Slashdot Mirror


Surveillance Story Turns Into a Warning About Employer Monitoring

rtfa-troll writes "The story from yesterday about the Feds monitoring Google searches has turned into a warning about how work place surveillance could harm you. It turns out that Michele Catalano's husband's boss tipped off the police after finding 'suspicious' searches (including 'pressure cooker bombs') in his old work computer's search history. Luckily for the Catalanos, who even allowed a search of their house when they probably didn't have to, it seems the policemen and FBI agents were professional and friendly. Far from being imperiled by a SWAT raid, Catalano spoke to some men in black cars who were polite and even mentioned to Catalano that 99 times out of 100, these tip-offs come to nothing. Perhaps the lesson is to be a bit more careful about your privacy, so that what you do on the internet remains between you and the professionals at the NSA."

21 of 382 comments (clear)

  1. Alright then. Carry On. by ObsessiveMathsFreak · · Score: 5, Insightful

    Oh I see. The man searched thinks it was all just a misunderstanding. I guess that makes it OK then.

    I guess it also covers the costs in time, money, equipment and paperwork spent on a search that should never have happened. I guess it also makes up for any useful work the men involved could have been engaged in like looking for actual terrorists or investigating organised crime in the banks. I would worry about how the NSA's Ur-dragnet/Informer hotline is throwing up so many false flags that law enforcement is now too busy to deal with actual problem, but this splendidly chipper blog post had allayed all of my concerns.

    I'm glad that's all cleared up then.

    --
    May the Maths Be with you!
    1. Re:Alright then. Carry On. by Somebody+Is+Using+My · · Score: 5, Insightful

      Even scarier is the acceptance of NSA monitoring as evidenced by the last line:

      Perhaps the lesson is to be a bit more careful about your privacy, so that what you do on the internet remains between you and the professionals at the NSA."

      It's not just /known/ that the NSA is monitoring everyone's conversation, it is seen as a good thing. Of course these "professionals" are listening. It's for the good of the country that the every citizen is monitored, after all.

      The bar is being set ever lower and comments like these train people to see it as perfectly alright. Increasingly I am of the opinion that this is not accidental.

    2. Re:Alright then. Carry On. by TheCarp · · Score: 4, Insightful

      > Well, I don't know about you, but if the police show up, act in a courteous and polite fashion, ask a
      > few questions, and then leave satisfied nothing bad is going on, I consider that a job well done.
      > They're out in the community, flying the flag, and helping people feel safe.

      You should try living next door to my old neighbour. The problem here is the assumption that people who report things are reasonable and sane people.

      The fact is, they should investigate if there is a reason to investigate and it should be more than perfectly normal behaviour (ie shopping and reading material related to recent news articles) to be suspected of anything.

      The bigger problem, I think, is this notion that a terrorist attack happening is a failure of the police and intelligence services. In the end, its such a needle in a haystack sort of problem that its entirely unreasonable to think they can ever be prevented, therefore any acceptance of that reasoning that starts with they should be able to catch it, inevitably leads to excessive measures, and guarantees more excessive measures later WHEN the next one happens.

      --
      "I opened my eyes, and everything went dark again"
    3. Re:Alright then. Carry On. by 0111+1110 · · Score: 4, Insightful

      This comment really surprises me coming from you. Usually you seem to be on the side of good, and of liberty and privacy and presumption of innocence. You seem to be looking at things from the POV of society. I look at things from the POV of the individual, of the innocent victim of such searches. Of course in this particular case the victim was complicit in the violation of their own rights. So I have little sympathy for them.

      But in a case where a search warrant is granted when it should not have been because the probably cause was pretty slight I think the victims should be compensated for the mistake. A google search should never, ever, ever be probable cause for a search of someone's home or car. The lack of permission in the constitution itself, as well as the first and fourth amendments should be protecting us from overly suspicious people invading our privacy because of something we said or wrote. An important part of the freedom of speech is that what we say, especially in an environment with at least some expectation of privacy, should not result in persecution by our government. The NSA could easily set up a system to send FBI agents with a signed search warrant, to the home of everyone who searched google for something like, "how to build a nuclear weapon". That is not the kind of society I want to live in.

      The fact that it was a work associate who contacted the FBI instead of the NSA does not improve matters in my view. Such calls should simply be ignored. I have little doubt that millions of people every day search for things that other people would find suspicous. The fact that another citizen is suspicious of me does not give the government any additional rights to violate my rights. Unfortunately American society is becoming a place where we are all each other's enemies, working as government informants against each other, potentially bringing down the wrath of government agents down on us with their groundless suspicions. This case should never have happend. The FBI should never have searched anything based on a google search. That is just stupid and a huge waste of resources that would be better spent protecting citizens from real crimes. Ones with actual victims. The government agents in this case should be fired or at least demoted.

      --
      Quite an experience to live in fear, isn't it? That's what it is to be a slave.
  2. Re:Private browsing by crafty.munchkin · · Score: 5, Informative

    Not sure if you realise... but when you're on a work computer, all your internet requests usually go through some form of proxy server - which is how your IT department finds out what you access regularly and blocks it. Clearing your browser history is useless since every request is logged in a centralised server before it goes out to the net.

    --
    ... wait, what?
  3. Er, no, that isn't the story by girlintraining · · Score: 5, Insightful

    Perhaps the lesson is to be a bit more careful about your privacy, so that what you do on the internet remains between you and the professionals at the NSA.

    I know you're being snarky, Slashdot, but I'd trust the professionals at the NSA over middle management any day of the week. The NSA doesn't ruin your life if it goes through your google history and finds a few keywords. It doesn't assume the worst. The NSA gathers up the data, forwards it to a team of analysts, and, seeing this kind of thing every day, make an informed and reasoned decision to either forward it up the chain, or bin it. And as your own article says: 99 times out of 100, it's nothing. That's probably a conservative estimate; There have only been a few dozen acts of bona fide terrorism in the past year or so, and if the tin foil hat crowd is right, the NSA is monitoring everyone pervasively, so it's more like 999,999 times out of a 1,000,000.

    The moral of the story here is that people who aren't law enforcement are really, really, epic bad at being judges of character. Especially when you're dealing with someone whose job is often earned on something other than critical thinking skills, investigative talent, and attention to detail... three things I think most will agree you don't find in most mid-level managers. It's like how during the midst of the Boston bombing, the internet armchair sleuth crowd wrongly identified many innocent people and forced the police to divert valuable resources to take those people into protective custody while the real bomber was left unidentified. The professionals, meanwhile, correctly identified them hours later, and then took them down without any innocent people getting caught in the cross fire.

    I know it's politically popular right now to say law enforcement is a bunch of clueless, authoritarian, surveillance-happy asshats, but that's a slanted view. On the whole, they know what they're doing, and most of the time they get it right. You only hear about the times when they screw up. Now, considering how low of esteem they're held in for that track record, ask yourselves about the track record of middle managers, internet armchair pundits, and vigilantes have had doing the same things... and I'm betting their reputation with you is a lot better.

    Chew on that for a bit.

    --
    #fuckbeta #iamslashdot #dicemustdie
  4. Prediction by swillden · · Score: 4, Insightful

    Prediction: this article will not get 850 comments, and many people will continue pointing to this story as proof that Google lets the federal government rifle through all of everyone's data.

    --
    Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
  5. 99 out of 100 by gsslay · · Score: 5, Interesting

    99 times out of 100, these tip-offs come to nothing

    That's not quite what was said. From the original blog ; "they mentioned that they do this about 100 times a week. And that 99 of those visits turn out to be nothing."

    So we have three possibilities;

    1/ this statistic is a bullshit overstatement, talking up a minimal danger
    2/ they are arresting terrorist bombers at a rate of 1 a week
    3/ they are prosecuting 1 person a week on an unrelated matter, after gaining access to their house on the pretext of "war against terrorism".

    Which do we think it is?

    1. Re:99 out of 100 by bws111 · · Score: 4, Insightful

      None of the above. It is the equivalent of Columbo's 'oh, you know, headquarters makes me ask these questions, nothing to worry about'. It puts the person at ease, and maybe they let their guard down a bit.

  6. Re:Devices which have only one purpose by Anonymous Coward · · Score: 5, Insightful

    Some people might want to search for news stories pressure cooker bombs, or information about what they look like so they might be able to identify one if they see it on the sidewalk.

  7. This could well be search suggestions. by jaseuk · · Score: 5, Interesting

    Typing "pressure cooker" lists pressure cooker bomb as the 3rd suggestion in Google.

    Jason.

  8. Re:A different lesson by girlintraining · · Score: 4, Insightful

    I take away a different lesson from this: maybe it's a good idea to wait until you have more facts before starting to run around screaming "The sky is falling!!!!111".

    Clearly, this middle manager only watches CNN and FoxNews. And let's be honest: It's the only thing playing in most break rooms, and middle managers aren't known for their critical thinking and investigative talents.

    The fact that some real shady things in terms of corporate and governmental surveillance do go on is no reason to just give up being rational.

    Neither is it a reason to ignore the fact that the police showed up, were polite and courteous, asked a few questions, and left satisfied. Now look, I'm no more happy having the police show up at my door than anyone else -- but by and far, the experiences have been professional, as this person learned. I've had people call in all kinds of things to the police about me; I know because they keep records of that kind of thing and I know the right people to ask to get them.

    Every one of you past the age of 30 has something in their police file from a "concerned citizen." All of you. Yes, even you, Mr. Above Average Driver who pays all his bills on time and even helps his land lady carry out the garbage. But most of you don't know about it because the police conducted their search discreetly, found nothing, and moved on. Which is exactly how surveillance should work. And most of the time, that is how it works; you guys only hear about the 1 in 10,000 case where they screw it up, not the other 9,999 where nothing newsworthy happened because they did it right.

    This wouldn't be news if it wasn't for the news agencies creating a story where there really isn't one to sell more advertising. "Over-zealous middle manager of questionable technical ability reports ex-employee after searching internet history and finding a few keywords and deciding it's a matter of national security..." is not exactly interesting to me, and it wouldn't be if not for the drum beat of "NSA... NSA... NSA..." all over the news right now. Please. Former employers are like ex-boyfriends -- take everything they say with a biiiig grain of salt.

    --
    #fuckbeta #iamslashdot #dicemustdie
  9. Re:Private browsing by MtHuurne · · Score: 5, Informative

    If your work browser is configured to accept certificates from the proxy server, SSL might not give you privacy.

  10. Re:Private browsing by Anonymous Coward · · Score: 5, Insightful

    Exactly! So, shut the fuck up, slaves. Employers pay for your time, not your work. Employers OWN you for the duration of that time. You have no rights beyond that which your employer affords you. You should act like the good little worker machines that you are unless your employer gives you permission to do otherwise.

    God damn these lazy employees these days, thinking they can be human on an employer's dime.

  11. Re:How will they be compensated? by cold+fjord · · Score: 4, Informative

    The important detail missing is that the couple wasn't searching for bombs. It appears the police added the word "bombs" to cover up their amateur-hour faux pas so that an investigation sounds reasonable.

    That doesn't appear to be correct according to the fine article:

    The former employee’s computer searches took place on this employee’s workplace computer. On that computer, the employee searched the terms ‘pressure cooker bombs’ and ‘backpacks.’

    --
    much of left-wing thought is a kind of playing with fire by people who don't even know that fire is hot - George Orwell
  12. Use discretion before calling the police by davidwr · · Score: 4, Interesting

    You CAN be too careful.

    Before calling the police in a non-urgent situation, ask yourself

    "If everyone in my exact situation called the police, a few crimes may be prevented but a lot of lives would be intruded on and a lot of police resources and taxpayer money would be spent. Would it be better for society if, as a rule, the police were called in this exact situation or if, as a rule, they were not?"

    This goes not just for bombs but for thinks like someone unfamiliar walking around your neighborhood at 3AM, your kid's friend sporting frequent unexplained bruises, and the guy who who hangs round the local kiddie park without kids in tow.

    Each of these "no matter what I do, there's a good chance that I could wind up doing the wrong thing" cases and many others like it require a gut-check and a realistic assessment of the situation before calling the police. Sometimes the "best answer" is to call the cops. Sometimes the "best answer" is to talk to the person acting suspicious or get friends and neighbors together and talk to the person. Sometimes the "best answer" is to do nothing.

    Finally, if you do make a well-thought-out decision and it turns out to be wrong - if you DON'T turn in the guy who searches for pressure cookers and he turns out to be a bomber, or if you DO turn him in and as a result the police are busy interviewing the person and can't get to an armed-robber-in-progress call in time to avoid bloodshed, don't feel guilty about your decision.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
  13. Re:Private browsing by davidwr · · Score: 4, Informative

    A good proxy server is going to allow your system administrators to decrypt your SSL connection.

    Yes and no. Yes, a proxy can do MITM attacks, but no, barring a key compromise, it can't do so undetectably. A computer-savvy employee who is concerned about a MITM attack can do some testing beforehand and on an ongoing basis to assess his risk.

    Some things an employee who doesn't 0wn his own box probably cannot check for is a keyboard logger. Employees probably cannot check for other things like hidden cameras and other off-the-computer surveillance.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
  14. Re:Private browsing by Anonymous Coward · · Score: 4, Insightful

    One or two rules in the firewall and no OpenVPN for you.

    Seriously, do your private shit from your home - or at least from your phone with your own data plan - instead of wasting your and sysadmin's time playing tag with network policies.

  15. Re:Private browsing by Salgak1 · · Score: 4, Informative

    When you're using your company's computer and your company's network, there is exactly ZERO expectation of privacy. No doubt, you've signed an "acceptable use policy". . . . Read it next time. . . .

  16. Re:How will they be compensated? by hacker · · Score: 5, Insightful

    It doesn't matter if she was searching for 'pressure cooker bombs', because that is not illegal!

    She has not committed any crime, nor should she be suspected of one. In fact, she shouldn't have let them in the house, because they have no warrant, nor any valid reason to suspect her of doing anything against the law.

    Since when was curiosity or knowledge seeking a crime? Is that where we are now? Living in fear of learning more, because those who think they're holding the power, are looking at everything we do?

  17. Re:Private browsing by RoknrolZombie · · Score: 4, Informative

    He's not lying (or even fibbing, not even a little). The last 3 jobs I've had as a tech required 10+ hour days Mon/Fri, and if I wanted to do anything on the weekend that would take more than a few hours I had to notify my boss (in case they tried to reach me and I was unavailable). I'm no manager or lead or anything like that...I'm just the guy that they want to make sure is available in case a computer breaks.

    Once upon a time those jobs were restricted to the heads of the company and they were awarded accordingly. Now those jobs are everywhere unless you're literally the bottom rung on the ladder.

    The working climate in the US is dismal.