8 ms·
Dropbox was revealed as a participant of the PRISM program: anything you store there is searchable. The same is true of Facebook and Google and Yahoo, Apple, al
by xnull 12y ago
Dropbox was revealed as a participant of the PRISM program: anything you store there is searchable. The same is true of Facebook and Google and Yahoo, Apple, all cell phone carriers, all internet carriers and other cloud storage companies including Skydrive/Onedrive.
- skuhn 12y agoDropbox is mentioned in the PRISM slide deck as being a desired participant, not an actual participant. I worked at Dropbox when those slides were released, and none of us on the operations team knew what it could possibly be talking about. Every company that wants to continue to operate in the US has to comply with US government orders, that is just a fact of life. No one in the technology industry is super excited about going to jail or having their equipment seized. But the kind of compliance that PRISM implies is not something that you just sneak in without anyone noticing. There was an internal accounting of every server and network connection -- it would have required a shadow ops team running shadow datacenters to sneak it by us.
- xnull2guest 12y ago> Every company that wants to continue to operate in the US has to comply with US government orders, that is just a fact of life. No one in the technology industry is super excited about going to jail or having their equipment seized I understand this and it is not contrary to my point. I'm actually trying to point out that the companies Snowden mentions have been specifically mentioned by NSA slides/documents and I think this has colored his suggestions. He suggests moving to others - but ultimately anything he suggests will get subverted if enough interesting material gets stored there. Not that that in itself is a reason not to adopt new technologies. > To sneak it by us... They aren't sneaking it by you as a company. They cooperate with the corporation and its internal organizational model to create a solution that fulfills the requirements. Most employees, however, can be blissfully ignorant. I think you overestimate your ability to know such things. I know plenty of Google employees that had no idea about Google's involvement, Facebook employees with no idea about Facebook's involvement, Apple employees with no idea about Apple's involvement and Microsoft employees with no idea about Microsoft involvement. I also work at a large company, and would have thought I would have seen clear indications of PRISM (& other) activity. Unfortunately that is not the case. Condolezza Rice (of all people) joined the board of Dropbox. This is their full time job and their professional expertise. I'm sure that PRISM infrastructure (or beta versions) were accounted for in full. Edit: It's not condusive to conversation to downvote something merely because you disagree with it. The downvote button (and upvote respectively) are for designating whether you believe something is irrelevant to (/contributes to) the topic.
- skuhn 12y agoIt's always hard to be absolutely certain about what goes on at a company, but I'm pretty confident about Dropbox not participating in PRISM (defined as a government system that automatically collects considerable data from within a company's private systems). I haven't been at Dropbox for a year now, but for most of the time I was there I was one of only two SREs that ran the production infrastructure. I knew every piece of server hardware in every datacenter, and what services ran on them. It was my job to qualify and deploy hardware, do the systems level automation, and run the user facing frontends. There is literally no way that something like PRISM could be put in place without my knowledge except by what would amount to sabotage. Keep in mind that while Dropbox is large for a startup, it only recently surpassed 1,000 employees (150 when I joined). The vast majority of those people are in customer service, and the number of people with access to production is likely still well under 100. For the first five years of the company's life there was one datacenter manager and network engineer (the same person), one SRE up until I was hired, and so on. In operations, we did more with less. However, this shouldn't make you feel like your data in Dropbox is guaranteed to be safe from prying government eyes. Dropbox can and does comply with government requests -- every company operating in the US does so, or they would not be operating anymore. I agree with your distaste towards Condoleezza Rice joining the board. It doesn't look good, but I also doubt that she has any day-to-day authority or responsibilities whatsoever.
- xnull2guest 12y agoI'm still not confident. Don't actually answer these questions (NDA and all), but how much traffic do you guys get? Could you possibly inspect it all? Have you inspected the hardware itself? Can you trust the switching equipment?It's reasonable to think that collection happens at the pipes between data centers (like some of the Google collections - which didn't involve any of the hardware present although that collection program wasn't a cooperative one). Some of the lengths they go for these programs are really impressive. It was revealed that AT&T had secret rooms built that blend into the building infrastructure but MITM every packet that gets sent through (what looks like) normal infrastructure lines. At some point it feels like you're being asked to prove a negative. That's the thing about discussing secret operations. And it is why the documents are so important. I wonder now that the Snowden leaks are getting dated about a year old (and it being a few since you've left Dropbox) how much has changed. Finally, the other companies on Snowden's list are certifiably on the list of already onboarded products, so it's hard to trust them. > I also doubt that she has any day-to-day authority or responsibilities whatsoever For example she assigned a new CFO for Dropbox. I doubt she has day-to-day authority (she's a busy woman), but being on the board and selecting upper management is a lot of power.
- colordrops 12y agoSo people should just upload unencrypted data willy nilly to 3rd party servers because they aren't mentioned in a leaked document? Sounds like a terrible security plan.
- mkal_tsr 12y agoThis! "Don't mind me, just putting important & sensitive personal information on the internet backed by the power of an easily guessible password and hints. Pre-Encrypt -> [OwnCloud || SpiderOak || AWS S3 || etc.] And re leaked docs ... I still don't understand the mindset that some people have (maybe someone can help me). When people say, "oh, but the US Gov isn't worried about you" all I can do is roll my eyes. * How can you verifiably prove that? (they can't) * How can you verifiably prove other governments aren't? * How can you verifiably prove chaos agents aren't? * How can you verifiably prove someone isn't silently watching you? * etc. Just because it was or wasn't in a leaked document does not mean that the ability does not exist nor does it mean that such capability is only in the hands of 1 government. In my eyes, the leaked docs showed "this is the current level" re: security/privacy/surveillance. We have to assume all other governments, corps, & individuals have equally or more powerful systems in place. Why? Because it's the only safe assumption. That assumption has no bearing on the merits of legality with how the NSA conducts its mission, nor bearing on how others act. The documents merely give evidence and a base-level run down of additional attack vectors. This has absolutely zero to do with a "legal vs. illegal"-action debate and everything to do with technological security and infrastructure. I encourage everyone to consider RFC 7258 [1] in their future projects. Do it for your users, whomever they may be. Consider RFC 7258 your USSINT 18 (if you're American) ... that is, fucking read it, understand it, and internalize it. Maybe the gov is good, maybe they're bad - that is irrelevant when there is more than just 1 gov in the world. [1] http://tools.ietf.org/html/rfc7258 http://tools.ietf.org/html/rfc7258
- lern_too_spel 12y agoYou left out half a sentence. "Anything you store there is searchable" if the US government has a court order for your data. This has always been the case. Other governments have similar systems for processing data obtained via legal requests, under different names.
- yuubi 12y agoDon't we have some examples of such court orders, basically "Acme Telecom is ORDERED to reveal ALL THE THINGS"?
- lern_too_spel 12y agoPRISM specifically isn't about revealing ALL THE THINGS. The documents reveal it is for ingesting specific users' data.
- xnull2guest 12y agoRight, but the Snowden revelations showed that the FISA court was/is? a rubber stamp circle without any real due process - and in fact they can search the data and afterwards make a request via the FISA court. The data is also collected and stored and processed by algorithms without any court oversight, it is just when they want a contractor to look through the data manually that the minimal paperwork is involved. It would be misleading to include that half sentence without also mentioning this.
- lern_too_spel 12y ago"The data is also collected and stored and processed by algorithms without any court oversight." This is false. PRISM doesn't get any data that wasn't specifically requested with a court order. It sounds like your understanding is still based on Greenwald's original reporting, which has since been shown to be inaccurate.
- xnull2guest 12y ago"Collected" legally means looked at by a human. I'm talking about sent to the NSA, processed by algorithms and stored. That's not 'collected'. It's a word game they play. My original assertion stands. And be careful of "not under the PRISM program". The "not this program" has been shown to be false over and over (in spirit) as there are many related programs that do joint work on shared datasets. Regarding Greenwald's reporting, can you link to something comprehensive (and trustworthy) about inaccuracies?
- newscracker 12y agoWhat's worse with Dropbox is that it deduplicates data across users. So it's really easy for someone who "needs to know" (like the NSA) as well as people who "would like to know" to "takedown" a single user for something and identify every other Dropbox user who has the same content.