Live data from Hacker News

Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

techcrunch.com

111–120 of 124 posts

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#111
post #55

Earlier quoted context omitted.

The issue is that the public discourse over this topic conflates the human need for privacy with the argument of "I have nothing to hide". These two things are not the same thing. Whether or not you have something to hide has no bearing on our basic need or basic right to privacy. Additionally, no one can really say "I have nothing to hide" and be intellectually honest. The honest statement is "I have nothing to hide…

"The wicked man flees when no one pursues." If everyone was constantly breaking the law then there would be no known criminals who haven't been arrested. There would no John Gottis or Whitey Bulgers. As soon as the government wanted someone arrested, they would just immediately arrest them for breaking copyright law or whatever. No need for the FBI to meticulously build cases, we're all guilty all the time and our on…

I specifically mentioned selective enforcement. http://en.wikipedia.org/wiki/Selective_enforcement

There are over 3000 FEDERAL criminal offenses on the books. (As an estimate, even the gov can't tell you exactly how many. If you think ALL of these fall under common sense then you are kidding yourself. Have you read the thousands of pages that span dozens of volumes to be sure you aren't an offender?

You've conveniently side stepped my main first point, which is that we have a right to privacy, and that right has NOTHING to do with our presumed guilt or innocence. To use the argument "I have nothing to hide" misses the point entirely. If you want to walk around exposed, that's fine, but don't argue that the rest of us should be made to.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#112
post #86

Earlier quoted context omitted.

for a lot of them, it is not "the crown jewels" that they put there.

And for others, they'd rather entrust the crown jewels to GitHub than to their rotating cast of employees relying on server closets with unreliable power supplies and lackluster physical security.

ah, so to GitHub's "rotating cast of employees relying on server closets with unreliable power supplies and lackluster physical security".

much better! problem solved. not our problem anymore.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#113

Earlier quoted context omitted.

Not under any program. None of Snowden's documents show that the US government has the access you think they have, and all the companies involved and the government have explicitly denied it. You're going with Greenwald's misinterpretation of a slide against all evidence to the contrary. Regarding Greenwald's incompetence: https://docs.google.com/document/d/1N0dRIEqagB9V4ipNMdT3q8h4...

Yeah, that's not right (your document discusses PRISM almost exclusively). To quote from your document "when you claim something, you should be able to prove it". Can you prove "not under any program?" Of course you can't. That's a bit mean (there's no way you can prove a negative). But it goes to show the level of sophistry and equivocation in your analysis. I looked through the document and was thoroughly unimpress…

Can you prove "not under any program?" No, but the preponderance of evidence (the denials from all parties, the laws that make it illegal, and the lack of any evidence to the contrary despite the fact that the release of this evidence would be a bigger story than any of the leaks so far by a country mile) shows that it is not happening under any program. Yet you still believe it is happening because you chose to believe Greenwald's thoroughly debunked misinterpretation of PRISM.

Where are these "other leaks" that show this is happening? There aren't any. You bought Greenwald's lie hook, line, and sinker.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#114

Earlier quoted context omitted.

Yeah, that's not right (your document discusses PRISM almost exclusively). To quote from your document "when you claim something, you should be able to prove it". Can you prove "not under any program?" Of course you can't. That's a bit mean (there's no way you can prove a negative). But it goes to show the level of sophistry and equivocation in your analysis. I looked through the document and was thoroughly unimpress…

Can you prove "not under any program?" No, but the preponderance of evidence (the denials from all parties, the laws that make it illegal, and the lack of any evidence to the contrary despite the fact that the release of this evidence would be a bigger story than any of the leaks so far by a country mile) shows that it is not happening under any program. Yet you still believe it is happening because you chose to beli…

I think we've exhausted this branch of this topic, but I'm sure we'll have an opportunity to discuss this further on other Snowden articles and I look forward to doing exactly that.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#115
post #86

Earlier quoted context omitted.

And for others, they'd rather entrust the crown jewels to GitHub than to their rotating cast of employees relying on server closets with unreliable power supplies and lackluster physical security.

ah, so to GitHub's "rotating cast of employees relying on server closets with unreliable power supplies and lackluster physical security". much better! problem solved. not our problem anymore.

GitHub does it full-time though. Also, for businesses, it's a real financial concern that it's not their problem anymore. Having someone for you and your customers to sue is a good position to be in and what drives a lot of B2B decisions.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#116

Earlier quoted context omitted.

I don't think any of those are particular minor quibbles. To summarize: BOUNDLESSINFORMANT: Initial reporting show concrete number on just how much NSA was spying on a whole slew of European citizens. Shortly afterward, the actual intelligence agencies of those countries stepped up and said that those were not reflected NSA spying on those countries, but instead those numbers reflected communications that they themse…

> handed over to the NSA under intelligence sharing agreements Right, there's a huge amount of intelligence sharing. That's one of the critical points. Domestic law can be skirted by International Law and International Law can be skirted by Domestic Law. Need an American's data? We can't take it off the wire, store it, process it, and inspect it (in all cases). But Canada can, or Israel can, or Australia can, or New…

> Right, there's a huge amount of intelligence sharing. That's one of the critical points. Domestic law can be skirted by International Law and International Law can be skirted by Domestic Law.

These slides aren't an example of skirting domestic laws - they're examples of expanding collection on the NSA's target through partnering with other countries. Greenwald and company were trying to spin these slides as saying "look, the NSA collected 300 million German calls" and truth ended up being that the German intelligence service shared their own foreign collection with the US. None of the documents released has shown any indication that the NSA has ever asked a foreign country to provide them with collection on Americans. See [1], [2], [3] and [4].

> First, the direct access the NSA DID have was not under the PRISM program.

These are Greenwald's own words[5]:

The Prism program allows the NSA, the world's largest surveillance organisation, to obtain targeted communications without having to request them from the service providers and without having to obtain individual court orders.

The Washington Post backtracked on their reporting and took out the references to direct access. Greenwald has yet to issue any corrections to his report.

> The 'targetted' collection of data itself turned out not to be very 'targetted' at all.

Except that PRISM did end up being only for targeted communications. See the Privacy and Civil Liberties Oversight Board report on PRISM[8] (they describe targeting starting on page 7, but go into further detail in other sections). To date, the only domestic non-targeted collection has been the Section 215 telephony metadata collection (you can see the gory details here: [9]) and the Section 402 e-mail metadata collection which was discontinued in 2011 (details here: [10]). If Snowden just wanted to reveal either of those two programs, I wouldn't be so harsh on him. PRISM doesn't resemble those two programs in the least bit, though. Nor do many of the other disclosures, which focused purely on gathering foreign intelligence.

Note that contrary to what much of the reporting has suggested, the 215 program did not data-mine for indiscriminate call patterns, and there are restrictions on how they can search the database (see the PCLOB report[9] p.27-28, sections "Contact Chaining and the Query Process" and "Standards for Approving Queries"). I'm not going to argue and, in fact, would largely agree with anyone who says the standards don't go far enough, but most people I've discussed this with start off with a whole set of assumptions; it's only through looking at these documents and listening to congressional testimony that I've been able to figure most of this stuff out, and not many people bother putting that much effort into it.

> in many cases the NSA was given direct control of the servers that stored the metadata (as with phone records)

I haven't seen any reporting which said that, and the PCLOB report directly contradicts that statement (see the Section 215 PCLOB report[9] p.23-24, "Delivery of Calling Records from Telephone Companies to the NSA")

> But it did show that there were mammoth amounts of American metadata present in the database (however it was collected).

Here[6] is the report and here[7] are the slides that it was based on. Note the dramatic difference in the number of times Americans' communications are mentioned in the report (I counted 11) and the number of times in the slides (I count 0). It seems more like he just took assumptions from the Section 215 reporting and faulty PRISM reporting and applied those biases. I've noticed that's a common theme in most of the NSA reporting - there's a lot of fear-mongering about the fact that they could be doing using their tools to target Americans, but no actual evidence. You could make similar arguments about police and guns: they could use their guns to go door-to-door and indiscriminately kill ordinary, law-abiding citizens. But they don't. There's a big difference between having the technical capability to do something and having the legal authority to do it.

> look at what the USAID Cuban Twitter program nearly succeeded in doing

1) USAID isn't the NSA, and 2) the only thing it nearly succeeded in doing was giving ordinary Cubans a means of using the internet to communicate free of government censorship. I don't see what I'm supposed to be outraged at.

> The JTRIG stuff is creepy, real and looks like something right out of a Stasi handbook.

JTRIG is GCHQ, not NSA, and when I think of things straight out of the Stasi handbook, I think of things like making people disappear from their homes in the middle of the night never to be seen again, not discrediting them on the internet.

In any case, I guess my ultimate point is that this issue defies all journalistic norms and really needs to be approached with much more scrutiny than most issues. This isn't a situation where we have dozens of reporters from AP, Reuters, ITAR-TASS, etc. all on the ground objectively reporting independently verifiable facts as they see them. Instead, this is an issue where we have mountains of classified documents who were handed over to few carefully selected reporters by a leaker who is only available for softball interviews by carefully chosen interviewers. The documents are largely incomplete, and the reporters display their biases quite plainly (Greenwald himself is an advocate of 'adversarial journalism,' which embraces bias rather than seeking to minimize it). I've had plenty of people tell me not to trust what the government says, but you can't analyze the situation critically without also extending the same degree of skepticism to the Snowden and his small circle of journalists.

[1] http://electrospaces.blogspot.com/2014/02/dutch-government-t...

[2] http://www.spiegel.de/international/world/german-intelligenc...

[3] http://rt.com/news/norway-nsa-snowden-spying-us-965/

[4] http://voiceofrussia.com/news/2013_11_21/Denmark-admits-to-t...

[5] http://www.theguardian.com/world/2013/jun/06/us-tech-giants-...

[6] http://www.theguardian.com/world/2013/jul/31/nsa-top-secret-...

[7] http://www.theguardian.com/world/interactive/2013/jul/31/nsa...

[8] http://www.pclob.gov/All%20Documents/Report%20on%20the%20Sec...

[9] http://www.pclob.gov/SiteAssets/Pages/default/PCLOB-Report-o...

[10] http://www.dni.gov/index.php/newsroom/press-releases/198-pre...

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#117
post #114

Earlier quoted context omitted.

Can you prove "not under any program?" No, but the preponderance of evidence (the denials from all parties, the laws that make it illegal, and the lack of any evidence to the contrary despite the fact that the release of this evidence would be a bigger story than any of the leaks so far by a country mile) shows that it is not happening under any program. Yet you still believe it is happening because you chose to beli…

I think we've exhausted this branch of this topic, but I'm sure we'll have an opportunity to discuss this further on other Snowden articles and I look forward to doing exactly that.

So you'll spout the exact same nonsense in another thread, I'll call you on it, you won't present any evidence for your nonsense, and suggest we do this again?

No, thanks. I'll pass.

If you have any evidence, present it now.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#118

Earlier quoted context omitted.

> handed over to the NSA under intelligence sharing agreements Right, there's a huge amount of intelligence sharing. That's one of the critical points. Domestic law can be skirted by International Law and International Law can be skirted by Domestic Law. Need an American's data? We can't take it off the wire, store it, process it, and inspect it (in all cases). But Canada can, or Israel can, or Australia can, or New…

> Right, there's a huge amount of intelligence sharing. That's one of the critical points. Domestic law can be skirted by International Law and International Law can be skirted by Domestic Law. These slides aren't an example of skirting domestic laws - they're examples of expanding collection on the NSA's target through partnering with other countries. Greenwald and company were trying to spin these slides as saying…

> These slides aren't an example of skirting domestic laws - they're examples of expanding collection on the NSA's target through partnering with other countries.

The NSA and Israel trade information about each other's citizens, circumventing domestic law. [1] [2]

"The memorandum of agreement between the N.S.A. and its Israeli counterpart covers virtually all forms of communication, including but not limited to “unevaluated and unminimized transcripts, gists, facsimiles, telex, voice and Digital Network Intelligence metadata and content.”"

Have you seen the memorandum between Israel and the US? [+]

Before you go excusing the memorandum as not being a backchannel, remember that Hoover famously left an official paper trail of "I'm sorry, but the information you requested can not be served without a court order" but would serve the memo to those who made an illegal request by sending a trusted FBI agent who also had a copy of requested documents.

Australia spied on US law firms and handed the data to the NSA (with no court/warrant process in US). [3] [4]

The NSA will spy on others' citizens for them and share results. [5] [6]

"Britain's GCHQ intelligence agency can spy on anyone but British nationals, the NSA can conduct surveillance on anyone but Americans, and Germany's BND (Bundesnachrichtendienst) foreign intelligence agency can spy on anyone but Germans. That's how a matrix is created of boundless surveillance in which each partner aids in a division of roles. They exchanged information. And they worked together extensively. That applies to the British and the Americans, but also to the BND, which assists the NSA in its Internet surveillance." [7]

"NSA 'offers intelligence to British counterparts to skirt UK law'" [8]

GCHQ provides more internet surveillance records than any other nation in the Five Eyes (ATM) and shares this, including the NSA without a warrant system. [9] [10] [11]

There's a great breakdown the GCHQ case specifically. [12]

Of course it goes the other direction as well. [13]

Don't just take this from journalists, leaked documents, whistleblowers, and embarassed officials. You can trust watchdog agencies inside of Canada to give you the scoop too. Watchdog agencies 'chastised' intelligence programs for using allied partners to circumvent domestic law in a 51-page document. [14] [15]

These partnerships are extremely common. The NSA has (had?) 37 partnerships of varying degree of collaboration. [16]

[1] http://www.huffingtonpost.com/2014/08/04/nsa-partnership-isr...

[2] http://www.nytimes.com/2014/09/17/opinion/israels-nsa-scanda...

[+] http://www.theguardian.com/world/interactive/2013/sep/11/nsa...

[3] http://www.bbc.com/news/world-us-canada-26216883

[4] http://www.theguardian.com/world/2014/feb/16/australia-spied...

[5] http://www.politico.com/story/2014/09/edward-snowden-new-zea...

[6] https://archive.org/details/dom-7501-1-the-moment-of-truth-n...

[7] http://www.spiegel.de/international/world/secret-documents-n...

[8] http://www.theguardian.com/politics/2013/jun/10/nsa-offers-i...

[9] http://www.theguardian.com/uk/2013/jun/21/gchq-cables-secret...

[10] http://www.theguardian.com/uk-news/2013/aug/01/nsa-paid-gchq...

[11] http://uk.reuters.com/article/2013/06/21/uk-usa-security-bri...

[12] http://www.theguardian.com/politics/blog/2013/jun/10/cameron...

[13] http://www.independent.co.uk/news/uk/home-news/us-spy-base-t...

[14] http://www.theglobeandmail.com/news/politics/canadas-spy-age...

[15] http://news.nationalpost.com/2013/11/25/court-rebukes-csis-f...

[16] http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl...

Going to get back to other bits later, as it is far too late at the moment. It's very difficult to square your claims against "not this program", leaks and reports by others (e.g. Risen, Binney), Senate Reports and legislation that tries to move the data from NSA hands back to telecom hands.

A short preview though.

WRT "they could be doing it" - there's a sordid history with intelligence agencies expanding their capabilities, and not having technical limitations in an area so easy to be covert (computer systems) is a recipe for disaster. Especially when you create an apparatus that won't just be used today, but will both store data from today and continue to get access to tomorrow and will be inherited by who knows who.

Of course USAID isn't NSA. The ethics don't concern me. Neither of those are relevant to the point, left woefully neglected.

You round JTRIG down. They disrupt individuals lives and aggressively target inducing paranoia. Yeah that's not the same as a black bag (that comes later, for those who are unfortunate to become a large enough problem). Black bag programs exist. How often are they wielded? Rarely. Thank god. It's not reasonable to draw your line in the sand at assassination or concentration programs. You've also missed the bit about being notified of your rights and being given a jury of peers.

JTRIG location aside, certainly CIA have those capabilities. NSA and GCHQ partner heavily. US has programs for 'persona management' and astroturfing (they at least have defense contractors that provide that ability) and the HBGary leaks show US intelligence contract for it. We aren't just talking about the NSA here. We're talking about institutionalized surveillance. That means signals intelligence, but also partners, HUMINT, ELINT, traditional law enforcement, etc.

Regarding Greenwald. I would love to see more people get access to more document (depends on which - I would like America and allies to win the cyber intelligence war). I'm not sure the powers that be want any more people looking at the documents. We'll see.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#119

Earlier quoted context omitted.

> handed over to the NSA under intelligence sharing agreements Right, there's a huge amount of intelligence sharing. That's one of the critical points. Domestic law can be skirted by International Law and International Law can be skirted by Domestic Law. Need an American's data? We can't take it off the wire, store it, process it, and inspect it (in all cases). But Canada can, or Israel can, or Australia can, or New…

> Right, there's a huge amount of intelligence sharing. That's one of the critical points. Domestic law can be skirted by International Law and International Law can be skirted by Domestic Law. These slides aren't an example of skirting domestic laws - they're examples of expanding collection on the NSA's target through partnering with other countries. Greenwald and company were trying to spin these slides as saying…

> > First, the direct access the NSA DID have was not under the PRISM program.

You did not provide a rebuttal to this. You quoted Greenwald about the PRISM program. I was making the claim that there are bulk data programs that are NOT PRISM.

> > The 'targetted' collection of data itself turned out not to be very 'targetted' at all.

From the NSA review panel:

"In May 2006, however, the FISC adopted a much broader understanding of the word “relevant.”84 It was that decision that led to the collection of bulk telephony meta-data under section 215. In that decision, and in thirty-five decisions since, fifteen different FISC judges have issued orders under section 215 directing specified United States telecommunications providers to turn over to the FBI and NSA, “on an

84 See In re Application of the Federal Bureau of Investigation for an Order Requiring the Prod. Of Tangible Things from [Telecommunications Providers] Relating to [Redacted version], Order No. BR-05 (FISC May 24, 2006). 5 ongoing daily basis,” for a period of approximately 90 days, “all call detail records or ‘telephony meta-data’ created by [the provider] for communications (i) between the United States and abroad; or (ii) wholly within the United States, including local telephone calls.”"

"Almost 90 percent of the numbers on the alert list did not meet the “reasonable, articulable suspicion” standard."

"The statutory objection asserts that the FISC’s interpretation of section 215 does violence to the word “relevant.”"

> > in many cases the NSA was given direct control of the servers that stored the metadata (as with phone records)

> I haven't seen any reporting which said that...

The NSA review panel:

"We recommend that legislation should be enacted that terminates the storage of bulk telephony meta-data by the government under section 215, and transitions as soon as reasonably possible to a system in which such meta-data is held instead either by private providers or by a private third party. Access to such data should be permitted only with a section 215 order from the Foreign Intelligence Surveillance Court that meets the requirements set forth in Recommendation 1."

"We recommend that, as a general rule, and without senior policy review, the government should not be permitted to collect and store all mass, undigested, non-public personal information about individuals to enable future queries and data-mining for foreign intelligence purposes. Any program involving government collection or storage of such data must be narrowly tailored to serve an important government interest."

http://www.whitehouse.gov/sites/default/files/docs/2013-12-1...

The rest of the objections are variations on a theme. If you think I missed something I'll be happy to reply.

Regarding adversarial journalism - journalists and judges are the watchdogs of democracy, as they provide the public with the information and stage that information in ways that the public can respond to. State owned media is a very dangerous thing and America and other countries have passed laws limiting the ownership and direct news bearing to citizens.

However, when certain leverage exists (especially in cases where the public does not pay for news media), and when journalists readily repeat whatever officials and PR spokespersons say as though it were fact, or even set the stage with a apologetic hearing, you end up with Judith Butlers and Ken Dilanians. You end up with uncited apologetic airings of Defense Industry officials on the major news channels (and no contrarian voice).

http://www.democracynow.org/2014/9/15/who_pays_the_pro_war_p...

“It was the best story in my life, and I wasn’t going to let anybody else write it…The whole global war on terror has been classified. If we today had only had information that was officially authorized from the U.S. government, we would know virtually nothing about the war on terror.” - James Risen, top US Military journalist for the NYT, Pulizer Prize winner

We need adversarial journalism just like we needed the mud rackers. And what I've seen of Glenn Greenwald's reporting has shown every sign of due diligence, or it has become clear later how well prepared the issues and articles were collated.

How can I vote without knowing what's going on? I'm a supporter of the United States, through and through. But I need to know what's actually going on to be a politically engaged citizen.

Adversarial journalism is the best way to do that.

Re: Edward Snowden’s Privacy Tips: “Get Rid of Dropbox,” Avoid Facebook and Google

#120
post #115

Earlier quoted context omitted.

ah, so to GitHub's "rotating cast of employees relying on server closets with unreliable power supplies and lackluster physical security". much better! problem solved. not our problem anymore.

GitHub does it full-time though. Also, for businesses, it's a real financial concern that it's not their problem anymore. Having someone for you and your customers to sue is a good position to be in and what drives a lot of B2B decisions.

I think you would do well to read this before recommending github on that basis then:

https://help.github.com/articles/github-terms-of-service/

"You expressly understand and agree that GitHub shall not be liable for any direct, indirect, incidental, special, consequential or exemplary damages, including but not limited to, damages for loss of profits, goodwill, use, data or other intangible losses (even if GitHub has been advised of the possibility of such damages), resulting from: (i) the use or the inability to use the service; (ii) the cost of procurement of substitute goods and services resulting from any goods, data, information or services purchased or obtained or messages received or transactions entered into through or from the service; (iii) unauthorized access to or alteration of your transmissions or data; (iv) statements or conduct of any third-party on the service; (v) or any other matter relating to the service."

Post reply on HN