Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

51–60 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#51

Earlier quoted context omitted.

A fair percentage of people (myself included) are far more concerned about protecting our data from marketers, advertisers, and data brokers, than we are about going 100% 'tinfoil hat' mode and worrying whether the NSA is monitoring my messages for thought crimes. These are two very distinct issues and not everyone is concerned about both equally.

> A fair percentage of people (myself included) are far more concerned about protecting our data from marketers, advertisers, and data brokers, than we are about going 100% 'tinfoil hat' mode and worrying whether the NSA is monitoring my messages for thought crimes. The main issue here is that people aren't worried about either of those problems :) otherwise Facebook, Google and other advertising companies would only…

> we should fight together for more privacy

It needs to be established as a human right.

I'm personally very disappointed to see the how good intentions of the aware subset of the citizenry are consistently channeled towards technical solutions to a problem that is fundamentally political.

At a meta-level, we saw the same (useless) dissipation of energies in the Occupy-x movement. And it should also be pointed out that the subtext of such approaches is de facto deligitimization of legal governance of societies and (speaking of "kings") establishing corporations as the arbitrators of social norms.

Get congress to pass a comprehensive privacy act and "Alphabets" (of the corporate and governmental variety) will have to toe the law of the land.

[edit:spelling]

Re: Google backs off on previously announced Allo privacy feature

#52

Earlier quoted context omitted.

A fair percentage of people (myself included) are far more concerned about protecting our data from marketers, advertisers, and data brokers, than we are about going 100% 'tinfoil hat' mode and worrying whether the NSA is monitoring my messages for thought crimes. These are two very distinct issues and not everyone is concerned about both equally.

Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? https://en.wikipedia.org/wiki/Martin_Luther_King_Jr.#NSA_mon...

> Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"?

Probably 'yes' for you, 'no' for him.

Sorry, but a random HN commenter is extremely unlikely to be targeted for the level of surveillance and treachery that Dr King was. If he feared it, he had good reason. If you are some random IT worker building the next smart pillow you cannot expect them to prioritize spying on you, that's all I'm saying. Mass surveillance isn't the same as targeted.

Re: Google backs off on previously announced Allo privacy feature

#53
post #48

Earlier quoted context omitted.

That's really just BS. What's the point of encryption if both the keys and the content is known by Google? They could as well use just SSL and that wouldn't make it safer than this kind of "encryption".

The benefits of this sort of encryption & privacy infrastructure: * Protects you (user) from eavesdroppers between you and Google. * Protects your data from eavesdroppers inside Google's data centers. * Protects your data at rest (on disk). * Protects your data from malicious employees. * Enforces a great deal of scrutiny over who can access your data, and what they are allowed to see. But, yes, they process and stor…

The rest of points are not addressed by this sort of encryption because the keys are on disk too. Google employees have access to the keys. It's like leaving the keys into the lock and claiming it's more secure because it has a lock. In practice the data is protected only by ACL. Encryption is just a marketing keyword in this case.

Re: Google backs off on previously announced Allo privacy feature

#54
post #36
post #25

Earlier quoted context omitted.

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

That's fine as far as trusting Google keeping their employees from doing bad things. But that's not the first concern one would have. Pervasive surveillance programs have penetrated service providers' data centers. Law enforcement can get warrants to access this information too easily, and many service providers turn over information on request, rather than requiring a warrant.

Well if you trust Google you don't need on-disk encryption in the first place. SSL already solved the transport issue.

Re: Google backs off on previously announced Allo privacy feature

#55
Was it really expected in the first place that the ordinary messages don't get saved on Google's servers? As someone with a passive interest in Allo but who hasn't been following it closely, I never assumed the "smart AI" messages were anything other than simple hangouts-type messages that get stored on Google's servers. I'd even expect (/hope) them to be someday accessible on the web or transferable to a new phone.

It's the incognito that are end-to-end encrypted and I expect are secure from Google's prying eyes. And I don't think anything has changed there.

This is a non-issue for me, anyway.

Re: Google backs off on previously announced Allo privacy feature

#56
post #37
post #9

Here's Moxie's related press release on doing E2E for Allo: https://whispersystems.org/blog/allo/ Curious if he'll comment on what happened: https://twitter.com/moxie https://news.ycombinator.com/threads?id=moxie ___ If you don't know about Moxie, highly suggest learning more about him: https://thoughtcrime.org/ https://en.m.wikipedia.org/wiki/Thoughtcrime https://en.m.wikipedia.org/wiki/Moxie_Marlinspike

The best new friend of Facebook Moxie? His "trust us, we checked FB Messenger code and it's all good" pitch made for a very entertaining read.

Aware of that issue (asked moxie about it on HN) and other issues too, but it doesn't change that there's zero reason to believe Moxie's intent is malicious and it's a stretch by any means to claim his contributions are anything but positive in sum.

Re: Google backs off on previously announced Allo privacy feature

#57

Earlier quoted context omitted.

How does it benefit by keeping data forever though? Of what use is aged data?

It doesn't. They need a constant stream of new data for their business model to work. Thus, they benefit from continuously collecting data on users.

So why do they store indefinitely? If they stated a retention period openly they'd get much less criticism over privacy.

Re: Google backs off on previously announced Allo privacy feature

#58
post #37
post #9

Here's Moxie's related press release on doing E2E for Allo: https://whispersystems.org/blog/allo/ Curious if he'll comment on what happened: https://twitter.com/moxie https://news.ycombinator.com/threads?id=moxie ___ If you don't know about Moxie, highly suggest learning more about him: https://thoughtcrime.org/ https://en.m.wikipedia.org/wiki/Thoughtcrime https://en.m.wikipedia.org/wiki/Moxie_Marlinspike

The best new friend of Facebook Moxie? His "trust us, we checked FB Messenger code and it's all good" pitch made for a very entertaining read.

Yes, moxie "knows it all" wants to control his apps so much he doesn't want them to be on f-droid https://f-droid.org/posts/security-notice-textsecure/

Re: Google backs off on previously announced Allo privacy feature

#59
post #30
post #25

Earlier quoted context omitted.

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

I don't think that is enough. Here we are relying on Google being magnanimous enough to not use the data to increase their profitability. And even beyond that, your opinion is a little naive to hold in a post-snowden world.

Right - their policies may be perfect today but they may not even exist tomorrow.
Post reply on HN