Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, that's generous. You don't have to be specifically investigated by the FBI (just 'related') and the court orders used to make requests can be quite large and in practice are primarily automated. If you look at the sort of processing the NSA is talking about they are discussing large scale sentiment and social media analysis (of the sort that non-related folks must be included). On this line we know that anyone 'three hops away' was considered legally relevant to an investigation. It was shown in the Snowden documents that NSA hacked into backend databases of US corporations to collect data - which gave data access with no warrant. Finally, companies are encouraged to give data to the government as a gift. This gifting of data is not compulsed legally and is outside the scope of (weak) legislation by FREEDOM providing some small limitations on bulk collection requests.


If you have an associate or an associate of an associate who is a known threat to national security, and the government submits a request for your data, you are specifically being investigated. From Google's transparency reports, we know that the number of foreigners being investigated is in the low tens of thousands, and the number of Americans being investigated is at most low single digit thousands.

We know that all corporations that had their inter-datacenter networks compromised (there is no evidence their databases were accessed) have since encrypted traffic on those links, making that a non-issue. The last remaining place to collect data in bulk is between the user and the service, which is what this blog post addresses.

The data-gifting is a figment of your imagination. Nobody will go out of their way to make their own data accessible to a third party for free, and these Internet companies in particular wouldn't share it with anybody.


Sure, if you can say that hundreds of millions of people can simultaneously be specifically investigated.

> We know that all corporations that had their inter-datacenter networks compromised have encrypted traffic on those links, making that a non-issue.

Actually, we know that they targeted the interlinks where encryption was removed and added back - giving plaintext (if you are referring to Google). If you remember after the Snowden exposures related to this hacking there was an industry wide call to encrypt data in transit - this very thing implies it was not the case before.

> The data-gifting is a figment of your imagination. Nobody will go out of their way to make their own data accessible to a third party for free, and these Internet companies in particular wouldn't share it with anybody.

Please familiarize yourself with the associated stored communication and service provider laws and data sharing programs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: