Live data from Hacker News

Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

techcrunch.com

81–90 of 124 posts

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#81

What should we use then? If someone tells me to change X program, please, give me alternatives, otherwise, I'll stick with that. PS: Quite ironic to see him saying "get rid of Google", through an Hangouts session.

Seafile is great if you dislike SpiderOak's closed-sourceness. Open source android and desktop clients, client-side encryption, can start with a free service then move to self-hosting when you're so inclined.

imho, it's the best option until we get a good user-friendly decentralized offering.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#82
post #55
post #5

I won't be getting rid of Dropbox, Google services, or Facebook anytime soon. I disagree with government spying, and would like to see major reform, but (disagreeing with Snowden) I actually have nothing to hide. I'm not excusing the companies that provide data to governments, but I like the services they provide. They solve problems I want solved, so I will continue to use them. Edit: Why all the down votes? If you…

The issue is that the public discourse over this topic conflates the human need for privacy with the argument of "I have nothing to hide". These two things are not the same thing. Whether or not you have something to hide has no bearing on our basic need or basic right to privacy. Additionally, no one can really say "I have nothing to hide" and be intellectually honest. The honest statement is "I have nothing to hide…

"The wicked man flees when no one pursues."

If everyone was constantly breaking the law then there would be no known criminals who haven't been arrested. There would no John Gottis or Whitey Bulgers. As soon as the government wanted someone arrested, they would just immediately arrest them for breaking copyright law or whatever. No need for the FBI to meticulously build cases, we're all guilty all the time and our only hope is to boycott Dropbox.

And if the government suddenly decides to start enforcing ex post facto violations of the law, we're all screwed anyway. There's no point in living your life by being afraid of what might be in and out of fashion in the future. If the government decides to start arresting people who have broken existing laws (not to mention future ones) there there are literally millions of people who have openly admitted to doing drugs or otherwise violating existing prohibitions. I can't think of many cases where the average citizen was prosecuted because they admitted to a minor crime on facebook, not to mention any cases where the government changed their minds on the law and started going after people.

I live a normal, boring life and do normal, boring things. I'm not going to get arrested for eating fast food while watching reality tv, or drinking beer and watching sports. I don't do anything that harms (or helps) anyone else, I'm the average American. I have nothing to hide and absolutely no fear of government intelligence collection.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#83
post #39
post #23

Earlier quoted context omitted.

[deleted]

The Standard .zip Crypto (know as "ZipCrypto") is 100% trash. However, it is possible to use AES-256 encryption in 7zip (and even WinZip, not that anyone actually uses that anymore...)

And even 7zip's AES implementation is hand-rolled, iirc, so I wouldn't exactly trust it with my life.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#84

Earlier quoted context omitted.

"The data is also collected and stored and processed by algorithms without any court oversight." This is false. PRISM doesn't get any data that wasn't specifically requested with a court order. It sounds like your understanding is still based on Greenwald's original reporting, which has since been shown to be inaccurate.

"Collected" legally means looked at by a human. I'm talking about sent to the NSA, processed by algorithms and stored. That's not 'collected'. It's a word game they play. My original assertion stands. And be careful of "not under the PRISM program". The "not this program" has been shown to be false over and over (in spirit) as there are many related programs that do joint work on shared datasets. Regarding Greenwald'…

Not under any program. None of Snowden's documents show that the US government has the access you think they have, and all the companies involved and the government have explicitly denied it. You're going with Greenwald's misinterpretation of a slide against all evidence to the contrary.

Regarding Greenwald's incompetence: https://docs.google.com/document/d/1N0dRIEqagB9V4ipNMdT3q8h4...

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#85

What should we use then? If someone tells me to change X program, please, give me alternatives, otherwise, I'll stick with that. PS: Quite ironic to see him saying "get rid of Google", through an Hangouts session.

Everything has to be served on a platter, right?

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#86

I use DropBox and Google Drive a lot, but I have scripts to encrypt data into ZIP files for anything that needs to be protected. It really is not much of a hassle. I have a SpiderOak account, but don't use it as often. Speaking of protecting data: I am surprised at how many companies seem to keep their software in private repositories on github and bitbucket. That seems like a security hole, if software if the core o…

for a lot of them, it is not "the crown jewels" that they put there.

And for others, they'd rather entrust the crown jewels to GitHub than to their rotating cast of employees relying on server closets with unreliable power supplies and lackluster physical security.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#87

Earlier quoted context omitted.

This is the actual legal definition of collected per DoDD 5240.1-R[1]: "C2.2.1. Collection. Information shall be considered as "collected" only when it has been received for use by an employee of a DoD intelligence component in the course of his official duties. Thus, information volunteered to a DoD intelligence component by a cooperating source would be "collected" under this procedure when an employee of such comp…

I don't know how to read that definition - it contains more legal jargon. What is "received for use by an employee"? When are electronic communications "processed into intelligible form"? Is a server that stores and processes data an employee? And for 100% sure PRISM received and stored mass data about American communications - both internet records and phone records. There's no debate about that. There was even (fau…

I don't think any of those are particular minor quibbles. To summarize:

BOUNDLESSINFORMANT: Initial reporting show concrete number on just how much NSA was spying on a whole slew of European citizens. Shortly afterward, the actual intelligence agencies of those countries stepped up and said that those were not reflected NSA spying on those countries, but instead those numbers reflected communications that they themselves had gathered, mostly from areas like Afghanistan, and handed over to the NSA under intelligence sharing agreements.

PRISM: Initial reporting said that the NSA had direct access to the servers of Google, Yahoo, Microsoft, etc., and could conduct data-mining from them without any oversight. Actual story ended up being that those companies were handing over data on specific targets under court order - NSA did not have access to any of their servers.

XKeyscore: Initial reporting was saying that the NSA was sucking up all communications including Americans. The author to the story that I linked to was pointing out that Marc Ambinder had previously disclosed XKeyscore in his earlier book saying that it was a system to index metadata that was already collected using other means, and there was no proof shown by Greenwald or indicated in his slides he published that it had been used to collect American's communications.

The Stewart Baker article: Stewart Baker was interviewed over the phone for the "NSA spying on porn habits" article, but they subsequently left out the core of his argument in order to not undermine their own argument. I thought that spoke to Greenwald's journalistic integrity somewhat - it also puts into perspective the fact that most of the slides he's published have been heavily cropped and there's no way to independently verify the contents of those slides.

The long list of mistakes article: Just pointing that there has been such a rush to report most of NSA documents that most of the initial reporting has had numerous mistakes of varying degrees of severity.

In any case, enjoy your social obligations!

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#88

Earlier quoted context omitted.

"The data is also collected and stored and processed by algorithms without any court oversight." This is false. PRISM doesn't get any data that wasn't specifically requested with a court order. It sounds like your understanding is still based on Greenwald's original reporting, which has since been shown to be inaccurate.

Director James Clapper of the NSA testified before congress that the NSA was not collecting any information on American Citizen. He was outright lying when he said that. [1] I would be interesting in how you know PRISM does not "collect" information for further "review" later? [1] http://www.washingtonpost.com/blogs/the-switch/wp/2014/01/27...

I know that (1) because Snowden's documents say so and (2) because I happen to have met one of the people who worked on one of the communication systems involved in PRISM at one of those companies and implemented the DITU integration at the time indicated in Snowden's slide -- and has the FBI T-shirt to prove it.

The New York Times interviewed several such people and got it right at the start (http://mobile.nytimes.com/2013/06/08/technology/tech-compani...). Greenwald still hasn't gotten it right.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#89
post #7

Earlier quoted context omitted.

Dropbox is mentioned in the PRISM slide deck as being a desired participant, not an actual participant. I worked at Dropbox when those slides were released, and none of us on the operations team knew what it could possibly be talking about. Every company that wants to continue to operate in the US has to comply with US government orders, that is just a fact of life. No one in the technology industry is super excited…

> Every company that wants to continue to operate in the US has to comply with US government orders, that is just a fact of life. No one in the technology industry is super excited about going to jail or having their equipment seized I understand this and it is not contrary to my point. I'm actually trying to point out that the companies Snowden mentions have been specifically mentioned by NSA slides/documents and I…

To your Edit: tell this to the socialist big time thought-police at the HN HQ that will not count your upvotes on your posts if they don't like them I.e.: I have almost twice as many upvotes on posts than the number appearing next to my nickname. Ah hh... "Land of the free" -- as long as they do and talk as they are told!

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#90

Does no one else see the irony in Snowden warning everyong to avoid Google.. via a Google+ Hangout?

If it was something intended to be public there is no harm in Google having it (they will scrape it off the web anyway) as the NSA are welcome to publicly access the content. Most people don't treat Dropbox/Google/Facebook (non-public) usage as being equivalent to CCing the government but maybe they should.

Pro-tip: anything you put on any service can and probably will at some point scroll past the eyes of a random sysadmin who's debugging why the database keeps crashing under load.

Most people are worried about "disclosure" - which is something Uber violated for a PR stunt at a party recently - i.e. we're usually okay wandering past the window naked, because we assume it's extraordinarily unlikely that someone will be pointing a camera at it right then, or that it wouldn't be more embarrassing for them to try and yell "hey that person is naked in the window I saw them!"

Conversely, we wouldn't be happy if someone did take photos, then uploaded them to the web, and showed them to all our friends etc.

In a practical sense, this is how people act. It's how you have to act - it would be practically neurotic to act any other way.

Post reply on HN