EFF Interviewed About Their Case Against AT&T 78
ntk writes "Glenn Greenwald from Salon has a long, informative interview with Cindy Cohn, the EFF attorney leading the suit against AT&T over their warrantless wiretapping of their customers. It talks about why the White House is pushing for retroactive immunity against the telco, what the suit has revealed so far, and how little Congressfolk appear to know about how Internet traffic is being monitored."
They should be suing others (Score:3, Informative)
Re:They should be suing others (Score:4, Insightful)
Re: (Score:2)
Just don't trust the middle (Score:5, Insightful)
The public needs to understand and accept the fact that neither telecos nor governments are trustworthy. Privacy is up to end users and they are free to secure their own traffic by wrapping it in real crypto. GPG, OpenSSL and OpenVPN are just a few free open-source toolkits available to provide secure ways to communicate without having to worry about the trustworthiness of the pipe between here and there.
It's just naive to wait for some politician to protect your privacy when you have the tools to insure this yourself. As a matter of practice, stick your letters in an envelope instead of waiting for the postmaster general to outlaw literacy of postal employees.
Re: (Score:3, Informative)
The mentioning of OpenSSL also implies that HTTP should go over TLS whenever possible, as long as you trust the website for properly handling your data. That means websites should provide an HTTPS version. There is a problem, though. Many websites on the web are name-based virtual hosts. SSL doesn't work on them because you have to exchange the certificate, which is site specific, before sending the Host header th
Re:Just don't trust the middle (Score:5, Insightful)
As long as those tools are legal. The US already has ridiculous export restrictions on crypto (as though people in other countries aren't capable of writing this stuff on their own!) and IIRC, the UK government has argued for a central, government-run crypto key database, such that it would be illegal to encrypt anything in a way that law enforcement can't immediately crack. What's naive is thinking that just because the tools exist, you'll always be able to use them without getting your door kicked down in the middle of the night, a flashlight shined in your face as you're hauled out bed and cuffed, and a booming voice asking, "Citizen, what are you trying to hide?"
Short of armed revolution, which is not something that any sane person should want to become necessary, our best defense against government intrusion is to get politicians on board. Laws protecting citizens from abuses of power can and do work; for most of its existence, the Bill of Rights has been a sterling example. On those occasions when the government chooses to disregard these laws, it is the responsibility of We The People to put it back in its place -- and it is far preferable to do that with ballots than with bullets.
Re: (Score:3, Insightful)
Most people wouldn't consider Thomas Jefferson to be insane, and yet he would consider us long overdue for a rebellion. I think the problem may have gone too far, the rot set in too deep, for political/legal measures alone to have much effect. I know some people that left the FBI because of what they saw happening there, because of the kind of people that are working there now. It's not good, and if the
Re:Just don't trust the middle (Score:5, Insightful)
Americans often don't realize how profoundly lucky we were, I think. Ours could very easily have been one in the long, depressing series of wars of colonial liberation in which the colonists Throw Off The Hated Chains Of Oppression only to descend into dictatorship. We were lucky that Washington didn't want a crown, lucky that it was Washington rather than Arnold who ended up as the hero of the day, deeply lucky that the authoritarians among the Founders generally didn't get their way. A million things could have gone wrong; we threaded the needle and -- just barely -- got it right. Meanwhile, South America and Africa have provided many tragic examples of how difficult this is.
Also, our "Revolution" was a war of colonial liberation, not a revolution in the ordinary sense; as bad as colonial rebellions often are, internal revolutions, attempts to replace a government in place by armed force, are generally worse. To tell the truth, I'm not sure I can think of a single example that's really worked out well -- and the ascending scale of horror represented by the English Civil War, the French Revolution, and the Russian Revolution show how easily they can work out badly.
Sometimes revolution is the best of several bad choices, yes. But that's the best it can ever be. People who talk about it casually have no idea what they're playing with.
Re:Just don't trust the middle (Score:4, Insightful)
What concerns me is the common attitude that "This is America, such things just can't happen here!" We're not bulletproof, our economy isn't powered by magic. Right now most of us have far too much to lose to even consider armed overthrow of the United States Federal Government. I know I do: the political and economic collapse of my country wouldn't do me personally any good. But, what happens when a significant number of us don't have anything left to lose? There's plenty of historical examples of what happens when an economy fails to provide for its people.
Re: (Score:2)
Re: (Score:2)
Re: (Score:3, Informative)
True. However, in some cases government replacement can be accomplished through force of social pressure without recourse to armed conflict. You should look up the ouster of Slobodan Milosevic. Most of the USA forgot about the
Re: (Score:2)
Succesful revolutions (Score:2)
Also Lucky That.... (Score:2)
Re: (Score:2)
Re:Just don't trust the middle (Score:5, Insightful)
I might add that if anyone had an interest in cracking popular encryption schemes right now, it would be the government that is trying to read every packet you touch. Things like this are never certain but I wouldn't trust my life to encryption anymore regardless of keysize or cipher length.
Re: (Score:2)
the most secure communication possible, as long
as you take normal precautions.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Voip and instant messaging programs probably could build in pgp or something similar so that whats transmitted isn't plain text or voice but I've yet to see anything like that, why is that?
A public / private key system should be easy to implement even over a standard messaging service like AIM or MSN or any of the others.
It would make sense to routinely encrypt i
Re: (Score:3, Insightful)
Privacy is up to end users and they are free to secure their own traffic by wrapping it in real crypto.
Sadly, Either the crypto has to be built into the product, in which case the gov will either outlaw it or demand back doors, or you are faced with the same situation that secure email has always been in i.e. for every person willing to encrypt there are a thousand who don't understand it, don't care, or just too lazy.
Re:Just don't trust the middle (Score:5, Insightful)
If Americans would just stop basing their vote on the rantings of Right-Wing radio idiots and start exercising their ability to influence the people we elect, we might actually be able to have a little trust in the government, in ourselves.
The authoritarian plutocrats have been spending billions to create this nonsense that government is the root of all evil, and if we'd just put all the power in the hands of corporate managers, life in America would be utopia. It's actually become conventional wisdom now that the private sector can do everything better than the public. The problem is, our experience with insurance companies, communication companies, energy companies, the very biggest of the big corporations, is uniformly horrible. But now we're supposed to happily turn over health care to those same insurance companies, media to those same communication companies (think of your cable provider) and the fuel of our lives over to Exxon.
I don't know about you all, but the last time I went to the DMV here in Chicago to renew my driver's license, it was a quick, inexpensive and efficient process. I was in and out in less than 15 minutes. I went to the DMV because the Secretary of State of Illinois sent me a timely letter telling me that my license was about to expire, and giving me instructions as to what I should bring and where I should go.
How was your last interaction with your insurance company?
I'm thoroughly sick of hearing people stridently assert that government can't do anything right. If any part of that is true, maybe it's because a certain segment of our ruling class and their corporate masters have been working and spending hard to destroy that very government, hoping that we'll happily open our wallets and our lives to them so they can do it right.
Maybe we ought to think about saving our government as created by our founding fathers with our Constitution before we decide to turn over control of our lives to the corporate sector, who, when it comes down to it, cares a lot more about their quarterly profits than about our welfare.
Re:Just don't trust the middle (Score:5, Insightful)
It's certainly not the monster of red tapes and conspiracies it's become. Distrusting this particular form of government so that the government our founding fathers intended (and the one we deserve) can again flourish is the most patriotic thing any American can do.
Re: (Score:2)
The government our founding fathers intended is supposed to be of, by and for the people. The government our founding fathers intended was supposed to always get warrants before performing any searches of citizens or property. The government our founders intended had three co-equal branches of government. Oh yeah, the government our founders intended gave no rights to A
Re: (Score:2)
I'm with you. It's time for us to show a little resistance to what our government has become. But remember one thing, when the founders said government was "supposed to stay out of our way", they were referring to individuals. Corporations have stretched the definition of "individual" to include them, and the definition of "speech" to include "money". Especially today, when multi-national corporations are increasingly not us, w
Re: (Score:2)
It also had no concern for civil rights, women and blacks voting, workplace safety, food and drug safety, building codes, emergency services, primary education, universities, or environmental protections. Its main provisions were contract enforcement, crime punishment, and military action.
Governments like the original Constitution still exist today, but you probably wouldn'
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
Yeah, you'd break a few popular apps at first, but it's entirely possible to do l7-filtering and only allow SSL connections by certain keys, so you could still allow the big names in https (banks, webmail, etc) while blocking self signed certs and others.
Re: (Score:2)
And neither — to judge from the article — is the EFF... And here is why.
Cindy Cohn talks
RIAA vs. Government (Score:4, Insightful)
Nope - in both cases it's wrong (Score:5, Insightful)
Change that and you change justice. Full stop.
Sadly, (Score:3, Insightful)
What Bush & Co have been doing is legal, at least according to the letter of the Constitution. The Constitution allows the President to suspend civil liberties (even habeas corpus) in cases of warfare, or for national defense. And the interesting thing is that the determination of national defense purposes lies with the executive branch.
If you have a problem with this, then you have a problem with the Constitution. Maybe the Constitution needs to be changed to support civil liberties even in time
Re:Sadly, (Score:4, Informative)
Can you provide a citation on that? Article I, Section 9 states "The privilege of the Writ of Habeas Corpus shall not be suspended, unless when in Cases of Rebellion or Invasion the public Safety may require it." -- but that is in Article I, which lays out the powers and limitations of Congress, not the President. Article II describes the role of the President, and I honestly can't see anything there that backs up your claim. (Not to mention that the US is neither in a state of rebellion nor being invaded at the moment.)
Re:Sadly, (Score:4, Insightful)
* The 2000 and 2004 elections both elected the Democratic candidates, and were overturned by electoral fraud favoring Republicans. If you want to imply that we get the government we deserve, then you only have the rather weak form of the argument that says we elected a government prior to those elections that didn't care to pursue and remedy electoral fraud.
Don't get me wrong; there is a frighteningly significant number of Americans who still support "mister 26%". Indeed, the only reason that electoral fraud is a viable tactic is that the country was so evenly split in previous elections. But what if the election were held today, after almost 3 years of a unitary executive who is almost completely unaccountable to the People or it's Congress? If the People were voting for anything, it was what was apparent to them from the first four years of the Bush presidency, before Gonzales' USA firings, before the exposure of warrantless wiretaps, before the Plame outing, before the "surge", before Katrina, before the Military Commissions Act, and before the SCHIP veto. I could go on, obviously.
Just because our previous elections have been contentious doe not mean that the system is not broken, or that it has not been compromised by corrupt interests. The Rovean Culture War is not a sign of a healthy democratic republic.
Re:Sadly, (Score:4, Insightful)
Even though Congress hasn't officially declared war, the mantra in Washington is that we are at war. With a noun. And this stretched definition of war ("We are constantly under threat of invasion by terrorists!") is sufficient to convince the Supreme Court, the Congress, and the Executive branch that the suspension of liberties is not illegal, per se. Yes, it is probably against the spirit of the Constitution, but that's hard to prove. Even so, you'll have people who would argue that if the founding fathers could have forseen Islamic terrorism, they would have included it in the Constitution as well.
The interesting thing, though, is that Clinton was impeached for lying about having "sex" with an intern, while GW has misinformed the Congress and the whole United States about WMD, and Congress does nothing.
So, IOW, we've elected a bunch of spineless Senators. While you might be able to claim election fraud wrt to Presidential elections, it would be a quite a stretch to claim the same for the Senate, especially considering the majority party is the Democrat Party.
So where is the voter outrage? Why hasn't GW been called on the carpet in the same way as Clinton? Do you really expect us to believe that the Democrats are part of the conspiracy as well?
It just might be that America is getting the government they deserve. The system of checks and balances is either completely broken, or our current situation is the result of indifference, or perhaps even support for, the "illegal" spying program. (As IANAL, I don't know if the program is legal or not, but I do know that I certainly don't like it.)
And it should be taken for granted that corrupt and partial interests are trying to control government. But we as the voters have the responsibility to root out corruption. Sadly, it appears that all too many Americans are content to endorse the Bush interpretation of the Constitution. Even the Democrats.
Re: (Score:2)
My personal opinion is that an Association/Company should not be permitted to donate money which is merel
Re: (Score:2)
Worse, we've elected a bunch of senators who expect their party to gain all the powers Bush has usurped.
I'm actually leaning just a trifle towards Democrat of late because there have been at least some real efforts to reign in the abuses, and we have a few true statesmen (of either gender) up there, but it looks like the party as a whole has decided to keep everything Bush is about to leave them.
What the fuck? (Score:2)
Excuse me? Last I recalled the only opposition to Bush in the last election conceded. He wasn't elected, he WON BY DEFAULT. I don't call that an election, I call that handing the keys over to a drunk driver.
Re: (Score:2)
Then why doesn't he have the testicles to come out and *say*
that, rather trying to slip something over.
And that suspension is supposed to be temporary, for the
duration of the emergency.
Re: (Score:2)
Re: (Score:3, Insightful)
What Bush & Co have been doing is legal, at least according to the letter of the Constitution. The Constitution allows the President to suspend civil liberties (even habeas corpus) in cases of warfare, or for national defense. And the interesting thing is that the determination of national defense purposes lies with the executive branch.
Uhh, no. You're wrong. Read up on Ex Parte Merryman, which specifically says that the president "cannot suspend the privilege of the writ of habeas corpus, nor authorize a military officer to do it."
If you have a problem with this, then you have a problem with the Constitution. Maybe the Constitution needs to be changed to support civil liberties even in times of war; maybe the American people believe terrorism warrants this erosion of civil liberties. Regardless, in a democracy, people get the government they ultimately deserve - you, and every other voter, chooses the President and members of Congress. If you feel your liberties are being unfairly compromised, rather than blaming Bush & Co (or Congress, who despite having a Democratic majority, continues to support the President), blame your fellow Americans. They elected Bush not once, but twice. If their civil liberties have been eroded, they have no one to blame but themselves.
The point of a constitutional government is that no matter how stupid the majority is, they still can't trample on the essential rights of the minority. And as far as electing Bush twice, many would disagree that that's the case (though at this point it's purely an academic debate).
Rather than whine about how our liberties have been eroded, we need to take the issue to the public, and present it in terms the average American can understand. And if you can't make it relevant to the average American, maybe the issue is not that important.
Considering that the admini
Re: (Score:3, Insightful)
The potential for a "Brazil" like episode is very real and I would be surprised if it hasn't already happened.
Re: (Score:2)
Yet.
Re:RIAA vs. Government (Score:4, Insightful)
I think there's a fair chance that this sort of surveillance is used against legitimate protesters too. Maybe the White House would protest that suggestion, but really, if they want me to trust them, they need to earn that trust and allow independent oversight. The other problem I have with the White House is that they seem to be very reluctant about that.
VeriSign's role as an NSA subcontractor (Score:5, Informative)
Look at how gleefully they advertise [verisign.com] exploiting their trusted thiry-party (SSL Certificate Authority) status.
I think we need to consider switching all our browsers to a more trustworthy CA.
Re: (Score:2)
I did some work at netsol almost a decade ago (writing diagnostics for the registry/regiatrar protocol). Those dudes are seriously smart people and good at what they do.
It's easy to see why people hated netsol. It was full of very smart people very good at what they do.
Re: (Score:3, Insightful)
The irony of this situation is that we have the tools to improve privacy and trust, if only the 'geek' community would focus on the doings of Certificate Authorities as a major issue instead of constantly prattling about shiny-shiny.
Re:VeriSign's role as an NSA subcontractor (Score:4, Interesting)
DailyKos is not a technology site, and the person who posted this diary doesn't understand that all Verisign normally gets is the signing request. (I'll probably post something like this there also.) They don't have your private key, they can't decode your communications.
What they could do is intercept it and man-in-the-middle it. With Verisign's help, they can trivially make a key that works in every browser. (And buying a non-verisign key won't help...end users will just be handed a 'legit' verisign one and don't know that server has a different one.)
I urge everyone with an SSL server to post the MD5 and SHA1 fingerprints of their public key, or even their entire public key, on their site and I urge people to occasionally check them against what their browser reports. Sadly, Firefox, at least, doesn't seem to actually report the public key in any usable format, and I can't see how to get the MD5 and SHA1 fingerprints from the key using openssl. If anyone has a set of step-by-step instructions, that tell exactly what to put up and how to instruct end users to check it, that would be nice to link to.
And if you have an SSL server and a Linux shell somewhere else, and run 'openssl s_client -connect example.com:443' from both the server and that other place to make sure the 'BEGIN CERTIFICATE' part matches.
I seriously doubt the NSA is doing this, but it should be easy enough to notice if it is.
And, speaking of 'occasionally checking', it would be nice if there was some Firefox extension to inform you that the encryption key had changed, and what the old and new key were. If the old key wasn't due to expire, and the new key has the same date as the old, it probably means someone is running a man-in-the-middle attack. They'd keep the dates the same, along with all the other info, to make it harder to notice, whereas while someone could buy a new key in advance, they wouldn't get one with the same date as the old.
How safe is SSL if Verisign is complicit in taps? (Score:1)
Re:How safe is SSL if Verisign is complicit in tap (Score:2)
Re:How safe is SSL if Verisign is complicit in tap (Score:2)
You tell your browser to go to your bank's website. Your browser connects to Mystery Computer. Your browser has the little padlock icon. If you are one of those unusual people (i.e. a computer dork) who actually clicks on the padlock to check the cert, you s
Re: (Score:2)
They have a number of pages advertising "Legal Intercept" services.... under the expanded CALEA (voice and data having any kind of international route) what do you think this means? Any CA with a real privacy policy wouldn't get within a million miles of government eavesdropping activities. Sadly, the short-term windfall from eavesdropping contracts probably far outweighs any certifi
Re: (Score:2)
X.509 identities, unlike OpenPGP identities, can only have one introducer. You can be betrayed by a conspiracy of .. one. You think you're talking to your bank, or a certain store, or your webmail server, and the CA says that you are, but if the CA is a liar, you could be talking to anyone. Maybe you talk to whom you think you're talking to. Or maybe it's the government. Maybe it's the CA himself. Maybe it's the Russian Mafia.
This is why I recomme
LIARS (Score:5, Insightful)
GG: John Boehner, the House Minority Leader, was on Fox News on Sunday arguing for telecom immunity, and this is one of the things he said in explaining why he believed in amnesty: "I believe that they deserve immunity from lawsuits out there from typical trial lawyers trying to find a way to get into the pockets of the American companies."
I have no doubt that Congressman Boehner is aware of the EFF's true motivations and is deliberately spinning them. His motivation for doing so can only be to defend the Bush Administration. Most importantly, He is absolutely aware that what has happened and is still happening is illegal and he is willing to lie on national tv to defend this. In board rooms, on conference calls, in the break room, at the pool hall down the street, people can't get away with this shit and they know they'll be called out for lying. We really need the people who interviewing these traitors to be more aggressive. Fuck politeness, just once I want some anchorman to say "Wo, hold the fuck on John, we all know that's bullshit."Our elected officials (all of them) lie and spout meaningless rhetoric with impunity everyday and that needs to change. They need to be put on the spot and grilled once in a while.
Re: (Score:2)
He doesn't. Ever. Full stop. See, e.g., Youngstown Sheet and Tube, 343 US 579 [cornell.edu]. Anyone who tells you otherwise is lying and has probably been committing war crimes.
do COURTS have the right and duty to ignore laws
No. That's the whole point of a having a society based on laws, rather than one based on a personality cult. Nobody is allowed to just ignore laws.
Courts, however, have a duty to say what the law is- so if Congress passes a bad law, federal courts
Re:LIARS (Score:4, Insightful)
Glenn Greenwald, AKA Socky McSockPuppet? (Score:2, Funny)
Salon was the wrong outlet for this article. (Score:5, Interesting)
Accessing the article, all I get is: Salon cannot set a cookie on your browser. This for an article on protecting privacy.
Re: (Score:1)
I know you don't really want to RTFA, but . . . (Score:2, Informative)
Re:Salon was the wrong outlet for this article. (Score:5, Funny)
Re: (Score:2)
Against? (Score:2)
Why does the White House need immunity from prosecution by AT&T?
I didn't realize AT&T had that kind of power.
I also thought I heard the White House was rather pushing for retroactive immunity for the telco.