12 ms·
Asking the U.S. to allow Google to publish more national security request data
- deleted 13y ago[deleted]
- skwirl 13y agoI'm just curious: If this program in reality did not give the government unfettered access to Google user data as has been claimed by The Guardian and Snowden, would there be any amount of evidence that could now be presented to you that would convince you that you were misled?
- 1010011010 13y agoNo one did.
- deleted 13y ago[deleted]
- rasterizer 13y agoAssertions in the press that our compliance with these requests gives the U.S. government unfettered access to our users’ data are simply untrue. Just read the damn thing, it's not long.
- deleted 13y ago[deleted]
- youngerdryas 13y ago>Assertions in the press that our compliance with these requests gives the U.S. government unfettered access to our users’ data are simply untrue. However, government nondisclosure obligations regarding the number of FISA national security requests that Google receives, as well as the number of accounts covered by those requests, fuel that speculation. Sounds suspiciously like they are going to ruin everyone's nerd rage.
- jlgreco 13y agoYou really love that phrase, don't you? I'm sure in other communities it is a great way to marginalize those with interests that you do not share.
- youngerdryas 13y agoI really doubt Google is going to play chicken about something so serious as giving away all their user data. Is it incomprehensible to you that they are telling the truth?
- anon1385 13y agoThe problem Google has is that a huge number of their users -- those in foreign countries -- have (finally) realised what has been public knowledge for years: they have no legal protection at all from the US government examining data Google holds about them and that Google readily comply with such requests and aren't really in a position to do much else. 'Telling the truth' involves restating this truth in the full glare of worldwide publicity. The more they try to reassure americans that everything they did was 'legal'[1] and only targeted foreigners, the more foreigners they alienate. So from a PR perspective I don't see how Google can fix this unless US law substantially changes (or they employ crypto on the users side but that undermines the economics of much of their business). [1] I'm not convinced that it is legal under EU data protection law and Google does have a presence in the EU, but I'm no lawyer.
- jlgreco 13y ago> "employ crypto on the users side but that undermines the economics of much of their business" This is true, at least in Google's situation. However I think there is an untapped market of people that want to be advertised to, provided the advertising is relevant. Surprisingly I think traditional print magazines actually have this figured out. The advertisements for designer clothing, watches, and booze get a lot of readership in "gentleman/bachelor/whatever" magazines (not sure what the correct term there is, not trying to refer to porn (well, except Playboy)) and I suspect that removing them would actually damage their subscription rates. Now, these adverts obviously are not targeted to the individual, but I think they nevertheless demonstrate the concept.
- jka 13y agoAggregate number of requests is one thing, but perhaps some indication of how much content is provided with the average request would be required to really indicate what is going on here? An API may serve millions of requests per day and return single-integer responses, or it might serve one batch query per day and provide a nested document with many sub-sections.
- powera 13y agoFrom the article: "We therefore ask you to help make it possible for Google to publish in our Transparency Report aggregate numbers of national security requests, including FISA disclosures—in terms of both the number we receive and their scope"
- jka 13y agoNot sure how I missed that on the first read through - good to see though, reassuring as long as the scope descriptions are reasonably clear!
- deleted 13y ago[deleted]
- rasterizer 13y ago"millions of requests per day"?! the number of FISA requests since 1979 is just short of 34,000: http://www.motherjones.com/mojo/2013/06/fisa-court-nsa-spying-opinion-reject-request http://www.motherjones.com/mojo/2013/06/fisa-court-nsa-spyin... Let's try and keep the speculation to a minimum.
- RobAtticus 13y agoPretty sure he was just giving a generic example rather than specifically talking about this case.
- masterzora 13y agoIt seems less like speculation and more an example of how raw number of requests doesn't mean a whole lot in and of itself.
- slg 13y agoThis is the kind of response I was expecting from tech companies. The mistrust of the government has extended to this industry and we can't simply rest on a simple denial of the accusations. Many people now believe that companies like Google send a complete copy of their entire customer records to the NSA. That is a dangerous belief and like discussed on other threads here, it could really damage the long term viability of the tech industry. This is at least a start to try to change public opinion.
- EthanHeilman 13y agoIt could really damage the long term viability of the __US__ tech industry dealing irreparable damage to one of the major assets of the US economy has. I would expect companies that need a strong international security reputation to begin closing up shop and moving away. The NSA just killed the goose that lays the golden egg and not much is going change that.
- slg 13y agoI disagree that this is a problem limited to US companies. With the global nature of the tech industry, I think a product's or service's country of origin has seen a reduced importance over the years. I don't think the average consumer knows that Waze is based in Israel. I don't foresee anyone considering the NSA and choosing a Canadian designed Blackberry phone over a US designed Apple one. Instead I think this will just instill a general distrust of technology and the cloud. I doubt people will be discerning enough to focus their suspicions.
- witek 13y agoYes and no. Example from the German government (10 Aug 2010): "Germany's interior minister said that politicians and senior civil servants in government should avoid mobile devices such as the iPhone and the Blackberry, citing security risks and increasing hacker attacks. (...) ministers and senior civil servants have been told to rely on the German-made Simko2 gadgets, on advice from the German federal office for information security (BSI)." http://digitaljournal.com/article/295798 http://digitaljournal.com/article/295798
- mtgx 13y agoI'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroad, and lose a ton of business and customers, both small and major. Maybe then they'll start doing some real lobbying to the government to end the madness, and maybe the government will stop thinking all the spying is worth breaking all international relationships and hurting the US economy in the process. Until that happens, if Google cares that much about encryption and their users' privacy, they should show me they are willing to implement OTR, ZRTP and PGP in their services. The same goes for Microsoft and Facebook. Otherwise, this press release means nothing except for showing that "they are doing something".
- tptacek 13y agoSo you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.
- rdl 13y ago1. Google probably should offer passive S/MIME on mail. START TLS goes a long way, but providing the same signals about message authenticity to people who IMAP from gmail as who use the web UI would be nice. A non-google-trusting way to do PGP with a better UI/UX would also be a nice feature for gmail. Just indicating "encrypted" at the message-list view or something. I have PGP working quite nicely in mutt, but a lot of people seem to prefer webmail. 2. I'd actually prefer a world where signals intelligence, outside extremely tactical intelligence, were impossible through technical means. I think we'll be there at some point, just because the cost of protection is dropping. (confidentiality and message integrity should be feasible for any reasonable government defender at this point. traffic analysis/direction finding/etc. burns bandwidth and latency budgets, so that might be harder, but you can do arbitrarily well.) The US (government and citizens/private industry) probably has more to gain from universally strong COMSEC vs. effective USG SIGINT.
- tptacek 13y agoIn expressing his view that Google is being harmed by USG's lack of transparency (combined with the godawful operational security of the contractor-run intelligence agencies), is Google's chief counsel here starting to build the standing to sue the government? If this whole debacle sets up an epic confrontation between Google and the DoJ, I may have to reevaluate how irritated I am at how "Prism" has been reported. More Greenwald agita! Let's see if we can pick a fight!
- haberman 13y agoJust to clarify, I think you are irritated with the inaccurate/sensationalist reporting of PRISM, and not that it was leaked to begin with?
- tptacek 13y agoMy perspective on this is going to sound weird to you. 1. I am very irritated at inaccurate and sensationalized reporting. 2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens. 3. I think leaking details of signals intelligence programs should be a crime. 4. I hope Google picks a giant fight with the DoJ and wins it.
- haberman 13y agoI agree with your perspective, with the exception of a slight modification to #3. I believe that leaking should be a crime, but I also believe that if the court of public opinion judges the original secret worse than the leak, that it should become politically out-of-bounds to actually prosecute the case. I think there's a world of difference between Bradley Manning and Edward Snowden. And while I think Manning's treatment has been harsh, I do think he should be prosecuted because he was reckless and untargeted. Snowden clearly has a much more focused goal and surgical approach.
- tptacek 13y ago
- WestCoastJustin 13y agoYou have to think, that with the limited data they are allowed to release, this must be extremely frustrating! A true rock and a hard place. The general public are led to believe, that they are willing to conspire secretly together with the government, to spy on their customers, must not only be infuriating, but brand damaging! Then you are required by law not to defend yourself ;) p.s. I'm taking google at their word -- that they are not giving 'direct access' to the NSA. I am assuming they know, that the truth could leak out at some point, where they to lie about it.
- spankalee 13y agoAs a Google employee I find it extremely frustrating. I'm sure it's even more so for the executives and founders who created the brand and are being personally questioned and attacked on top of it.
- lignuist 13y agoI'm more interested in the international numbers, as US politics seems to differentiate between US citizens and non-US citizens when it comes to human rights. Edit: Or is this also including requests for users in other countries? Sorry, English is not my mother tongue, so I might got it wrong.
- asperous 13y agoI believe, if it continues as it is currently, the numbers are government requests, and how many users effected. There is no check or distinguishment in whether the government and the user's country match. They also publish non-us government requests as well.
- mpyne 13y agoThe cat's definitely out of the bag anyways, so Drummond is definitely right that mentioning FISA numbers can't further harm national security. Make the right call, Mr. Attorney General!
- corresation 13y agoWhat are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the NSA would look great on a resume, and put the person in a position to compromise essentially all internal security and data integrity.
- tptacek 13y agoIt would be a felony for anyone at NSA to attempt to "turn" an employee of Google and get them to leak secret information from Google's systems.
- ck2 13y agoIf google wants absolution it needs to state it's saving no more tracking data than the minimum required by law. But it's saving a whole lot more than that. Much more.
- ben_pr 13y agoThe issue here is that Google doesn't know how much data the NSA collects. The NSA has access to the internet backbone that Google uses and can read whatever traffic it wishes that leaves the Google network. Obviously this is not everything but most everything. It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. So while Google can claim they do not allow the NSA direct access to it's servers that is only a small comfort in the big scheme of things. This sort of response from Tech companies is just a distraction from the real issue.
- youngerdryas 13y ago>So while Google can claim they do not allow the NSA direct access to it's servers That is the entire story in this case, direct access to the servers.
- lawnchair_larry 13y ago> It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. No it isn't.
- ben_pr 13y agoWell, think again. You really think the NSA can't make the SSL cert vendors turn over the keys? I wouldn't count on it. https://news.ycombinator.com/item?id=5933784 https://news.ycombinator.com/item?id=5933784
- kllrnohj 13y ago> It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. For most SSL certs this is probably true, but Google uses perfect forward secrecy which makes this very unlikely if not damn near impossible: http://googleonlinesecurity.blogspot.com/2011/11/protecting-data-for-long-term-with.html http://googleonlinesecurity.blogspot.com/2011/11/protecting-...
- jmillikin 13y ago
- ChuckMcM 13y agoOk, so its a bit snarky, but I wish Google would invest as much cleverness in evading the letter of these non-disclosure rules as they do in evading the letter of the tax laws in their various jurisdictions. Perhaps they could create Google Panama Ltd which is the official entity to petition for all FISA and NSL requests which is an independently operating subsidiary based in Panama and outside the jurisdiction of the disclosure rules or something. There are a lot of smart people there, you can figure this out.
- billnguyen 13y agoThe US needs to close its tax loopholes and stop blaming people for taking advantage of its own terrible laws. As long as the loopholes exist its in everyones best interests to take advantage of everything they can.
- jholman 13y agoIt's not just snarky, it's preposterously unreasonable. How much work do you, personally, put into making money? At least 40 hours a week, I'm guessing, plus the time you spend on managing your investments, doing your taxes, and so on? How much work do you put into maintaining your own privacy? Is it even 1 hour per week, on average? Really? Note that Google has, allegedly, already put a LOT of work into pushing back on ensuring that due process is followed. Many engineers, many lawyers, lots of executive-decision-effort. Maybe you don't believe anything Drummond or Page say? Maybe you think google.com/transparencyreport is purely fabricated? Maybe you think Google should violate the law and get shut down (that's what you said, actually, with "evade the letter of the law", but I find that position so laughable that I assume I misunderstood you)? Maybe you yourself actually DO spend the same time on privacy that you spend on pecuniary gain, or maybe you expect Google to hew to a higher standard than you yourself do?
- nitrogen 13y agoOn your last point, I would argue that the more power and information an organization or individual has, the higher the standard should be.
- 13y ago
- jroseattle 13y agoUnfortunately, the statements from everyone involved have made me skeptical to the point I feel I have to consistently read between the lines and pick a statement apart. What does "unfettered access" mean? What are "valid legal requests"? While there is an implication of spirit in their words, I know deep down that everyone involved is focused on the letter of their words. This has nothing to do with my personal trust and confidence in Google, but in my trust and confidence in this entire charade. Google is part of it, whether they're on the right side or not. I simply cannot tell.
- acqq 13y agoExactly, if the requests exist only to cover the legality of the access of the U.S. citizen data as long as they are on U.S. soil, the numbers they mention would still represent just a small piece of the whole picture. At least they mention in one sentence "the number of FISA national security requests that Google receives, as well as the number of accounts covered by those requests" which is already much more useful information than only the "number of requests." We saw that in Verizon case one single request was enough to mean "give me all about everything from everybody."
- saalweachter 13y agoWhile I'd like to know how many secret requests are being made to whom, why should I ever believe any numbers? We're living in crazy-town, maybe we always were. What is to stop the A.G. from publicly saying "Yes, disclose away!" and then to privately send one of those magic-do-anything-we-say requests saying, "Don't disclose X, Y, and Z."? Or if we are given an accurate count today, what is to prevent the government from in the future secretly retracting that privilege? I think in the end we can be satisfied by nothing less than some sort of "Too Many Secrets" Constitutional Amendment, stating clearly that no private citizen can be required or compelled to partake in a "National Security" cover-up, so that everyone currently bound up in the web of lies could speak up without fear of persecution. That is what galls me as much as anything. If the government wants to gather data and keep secrets, let them gather and keep them themselves. Drafting people against their will into compulsory service in signals-intelligence, forcing them to lie to their loved ones and the world, and persecuting them for honesty, is absolutely amoral.
- bo1024 13y agoGood point. If they can force companies to lie about the existence of FISA requests, why wouldn't they force them to lie about the number of such?
- kvb 13y agoWhat lies have companies told?
- Spearchucker 13y agoDifficult to tell. The fact the Google's name is singled out with 8 others on an NSA slide fuels speculation, and is at odds (again, speculation) with this letter. Someone on either side will have to provide something spectacularly believable to kill that speculation.
- bo1024 13y agoFrom the news I've read, my understanding about FISA is that if someone asks you whether you've been subject to one, you're legally obligated to lie and say no. Right, or am I missing something?
- pvdm 13y agoThe seed of doubt has already been planted. Sorry, I am looking to secure my data and will not trust any third party ever again.
- mrschwabe 13y agoWho cares people? The gig is up on Google. They are in PRISM. Instead of upvoting every piece of Google PR we should be ignoring their rhetoric and distancing ourselves from this company; and the other 9 implicated in PRISM. Secret partnerships with government agencies is detrimental to free market capitalism and goes against the true spirit of entrepreneurship.
- anoncowardftw 13y agoSo I'm a bit confused. Google has been happily complying with NSA without a care or concern in the world. Now some news leaks that they have been.. Happily complying with NSA without a care or concern in the world. So they release an "open" letter trying to redirect the masses attention, and I'm not a little shocked it's working. People are actually praising Google? WTH? If Google really cared this letter is like 5 years too late doncha think? Google cares about one thing! That they got caught not giving a crap about the privacy/rights of their customers. News Flash, they still don't give a crap. But hey, if losing gmail, google+, picasa, blogspot, drive etc. would just cause your world to fall apart, then keep using it and just be honest that you don't give a crap about your privacy or rights any more than Google does.
- mrschwabe 13y agoThe sad thing is that this letter is currently frontpage/top of HN. The #1 most important company implicated in this NSA leak; the very company accused of co-operating & enabling the NSA's intrusive violation of our privacy - is now enjoying this great exposure at the top of HN as 'hackers' eat it up.
- wutbrodo 13y ago> So they release an "open" letter trying to redirect the masses attention > If Google really cared this letter is like 5 years too late doncha think? You should read the news occasionally. Google has been publishing a Transparency Report since 2010, and has been expanding it since then. Not quite 5 years, but more than long enough to render your comment paranoid nonsense.
- aresant 13y agoTraitor or not, you can't argue with the fact that Ed Snowden just gave Google, FB, Yahoo, MSFT, etc fighting ammunition to at least address these issues with the government publicly, and for that I am thankful.
- furyofantares 13y ago> Google has nothing to hide. Strange phrase to put in there.
- hoytie 13y agoI suppose it would be nice to know how many FISA requests there have been, but what does the number of requests have to do with the core issue? Is the number of FISA requests in proportion to the amount of data being shared? Does it tell us the nature of what is shared or how it is shared? We still know nothing about the contents of legal FISA requests and therefore can't really say whether a single request violates our rights or not. Publishing aggregates tells us essentially nothing because we still don't know the limits of a request, or at least I don't.
- javyerderderyan 13y agoToo late...
- malandrew 13y agoPlease also request tagging for each of the requests. e.g. 2013-07-12 Foreign National Drug Related - Cocaine 2013-07-18 US Citizen Drug Related - Marijuana Request from FBI 2013-07-22 Foreign National Terrorism Related 2013-08-01 Foreign National Industrial Espionage I think it's really important that we know how many of the requests have to do with the existential threat of terrorism, since that is the example the administration and Congress keep using to justify these actions. The more metadata the better. If they want our metadata, it's only fair that we get their metadata too, to be able to keep tabs on their actions.
- malandrew 13y agoI would also like to see Google and other companies specifically fund counter-surveillance technologies, like end-to-end human friendly encryption. I would love it if Chrome came with a GPG chrome extension that worked with Yahoo Mail, Gmail and other popular webmail clients right out of the box. Mozilla should also have a plugin that comes preinstalled for this. The limiting factor in adopting end-to-end encryption in email is network effects. Preinstalling GPG support in browsers is half the battle.
- taktix 13y agoGoogle's statement is too stuffed with presuppositions and it comes off as manipulative, at least to me. If it wasn't for this earth-rattling leak, Google would still be merrily handing over my emails to the NSA. Fail.
- hoytie 13y agoI'm really curious what they intend to share as what they describe as the scope of the requests.
- spinchange 13y agoNow, THIS is deserving of a White House petition.
- return0 13y agoAre they allowed to disclose the nondisclosure order?
- TomGullen 13y agoGoogles lost my trust. To my newly discovered emabarassment I naively and passionately defended them amongst my friends for several years. Seems like if a company gets big enough it's ethical demise is a certain inevitability (yes, I'm a little late to the party). What a pathetic untrustworthy world I find myself now living in.
- o0-0o 13y agoWhy doesn't the government just profile. We all know who the terrorists are.
- Lost_BiomedE 13y agoReally, this is exactly what I expect of people wanting to do the right thing when in between a rock and a hard place. I imagine this is what I would do if sincere and in their position. Thanks Google.
- etherael 13y agoFrom here on in this is the only privacy model I will consider trustworthy for a cloud service; You have the encryption key, the data on our servers is completely useless without that encryption key. We are physically unable to be compelled to comply with any orders to violate your privacy from anyone. The only example of a cloud service I can think of that matches this off the top of my head is spideroak and tarsnap, perhaps also the new torrent sync? I'm not entirely certain how that works but I do recall a client side crypto key being involved in there somewhere?
- plywoodtrees 13y agoYou can use things like Duplicity which locally encrypt backups and then store them to arbitrary cloud services. The problem is, if the data is opaque to the cloud service, it is very hard for it to do anything other than passively store and retrieve it, at which point it is not really a cloud service at all. And even then: they can give logs to authorities showing what you accessed when and from where, they probably know your credit card and billing details.
- etherael 13y agoI have an 8gb truecrypt file on dropbox, pretty much regardless of what they're compelled to do, it's secure. That's the model I think should be standard for cloud ops. However, you do bring up an interesting point, it is indeed harder to do "useful stuff" when the store is untrusted and has no idea what it's holding, string searches et al become pretty much impossible generally speaking, big bummer there. Perhaps this will be a good accelerant for the adoption of homomorphic encryption algorithms?
- plywoodtrees 13y ago'Visions of a fully homomorphic cryptosystem have been dancing in cryptographers' heads for thirty years. I never expected to see one. It will be years before a sufficient number of cryptographers examine the algorithm that we can have any confidence that the scheme is secure.' -- Bruce Schneier Even without PRISM, the rise of cloud computing is a strong incentive for people to try to develop practical homomorphic encryption. Until there's a practical algorithm adoption will be limited.
- annnnd 13y agoSmart response. Very smart. Damage control at its best: "How we wish we could tell you that it's not so bad as you think it is... but government won't let us... Government, pretty please?" They just put the spotlight on Administration, which of course won't allow it. Smart.
- wmt 13y ago"Assertions in the press that our compliance with these [FISA] requests gives the U.S. government unfettered access to our users’ data are simply untrue." What about the non-FISA requests, has any of them given the U.S. government unfettered access to user data? What does unfettered mean? "You only can access all user data for 2 hours" "You need to specify (through tickboxes?) all the user data you wish to download to PRISM" "You only access all user data of all German users"
- patrickmay 13y agoAsking is far too polite. Every citizen, not just Google, should be demanding the end to these secret orders and secret courts. The government is supposed to be our servant, not our master. We need to start treating it appropriately.
- Ziomislaw 13y agothe first question anyone should ask themselves is - how do you know they will tell the truth? they might be forced by their police state law to pretend the numbers are low and you have no way to be sure. you can not trust any company based in Police State of America, everything they tell you might be because law requires them to.