Technical Risks of the US Protect America Act
A group of respected security researchers has released a paper on the security holes that would be opened up if a broad warrantless wiretapping law is passed. The subject could hardly be more timely, as Congress is debating the subject now. Steve Bellovin, Matt Blaze, Whit Diffie, Susan Landau, Peter Neumann, and Jennifer Rexford have released a preprint of Risking Communications Security: Potential Hazards of the Protect America Act (PDF), which will appear in the January/February 2008 issue of IEEE Security and Privacy. It will hit the stands in a few weeks. From Matt Blaze's blog posting: "As someone who began his professional carrier in the Bell System (and who stayed around through several of its successors), the push for telco immunity represents an especially bitter disillusionment for me. Say what you will about the old Phone Company, but respect for customer privacy was once a deeply rooted point of pride in the corporate ethos. There was no faster way to be fired (or worse) than to snoop into call records or facilitate illegal wiretaps, well intentioned or not. And it was genuinely part of the culture; we believed in it, even those of us ordinarily disposed toward a skeptical view of the official company line. Now it all seems like just another bit of cynical, focus-group-tested PR."
The only thing that we can do is look at material like this and make sure that we communicate these points to those who represent us. It's only natural to be cynical about the likelihood of making a difference with your call, but unless you take that action we'll never know if we could stop this thing.
Regards, Ian
"All that is necessary for evil to triumph is for good men to do nothing."
As a bonus, pass a law giving evil men immunity.
You can't talk about Wikipedia's flaws on Wikipedia
unfortunately you got the right impression. living/working in Albany, NY I get to see a lot of this with friends that work in (state) senators' offices, nothing ever gets to them without being filtered and they already know where they stand on bigger issues and outright ignore their constituents unless the media gets involved (like spitzer and his give illegals drivers licenses thing)
heck I've written our 'good' senator Schumer a number of times on big issues and all you ever get back is a form letter written by an office intern, no big deal there but you have to know he never reads any of those emails, they get read by the same intern and if you're lucky he summarizes a few of them to his boss later.
My Sig Sucks
One more document showing privacy = security.
"Now it [privacy] all seems like just another bit of cynical, focus-group-tested PR."
The U.S. government has become extremely corrupt. One method is the one mentioned, testing for weaknesses in public understanding, or willingness to act, and exploiting those weaknesses.
Here are others:
Making sure that honest, public-minded leaders from both parties are defeated.
Giving bills in Congress misleading names, like "Protect America".
Giving bills misleading features and widely publicizing the misleading features. For example, the "economic stimulus" bill only causes the government, which is deeply in debt, to print more money. That will make the value of the dollar go down even further. The "economic stimulus" bill also contains provisions to funnel money to banks. The banks apparently deliberately created the mortgage finance crisis doing so was profitable, and because banks were sure that the U.S. government would pass a bill to lessen the losses.
...once this has passed, I hope that someone (with a quickness) is able to exploit the system, record the personal calls of the legislators who passed the bill, and subsequently post them on the internet.
Everything from making dentist appointments to arranging for private meetings.
Live streaming if possible.
Ramen
In typical slashdot fashion, I have not taken the time to read the whole bill. I have not even read a summary of it. However, having read the title, I can say that I, living in America, support this whole concept of "protecting America." Go on Congress, allocate the funds for some more tanks or something, I'm behind you!
Your ad here. Ask me how!
"The debate isn't security versus privacy. It's liberty versus control."
RIAA, MPAA, and now USPAA....tell me you don't notice a problem here.
There was no faster way to be fired (or worse) than to snoop into call records or facilitate illegal wiretaps, well intentioned or not.
Bull*shit*, chief. Hoover wiretapped and bugged whatever and whomever the hell he wanted, and nobody dared complain- he was 'fighting' communism. Hoover did it entirely on the premise that, as director of the FBI, it was his purview. That's it. No fancy legal mumbo-jumbo. "I'm the boss."
I hate the current wiretapping as much as the next guy, but let's not get caught up in "when I was your age, candybars cost 5 cents and the phone company didn't tap your phones illegally."
Our phones have been tapped almost since their inception; all the changes is who's calling the shots, what "evil" group is being targeted, and whose definition of "legal" is being used.
Please help metamoderate.
...And I'm proud to be an American,
Where at least I know I'm free
As long as I follow the party line
And carry my ID...
(With apologies to Mr. Greenwood)
Strike while the irony is hot! -- The Freethinker
No congressperson has read the bill either!
I think Mr. Greenwood is the one who should apologize to all of us.
"We shall grapple with the ineffable, and see if we may not eff it after all." - Douglas Adams
The fourth ammendment to the constitution and the Geneva Conventions used to be a strong part of the ethos of american culture.
But those were the good ol' pre-9/11 days.
Wake up and smell and the realized nightmares of the founding fathers, and don't waste your time thinking that whatever is left of their foundation of democratic principles can help us.
We are sliding full speed down the slippery slope already. The only hope is that america will survive the impact at the bottom, and that the result will be painful enough, that the constitution gets ammended, and a new dawn of liberty arises.
I was the longest holdout in believing that intelligent debate could actually help. It is clear to me that the only thing to do is to sit back, suffer the consequences along with everyone, and hope that people are capable of learning from their mistakes.
O what a brave new world. Human cloning, animal-human hybrid research, warrantless wiretaps. Someone could really write a good book about all of this... But these days you probably wouldn't want to purchase it or check it out of a library, lest your name be put referenced in database queries for threat index assessments.
-dmc
Bush and his Republicans say that the FISA renewal is the most important weapon we have to protect ourselves against attack. But Bush says he'll veto it if it lets people sue telcos for helping Bush wiretap us, and his Republicans also have tried to stop the bill from being amended, or even debating amendments. And now these Republicans are even trying to stop FISA from being extended while the Congress debates what the renewed version contains.
So Bush and his Republicans say that telco amnesty, retroactive immunity, is worth going without FISA at all. Even though they say it's our most important defense. So telco immunity, even though telcos would be immune under current law if they can show evidence that Bush assured them they were immune, is more important than our security.
If you're a Republican, it is.
--
make install -not war
I write sci-fi for metalheads
You can mod me as a troll or flame bait or what ever you like. The fact of the matter is that we're on the slippery slope toward becoming a police state. Stay with me...
First the Patriot Act - no more do you have show probable cause and get a search warrant. The enforcement branch is now unfettered by little things like the Bill of Rights.
Second the Emergency Powers Act - this allows martial law to be declared and turns the President into a military dictator if there's "catastrophic emergency" but utterly and complete fails to define what qualifies as a "catastrophic emergency"
Third is this - Now they have the unlimited ability to spy on the average citizen.
Am I seriously the only one who sees a pattern in all of this? Shall I start citing historical examples? Wake up people!!!
2 cents,
QueenB
HDGary secures my bank
Why should I listen to such a bunch of no-names? I'm waiting to see what John Dvorak says.
"It doesn't cost enough, and it makes too much sense."
The real problem is that people don't give a crap about the constitution.
More recent information about U.S. government debt:
U.S. Government Debt Graph (2007 Budget data) (Good for a quick view.)
U.S. Government Debt Clock
U.S. Government Debt
The law that established FISA isn't going to expire; only the Protect America Act. What's the difference? It's the Protect America Act that allows the wiretapping without warrants of people "reasonably believed to be outside the United States." What happens if it expires? Theoretically, they'll again need to get warrants for when they want to wiretap people, which they can do up to 72 hours after they've done initiated the wiretap. But it's not like the whole system is going to shut down. FISA has been on the books since 1978 and isn't going anywhere.
On around page 28 of the PDF, it talks about domestic traffic (where both participants are inside the US) that may cross the border, due to network routing that goes through Canada, Skype relay nodes, etc. If you intercept all traffic that crosses the border, you may end up intercepting US-citizen-to-US-citizen communications.
But wouldn't Big Brother counter that the mere fact that the traffic crosses the border, makes it fall under their 'legitimate' border-protecting authority anyway, regardless of the apparent endpoints? So what if it's "virtually" domestic traffic -- physically it's not, and that alone possibly makes it fall under their authority. And we have a (regrettable) historic precedent that even US citizens lose some rights when they interact with the border (e.g. You can be searched for drugs w/out a warrant, whenever you enter the country).
Also, keep in mind that of you're communicating through a proxy, then that's an opportunity to set up a covert channel to a third party. For example: I talk to grandma through a foreign proxy. My conversion seems to be "Hello grandma, I got the cookies you sent me last week." A steganographic bit is seen by the proxy, and I just transmitted "0" (meaning: "sorry, I will not have collected the resources in time for next week's attack") to my mission control in Afghanistan. (Not that the NSA, even if it had legal authority to tap my call to grandma, would be able to detect whether I'm doing that or not...)
I'm strongly opposed to warrantless domestic eavesdropping, but I think the argument that sometimes domestic traffic leaves the country, is not a valid argument against spying on border-crossing traffic. A lot of other good points in the PDF, though.
As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
Well, I'm not sure which proposal has been dubbed the "Protect America" act, but I'll bet that it has, in all likelihood, nothing to do with protecting America. Who names these things? Karl Rove? Why are Republicans so much better at the art of framing the debate than the Dems are? It's the "Clear Skies Initiative", the "Death Tax", the "Patriot Act" LOL. Dems need to start renaming these bills to reflect what effects they really have.
It is a stretch to say that the scenarios of abuse of power are "fantastic". The administration repeatedly stated publicly that no one's rights were in danger, that the surveillance they were undertaking required a warrant. This was the whole point of the FISA law, to allow the government to perform surveillance on those who might want to harm us while preventing any potential abuses of the ability to monitor communications.
Then the administration was caught doing an end-run around the FISA law by doing "wiretaps" without bothering to obtain a FISA order (similar to a warrant) even though FISA allows the order to be obtained after the fact and the FISC (FISA court) created by the law virtually never denied a request for an order.
A major issue many people have with the law currently before the Senate is the retroactive immunity for the telecom companies, especially in light of allegations that the NSA was monitoring communications without obtaining the required FISA orders seven months *before* the 9/11 attack. If the telecom companies were not doing anything illegal, why is the immunity necessary?
Never let reality temper imagination
Never let reality temper imagination
Actually, the wiretap act was not passed until 1968. The stuff AT&T did in Bamford's book was LEGAL at the time.
In order to change the way things are going, running for office can certainly help. You'll be bringing awareness to fresh concerns and issues just by voicing your platform, even if you have worse odds than a snowball in hell.
I am doing just that. My name is Richard Matthews and I am a Network and Security Engineer by trade and I am running for Congress Maryland's Second Congressional District.
I am a Republican standing for small government, civil liberties and following the US Constitution. My Democratic opponent Dutch Ruppersberger has voted for the reauthorization of the Patriot Act and many Iraq War spending bills. I will be monitoring closely his vote for this act and will comment accordingly at my website.
http://www.richardmatthews.org/
Although privacy is important, this is not a question about privacy, but about accountability. The sad truth is that even if they have to ask a judge about it, they will still get all the warrants they want - remember, this is about National Security (TM). But when you get a warant from a judge, a record is made of the event, by an authority that is independent (at least in principle), unless I am much mistaken, which means that in principle it will be possible to review the events later and possibly prosecute things like abuse of power etc.
If there are no independent records, what is there to stop agents from spying on their neighbors? Only the personal integrity of the individual agent, and while most may be decent people, some aren't. And much worse than that, it will be a lot easier for powerful interest groups to infiltrate and abuse the system - do we want, say, Scientology to have agents in a position where they can tap our private communications? They aren't exactly know for their respect for their fellow humans, and there are many other groups exactly like them.
You Americans.
A few intelligent people will tell you in no uncertain terms that you MUST NOT LET THIS ACT PASS. They will explain that it'll smash your privicy into tiny peices, they'll say its up to YOU to speak to your representitive to get it thrown out. And you know what? You'll all do fuck all.
Then four months down the line thousands and thousands of you will be back here, whinging about "yet another affront to our privicy" through a act they "sneaked through".
You vote a Paranoid Texan Oil Baron into office, TWICE, so what the hell do you expect? The man's a joke the world over, so if I was you I'd try and stop him passing any laws (that will be very hard to revoke when you finally get a President with two braincells to rub together).
Yet all you seem to do is COMPLAIN. Fucking do something about it.
Oh yeah, and to the torrent of "Bush cheated his way in! Recounts were fixed" comments coming up, I say "What? Twice motherfucker? And if the country is REALLY that against him, why did it all come down to Florida."
Your president is terrible, the American public are worse.
You feel sleepy. Close your eyes. The opinions stated above are yours. You cannot imagine why you ever felt otherwise.
Australia still having a good government for the most part that apparently sincerely tries to do its citizens' bidding (as the continuing success of Prime Minister Howard instructs us), whereas American representative democracy has been replaced by a kleptocratic oligarchy - just like the old Taster's Choice commercials, only with far greater impact.
Part of the problem in the States is that our form of government became fatally flawed the day corporations attained legal personhood since a) there's so little flexibility in the system and b) the people who benefit most from the status quo get to write the rules that keep them there. A Westminster system, on the other hand, has to be more responsive - your PM is still an MP representing real constituents, and the formalization of the "shadow" Government helps keep everybody honest while still providing leadership opportunities and publicity for the parties presently out of power. We Americans have been much too smug about the 'superiority' of our form of government for the last 50 years or so, even as it has been steadily, visibly and openly removed from our influence.
How about renaming it to the "TBBA: The Big Brother Act"
or "TONFTAF: Things Old Nixon Forgot To Ask For".
Every time you pick up your phone:
"Thank you for using BellSouth.
Your calls may be monitored for National Security Purposes."
Don't worry, everything will be all right once it's under government control.
Just like education, foreign policy and health care, the government knows what's best for you!
In Republican America, the government tells the people who to vote for!
"I was in love with a beautiful blonde once, dear. She drove me to drink. It's the one thing I am indebted to her for."