6 ms·
Again with the 'carefully worded denials' - the denials were similar because they were accused of the same thing, which is allowing "direct access". The most w
by rasterizer 13y ago
Again with the 'carefully worded denials' - the denials were similar because they were accused of the same thing, which is allowing "direct access".
The most worrisome and misunderstood part of these reports is the "direct access" bit: can the government arbitrarily query company servers? their denials address that, they clearly say that is not the case, instead they sftp the data after being served with court orders or warrants and yes also the secretive FISA requests.
So by revealing the number of FISA requests they receive and their scope they hope to clear this "direct access" mess. As even FISA orders are much more acceptable than wholesale access.
As for the development being reported here: I think it has merit seeing how this clearly falls under the first amendment, but I'd like a lawyer to chip in.
[edit: clarity]
- burntsushi 13y ago> So by revealing the number of FISA requests they receive and what sort of data is being sought they hope to clear this "direct access" mess. As even FISA orders are much more acceptable than wholesale access. Not necessarily. As another commenter pointed out [1], a single FISA order doesn't have to correspond to a single citizen. One order can encompass millions of accounts. > their denials address that, they clearly say that is not the case, instead they sftp the data after being served with court orders or warrants and such, including the secretive FISA requests. While I think it's reasonable to doubt the claim that the NSA has true direct access to servers, I haven't been given a reason to doubt that information can be requested without court orders, warrants or FISA requests. [1] - https://news.ycombinator.com/item?id=5901811 https://news.ycombinator.com/item?id=5901811
- GreatBuck 13y ago> Not necessarily. As another commenter pointed out [1], a single FISA order doesn't have to correspond to a single citizen. One order can encompass millions of accounts. The court document from Google (http://assets.nationaljournal.com/img/MOTION.pdf http://assets.nationaljournal.com/img/MOTION.pdf) clearly states the desire to clearly list, in aggregate, the number of accounts impacted.
- burntsushi 13y agoI know. I wasn't responding to Google's court document. I was responding to rasterizer.
- rasterizer 13y agoThey would want to publish the scope of the FISA requests. The other companies aren't going this far and I think they deserve a credit for what they're doing. And I disagree with commend you link to, the solution isn't limiting data collection, sure it makes you a target but more data equals a better product. It's an issue of government overreach not engineering decisions.
- burntsushi 13y agoWe've had a misunderstanding. I agree with this entire comment. Even the part where you disagreed with part of the comment I linked to. I even responded to that poster before replying to you. :-) (Sorry about that. I meant to link to the comment for the text of the FISA order, and not for the jab against Google.)
- redblacktree 13y agoThis is a distinction without a difference. If I (the NSA) can request yesterday's backups, isn't that close enough? I don't particularly care if they have direct access to Google's servers. Having access to the backups (through sftp or whatever other mechanism) is bad enough.
- skybrian 13y agoIt's a checks and balances thing. If you're a large ISP and you retain physical control over your servers and network, if you're asked to hand over too much information, it's at least possible to delay and fight it in court. If they have root then you don't even know what they've done.
- lazyjones 13y agoIf they had to request anything from Google or FB, they wouldn't need such huge storage capacities. My guess is that these large companies have been forced to forward data (e-mail, chat lines, posts...) to the NSA as it arrives. It's not "direct access", it facilitates all the searches the NSA could wish for on NSA's own servers and does not contradict any of Google's, FB's or the NSA's claims so far from what I can tell (they store the data, then "collect" it as needed).
- discostrings 13y agoFrom what Google's said, it appears the government can't arbitrarily query Google's servers. Google has stated pretty clearly that someone at Google has to check off before an account is pushed to a machine that the government can access and that the data cannot be accessed without this happening. That's Google. We've yet to hear from many of the other companies in the program about whether this sort of access is technically impossible, or whether it's an honor system that the government is supposed to follow.[1] I haven't been closely following the Facebook, Microsoft, or Apple statements, so maybe they have also been explicit that it is a restriction that is implemented by technical means. Some of the companies haven't said anything yet. How many of the companies really make sure there is legitimate documentation for each request? Do they really do this every time, or have they become resigned to the fact that there's nothing they can do, so they just rubber stamp each request coming through, even without the proper legal documentation? [1] This seems to be a major issue--the President and NSA leaders have claimed that analysts "cannot" access your phone metadata and phone call content without the correct legal instruments. But by "cannot", they seem to mean "they are not allowed to" rather than "it is not possible for them to".
- famousactress 13y agore: [1]... Right. In fact, this morning I think we heard this is definitely policy and not technology. We were told that for this to happen [paraphrasing from memory] "One person would have to break the law [analyst], his boss would have to break the law [because he's supposed to approve the access], and remember this entire process is 100% auditable, so we'd catch them for sure." Of course, this isn't remotely reassuring for a bunch of reasons. Most of all though, I'd be curious to hear more about how the auditing process works. He kept saying "auditable" I noticed, not you know... "actually audited".
- mpyne 13y agoSnowden mentioned in the Q&A that 5% of the GCHQ accesses are audited, as one example. He mentioned 5% as if it's a low value but that's actually fairly high, especially if randomly-picked.
- humanspecies 13y agoThe leaked slides say clearly the government can query the servers at will. They get real time login data, logout data and payload data. I don't know why people keep putting this into question, giving Google the benefit of the doubt, when they were caught pants down, no questions asked. If the companies mentioned in the slides just complied with the law, why would they be singled out in those slides? Honoring search warrants and FISA requests is an obligation, not an extra. The reason Google was singled out as a partner since 2009 is because they gave the government full unrestricted access.
- smtddr 13y agoWell, judging by your comment history(about 100% anti-Google), I won't be taking your word for it. I'm still waiting for the dust to settle and see where Google ends up. Right now, it's just a bunch of people pointing fingers at each other. The truth will be found once everyone calms down.
- kryten 13y agoOr when everyone agrees on a mutual truth even if it's not the real truth...
- grey-area 13y agoThe reason Google was singled out as a partner since 2009 is because they gave the government full unrestricted access. Which part of the PRISM slides make you think that? They certainly indicate pretty much full access to accounts which have been OK'd by Google (at least in archive form), but that is very different from 'full unrestricted access' to servers. I'd say we don't really know the extent of it, and welcome Google's decision to try to challenge the government in court to reveal more details. As far as I read them the few PRISM slides we've seen don't really indicate: 1) The extent of access (how many accounts, how many accounts per order etc) 2) The mechanisms for FISA access 3) Any time delay in receiving documents/access 4) Whether data is realtime or not after access is granted and the figures that FB, MS, Apple have announced hardly constitute full unrestricted access to all accounts as you seem to be implying. It's still a serious invasion of privacy, there are serious doubts about the efficacy of the FISA court supervision, and for foreigners I'm not even sure there are any protections at all (the NSA might not even feel obliged to get specific permission for non-US communications), so for everyone outside the US this is really invasive, but I'm not sure I can agree with your characterisation of these slides as showing full access (full access to what, to all Google servers, seriously?).
- aryastark 13y agoGoogle and Facebook are trying to clear their name here. But what I'm afraid of is that this mess with deciding exactly how much access the government has to Google will turn into a distraction from the larger picture. Which is that, in all likelihood, the NSA does not have access to Google. What they do instead, and what the name PRISM implies, is that they connect to the backbone (Verizon/AT&T), scoop up ALL data, and store it in their freshly built data center in Utah. The slides I saw seemed to indicate when certain applications or filters came online. Such as a filter for Facebook data, or a filter for Google search/map/GPS data, etc. That's how I interpreted the graph, at least. It would indicate the NSA is rolling out specialized applications to handle data coming to and going from specific sites. Which allows them to more intelligently decipher what is being said, in more or less shotgun fashion. Hence, the name PRISM. It's a project to split the full Internet stream into a Facebook bucket and a Google bucket, etc.
- seanmcdirmid 13y agoIt doesn't help just to have network transmission data if the data is encrypted. Google has increasingly been moving all of their services to https, I think facebook might be also.
- chaz 13y agoThe problem I have with the "duplicate the Internet" theory is that it favors the hard solution vs the easy solution. The hard solution is to secretly duplicate traffic from every data center operated by each of these companies, reverse engineer every HTTP request that goes back and forth so that the data can be parsed, maintain it for every product change that happens at these companies, circumvent HTTPS by compromising the certificate authorities, store it all, and still maintain a massive analytics tool that can make sense of the astounding amount of data coming through. The easy solution is to avoid all of the technical ugliness of acquiring the data, and just legally make the companies give you the relevant information, neatly structured and packaged. NSLs are the ultimate hack.
- sneak 13y ago> circumvent HTTPS by compromising the certificate authorities You cannot decrypt passive monitoring with a CA's key.
- fernly 13y agoSteve Gibson presented a good case[1] that the companies are telling the truth, but that NSA nevertheless has the equivalent of full access by tapping the tier-1 or -2 router nearest to each. Fiber-optic "splitter" makes the codename "Prism" cogent. [1]http://twit.tv/show/security-now/408 http://twit.tv/show/security-now/408 for audio and relevant links
- MichaelGG 13y agoSteve Gibson doesn't really know what he's talking about, does he? At any rate, assuming all fibre optic is tapped, how does that explain breaking SSL? That's a really big jump.
- jshen 13y agoYou didn't add any valuable information to this discussion. Why doesn't Gibson know what he's talking about? Explain what exactly regarding SSL breaking? What's the jump?
- jamesaguilar 13y agoIf you're talking about this, you should have a cursory understanding of what SSL is and why the MitM attack Gibson is describing is, at best, far fetched.
- jshen 13y agoI'm pretty sure Gibson knows how SSL works, and I don't see why you think it is far fetched.
- fernly 13y agoHis point wasn't "all fibre optic" but that by tapping specific routers, e.g. one close to Facebook where FB traffic is concentrated, the NSA can filter and store nearly all FB traffic while FB has full deniability. At the referenced link are links to court documents in which exactly this kind of tap was revealed to exist at AT&T. As to SSL, is there a claim that NSA has broken it? I wasn't aware of that. Not relevant to Gibson's idea, anyway.
- salmonellaeater 13y agoFrom the article: When news of the PRISM program was first revealed two weeks ago, officials at Facebook, Google and other tech firms informally conferred on a public response...
- flyinRyan 13y agoFirst of all, it doesn't really matter what Google says because they could be lying. Second of all, there are trivial ways around "direct access". Google will have world class mirroring capabilities, so they need only mirror to a government server. They could do this manually (per request) or automatically. This would fit within "no direct access".