Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

61–70 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#61

Earlier quoted context omitted.

Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? https://en.wikipedia.org/wiki/Martin_Luther_King_Jr.#NSA_mon...

> Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? Probably 'yes' for you, 'no' for him. Sorry, but a random HN commenter is extremely unlikely to be targeted for the level of surveillance and treachery that Dr King was. If he feared it, he had good reason. If you are some random IT worker building the next smart pillow you cannot expect them to prioritize spying on you, that's…

Fair enough. Though my concern is not for myself, but rather for any potential great leader who could be silently neutralized/blackmailed/extorted by mass surveillance techniques.

Whether the culprits' organizational classification is public or private is of negligible importance.

>Mass surveillance isn't the same as targeted.

Mass surveillance is the first step in the discovery process, targeted surveillance is the second step after a target has been flagged by the dragnet.

Re: Google backs off on previously announced Allo privacy feature

#62
post #25
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

> extremely hard for a Googler or product team to do something directly nefarious

Unless the user is the only party that can access the keys (i.e. they are only stored locally on the user's device), then I'm sure Google will it very easy to access personal information when a government demands access.

Or did we forget that Google is part[1] of PRISM?

[1] https://en.wikipedia.org/wiki/File:Prism_slide_5.jpg

Re: Google backs off on previously announced Allo privacy feature

#63
post #48

Earlier quoted context omitted.

That's really just BS. What's the point of encryption if both the keys and the content is known by Google? They could as well use just SSL and that wouldn't make it safer than this kind of "encryption".

The benefits of this sort of encryption & privacy infrastructure: * Protects you (user) from eavesdroppers between you and Google. * Protects your data from eavesdroppers inside Google's data centers. * Protects your data at rest (on disk). * Protects your data from malicious employees. * Enforces a great deal of scrutiny over who can access your data, and what they are allowed to see. But, yes, they process and stor…

> SSL only handles the first two bullet points.

Only the first point. If Google works like every other data center in the world, then SSL stops the moment your data hits their first load balancer.

Re: Google backs off on previously announced Allo privacy feature

#64
post #3
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Perhaps it's some kind of homeomorphic encryption scheme. Hey it technically leaves the original message encrypted!

As rad as it would be if Google started doing privacy-friendly-ish datamining on user data by homomorphically encrypting it, you and I both know that's not what they're doing. You forgot the `/s`, sadly.

Re: Google backs off on previously announced Allo privacy feature

#65

Earlier quoted context omitted.

It doesn't. They need a constant stream of new data for their business model to work. Thus, they benefit from continuously collecting data on users.

So why do they store indefinitely? If they stated a retention period openly they'd get much less criticism over privacy.

I'd assume for machine learning developments, specifically as training data and back testing. Build a new model with 3x the data you had before or be able to retrospectively see how a model would have performed over 3 years rather than 1.

Re: Google backs off on previously announced Allo privacy feature

#66
post #25
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

I actually trust Google. And I believe they do their best to make it work this way. What I don't trust is the government. :(

Re: Google backs off on previously announced Allo privacy feature

#67
post #26
post #20

Earlier quoted context omitted.

Sure, whatever safe hands mean. Safe in an NSA datacenter. Safe in the hands of the Chinese government. Safe with whatever sysadmin has access to it. Instead of worrying about what "safe hands" mean, just keep it accessible only to me, and each respective conversation with the people I communicate with.

> just keep it accessible only to me One could also argue that the service is free and the service provider needs a (or yet another) way to monetize it. If the privacy settings are insecure by default, one shouldn't have high expectations anyways.

> One could also argue that the service is free and the service provider needs a (or yet another) way to monetize it.

True, which is why I pay Apple money. No incentive to mine my data... in fact given that privacy is a big marketing angle Apple's incentives are to make it impossible for them to access your data even if subpoenaed or presented with a warrant.

Re: Google backs off on previously announced Allo privacy feature

#68
post #25
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

> but you do have to trust Google's privacy infrastructure.

The NSA have already backdoored it.

Re: Google backs off on previously announced Allo privacy feature

#69
And just yesterday someone on HN didn't understand why the recent Google messaging apps weren't being more widely adopted.

It's clear the public wants some assurances around privacy, or at least transparency where it is lacking. Not to mention, this is the umpteenth product they are planning to deprecate, uh, I meant launch (Grand Central, Voice, Wave, Talk, Hang Outs, etc).

Re: Google backs off on previously announced Allo privacy feature

#70
post #37

Earlier quoted context omitted.

The best new friend of Facebook Moxie? His "trust us, we checked FB Messenger code and it's all good" pitch made for a very entertaining read.

Yes, moxie "knows it all" wants to control his apps so much he doesn't want them to be on f-droid https://f-droid.org/posts/security-notice-textsecure/

Do you feel f-droid's build security should be trusted, an if so, why?

>> ""F-Droid has received criticism for distributing out-of-date versions of official applications and for its approach to application signing."

https://en.m.wikipedia.org/wiki/F-Droid

Post reply on HN