Who Will Take The Privacy Seppuku Pledge?

from the after-you dept

When Techdirt wrote recently about yet another secure email provider opting to close down its service rather than acquiesce in some future US government demand to spy on its users, we noted that Cryptocloud has promised something similar for a while — what it terms “corporate seppuku“:

In the context of privacy issues, “corporate seppuku” means shutting down a company rather than agreeing to become an extension of the massive, ever-expanding, secretive global surveillance network organized by the U.S. National Security Agency. It means, in short, saying “no.” Sometimes, we hear people say that this or that company “had no choice” in what they did. Bullshit. There’s always a choice; it’s just that the consequences of certain options might be really severe, and are thus not chosen. But that’s a choice. It’s always a choice.

It has even formulated what it calls the Privacy Seppuku pledge:

if a company is served with a secret order to become a real-time participant in ongoing, blanket, secret surveillance of its customers… it will say no. Just say no. And it will shut down its operations, rather than have then infiltrated by spies and used surreptitiously to spread the NSA’s global spook malware further. You can’t force a company to do something if there’s no company there to do it.

It’s a noble gesture, but would it do much good in the real world of US government spying? Cryptostorm, the company behind Cryptocloud, has provided a fuller analysis of why it thinks such a pledge would work. Here’s a key point:

That one that went thru with the seppuku? She’ll likely have a new service up and running in a few days or weeks. The customers who got dinged by the shutdown? They’ll all get up and running on her new service. This is all 1s and 0s, remember? You don’t have to demolish a car manufacturing plant, after all — you’re just wiping some VMs and reincorporating elsewhere. Lease new machines. Call it “lavabutt” on the new corporate docs, in Andorra. Sign on to the Privacy Seppuku pledge, as lavabutt, again. Off you go. Do you think it’ll be hard to get customers — old ones migrated over, and new ones alike? Think on that: a privacy company that shut down rather than be #snitchware… do you trust them, now?

That resilience flows from the service’s digital nature, the availability of powerful but free software, and Moore’s Law driving down the cost of commodity hardware. Put together, they make it easy to to recreate a business if it is shut down (apart from the lost data, of course.) The NSA will get this salient feature, CryptoStorm believes:

Spooks aren’t dumb — far from it. They do these kinds of analysis — hell, they hire some of the best game theoretic minds in the world, and always have. Local cops might be power-drunk and unable to see how their actions play out over time; the NSA isn’t any of that. They have whole buildings full of very smart people paid good money to think about this stuff. They won’t get it wrong.

And the outcome is simple: if the Privacy Seppuku concept spreads, it becomes useless to target companies on the pledge list! You won’t get what you want, you’ll make some heroes who go out and do bigger stuff next, you’ll out yourselves as dangerous thugs, your “secrecy” is shot to hell, and after all the effort involved you end up backwards from where you were before. That’s the scenario, it’s how it plays out. There’s really no alternative scenario.

It’s an optimistic vision, but the fact is that at the time of writing, only two services are listed as having made the Privacy Seppuku pledge — Cryptocloud and Cryptocat. Until more join the club, it remains more a nice idea than a practical way of fighting back against today’s mass surveillance.

Follow me @glynmoody on Twitter or identi.ca, and on Google+

Filed Under: , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Who Will Take The Privacy Seppuku Pledge?”

Subscribe: RSS Leave a comment
seeker (profile) says:

Re: And....

it is the US govt that are the terrorists from our point of view. Terrorists and nazies of the USA war criminal regime with illegal invasions, DU and white phosphorous murders, drone murders, assassination squads, torture as official policy, illegal spying, what is it that americans fail to comprehend about their nation being a psychopathic entity run by international war criminals and thieves? Evil is as evil does, and while it is clear that US citizens are mostly in ‘denial’ the evidence is overwhelming, 911 was an inside job, the thin aluminium of wingtips will not cut thru the 14 inch thick steel beams surrounding the twin towers creating a ‘cardboard cutout’ plane shape so the stupid of america will believe there were planes… talk about retards! And now the nation has gone over the edge into butter disaster land… and those americans who failed to stop the criminals are getting the govt and lwas they deserve for not standing against evil when they should, so Corporate Sepuku’shows that not all americans support the evil ‘TERROR STATE THAT IS THE USA’!

mvario (profile) says:

Standard part of Privacy Policies

I think that as a part of their privacy Policy, all sites should state what their actions will be in the event they are served with a National Security letter. Users will then have that information up front to aid in their decision whether to use the site, and not have to guess whether a site will secretly comply, challenge it, or close their doors.

Atkray (profile) says:

Faulty premise

“Spooks aren’t dumb — far from it. They do these kinds of analysis — hell, they hire some of the best game theoretic minds in the world, and always have. Local cops might be power-drunk and unable to see how their actions play out over time; the NSA isn’t any of that. They have whole buildings full of very smart people paid good money to think about this stuff. They won’t get it wrong. “

They will and did. If they were so smart they would have realized early on what Ed Snowden had in his possesion and moved heaven and earth to make a deal with him to bring him home and stop the releases. Give him immunity throw a couple administrators on the sacrificial altar and move on.

These people are arrogant and believe themselves above the law and incapable of failure.

See also: Pirate Bay Whack-a-mole.

That One Guy (profile) says:

Re: Faulty premise

Nah, they didn’t go the rational route with Snowden because they found themselves dealing with the kind of person that they had no experience with from their day to day lives: someone with a moral code higher than zero, and who was more interested in justice than power.

Add to that the fact that Snowden is no fool, and wouldn’t have been tricked by some sacrificial lambs being tossed out to make it look like they had ‘changed their ways’, and the only way they could get him was the underhanded/political fashion.

Mind, that doesn’t change the ‘arrogant and above the law’ line one bit, that I fully agree with, it suits them perfectly.

Haudenosun (profile) says:

Re: Faulty premise

I agree, in part with Atkray

“Spooks Are dumb”

1st there is something called “incompetence” which happens every minute of ever day, – around the globe. Errors and oversight will occur.

2nd is hubris, a byproduct of ” Emperialistic” thinking. This hubris can lead to the underestimation of a threat or overconfidence in a mission achievement.

3rd there are some incredibly bright people who choose not to work for the spooks. And lets not underestimate the hacker mentality.

4th, there is a little something called morality. There do exist people who can’t be bought and who will not compromise their principles.

This is where we get to Snowden. Listen to his interviews. “The truth is coming and it can’t be stopped.” There was no deal possible. Remember, he believed like many others, that Obama would bring change. He sat on all this knowledge waiting for those changes to happen.

There will be more I’m sure (whistleblowers) . I’m guessing that it’s already too late for the government and the spooks to find them and shut them up.

Uriel-238 (profile) says:

Maybe they will go Full Gestapo.

Now that Ladar Levison might potentially be arrested for espionage or conspiracy, that might halt companies from carrying out corporate seppuku, even if it means disappearing all non-cooperative corporate officers and replacing them with government agents.

We don’t know. It’ll be interesting to see the Levison fate (and I hope he has an offshore haven somewhere), but I’m sure if they made an example of Levison, later corporations would either bail early or fail to follow through on the pledge.

Postulator (profile) says:

A gut-wrenching decision

Two problems with this:

– Once you’re served with that order, to destroy any data may be a criminal offence (where is that link to the Lavabit guy’s defence fund, by the way?)
– Announcing your intent means that anyone wanting to spy on your users will look for back doors.

A third problem being for listed companies – you try doing this, your shareholders will be after your head (as opposed to your guts).

I had to look up seppuku (although I had heard of the more popular term). Wikipedia had a very nice article on it. One very important thing to note is that it is incredibly difficult to intentionally hurt yourself – the human mind is trained to avoid harm, and seppuku intentionally causes enormous pain leading to death. I think Cryptocloud has chosen the right term. For the company owner making such a decision, they would face enormous pain.

techdirt commentator says:

Full Gestapo

If refusing such requests and preemptively shutting up shop is made illegal, and precedents are set to deter future copycats, the next best thing to do would be to comply with the orders but then shut up the business about 1 minute after the installation of government spywarez has been completed. That way you comply with the order but they get minimal useful data.

avideogameplayer says:

You’re forgetting about the big companies like Google and M$, etc…

Do you REALLY expect them to shutdown and piss off all their shareholders?

Plus they’re WORLDWIDE shutting down operations on that big a scale would have to take a tremendous amount of coordination and cooperation…

Not to mention the costs of restarting under a different company and all new equipment for it…

Not to mention about what to do with the employees in the meantime…

Realistically, I can’t see that happening…

Anonymous Coward says:

Re: Re:

However, they have WAY more power to fight back should they choose to. They have access to HUGE expert legal teams, plenty of political connections, and the funds to tie things up in the courts while they resist. Also with regards to a company like Google that is hugely popular, directly trying to shut them down would also likely be political suicide. Furthermore, think of all of the businesses in the US that are built and rely on the use of Google’s products and services. An attempt by the government to shut them down over a flat refusal to comply would have a significant impact the entire US economy. What administration wants to be responsible for that if they suddenly went rogue and stopped complying and publicly stated everything that was occurring even if it was in violation of a court order?

Anonymous Coward says:

Re: you get a court order

Are you saying that in a so called capitalistic environment, a business is not allowed to fail, even though they are not too big?

Rather than shutting the business down, what if the owner simply raised the fees through the roof? Would that also be illegal?

If the government can force a business to continue operations regardless of whether it is profitable, would the inevitable losses then be a write off or a credit?

Is this the new face of slavery?

Anonymous Coward says:

I wonder

Would Masnick close Techdirt if NSA sent him a secret order for the IP address and collected info on visitors to this site ?

Would he say NO ?? and shut up shop, would he even disclose such an order if the order stated he was not allowed too ?

Would he disclose such an order if it did not have a clause not to talk about it ? Would he comply with the order ?

The Real Michael says:

Re: I wonder

That’s an interesting question…

How by giving companies an ultimatum (“Allow us to spy or else”) is that not quivalent to hostile government takeover, a serious affront to freedom? If they know that companies would rather shut down their services rather than play ball with the NSA, this cause-and-effect scenario would give the latter the ability to get rid of sites they don’t like in a roundabout way. To use a real-world analogy, imagine if you opened a business and one day an NSA agent walked in and told you that he was going to secretly set up cameras on your property and that you didn’t have a say in the matter. How would you feel?

Lurker Keith says:

Re: I wonder

Considering that the theoretical court order would likely be Unconstitutional, I have a feeling Mike would refuse to comply until he’s given indisputable proof it is Constitutional, & make a carefully worded post about being given an Unconstitutional court order.

Then again, what do I know? I’ve only been here since the SOPA Blackout.

robin (profile) says:

Not So Easy

This is all 1s and 0s, remember? You don’t have to demolish a car manufacturing plant, after all — you’re just wiping some VMs and reincorporating elsewhere. Lease new machines. Call it “lavabutt” on the new corporate docs, in Andorra. Sign on to the Privacy Seppuku pledge, as lavabutt, again. Off you go

Levison said in an interview that he could not just do that, for as a U.S. citizen, he is still subject to the nation’s laws, regardless of where the company is inocrporated and it’s servers are located.

Anonymous Coward says:

Re: Not So Easy

He didn’t say he couldn’t do it. He said he wasn’t willing to at this point because he doesn’t want to relocate personally to another country. He could also always sell any corporate assets that he still has to another entity that would be willing to do just that. It doesn’t have to be carried on necessarily by himself personally.

Ninja (profile) says:

We should ask those people telling “if u got nothing to hinde then you don’t need to fear the surveillance” to hand over every single piece of data they have to the NSA. Every single bit. Pictures (physcial or not), exact itineraries with detailed gps data, all your letter, documents, all of your private conversations, tapes of every sexual interaction you have with your partner, tapes of you using your bathroom… You know, commit privacy sepukku in the other end too. After all if you don’t mind the intrusive surveillance you wouldn’t mind giving all of your data to the Govt, right?

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...