5 ms·
U.S., companies: Internet surveillance does not indiscriminately mine data
- danso 13y agoTwo things about the submission title, which is currently: "WaPo: Execs From Internet Companies Acknowledge PRISM" 1. The original title for the article is "U.S., company officials: Internet surveillance does not indiscriminately mine data" 2. The excerpt that the submitted title refers to is this: "Executives at some of the participating companies, who spoke on the condition of anonymity, acknowledged the system’s existence and said it was used to share information about foreign customers with the NSA and other parts of the nation’s intelligence community." Some, not all of the companies involved. So too soon to conclude that the public statements were lies...but Zuckerberg and Page, at the least, could be said to have lied if the companies referred to in the OP are them (both Page and Zuckerberg said that they (they as in "we") had no prior knowledge of PRISM at all)
- ennuihenry 13y agoI agree on #2 and changed the title as I don't want that inference to be made.
- waterlesscloud 13y agoThere's definitely some questions here, though. "government employees cleared for PRISM access may “task” the system and receive results from an Internet company without further interaction with the company’s staff." What does that mean? Does the company have any oversight over what's being requested? It doesn't sound like it. How does that square with the statements from the CEOs that each request is carefully considered and restricted? “The server is controlled by the FBI,” an official with one of the companies said. “We do not offer a download feature from our server.” This is a very fine distinction that doesn't matter much. Word games are being played here.
- leoc 13y ago> What does that mean? Does the company have any oversight over what's being requested? It doesn't sound like it. How does that square with the statements from the CEOs that each request is carefully considered and restricted? This was covered yesterday, in the NYT article http://www.nytimes.com/2013/06/08/technology/tech-companies-bristling-concede-to-government-surveillance-efforts.html http://www.nytimes.com/2013/06/08/technology/tech-companies-... : > The data shared in these ways, the people said, is shared after company lawyers have reviewed the FISA request according to company practice. It is not sent automatically or in bulk, and the government does not have full access to company servers. Instead, they said, it is a more secure and efficient way to hand over the data. So, it seems, there are Google-lawyer mechanical Turks clicking "OK" or "Contest" (or whatever) for each FISA order in the Google FISA-order queue. If the lawyer clicks "OK" it seems the requested information is slurped automatically from the Google user-data servers into the PRISM server's outbox (and/or a live data feed is set up). If the lawyer clicks "Contest" then presumably something messier and more manpower-intensive happens. A system like this raises plenty of questions - but it doesn't at all automatically conflict with or falsify what the tech CEOs said. EDIT: Actually there's apparently a direct conflict between the NYT's version and what WaPo appears to be saying here: > According to a more precise description contained in a classified NSA inspector general’s report, also obtained by The Post, PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises, according to sources familiar with the PRISM process. That seems to imply that there's no Google-lawyer mechanical Turks reviewing the individual FISA orders. Given that that would contradict both the NYT report and the statement from (for example) Page and Drummond http://googleblog.blogspot.ie/2013/06/what.html http://googleblog.blogspot.ie/2013/06/what.html this is a big deal. Given the WaPo's demonstrated ability to misunderstand information from NSA sources, for the moment I'm inclined to assume that the Post has got this wrong, too - but let's see. (Another possiblity might be that some companies are waving FISA orders of the form "give us the personal data of Suspect X" through automatically, while others still have a lawyer clicking "OK".)
- danso 13y ago
- leoc 13y ago> Zuckerberg and Page, at the least, could be said to have lied if the companies referred to in the OP are them (both Page and Zuckerberg said that they (they as in "we") had no prior knowledge of PRISM at all) How so? They said they had no system for direct access, and indeed PRISM is apparently not a system for direct access. They said they hadn't heard of PRISM, but it's at least quite possible that they weren't familiar with the NSA's "PRISM" moniker, as opposed to the system itself.
- eightyone 13y agoAccording to a new slide released by the Guardian, PRISM does give direct access. [1] [1] http://guardiannews.com/world/2013/jun/08/nsa-prism-server-collection-facebook-google http://guardiannews.com/world/2013/jun/08/nsa-prism-server-c...
- leoc 13y agoThis is not direct access in the sense which the Guardian and Washington Post suggested yesterday and the tech companies denied. OP is the Washington Post (which has access to the full PowerPoint) backing down from that claim, something it had already started to do yesterday http://www.forbes.com/sites/jonathanhall/2013/06/07/washington-post-updates-hedges-on-initial-prism-report/ http://www.forbes.com/sites/jonathanhall/2013/06/07/washingt... . In the context of the latest slide it's clear that direct collection probably means collection from the endpoint - Google, Facebook etc. - as distinct from "upstream" collection by wiretapping IP traffic through US telcos' networks.
- grey-area 13y agoWhat's the difference? If PRISM means the NSA has unsupervised access to any records they want from these providers, that's pretty disturbing, irrespective of word-games over the meaning of 'direct'. The scope for abuse of this sort of unregulated access rubber stamped by a secret court is huge, and there doesn't appear to be any effective supervision as people like clapper are happy to lie to congress about the extent and methods of the various surveillance programs, and the companies are obliged to lie about the program and conceal its existence.
- waterphone 13y ago> “The server is controlled by the FBI,” an official with one of the companies said. “We do not offer a download feature from our server.” Now we know why they phrased their statements so specifically.
- runn1ng 13y agoyour comments seem to be helbanned (i am writing it here since it's the newest non-helbanned comment of yours)
- fiatmoney 13y agoSeems to indicate the NSA is performing some sort of MITM, or running intercepts from inside the datacenter after the traffic has been decrypted: "PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises" "From their workstations anywhere in the world, government employees cleared for PRISM access may “task” the system and receive results from an Internet company without further interaction with the company’s staff."
- deleted 13y ago[deleted]
- cupcake-unicorn 13y agoYou don't have to be the NSA to intercept public WiFi traffic..I do it all the time on Wireshark :P
- jtchang 13y agoTwo ways I could see this being set up: 1. NSA goes to Facebook and tells them to install a server/rack in their data center. The server needs to be on a port that can "see" all traffic unencrypted. The servers then transparently record data and analysts on the backend parse it into something useful. 2. NSA puts servers on premises but instead they are pushed formatted feeds of data. This would require them to work more closely with the company to make sure they provide a feed that is workable. They would store the data and as requests for data came in the server would feed it back.
- dm2 13y agoYou're assuming that the NSA requires physical access to unencrypted data. The NSA has been in the IT security game for a very long time, they employ the best of the best, and have practically unlimited funds. I'd imagine that very complicated algorithms determine who to monitor and what keywords to look for. Images from the middle east or a VPN are likely more heavily analyzed than images from a college campus inside the US. Why set up shop at specific social media companies when they have physical access to backbone routers and root certificate private keys? Yes, it would be easier to just ask FB/Google/Apple to give them unlimited read access to their databases, but that would be a scandal waiting to happen.
- acqq 13y agohttp://www.guardian.co.uk/world/2013/jun/08/nsa-prism-server-collection-facebook-google http://www.guardian.co.uk/world/2013/jun/08/nsa-prism-server... The slide with the explicit formulation was published, written by NSA, that made claims of "not inside companies" much less believable: "Collection directly from the servers of these U.S. Service Providers: Microsoft, Yahoo, Google, Facebook, Paltalk, AOL, Skype, YouTube, Apple." This supports the claims of Glenn Greenwald's article and is exactly what companies claimed not existing. Read the slide: they explicitely name the collecition on the "fat pipes" under other code names. As they have the access to the big pipes, the real time data (c.f. the other slides, earlier) from the inside of companies is certainly unencrypted.
- 13y ago
- deleted 13y ago[deleted]
- dclowd9901 13y agoThey simply don't get it: I DO NOT BELIEVE THE US GOVERNMENT HAS ANY RIGHT TO VIEW MY DATA THAT I ENTRIST TO PRIVATE COMPANIES. In the event they somehow have stumbled upon the right, I should be notified that my data has been examined.
- necubi 13y agoThat's great, but it's not the law. If you would like it to be the law, work on repealing the Patriot Act and rolling back the worst abuses of the post-9/11 surveillance state. Or donate to the EFF and ACLU, who have been raising alarm about these laws for over a decade. But don't blame the companies involved. They're following the law, as laid down by duly-elected representatives. The alternative is that their executives go to jail for contempt of court.
- mtgx 13y agoWell EFF have already discovered that the law has been declared unconstitutional, but the administration is keeping it secret. What now?
- richcollins 13y agoThe companies are people. You should always blame people that engage in activities they know to be unethical. Why should they get a pass?
- dm2 13y agoHow can you trust the US government less than private companies? Data mining exists at every company because of its value. I'm much more concerned that private companies (Lexis Nexis I'm looking at you) have access to so much of my data and have no obligation to inform me of what data they have. The US government exists to protect the United States and its citizens. If we put left vs right politics aside, why is there inherit distrust of the government? What would make you trust them? More transparency? If anybody is to blame it is congress. As elected representatives, they should have ultimate responsibility as to what happens in this country. They should also be held liable for ALL of their actions, but good luck getting them to approve that. How can congress enact laws that only affect themselves or give them more power? That is corruption and should be considered treason.
- detcader 13y agoSome guy on Tumblr picked apart Yahoo's carefully worded denial, actually [1] turns out it's totally bunk [1] http://peterhassett.tumblr.com/post/52499296411/exclamation-setting-the-record-straight http://peterhassett.tumblr.com/post/52499296411/exclamation-...
- Kylekramer 13y agoAnalysis of text related to subjective ideas can make anything bunk ("What do they mean 'all men are created equal'? Isn't our individualism what makes us great", etc.). Line by line analysis are particularly insidious because any idea can be proposed and appear to be a reasonable response without any likelihood of response from the original party. If you want to find problems with the various companies' responses, you sure can. I am positive things have happened with Google, Microsoft, Yahoo, Apple, etc. and the government that most people would find offensive. But playing semantic games that push particular agendas without the full story is misleading and imprudent.
- josephagoss 13y agoBut he makes some good points, especially about the heavy use of the word "volunteer" and also "give", all which imply Yahoo! isn't freely giving access to the NSA. Yahoo! never said that they were disallowing NSA lawful requests for bulk data, which is the topic of concern. (Of course Yahoo! isn't volunteering information, that is not concern at all, if the NSA demands then its not volunteering information) The issue is that all the PR from Facebook, Google and Yahoo! are using very specific non-broad language to say they are not doing a very certain thing, a thing that is not the concern. The concern is about lawful access to all servers and not one piece of PR said this was not happening. (In the current definition everything the NSA is doing would be considered lawful as the Government post 9/11 is able to use its various provisions to allow for a whole manner of things that we might disagree with, but we are not writing the law, they are.)
- dclowd9901 13y agoHe misses the part about them not giving the government "unfettered" access. That's narrow enough to meet the criteria of "otherwise" access. That's the problem with all of these statements. They're very specific with their language.
- l33tbro 13y agoOne question: Where is Anonymous in all this? I was expecting all kinds of DDOSing going down in the last 48 hours, but they have been unusually quiet.
- deleted 13y ago[deleted]
- btilly 13y agoIf I were a Chinese official reading this, my #1 priority would be to try to get access to PRISM. No matter what checks and balances the US may employ to make sure legitimate access stays within bounds, any time you have an automated system, you're open to the possibility that someone can get access and automate it in ways you don't like.
- wyck 13y agoYou can apply here: http://jobs.saic.com/job/Molesworth-NATO-Intelligence-Fusion-Center-Collection-Manager-Job-ENG/2582487/ http://jobs.saic.com/job/Molesworth-NATO-Intelligence-Fusion... Intelligence Fusion Center Collection Manager Requires proficiency with PRISM, RMS, and Coliseum and Top Secret clearance, amongst other things.
- tsotha 13y ago>If I were a Chinese official reading this, my #1 priority would be to try to get access to PRISM. No it wouldn't. You'd be after the things Chinese spies are already after: trade and military secrets. They don't care who's calling who.
- chaz 13y agoI wouldn't rule it out. According to the reports from early this year, China appears to be very interested in finding sources and dissidents, which is why US journalists have been hacked.
- nostrademons 13y agoOne of the things that's probably in PRISM is a list of people who are currently suspected of being Chinese agents. That's very important information if you're China. China's also known for doing indirect attacks, where they try to compromise one system in order to get clues on how to compromise another. Having access to PRISM, depending on how it's implemented, would potentially open up access to all sorts of information collected by American tech companies. Heck, if they had access to social-graph data, they could determine who is friends with a lot of employees of the targeted company, and that would be a likely person to try to mine for trade secrets.
- OldSchool 13y agoGotta love a headline that's worded in such a way that it looks like a fact. Thirty straight days of these on every major outlet and most people who were not already concerned won't be doing anything differently, if they ever did. As a bonus, no need to worry about breaking the story anymore.
- OldSchool 13y agoThe best thing the government could do to legitimately appease citizens is pass a statute that nothing gathered through these means will be used to prosecute anything but terrorism or threats to national security. If that's the real purpose, then they should have no problem putting it in writing.
- bilbo0s 13y agoJust playing Devil's Advocate here... What's to stop them from classifying... say .... computer hacking... as a threat to National Security?
- tsotha 13y agoThat's what happened with RICO. When it was passed they told us racketeering was only organized crime. Now you can get RICO charges doing just about anything.
- OldSchool 13y agoI'm guessing you're referring to something at the level of discussion of vulnerabilities as opposed to actually breaking into some government resource or an enterprise with enough leverage to affect the nation in some way. Yes, enough lawyer-speak combined with general ignorance could probably make a jury believe any kind of security talk is somehow threatening. I suppose that's where careful wording comes in, for example limiting a threat to include intent to act on at least some specific class of target.
- sneak 13y agoYou can use the information in ways to harass and intimidate even without using it for prosecution; e.g. the FBI threatened to publicize MLK's extramarital affair (which they'd discovered by putting him under surveillance (authorized by the then-Attorney General RFK)) if he didn't give up his civil rights work.
- OldSchool 13y agoSounds like we'd all need a broader term than prosecution in addition to clearly defining an actual threat. All documented by the same personalities who are often tasked with finding holes in such statutes.
- joe_the_user 13y agoCan anyone say exactly what this paragraph is supposed to mean (or really mean, if there's a difference): Intelligence community sources said that this description[direct access], although inaccurate from a technical perspective, matches the experience of analysts at the NSA. From their workstations anywhere in the world, government employees cleared for PRISM access may “task” the system and receive results from an Internet company without further interaction with the company’s staff. So they get data from an ad-hoc query without interaction with the company's staff. And yet it is not direct access? I've read the other back-and-forths but I'm still not sure what this could even trying to imply. Edit: and read - According to a more precise description contained in a classified NSA inspector general’s report, also obtained by The Post, PRISM allows “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers. The companies cannot see the queries that are sent from the NSA to the systems installed on their premises, according to sources familiar with the PRISM process. But that the meaning is no more clear. Or the meaning is, we buy an "indirect access cable at Best Buy and so everything is OK", ie, the distinction is nothing but word games.
- leoc 13y agoThere's a major apparent contradiction between that second quotation and other sources (the NYT, Google itself) - see my other comment https://news.ycombinator.com/item?id=5847846 https://news.ycombinator.com/item?id=5847846
- efsavage 13y agoyet