Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

31–40 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#31

Earlier quoted context omitted.

A fair percentage of people (myself included) are far more concerned about protecting our data from marketers, advertisers, and data brokers, than we are about going 100% 'tinfoil hat' mode and worrying whether the NSA is monitoring my messages for thought crimes. These are two very distinct issues and not everyone is concerned about both equally.

Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? https://en.wikipedia.org/wiki/Martin_Luther_King_Jr.#NSA_mon...

How is that relevant to the fact that many people are more worried about marketers than the NSA? Nobody's questioning that some people are in fact so monitored. "I am more concerned about A than B" is not a claim that B does not exist, nor is it a claim that "I" am unconcerned about B.

Re: Google backs off on previously announced Allo privacy feature

#32
post #26
post #20

Earlier quoted context omitted.

Sure, whatever safe hands mean. Safe in an NSA datacenter. Safe in the hands of the Chinese government. Safe with whatever sysadmin has access to it. Instead of worrying about what "safe hands" mean, just keep it accessible only to me, and each respective conversation with the people I communicate with.

> just keep it accessible only to me One could also argue that the service is free and the service provider needs a (or yet another) way to monetize it. If the privacy settings are insecure by default, one shouldn't have high expectations anyways.

And that's a little scary, you sell a bit of yourself to get access to a service. It's not really the best case scenario I would want.

Re: Google backs off on previously announced Allo privacy feature

#33
post #27

Earlier quoted context omitted.

> Stay evil. Wow. Google went a full 180 from being a company that promoted itself by saying "Don't be evil" to something evil. Couldn't Google have made its billions still being not evil, without its privacy issues, without its obnoxious desire for tracking everything. Did they turn to this evil for the money or just because they can do it (or if not someone else will).

>Couldn't Google have made its billions still being not evil No. Google is advertising company and advertisement companies need a lot of user data for targeted ads.

How does it benefit by keeping data forever though? Of what use is aged data?

Re: Google backs off on previously announced Allo privacy feature

#35
post #30
post #25

Earlier quoted context omitted.

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

I don't think that is enough. Here we are relying on Google being magnanimous enough to not use the data to increase their profitability. And even beyond that, your opinion is a little naive to hold in a post-snowden world.

[deleted]

Re: Google backs off on previously announced Allo privacy feature

#36
post #25
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

That's fine as far as trusting Google keeping their employees from doing bad things.

But that's not the first concern one would have. Pervasive surveillance programs have penetrated service providers' data centers. Law enforcement can get warrants to access this information too easily, and many service providers turn over information on request, rather than requiring a warrant.

Re: Google backs off on previously announced Allo privacy feature

#37
post #9

Here's Moxie's related press release on doing E2E for Allo: https://whispersystems.org/blog/allo/ Curious if he'll comment on what happened: https://twitter.com/moxie https://news.ycombinator.com/threads?id=moxie ___ If you don't know about Moxie, highly suggest learning more about him: https://thoughtcrime.org/ https://en.m.wikipedia.org/wiki/Thoughtcrime https://en.m.wikipedia.org/wiki/Moxie_Marlinspike

The best new friend of Facebook Moxie?

His "trust us, we checked FB Messenger code and it's all good" pitch made for a very entertaining read.

Re: Google backs off on previously announced Allo privacy feature

#38
This seems to be where the "backing off" claim is coming from:

http://www.theverge.com/2016/5/18/11699122/google-allo-messa...

> First, all conversations are encrypted "on the wire," which means that nobody on the internet can read them as you send your message. They are read by Google's servers, but Kay assures me that the data is stored "transiently," which is to say that Google doesn't keep your chat logs around to be subpoenaed. And Fulay adds that Google doesn't assign identity to the chat logs on those servers even then.

I think this is a misunderstanding -- either on the part of the authors or from the Google employees on understanding the question asked by the authors.

Kay probably meant that in Incognito mode, messages are stored transiently. I don't believe that has changed, has it?

Did Google really say that non-Incognito messages would not be stored server-side? What happens if you lose your phone -- do you lose all your Allo chat history? That would be a really shitty user experience.

Re: Google backs off on previously announced Allo privacy feature

#39
post #38

This seems to be where the "backing off" claim is coming from: http://www.theverge.com/2016/5/18/11699122/google-allo-messa... > First, all conversations are encrypted "on the wire," which means that nobody on the internet can read them as you send your message. They are read by Google's servers, but Kay assures me that the data is stored "transiently," which is to say that Google doesn't keep your chat logs around t…

That basically happens with WhatsApp if you don't back it up somewhere.

Re: Google backs off on previously announced Allo privacy feature

#40

Was anybody actually planning to use Allo for encrypted communications? I was under the impression it was written off at its announcement.

Why was it written off? It's using Whisper Systems tech to do it's end-to-end encryption[0]. Is there someway Google could inject itself into this, or some reason people shouldn't trust it?

[0] https://whispersystems.org/blog/allo/

Post reply on HN