Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

>A lie gets halfway around the world before the truth gets its pants on. This story made it 1/3rd up the front page; stories based on the most extreme possible interpretation of what seems to be Greenwald's own extreme interpretation of a slide deck covered the entire front page for days.

There's definitely some extreme speculation going on--both from those trying to maximize as well as those trying to minimize this issue. It will take some time to get to the truth. This article is a perfect example of an extreme attempt to minimize this issue.

This article seeks to minimize the Guardian's original story by saying the Guardian is "walking back" their claims. That doesn't seem to be the case. This article cites a paragraph near the end of a minor story published days later as the passage where they "walk back" their original story. The intent of the paragraph seems to be to illustrate that both the "direct access" claim from the NSA and the "no direct access" claims from tech companies can both be true. The original article doesn't seem to be changed.

Beyond that, the Guardian never claimed the NSA had "direct access". They claimed that the NSA slides stated the NSA had direct access. The Guardian has not stated they read too much into "direct access" in the slides, and the original article is pretty clear that "direct access" is simply the NSA claim in the slides, not the Guardian's verdict.

There is another remaining issue: the original article claims access to "live communications", which has yet to be supported by a slide, but it would pretty much rule out the SFTP-only possibility that some people seem to be accepting as fact at this point. Maybe there is direct access to live information from Skype and Apple, but Google insisted on SFTP? We still have a lot to find out.

It could be that the Guardian did exaggerate. But it is far too early to conclude that with so many questions remaining. Not all the companies have described their systems.

One thing is certain: the Guardian does not seem to be walking back their claim.



How is running a story that defines "direct access" as a "dropbox system" where "legally requested data could be copied from their own server out to an NSA-owned system" possibly not a walk-back, given Greenwald's original story?


The original story is a report about the "direct access" claim from the NSA. People seem to have interpreted the article as claiming as fact that the NSA had a root password to all the companies' servers, but that's not what the Guardian reported. They simply reported an NSA claim.

This separate article covers the story that the original article broke. This paragraph in the article gives an attempt to reconcile the competing claims from the NSA and the companies. What makes you say this attempt should invalidate the original story?


The Guardian's original story http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-n... really does seem to be specifically claiming NSA root access or the equivalent:

> When the FAA was first enacted, defenders of the statute argued that a significant check on abuse would be the NSA's inability to obtain electronic communications without the consent of the telecom and internet companies that control the data. But the Prism program renders that consent unnecessary, as it allows the agency to directly and unilaterally seize the communications off the companies' servers.

As soon as people suggested that "collection directly from the servers" actually meant a FISA workflow-automation system involving an API and maybe dropbox servers, Glenn Greenwald indignantly denied, or maybe didn't understand, the possibility that the companies' statements could actually be compatible with the PRISM document https://twitter.com/ggreenwald/status/343421926057861121 https://twitter.com/ggreenwald/status/343422182589870081 https://twitter.com/ggreenwald/status/343423399609131008 https://twitter.com/ggreenwald/status/343423727066824705 . Meanwhile both the Washington Post and the Guardian started backing down from the NSA-has-root idea. The paragraph WaPo added to its original story

> It is possible that the conflict between the PRISM slides and the company spokesmen is the result of imprecision on the part of the NSA author. In another classified report obtained by The Post, the arrangement is described as allowing “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers.

plus the later story it printed http://www.washingtonpost.com/world/national-security/us-com... both help to make clear that the Post did intend its original PRISM story to be understood as NSA-has-root.


I agree that whether or not the NSA can pull records from these companies without the companies meaningfully reviewing each request is a very important detail.

"But the Prism program renders that consent unnecessary, as it allows the agency to directly and unilaterally seize the communications off the companies' servers" is a strong statement. I agree that it is probably not compatible with the details Google has divulged about its "SFTP and manually by human only" process. But that is only one of the many companies.

I understand the "slides or GTFO" attitude that I'm seeing in these claims that the original story is inaccurate, but I think it's a bit arrogant and premature. A journalist who has seen the entire slide deck continues to tell us that the nature of what the whole presentation reveals is more invasive than a digital lockbox with workflow management software where humans meaningfully verify, evaluate, and approve requests. He could have misinterpreted the slides, but I doubt he would stick to the report so steadfastly once all these objections arose if he were not pretty confident he understood the claims in the Prism presentation.

We shouldn't accept that the NSA can grab a user profile without explicit, individual legal approval from the company as fact yet--there's a lot more we will hopefully learn. And how true this is could vary from company to company. But it's silly to ignore that a credible voice who has seen the presentation is telling us something.


I would be slow to assume that anything is known for certain in this kind of "spook biz". I also don't assume that everything interesting has been released on the slides already. (For example, there's interesting reporting in the first Guardian story about what happened to FISA 702 request rates since PRISM was introduced which includes quotations from the slides, but hasn't got much attention seemingly because the relevant slide or slides have not been reproduced yet.) However, there a couple of things that make me fairly confident Greenwald is (or was? I'm not sure if he is still standing by his claim) wrong about this.

One is that AFAIK the Guardian and the WaPo both have access to all the same materials Greenwald has, and they have both been backing away from the NSA-has-root claim for some time. But an even bigger factor is how Greenwald defended his claim. If he'd said "there's still-unreleased material which proves me right, hold tight" that would be one thing. But instead he quoted the "collection directly from the servers" text and linked the new slide it came from, implying that the quotation unambiguously ruled out the drop-box/API interpretation and supported the NSA-has-root interpretation. But in fact "collection directly from the servers" is not at all unambiguous between the two interpretations. And even worse, the You Should Use Both slide, which Greenwald produced as his trump card, provides context which clearly undermines the NSA-has-root interpretation! In that slide it's clear that "collection directly from the servers" is being contrasted with upstream collection of IP data from the telcos. The fact that Greenwald evidently didn't pick up on this himself is pretty clear evidence that his understanding of the presentation is imperfect, whether because it's being distorted by his desire for a bigger and more damning scoop or just impeded by a lack of technical savvy.


You're missing the big picture.

The truth that has spread around the world is that there is a surveillance system in the US which spies on Americans.

If you feel journalists have misinterpreted the capabilities of the system, feel free to call the PRISM hotline for clarification and tell us what you find out.


(not just Americans...)


I agree with your assessment of whether the Guardian claimed direct access, or if they claimed the NSA claimed direct access. But I don't like how they went about it:

"The National Security Agency has obtained direct access to the systems of Google, Facebook, Apple and other US internet giants, according to a top secret document obtained by the Guardian."

They're not any less guilty than other papers, though. "Categorical statement, according to Source" is a common construct in journalism. But I don't like it, because it de-emphasizes the uncertainty in the statement. Reversing the phrases would put the correct emphasis, I think.


The story they ran does not reliably attribute claims about surveillance to the NSA slides, but adds its own speculative claims and, later in the story, blurs the line between what the document is claiming and what the Guardian believes to be fact.


I don't see where the lines are blurred. If you're referring to what you expressed here[1], I'm not convinced. The story is very clear about the source of the information at the beginning of the article, and it then follows the common convention of not appending the repetitive "according to the source material" to the end of each sentence.

I suppose you could say that some of the statements are speculative in that they say "if the claims in the Prism presentation are true, then...", but I think that's speculative in a very narrow way. It makes sense to draw out possible consequences of the program as expressed in the source material that are rooted in fact and not in speculation.

The article is definitely not speculative in the dangerous sense; it does not say things like "direct access probably means root access to production servers" or "since this program costs only $20 million it's likely to keep growing".

It does make claims we have not yet seen evidence for, but there's no indication they're speculative...

[1]: https://qht.co/item?id=5845649


When the FAA was first enacted, defenders of the statute argued that a significant check on abuse would be the NSA's inability to obtain electronic communications without the consent of the telecom and internet companies that control the data. But the Prism program renders that consent unnecessary, as it allows the agency to directly and unilaterally seize the communications off the companies' servers.


> There is another remaining issue: the original article claims access to "live communications", which has yet to be supported by a slide, but it would pretty much rule out the SFTP-only possibility that some people seem to be accepting as fact at this point. Maybe there is direct access to live information from Skype and Apple, but Google insisted on SFTP? We still have a lot to find out.

http://en.m.wikipedia.org/wiki/Room_641A




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: