Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

81–90 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#81

Earlier quoted context omitted.

There is always a way to inject malicious code in a codebase you control. The Allo apps are closed-source and their code is solely controlled by Google. Doesn't matter which protocols they claim to be using, when they could simply push an update which silently uploads your private keys to their server (or breaks the claim in any of the many different ways). This is the same reason even WhatsApp's use of 'end-to-end e…

so, do you write your own compiler as well?

Repost

Re: Google backs off on previously announced Allo privacy feature

#82
post #31

Earlier quoted context omitted.

How is that relevant to the fact that many people are more worried about marketers than the NSA? Nobody's questioning that some people are in fact so monitored. "I am more concerned about A than B" is not a claim that B does not exist, nor is it a claim that "I" am unconcerned about B.

>the fact that many people are more worried about marketers than the NSA? How do you know this is a fact , was a global survey done? >I am more concerned about A than B" is not a claim that B does not exist, nor is it a claim that "I" am unconcerned about B. Indeed, however the phrase "100% tinfoil hat mode" does imply being unconcerned about B, and that anyone who is is a lunatic.

You seem to have a problem with adjectives. "Many" is not most. I don't need a "survey" to establish the "many" when I can just read many people expressing their concerns on HN. That's "many" enough for me.

Now, to be clear, by "people" I mean "humans" not "abstract sentients including AIs that don't yet exist", and by "concerns" I mean "things that are at least slightly negative to the thinker" and not "things that keep the thinker up at night wetting the bed and driving them to fits of existential madness", etc. etc.

Re: Google backs off on previously announced Allo privacy feature

#83
post #79

Earlier quoted context omitted.

"Russia, if I Googled correctly." You clearly trust Google to some extent, since you search with it. I don't think you can accuse Google of not taking security seriously. They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make, and a legitimate thing to criticize them for. Apple makes a different choice, and it's important that we have a d…

> I don't think you can accuse Google of not taking security seriously. I don't think they take my security, and the security of my data, seriously. They seem to care very much about their security. > They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make No, at this point I don't believe that it is legitimate, any more than it's legitima…

Google's business is based on destroying what you and I consider to be privacy, so I don't see how you could expect them to change their minds about that.

Google and similar companies have a coherent worldview in which they collect user data, protect it from outsiders and inside threats, and do benign and wonderful things for users in return. Within that worldview, they do an excellent and commendable job. Calling their beliefs on data collection a security issue muddies the debate.

I'm curious about your comments on Apple. If I back up my phone to iCloud, how can Apple "MITM any time they want"?

Re: Google backs off on previously announced Allo privacy feature

#84
post #30
post #25

Earlier quoted context omitted.

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

I don't think that is enough. Here we are relying on Google being magnanimous enough to not use the data to increase their profitability. And even beyond that, your opinion is a little naive to hold in a post-snowden world.

How is it necessarily wrong if Google uses the data to increase their profitability?

Re: Google backs off on previously announced Allo privacy feature

#85
post #76
post #25

Earlier quoted context omitted.

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

> Which, IIRC, means no human is given direct access without the account holder's permission. Or compulsion by any government to which Google is responsible (e.g. Russia, if I Googled correctly). Or a suitably clever Googler (as you note, it may be difficult, but 'difficult' ≠ 'cryptographically secure'). As when Facebook didn't think HTTPS made sense until someone sniffed Zuckerberg's password in a coffee shop, I do…

A "suitably clever Googler", an insider threat, is something that Google actively defends against, at multiple levels. The general assumption is that you can't blindly trust internal users, devices, etc. See the BeyondCorp paper for an example. The internal security infrastructure (monitoring, logging, auditing, analysis) probably consumes more CPU cycles than what's needed to run a large number of entire business out there, especially after the China incident -- remember who alerted the 30+ companies that got infiltrated.

The security whitepaper gives only a hint of what's done, such as checks on former employees' accounts and so on:

https://static.googleusercontent.com/media/1.9.22.221/en//en...

Re: Google backs off on previously announced Allo privacy feature

#86
post #25

Earlier quoted context omitted.

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

I actually trust Google. And I believe they do their best to make it work this way. What I don't trust is the government. :(

Bad news then... Google is not what it seems. http://www.newsweek.com/assange-google-not-what-it-seems-279...

Re: Google backs off on previously announced Allo privacy feature

#87
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

They could be using some form of homomorphic encryption here, in which case it would still be meaningfully encrypted.

Re: Google backs off on previously announced Allo privacy feature

#88

Earlier quoted context omitted.

It doesn't. They need a constant stream of new data for their business model to work. Thus, they benefit from continuously collecting data on users.

So why do they store indefinitely? If they stated a retention period openly they'd get much less criticism over privacy.

Don't forget that they're also entirely complicit to NSA demands for live access to data as well, per the somewhat-recent leaks. That's another level of evil above regular profit motivations.

Re: Google backs off on previously announced Allo privacy feature

#89

Earlier quoted context omitted.

The rest of points are not addressed by this sort of encryption because the keys are on disk too. Google employees have access to the keys. It's like leaving the keys into the lock and claiming it's more secure because it has a lock. In practice the data is protected only by ACL. Encryption is just a marketing keyword in this case.

On disk somewhere (encrypted, with a different key) is not the same as "leaving the keys into the lock" in a large distributed system designed to avoid single points of failure. There are always weaknesses, but think about why a bank employee can't just decide to take your money. Internal controls are a thing.

>> Internal controls are a thing.

That's what ACL is...The encryption doesn't improve the security of the data if the keys are not stored securely. Simply put the data security is as good as the ACL of the keys is. For your peace of mind you may want to know the processes(i.e. audits, ISO standards/certifications) rather than a marketing keyword("encryption", "military grade" etc). Encryption may be part of that framework but I don't think it's relevant enough to be advertised as a stand alone 'product'. You can be sure that your account balance is not encrypted. It's the ACL process that protects you from a rough employee.

We already know that Google has a relative good security process in place. However this is not about security in the first place. It's about privacy. And here encryption brings no privacy gain because Google has the keys so as I previously said it's just marketing BS. Most people are not worried that Google gets hacked. They are worried that Google is selling their data to 3rd parties for profit and to governments for political reasons.

Re: Google backs off on previously announced Allo privacy feature

#90

Earlier quoted context omitted.

The rest of points are not addressed by this sort of encryption because the keys are on disk too. Google employees have access to the keys. It's like leaving the keys into the lock and claiming it's more secure because it has a lock. In practice the data is protected only by ACL. Encryption is just a marketing keyword in this case.

On disk somewhere (encrypted, with a different key) is not the same as "leaving the keys into the lock" in a large distributed system designed to avoid single points of failure. There are always weaknesses, but think about why a bank employee can't just decide to take your money. Internal controls are a thing.

[deleted]
Post reply on HN