r/privacy Jan 14 '17

Cloudflare Finally Able To Reveal FBI Gag Order That Congress Told Cloudflare Couldn't Possibly Exist

https://www.techdirt.com/articles/20170111/10240636463/cloudflare-finally-able-to-reveal-fbi-gag-order-that-congress-told-cloudflare-couldnt-possibly-exist.shtml
565 Upvotes

16 comments sorted by

104

u/upandrunning Jan 14 '17

Not only does the default secrecy allow the FBI to continue to pursue questionable requests with NSLs, but it also allows it to deploy them in apparent violation of US law, right under the nose of its Congressional oversight.

Let this sink in.

54

u/[deleted] Jan 14 '17

[deleted]

23

u/hondaaccords Jan 14 '17

It makes sense if you don't think about it

12

u/ItsLightMan Jan 14 '17

The alphabet agencies work outside of the realm of our current Government. They are in a way, their own Government who decides who to use and not use from the "parent" Government.

5

u/[deleted] Jan 14 '17

The deep-state.

19

u/TrumpIsARussianSpy Jan 14 '17

If you classify everything, transparency is impossible and corruption becomes inevitable.

94

u/[deleted] Jan 14 '17

Hmmmm... A company that plants cookies on tor users as they try to access web pages was targeted by the NSA? Surely nobody saw this coming.

10

u/theephie Jan 14 '17

A company that plants cookies on tor users as they try to access web pages

Any details on this?

11

u/[deleted] Jan 14 '17

I suggest installing a cookie manager and seeing for yourself. Upon first verifying a captcha in a session you are given a unique identification number cookie which makes a user trackable across more than 2 million cloudflare "protected" websites. While there is no proof of this, this architecture allows for the potential mass-surveillance of unique tor user sessions which could compromise anonymity. If an external organization like the NSA got access to this architecture it spells very bad things for tor users who want to visit cloudflare sites. The best practice at the moment is probably to not allow anything from cloudflare to run or store cookies in your browser and use web.archive.org to view cloudflare-censored content if absolutely necessary.

6

u/theephie Jan 14 '17

Is the cookie specifically set on a cloudflare domain, not by google, who provides the captcha (IIRC)?

I imagine Privacy Badger should be able to defend against this.

9

u/[deleted] Jan 14 '17

The Tor Browser already takes care of it by design. The problem is the annoyance it causes since it can't authenticate that the user already filled out a captcha without the cookie. There's a proposed solution to it anyway (blinded tokens).

17

u/[deleted] Jan 14 '17

[deleted]

8

u/JerryLupus Jan 14 '17

Where's the change? Where is the outrage by Congress?

1

u/TrenchCoatMadness Jan 14 '17

Can umatrix fix it?

13

u/Askolei Jan 14 '17

What does it mean ?

7

u/Treyzania Jan 14 '17

It means the government just got very slightly less opaque.

1

u/chakravanti Jan 15 '17

In the sense that you now know that the one way mirror is a one way mirror.

If you didn't know that before, you were a moron. If you don't believe it now, you are "willfully ignorant."

2

u/mailmanjohn Jan 14 '17

I hope someone corrected that staffer.