Live data from Hacker News

US intelligence mining data from 9 US Internet companies in broad secret program

washingtonpost.com

41–50 of 420 posts

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#41
I'm saddened to see Dropbox on the list. Did they choose to participate or is it mandatory?

In any case, we've moved several projects to BTSync recently from Dropbox (for no other reason than to free up space on Dropbox for our personal files) and have been enjoying the service.

As a p2p encrypted protocol, I imagine it's much more difficult to eavesdrop on your files and would actually require a warrant to obtain.

I presume that's true for AeroFS as well.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#42
This is fucking atrocious. How much money do we allocate to national security in a year and this is the kind of amateurish PowerPoint slide their analysts come up with?

http://www.washingtonpost.com/wp-srv/special/politics/prism-...

I wonder which cub analyst got the job of putting together a collage of logos for that final slide?

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#43
post #23

Earlier quoted context omitted.

How does this stuff work? Would someone at the NSA contact dropbox and ask them to build in a backdoor or are they just able to access whatever the fuck they want and simply do?

I don't believe they need backdoors, they probably just ask for the data and it's provided to them by those companies to comply with the current laws (or at least their interpretation of it.) I'm pretty sure dropbox can reverse any encryption they use for the files they store. Or do they even encrypt the data?

They only encrypt it in a meaningless way. Otherwise, their deduplication wouldn't work.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#45
post #31

At least we know beyond a shadow of a doubt that Skype has a backdoor now. Not really surprising although they did have some security people analyze the protocol and state that it was e2e secure. FTA: "According to a separate “User’s Guide for PRISM Skype Collection,” that service can be monitored for audio when one end of the call is a conventional telephone and for any combination of “audio, video, chat, and file t…

I'm not sure when the security people you are talking about did their audit, but when Microsoft bought Skype a few years ago they changed it from P2P communications to routing everything through a central server. After that it would be child's play to put in a backdoor.

Not to be too conspiracy theorist but maybe just maybe this was why Skype was bought by Microsoft in the first place? The thought crossed my mind at the time of purchase but I sent it away skuttling because I deemed it too tinfoil hatty. My main regret at the time as a Linux enthusiast was that Skype's Linux offering was sure to suffer, so I had that angle more on my mind than government aiding and abetting.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#46
This is why've were trying to make it legal lately. They were already doing it. The same thing happened with the Patriot Act.

It seems FBI/NSA "test-drive" a new illegal spying program first, and then lobby Congress to pass a law to make it legal (regardless of its constitutionality, as we've seen so far).

I bet they would've wanted retroactive immunity, too, in these new laws. Also, let's see how those supporters of FISA, like Dianne Feinstein, try to spin this one as "they already knew about it" (which makes it that much worse) and that it's nothing new.

Also let me see them say with a straight face that this is constitutional and doesn't violate the 4th Amendment. But seeing how cynical these people have become, I don't think it would be too hard for them to do it.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#48
post #35
post #23

Earlier quoted context omitted.

I don't believe they need backdoors, they probably just ask for the data and it's provided to them by those companies to comply with the current laws (or at least their interpretation of it.) I'm pretty sure dropbox can reverse any encryption they use for the files they store. Or do they even encrypt the data?

Dropbox has every encryption key used with Dropbox, so they can decrypt any file. Both transport keys and storage keys. Dropbox does at least (allegedly) encrypt stuff for storage, so they can RMA hard drives without having to destroy them first, but that's pretty meaningless. There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good…

What alternative do you suggest?

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#50
post #9

What sort of threats does the NSA give to these companies so they participated without any leaks? Just curious what the penalty would be if the NSA approached me about sucking down my user data and I refused.

Many many years ago I worked at an ISP and I remember getting emails of the form:

  From: manager@corp.com
  To: minimax@corp.com

  Subject: When you get a minute

  We got a subpoena to provide information about 
  . When you get a second 
  can you grep through the logs and provide any 
  connection details if he was online from  
  to . Thanks.
I didn't even think about it. Maybe the people in legal did? Once or twice I heard that the guy we helped track down was a legitimate bad guy (like a murderer or something), but in general I just remember it being just like any other day-to-day task. I'm not saying I actually handled any of these NSA requests. I have no idea if I did. I never actually saw any of the subpoenas.
Post reply on HN