Live data from Hacker News

Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

techcrunch.com

101–110 of 124 posts

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#101
post #92

I can't agree with his logic here : "When you say, ‘I have nothing to hide,’ you’re saying, ‘I don’t care about this right.’" How does he arrive at that conclusion? I have nothing to hide, but I still don't support the violation of these rights. Does he suggest that we instead support some other service or method under the illusion that we are immune from NSA spying?

I think it's pretty clear he means people who say "I have nothing to hide. They can look at whatever they want"

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#102
post #39
post #23

Earlier quoted context omitted.

[deleted]

The Standard .zip Crypto (know as "ZipCrypto") is 100% trash. However, it is possible to use AES-256 encryption in 7zip (and even WinZip, not that anyone actually uses that anymore...)

> and even WinZip

Most big corps still use licensed WinZip, but we've had problems sending AES-encrypted-by-WinZip files to external MS Windows users because the built-in Windows Explorer dezipping algo can't handle AES.

The users double-click on the encrypted Zip file and receive some irrelevant error message ( 'could not create temp file' or thereabouts ).

So often one has to fall-back to the Zip encryption algo.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#103
post #58

Earlier quoted context omitted.

http://owncloud.org/ You don't have to write your own Dropbox. You just have to host one. And even beside the question of government surveillance there is the advantage that it is under your control, not somebody else's. File sharing is so generic that the lockin opportunity is less than it is in other domains (like social networking) but there still can be advantage to being the owner and not merely a renter.

With owncloud if there's a fire in your house, or your cat knocks over a pitcher of water over your server, you lose your stuff. Plus it would be slow as dirt, since upload is limited by your ISP, and especially slow if you're traveling to some other continent. If you use a third party host you're basically as vulnerable as you would be on Dropbox, plus you have to maintain the thing and it's only a subset of the fea…

Precisely my point. I don't / can't host in my house/office. And if i host on any remote servers, the servers themselves can be compromised or forced to. What guarantee they are not, if we look at the scale of revelations on NSA snooping so far.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#104

What should we use then? If someone tells me to change X program, please, give me alternatives, otherwise, I'll stick with that. PS: Quite ironic to see him saying "get rid of Google", through an Hangouts session.

PS: Quite ironic to see him saying "get rid of Google", through an Hangouts session.

It's only ironic if you didn't read the first half of the title. He wasn't looking to keep this call private, was he?

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#105
post #55

Earlier quoted context omitted.

The issue is that the public discourse over this topic conflates the human need for privacy with the argument of "I have nothing to hide". These two things are not the same thing. Whether or not you have something to hide has no bearing on our basic need or basic right to privacy. Additionally, no one can really say "I have nothing to hide" and be intellectually honest. The honest statement is "I have nothing to hide…

"The wicked man flees when no one pursues." If everyone was constantly breaking the law then there would be no known criminals who haven't been arrested. There would no John Gottis or Whitey Bulgers. As soon as the government wanted someone arrested, they would just immediately arrest them for breaking copyright law or whatever. No need for the FBI to meticulously build cases, we're all guilty all the time and our on…

If everyone was constantly breaking the law then there would be no known criminals who haven't been arrested. There would no John Gottis or Whitey Bulgers. As soon as the government wanted someone arrested, they would just immediately arrest them for breaking copyright law or whatever.

The unquestioned premise in your argument is that the government wants all criminals to be arrested.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#106
post #58

Earlier quoted context omitted.

http://owncloud.org/ You don't have to write your own Dropbox. You just have to host one. And even beside the question of government surveillance there is the advantage that it is under your control, not somebody else's. File sharing is so generic that the lockin opportunity is less than it is in other domains (like social networking) but there still can be advantage to being the owner and not merely a renter.

With owncloud if there's a fire in your house, or your cat knocks over a pitcher of water over your server, you lose your stuff. Plus it would be slow as dirt, since upload is limited by your ISP, and especially slow if you're traveling to some other continent. If you use a third party host you're basically as vulnerable as you would be on Dropbox, plus you have to maintain the thing and it's only a subset of the fea…

If you're specifically targeted by the state (especially extralegally), you're screwed. Personally, I just want to be in control of my data, and don't want others (government or otherwise) to be indexing or 2 clicks away from my data.

As you mention, hosting OwnCloud removes your cat/fire scenario. Even by hosting it at a US ISP, you are significantly reducing the likelihood that the government can index or be two clicks away from your data, and your host (unlike Google/Dropbox) isn't likely to be mining your data for future business models. Hosting it at an ISP in a country that respects individuals privacy (e.g. Iceland) means your data won't be in the government's hands unless you're directly targeted by a state actor.

A subset of the features is, for me, an advantage. Hosting my password database myself is a huge feature. My Mac's built in screen capture writes stuff to disk. I can set that to be the Owncloud folder. No third party app required! :)

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#107
post #63

Earlier quoted context omitted.

> Every company that wants to continue to operate in the US has to comply with US government orders, that is just a fact of life. No one in the technology industry is super excited about going to jail or having their equipment seized I understand this and it is not contrary to my point. I'm actually trying to point out that the companies Snowden mentions have been specifically mentioned by NSA slides/documents and I…

It's always hard to be absolutely certain about what goes on at a company, but I'm pretty confident about Dropbox not participating in PRISM (defined as a government system that automatically collects considerable data from within a company's private systems). I haven't been at Dropbox for a year now, but for most of the time I was there I was one of only two SREs that ran the production infrastructure. I knew every…

> There is literally no way that something like PRISM could be put in place without my knowledge except by what would amount to sabotage.

Which we know the NSA has performed, intercepting shipments of servers in order to modify them.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#108
post #80

Earlier quoted context omitted.

I'm still not confident. Don't actually answer these questions (NDA and all), but how much traffic do you guys get? Could you possibly inspect it all? Have you inspected the hardware itself? Can you trust the switching equipment?It's reasonable to think that collection happens at the pipes between data centers (like some of the Google collections - which didn't involve any of the hardware present although that collec…

You're right, there's no way to be completely certain. It's like the adage: "Two can keep a secret, if one of them is dead." When someone else has access to your data, there always exists the possibility that it can be used in some way you don't like. What I wanted to convey is that user data was not used (at that time) in an untoward fashion by Dropbox. Everyone that I worked with took privacy and security very seri…

Not too sure about the quote based on it's other implications - and I don't think it's exactly the appropriate analogy here...

As an aside the NSA keeps secrets between tens of thousands of employees (although I hear it's Orwellian and depressing to work there). You can keep secrets between small and even large groups of people. You just have to have the right processes and leverages.

'Punishing' companies that collaborate with the government has a few parallel goals:

1.) Wanting to use something that has not yet been purposefully subverted.

2.) Give the companies a real argument for resisting programs.

3.) Speak out against the practices (since it isn't on a ballot anywhere).

Yes, ultimately it isn't the companies' faults (however the complicit few with blinders on for profit motive should be shunned for not putting up a fight).

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#109

Earlier quoted context omitted.

I don't know how to read that definition - it contains more legal jargon. What is "received for use by an employee"? When are electronic communications "processed into intelligible form"? Is a server that stores and processes data an employee? And for 100% sure PRISM received and stored mass data about American communications - both internet records and phone records. There's no debate about that. There was even (fau…

I don't think any of those are particular minor quibbles. To summarize: BOUNDLESSINFORMANT: Initial reporting show concrete number on just how much NSA was spying on a whole slew of European citizens. Shortly afterward, the actual intelligence agencies of those countries stepped up and said that those were not reflected NSA spying on those countries, but instead those numbers reflected communications that they themse…

> handed over to the NSA under intelligence sharing agreements

Right, there's a huge amount of intelligence sharing. That's one of the critical points. Domestic law can be skirted by International Law and International Law can be skirted by Domestic Law.

Need an American's data? We can't take it off the wire, store it, process it, and inspect it (in all cases). But Canada can, or Israel can, or Australia can, or New Zealand can (etc).

Need a foreigner's data that blocked by espionage laws? The country may itself be able to. Or a partner that doesn't have an agreement may be able to.

> PRISM: Initial reporting said that the NSA had direct access... NSA did not have access to any of their servers

Right, but this is one of those word games. First, the direct access the NSA DID have was not under the PRISM program. Reading "PRISM program did not give NSA direct access to servers" reads the same as "NSA has no direct access to servers" but it's not.

The 'targetted' collection of data itself turned out not to be very 'targetted' at all. Many requests were for large swaths of data and in many cases the NSA was given direct control of the servers that stored the metadata (as with phone records) but would need to request the companies for the content itself. Metadata = surveillance.

To extend the skirting laws above, the federal government is able to bypass laws on search and seizure by forcing private enterprises to do it and then requesting it as they see fit later on.

Why are these companies allowed to surveil and have access to my information? I don't trust employees at Google or Apple any more than a stranger on the street or any random government employee. Actually, as there are few to nil restrictions on what corporations can do with databases of my and other communications, in some sense it's worse. Aren't we guaranteed security in our persons and our affects? If a federal government forces a private company to censor you, or to surveil you, isn't that still censorship or surveillance - regardless of whether as feds they act on, collect, mine or process that information/data at all?

> XKeyscore ... no proof shown by Greenwald or indicated in his slides he published that it had been used to collect American's communications

But it did show that there were mammoth amounts of American metadata present in the database (however it was collected). Doesn't seem to matter whether XKeyScore was the collector or just a repository.

> The Stewart Baker article... porn

There is a lot that the NSA and CIA can do to influence people, their credibility and the credibility of an idea in groups (MINERVA, etc) - look at what the USAID Cuban Twitter program nearly succeeded in doing, and what similar efforts may have had a role playing in Hong Kong (and dare I say Scotland).

There is no doubt about the use of using Porn to discredit 'radicalizers' (a term used to refer to foreign and domestic targets). AFAIK there have been 0 revealed domestic cases of this, and IIRC only 7 or so foreign targets are known about (and 1 being a Westerner?)

The JTRIG stuff is creepy, real and looks like something right out of a Stasi handbook.

"Used to... discredit a target"

"Write a blog purporting to be one of their victims"

"Email/text their neighbors, colleagues, friends, etc"

"Get someone to go somewhere on the internet or in the real world"

"Can take 'paranoia' to a whole new level"

"Stop someone from communicating [by] bombarding their phone [...], delet[ing] their online presence, block up their fax machine"

"Stop someone's computer from working"

"Why do an Effects Operation?"

Answer 1: "Disruption v Traditional Law Enforcement" (presumably - it's effective and we can do it without the same paperwork/groundwork/courts/etc)

Answer 3: "...could save time and money"

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#110

Earlier quoted context omitted.

"Collected" legally means looked at by a human. I'm talking about sent to the NSA, processed by algorithms and stored. That's not 'collected'. It's a word game they play. My original assertion stands. And be careful of "not under the PRISM program". The "not this program" has been shown to be false over and over (in spirit) as there are many related programs that do joint work on shared datasets. Regarding Greenwald'…

Not under any program. None of Snowden's documents show that the US government has the access you think they have, and all the companies involved and the government have explicitly denied it. You're going with Greenwald's misinterpretation of a slide against all evidence to the contrary. Regarding Greenwald's incompetence: https://docs.google.com/document/d/1N0dRIEqagB9V4ipNMdT3q8h4...

Yeah, that's not right (your document discusses PRISM almost exclusively).

To quote from your document "when you claim something, you should be able to prove it". Can you prove "not under any program?" Of course you can't.

That's a bit mean (there's no way you can prove a negative). But it goes to show the level of sophistry and equivocation in your analysis.

I looked through the document and was thoroughly unimpressed. I don't think you're engaging with the material at the same level others are (e.g. metadata = surveillance & NSA has direct access to metadata -> NSA surveillance by modus ponens). Nor are you considering the vast body of documents, just some choice ones related to PRISM.

I would very much like to believe that somehow Pulitzer Prize winning journalists with the endorsement of The Guardian and everyone who followed merely read some diagrams wrong but after having read your document I can't convince myself of that, nor would it be consistent with other leaks, whistleblowing accounts, policy objectives, etc.

Good work though, I think it's important for people to actually look through the slides/material themselves. I think it's great you're doing that.

Post reply on HN