HN user

rasterizer

1,345 karma
Posts7
Comments66
View on HN

You want me to speculate about arrow direction?! alright, generally speaking the access is not "direct" because the "boxes" act as buffers. I can't say if they "pull" the boxes or they just serve subpoenas to them and get the data pushed back.

Obviously there is plenty of room for speculation but what seems to emerge, at least as I see it, is that even the worst case scenario doesn't entail actual "direct access".

In the case of activity timestamps (which I'm sure legally don't get the same protection as content) they would be sent by the companies to the FBI/NSA not have their actual servers monitored by them.

Interesting. Some insight, some contradiction and confusion especially when compared to earlier reportings on the first slides:

- The "direct access" claim is replaced with "FBI interception unit" which is "government equipment on private company property to retrieve matching information from a participating company" that detail isn't mentioned in slides but provided in annotations.

- The case format notation points to "real-time notification" when a target logs in or sends emails/IM/VOIP etc:

"Depending on the provider, the NSA may receive live notifications when a target logs on or sends an e-mail, or may monitor a voice, text or voice chat as it happens (noted on the first slide as "Surveillance").

The "Depending on the provider" bit is interesting as it suggests that there are potentially different levels of "participation".

- "On April 5, according to this slide, there were 117,675 active surveillance targets in PRISM's counterterrorism database." can a FISA order cover a target across service providers or each provider requires its own order? the number of targets could dramatically be revises downwards depending on that.

HN is seemingly so oversaturated with NSA items that they're seeping into all submissions regardless:

I'll assume you are not trolling and just misinformed so I'll address your 'elephants':

- Google already said that there are no "links": http://www.guardian.co.uk/technology/blog/2013/jun/19/google...

- Statistical analysis of Google closures shows that they deprecate products at below industry pace, so your impression about that is also wrong: http://www.gwern.net/Google%20shutdowns

According to Google "NSA powers" in their case are restricted to FISA orders, so I'm not sure how a random worker at a government contractor can produce these. Snowden was a sysadmin for a contractor and that is how he got his hands on their internal documents.

Is no one else paying attention to anything beyond the "slides" in this story?!

That's stupid. Particularly how you list 'plentiful storage' as a drawback, if that's the case then it's plainly an issue of law as it pits privacy against usability.

Also Gmail is the only webmail that offers server-to-server encryption: http://news.cnet.com/8301-13578_3-57590389-38/how-web-mail-p...

And as mentioned in another comment you can delete messages over IMAP.

So in the future make sure you do some research as to avoid spreading false information.

They would want to publish the scope of the FISA requests.

The other companies aren't going this far and I think they deserve a credit for what they're doing.

And I disagree with commend you link to, the solution isn't limiting data collection, sure it makes you a target but more data equals a better product. It's an issue of government overreach not engineering decisions.

Again with the 'carefully worded denials' - the denials were similar because they were accused of the same thing, which is allowing "direct access".

The most worrisome and misunderstood part of these reports is the "direct access" bit: can the government arbitrarily query company servers? their denials address that, they clearly say that is not the case, instead they sftp the data after being served with court orders or warrants and yes also the secretive FISA requests.

So by revealing the number of FISA requests they receive and their scope they hope to clear this "direct access" mess. As even FISA orders are much more acceptable than wholesale access.

As for the development being reported here: I think it has merit seeing how this clearly falls under the first amendment, but I'd like a lawyer to chip in.

[edit: clarity]

I disagree. Opt-out is the right approach, if you are using someone else's product you should assume you're interactions with it are being measured.

It's beyond quid pro quo, it's how software improves and evolves, and it is to the benefit of everyone: you, other users, vendor.

You are overreacting, not to mention reaching the wrong conclusions from these NSA reports. The problem isn't measurement, that is a cornerstone of engineering (and of everything else really), the problem is government overreach.

It's almost as insane as that piece in Slate claiming that Hadoop is evil because it enabled large scale data analysis (http://www.salon.com/2013/06/14/netflix_facebook_and_the_nsa...). Technology is not the issue.

This newly found aversion to tracking and measurement is a stupid knee-jerk reaction to the news.

Are you suggesting that they shouldn't have a transparency report at all unless everything is on the table? I disagree. They aren't even allowed to mention FISA so they don't, and they don't have to disclose anything.

Edit: also as someone already commented here: they do mention that the data is 'not comprehensive'.

It wouldn't just break IMAP, POP, and search; it would also break the cooler new stuff like Inbox Actions and Google Now.

Is it either privacy or usability?!

It's fundamentally an issue with the law: if they can't even feature FISA orders in their transparency report then their hands are pretty much tied. One could only hope that these reports will result in a change in the law itself.