So the PRISM consist of FBI electronic wiretap portals/devices within a company's infrastructure.
Now we know the FBI will generally require a court order or an NSL before accessing the portal to request user information.
No one has been clear about what the role of the NSA is in these devices are.
1. They could just be administering the system for the FBI.
2. They could be copying all the data that goes to the FBI into their corporate store.
3. They could be applying 51% probability foreign standard to any data they can see with theses devices.
I've seen this question asked of numerous tech executives and no one is able to give a good answer so I'm suspicious. What Bruce Schneier keeps telling us is that the NSA's email interception is robust, they wrap a program in multiple overlapping legal justifications.
Google is the only company to deny having FBI/NSA devices on their network.
When Spylockout asked Apple's general counsel about devices on their network, we could not get a denial. Apple also made iMessage e2e encrypted for a reason...
I'm really supportive of Google's efforts to genuinely protect user privacy. I think they are correct if they believe the only ultimate guarantee of user privacy is end to end encryption in the current legal environment in the US.
I would be surprised if any of the companies allowed FBI equipment to have direct access to all their users' data. Not only is it a bad idea from a privacy perspective, but it is a terrible idea from an engineering perspective as well.
If I was going to start this thread over again, I'd have done a better job differentiating between the concepts of in the data center and in the server. Also I'd do a better job of discussing Section 215 of the Patriot Act which is in transparency reports and Section 702 of the FISA Amendments which in not.
Thanks for improving my arguements for next time :-)
Neither the FBI nor the NSA have code related to data requests running in any of these companies' servers either, so the in-server versus in-datacenter distinction does not make a difference.
Now we know the FBI will generally require a court order or an NSL before accessing the portal to request user information.
No one has been clear about what the role of the NSA is in these devices are.
1. They could just be administering the system for the FBI.
2. They could be copying all the data that goes to the FBI into their corporate store.
3. They could be applying 51% probability foreign standard to any data they can see with theses devices.
I've seen this question asked of numerous tech executives and no one is able to give a good answer so I'm suspicious. What Bruce Schneier keeps telling us is that the NSA's email interception is robust, they wrap a program in multiple overlapping legal justifications.