3 ms·
Rather than parsing the meaning of the term "direct access", this is what makes the most sense to me: that the NSA did this to Silicon Valley companies without
by temphn 13y ago
Rather than parsing the meaning of the term "direct access", this is what makes the most sense to me: that the NSA did this to Silicon Valley companies without their knowledge or consent by wiretapping the backbone in bulk via abuse of private keys for SSL certificates.
I think the backlash is going to be greater than the USG anticipates. One thing that engineers can do is to simply refuse to work for the US government, or leave if they already work there. Deprive them of talent. Stop them from recruiting on college campuses.
There's a precedent: the campus campaigns against Don't Ask, Don't Tell. The NSA of course has its own very unique interpretation of "Don't Ask (for permission), Don't Tell (what you're recording)". But it's probably just as worthy of censure.
- cpleppert 13y agoThe presentation made it seem as if each company was not participating passively. Specifically the stored intelligence "varies by provider" and there are "special requests available." Interestingly, there is no mechanism described which captures all content of a certain type i.e. email; it seems to be apparent that only content from the providers is available. Surely, if you can intercept email from google without their help you can grab ALL email traffic as well. The slides also show that providers join over time. If they were just intercepting you would expect all email providers to join at once; that doesn't appear to be the case. There are also stuff like "online social networking detail" and "login notifications" which make it seem like facebook has given access to their systems.
- mpyne 13y agoHonestly it could be as simple as a "Law Enforcement API", that's configured with a company-run interface to NSA. The NSA analyst gets intel on such-and-such an account ID/phone number/email/etc., uses PRISM to send a request (probably something stupid like SOAP, it's the govt after all). The company computer verifies a valid warrant ID, valid request type, "hoovers up" the data requested and spits it back to NSA. Technically not direct access. Certainly not a direct wiretap into the entire company database. But NSA is able to get the "special source data" they need for correlation on their end (possibly using tools as provided by Palantir). They figure out whatever network of conspirators they're researching, develop "actionable intel", good guys win (note: depends on your interpretation of good guys, obviously :P). Zuck and Page are still right in this scenario. I just wish someone would speak up about what the hell is actually going on!
- cpleppert 13y agoI think that you are broadly right. The government can already get access to Google, facebook etc so PRISM could be just a friendlier user interface around the whole process. So instead of: 1)investigate 2) get warrant 3) send warrant to companies with data request 4)companies send data back 5) repeat 3-4 until investigation complete PRISM allows an analyst to load up a warrant and start exploring data immediately without having to wait for the company to verify it and then do a ETL operation back to the NSA.
- natrius 13y agoWhat if "provider" is a euphemism? If they're intercepting and decrypting all traffic to and from the "providers", they have to write code to actually extract the data from those streams. Such code would "vary by provider", and an analyst could make "special requests" for code to parse a certain kind of data from the stream. The timeline of providers entering the program could be a timeline of when the NSA wrote the code to extract that company's data. Also, the published slides are just three out of forty-something. The bottom of the slide that lists the capabilities says "complete list and details on PRISM web page." I agree that if they're doing this, they probably are already intercepting all unencrypted SMTP traffic.
- MichaelGG 13y agoRemember that there are plenty of people that think this is a good thing. Lots of people work in the government doing all sorts of terribly unethical things that they think is right. Elite hackers don't have a stranglehold on intelligence and technical prowess. Even then, how much more do you have to pay someone? After all, it'll get done one way or another. There are plenty of intelligent people that will decide they might as well make a lot of money at it, and perhaps protest on the inside.
- kvb 13y agoAnd it's not like private sector jobs are necessarily much less repugnant... There are plenty of stories about Silicon Valley excesses, creepy big data projects, etc.