4 ms·
I believe these statements are sidestepping the facts. Explicit requests for user data and backdoor access are a separate issue. If Prism involves capturing and
by jread 13y ago
I believe these statements are sidestepping the facts. Explicit requests for user data and backdoor access are a separate issue. If Prism involves capturing and storing packets at major Internet backbones (perhaps just upstream from private networks like Google's), anything plaintext could be searched and extracted after the fact - email messages, web browsing, chat, etc. To this day, a significant amount of communication related Internet traffic is not encrypted. I've worked on software that does exactly this. Here is a public marketing writeup:
"Every packet is recorded, classified, and indexed, making quick discovery, reconstruction, and delivery of files in their original formats easy and intuitive. Reconstruct email attachments, windows file transfers, PDF, Word, PowerPoint, Excel, and more, giving you full visibility into everything on your network.... Show all activity over time for a single user or all file-type activity over time for all users."
NSA could apply simple port based filtering to limit capture to only those packets related to communication, thereby streamlining storage requirements. If this was the Prism architecture, then these company statements would be truthful, but misleading. The NSA does not have direct access to their systems or user data, but if the NSA is allowed to record user traffic before it enters, or after it leaves their doors, then the end result is similar.
- alwaysdoit 13y agoSure, but Google has been pushing enabling HTTPS including forward secrecy by default for years now.
- jread 13y agoSource encryption does not guarantee endpoint encryption. In the case of gmail via https, an email recipient might download or forward in it in plaintext via pop, imap, smtp or an http email client.