13 ms·
Sharing National Security Letters with the Public
- CiPHPerCoder 10y agoHas anyone on HN ever been notified by Google/Yahoo/other that they were the subject of an NSL? I wonder if the people most likely to care about that are unlikely to ever be targeted?
- rhizome 10y agoNSLs prohibit informing the target.
- dewey 10y ago"A Google spokesperson said the usernames were redacted to protect user privacy and that the targeted individuals had been notified."
- privong 10y agoThe notification to targeted individuals was presumably after Google had successfully fought the gag order.
- CiPHPerCoder 10y agoRight. I meant one of the published NSLs where "the targeted individuals have been notified", not the unpublished ones.
- swalsh 10y agoImagine the possibilities of this, combined with McCarthy's wet dream palantir.
- plussed_reader 10y agoYou mean Trumps wet dream, Palantir? What a perfect vessel for public/private cooperative actions! I'm sure his buddy Pete would give him a huge referral.
- indolering 10y agoI've had at least half-a-dozen non-techie friends signup for Signal since Trump's election.
- hlieberman 10y agoSignal is awesome! However, it does very little to help the very case we'd have to deal with around NSLs. Signal doesn't aim to conceal metadata about who is communicating, just what they are communicating about.
- colordrops 10y agoI'm not sure what to think about Signal. It's got some great supporters like the EFF, but on Android, it requires about a dozen permissions, most unnecessary. It also requires your phone number to register, and uses a Twilio API at registration. WTF? What are peoples' thoughts on Silent Phone? It's written by the creator of PGP, only requests permissions when it needs them (at least on Android 6 and up), and stores encryption keys locally.
- james_pm 10y agoBut not under Obama or (potentially Hillary)? What about Trump makes them so fearful now where they weren't under the current state of affairs. I'm not saying that a Trump presidency isn't a great way to convince people to get a Signal account, but it strikes me that NSA spying and everything else that's gone on over the past decade should have been enough.
- cmdrfred 10y agoObama put the left to sleep. Ironically Trump will probably be the best possible outcome for civil liberties as people will actually fight him.
- whybroke 10y ago>...combined with McCarthy's wet dream... His dreams really can come true: http://mediamatters.org/video/2016/06/13/fox-s-gingrich-calls-new-version-house-un-american-activities-committee-response-orlando-shooting/210888 http://mediamatters.org/video/2016/06/13/fox-s-gingrich-call...
- secfirstmd 10y agoI wonder how this writing of a NSL letter would affect an organisation's warrant canary (if they have one).
- kakarot 10y agoThere's always blackmail, too. Plenty of ways to force a warrant canary to continue as normal
- indolering 10y agoThat's what an NSL is ... if you don't comply they throw you in jail. If you challenge a charge, the prosecutor will often add new ones.
- jonlucc 10y agoWho do they jail? You can't jail a corporation, so do they jail the CEO? The lawyer who sends the letter saying they won't comply? Either way, isn't that just begging for that information to be made public? Suddenly, Sundar Pichai is missing, and someone finds out he's in jail. That's going to be a story that gets reported (and probably leaked widely).
- kabdib 10y agoThe IRS suddenly starts audits of company officials. Srsly.
- komali2 10y agoI was under the impression the FBI and CIA are separate agencies from the IRS, i.e., they can't just secretly tell the IRS to audit someone.
- kabdib 10y agoTrying to dredge up the articles; I believe that the CEO of a high-tech company was heavily investigated by the IRS after he threatened to make an NSL public. In the past, the IRS has definitely been used as a tool to apply pressure. It's not supposed to happen, but it does.
- bradleyjg 10y agoThis is probably a better link: https://blog.google/topics/public-policy/sharing-national-security-letters-public/ https://blog.google/topics/public-policy/sharing-national-se...
- azurezyq 10y agoI really think HN should block/downvote all TC links, which are most of the time worse than the original source.
- gurneyHaleck 10y agoNo, that's a bad idea. TC articles ARE many times vapid, uniformative and click-baity, but... They will remain tech-oriented, timely and do serve the purpose of initiating conversation, by drawing attention to information sources that might not have gained visibility on their own. In short, you risk harming the network effect by applying a censor or restriction against such behavior. This is one of those nuances that requires to blood and sweat of moderation. Unless there's a reasonable way to maybe crawl the submission and search its contents reliably, preventing such links carries risk.
- pvg 10y agoThe site guidelines actually ask you to prefer the original source, when available. It's not complicated at all in this case.
- deleted 10y ago[deleted]
- jacoblambda 10y agoI think instead they could possibly add a report button for links explicitly for providing the original source. To help limit people just bashing it for the hell of it, the report could be set up to only submit with a valid URL. Then the mods could quickly correct it.
- 10y ago
- gxs 10y agoIt's interesting that most of these are only for: >>...name, address, length of service, and electronic communications transactional records for all services, as well as accounts... Makes me think they would submit two requests: one for metadata and one for content. This would allow them to let google publish more "innocuous" letters while continue to gag order letters where they request more intrusive information. Would love to hear the opinion, however, of someone who unlike myself knows what they are talking about.
- londons_explore 10y agoMultiple requests would also likley mean that if one were challenged in court, the other could still be fulfilled.
- magicalist 10y ago> Makes me think they would submit two requests: one for metadata and one for content NSLs can't (legally) be used for content, only metadata. (putting aside, of course, that metadata is itself content)
- gxs 10y agoAh see, this is what I meant. This makes sense. Thanks for the clarification.
- boomboomsubban 10y agoI only looked at one of them, but it seems that these are able to be released as they have the same illegal language as the Internet Archive release. Their language makes it sound like they were released due to the government being forced to review if they should be upheld.
- bahmboo 10y agoFrom the statute (and in the letters): > the information sought is relevant to an authorized investigation to protect against international terrorism or clandestine intelligence activities, provided that such an investigation of a United States person is not conducted solely upon the basis of activities protected by the first amendment to the Constitution of the United States. Of course they could still lie but you can't be investigated just for your protected speech. Not defending the whole thing, but didn't realize that requirement until now. [edit: formatting]
- sandworm101 10y ago>> ... but you can't be investigated just for your protected speech. Yes you can. All law enforcement regularly investigate wholly innocent people. It's called following leads. The vast majority of people investigated are totally innocent and never hear a peep. Sometimes those investigations lead to bad people, sometimes the lead was false, and sometimes they discover there is no real crime. They look at the speech, determine it is perfectly legal, and that's the end of the situation. But that is still "investigating".
- dannypgh 10y agoIt's not as simple as that. "The price of lawful public dissent must not be a dread of subjection to an unchecked surveillance power. Nor must the fear of unauthorized official eavesdropping deter vigorous citizen dissent and discussion of Government action in private conversation." From https://en.wikipedia.org/wiki/United_States_v._United_States_District_Court https://en.wikipedia.org/wiki/United_States_v._United_States... And "These Guidelines do not authorize investigating or collecting or maintaining information on United States persons solely for the purpose of monitoring activities protected by the First Amendment or the lawful exercise of other rights secured by the Constitution or laws of the United States" from the Attorney General's guidelines for the FBI, which were originally created because of said case. Much as how there's a legal distinction between firing someone for no reason and firing someone for an illegal reason, there is certainly reasonably interpretable legal precedent that investigating someone solely for their protected first amendment activities may violate their first and fourth amendment rights. Of course, IANAL, but that doesn't seem to stop many people on the internet.
- mr_spothawk 10y ago> Over 300,000 NSLs have been issued in the past 10 years alone. The most NSLs issued in a single year was 56,507 in 2004. In 2013, President Obama’s Intelligence Review Group reported; that the government continues to issue an average of nearly 60 NSLs every day. By contrast, in 2000 (the year before the passage of the USA PATRIOT Act that loosened NSL standards), 8,500 NSLs were issued. [https://www.eff.org/issues/national-security-letters/faq#5 https://www.eff.org/issues/national-security-letters/faq#5] * - formatting
- deleted 10y ago[deleted]
- bogomipz 10y agoI am trying to imagine just how much the legal council alone for 300K NSLs a year costs the American Economy. I would like to know what proportion of those 300K are tech companies.
- Vintila 10y agoI would also like to know the probability of indictment given an NSL.
- wavefunction 10y agoPretty high, I imagine. "We have proof but we can't tell you about it because of national security." That would work on most citizens and/or secret FISA court personnel.
- ubernostrum 10y agoA tip: * Council is a group of people, often in charge of something. * Counsel is an attorney (whose job is in part to advise you, like any other counselor).
- sndiciejend 10y agoIt's more confusing than that. A "council" can be an advice-giving body (such as the US President's National Economic Council) and "counsel" can be the advice given, either by your counsel (attorney) or council (advisory panel.) President Obama received sage counsel from his council but wanted to run it by his counsel first.
- JorgeGT 10y agoTangential: it always annoys me how difficult it is to highlight text in a Google blog post and look it up. Drag doesn't work and right click clears the selection. My only working approach is highlight and hit menu key.
- ominous 10y agoFirefox 50.0.2 (just noticed there's an update) on Windows 10. Drag to select, ctrl+c, ctrl+k, ctrl+v, enter. Drag to select, ctrl+c, ctrl+t, ctrl+v, enter. Drag to select, ctrl+c, ctrl+l, ctrl+v, enter. working for me.
- hashhar 10y agoAlso, right click on any term and hit "Search for <term> using <engine of choice>".
- eriknstr 10y agoI was about to say that it worked fine for me but then I realized that it might be because I have uMatrix, so I allowed the site everything it wanted in order to test and indeed that interferes with right click due to a dumb black popup thing with a twitter and two other icons on it. Disappointed. Would have expected more in terms of UX from Google. Anyway you might enjoy uMatrix, it's pretty good although it can be a tad bit annoying to figure out what I need to allow each domain in order for their pages to load content when they host content-critical scripts and such on a separate CDN-domain that they own or through a third-party CDN. I also don't know if it's possible to allow some domain to always be allowed to be iFramed by any other. For example I would like to always allow embeds from SoundCloud, YouTube and Vimeo on any site.
- komali2 10y agoI don't know why you'd expect better from UX, Google has had notoriously terrible UX for as long as I can remember. Off the top of my head - blogger/blogspot, youtube, hangouts android app, google voice android app, gmail settings, google maps (especially the android app), etc.
- bflesch 10y agoThey redacted the NSL letter number on the top left of the second pages, but kept the file reference number "In reply, please refer to NSL 10-272979" both in the address box on first page and the name of the PDF file.
- christop 10y agoAre you sure that's the NSL number being redacted at the top-left? The NSL numbers are also listed in the Google blog entry, and are in the URLs of each PDF, so the numbers definitely aren't something that Google intended to censor.
- pauleastlund 10y agoZ
- awqrre 10y agoI wish the FBI would be required to produce the original digital document instead of poor quality scans...
- bogomipz 10y agoI agree. Is that intentional you think?
- slig 10y agoI'm guessing here that the original, even if redacted, can leak extra data that they don't intend to leak.
- hobarrera 10y agoThe probably only move this copy around since most likely, they're actually hand-signed (rather than a pasted jpeg-signature).
- timbowhite 10y ago> we have been freed of nondisclosure obligations. > the Act restricts the use of indefinite gag restrictions that prevent providers from ever notifying customers Did Google say anywhere in that blog post that they've notified the users the NSLs were targeted at? EDIT: no, but from the TC article[1] > A Google spokesperson said the usernames were redacted to protect user privacy and that the targeted individuals had been notified. [1] https://techcrunch.com/2016/12/13/google-national-security-letters/ https://techcrunch.com/2016/12/13/google-national-security-l...
- haikuginger 10y agoThe fact that the NSL numbers are sequential gives an interesting look into the scale of issuance.
- paganel 10y agoI checked the article again after reading your comment and you were not kidding. Damn! I thought maybe they had learned something from the "German tank problem" (https://en.wikipedia.org/wiki/German_tank_problem https://en.wikipedia.org/wiki/German_tank_problem), but maybe they just don't care how all this looks to us, regular people.
- h4nkoslo 10y agoThe interesting aspect of NSLs to me has always been authentication. One gets a fax, and one faxes some crap back? Trivially hackable. One contacts the phone number listed on the NSL? Ditto. How difficult would it be for the Chinese or the Russians to slide in their own "NSL" in the 30K / year "legitimate" ones? In fact the feds make it intentionally difficult to authenticate requests; for instance they prohibit taking copies of federal IDs, they often won't submit them for actual inspection, and they have no directory of employees to consult. If one wants to confirm that one is speaking to a bona fide FBI agent you're looking at minimum an hour in phone tag, and then there is the issue of if they are relating a bona fide request or going off the reservation.
- mikiem 10y agoYou can Google the phone number in the letter and also look up the number for the field office they are from, call the office and ask for the agent. Yes, it may take time. But you don't get many NSLs, so you do it. You do it to protect yourself (liability of disclosing info without a legal order) and your customer/user who is the subject of the letter. Every time.
- tehwalrus 10y ago> In 2015, Congress passed the USA Freedom Act Really?! That is a terrible name for a piece of legislation - it says nothing - even before you consider that it was messing with gag orders about executive overreach.
- throwaway199729 10y agoCertain names are timeless favorites with bureaucrats (and worse): "Freedom Act", "Freiheitsgesetz": https://en.wikipedia.org/wiki/German_referendum,_1929 https://en.wikipedia.org/wiki/German_referendum,_1929 "Extraordinary rendition", "Sonderbehandlung": https://en.wikipedia.org/wiki/Sonderbehandlung https://en.wikipedia.org/wiki/Sonderbehandlung
- mikiem 10y agoInteresting. As a service provider (hosting) we have received many "court orders" that are very similar to these NSLs... but they were not NSLs. Now that I see these NSLs, I am not that freaked out by them. I'm not sure of all the hub bub, at least for these particular NSLs. The scope of these is basically limited to identifying the user. These specifically say to not provide content of the account to the FBI. The not-NSL court orders we have received have included verbage to not disclose the request to the subject of the request. I thought NSLs were supposedly non-contestible, broad and were for communication detail. These don't seem to be any if that. The requests we have received have been from a variety of organizations (but signed by a magistrate) ranging from local law enforcement to three letter acronyms and one entity that is neither. While the requests don't say why the order is being issued, we usually receive a call from the agent/detective beforehand and dialog ensues in which they explain what's going on. While many companies will just give the info, we scrutinize the request and ask the agent/detective politely and apologetically that we can help, but only if they acquire a court order. We have caught not-legitimate requests before, so we verify the request is legit before responding. We have never been asked for content of communications. If Google is not doing the same thing... oof. Just as a matter of process I assume they do. I recall in the past some networks having right in their WHOIS info, how/where Law Enforcement can send FAX requests.