Skip to main content

PRISM

See All Stories

Google encrypting Chinese web searches, plans to do so globally to thwart NSA

Site default logo image
Photo: Li Xin for AFP/Getty Images

Photo: Li Xin for AFP/Getty Images

The Washington Post reports that Google has begun automatically encrypting web searches carried out in China to defeat government monitoring and censorship, and plans to continue rolling out the program globally to prevent monitoring by the NSA.

China’s Great Firewall, as its censorship system is known, has long intercepted searches for information it deemed politically sensitive. Google’s growing use of encryption there means that government monitors are unable to detect when users search for sensitive terms, such as “Dalai Lama” or “Tiananmen Square,” because the encryption makes them appear as indecipherable strings of numbers and letters … 
Expand
Expanding
Close

Google joins tech titans in calling for government spying reform and limitations

Site default logo image

PRISM-slide

The Wall Street Journal reports that Google has joined Microsoft, Twitter, Apple, Yahoo!, Facebook, and other giants in the tech industry in calling for a reform of the NSA’s surveillance tactics. Earlier this year it was revealed that the National Security Agency was using information from these companies and more to monitor citizens across the nation without warrants.

The companies allegedly involved in the “PRISM” program denied turning over any user data to the government, but a leaked NSA slidedeck (seen above) seemed to imply the opposite.

The new collaborative campaign, called Reform Government Surveillance, cites five driving principles in its drive to curb excessive government spying:


Expand
Expanding
Close

Talking Schmidt: Google Chairman SHOCKED at NSA hacking of Google network, says he told buddy Obama that it is ‘not OK’

Site default logo image

[protected-iframe id=”b39f4611921b09f9ac17e6fc7b8a4f06-22427743-8994189″ info=”http://live.wsj.com/public/page/embed-EDDA7151_9316_4F64_80FA_EFC2F9F707BD.html” width=”512″ height=”288″ frameborder=”0″ scrolling=”no”]

Google executive chairman Eric Schmidt expressed his shock at reports that the NSA tapped into the internal communications links between Google servers, describing it as “outrageous” in an interview with the Wall Street Journal. The claim was made as part of the ongoing PRISM revelations.

It’s really outrageous that the National Security Agency was looking between the Google data centers, if that’s true. The steps that the organization was willing to do without good judgment to pursue its mission and potentially violate people’s privacy, it’s not OK … 
Expand
Expanding
Close

Site default logo image

Google and other leading tech companies support USA Freedom Act to limit NSA powers

nsa1

Google, Apple, Facebook, Microsoft, Yahoo and AOL have all signed an open letter expressing support for the USA Freedom Act co-sponsored by Democrat Senator Patrick Leahy and Republican Representative Jim Sensenbrenner. The Act, if passed, would outlaw the NSA’s speculative bulk collection of data and allow the companies to be far more transparent about the data they are obliged to make available to the government.

As companies whose services are used by hundreds of millions of people around the world, we welcome the debate about how to protect both national security and privacy interests and we applaud the sponsors of the USA Freedom Act for making an important contribution to this discussion.

The companies had previously complained that gag orders forced them to issue denials that were technically true but misleading. They had asked to be allowed to release more specific figures about the number of demands they receive for personal data.

This letter goes further, in supporting moves to actually limit the powers the government would have to gain access to the data in the first place.

Transparency is a critical first step to an informed public debate, but it is clear that more needs to be done. Our companies believe that government surveillance practices should also be reformed to include substantial enhancements to privacy protections and appropriate oversight and accountability mechanisms for those programs.

In introducing the bill, Senator Leahy said “The government surveillance programs conducted under the Foreign Surveillance Intelligence Act are far broader than the American people previously understood. Modest transparency and oversight provisions are not enough.”

The Verge reports that Google is tightening the security of its internal networks, and that Twitter has already moved to encrypt direct messages.

Full text of the open letter below.

 October 31, 2013

The Honorable Patrick J. Leahy
Chairman, Committee on the Judiciary
United States Senate
224 Dirksen Senate Office Building
Washington, DC 20510

The Honorable Michael S. Lee
Member, Committee on the Judiciary
United States Senate
316 Hart Senate Office Building
Washington, DC 20510

The Honorable John Conyers, Jr.
Ranking Member, Committee on the Judiciary
U.S. House of Representatives
2138 Rayburn House Office Building
Washington, DC 20515

The Honorable Frank James Sensenbrenner, Jr.
Member, Committee on the Judiciary
U.S. House of Representatives
2449 Rayburn House Office Building
Washington, DC 20510

Dear Messrs. Chairman, Ranking Members and Members:

As companies whose services are used by hundreds of millions of people around the world, we welcome the debate about how to protect both national security and privacy interests and we applaud the sponsors of the USA Freedom Act for making an important contribution to this discussion.

Recent disclosures regarding surveillance activity raise important concerns both in the United States and abroad. The volume and complexity of the information that has been disclosed in recent months has created significant confusion here and around the world, making it more difficult to identify appropriate policy prescriptions. Our companies have consistently made clear that we only respond to legal demands for customer and user information that are targeted and specific. Allowing companies to be transparent about the number and nature of requests will help the public better understand the facts about the government’s authority to compel technology companies to disclose user data and how technology companies respond to the targeted legal demands we receive. Transparency in this regard will also help to counter erroneous reports that we permit intelligence agencies “direct access” to our companies’ servers or that we are participants in a bulk Internet records collection program

Transparency is a critical first step to an informed public debate, but it is clear that more needs to be done. Our companies believe that government surveillance practices should also be reformed to include substantial enhancements to privacy protections and appropriate oversight and accountability mechanisms for those programs.

We also continue to encourage the Administration to increase its transparency efforts and allow us to release more information about the number and types of requests that we receive, so that the public debate on these issues can be informed by facts about how these programs operate. We urge the Administration to work with Congress in addressing these critical reforms that would provide much needed transparency and help rebuild the trust of Internet users around the world.

We look forward to working with you, the co-sponsors of your bills, and other members on legislation that takes into account the need of governments to keep individuals around the world safe as well as the legitimate privacy interests of our users around the world.

Google testing encryption to hide your Drive files on heels of NSA surveillance controversy

Site default logo image

google_drive

Privacy protection in the apps we use on a daily basis has been a big topic of conversation following accusations that Google and other large tech companies were working with government agencies to provide user data. Google has worked tirelessly to clear its name during the scandal, and today CNET reports that the company is testing encryption for Drive files that could further keep its users’ data protected from prying eyes.

As a reminder, Google does not currently encrypt files store in its Drive cloud storage service, but rather only encrypts files being transferred on their way to Drive:
Expand
Expanding
Close

Google asks U.S. government to disclose national security FISA requests

Site default logo image

PRISM-slide

Following Google’s denial of being involved in the PRISM surveillance claims in which the National Security Agency was accused of tapping into servers of 9 tech companies for details of user activity, Google today published a letter it just sent to the U.S. government requesting the release of more national security request data.

Google this morning sent a letter to the Attorney General and the Federal Bureau of Investigation asking that it be allowed to publish “aggregate numbers of national security requests, including FISA disclosures—in terms of both the number we receive and their scope.”

Assertions in the press that our compliance with these requests gives the U.S. government unfettered access to our users’ data are simply untrue. However, government nondisclosure obligations regarding the number of FISA national security requests that Google receives, as well as the number of accounts covered by those requests, fuel that speculation.

Google continued by noting that the numbers “would clearly show that our compliance with these requests falls far short of the claims being made. Google has nothing to hide.”

The full letter is below:
Expand
Expanding
Close

PRISM update: how both the claims and the denials may be true

Site default logo image
The NSA's $2b data centre in Bluffdale, Utah (source: businessweek.com)

The NSA’s $2b data centre in Bluffdale, Utah (source: businessweek.com)

Security researchers examining the PRISM denials made by the companies alleged to be providing data to the NSA say that the language used is suspiciously similar. The emphasis is ours:

Google: First, we have not joined any program that would give the U.S. government—or any other government—direct access to our servers.

Apple: “We do not provide any government agency with direct access to our servers, and any government agency requesting customer data must get a court order.”

Facebook: Facebook is not and has never been part of any program to give the US or any other government direct access to our servers.

The fact that the exact same phrase has been used seems unlikely to be a coincidence. One security researcher I spoke to said the wording only eliminated the NSA pulling data from the servers; it did not mean the companies were not pushing the data to the NSA. If the NSA obtained a secret court order requiring the companies to hand over the data, then of course statements that they only provide data when required to do so by law would also be true … 
Expand
Expanding
Close

Google and other tech companies deny PRISM surveillance claims, NSA says claims ‘inaccurate’ and not used domestically

Site default logo image

PRISM-slide

Claims made by The Washington Post that the National Security Agency was tapping into the servers of nine tech companies for details of user activity have been denied by Google and most of the other companies alleged to be involved.

Google cares deeply about the security of our users’ data. We disclose user data to government in accordance with the law, and we review all such requests carefully. From time to time, people allege that we have created a government ‘back door’ into our systems, but Google does not have a ‘back door’ for the government to access private user data.

Similar denial statements have been issued by Apple, Dropbox, Yahoo, Microsoft and Facebook.

The Post published slides from what it said was a Powerpoint presentation detailing the top-secret program, in which it was implied that the companies listed were knowing participants … 
Expand
Expanding
Close