7 ms·
Who Has Your Back? Government Data Requests 2015
- yuvadam 11y agoCurious if there's any project that aggregates all the transparency data data into a nice CSV, could be useful to chart and track trends.
- afsina 11y agoWhy does Google have only 3 stars?
- zerocrates 11y agohttps://www.eff.org/who-has-your-back-government-data-requests-2015#google-report https://www.eff.org/who-has-your-back-government-data-reques... Edit: (less cheekily) Inform users about government data demands: "...Google does not commit to providing notice after an emergency has ended or a gag has been lifted" Disclose data retention policies: "Google publishes some information about log data and deleted data, but it is not complete and representative of all its services and thus does not qualify for a star."
- learnstats2 11y agoParticularly since I recall that Google had six stars last year. Has Google gotten so much worse in the last year? Or has it perhaps stopped funding the EFF? Edited to add citation: http://www.theregister.co.uk/2014/10/14/assange_bollocks_google_eff/ http://www.theregister.co.uk/2014/10/14/assange_bollocks_goo...
- magicalist 11y agoThis is covered quite well (multiple times) by the article. The categories are not the same as last year.
- learnstats2 11y agoI agree that the changes are covered, but I disagree that they are covered well. The following companies have gone from at least one star below Google to at least one star above Google, on a 4-6 star rating system, in the last year: Adobe, LinkedIn, Wickr, Wikimedia, Wordpress. despite no company materially changing their terms in that time. How is this a robust or meaningful measure, in that case? The exceptionally large variation is not addressed. Why has this happened? In my opinion, it's because the 2014 report is bogus (two of the categories are "published a report"), and most probably it was just permitted to be bogus because Google were heavily funding the EFF in 2014.
- npizzolato 11y agoThree of the stars last year -- "requires a warrant", "publishes transparency reports", and "publishes law enforcement guidelines" -- were merged into a single star "follows industry best practices". According to the report, a company has to do all three of those things to qualify. It's perfectly reasonable for the EFF to evolve how they're rating companies as the years go on. After all, the privacy landscape changes and they're trying to push companies to making some changes. That explains the drop in stars. According to the EFF, Google is doing things that are now considered standard, and they're no longer on the forefront of defending privacy. Your accusations of bias because Google isn't funding the EFF are, frankly, ridiculous.
- learnstats2 11y ago>Three of the stars last year were merged If that were the only major difference, Google would still have 4 stars with the 5th undecided. Google now have 3 stars. >Your accusations of bias because Google isn't funding the EFF are, frankly, ridiculous. To be clear, I am not accusing EFF of bias against Google. Other privacy organisations have literally accused the EFF of lobbying for Google. From Wikipedia: "In 2011, the EFF received $1 million from Google as part of a settlement of a class action related to privacy issues involving Google Buzz. EPIC and seven other privacy-focused nonprofits protested that that the plaintiffs lawyers and Google had, in effect, arranged to give the majority of those funds "to organizations that are currently paid by Google to lobby for or to consult for the company."" Since then, the EFF spoke up loudly against the right to be forgotten (Google Spain v AEPD and Mario Costeja González), even though this is considered a privacy basic by EU data protection principles.
- DanBC 11y agoLook at pages like DataSaver. https://support.google.com/chrome/answer/2392284?p=mobile_bandwidth&hl=en-GB# https://support.google.com/chrome/answer/2392284?p=mobile_ba... There's nothing there about privacy considerations. It'd be great if Google started letting users know of there are (or aren't) privacy implications.
- Splendor 11y agoI'm interested in why the EFF chose these companies to rate. For example, rating AT&T and Verizon but not Sprint and T-Mobile seems odd to me. Rating Snapchat but not Instagram almost makes sense becuase they're rating Facebook, but then they've rated WhatsApp separately.
- ethanbond 11y agoThe ATT/VZW/Sprint/TM differentiation is weird, but Instagram versus Whatsapp doesn't seem strange... Instagram doesn't honestly seem like a hugely valuable target. That's not to say I'm comfortable with them giving up info freely, but I'd be much more concerned about my WhatsApp data being turned over than my Instagram data. I'd rather lists like these not be polluted by things like that.
- deleted 11y ago[deleted]
- 0xCMP 11y agoI'd like to point out something related to what others have already said. First, they've pointed out the seemingly illogical picking of companies. Snapchat but not Instagram (maybe part of facebook?) and AT&T but not T-Mobile? etc. Another issue here is that by looking at the past reports you see how quickly one company is the favorite and soon becomes the ugly step child. The columns with stars are also changing to what sound like very vague and lax requirements compared to the year before. I didn't see any explanation there why. For instance they took out the "requires warrant" column. I wonder if companies are contributing to the EFF and so the EFF feels the pressure to make these companies look good in the face of this new Snowden era. For instance, isn't it great that Apple now has 5 stars as it's starting it's big "we're private" push while Google is now very low compared to previous years? And how about twitter? They used to be a poster child for good behavior as far as companies go.
- sqeaky 11y agoYou can read the description below the chart, they rolled the requires warrant column into another column. A company must do both things to get a star.
- ywecur 11y agoThe only ones that actually have your back are those that use encryption to make data collecting impossible.
- jacquesm 11y agoThis is about requests for stored data and then the encryption is moot, that mostly affects data in-flight or seized computers if the data is stored. In the latter case you will probably be forced to cough up the decryption keys.
- icebraining 11y agoHence cperciva's "Playing chicken with cat.jpg": http://www.daemonology.net/blog/2012-01-19-playing-chicken-with-cat-jpg.html http://www.daemonology.net/blog/2012-01-19-playing-chicken-w... When we're talking about protection against government data requests, only companies that make sure they have access to the absolute minimum client information they possible can do truly have our backs. Everyone else just has good intentions.
- jacquesm 11y agoColin has it right. If you don't want to ever compromise your clients data make sure you can't read any of it. It's that simple. Anything else simply won't do. That's why I keep recommending tarsnap to customers.
- stephenr 11y agoOr you could.. you know... recommend an appropriate client-side encryption tool so they can then store the archive/backup data on the storage provider of their choice...
- frankzinger 11y agoThe advantage of having client-side encryption built into tarsnap is that it encrypts only after data deduplication and compression. Obviously there could be a tarsnap option to stream the data to be uploaded through an encryption program of your choice, but doing it just as you suggest would nerf a few of tarsnap's prime advantages.
- dimino 11y agoThe stars should link to sources of each of these categories, that'd be cool.
- suprgeek 11y agoUsually the EFF does a good job with these reports but you got to wonder with a company like Dropbox. - Condi Rice is on the Board of directors - an avowed supporter of NSA warantless wiretaps - Users cannot control thier Keys such that it becomes impossible for them handover data to the Govt. even if they complied to the NSL or whatever other BS demand And they get 5 stars for "Having our Backs" (!)
- lighthazard 11y agoThey also scan user files for copyright protection and a few years ago had some clear breaches of trust between users and the company.
- numbsafari 11y agoThe point of this effort is to elicit change from these organizations. If having breaches "a few years ago" means never getting a star, why would a company care?
- deleted 11y ago[deleted]
- ytdht 11y agoMicrosoft opposes backdoors but not some process that is very similar that allows "legitimate legal requests" to be fulfilled ...