4 ms·
This reads like it was penned by someone who's never heard of the Stanford Prison experiment or Milgram's research. When I read "I have a very high opinion of m
by sedev 13y ago
This reads like it was penned by someone who's never heard of the Stanford Prison experiment or Milgram's research. When I read "I have a very high opinion of my former coworkers ... NSA employees are the law-abiding type ... You take a long automated psych test that flags troubling personality traits," I take away "the NSA is full of the kind of person who won't look at the big picture, who will follow orders without exercising critical thinking, and who can be counted upon to be a Good German."
The problems that the HN crowd (speaking broadly) has with the NSA and related entities, are systemic problems. They are not about, "is act X legal or not," they are not about "was this particular incident harmful or not." They are about root of the thing: about the high-level agenda, about the strategies, about the ideas. It does not in the least address these concerns to say "oh, my coworkers are fine folks, we work hard to obey the law, there are scary people out there!" This says nothing to the counterarguments of "we shouldn't have to trust you" (really, you could say that the field of cryptography is about replacing situations where you have to trust a human with situations where you only have to trust math), "the law itself is a problem," and "you haven't proven that you are doing more or better compared to other ways we could push back against scary people."
As with any government agency, the more they insist that they must not be held accountable, the more accountability we should jam down their collective throats. The first sign of someone who can't be trusted with power is that they ask for more of it.
- emiliobumachar 13y agoMinor nitpick: at cryptography you are not trusting math, because it has not been mathematically proven that no algorythm exists to break a certain crypto method in five seconds on an off-the-shelf processors given only the cyphertext (except possibly for one-time pads with their drawbacks). But after hardworking experts try and fail for years to break a crypto method, you can somewhat trust that attackers won't find it either.
- eliteraspberrie 13y agoI take away "the NSA is full of the kind of person who won't look at the big picture, who will follow orders without exercising critical thinking, and who can be counted upon to be a Good German." That is exactly right. Employees of intelligence agencies are selected primarily for loyalty, not critical thinking. Most people find that hard to believe, especially those inside who tend to have a very high opinion of themselves. In intelligence, recruiting independent minds is a mistake.
- tmzt 13y agoIt feels like saying Bletchley Park just needed more diligent and loyal crib workers and they would have solved the Enigma. Without Turing and the Bombe where would we all be?
- jessaustin 13y agoYeah well back then we had actual opponents. North Korea are crackpots, and some fundamentalists prefer living with goats in caves to comfortable air travel, but never in a million years will those cranks be the threat that the Axis or even the Soviets were.
- f00_ 13y agoObviously North Korea isn't near the threat of the Soviets/Axis, but I'd say they have a very real capability to destabilize, at the very least, the Korean Peninsula (non-violent dissolution), and at the most all of SE Asia (A nuclear attack/violent dissolution)
- PeterisP 13y agoDo you believe that China isn't a worthy enough competitor in electronic espionage? Or the occasionally conflicting interests with Russia and other countries? The main job of NSA isn't to support short-term military operations in whatever location they're fighting today, they have to ensure that if they suddenly need to focus on country X, then they already have years/decades worth of collected intelligence.
- deleted 13y ago[deleted]
- CamperBob2 13y agoAnd of course, what you say about "country X" also applies to "individual Y," doesn't it? How convenient.
- aet 13y ago
- mpyne 13y ago> As with any government agency, the more they insist that they must not be held accountable, the more accountability we should jam down their collective throats. Did you read the same essay I did? He didn't argue for less accountability (indeed, he argued for more). He did argue that the capability had to remain in order for the U.S. to maintain its ability to survive in the ongoing shadow cyber battles. I agree with you that the high-level concerns are the real key, but you seem to working at it in the opposite direction. You have a specific end in mind, seemingly independent of any high-level examination of the effects of achieving that end. Then you say that the high-level things (law, trust, comparisons, etc.) should be arranged to meet the specific end. Rather I'd argue it from the other direction, just as I have from day 1 of all of this: Does a country need to have the ability to monitor the goings-on of electronic communications (including the Internet) for its welfare & national security purposes? If so, what capabilities are needed? Is "pre-emptive self defense" needed (or even allowed)? Do the totality of these capabilities introduce a risk towards civil liberties, or otherwise conflict with law? If so, can they be mitigated, must the law be changed, or should the state simply abdicate its security/welfare reponsibility (noting that it would be only the US doing the "abdicating" here)? Can the state employ other capabilities that can achieve the same essential effect with less risk on civil liberties? Some of these questions you touch on, e.g. "you haven't proven that you are doing more or better compared to other ways we could push back against scary people.", but many are ignored completely as it is simply assumed that absolute privacy on the Internet is sacred (but only for the NSA; criminal organizations, other nation's intelligence agencies, and the local cypherpunk wardriving around are obviously not a threat), even while absolute privacy on the old landline phones was never a reality. The best argument I've heard so far has been that the sheer scale of this type of network surveillance, along with its near-undetectable nature, makes it different in kind. I actually agree with that viewpoint, but I also think that this matter of scale makes it possible to install good oversight and accountability if the capability is actually needed. It would take probably at least 10 people just from a "command + control" sense to launch a U.S. nuclear missile; there's no reason even better accountability, oversight, and specific legal guidance and safeguards can't be baked-in to a one-and-only central monitoring system. But the question is whether we need the capability, and no one seems to want to take a specific answer as to why the U.S. (and the U.S. alone) can survive without it.