11 ms·
Apple, Facebook, others defy authorities, notify users of secret data demands
- orky56 12y agoWhat are the legal consequences to these large tech companies tipping off users? Are these companies just calling the bluff of enforcement agencies who are not willing to risk the bad PR? I'd love to hear from someone who has a better idea on why this issue is as gray as it seems.
- rtpg 12y ago> Apple, Microsoft, Facebook and Google all are updating their policies to expand routine notification of users about government data seizures, unless specifically gagged by a judge or other legal authority To my knowledge people are allowed to say they were questioned by the police. I think this is mainly a "we don't feel like helping you guys out anymore" move (as well as a "hey our customers would probably trust us a bit more" move and being generally the Right Thing™
- amirmc 12y agoWorth pointing out: "The changing tech company policies do not affect data requests approved by the Foreign Intelligence Surveillance Court, which are automatically kept secret by law. National security letters, which are administrative subpoenas issued by the FBI for national security investigations, also carry binding gag orders." But also: "The shifting industry practices force investigators to make difficult choices: withdraw data requests, allow notification to happen or go to magistrate judges to seek either gag orders or search warrants, which typically are issued under seal for a fixed period of time, delaying notification." I hope that the public don't misunderstand these two things.
- PaulKeeble 12y agoSo nothing has really changed then. Its more marketing than substance in the hope that fluffy minimal changes to their policy will restore confidence while the same thing is continuing to happen.
- skue 12y agoNo, this is different. In the past, tech companies might comply with requests from prosecutors to not inform customers that their data has been requested. This story claims that tech companies now require a gag order from a judge (FISC or otherwise). I have a lot of issues with FISA, but it sounds as though FISA requests are a far rarer than prosecutors requesting records. To restore balance we really do need to get back to requiring judges to weigh each request for data individually.
- HenryMc 12y agoJust PR, no real substance.
- moskie 12y agoAlong those lines, it's good to keep these numbers in mind: https://govtrequests.facebook.com/country/United%20States/2013-H2/ https://govtrequests.facebook.com/country/United%20States/20... So in the most recent time period reported, there were ~12,000 requests for data, and between 0 and 1000 of them for NSL/FISA requests. Meaning these policies theoretically affect over 90% of the requests. Providing this perspective in contrast to the "this changes nothing" sentiment.
- deleted 12y ago[deleted]
- ipsin 12y agoAdministrative subpoenas have really been the hammer agencies have used to crack into business records, time and again. I hope this change is as widespread as the article seems to claim. A lawful warrant should be the gold standard for record requests.
- deleted 12y ago[deleted]
- mark_l_watson 12y ago+1000 to these companies, if they are truly doing this. Time for us all to contact our Congress-critters, supporting this.
- telecuda 12y agoI hope there's some discretion used here based on the nature of the request. Child Sextortion (send me naked photos or record these sex acts with your sibling or I'll send this devastating photo to all of your friends on Facebook) is a very real and frequent problem. If mom & dad show the sextortion messages to their local police detective and s/he fills out a Facebook records request to see if the suspect is victimizing other minors, will Facebook notify the suspect? The average local investigator is low-tech, has good intentions to help a victim, and has nothing to do with FISA or national security issues. I'd much rather see a tech company say, "Hey, we're not just going to give you everything on this user. In fact, we'll notify the user unless you provide more justification or background on the reason for your request," than notify the suspect without warning. At least then the investigator can provide more info for consideration, or go back to a judge.
- eipipuz 12y agoI'm naïve, is sextortion a very real and frequent problem? Do you have stats?
- telecuda 12y agoI don't have stats, no, but Facebook openly acknowledges the problem at child safety conferences. Google "Facebook Child Sextortion" and you'll find your share of articles. I recognize "take my word for it" doesn't go very far!
- sillysaurus3 12y ago"Hey, we're not just going to give you everything on this user. In fact, we'll notify the user unless you provide more justification or background on the reason for your request," It seems like it isn't necessarily a good idea to let companies decide whether an individual request is justified. Suspects are innocent until proven guilty in a court of law. It's up to our society to remember that they are indeed innocent unless proven otherwise, and there's no way at that point for the investigator to prove anything. Imagine that an investigator comes to Facebook and asks them for information regarding one of Facebook's employees. Facebook asks why, and the investigator responds that they suspect they're involved in something like what you've mentioned. At that point there's a chance FB might become extremely uncomfortable retaining the services of that employee, even though nothing has actually been proven yet. Accusations like that can ruin lives. You make some good points, and it might be good to have more open communication between law enforcement and companies. It just seems a little dangerous. There are some unexpected ways that it could turn out to be a bad thing.
- suprgeek 12y agoFirst: Thank you Snowden for introducing Privacy as a Banner issue which makes things like competing on providing greater privacy a "Business Differentiator". Before the disclosures there was only a murmur of privacy violations that too only amongst the tech literate. Yesterday the old guy manning the register at a store said "Now they can't track you when you pay by cash" to the customer in-front of me. Second: What a lazy-ass way to dragnet everybody and get stuck with huge irrelevant data! If you really suspected some one, the govt. should be able to convince a judge to get a "tap&gag".
- joe_the_user 12y ago...allow notification to happen or go to magistrate judges to seek either gag orders or search warrants, which typically are issued under seal for a fixed period of time, delaying notification Yes, whine-away, when law enforcement is required to get an adult in the room before they go all Rambo, "obviously the terrorists have won".
- ZoF 12y agoSorry for the tangent here, but I'm curious; how were they previously tracking customers paying with cash? Was it some form of membership with the store that would need to be provided on checkout?
- davorb 12y agoCredit cards.
- GotAnyMegadeth 12y agoI read it as a "Now listen here", not a "Now they have the internet on phones you know".
- ZoF 12y agoHaha, this is a late reply, but you got me parsing that statement correctly, thanks :)
- 12y ago
- free2rhyme214 12y agoThey still can do whatever with your data so whoop dee do.
- sounds 12y ago"Others" would in this case be "Google, Microsoft."
- shimon_e 12y agoApple wouldn't be my example of choice of a provider holding tons of private data.
- gkoberger 12y agoBillions of text messages.
- zekers 12y ago800 million credit cards on file.
- GregorStocks 12y agoThat's extremely valuable data to Apple and a great target for criminals, but I'm not sure the government would have much interest in it.
- sukuriant 12y agoThis should be qualified with: since they already have it via credit card companies. You give your social security number when getting a credit card for a /lot/ of reasons. And these tend to be a good reasons.
- lostlogin 12y agoThe majority of Apple's revenue is from outside the US. I have no idea what proportion of their credit card data is from outside the US, but we don't have these ID numbers. http://www.worldofapple.com/archives/2014/01/27/apple-posts-q114-revenue-of-57-6bn-profit-13-1bn/ http://www.worldofapple.com/archives/2014/01/27/apple-posts-...
- 12y ago
- wellboy 12y agoWhat happens if a company ignores a gag order? What will realistically happen, they won't put Sergey Brin in Jail will they?
- kijin 12y agoThey will not ignore a legal gag order (court order or national security letter). They will only ignore non-legally-binding requests to keep quiet, which they previously complied with, but which they were never under any obligation to comply with. They won't even refuse to provide data to law enforcement. Today's announcement only concerns whether the person whose data it is gets notified or not.
- tantalor 12y ago> refuse to provide data to law enforcement That would be illegal. They are subject to subpoena, i.e., "under penalty".
- wellboy 12y agoYeah it's illegal, but what the government does is also illegal apparently. So what if a company ignored the gag order, what would REALISTICALLY happen. Will the CEO be jailed or will they not be able to put anybody into prison. Will they have have to pay a $5M fine, will they have to pay a $500M fine? Or will the companies be able to supersede the government.
- lgas 12y agoI'm not sure exactly what would happen but I'd bet against the companies replacing the government by just not complying with a gag order.
- slowmotiony 12y agoThat was not his question now was it?
- davidp 12y ago"... companies grew determined to show that they prized their relationships with customers more than those with authorities" I've noticed that the words 'customer' and 'user' are starting to draw my conscious attention when I see them used (and misused) in mainstream journalism. Consider: For most of the companies listed in this article, the customer is exactly that -- someone who pays the company for something, e.g. a cable or internet subscriber. But for Google, Facebook, et al, the customer isn't the user; the customer is the advertiser. The user is the product. Google's customers could care less about privacy and user notification, except insofar as it spooks the users away from the service. The distinction is worth keeping in mind when trying to gauge just how far companies might take this newfound willingness to resist.
- deleted 12y ago[deleted]
- skj 12y agoI'm not really sure about this customer/product distinction. Both the people who view the ads and the people who buy the ad placement give Google something they want in exchange for something they have. That is, Google has products and services that it gives to customers in exchange for their eyeballs. Then, Google is able to convert some of those eyeballs into clicks, which they sell to advertisers in exchange for money. The transfer of goods in exchange for value is not only possible when money exchanges hands. If Google was unable to create products that convinced one of its classes of customers to sell their eyeballs, they would not be able to resell the eyeballs for cash.
- qwerty_asdf 12y agoHmmm... Let's try on a different quote for size: "... companies grew determined to show that they prized their relationship with their product more than their relationships with paying customers, such as advertisers, as well as other non-paying, but similarly coercive entities, such as law enforcement organizations" Yeah... I'm not sure how I feel about that version... It kind of makes me want to crawl in a hole and die.
- secfirstmd 12y agoThis is a great step in the right direction but what about the other 6.7 billion people not living in the US?
- jacquesm 12y agoYou're not a part of 'we the people'.
- aqme28 12y agoTrue, but the constitution does make deliberate distinction between 'people' rights and 'citizen' rights. Due process is among those that affect more than just citizens.
- raldi 12y agoPressure your government to demand "we won't spy on your citizens" pledges from each of their allies. If the US declines, ask how it can seriously call itself an ally.
- secfirstmd 12y agoI think people in the US don't understand effectively how afraid US allies are about criticising it. No one ever wants to stick it's head above the parapet and risk damaging relations - even when the US does bad stuff like torture in Gitmo. Especially if your from a small country. Even a big country like Germany is more afraid about damaging relations than standing up for the rights of its own citizens.
- aragot 12y agoToday I noticed my French insurance contract for my company explicitly forbid me from storing data in the US. It's certainly not related to privacy, but I'm happy they push that way.
- hoodoof 12y agoThey might face devastating consequences like fines of hundreds of millions of dollars.
- joelrunyon 12y agoIs that really devastating to billion dollar companies? Also - what's the opportunity cost in lost business from not doing this?
- hoodoof 12y agoShattering consequences.
- tsaoutourpants 12y agoThe consequences will never be the same!
- aqme28 12y agoHundreds of millions of dollars is something to seriously consider no matter how big the company.
- joshfraser 12y agoMeanwhile, all emails older than 180 days are still considered "legally abandoned" and any government agency can look at them with a simple statement saying they are relevant to an investigation. Does anyone know if user notifications are being sent when those emails are accessed too?
- ryanfreeborn 12y ago...citation?
- joshfraser 12y agoThe Electronic Communications Privacy Act of 1986 (ECPA) http://www.businessinsider.com/when-can-the-government-read-your-email-2013-6 http://www.businessinsider.com/when-can-the-government-read-...
- judk 12y ago"Can look" is not the same as "can compel the company to not notify the victim".
- samstave 12y agoSo, can one submit a FOIA request for all Obama, Clapper, Alexander emails older than 180 days?
- Istof 12y ago"...unless specifically gagged by a judge or other legal authority..." a legal authority... that is very broad
- malandrew 12y agoTBH, the default at all tech companies once they reach a certain size is to make a page that notifies users every time they are included in any query and the purpose of that query. I should be able to go to Facebook, Google or any other large company and see every single query where I was included in the results. Every query run should include a 1-4 sentence blurb explaining the purpose of the query run and an ID that can identify the employee/entity/user that ran the query. A large hash table could be used to anonymize the counterparty. Users, when seeing a suspicious query, could then petition the companies to divulge more information about the query in question, possibly even resorting to the courts if they can make a reasonable appeal for the information. I would love to see the EU to push for this as the default. If this was the default, then public policies researchers could gather data from volunteers to get a better picture of how companies are using personal data. Quis custodiet ipsos custodes?
- Eye_of_Mordor 12y agoObama hasn't done his job of bringing change. Quite what the word "hope" means to him is anyone's guess. What we've got instead is a system of government so ridiculous and bizarre that it's not worth following at all.
- perlpimp 12y ago“It serves to chill the unbridled, cost-free collection of data,” said Albert Gidari Jr., ... I thought corporations received some number of millions of dollars to perform these procedures?