Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

111–120 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#111

Earlier quoted context omitted.

On disk somewhere (encrypted, with a different key) is not the same as "leaving the keys into the lock" in a large distributed system designed to avoid single points of failure. There are always weaknesses, but think about why a bank employee can't just decide to take your money. Internal controls are a thing.

>> Internal controls are a thing. That's what ACL is...The encryption doesn't improve the security of the data if the keys are not stored securely. Simply put the data security is as good as the ACL of the keys is. For your peace of mind you may want to know the processes(i.e. audits, ISO standards/certifications) rather than a marketing keyword("encryption", "military grade" etc). Encryption may be part of that fram…

I think you're defining "security" and "privacy" to mean what you want them to mean. The absolutist definition that's popular in certain circles isn't the common definition.

Privacy is mostly not about keeping data from the government. Your bank account is private for most practical purposes though I'm sure with a warrant, law enforcement can find out about it. It's not going to show up in the news and your competitors aren't going to see your bank statements.

Also, Google isn't handing your private email over to advertisers - never has, probably never will.

Authentication and authorization (ACL's) are useful for both security and privacy. This is what makes cloud computing possible (along with encryption, too).

Yes, we can talk about weaknesses in our systems, but let's not completely dismiss the security and privacy features that are already there.

Re: Google backs off on previously announced Allo privacy feature

#112
post #25
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

It doesn't matter how well its designed. Once they get an NSL, they would need to make compromises, unless the messages are not in a readable form.

All that Google has accomplished, is convinced me to steer clear of Allo.

Re: Google backs off on previously announced Allo privacy feature

#113
post #6

These privacy articles make a big deal about law enforcement being able to access messages. Surely a much bigger concern is Google being able to access the content?

Unlike law enforcement however, Google has a much higher level of trust in the public eye.

Re: Google backs off on previously announced Allo privacy feature

#114
post #27

First thing I thought when saw the release of this app is that it will record everything I do because it's google. Thanks but no thanks, google. Stay evil.

> Stay evil. Wow. Google went a full 180 from being a company that promoted itself by saying "Don't be evil" to something evil. Couldn't Google have made its billions still being not evil, without its privacy issues, without its obnoxious desire for tracking everything. Did they turn to this evil for the money or just because they can do it (or if not someone else will).

Google is a company that uses algorithms to sell ad space to you. How is a company not evil when you are the product?

Re: Google backs off on previously announced Allo privacy feature

#115
post #104
post #100

Earlier quoted context omitted.

Google does not work like every other data center in the world. All internal services communicate over SSL (or similarly encrypted links)

Though only because they discovered their internal unencrypted links were being systematically compromised on a truly massive scale for years.

False. There was already internal encrypted traffic and the revelations only sped up the migration for the rest.

https://www.washingtonpost.com/business/technology/google-en...

Re: Google backs off on previously announced Allo privacy feature

#116
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

There is actually some research work on this front because it is highly valuable to analyze some data but not have access to it.

However, it's better just to encrypt everything and not be tempted by the advertising surveillance dollars.

Re: Google backs off on previously announced Allo privacy feature

#117
post #96

Earlier quoted context omitted.

A fair percentage of people (myself included) are far more concerned about protecting our data from marketers, advertisers, and data brokers, than we are about going 100% 'tinfoil hat' mode and worrying whether the NSA is monitoring my messages for thought crimes. These are two very distinct issues and not everyone is concerned about both equally.

One of those things can kill you, or imprison you. The other one can send you mildly annoying ads.

>The other one can send you mildly annoying ads.

That isn't quite accurate. Your information is extremely valuable for identity thieves and for spammers and for running other scams. I guess you've never had your identity stolen or been harassed.

Re: Google backs off on previously announced Allo privacy feature

#118

Earlier quoted context omitted.

Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? https://en.wikipedia.org/wiki/Martin_Luther_King_Jr.#NSA_mon...

> Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? Probably 'yes' for you, 'no' for him. Sorry, but a random HN commenter is extremely unlikely to be targeted for the level of surveillance and treachery that Dr King was. If he feared it, he had good reason. If you are some random IT worker building the next smart pillow you cannot expect them to prioritize spying on you, that's…

Actually a random HN commenter is precisely the person to target, they're more likely to have technical skills and access to servers. It isn't just about surveillance it's about increased attack vectors when your information is distributed.

A random IT worker building the next smart pillow has no reason to target you...but the creepy pervy sales manager at the same company might have reason to.

Re: Google backs off on previously announced Allo privacy feature

#119
post #24

Earlier quoted context omitted.

Ifmeaningful homomorphic encryption was an option, then we'd be living in a quite different world.

Surprisingly, homomorphic encryption is now practical enough to run a Kaggle-like data science competition, but without disclosing data. At least one such competition is known to run with real money prize. https://medium.com/@Numerai/encrypted-data-for-efficient-mar...

This reads like fake smoke and mirrors to trick investors/data providers/participants instead of anything that's real cryptographically.

Re: Google backs off on previously announced Allo privacy feature

#120
post #75

Earlier quoted context omitted.

> Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"? Probably 'yes' for you, 'no' for him. Sorry, but a random HN commenter is extremely unlikely to be targeted for the level of surveillance and treachery that Dr King was. If he feared it, he had good reason. If you are some random IT worker building the next smart pillow you cannot expect them to prioritize spying on you, that's…

Actually, I'd say a random HN commenter is extremely likely to be targeted for surveillance and exploitation compared to general population at least. Not because they personally are important, but because of their jobs. So many administrators, programmers, etc. with access to relevant data.

Yes, I almost mentioned the Belgacom sysadmins in one of my responses.

How many people here work for Google, Facebook, Apple, etc? What if you could compromise their workstations and get privileged access to the backend of social networks, email systems, etc? We are being actively hunted and there's evidence of that.

Post reply on HN