Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

71–80 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#71
post #40

Earlier quoted context omitted.

Why was it written off? It's using Whisper Systems tech to do it's end-to-end encryption[0]. Is there someway Google could inject itself into this, or some reason people shouldn't trust it? [0] https://whispersystems.org/blog/allo/

There is always a way to inject malicious code in a codebase you control. The Allo apps are closed-source and their code is solely controlled by Google. Doesn't matter which protocols they claim to be using, when they could simply push an update which silently uploads your private keys to their server (or breaks the claim in any of the many different ways). This is the same reason even WhatsApp's use of 'end-to-end e…

so, do you write your own compiler as well?

Re: Google backs off on previously announced Allo privacy feature

#73
post #45
post #38

This seems to be where the "backing off" claim is coming from: http://www.theverge.com/2016/5/18/11699122/google-allo-messa... > First, all conversations are encrypted "on the wire," which means that nobody on the internet can read them as you send your message. They are read by Google's servers, but Kay assures me that the data is stored "transiently," which is to say that Google doesn't keep your chat logs around t…

I lost all my WhatsApp chat history after a phone upgrade went wrong, and it didn't cause me any problems at all. I recognise that my use case is not the same as everyone's, but if I want to save something from WhatsApp, I put it somewhere else.

Yeah, and I normally don't bother to copy over my SMSes. I can, and I appreciate that, but they're really so ephemeral that it's not worth the bother.

Re: Google backs off on previously announced Allo privacy feature

#74
post #48

Earlier quoted context omitted.

The benefits of this sort of encryption & privacy infrastructure: * Protects you (user) from eavesdroppers between you and Google. * Protects your data from eavesdroppers inside Google's data centers. * Protects your data at rest (on disk). * Protects your data from malicious employees. * Enforces a great deal of scrutiny over who can access your data, and what they are allowed to see. But, yes, they process and stor…

The rest of points are not addressed by this sort of encryption because the keys are on disk too. Google employees have access to the keys. It's like leaving the keys into the lock and claiming it's more secure because it has a lock. In practice the data is protected only by ACL. Encryption is just a marketing keyword in this case.

On disk somewhere (encrypted, with a different key) is not the same as "leaving the keys into the lock" in a large distributed system designed to avoid single points of failure.

There are always weaknesses, but think about why a bank employee can't just decide to take your money. Internal controls are a thing.

Re: Google backs off on previously announced Allo privacy feature

#75

Earlier quoted context omitted.

Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? https://en.wikipedia.org/wiki/Martin_Luther_King_Jr.#NSA_mon...

> Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? Probably 'yes' for you, 'no' for him. Sorry, but a random HN commenter is extremely unlikely to be targeted for the level of surveillance and treachery that Dr King was. If he feared it, he had good reason. If you are some random IT worker building the next smart pillow you cannot expect them to prioritize spying on you, that's…

Actually, I'd say a random HN commenter is extremely likely to be targeted for surveillance and exploitation compared to general population at least. Not because they personally are important, but because of their jobs. So many administrators, programmers, etc. with access to relevant data.

Re: Google backs off on previously announced Allo privacy feature

#76
post #25
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

> Which, IIRC, means no human is given direct access without the account holder's permission.

Or compulsion by any government to which Google is responsible (e.g. Russia, if I Googled correctly). Or a suitably clever Googler (as you note, it may be difficult, but 'difficult' ≠ 'cryptographically secure').

As when Facebook didn't think HTTPS made sense until someone sniffed Zuckerberg's password in a coffee shop, I don't think Google (or any other cloud firm) will take security seriously (as opposed to paying lip service to it for marketing purposes) until someone in the C-suite is materially embarrassed by its lack.

Re: Google backs off on previously announced Allo privacy feature

#77
post #27

Earlier quoted context omitted.

> Stay evil. Wow. Google went a full 180 from being a company that promoted itself by saying "Don't be evil" to something evil. Couldn't Google have made its billions still being not evil, without its privacy issues, without its obnoxious desire for tracking everything. Did they turn to this evil for the money or just because they can do it (or if not someone else will).

>Couldn't Google have made its billions still being not evil No. Google is advertising company and advertisement companies need a lot of user data for targeted ads.

Even if they weren't (mainly) an advertising company, even if they charged for all the free things, they'd still need all the data they suck in to provide services they provide.

Re: Google backs off on previously announced Allo privacy feature

#78
post #76
post #25

Earlier quoted context omitted.

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

> Which, IIRC, means no human is given direct access without the account holder's permission. Or compulsion by any government to which Google is responsible (e.g. Russia, if I Googled correctly). Or a suitably clever Googler (as you note, it may be difficult, but 'difficult' ≠ 'cryptographically secure'). As when Facebook didn't think HTTPS made sense until someone sniffed Zuckerberg's password in a coffee shop, I do…

"Russia, if I Googled correctly." You clearly trust Google to some extent, since you search with it.

I don't think you can accuse Google of not taking security seriously. They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make, and a legitimate thing to criticize them for. Apple makes a different choice, and it's important that we have a debate around which is the right security design.

But making a claim that Google is not serious about security does a disservice to the really good people there who move mountains to secure the service.

Re: Google backs off on previously announced Allo privacy feature

#79
post #76

Earlier quoted context omitted.

> Which, IIRC, means no human is given direct access without the account holder's permission. Or compulsion by any government to which Google is responsible (e.g. Russia, if I Googled correctly). Or a suitably clever Googler (as you note, it may be difficult, but 'difficult' ≠ 'cryptographically secure'). As when Facebook didn't think HTTPS made sense until someone sniffed Zuckerberg's password in a coffee shop, I do…

"Russia, if I Googled correctly." You clearly trust Google to some extent, since you search with it. I don't think you can accuse Google of not taking security seriously. They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make, and a legitimate thing to criticize them for. Apple makes a different choice, and it's important that we have a d…

> I don't think you can accuse Google of not taking security seriously.

I don't think they take my security, and the security of my data, seriously. They seem to care very much about their security.

> They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make

No, at this point I don't believe that it is legitimate, any more than it's legitimate to sell an oven which will explode if the temperature dial is set above 600° ('just don't set it that high!').

Yes, there are people at Google who work very hard to secure Google's data; there are people at Google (e.g. Adam Langley) who care a lot about users' data. There may even be people at Google who are working very hard to change its course on user privacy.

But Google, the company, does not take the security of user data against privacy threats seriously: if it did, it would use a better architecture (note that Apple doesn't take user-data security seriously, either, since they can MITM any time they want; nor does Mozilla, nor does Microsoft: no organization's hands are clean, so far as I can tell).

Post reply on HN