6 ms·
White House Takes Security Pitch to Silicon Valley
- rurounijones 11y ago“I think that people and companies need to be convinced that everything we do in the cyber domain is lawful and appropriate and necessary,” (Emphasis mine) Step 1, make this first point true at least (the second and third points will probably be debated until the heat-death of the universe). Quite heartened by the rest of the article though; techies standing by their principles.
- pen2l 11y ago> Quite heartened by the rest of the article though; techies standing by their principles. Funny principles, those. Ads, privacy violations, more ads, dark patterns, some more ads.
- AndrewKemendo 11y agoNo, those are just those pesky business people forcing that on the purity of my Docker lib.
- higherpurpose 11y agoUnfortunately they've already managed to convince Apple that its zero-day sharing program is "lawful" and that Apple is doing a good thing there. Or Apple just conveniently ignored the fact that those zero-days are given to the NSA on a silver platter, so the company can get its Apple Pay integrated with federal services (funny how that deal was announced at the same time Apple agreed to share its zero-days with the government - no? Yet, virtually all the Apple-loving media seemed to conveniently ignore what that meant). http://www.ibtimes.com/us-federal-government-accept-apple-pay-starting-september-1816084 http://www.ibtimes.com/us-federal-government-accept-apple-pa... Either way, the deed is done, and now the government thinks that if it could convince Apple, then it can convince other weaker-minded people and companies as well. And it's just a matter of putting enough pressure on them (through the new DHS office in Silicon Valley). After all, their deals made with the telecom companies many decades ago worked pretty well - so why not tech companies, too, especially if they promise them immunity from ever having to worry about legal repercussions for their relationship with the NSA.
- chrisbolt 11y agoAny citations? I can't find anything when I search for "apple zero day sharing program" or "apple zero day nsa". http://arstechnica.com/security/2013/06/14/nsa-gets-early-access-to-zero-day-data-from-microsoft-others/ http://arstechnica.com/security/2013/06/14/nsa-gets-early-ac... doesn't mention apple.
- higherpurpose 11y agoThen try "cyber-sharing" executive order. It's the same thing. They are supposed to share "vulnerabilities" and "other data" about the potential targets. Same thing with the new CISA/NPCA bills.
- tptacek 11y agoI'm pretty certain none of this is true. It's frustrating that people can collect easy upvotes for writing innuendo like this. Note: you didn't argue that there were public policy implications to proposed legislation. You said Apple is sharing zero-day vulnerabilities, and that they're doing it to get Apple Pay accepted by FedGov clients. You've made extremely serious accusations here and insulted the integrity of a lot of good people. So I think you're now obligated to back up your extraordinary claims with evidence. Will you do that, please?
- tptacek 11y agoYour other option, if you don't have evidence that Apple has deliberately shared zero-day vulnerabilities with the USG, let alone done so in order to secure contracts with them, would be to apologize. Everyone's different, but personally: I would be uncomfortable in the limbo of having neither supported such a grave and specific argument nor apologized for carelessly starting a rumor campaign about it.
- Canada 11y ago> "I think that people and companies need to be convinced that everything we do in the cyber domain is lawful and appropriate and necessary," Mr. Carter told students and faculty at Stanford. Right, because what they're doing in the cyber domain isn't lawful. Naturally they'll fix that retroactively. > He urged the next generation of software pioneers and entrepreneurs to take a break from developing killer apps and consider a tour of service fending off Chinese, Russian and North Korean hackers... Yeah, exploitation of vulnerability isn't partisan or nationalistic. While narrowly possible, it isn't really practical to fend off Chinese hackers without also fending off American ones, and vise versa. > ...even as he acknowledged that the documents leaked by Edward J. Snowden, the former intelligence contractor, "showed there was a difference in view between what we were doing and what people perceived us as doing." I can't help but picture these hacks that shill for the administration like cheaters who've been caught trying to talk their way out of it. "Baby, I know I said I was visiting my grandma last night, and while I admit that leaked photograph of me kissing and groping my former lover is authentic, I swear to you it's not like that! The kiss had to be collected in case it was needed in the future but it's not cheating because I wasn't feeling into it at the time. You've got to understand there's a difference in view between what we were doing and what people perceived us as doing. I lied to keep you safe! Think of the greater good baby!!"
- spin 11y ago> ...even as he acknowledged that the documents leaked by Edward J. Snowden, the former intelligence contractor, "showed there was a difference in view between what we were doing and what people perceived us as doing." That one boggles my mind. On 2013, Mar 12, Clapper lied to congress about NSA spying. The purpose of a lie is so that people perceive something different from reality. So they achieved their goal, they're just sorry they got caught.
- Canada 11y agoBaby it was just the most truthful answer I could tell you. I mean, I'm sorry, I should have been more careful in my statement. I acknowledge that. But I must stress, that I did not wittingly make out and fondle. What I did was not, in any way, targeted at our relationship. My eyes were closed, and I was merely doing my duty to feel up our enemies. There is just no other technical way to go about it. And I resent the implication of wrongdoing in the unfair way you questioned me about the situation. Now, you know I love you. I would never do anything behind your back. That's why all of your friends were fully briefed on this encounter. And they all agreed that it was necessary and appropriate. Well, almost everyone. I vow to bring the perpetrator who leaked the photo to justice! And so in light of this, we can have an important debate about who else I deny I have slept with, who else you have proof I sleep with and what other sexual acts I must do with them in order to safeguard our relationship. But let's not forget what's important. We need to work together to build a framework for a process where I continue to see others I'm attracted to, particularly the Russian and Chinese ones, in a way that respects privacy, by preventing you from finding out, but with proper oversight that is transparent, accountable, and consistent with my unwavering support for monogamy. After all, the security of our relationship depends on it.
- BinaryIdiot 11y agoIt baffles the mind how little the government seems to understand technology. Yes let's create a universal key but to make sure it's not abused or falls into the wrong hands we'll just split it up over agencies or setup an escrow. Never mind the fact that this undermines the security of every single piece of American data if we're compelled to use it. If you're up to not good you're just going to download a non-backdoored encryption toolkit from somewhere else.
- kbart 11y ago"If you're up to not good you're just going to download a non-backdoored encryption toolkit from somewhere else." Good point. Software is made all around the world and there's no way for USA government to force it's backdoors (call it "golden key" or whatever) into all of it, especially in the age of open source. The purpose of wiretaping consumer grade software is clearly monitoring and controlling of casual citizens, not fighting serious criminals, hackers or enemy cyberarmies.
- pdkl95 11y agoIt is always a mistake to assume the opponent is ignorant or stupid. Of course the government knows the futility of trying to enforce the use of only "approved" encryption. A law that required the use of "approved" encryption necessarily bans real encryption tools. Anybody that is actually secure is made a criminal, which is one more law that can be enforced arbitrary if someone decides you are a problem. It should be fairly easy to filter for non-approved encryption with DPI. This gives them a nice map of all the "subversives" that are trying to evade the "monitoring and controlling of casual citizens".
- staunch 11y ago> “I think that people and companies need to be convinced that everything we do in the cyber domain is lawful and appropriate and necessary,” Mr. Carter told students and faculty at Stanford. Good luck with the convincing. Quite a few of us can read, so it will be rather impossible. > The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized. http://en.wikipedia.org/wiki/Fourth_Amendment_to_the_United_States_Constitution http://en.wikipedia.org/wiki/Fourth_Amendment_to_the_United_... > Shortly after the terrorist attacks on Sept. 11, 2001, President George W. Bush secretly told the N.S.A. that it could wiretap Americans’ international phone calls and collect bulk data about their phone calls and emails without obeying the Foreign Intelligence Surveillance Act. http://www.nytimes.com/2015/04/25/us/politics/value-of-nsa-warrantless-spying-is-doubted-in-declassified-reports.html?_r=0 http://www.nytimes.com/2015/04/25/us/politics/value-of-nsa-w... > On July 9, 2012, when asked by a member of the press if a large data center in Utah was used to store data on American citizens, Alexander stated, "No. While I can't go into all the details on the Utah data center, we don't hold data on U.S. citizens." http://en.wikipedia.org/wiki/Keith_B._Alexander#Statements_to_the_public_regarding_NSA_operations http://en.wikipedia.org/wiki/Keith_B._Alexander#Statements_t... Why are these people not in prison for violating the constitution on a mass scale? Their only defense can be that they were simply "following orders." The USA PATRIOT Act will be viewed by historians as something akin to the Reichstag Fire Decree http://en.wikipedia.org/wiki/Reichstag_Fire_Decree#Background http://en.wikipedia.org/wiki/Reichstag_Fire_Decree#Backgroun...
- afarrell 11y agoSo, it is not actually a criminal offense for law enforcement to violate the 4th amendment in collecting evidence. All that happens is that in pre-trial, a defense counsel can file a motion to suppress that evidence based on the exclusionary rule[1]. If the judge decides that the evidence was collected illegally, it is thrown out and cannot be presented to the jury. Less than 90% of cases go before a jury, but a knowledgable and zealous attorney can get evidence thrown out (or "c'mon, you know that will never fly with Judge Saris"d out) before a plea deal. This is the only way we have that warrants be sought, that they be validly[2] issued and that they be followed.--the threat that a criminal will "Get off on a technicality", either because the DA doesn't think she can prosecute, or because the evidence gets thrown out in pre-trial, or because an appeals/SCOTUS decision throws out the case. None of that matters if the evidence collected is never intended for criminal prosecutions. Either by the FBI or by the NSA. At least one of Boston's federal judges serves on the FISA court and I have it on the word of Boston's clerk of court that the FISA court judges care deeply about doing a good job and being a check on executive overreach. I believe him. But that doesn't matter at all. [1] Everyone should read http://lawcomic.net/guide/?p=1585 http://lawcomic.net/guide/?p=1585 and actually look at this flowchart for the 4th amendment http://lawcomic.net/guide/?p=2256 http://lawcomic.net/guide/?p=2256. [2] Most warrant requests are granted, not because it is a rubber stamp, but because the conditions for warrant approval are predictable and judges don't like having their time wasted with dumb requests. It's not like the patent office.
- phaed 11y ago> He urged the next generation of software pioneers and entrepreneurs to take a break from developing killer apps and consider a tour of service fending off Chinese, Russian and North Korean hackers, even as he acknowledged that the documents leaked by Edward J. Snowden, the former intelligence contractor, “showed there was a difference in view between what we were doing and what people perceived us as doing.” You mean there was a difference in view between what you said you were doing, and what your leaked internal documents SHOWED beyond a shadow of a doubt what you were actually doing and planning on doing. Do these guys not know their audience?
- wiggumz 11y agoWhite House Takes Backdoor Insecurity Pitch to Silicon Valley
- white-flame 11y agoI, for one, appreciate that this is a mainstream media article that doesn't seem to paint the government as in the right at all. It leaves the last word with the tech sector in refuting the government's positions, which is refreshing to see. (at least that's how I read it as a tech guy)
- tsunamifury 11y agoCarter's words sound like the man who see's his judgement, but still uselessly pleads innocent for the decisions he believes should be kept in the dark. I remember when my small private university received its first DOJ request in 2005 to install wire-tapping hardware on our servers. We in the IT department circled up and met, deciding to ignore this letter as a disgrace to the American public, the constitution, and the human values we believed in. Even receiving shamed us, and stirred anger and fear for years after. When we ignored it, no request came again and no consequence -- because the people who asked us to do wrong would never ask us to do it again by the light of day. Remember: stand true to what is right for you and those around you, whether in private or in public, and you'll never regret that choice from this day to your last.
- webreac 11y agoThey asked to install wire-tapping hardware on your servers because it is cheaper than hidden wire-tapping. If they do not ask again, it may be that their hidden wire-tapping hardware is in place. Or maybe, this is only conspiracy theory ?
- r00fus 11y agoSure, just like the Quest CEO who got thrown in the slammer for not cooperating with the NSA [1]. If you're big enough fish, you will be caught either with a lure or a net. [1] http://www.washingtonpost.com/blogs/the-switch/wp/2013/09/30/a-ceo-who-resisted-nsa-spying-is-out-of-prison-and-he-feels-vindicated-by-snowden-leaks/ http://www.washingtonpost.com/blogs/the-switch/wp/2013/09/30...
- mikeyouse 11y agoHe was 'thrown in the slammer' for a decade worth of accounting fraud and insider trading.. His excuse was that the big bad NSA was out to get him, but I'm not quite sure how that explains his fraudulent Enron deals; http://www.nytimes.com/2002/03/29/business/enron-s-many-strands-the-transactions-enron-s-swap-with-qwest-is-questioned.html http://www.nytimes.com/2002/03/29/business/enron-s-many-stra... Or why they had to restate $550M in revenue and then take $11 billion in writedowns from overvalued assets.. http://www.deseretnews.com/article/945565/Qwest-plans-to-restate-531-million-in-revenue.html?pg=all http://www.deseretnews.com/article/945565/Qwest-plans-to-res...
- dbpokorny 11y ago"With so much more data at stake, and attacks so frequent, cryptographers say the need for encryption is greater than ever." The NSA has discouraged the study of this branch of mathematics for decades. This is not a problem the people created; it is a problem the NSA created, and the NSA should solve the underlying problem before whining about this. You don't water your garden -> no flowers
- diminoten 11y agoI'm just tried of the general shitty attitude towards anything security on HN. Please catch up with the adults; we're trying very hard to solve a problem, and you're all pretending like the problem doesn't exist.
- fragmede 11y ago> Please catch up with the adults The condescending attitude does not do those of us, who are making progress solving that problem, any favors.
- diminoten 11y agoAnd yet others of us who are making progress solving that problem have thicker skin, and can handle a little prodding.
- emiliobumachar 11y agoIt's not that we don't take security seriously. It's that we often see governments, including the US government, as the biggest threats around.
- diminoten 11y agoAnd that's a huge mistake.
- icebraining 11y agoYou make some very good -if wordy- arguments. I'm sure everyone here has been convinced by the multiple well-defended reasons given.
- diminoten 11y agoPearls before swine. Also, they're not my arguments -- better men have written more on this topic than I have, and with higher quality writing.
- joshkpeterson 11y agoThe text for this article on the nytimes fronpage reads: >The computer industry is seeking to block surveillance, including by the N.S.A., which fears “going dark” on terror threats. I find something about the use of "the computer industry" to describe Google et al be really quaint. It's understatement. Also, what industry doesn't depend on the computer industry these days?
- tomelders 11y agoI'm sure there's a way for Silicon Valley and the US government to work together, but Silicon Valley can and should bring it's own demands to the negotiating table. This looks like a very one sided deal right now. The government gets to keep its secret courts, mass surveillance, secret drone strikes and foreign policy interference and expects the brightest and best minds in tech to sign up to facilitate all that. No deal. There is another way. I'm sure many in tech would take up the gauntlet of protecting all people if it were to be executed in a way that fits with the ideals of those people - which coincidentally align pretty well with what the US Constitution and Bill of Rights put forth 223 years ago. If the US wants security they can have it. If they want to continue to expand the military industrial complex, they should go looking elsewhere.
- forgottenpass 11y agoI'm sure there's a way for Silicon Valley and the US government to work together, but Silicon Valley can and should bring it's own demands to the negotiating table. I don't exactly trust the policy positions of the handful of major corporations that rate on the White House's radar to be beneficial to the end user/society in general.
- wahsd 11y agoNot only that, but there is simply zero confidence in negotiation with the government and you are a fool to believe anything else. You don't even have to rely on echos and messages from ancestors and predecessors, with general warnings about the abuses of the power of governance in the hands of humans; you can just look at the last few years of all the deception, all the abuses, all the killing, all the thieving, all the protection of thieves, and pilfering of civil society, and all the lies. There is absolutely zero trust or confidence to be found. Unfortunately for the government and any government, its track-record is permanent, there are no re-dos without revolution. Once the image, once the record has been sullied in the most grotesque and lazy manner in which it has been for the last 15 years+ there is simply no going back. The damage is permanent, irreplaceable, and immutable. You had one chance and choice on 9/12/2001, government; and you chose to play right into the hands and goals of the tactic of terrorism ... turning on your own people and sacrificing your principles at the cost of vanquishing the tenuous and feeble trust civil society had placed in you. Maybe you will be successful in steering the massive ship and changing perceptions and molding society as you have before in the past, government. But for now, there is a lot of trust to be made up through apology, action, and prosecuting perpetrators, i.e., showing that your actions are not just more empty promises and lies that any other run of the mill addict uses to avoid accountability for their actions and impacts on those in their lives.
- kokey 11y agoI wonder if this is going to work out as well for them as working with Silicon Valley in the 90s worked out: http://en.wikipedia.org/wiki/Clipper_chip http://en.wikipedia.org/wiki/Clipper_chip
- Lancey 11y agoSo is Washington ever going to acknowledge that they've done something wrong or are we going to keep playing the fascism game?
- cryoshon 11y agoKeep playing the fascism game. So far their strategy has been to double-down every time there's a debate. Their only real trick is to clamp down more and insist it's permanent when they're questioned. It'll break eventually.
- cryoshon 11y ago"Mr. Obama, on a trip to Stanford in February, had expressed sympathy with those who were striving to protect privacy, even while saying it had to be balanced against the concerns of the F.B.I. and other agencies that fear “going dark” because of new encryption technologies." "Expressing sympathy" means absolutely nothing when concrete actions have been taken to undermine privacy and security. I hope that the tech industry can organize around resisting the government to provide security and privacy for their users. The more robust anti-spying measures we have, the more secure we'll be from malicious actors who would use our communications against us for their own gain.
- JulianMorrison 11y ago"Going dark" is exactly what should happen. The only secure system is a secure system. For all countries X, the government of X is absolutely untrustworthy.
- datashovel 11y agoI sure hope Silicon Valley isn't buying what D.C. is selling.
- datashovel 11y agobtw, not inferring that there's no room for compromise. But I think one of the only ways to make "surveillance" policies sustainable is by making their operations fully transparent. I get the eerie feeling this is not what US Govt. wants to do.