5 ms·
To be fair, according to this article, Google, Microsoft, Apple, and others have explicitly denied allowing government officials direct access to their servers.
by crystalmeph 10y ago
To be fair, according to this article, Google, Microsoft, Apple, and others have explicitly denied allowing government officials direct access to their servers.
However, due to the secrecy requirements of the law, we cannot know if they did allow the government some other form of access that was functionally equivalent to a rootkit on the server in terms of what the government could access.
Pure speculation on my part: Yahoo probably got the court order and made the decision that the government was going to get what they wanted anyway in the end, and resistance was going to be futile, and they probably figured that since no-one was going to be able to hear about them fighting against this order, it wouldn't even do their reputation any good to fight it. Of course, if I'm right, they miscalculated a little bit on that last part, since they obviously didn't count on a leak of the fact that they did roll over, which now has damaged their reputation.
- jwtadvice 10y ago> To be fair, according to this article, Google, Microsoft, Apple, and others have explicitly denied allowing government officials direct access to their servers. Right, but the statements were very carefully crafted PR statements that only implied that there were no similar feeds while leaving open the possibility that there may be. Having watching the industry for some time (Skype's PR denials come to mind as well as all the companies implicated in the Snowden disclosures) I have no confidence that those PR releases mean anything of significance besides a recognition from the companies that their users might not like certain activities by their customers.
- CobrastanJorji 10y agoBruce Schneier agrees with you, which lends your argument some credence to me, but I thought "We’ve never received a request like this, and were we to receive it we’d challenge it in a court" was about as broad and clear a statement as could reasonably be made about this. What would you need them to say?
- jwtadvice 10y agoSomething like "We do not have any programs or agreements whatsoever with law enforcement to share any user data or metadata or summaries or analysis of said information. We screen our employees for infiltration from intelligence community members, putting them only in positions where they can not influence our systems without significant risk of discovery and where they can not influence our systems without involving a large number of other people who we empower to contact the public and the media if they see anything suspicious. Furthermore, we have no shareholders or executives with business, security or personal relationships with federal police / national security personnel. Finally, we've designed our product such that the very most minimal set of information and meta information is ever available to us, even if we try, and so the amount of abuse that we could perpetrate is at the very most X, where X can be understood by someone who carefully looks at our design. In addition to this, I and significant parts of our company leadership will step down from our roles if any information contradicting any of this ever comes out." Though I wouldn't hold my breath. The wiggle room in "request like this", for example, is huge. That's not something that I'm being particularly pedantic about - it's something we've seen repeated evidence for. Basically, I've lost trust in the public relations portions of these businesses - which are not empowered to know the truth about what goes on at their organizations to begin with. The only technologies I feel confident placing trust in are ones that don't require placing a trust (forever) in one of these corporations (as well as all future employees and shareholders). (Twitter is a good example of a company that has held out for a very long time, but has eventually given way to pressure.)
- CobrastanJorji 10y agoYour proposed requests would include responding to legal warrants, which all of those companies already admit to doing. Could I suggest "We do not ever voluntarily comply with any requests for user data or metadata or summaries or analysis, we resist involuntarily, legally mandated compliance as much as legally allowable, and we publish as much information about information we give away in as much detail as we legally can."?
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- Ygg2 10y ago> Google, Microsoft, Apple, and others have explicitly denied allowing government officials direct access to their servers. Yes, of course I will trust them. I am sure that they were paragons of user rights
- erichocean 10y ago> Google, Microsoft, Apple, and others have explicitly denied allowing government officials direct access to their servers And the government can compel them to lie about that, too. So their statements are literally useless and cannot be trusted. Period.