Live data from Hacker News

It's Time to Break Up the NSA (2014)

schneier.com

41–50 of 140 posts

Re: It's Time to Break Up the NSA (2014)

#41
post #34
post #14

Earlier quoted context omitted.

Yes. Imagine if the NSA were tasked with being a gatekeeper for data privacy and integrity that large companies like Facebook had to work with any time they pushed an update that sent data somewhere new, in the same way that the FDA verifies safety and efficacy of pharmaceuticals when they're applied to a new problem-domain. (I know that sounds almost satirically over-the-top, but it could work—if it were limited to…

> ...any time they pushed an update that sent data somewhere new... So you think making the NSA (or any govt agency) the gatekeeper for all data, public and private, would be a good idea? As if there's no way that could be abused? No thanks.

The data wouldn't go through them, nor would they be responsible for auditing the algorithms themselves. The comparison with the FDA was exact: they would simply require the company to execute a study proving (to peer review) the data-integrity of each change they were going to make.

The one interesting thing is that this would likely enforce an open-core-SOA software development model: companies would be incentivized to build a "trust kernel" of services that the government regs apply to, exposing an API with stringent access controls; and then a view layer that consumes that API, which can have whatever sloppy code they wish. The trust kernel would then have to be at least shared-source to enable the peer review necessary for study. (The company couldn't just pass the code around within a cabal of trusted peer companies, since those peers might be unfairly positively-biased.)

Re: It's Time to Break Up the NSA (2014)

#42
post #14
post #3

I think an even better argument for breaking up the NSA is that there's a fourth category of work they (should) do that's totally unrelated to surveillance and that I'd classify as "very good:" actively working to secure the communications of US government and companies against the NSA-equivalents of other nation-states and rogue actors. Having this is on the same list as encryption sabotage is a recipe for mismanage…

Yes. Imagine if the NSA were tasked with being a gatekeeper for data privacy and integrity that large companies like Facebook had to work with any time they pushed an update that sent data somewhere new, in the same way that the FDA verifies safety and efficacy of pharmaceuticals when they're applied to a new problem-domain. (I know that sounds almost satirically over-the-top, but it could work—if it were limited to…

having the government be the gatekeeper for private company data is a horrible idea

Re: It's Time to Break Up the NSA (2014)

#43
post #29

Regarding NSA and CIA, what do they have to do to get shut down completely? Do we wait until genocide? It doesn't seem like a re-org is the proper response to institutionalized torture, semi-automated assassination campaigns, and creation of a panopticon.

It's better to keep the good parts and reform the bad parts than to throw the entire baby out completely.

Let's draw a parallel to something more tangible than the cyberwar we don't see. Recently there was a number of high-profile cases where police got into a clash with unarmed civilians, with disastrous results. Should police be shut down completely? Would you be safe in a city with no police? Many cities in the world have places where the police don't go, and those are dangerous places.

NSA and CIA serve important functions. They just need to be properly balanced.

Re: It's Time to Break Up the NSA (2014)

#44
post #25

What about the problem of distinguishing domestic vs foreign communications? NSA already minimizes American information, plus FBI doesn't have authority to track who called to or from the US to a foreign nation like Pakistan from what I understand, so no phone meta data. The NSA may be too big but I haven't seen anyone bring an actual technical solution for setting the boundaries and so forth.

As long as you believe in Santa Claus, how about the NSA also be put in charge of delivering Christmas presents to children who are nice by drone, and punishing children who are naughty (also by drone), since they are already monitoring everyone and everything, and they make it their business to know who's naughty and nice.

Re: It's Time to Break Up the NSA (2014)

#45
Interesting, but I doubt it would go far in helping anything. You can't cut and disperse the cancer growing inside of the US Government and expect anything to be solved or fixed, it needs to be uprooted and burned. Would any of this address secret courts, police brutality, domestic propaganda, or corruption? It'll have to be all at once, otherwise it's just rearranging the furniture in our cell.

Re: It's Time to Break Up the NSA (2014)

#46
post #34
post #14

Earlier quoted context omitted.

Yes. Imagine if the NSA were tasked with being a gatekeeper for data privacy and integrity that large companies like Facebook had to work with any time they pushed an update that sent data somewhere new, in the same way that the FDA verifies safety and efficacy of pharmaceuticals when they're applied to a new problem-domain. (I know that sounds almost satirically over-the-top, but it could work—if it were limited to…

> ...any time they pushed an update that sent data somewhere new... So you think making the NSA (or any govt agency) the gatekeeper for all data, public and private, would be a good idea? As if there's no way that could be abused? No thanks.

The parent comment is not suggesting that they are the gatekeepers of the data, but rather that they act as a third party to authenticate data transmission. For example, company X says it wants to get you data, pass it through service Y and return Z, with the claim that the sensitive parts be secure. The role of the NSA would be to provide an audit of this process to determine whether or not security was in place. So if a service passed this hypothetical NSAs test they would actually never see any private information. The only danger is that the NSA withhold information about known insecurities, but that isn't any different from the current situation, and does not amount to "gatekeeping".

Re: It's Time to Break Up the NSA (2014)

#47
post #14
post #3

I think an even better argument for breaking up the NSA is that there's a fourth category of work they (should) do that's totally unrelated to surveillance and that I'd classify as "very good:" actively working to secure the communications of US government and companies against the NSA-equivalents of other nation-states and rogue actors. Having this is on the same list as encryption sabotage is a recipe for mismanage…

Yes. Imagine if the NSA were tasked with being a gatekeeper for data privacy and integrity that large companies like Facebook had to work with any time they pushed an update that sent data somewhere new, in the same way that the FDA verifies safety and efficacy of pharmaceuticals when they're applied to a new problem-domain. (I know that sounds almost satirically over-the-top, but it could work—if it were limited to…

In the EU this is the role of national data protection authorities.

http://ec.europa.eu/justice/data-protection/bodies/authoriti...

e; well, not actually pen testing, but knowing what personal information companies store, and mandating minimum safekeeping measures and limits on sharing.

Re: It's Time to Break Up the NSA (2014)

#48
post #29

Regarding NSA and CIA, what do they have to do to get shut down completely? Do we wait until genocide? It doesn't seem like a re-org is the proper response to institutionalized torture, semi-automated assassination campaigns, and creation of a panopticon.

The US Army kills people. What does the US Army have to do to get shut down completely? Do we wait until genocide?

Re: It's Time to Break Up the NSA (2014)

#49
post #41
post #34

Earlier quoted context omitted.

> ...any time they pushed an update that sent data somewhere new... So you think making the NSA (or any govt agency) the gatekeeper for all data, public and private, would be a good idea? As if there's no way that could be abused? No thanks.

The data wouldn't go through them, nor would they be responsible for auditing the algorithms themselves. The comparison with the FDA was exact: they would simply require the company to execute a study proving (to peer review) the data-integrity of each change they were going to make. The one interesting thing is that this would likely enforce an open-core-SOA software development model: companies would be incentivize…

Sorry, I tried to write what I imagined was a clarifying comment, at least along the lines of what I thought you were trying to say. But while I was typing it you (who I imagine is the real authority on your own opinion) did exactly the same, but better.

Re: It's Time to Break Up the NSA (2014)

#50
post #14
post #3

I think an even better argument for breaking up the NSA is that there's a fourth category of work they (should) do that's totally unrelated to surveillance and that I'd classify as "very good:" actively working to secure the communications of US government and companies against the NSA-equivalents of other nation-states and rogue actors. Having this is on the same list as encryption sabotage is a recipe for mismanage…

Yes. Imagine if the NSA were tasked with being a gatekeeper for data privacy and integrity that large companies like Facebook had to work with any time they pushed an update that sent data somewhere new, in the same way that the FDA verifies safety and efficacy of pharmaceuticals when they're applied to a new problem-domain. (I know that sounds almost satirically over-the-top, but it could work—if it were limited to…

>"..in the same way the FDA verifies safety and efficacy of pharmaceuticals.."

There is some merit to what you say, but I'd not use the FDA as a model. To me that sounds like a recipe for disaster, imagine the NSA auditing our software with FDA like cronyism and inefficiency? Green-light passes to be auctioned off to the highest bidder, and otherwise legitimate products will be hampered by woe-some delays. "Sorry, cant launch your new update until the NSA approves it."

Post reply on HN