8 ms·
> "collection directly from the servers" So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direc
by btipling 13y ago
> "collection directly from the servers"
So either Snowden has incorrect slides, the slides are falsified, or everyone has been lying. Actual evidence of direct access would be better than these slides. I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Or maybe even the NSA, but we know they share inaccuracies under oath, so maybe that isn't worth so much.
- kimlelly 13y ago> I would like someone from Google, Facebook, et al to testify under oath that there is no direct access. Do you really have that much faith in those companies? Seems like some kind of super-power to me.
- count 13y agoSo, if you're under oath, you're not allowed to lie. And if you're read into an SCI program that controls the disclosure of the existence of such access, you're most definitely not allowed to say anything about it (or, in many cases, even acknowledge that such a thing exists). There is no way someone would risk perjuring themselves OR disclosing classified information under oath.
- btipling 13y agoNot saying anything would say a lot. It would be enough to affect consumer confidence in that products are not being accessed by the NSA.
- count 13y agoI wonder if it could be construed as disclosing classified info by taking the 5th when asked. You didn't say anything, but did you say anything without saying anything?
- betterunix 13y ago"So, if you're under oath, you're not allowed to lie" Yeah but what stops you from doing so? I mean, not lying, just giving the "least untruthful" statement you can: http://www.washingtonpost.com/blogs/fact-checker/post/james-clappers-least-untruthful-statement-to-the-senate/2013/06/11/e50677a8-d2d8-11e2-a73e-826d299ff459_blog.html http://www.washingtonpost.com/blogs/fact-checker/post/james-...
- rythie 13y agoI wonder if anyone would be brave enough to test this, i.e. use TLS 1.2/forward security to one of sites mentioned, send a message to a "friend" (dumby account) that says you are planning an attack, and see what happens (i.e. it's only viewable by facebook/google whatever, not in transit)
- redblacktree 13y agoGreat idea! I nominate you.
- threeseed 13y agoSounds like a wonderful idea. Because law enforcement (like everyone really) LOVES having their time wasted.
- SilasX 13y agoI suggested that on a forum 10 years ago (though about unencrypted emails) to see if the spooks were really monitoring email, and no one seems to want to take up that offer.
- mtgx 13y agoYes, either the slides are wrong, and they don't mean "direct access" the way we're thinking about it, and they may be referring to those "lock boxes" or those "secure FTP" connections that the companies use to send them the requested data - or they've managed to hack these companies somehow, and they just aren't aware of it. This is assuming the companies didn't allow them to put backdoors on their servers. Either way, the tapping of cables is bad enough.
- ck2 13y agoI remember a few years ago or so Google was saying China hacked into the access meant for law enforcement. This might be what the slides meant. And the NSA has already lied under oath to congress. Maybe even twice.
- jellicle 13y agoThey're getting the info directly from Google et al., but they don't have root on Google's servers. Google is required by law (CALEA, the Communications Assistance for Law Enforcement Act) to provide the ability for law enforcement to get information from them. This includes - required by law - the ability both to get stored data and to make real-time intercepts of new communications. Google is paid a fee to provide these services as well. Google et al. have fully complied with this law. The FBI manages the government-end of the CALEA tapping capabilities. The NSA makes requests to the FBI, which passes them on to Google, which flips a switch and enables the tapping of user "xyzzy123". From then on, xyzzy123's stored data and new communications get sent to the FBI through the CALEA connection, which forwards them to the NSA. CALEA also requires the service provider to provide all sorts of metadata about the user. This IS "direct access" to Google's servers. The denials about this have been carefully worded things that all access is supported by some sort of legal process, etc. The denials are non-denial denials. Yes, GOOGLE (et al.), not the NSA, flips the final switch which sends the data. But Google is required by law to do so, so....... And once the switch is flipped, all of the data is flowing automatically to the NSA. I hope this is clear.
- indiefan 13y agoCorrect me if I'm wrong, but you left out the step where a judge reviews the request to make sure it's not overly broad or based on flimsy reasoning. Aside from that I'd say it's a very clear, and it's sad that there seems to be a pervasive inference that these companies are something something beyond what our elected law makers have forced them to do. Why isn't more angst directed at the politicians responsible for this?
- pvnick 13y agoJust like a judge reviewed the request compelling Verizon to turn over the details of every single call being made by everyone to everyone?
- lisper 13y agoA judge does review the request. Whether that judge "makes sure it's not overly broad or based on flimsy reasoning" is far from clear. The judge has been hand-picked by John Roberts and only hears the government's side of the case. The FISA court has rejected 0.03 percent of the government's requests. Now, maybe that's just an indication that 99.97% of the government's requests are reasonable, but here's the problem: we have no way of knowing, because it's all secret. THAT is the problem IMHO, more than the surveillance itself.
- yk 13y agoLast time this came up I realized that Google is denies overspecificly everything that is not wiretapping. So my take is, that Google is saying "no direct access to the Google servers," as in no access to the actual boxes, while NSA and Guardian use servers in a somewhat looser sense. So my speculation is, that the NSA sits between the TLS reverse proxy and the actual servers. ( The mentionend post for reference and sources: https://news.ycombinator.com/item?id=5965994 https://news.ycombinator.com/item?id=5965994 )
- moskie 13y agoThe real problem is that "direct access to servers" is not a specific term. Given the various definitions it could have, everyone could be being truthful. Some would interpret "direct access" to mean root level access to their entire infrastructure, which sounds absurd to me, yet some people seem to believe that's what's happening. And it's my understanding that this is what Google, facebook, etc. have been denying. They could instead be giving "direct access" to an FTP server or some other portal set up to provide the requested data, meaning that Snowden and these slides are being truthful in that context. I also think it could be argued that we all gain "direct access" to Google's servers every time we type "www.google.com" into a browser's address bar. It is just not a useful term, and should be replaced with something more specific in all these instances.
- mpyne 13y ago> It is just not a useful term, and should be replaced with something more specific in all these instances How about "collection directly from the server of..." just like it appeared in the actual slide, instead of 'direct access' as everyone else misquotes it?
- moskie 13y agoBut it seems like that still has all the ambiguity I mentioned. It could still be construed as root level access, or an FTP server, or anything in between. Also realize that Glenn Greenwald shares a good amount of blame for this misquote. The first line in the first article about PRISM is "The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants." (http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-nsa-data http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-n...)
- trestles 13y agoThe problem is with Greenwald / Snowden - they needed to provide indisputable evidence regarding their most garish claims; or `direct access` to a representation of the evidence
- 13y ago
- indiefan 13y agoI think it's also worth noting that the intended audience of these slides wasn't the general public/press. It's possible the purpose of using wording like "directly from the servers" was simply to delineate the origin of the data from the data pulled off the wire, not the mechanism of retrieval (e.g. some backdoor outside of the existing legal procedure for acquiring such data). I just picture the person who wrote these slides and chose those words either laughing their ass off, or face-palming right now. The companies involved have been pretty explicit (at great risk I might add by putting their founders' names on the denials) that there isn't "direct access" or anything like it. The real story here is the "Upstream" collection. Just horribly irresponsible behavior for a steward of much of the Internet's infrastructure. Shameful.
- brown9-2 13y agoThe other option is that the slides use ambiguous language.
- samstave 13y agoIf clapper was outright lying to congress about the data collection... what makes you think getting Zuck under "oath" is going to do any better. After all, he thinks we're all a bunch of "dumb fucks" and it would appear he happily sold all global user data to the USG without even a second thought.
- stcredzero 13y agoMaybe the creepy illuminati hoodie makes more sense now.
- samstave 13y agoIn have to tell you, it warms my skeptic heart to see HN so damn discerning over all this info regarding the true state of the world; HN has really surprised me at how many people here are really paying attention!!
- stcredzero 13y agoIt was said in jest.
- H3g3m0n 13y agoFrom my limited understanding, the slides are unlikely to be 'incorrect' as Snowden worked there so he would know what was actually going on. It's possible Snowden is making the whole thing up but the government haven't denied anything is going on. It should also be possible for at least some of Snowdens claims to be verified. For example he has claimed that the government was hacking Universities it might be possible to see evidence of that. Or he claimed people have been wiretapped, maybe he knows some of the conversations. It's possible the government won't deny due to a policy of denial and are sticking to it despite the huge PR issues. Or maybe they want people to think they are watching. Or maybe the people in positions to deny stuff want the current government to look bad. Maybe the government will deny later and it's taken a while due to bureaucracy. But by that time it will be to late since if there was anything they will have had time to clean house. Only Google have so for made a post saying the whole thing is fake.
- CyberDroiD 13y agoOf course everyone is lying. It's the law: you can't divulge this info, you must lie. Such naivety.
- rtpg 13y agoOr the slides use shortened terminology, because it's sorta equivalent in that the processes seem very streamlined. It's not direct from the servers, but to the analysts it might as well could be the same. These slides might have been meant for tech-illiterate people, saying that might be clearer.