How To Foil NSA Sabotage: Use a Dead Man's Switch
mspohr writes "Cory Doctorow has an interesting idea published in today's Guardian on how to approach the problem of NSA 'gag orders' which prevent web sites, etc. from telling anyone that they have been compromised. His idea is to set up a 'dead man' switch where a site would publish a statement that 'We have not been contacted by the government' ... until, of course, they were contacted and compromised. The statement would then disappear since it would no longer be true. He points out a few problems... Not making the statement could be considered a violation of disclosure... but, can the government force you to lie and state that you haven't been contacted when you actually have?"
Rsync.net has been doing this for years; rather than the statement disappearing in case of an NSL being issued, it simply would stop updating. Indeed, their canary text also points out the same possible flaws: "This scheme is not infallible. Although signing the declaration makes it impossible for a third party to produce arbitrary declarations, it does not prevent them from using force to coerce rsync.net to produce false declarations. The news clip in the signed message serves to demonstrate that that update could not have been created prior to that date. It shows that a series of these updates were not created in advance and posted on this page."
As we should have learned, the government by large does not care if they "can" (in a legally sense), they just do it. But if necessary: Those rubber stamp courts will surely find a way to make it happen in a way which is legal on paper.
Don't expect a prosecutor to buy this argument. Anything you do that alerts others to a gag order will be treated as a violation. You may win in court, but you will be thousands of dollars in debt defending yourself.
Although cute, this 'idea' is irrelevant. Even if you made the case that you weren't contravening the letter of the request, you could still be charged with obstruction of justice, should your behaviour alter the conduct of the subject(s) under scrutiny. This puts the onus on you to lie.
In short, good luck with that. They're already way ahead of you. Way, way ahead.
When in the Course of human events, it becomes necessary for one people to dissolve the political bands which have connected them with another, and to assume among the powers of the earth, the separate and equal station to which the Laws of Nature and of Nature's God entitle them, a decent respect to the opinions of mankind requires that they should declare the causes which impel them to the separation.
We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness.
That to secure these rights, Governments are instituted among Men, deriving their just powers from the consent of the governed, That whenever any Form of Government becomes destructive of these ends, it is the Right of the People to alter or to abolish it, and to institute new Government, laying its foundation on such principles and organizing its powers in such form, as to them shall seem most likely to effect their Safety and Happiness. Prudence, indeed, will dictate that Governments long established should not be changed for light and transient causes; and accordingly all experience hath shewn, that mankind are more disposed to suffer, while evils are sufferable, than to right themselves by abolishing the forms to which they are accustomed. But when a long train of abuses and usurpations, pursuing invariably the same Object evinces a design to reduce them under absolute Despotism, it is their right, it is their duty, to throw off such Government, and to provide new Guards for their future security. ...
He has erected a multitude of New Offices, and sent hither swarms of Officers to harass our people and eat out their substance.
We're talking about the government doing just about anything they want, and we're wondering if they'd restrain themselves according to something as little as the "letter" of the law?
+2 Funny.
+4 Sad.
-Styopa
If you like the law, or do not disagree with it, comply.
If you don't like the law, comply.
If you don't trust your government, comply.
And if all else fails, comply.
Closing your website as a form of protest simply accomplishes the goals of the administration. If they can prevent your servicing a hundred other bad guys, they may happily choose to sacrifice chasing the one bad guy through your system. (Besides, it's not like there aren't other clues or trails out there.)
Of course, such an act is visible, noble, and it gets people talking; and you're seen as a good person for doing so. But those effects are all transient, and little more than a flap in today's breeze. The administration knows the negativity will fade over time. So over the long term, the closings provide the chilling effect the administration desires.
John
Most people cannot legally emigrate, so that isn't really an option. If you have dual citizenship, or unique in-demand skills, this may be more feasible, but China is not going to accept random American citizens who want to move there, especially not people who want to move there due to political disgruntlement.
10 PRINT CHR$(205.5+RND(1)); : GOTO 10
The rsync canary is a good idea, another standard approach for delicate communications are job advertisements.
In this case:
A large ad in a suitable newspaper that you are searching for a lawyer.
There are different ways you might be contacted by the government.
For example, maybe somebody who uses your website stole something. Suppose for example the FBI suspects that person of having sold it to someone else who uses your website and is looking for evidence of the same. So they get a warrant and go throught is one person's email, don't find the evidence they were looking for leave.
In another example, maybe one person who uses your website had his car washed by a guy who got an email from a dude who was seen in a cafe with a suspected terrorist. They issue a National Security Letter that threatens you with horrible consequences if you divulge anything, seize a copy of every record on your site going back to 2005, discover another 50 people who got messages from the guy whose car was washed and by the associative property of terrorism, they're terrorists, you're a terrorist and everybody who uses your site is a terrorist.
See the difference? It's not about being contacted by the government. It's about being swept up in a potentially vast and unwarranted (literally) investigation when you didn't do anything wrong.
If you read TFA, the method suggested by Corey is actually a dead man's switch: when the user fails to respond with a signed version of a random number generated by a website on time, the website notifies all subscribers of the event.
I'm curious, as that I've not played around with them in years, but are the nym servers , and the mixmaster and other anonymous remailers out there still functioning and useful?
Light travels faster than sound. This is why some people appear bright until you hear them speak.........
Yes, but say there are only 30,000 people in the entire country who AREN'T being tracked, then "we don't search and store data on 10's of 1,000's of Americans" is true.
The converse statement is, "We DO search and store data on 329,970,000 Americans"...
I bet the employee orientation at the NSA and CIA includes the admonition "Yes, you're going to lie to Congress, The President, and the American people. You're going to do it every fucking day, and LIKE it. And if you DON'T like it, either head to Russia or we'll arrange a cell for you right next to Bradley Manning."
The cow says "Moo." The dog says "Woof." The Timothy says "Thanks, valued customer. We appreciate your input."
...aaaand, here's some code to use to make your own (which I just posted about only yesterday
At what point does a gag-order come into force? Just send a tweet "A government official has just entered the building with an envelope I haven't opened yet. Updates to follow...", followed by no updates.
Wouldn't it be better to always have a message saying that you are collaborating with the NSA / currently being gaged. If that siuation does ever occur, you then remove the message because otherwise you will be breaking the law...
The librarian Jessamyn West has had a similar idea for years.
We all need to ostracize and refuse to have anything to do with any of these people. Looking to hire a subcontractor, and one of the firms in the running has connections to these people? Knock them out of the running and let them and their competitors know why. If we tag and track all of them and make them effectively persona non grata everywhere, and those who do their bidding likewise persona non grata, then we would begin to see change.
Society in general must excise these people or risk imploding catastrophically.
Do what you can, with what you have, where you are.