an employee of a DoD intelligence component in the course of his official duties. Thus, information volunteered to a DoD intelligence component by a cooperating source would be "collected" under this procedure when an employee of such component officially accepts, in some manner, such information for use within that component. Data acquired by electronic means is "collected" only when it has been processed into intelligible form."

That would include sent to the NSA, processed by algorithms and stored. The "read by a human definition" as far as I can tell comes from the EFF selectively quoting that definition[2] and drawing their own conclusions from their selective quotation, not the regulation itself. As the regulation itself states, as soon as any DoD intelligence components receives it and processes it, it is considered collected.

The misunderstanding is compounded by Clapper's June 9th 2013 interview with Andrea Mitchell, where he tries to explain that there's a legal difference between collecting content and metadata and fails miserably[3]. Mind you, Clapper is not part of the NSA. That's not an excuse, since as DNI he should know better, but it does explain it somewhat...

Regarding issues with Greenwald's reporting, here's a few:

- Misinterpretation of the BOUNDLESS INFORMANT slides that led to the series of "NSA is collecting millions of a communications inside (insert country here)": http://www.matthewaid.com/post/67998278561/greenwalds-interp...

- Innacuracies in the early PRISM reporting: http://www.vanityfair.com/online/eichenwald/2013/06/prism-is...

- Innaccuracies in the early XKeyscore reporting: https://medium.com/state-of-play/f49beeaf6a9c

- Stewart Baker, quoted extensively in the "NSA spies on porn" article, claims the authors omitted key parts of his quotes because it would make them look hypocritical: http://www.volokh.com/2013/11/27/understanding-enemy/

- A long list of early mistakes in NSA reporting: https://medium.com/state-of-play/bb27db32ae38

For a good rundown of various NSA programs, I'd recommend reading the Electrospaces analysis[4]. In particular, his analysis of PRISM[5] and BOUNDLESSINFORMANT[6] are really good, as is his recent Strategic Missions List post[7].

[1] http://www.dtic.mil/whs/directives/corres/pdf/524001r.pdf (see page 15)

[2] https://www.eff.org/nsa-spying/wordgames#collect

[3] http://www.nbcuni.com/corporate/newsroom/nbc-news-exclusive-...

[4] http://electrospaces.blogspot.com/

[5] http://electrospaces.blogspot.com/2014/04/what-is-known-abou...

[6] http://electrospaces.blogspot.com/search/label/BoundlessInfo...

[7] http://electrospaces.blogspot.com/2014/09/nsas-strategic-mis...

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#76
post #54

Earlier quoted context omitted.

Go ahead and list those alternatives for me. Please make sure they're immune to the power of USgov & NSA. Below is my list of tech companies that are immune to the USgov/NSA: ____

Tech companies can't give up what they've never had, and tech companies choose whether or not they'll store user data centrally. Here's one for your list: http://syncthing.net/

[deleted]

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#77

What should we use then? If someone tells me to change X program, please, give me alternatives, otherwise, I'll stick with that. PS: Quite ironic to see him saying "get rid of Google", through an Hangouts session.

Did you read the article? They talk about an alternative at length.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#78
post #54

Earlier quoted context omitted.

Go ahead and list those alternatives for me. Please make sure they're immune to the power of USgov & NSA. Below is my list of tech companies that are immune to the USgov/NSA: ____

Tech companies can't give up what they've never had, and tech companies choose whether or not they'll store user data centrally. Here's one for your list: http://syncthing.net/

>>tech companies choose whether or not they'll store user data centrally

...until the USgov/NSA chooses for them. Also, while it's all great the Syncthing tool is open source I see that they have precompiled binaries. Now I ask you, what percentage of people will compile themselves instead of downloading the readily available binary? Especially Windows users? In short, syncthing isn't immune to the USgov/NSA. We're talking about the general public; not just hardcore techies who can download & compile source code. I can just get GPG & rsync if I wanted... but that's not the point. Me and the person I replied were talking about "services"(tech companies), not stand-alone tools.

Anyways, Syncthing doesn't even replace Dropbox. Syncing files is just one of Dropbox's several features. And without a 3rd-party central server, Syncthing won't be able to deal with the person who wants their work computer to sync with their home computer. That central server is how you get around corporate firewalls, NAT and port-forwarding. If there's another way to deal with this, I'd love to hear it.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#79

Earlier quoted context omitted.

"Collected" legally means looked at by a human. I'm talking about sent to the NSA, processed by algorithms and stored. That's not 'collected'. It's a word game they play. My original assertion stands. And be careful of "not under the PRISM program". The "not this program" has been shown to be false over and over (in spirit) as there are many related programs that do joint work on shared datasets. Regarding Greenwald'…

This is the actual legal definition of collected per DoDD 5240.1-R[1]: "C2.2.1. Collection. Information shall be considered as "collected" only when it has been received for use by an employee of a DoD intelligence component in the course of his official duties. Thus, information volunteered to a DoD intelligence component by a cooperating source would be "collected" under this procedure when an employee of such comp…

I don't know how to read that definition - it contains more legal jargon. What is "received for use by an employee"? When are electronic communications "processed into intelligible form"? Is a server that stores and processes data an employee?

And for 100% sure PRISM received and stored mass data about American communications - both internet records and phone records. There's no debate about that. There was even (faux) legislature proposing moving the storage site from NSA hands to partner hands.

These articles seem like minor quibbles, mostly to do with terminology, but not the broad implications of the program.

There are so many damning slides. Like...

"Of these 1,789 applications, one was withdrawn by the government The FISC did not deny any applications in whole or in part." (42)

"With all querying if you discover its in the US, then it must go to the OSC quarterly report... 'but its nothing to worry about'" (99)

http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl...

Looked quickly through the articles, not sure if I saw anything really damning - they seemed like minor quibbles.

I must depart for non-tcp-mediated social obligations and consider this an incomplete reply - apologies for that. Hopefully the thread is alive later, and another poster can fill in the conversation here as it evolves. Adeiu.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#80
post #63

Earlier quoted context omitted.

It's always hard to be absolutely certain about what goes on at a company, but I'm pretty confident about Dropbox not participating in PRISM (defined as a government system that automatically collects considerable data from within a company's private systems). I haven't been at Dropbox for a year now, but for most of the time I was there I was one of only two SREs that ran the production infrastructure. I knew every…

I'm still not confident. Don't actually answer these questions (NDA and all), but how much traffic do you guys get? Could you possibly inspect it all? Have you inspected the hardware itself? Can you trust the switching equipment?It's reasonable to think that collection happens at the pipes between data centers (like some of the Google collections - which didn't involve any of the hardware present although that collec…

You're right, there's no way to be completely certain. It's like the adage: "Two can keep a secret, if one of them is dead." When someone else has access to your data, there always exists the possibility that it can be used in some way you don't like.

What I wanted to convey is that user data was not used (at that time) in an untoward fashion by Dropbox. Everyone that I worked with took privacy and security very seriously, and we knew that user trust is tough to earn and easy to lose. Handing data to the government automatically, without a warrant or confirmation of authority, would not have been something that anyone was interested in doing. But the government does have ways of making you do things that you don't want to do (see: Yahoo).

The biggest problem that I have with all of the Snowden revelation stuff is this: people seem quick to blame the companies who are complicit rather than the government who is the root of the problem. The government's efforts against security and privacy are the biggest threat the technology industry has ever faced, and if left unaddressed I believe it will inevitably lead to the US losing it's leadership position.

One last point, regarding Dropbox's CFO. Sujay had been at Dropbox for over three years (since 2010) and was involved in the CFO search for a long time. That they picked him for the role says a few things, but I don't see it as Condoleezza stacking the deck.

Post reply on HN