Live data from Hacker News

US intelligence mining data from 9 US Internet companies in broad secret program

washingtonpost.com

11–20 of 420 posts

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#11
Edit: Just saw the portion markings (the stuff on the slides that says their classification level), and I'm going to change my judgement to "this was pretty classified." And whoever released these slides to the public is going to jail for violating the NDA they signed. Jail for quite a few years for knowingly revealing TS information. I'll leave my previous comment below so you won't think I erased anything.

My problem is how they portray this. Direct from the article:

"The highly classified program, code-named PRISM, "

and also:

"The technology companies, which participate knowingly in PRISM operations, include most of the dominant global players of Silicon Valley."

If you have numerous (non-government contractor type) companies knowingly participating in the program, then it isn't "highly classified." And if you thought that your communications were private then you were fooling yourself. Even Tor, the darling of the EFF, was initially developed by the Navy. It's very tough for people to communicate electronically these days without the government being able to listen in.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#12
post #4

So if I'm using a US based hosting provider for my customers websites, their data will be extracted ?

US or else, I wouldn't trust other governments either, even if you trust governments, your cloud provider could still get hacked and even if it doesn't get hacked you still have to trust a third party: your cloud provider. If you're storing stuff on the cloud, encrypting it on the client first is probably the only way to get (pretty good) privacy.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#13
I just emailed Tim Cook that imho iCloud is dead.

He is welcome to add options to use my own cloud storage while using clientside encryption, and I might reconsider.

You're welcome to send him your opinion as well. It's tcook@youknowntherest.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#14
post #3

The National Security Agency and the FBI are tapping directly into the central servers and then they're extracting audio, video, photographs, e-mails, documents and connection logs from... Microsoft, Yahoo, Google, Facebook, PalTalk, AOL, Skype, YouTube, Apple. and it gets better Dropbox, the cloud storage and synchronization service, is described as “coming soon.”

How does this stuff work? Would someone at the NSA contact dropbox and ask them to build in a backdoor or are they just able to access whatever the fuck they want and simply do?

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#15
post #4

So if I'm using a US based hosting provider for my customers websites, their data will be extracted ?

Probably slightly safer using a US hosting company. At least some civil rights apply but I don't think there are any rules against the NSA spying on people outside the US.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#17
post #9

What sort of threats does the NSA give to these companies so they participated without any leaks? Just curious what the penalty would be if the NSA approached me about sucking down my user data and I refused.

I've been on the receiving end and posted a couple times trying to explain how it happens. In short, the NSA doesn't typically appear directly. Instead they use the courts and subpoenas to induce compliance for what seem like mundane court cases.

See a previous post: https://news.ycombinator.com/item?id=5754641

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#18
post #9

What sort of threats does the NSA give to these companies so they participated without any leaks? Just curious what the penalty would be if the NSA approached me about sucking down my user data and I refused.

I suspect just getting a request from a three letter agency is enough to make most CTOs and CEOs wet themselves and roll over. (Standing up against the government is not usually part of the business plan.)

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#19
At least we know beyond a shadow of a doubt that Skype has a backdoor now. Not really surprising although they did have some security people analyze the protocol and state that it was e2e secure.

FTA: "According to a separate “User’s Guide for PRISM Skype Collection,” that service can be monitored for audio when one end of the call is a conventional telephone and for any combination of “audio, video, chat, and file transfers” when Skype users connect by computer alone. Google’s offerings include Gmail, voice and video chat, Google Drive files, photo libraries, and live surveillance of search terms."

Post reply on HN