Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Google tried to resist FBI requests for data, but the FBI took it anyway (venturebeat.com)
341 points by cwilson on June 7, 2013 | hide | past | favorite | 81 comments


300,000 NSL's? Is that really how many terrorist plots they've foiled or even suspected? Because I'm very skeptical about that.

The fact that the government can put a gag order 300,000 times on companies and people like this is insane. Forget about "future abuses". It has already happened and keeps happening. It's pretty clear the government is very loosely using these NSL's now. Where are the checks and balance?


We found out the PATRIOT Act was really used for drug enforcement[1] so I wouldn't be surprised if it was the same with NSLs.

[1] http://www.washingtonpost.com/blogs/blogpost/post/patriot-ac...


>It's pretty clear the government is very loosely using these NSL's now

Now? It's never been any other way. I wonder if they ever intended anything else.


Let me get this straight, when you receive an NSL from the FBI (executive branch) then you are not allowed by law to contest it in court (because of the gag order) without fearing repercussions for violating the gag order by revealing the NSL to the executive branch? Where are the checks and balances??


You are allowed to contest it and Google did contest it.

This is true since, at least, 2006.

http://www.law.cornell.edu/uscode/text/18/3511


You aren't even allowed to contact counsel for advice.



So what happens if you tell them to go away anyway? They take you to court? Raid your datacenter? Good luck getting public support for that. Seems the problem with these secret orders is, you can't actually _enforce_ them without making them public, you can just make threatening gestures.

I'm dissapointed no tech company has decided to play hardball on this...


Wouldn't defying the court order mean you are breaking the law? I wonder what that would mean in terms of fines and possible legal implications for the directors?

I am sure the Government would say that the company is with holding data essential to counter-terrorism. With a bit of Government spin I don't see how the tech company could come off positively from making such a stand.


I hate the counter-terrorism card being played so often to get free pass with no consequence at all, usually not involving terrorism in retrospective.

Counter-terrorism is the new terror.


You and I both, but the problem is convincing the rest of America.


They would accuse you of 'supporting terrorism' and 'aiding the enemy' - both of which can come with lengthy jail terms.

Pretty sure that no matter how outraged you or I might be by this, the person in the street would believe the spin: 'I can't believe company X really wants to support terrorists by keeping information from those that are trying to make this country safe'.

Look at the lack of outrage at the treatment of Manning (or god forbid the inhabitants of Guantanamo Bay - most held without charge with no hope of a trial, simply still held because no (friendly) country will take them - and you know we can't have them going home now can we...)


Are people actually upset with Google and the other tech companies over all of this? It seems they were legally compelled to do it. Be furious at Washington, not Silicon Valley.


Funny how tech companies don't mind breaking the law on principle when it aligns with growing their company, but when it comes to principle alone, they break like twigs.


I think this sums up the issue really well. But I think that's how the world works I guess !


They can certainly manage to avoid compliance with at least the spirit of the law when it really matters to them. I guess avoiding paying tax is important enough to engage armies of lawyers and reorganise your corporate structure, while this isn't.


In this case, I would be happy if some CEO refused, breaking the law in support of a higher principle.


Good luck finding someone who is willing to risk his own reputation and livelihood, including hireability (after he and the company have the shit sued out of them by their shareholders, including institutional investors), as well as the livelihood of his employees.


These guys have millions of dollars already, and just think about the goodwill generated from standing up on principle. We're not at the point where the government can seize their assets "because f___ you, that's why"

They're just as cowardly as many others facing this situation, except the CEO has a lot less to lose (if you can understand this paradox, cheers)


Isn't that the reason they seized Dotcom's assets? They had no legal basis for that.


in dotcom's case, the calculation was that he would be an unsympathetic character:

fat, obnoxious, foreigner, fortune gained from a somewhat illicit business (let's be honest about the service he provided to both licit and illicit customers)


I understand. But the world would be totally different and much better if people didn't cave in like this.


Very few people don't cave when you put a gun to their head (NSA information demands like this require the direct supporting threat of violence as an or-else).



Qwest CEO Joseph Nacchio did that when it was blatantly illegal - he's serving a six year prison sentence now.


This implies he was chucked into prison for refusing to hand over data to the US government, which is misleading at best.

He was imprisoned for insider trading, appealed on the basis that a witness's testimony (relating to the data-grab) was excluded from his defence, and won a re-trial where he had his conviction and sentence re-instated.

My understanding of this sequence of events is that while the witness was improperly excluded from his trial (thereby allowing him a re-trial), it did not materially alter anything about the 19 counts of insider trading of which he was convicted. So basically he did a good thing, then did a bad thing, and went to prison for the bad thing. Seems all right.


That is exactly what happens when you fight the powerful. You don't go to jail for fighting. You go in for something else that is entirely disconnected. It could even be a rape case (Yes, I'm talking about Assange)


And that is exactly the problem with PRISM. It gives people in power the ammunition to find you guilty of some unrelated crime if you challenge them.

    “Show me the man and I’ll find you the crime.”
    - Lavrentiy Beria, head of Joseph Stalin's secret police


It doesn't matter. If you use their services, you are under the watch of Big Brother. Now I have to go untangle the mess that is my integration with Google. VPS in Argentina here I come!


Were their only options really "comply or go to jail"? I feel like they should have done more.


You're right.

But google also has part of the blame: it reassured people with "do no evil" and it's fights with government, instead of telling from the start that this would happen , as they would probably have known , and offering better technical protections against such things.

But in reality , it's a complex subject. Maybe they really thought that in world with global terrorism and crime , internet surveillance is the lesser of two evils.


Schmidt already tried telling people this would happen:

"I think judgment matters. If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place. But if you really need that kind of privacy, the reality is that search engines, including Google, do retain this information for some time. And it’s important, for example, that we are all subject in the United States to the Patriot Act. It is possible that that information could be made available to the authorities."

Instead of praising him for honesty, people started taking his quote out of context. "If you have something that you don’t want anyone to know, maybe you shouldn’t be doing it in the first place."


They should have moved all their operations to a free country instead of caving in.


I just want the option to choose my data locality when I sign up. e.g. "Google, please save all my data in your Switzerland data centers".


Five years later, the population of Iceland has exceeded that of the United States.


I can't do anything to Washington. But if enough of us can make e.g. Google bleed cash they can do something.


If you don't want Google giving your data to the FBI, then don't use google. Oh - wait - Google is gonna get your data no matter what. Google Analytics.


This is isn't specific to Google, and I would go further and say that ISPs are a much juicier target than Google. ISPs have the raw access to all your traffic and wilt more easily when pressed by law enforcement (eg Carnivore).

I don't think there is an easy way to solve this. From law enforcement's perspective, big tech companies have already done the hard work of getting users' data; all they need is a warrant or a NSL or any other magic ticket. That is the problem we should solve.

Disclaimer: I work on Google Analytics.


> This is isn't specific to Google, and I would go further and say that ISPs are a much juicier target than Google.

This statement probably would have made more sense when Google wasn't an ISP.



I found blocking GAnalytics broke too many websites (although that may be poor design of those sites). There's an opt out[1] which I'm sure is carefully worded that if enough people used it they could still track us but at least websites load.

[1] https://tools.google.com/dlpage/gaoptout


Both Ghosterly and NoScript have a built in ability to unbreak sites that have tight Google Analytics integration.

https://news.ycombinator.com/item?id=5182359

not sure if this applies to Chrome versions, but if you are using Chrome, and dont trust Google, im not really sure what you are thinking.


Is this getting downvoted because of advertising or because of the integrity of the software?


Currently, the comment's font color is black. It appears gray for you because you have visited that site.


Why is the text so small?


Are you using chrome on android? It does that for some idiotic reason.


Nope, I was using Safari on the latest version of iOS. I'm on my laptop now and it looks normal.


For some reason, comments on HN appear with seemingly random font sizes when viewed on mobile. I've seen it on both android and iOS.


+1 i see the same behavior on my android, but don't see the issue on the desktop !


I always thought it was due to a comment being of less than a certain number of characters, as a way of diminishing throwaway comments that may generally not add much to a debate. I guess not?


The software works well and the company has been very open.


I don't even understand the ignorance of this comment every major tech company had been cited as participating and especially the isp's. Google analytics is nothing in comparason to what the isp's know


Google Analytics doesn't profile users - it's aggregate data for webmasters.


Can you prove that Google doesn't gather that data for themselves?


You just see some pretty statistics but you don't know (and possibly can't) what happens behind the scenes.


if it doesn't profile users, how is it able to supply you with the demographics of your visitors?


How to be completely Anonymous on the internet:

http://www.slashgeek.net/2012/06/15/how-to-be-completely-ano...


You could also stop using the internet altogether, because someone is going to provide an analytics service, even if Google didn't.


What I was trying to say is that the problem is not some company, but the government itself.


https://disconnect.me/

Also blocks as many other tracking scripts as can be found. I've found it to be faster than ghostery etc.


Doesn't Google Analytics just collect metadata that you're sending in your HTTP requests anyway? And basic tracking cookies for distinguishing unique users/visits?

I don't think there's really a reasonable expectation of privacy for that sort of data. You're already sharing it with every other website you visit.


Yeah there are plenty alternatives now like Cozy Cloud or Owncloud.

https://www.cozycloud.cc/

http://owncloud.org/


Even if we could trust google to fight for our interest, we may not be able to trust our governments to do the right thing.


Here in the USA, we can trust our government not to do the right thing.


Companies like Google, FB, Tweeter even Amazon and Opera are intentionally built to collect, mine and analyze, then sell (or profit from) its user's data. This is just a standard way of making money - collect a huge dataset of user-generated data and then monetize it.

No wonder that authorities will use the data, because, well, it is just business as usual.)


Sure, but let's say there was a very popular e-mail company where you paid for the service. They would be keeping your e-mail anyway. Do you really think it would make any difference for NSA/FBI? They'd still get them just as easily as from Google, Apple and others.


Misleading headline. Google fought that one time but it's been years since they've been part of PRISM.


PRISM is the NSA. This article was about the FBI.

The FBI has always had less access to SIGINT than the FBI.

The NSA has one purpose: SIGINT. The FBI is a much broader and, in this sphere, weaker authority.


Oh OK Google "tries" to resist FBI requests, but how about requests from the NSA? Top secret:

http://www.pcworld.com/article/217550/google_watchdog_white_...


I can't help but wonder how such a system can be practically implemented. I cannot imagine that engineers at companies like Google, Apple, MS etc, the ones working on stuff like Gmail, YouTube, iOS, would co-operate with such unethical practices.

But it has been proved again and again that authority trumps conscious.


This is a classic "technology is neutral" situation, or if you prefer, "social problems don't have technical solutions".

I'm sure some of the technologies I've worked on during my professional career could be used to do things under ethically dubious circumstances. They could also be used to do the exact same things with a sound ethical and legal basis that almost everyone would agree was reasonable. And they could also be used to do many other completely unrelated and useful things where there is no ethical dilemma at all. Context is everything.

I would guess that the majority of people who work in any kind of manufacturing or information services industry could say the same thing, probably including technicians working on communications systems at the kinds of organisation you mentioned. Most of those people have no way to know or influence the way their work will ultimately be used further down the line. Society is too big and too complex to expect action or accountability for everything at that level.

That means the only practical position is to say that responsibility for (mis)use of general purpose tools must lie with the (mis)user, and if the system isn't working, that is the level where any fixes need to be applied.


I'm surprised google didn't go public with all of this information. They have more legitimacy and support than the government at this point, and I think that if push came to shove, google would just refuse and call the NSA's bluff.


Could they just partition user data so that data locality on citizens of country X are located in country Y and therefore outside the jurisdiction of country X.

When you sign up, they could make this an option. "Do you prefer faster access to your data or have you data located in a specific jurisdiction?"


How does this effect foreign users of these services? I mean I'm pretty sure that they haven't restricted their data collection to US citizens. Is there international law about this?


Uh, the NSA's primary mission is to conduct data surveillance on foreign entities. The reason why PRISM exists is that much of this data flows through American companies' servers.


Of course. Just surprised that EU politicians don't take the chance to gain some popularity by screaming that they're angry at the US.


Don't worry, they will.


Wait.... if I use Google Analytics on a site this implies that the IPs of every visitor to the site is available to the NSA? Correct?


Someone high up at Google could have risked jail time if the issue mattered. None did. That says it all.


Probably not as easy as resisting paying proper taxes...


Says google




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: