I can't help think that if this were the 1970s and we were talking about the post office and phone company automatically forwarding copies of all communications to the us gov't, there would be riots in the streets. Oh how things have changed.
US intelligence mining data from 9 US Internet companies in broad secret program
121–130 of 420 posts
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#122Earlier quoted context omitted.
This is unsubstantiated speculation.
Three letter agencies approach the executive team directly. A decision to participate has to be made at the exec team/board level. If the CEO doesn't know about it, then the company has some serious communication issues.
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#123Earlier quoted context omitted.
How does this stuff work? Would someone at the NSA contact dropbox and ask them to build in a backdoor or are they just able to access whatever the fuck they want and simply do?
It's described for a couple of the cooperating corporations in the article. For example, for Facebook, the analyst goes to a special webpage/site at Facebook, then they simply clicks through a "Yep, this person is a terrorist" EULA and they have full access to Facebook's database (eg. full access to user content). I bet they rejoiced when Facebook Graph opened shop.
LE requests to FB simply do not work that way. They can make a request online, which is checked for proper authority, etc. The guidelines FB follows can be viewed at https://www.facebook.com/safety/groups/law/guidelines/ and the idea that FB just randomly hands out full read access to user data is either a paranoid delusion or calculated deception. Maybe you can tell us which one you were aiming for.
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#124Sounds like some one (or many) are blowing whistles. A lot of documents leaking.
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#125I'm saddened to see Dropbox on the list. Did they choose to participate or is it mandatory? In any case, we've moved several projects to BTSync recently from Dropbox (for no other reason than to free up space on Dropbox for our personal files) and have been enjoying the service. As a p2p encrypted protocol, I imagine it's much more difficult to eavesdrop on your files and would actually require a warrant to obtain. I…
I've read somewhere that it's voluntary edit: read it here http://mobile.theverge.com/2013/6/6/4403868/nsa-fbi-mine-dat...
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#126Earlier quoted context omitted.
How does this stuff work? Would someone at the NSA contact dropbox and ask them to build in a backdoor or are they just able to access whatever the fuck they want and simply do?
It's described for a couple of the cooperating corporations in the article. For example, for Facebook, the analyst goes to a special webpage/site at Facebook, then they simply clicks through a "Yep, this person is a terrorist" EULA and they have full access to Facebook's database (eg. full access to user content). I bet they rejoiced when Facebook Graph opened shop.
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#127Can I cut out the middle-man and just use the NSA as my cloud provider?
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#128Answer: never
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#129Earlier quoted context omitted.
Dropbox doesn't RMA drives, everything is de-duped then stored on S3. (or at least that is what they told me when I interviewed with them)
They were on S3 at one point in time (and pretty widely known as the biggest S3 customer). I'm not sure if they are on S3 today. This may depend on when you interviewed.
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#130These are national security assets: evidence gathered here will never be used in a drug case, or a tax evasion case. Why not? These tools exist for the bigger fish: the dozens of Soviet-era nuclear weapons believed to be missing, or the small amounts of dangerous pathogens that periodically vanish from research labs. These are what the government is worried about, and they're not going to risk revealing their methods for something lesser.
Warren Buffet has predicted a major nuclear terrorist attack on an American city to be a "virtual certainty" given enough time.
Ok, but no one here is going to argue that stopping terrorism is bad: the problem is in how we define terrorism. What happens when the definition becomes progressively wider? What counts as "terrorism" is political, after all.
It's important to remember that we still have a functioning democracy. If you -- Hacker News reader -- decided to run for congress tomorrow, you might not win, but you won't be killed, sabotaged, or secretly blocked. While some individual politicans may be corrupt, the system broadly is not. These programs are enforcement mechanisms; the laws themselves are still made by the people, and maybe corporations. While we as a population may argue about social issues like gay marriage and abortion, our government is not fascist.
Further, I take these programs as a great example that security is much harder to create than it is to destroy. Extreme efforts such as these may still be insufficient to prevent New York from being destroyed by terrorists. In that case, the acts of a few crazy people still overcame a monumental effort by the entire intelligence apparatus. What does that say about the time Hacker News is so afraid of, when it's more than only a few crazy people that the government is "worried about"?
Should these programs exist? I don't know. I'm as worried as anyone about the scope creep. I'm willing to accept a level of inherent danger with living in a free society. However, do not forget that we can't see NSA success stories. I might be willing to accept a risk of periodic car bombs, which while tragic are not statistically significant; however, if PRISM is actually effective at tracing and intercepting Soviet nuclear weapons, I can see multiple sides of this issue.
We have rights to privacy and protection from unreasonable search and seizure. Those rights were created to prevent unfair loss of life, liberty, and property. These programs, hidden in the background, don't inconvenience you, or lead to loss of freedom or property. Is privacy good? Of course. But the incentives the intelligence apparatus have to not use any data collected here against anyone for reasons less than "real" terrorism are strong enough, that I think it's not open-and-shut.