Showing posts with label Prism. Show all posts
Showing posts with label Prism. Show all posts

Tuesday, 24 September 2013

Mark Zuckerberg and Marissa Mayer field questions about Prism

The CEOs of Yahoo and Facebook were each on the hot seat Wednesday answering questions about the U.S. government’s data surveillance programs.

Yahoo CEO Marissa Mayer, in an on-stage interview at the TechCrunch Disrupt conference in San Francisco, said she couldn’t say more about the programs than Yahoo already has because doing so could be “treason.”

“We can’t talk about these things because they’re classified,” she said.

Marissa Mayer (4)Martyn WilliamsMelissa Mayer, Yahoo CEO

Pressed by TechCrunch founder Michael Arrington about what would happen if she revealed details about the government’s data requests, Mayer said she could go to prison.

“It makes sense for us to work within the system,” she said. For Yahoo, Mayer said, that means examining each request it receives and pushing back if it seems unreasonable.

In a separate interview, Facebook CEO Mark Zuckerberg was more outspoken. The U.S. government “blew it” by not communicating better about its surveillance efforts and made it harder for U.S. Internet firms to do business overseas, he said.

“It’s our government’s job to protect all of us, and also to protect our freedom and the economy, and I think they did a bad job of balancing those things,” Zuckerberg said.

“I think the government blew it,” he said.

The U.S. government, when asked about the surveillance programs, has said it was not spying on American citizens, Zuckerberg noted. That wasn’t helpful to Internet companies that do business overseas, he said.

“I think that was really bad.”

Both executives highlighted their efforts to push for greater transparency, and both said their goal is to protect their users. Both companies, along with Google and Microsoft, have filed lawsuits to force the government to let them disclose how many national security-related data requests they receive.

Those efforts have so far been unsuccessful. Earlier this week, the companies asked again for permission to provide more information about the data requests.

The latest round of leaks revealing U.S. government surveillance programs, including a data collection program known as Prism, were published in June by the Guardian and The Washington Post.

Since then, tech firms have come under scrutiny for the extent of their involvement with the government programs, and to what extent they have cooperated. They have all said they have cooperated only to the extent they are required to legally.


View the original article here

Tuesday, 30 July 2013

Tech firms squirm over their role in Prism surveillance

The disclosures about the National Security Agency's massive global surveillance by Edward Snowden, the former information-technology contractor who's now wanted by the U.S. government for treason, is hitting the U.S. high-tech industry hard as it tries to explain its involvement in the NSA data-collection program.

Last week, a gaggle of 22 large U.S. high-tech firms—including Apple, Facebook, Google, Microsoft, and Yahoo which have acknowledged they participate in NSA data-gathering efforts in some form, if not exactly as Snowden and some press reports have described it—begged to be freed from the secrecy about it in their pleading, public letter to President Obama, NSA director Keith Alexander, and a dozen members of Congress.

nsa

The July 18 A letter from America's high-tech powerhouses, which was also signed by almost three dozen nonprofit and trade organizations as well as six venture-capital firms, begged for "greater transparency around national security-related requests by the US government to Internet, telephone, and web-based service providers" in terms of how much information the government demands on high-tech customers and subscriber accounts and how.

The letter begged for the U.S. government to make the amount of requests the government makes related to national security for individual customer information public.

"This information about how and how often the government is using these legal authorities is important to the American people, who are entitled to have an informed public debate about the appropriateness of those authorities and their use, and to international users of US-based service providers who are concerned about the privacy and security of their communications.," the letter to President Obama, Congress, the NSA director and Director of National Intelligence, stated yesterday.

The revelations last month from Snowden about NSA's extensive involvement in U.S. high-tech firms for purposes of information collection has suddenly put the U.S. high-tech industry on the defensive as they struggle to offer an explanation about all this to their global users while still bound by secrecy under the U.S. Patriot Act. There's no indication yet from the White House or others in government that any change in the NSA spying program, which relies on the participation of U.S.-based firms, will change.

"This should be debated in a public setting," said John Dickson, principal at security firm Denim Group and a former U.S. Air Force officer, about the situation in which NSA's global surveillance is tied so clearly to U.S.-based companies. He noted the U.S. government has actually said little but the media much.

spyware privacy

This is all putting tremendous pressure on the U.S. high-tech industry, especially abroad in Europe where privacy questions may be making U.S. industry seem less competitive. This week Brad Smith, Microsoft general counsel and executive vice president, legal and corporate affairs at Microsoft, A issued a public statement that sought to clarify Microsoft's participation in the U.S. government's content gathering methods.

""Recent leaked documents have focused on the addition of HTTPS encryption to Outlook.com instant messaging, which is designed to make this content more secure as it travels across the Internet," Microsoft counsel Smith wrote. "To be clear, we do not provide any government with the ability to break the encryption, nor do we provide the government with the encryption keys. When we are legally obligated to comply with demands, we pull the specified content from our servers where it sits in an unencrypted state, and then we provide it to the government agency."

Microsoft's SkyDrive and Skype A is handled somewhat similarly in terms of government requests, Smith said. As far as enterprise and document storage for business customers, "we take steps to redirect the government to the customer directly, and we notify the customer unless we are legally prohibited from doing so," Smith stated in his July 16 post. "We have never provided any government with customer data from any of our business or government customers for national security purposes."

Smith added Microsoft got four requests related to law enforcement in 2012. "We do not provide any government with the ability to break the encryption used between our business customers and their data in the cloud, nor do we provide the government with the encryption keys."

In the meantime, it's safe to assume in this NSA leaks debacle that "the bad guys have switched tactics" and probably wouldn't use U.S.-based high-tech services, Dickson points out. And in this atmosphere of rising cyber-nationalism, the possible role of China's government and its own high-tech industry have to be asked, too, he noted.

Former head of the U.S. Central Intelligence Agency and the NSA, Gen. Michael Hayden, recently charged forward on that topic in an interview with The Australian Financial Review.

Hayden said he believes that China-based network vendor Huawei conducted clandestine activities and shared with the Chinese state "intimate and sensitive knowledge of the foreign telecommunications systems it is involved with." According to the published report, Gen. Hayden said the Huawei is a significant security threat to Australia and the U.S., has spied for the Chinese government, and intelligence agencies have evidence of this.

A Huawei spokesman, John Suffolk, Huawei's global cyber security officer, is quoted by the Australian publication yesterday as calling Hayden's remarks "unsubstantiated and defamatory" and that any critics of the company should present any evidence publicly.In an opinion piece on CNN.com today, Gen. Hayden railed openly against Edward Snowden as a national security threat, saying he "fled to China with several computers' worth of data from NSANET, one of the most highly classified and sensitive networks in American intelligence."

Hayden acknowledged that one aspect of the fallout from Snowden's leaks is that "the undeniable economic punishment that will be inflicted on American businesses for simply complying with American law."

Hayden's remarks on CNN also seem to sarcastically criticize the Europeans now complaining about the NSA activities and how they may violate European data-privacy laws. "Others, most notably in Europe, will rend their garments in faux shock and outrage that these firms have done this, all the while ignoring that these very same companies, along with their European counterparts, behave the same way when confronted with the lawful demands of the European states."

Hayden continued: "The real purpose of those complaints is competitive economic advantage, putting added burdens on or even disqualifying American firms competing in Europe for the big data and cloud services that are at the cutting edge of the global IT industry."

As if all this weren't enough, former President Jimmy Carter also spoke out yesterday on NSA global surveillance, suggesting the NSA data collection practices were harming democracy. Former president Carter also said Edward Snowden's revelations didn't really harm national security and and was actually "beneficial" because "they inform the public."

Ellen Messmer is a senior editor at Network World. She covers news and technology trends related to information security.
More by Ellen Messmer


View the original article here

Yale grad's 'Prism' program turns text metadata into wavy art

What if the NSA took your text message metadata and made a flowing, colorful diagram with a timeline?

The U.S. spy agency -- probably -- doesn't do that. But a 22-year-old Yale graduate, Bay Gross, was actually inspired by the U.S. government's Prism surveillance program revealed by whistle-blower Edward Snowden.

Gross, who just started working at Google in New York on Monday, created an application he describes as "part data, part art" that analyzes a person's own SMS messages and lays them out in a rainbow wave. Appropriately, he named it "Prism."

Prism, which works on Mac OS, draws the SMS metadata from the user's own unencrypted backups within iTunes. It pulls who was texted and when and plots the data in a "Streamgraph," a type of stacked graph developed by Lee Byron, who is an interactive information designer with Facebook.

Byron, who was a graphics intern with the New York Times in 2008, developed a Streamgraph for the newspaper that displayed box office revenues for films. The graphic drew praise and criticism due to its unorthodox approach.

Streamgraphs emphasize the "legibility of individual layers, arranging the layers in a distinctively organic form," according to an academic paper authored by Byron and Martin Wattenberg.

Gross says from an analytical view the Streamgraph is "kind of useless." The y-axis, for example, which appears to represent volume of texts to a recipient, is "completely made up."

But Prism does enable a more emotive or romantic view of data. The x-axis, which represents time, can show the degree to which some relationships are zero sum or even seasonal, Gross said. You can see, for example, how some texting relationships start fast and furious but atrophy to a meager small stream.

The application doesn't show the content of the messages. Gross has also put in a feature where the graphs created by Prism can be exported but minus people's names. The graph can be manipulated using a variety of parameters, such as by date, popularity and frequency of contact.

Prism is a desktop application for Mac. Apple lets people encrypt their iPhone backups on a computer, but Prism needs access to an unencrypted backup. All of the processing is done on a person's computer, and nothing is sent to a remote server, Gross said.

Apple rejected Prism from inclusion in its App Store, but Gross said that's due to the company's strict guidelines for its store. However, Prism is a certified developer application.

Prism is free as part of its launch, but will eventually cost US$0.99.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


View the original article here