More denialism from tptacek. For those who care about the actual source, the NSA slide in question says "Collection directly from the servers of".... Viewers can decide for themselves whether the NSA or tptacek has greater credibility when it comes to describing the capabilities of the NSA system.
It's not "NSA vs. tptacek". It's "Greenwald's interpretation of NSA slide deck vs. Google". Google categorically denied Greenwald's report. The Guardian then began walking it back.
Nonsense. You have repeatedly insisted that the NSA document must be wrong ("nothing to see here, folks"), simply because Google denies providing "direct access". You do this by drawing a semantic equivalence between what the NSA asserts and what Google denies, and then assuming that the NSA is wrong.
This is not a reasonable position for anyone with a technical background. Because anyone with such a background should surely realize that the two statements are not mutually exclusive, and there are plenty of ways for data to be collected which the NSA might reasonable categorize as "direct" while leaving Google with plausible grounds to categorize as "indirect" or otherwise deny knowledge of.
Everyone, including The Guardian, now agrees that Google had "plausible grounds" to "categorize access as indirect", because that's exactly what their access was.
I agree it is a semantic distinction and that your characterization of what Google is doing is probably accurate. I disagree that holding this viewpoint gives you any grounds for attacking Snowden's credibility (as you have repeatedly done) or asserting that widespread claims of inappropriate NSA surveillance are implausible or technically impossible.
Why do people treat this sentence as if it is absolute proof of "direct access" to the company's servers and data?
It's easy to see how this sentence, in light of the entire "dropbox" thing, means that NSA grabs data directly from the "dropbox" set up and operated by the company.
There is ambiguity and room for interpretation in almost all language, especially the vagueness of a Powerpoint presentation.
>means that NSA grabs data directly from the "dropbox" set up and operated by the company.
the "direct collection" is a part of "FAA702 operations". The FAA702 is unrestricted collection of data of "non-USPER"sons, and in particular no individualized FISC orders required.
Now there is a choice - either Google combs their data, decides who is FAA 702 "eligible" and of interest to NSA and dumps the "non-USPER" data it has identified to the "dropbox" or the NSA does the combing/identifications itself (and if NSA does the combing - where it does it? on NSA servers attached to Google datacenters or does it transfer all data to NSA datacenter and combs it there?). What do you think NSA has chosen?
Individualised FISC orders are required. http://www.govtrack.us/congress/bills/110/hr6304/text (Or more precisely, FISC review and approval of individualised FISA 702 orders are required - the court doesn't actually issue 702 orders.) That's almost the only protection non-resident aliens have under FISA and the jurisprudence that upholds FISA, but the protection is there. It could be undermined by issuing millions of FAA 702 orders or one FAA 702 order covering millions of people, but we have reasonable assurance that this hasn't happened (yet) https://news.ycombinator.com/item?id=5865717 .
Yes, a FISA order, like a warrant, can identify more than one person. But again, in order to target (for example) every Facebook user, the 2000 FISA orders in 2012 would have to have covered an average of about 500,000 Facebook accounts each. That has probably not happened https://news.ycombinator.com/item?id=5865717 .
Again, for FAA 702 collection no individualized FISC required. 1 order for the whole Facebook, 1 order for whole Google, ... it seems that NSA does really need that server farm in Uta.
> Again, for FAA 702 collection no individualized FISC required.
That's not a FAA 702 order though. In fact it's in a different category to all the 70* orders, which fall under the "electronic survellance and/or physical searches" category in the https://www.fas.org/irp/agency/doj/fisa/2012rept.pdf annual report. The Verizon order would be a FAA 501 order, though people only ever seem to refer to it as a 50 USC § 1861 order. They're the "Applications for Access to Certain Business Records (Including the Production of Tangible Things)" on the annual report. These orders seem to be intended for things like the Verizon metadata, which it seems (IANAL) are considered to be unprotected by the probable-cause requirement even for USPERS. So I presume a 501 order couldn't be used to grab users' full private data from Google. In any case Google has denied that it has ever complied with http://www.wired.com/threatlevel/2013/06/google-uses-secure-... (or even been served http://googleblog.blogspot.ie/2013/06/what.html ) any order nearly as broad as the Verizon one, and Facebook and MS have more or less followed suit.
No, but then I also find it unlikely that they're actually giving away their Top Secret program by getting such data from Facebook through a secret order (whether it covers one person or many) and then handing it over for immigration desk staff to wave around.
Why is it a non-issue? One interpretation implies that the NSA is constantly accessing the data of anyone, anywhere. The other implies something incredibly smaller in scope and with a legal framework (which you may or may not like) behind it.
This seems to be the entire issue to me with PRISM - whether it's an unprecedented level of access or merely a statement of what has known to have been going on, and what was covered under FISA, for years, but just in a more technically expedient manner.
It is a non-issue because tptacek is inventing semantic distinctions (apparently irrelevant to whomever created the NSA document) to attack the credibility of multiple whistleblowers who allege widespread surveillance and abuse.
Especially given the fact that the leaked documents specifically encourage analysts to use a range of tools (i.e. "You should use both"), he has no technical grounds for suggesting that such a minor semantic debate (between NSA and Google) discredits the claims of multiple people with first-hand experience of the NSA who are coming forward with claims of its abuse of power.
Every USG veteran knows to be skeptical of mission briefs, regardless of important-looking classification markings.
That deck was put together by a mid- to low-level government program manager who owned the program. He is playing politics, making his program sound like the most awesome thing EVAR so he gets promoted. It's not an "official" document, despite all the fancy markings.
http://media.hotair.com/wp/wp-content/uploads/2013/06/prism-...