Live data from Hacker News

US intelligence mining data from 9 US Internet companies in broad secret program

washingtonpost.com

111–120 of 420 posts

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#111
post #13

I just emailed Tim Cook that imho iCloud is dead. He is welcome to add options to use my own cloud storage while using clientside encryption, and I might reconsider. You're welcome to send him your opinion as well. It's tcook@youknowntherest.

Apple demonstrated that resistance is possible, for reasons unknown, when it held out for more than five years

I'm pretty sure that unknown reason was Steve Jobs. Apple became a participant 1 year after Tim Cook took the helm.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#112
post #91
post #35

Earlier quoted context omitted.

Dropbox has every encryption key used with Dropbox, so they can decrypt any file. Both transport keys and storage keys. Dropbox does at least (allegedly) encrypt stuff for storage, so they can RMA hard drives without having to destroy them first, but that's pretty meaningless. There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good…

Dropbox doesn't RMA drives, everything is de-duped then stored on S3. (or at least that is what they told me when I interviewed with them)

They were on S3 at one point in time (and pretty widely known as the biggest S3 customer). I'm not sure if they are on S3 today. This may depend on when you interviewed.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#113
post #103

> "In 2008, Congress gave the Justice Department authority to for a secret order from the Foreign Surveillance Intelligence Court to compel a reluctant company “to comply.”" One more reason FISA is one sick, disgusting piece of legislation, and it was just extended to 2017, last year - yet too many were dormant when all of it was going down.

> One more reason FISA is one sick, disgusting piece of legislation, and it was just extended to 2017, last year.

I think you are confusing the nature of FISA -- a piece of legislation designed to constrain excessive executive domestic surveillance passed in the wake of widespread and highly politicized abuses by the Nixon Administration -- and recent amendments to FISA to expand the scope of allowed surveillance that were passed under the justification of the necessities of the "War on Terror".

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#114
post #48
post #35

Earlier quoted context omitted.

Dropbox has every encryption key used with Dropbox, so they can decrypt any file. Both transport keys and storage keys. Dropbox does at least (allegedly) encrypt stuff for storage, so they can RMA hard drives without having to destroy them first, but that's pretty meaningless. There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good…

What alternative do you suggest?

If only there was a provider that respected your privacy and allowed you to use basic unix primitives to interface with your cloud storage...

If only...

http://www.rsync.net/resources/notices/canary.txt

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#115
post #66

Earlier quoted context omitted.

This is a reply to gknoy: I would suggest Spider Oak, however, their support is not timely and there's currently a bug in the Windows 8 client that doesn't let it work. But if they get those issues sorted it could be a decent service. Could someone please tell me why I can't reply to any comments that are below the third level? The reply link simply disappears! Edit: Now that I've made this statement there's a reply…

Reply links don't appear until a few minutes after a comment is made. It's intended to have a dampening effect on flame wars.

You can just click on the "link" link and then reply from there, instantly.

(I kind of hate the feature, since most of the time "you suck" "no, you do" "no, you do" only goes on a few levels, so the exponential delay isn't an issue, but an actual technical discussion goes deeper. False positives and false negatives. :( )

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#116
post #31

At least we know beyond a shadow of a doubt that Skype has a backdoor now. Not really surprising although they did have some security people analyze the protocol and state that it was e2e secure. FTA: "According to a separate “User’s Guide for PRISM Skype Collection,” that service can be monitored for audio when one end of the call is a conventional telephone and for any combination of “audio, video, chat, and file t…

I'm not sure when the security people you are talking about did their audit, but when Microsoft bought Skype a few years ago they changed it from P2P communications to routing everything through a central server. After that it would be child's play to put in a backdoor.

Microsoft now runs the supernodes instead of them being random high bandwidth Skype users. Your computer uses a supernode to find the address of the user you want to reach, but you still connect directly to that user to communicate. People misunderstood this change to mean that call traffic traversed Microsoft servers.

That said, it has been shown that at the minimum China has keys to decrypt peer to peer communications, likey the NSA does as well. The NSA doesn't need Microsoft to route call traffic via their servers, because they already have taps at all the major exchange points.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#117
post #114
post #48

Earlier quoted context omitted.

What alternative do you suggest?

If only there was a provider that respected your privacy and allowed you to use basic unix primitives to interface with your cloud storage... If only... http://www.rsync.net/resources/notices/canary.txt

Do something for mobile please? You're one of the most trustworthy providers, particularly if you build things on mobile so we don't necessarily need to trust you...

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#118
post #21
post #9

What sort of threats does the NSA give to these companies so they participated without any leaks? Just curious what the penalty would be if the NSA approached me about sucking down my user data and I refused.

They hand out these: http://en.wikipedia.org/wiki/National_security_letter You're not even supposed to reveal that you are complying (gag order). Google has been in the news recently about fighting one in court.

We have been fighting this US policy since 2006:

http://www.rsync.net/resources/notices/canary.txt

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#119
post #82
post #61

Earlier quoted context omitted.

When people wanted to talk about this kind of massive wiretapping program years ago, they were called paranoid nutcases. Now that the truth is coming out, people who want to talk about it are called out for belaboring the obvious. I see this "are you so naive as to be surprised?" reaction in almost every thread about this. It's some kind of defense mechanism.

>I see this "are you so naive as to be surprised?" reaction in almost every thread about this. It's some kind of defense mechanism. That's why I'm saying you are right to be upset. I like the saying "being paranoid does not mean they are not after you". And being paranoid turned out to be realistic.

Well then try this on for size. Getting data through requesting it is only one way to get data. Another way to get data is to hack into the source. Consider that a number of governments, including the US, have active hacking teams. What are they hacking in to, exactly? I leave that up to you for speculation.
Post reply on HN