9 ms·
Rackspace Response to PRISM
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- makeshifthoop 13y agoDmitry's followup at the bottom of the page is both insightful and indicative of our nitpicking attitude to this. Is metadata covered under this? How about their routing and network equipment's logs? In the same time, when do we stop asking clarifying questions and arguing about the semantics of the message, a process that might turn into legalese and then lawyers talking to each-other?
- femto 13y agoStrip away the accompanying material and the statement reduces to: "We have never been served with a blanket warrant, or anything close to it, that requires us to give data owned by multiple customers." Those are the words that need to be examined for loopholes.
- purephase 13y agoProbably one of the better responses that we've seen. Regardless of my earlier posts, I'm actually inclined to believe these service providers. I'm curious, has anyone seen/heard anything from CA's? I imagine it would be much easier to just create a split network route at the ISP layer and decrypt all traffic. Wouldn't be that crazy if you had all of the root keys.
- jackowayed 13y agoUgh, this keeps coming up. No amount of cooperation from Certificate Authorities will enable passive attacks on SSL. All the CA does is cryptographically certify "this is the public key that the Company (eg. Google) gave me"; they never see the corresponding private key. Cooperation from the CA might give the NSA their own certificates for Google, which would allow for an active man-in-the-middle attack. Certificate pinning would defeat that, and doing that on the fly in the Internet at large would be a serious undertaking. But if they want to decrypt traffic passively and they don't know about serious SSL vulnerabilities, they would have to have Google's private key. And with Perfect Forward Secrecy, even that is not sufficient. (PFS requires an active attack because the session key can only be determined if you're actually one of the two doing the handshake, or you know how to factor very large numbers.)
- mentat 13y ago1) Generating certificates on the fly for arbitrary domains has been the usual operating mode for transparent proxies for at least 8 years. 2) There have been many public SSL vulnerabilities in the last year. To think that there might be some non-public ones is not a stretch. 3) If anyone can factor very large numbers, it is the NSA. The move to ECC for Suite B has been interpreted to imply this may be becoming more feasible.
- sneak 13y agoLarge-scale active attacks on SSL are infeasible, as many applications (Chrome included) support certificate pinning. Furthermore, this would be easily reproducible evidence that they are actively intercepting (and proxying) traffic. Never happen.
- blhack 13y agoThe attack is to generate a certificate, sig. it themselves as valid, and then man in the middle the target. it's not about decrypting somebody else's session, it's about creating their own, seemingly valid one.
- marshray 13y ago> No amount of cooperation from Certificate Authorities will enable passive attacks on SSL Actually, it's quite common for CAs to do the site admins a favor and generate the keypair for them. The admin then downloads the private key and installs it on his server. On TLS connections where the client and server do not negotiate the use of Ephemeral Diffie-Hellman (EC)DHE (sometimes called EDH), then the CA could have retained the private key data which could be used to decrypt the packet capture after-the-fact. Google should be applauded for configuring their servers to prefer (EC)DHE on their TLS services. It also means they can fight a law enforcement subpoena for their private key.
- micah94 13y agoWhat I think you're driving at is what this device (and others like it already do) http://www.nextgigsystems.com/netronome/ssl_inspector_SI-8000.html http://www.nextgigsystems.com/netronome/ssl_inspector_SI-800.... However, you must be sitting in between the client and server and inject into the exchange (be a proxy). You can't just listen to both sides and reconstruct it later. Well, that is if you believe the NSA has not straight-up cracked SSL -- which I don't believe it has above 128-bit keys. Their cpu cycles are better used elsewhere, plus they have so much unencrypted data to analyze. But the race continues...
- j2d3 13y agoI would imagine the tech used in the device you linked to has been in use for quite some time. Nothing stated in the Rackspace or other ISPs posts says anything about the routers in place at these facilities. They're all quite careful to say how secure the customer's "stored data" is safe on the "servers" - nothing is said about data flows through routers.
- smithian 13y agoYes, and his answer is also carefully crafted to talk about dedicated servers, not Rackspace's 'cloud' service.
- pionar 13y agoHow so? It says "All Customer Data" and across all their products.
- bigiain 13y agoI note there's been no statements - suspiciously scripted or not - from the likes of Juniper, EMC, HP, Dell, Cisco... The social media company presumably-NSA-supplied denial script says "no direct access to servers".[1] I wonder just how few bits of networking gear (or switch OSs) you'd need to root - gear that sits between the SSL termination and the servers - to not even need to ask for "direct access"? [1] In fairness - perhaps that turn-of-phrase only appeared in every CEO denial because it was a direct quite from the WaPo article.
- icambron 13y ago> A blanket warrant covering thousands of customers cannot possibly comply with the Fourth Amendment How about a blanket FISA order?
- mehmehshoe 13y agoI saw the word "blanket" and cringed as well.
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- vertr 13y agoThe thing most bothering me right now is the lack of meaningful response from the companies that really matter: Google, Microsoft, Apple, and others. The responses we do have seem to be downright lies.
- sneak 13y agoThese sorts of things are gag-ordered. It may be that the top brass doesn't even know, for plausible deniability's sake, or that they've been told and now immediately face federal felony charges if they tell anyone (spouses and PR flacks included). There was a fight (which was won) to get the gag-order provisions of PATRIOT NSLs lifted, at least for speaking to one's own lawyer, which is a protected right (spouses and coworkers are still out, tho). Who knows if those rights extend to FISA orders, though we've seen how they interpret other constitutionally protected rights. It's not their fault that they don't want jail time. Blame your government. Support courageous people like Snowden. Tell your friends.
- skwirl 13y agoI haven't read all the responses, but Google's seems pretty meaningful and clear. How do you know it is a "downright lie?"
- dmourati 13y agoSCOTUS says Fourth Amendment does not apply to third parties. Smith v. Maryland - 442 U.S. 735 (1979). Third party doctrine.
- magicalist 13y agoThat is most definitely incorrect. The third party doctrine is shaky judicial construction at best (see, for instance, US v Warshak for the latest example and a case many can now use to justify holding off court orders until the Supreme Court or Congress weighs in on the ECPA), it is not held universally (wiretaps being the longest existent example), and Smith v Maryland would only get you things like call metadata at best anyways. Certainly not server contents. And certainly not with an indefinite gag-order on the service provider.
- dmourati 13y agoThe sixth circuit court of appeals can decide whatever it wants but they can in no way overturn a decision of the Supreme Court.
- einhverfr 13y agoBut as I noted separately, widespread collection of call detail records is not really at issue in Smith v. Maryland. Rather it sits at the intersection of Jones v. United States, United States v. Knotts, and California Bankers Association v. Shultz. If you read these (I noted them in order from most recent to oldest) and read/carefully count votes on concurring and dissenting opinions (after having read Smith v. Maryland), I think you could be pardoned for thinking the Supreme Court had said a bunch of things about this, much in conflict with a bunch of other things.
- gergles 13y agoSomeone trots this horse out of the barn every time privacy issues come up. I don't give a fuck what SCOTUS said in 1979. They could have gotten it wrong. Their interpretation could disagree with a plain reading of the Constitution, or they could have based their decision on inaccurate or incomplete data. Even if neither of those things are true, times have changed; issues at hand are wildly different than would ever have been conceivable in 1979. Going "SHUT UP, SCOTUS DECIDED THIS ALREADY" does nothing for the discussion, and it comes out every single time there's an ECPA or 4th Amendment thread.
- sneak 13y agoNote well that Rackspace offers primarily dedicated server services, which would make it rather difficult for them to participate in PRISM as shown. You'd tend to notice if someone rebooted your box and installed a service. :D Nothing stopping NSA from splitting their transit fibers on the (3), Telia, and Qwest sides though. What's going to be really interesting is how PRISM integrates with AWS, once some brave Amazon soul decides to self-immolate for our own intellectual curiosity.
- lightknight 13y agoMaybe you would, maybe you wouldn't. See, that's part of the problem in terms of economic calculation when dealing with a surveillance society -> since it's largely impossible to quantify the amount of lost business due to various surveillance / justice actions, as the methods and individual events in which such actions took place may never see the light of day, a society could be going bankrupt due to an overly large security division, and never know it. Let's consider a real-life plausible scenario: a DEA agent gets a tip from a questionable source about a large shipment of Molly coming in tonight on the docks (cliche, but let's roll with it). The information isn't good enough to get a warrant, but the DEA hasn't had a bust in a while, and the agents are being pressured to find something to justify their jobs. This DEA agent figures that it wouldn't hurt to have a look around (nothing illegal there, right?), and spotting nothing immediately out on the docks, begins to think that it's a bust. The agent notices that an upper window is open on one of the warehouses, and that there are voices being heard within; it would take a little effort, shimmying up the side, but the agent could peak through the window (questionable)...and maybe even climb inside if the agent sees something. The agent climbs up, and hears rising voices from within. Not seeing anyone, the agent climbs in. The agent, walking on top of some crates, sees the owners of the voices, and after listening for several moments, realizes that it's just a typical worker's spat. The agent goes to leave, not seeing anything of interest...but as the agent moves, one of the crates topples, pushing the one in front of it, and so on in a domino fashion. The agent manages to leave undiscovered, but not before $30 million in Lowe's Italian Chandeliers are dropped three stories onto a hard concrete floor. The workers will be blamed for not stacking the crates correctly, and the owner of the warehouse cited. The insurance company will, of course, cover the costs of the damaged merchandise. However, the cost to society, for this overstep, was more than a minor civil rights violation...it was more than those workers make in a decade, possibly their lives. And that's kind of at the heart of these infringements...when the intelligence agencies screw up, when the police screw up, it's not like they're shouldered with that debt; it's charged to society as the cost of doing business...no different from what the bankers did recently when they 'privatized the gains, and socialized the losses.'
- rachelbythebay 13y agoRackspace? Look up the history regarding Indymedia in 2004.
- Domenic_S 13y agoThat was a weird situation. Italian government asks US government for "help" with servers (well, logs) in a UK datacenter run by US-based Rackspace. They'd still do it today, IMO: > we are of the view that Rackspace is prohibited from accessing and turning over customer data stored on a customer’s server or other storage device in a U.S. data center without a properly issued, lawful request ( e.g. search warrants, court orders, Foreign Intelligence Surveillance Orders) > without a properly issued, lawful request > lawful request When you write the laws, anything is lawful.
- leoc 13y agoThanks: here's a decent-looking media report from the time. http://www.theregister.co.uk/2004/10/11/home_office_fbi_mlat_request/ http://www.theregister.co.uk/2004/10/11/home_office_fbi_mlat...
- _pmf_ 13y ago"We did not have an unconstitutional relationship with that authority."
- leoc 13y agoFrom the point of view of any non-resident alien who has US cloud data, this is a very ponderable answer. We know what the Fourth Amendment says. The problem is that apparently (IANAL!) the US courts are upholding the idea that the Fourth Amendment does not apply to the US-based cloud data of non-US-resident non-US-citizens. I've heard a couple of people suggesting that this interpretation is based on the idea of border search, but that's neither here nor there: the upshot is that, unlike for example the US property of non-US-resident non-US-citizens, which is protected by the Takings Clause, the US cloud data of non-resident aliens seems to have no Constitutional protection. This seems to be the Constitutional foundation of FISA http://www.gpo.gov/fdsys/pkg/STATUTE-92/pdf/STATUTE-92-Pg1783.pdf http://www.gpo.gov/fdsys/pkg/STATUTE-92/pdf/STATUTE-92-Pg178... 702 http://www.govtrack.us/congress/bills/110/hr6304/text http://www.govtrack.us/congress/bills/110/hr6304/text , the law which allows the NSA to get Foreign Intelligence Surveillance Orders against non-resident aliens. Absolutely the only thing the government has to prove to the FISC court to get one of these orders is that the targets are (more likely than not!) non-resident aliens. No probable cause, no standard of suspicion for anything: the government doesn't even have to state its motivation. And the "Notwithstanding any other provision of law" language in 702 seems to sweep away any other statute law you (or Rackspace etc.) might want to use against the order. (Again IANAL.) So how are we to interpret "Based on our interpretation of the Fourth Amendment and ECPA, we are of the view that Rackspace is prohibited from accessing and turning over customer data stored on a customer’s server or other storage device in a U.S. data center without a properly issued, lawful request ( e.g. search warrants, court orders, Foreign Intelligence Surveillance Orders) from a U.S. court with appropriate jurisdiction over Rackspace and the data sought." ? Coming right after the recitation of the Fourth Amendment, this gives the impression that Rackspace will only hand out your data in response to a warrant (or warrant-like-thing) that demonstrates probable cause. But in fact, when the customer is a non-resident alien, the order is a FISA 702 order, and the court is the FISC, probable cause never comes into it: the US can (completely properly and lawfully!) get such an order for no stated reason at all. Imagine the following conversation in 1860: Q: I hear that you have slaves on your Virginia cotton plantation. Is this really true? A: The Fifth Amendment to the US Constitution states that 'No person shall [...] be deprived of life, liberty, or property, without due process of law'. No-one is forcibly detained on this plantation except fully in accordance with the law and the Fifth Amendment. This answer seeks to suggest that the only prisoners on the plantation are convicted criminals, which is false - the plantation is worked by slaves. But in fact the answer is precisely true though devious: slaves have no rights under the law, while the Fifth Amendment does not apply to slaves. I really hope this isn't the correct way to interpret Rackspace's statement as well.
- callmeed 13y agoI was thinking about Rackspace and PRISM today (I spend > $10K/month at Rackspace) ... and that thread about how all this could harm the startup ecosystem. If the Govt/NSA wanted access to certain metadata and a company refused (like some claim Twitter did), what's to stop them from going to Amazon or Rackspace and throwing their weight around to get access that way? Or, if that didn't work, they could just keep going up the OSI layers (or tier 1 providers) until they get the access they want OR can force it be threatening to disrupt service. My point is, even awesome companies like Rackspace are dependent on less-than-awesome companies for some types of infrastructure.
- zero_intp 13y agoDING DING DING we have a winner. Any company that doesn't comply and hand the data by API will have it's links scraped. Sure it's more costly. That's why they go through the arm twisting.
- vertis 13y agoI would very much like to have the same question answered by Amazon in regards to AWS (maybe it has been already).
- vertis 13y agoSo I've opened support cases with both Amazon and Linode, the former will probably get back to me in several days, but as usual Linode has already replied. --- vertis 29 minutes ago I am an Australian (i.e. Non-US-Resident Non-US-Citizen). While I have nothing of particular interest on my servers, the revelations of the last week have concerned me for multiple reasons. The Guardian story about the PRISM program suggests there is extensive surveillance and interception of foreign citizens' data without a court order. Do I need to move my servers to a provider that is based in a country that respects my rights to not be surveilled? lmatos 18 minutes ago Hello, As an American citizen, I completely understand. With that said, we have to comply with all US law as we are a US based company. If there is anything else that we can do to help, please do not hesitate to ask. Regards, Lee M
- deleted 13y ago[deleted]
- Zarathust 13y agoTheir main defense is that they operate within the boundaries of the law, which the Obama administration also claims. If they ever face a court order telling them to hand over everything, as long as it follows law at face value then their statement is true.
- madaxe 13y agoSo, they don't do it like google etc. don't do it? Encrypt your disks. Only allow https. Don't let their support anywhere near your kit. Although then again they could stick a physical intercept in a box.
- SeanDav 13y agoThey don't address Government back doors into their routers as a result of CALEA etc. See: http://www.cisco.com/en/US/docs/routers/7600/ios/12.2SR/configuration/lawful_intercept/76LIch2.html http://www.cisco.com/en/US/docs/routers/7600/ios/12.2SR/conf... and: http://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act http://en.wikipedia.org/wiki/Communications_Assistance_for_L...
- adinb 13y agoAre the intel services (DIA, CIA, NSA, NRO, etc...) considered actual LEAs? Part of the issue here afaik is the collection of data for intel, not actual LEA. Or else the FBI would be getting all this juicy NSA data to o after actual criminals.
- ihsw 13y agoMany USG agencies (Pentagon, NSA, Department of Energy/Justice/Labour/Education, et al) have their own police services[1]. Their training and expertise ranges from glorified security guards to para-military. [1] http://en.wikipedia.org/wiki/Federal_law_enforcement_in_the_United_States http://en.wikipedia.org/wiki/Federal_law_enforcement_in_the_...
- zero_intp 13y ago95/5 splitters. Rackspace buys service from somewhere. Those fibers are suspect.