Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

121–130 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#121
post #75

Earlier quoted context omitted.

Actually, I'd say a random HN commenter is extremely likely to be targeted for surveillance and exploitation compared to general population at least. Not because they personally are important, but because of their jobs. So many administrators, programmers, etc. with access to relevant data.

Yes, I almost mentioned the Belgacom sysadmins in one of my responses. How many people here work for Google, Facebook, Apple, etc? What if you could compromise their workstations and get privileged access to the backend of social networks, email systems, etc? We are being actively hunted and there's evidence of that.

Some years ago FreeBSD had an intrusion via one of the commiter's machine or stolen SSH key, I don't remember which any more, but I do remember that it took months for the package building infrastructure to get fully operational again. I think they never got to the bottom of that (who did it or why). Linux had a very similar incident if I'm not mistaken.

It's such a standard and effective method in human intelligence, that it's extremely naive to think an analogue wouldn't be used extensively in signals intelligence too.

Re: Google backs off on previously announced Allo privacy feature

#122
post #101
post #87

Earlier quoted context omitted.

They could be using some form of homomorphic encryption here, in which case it would still be meaningfully encrypted.

Homomorphic encryption isn't currently practical, even for small-ish problems. It needs to use constant space, and every operation needs to flip on average half of the bits. There aren't obvious ways around these restrictions, though off hand I can only come up with a quick hand-wavy "proof" that this must always be so if less than one bit of the unencrypted state is to be lost with every state update. So, in order t…

That is only true for fully homomorphic encryption. There are simpler cryptosystems (e.g. ElGamal for a trivial example) that have more constrained homomorphisms that theoretically could be used here.

Re: Google backs off on previously announced Allo privacy feature

#123
post #56
post #37

Earlier quoted context omitted.

The best new friend of Facebook Moxie? His "trust us, we checked FB Messenger code and it's all good" pitch made for a very entertaining read.

Aware of that issue (asked moxie about it on HN) and other issues too, but it doesn't change that there's zero reason to believe Moxie's intent is malicious and it's a stretch by any means to claim his contributions are anything but positive in sum.

I'm not sure why Moxie gets so much grief on some of these issues. To his credit, he's released just about everything under a free software license -- with reproducible builds and all.

Ultimately, it's his baby and he can do what he wants with it.

Re: Google backs off on previously announced Allo privacy feature

#124
post #25
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

This is the first time I'm reading about that sort of restrictions at Google. What are your sources? Or did/do you work there?

Still, I wouldn't trust that. I can think of enough cases in which algorithms fed with that information would do things not in my interests. (You could easily imagine some internal scoring or profiling a lgorithms taking advantage of the data for example)

Telling "it's only algorithms" doesn't make it secure it I don't know what the algorithms do. (Which of course I can't as it is the core of their busyness)

Re: Google backs off on previously announced Allo privacy feature

#125
post #97

Earlier quoted context omitted.

Google's business is based on destroying what you and I consider to be privacy, so I don't see how you could expect them to change their minds about that. Google and similar companies have a coherent worldview in which they collect user data, protect it from outsiders and inside threats, and do benign and wonderful things for users in return. Within that worldview, they do an excellent and commendable job. Calling th…

> I'm curious about your comments on Apple. If I back up my phone to iCloud, how can Apple "MITM any time they want"? I was referring to iMessage: my understanding is that it Apple is the CA for all iMessage keys, and thus they can issue a certificate to anyone, if they wish to or are compelled to.

Theoretically, just like they could prepare a broken version of iOS that disables security and push it to targeted users. In reality, such a software/infrastructure does not exist today, and we've been shown what happens when Apple is asked to write it.

Re: Google backs off on previously announced Allo privacy feature

#126

Earlier quoted context omitted.

> A fair percentage of people (myself included) are far more concerned about protecting our data from marketers, advertisers, and data brokers, than we are about going 100% 'tinfoil hat' mode and worrying whether the NSA is monitoring my messages for thought crimes. The main issue here is that people aren't worried about either of those problems :) otherwise Facebook, Google and other advertising companies would only…

> we should fight together for more privacy It needs to be established as a human right. I'm personally very disappointed to see the how good intentions of the aware subset of the citizenry are consistently channeled towards technical solutions to a problem that is fundamentally political . At a meta-level, we saw the same (useless) dissipation of energies in the Occupy-x movement. And it should also be pointed out t…

It needs to be established as a human right.

It already is. Article 12 of the universal declaration of human rights:

No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.

Re: Google backs off on previously announced Allo privacy feature

#127

Earlier quoted context omitted.

>> Internal controls are a thing. That's what ACL is...The encryption doesn't improve the security of the data if the keys are not stored securely. Simply put the data security is as good as the ACL of the keys is. For your peace of mind you may want to know the processes(i.e. audits, ISO standards/certifications) rather than a marketing keyword("encryption", "military grade" etc). Encryption may be part of that fram…

I think you're defining "security" and "privacy" to mean what you want them to mean. The absolutist definition that's popular in certain circles isn't the common definition. Privacy is mostly not about keeping data from the government. Your bank account is private for most practical purposes though I'm sure with a warrant, law enforcement can find out about it. It's not going to show up in the news and your competito…

You and me have different views about privacy. I think you should have control over your data. Google indirectly provides your email information to advertisers. Example: You receive a flight notification. Google reads your email and targets you with ads related to your trip(i.e. hotels, things to do etc based on your age, gender etc) though various channels(i.e. gmail UI, google search, Google Now/AI etc). It wants to do the same with this Allo application. The encryption they claim it's in place it's worthless because it doesn't protect you from this. They try to claim your data is `private` because it's encrypted.

The other case which is uglier is that Google gives your data to foreign governments or other agencies. This may have great consequences. Cloud computing is based on trust and it's possible because the main players(i.e. US government, cloud providers such Amazon) are trusted not to spy their clients but I don't see many rushing to a chinese cloud vendor to host critical data(i.e. email) on their servers.

The security and privacy features we have are currently based on the good will of the provider (i.e. Google). If we talk about encryption of personal data I think it's worth to ask a bit more than a buzzword. One such thing is to do not share the encryption keys.

Re: Google backs off on previously announced Allo privacy feature

#128
post #100

Earlier quoted context omitted.

> SSL only handles the first two bullet points. Only the first point. If Google works like every other data center in the world, then SSL stops the moment your data hits their first load balancer.

Google does not work like every other data center in the world. All internal services communicate over SSL (or similarly encrypted links)

I think the load-balancers do not communicate over SSL. At least not the ones in front of Appengine applications. Perhaps only inter-services communication is encrypted(i.e. app service with database service).

Re: Google backs off on previously announced Allo privacy feature

#129
post #102

Earlier quoted context omitted.

Most datancenters are lost once the internal network is hacked so I think that's a different issue. Encryption wouldn't help either because the attacker could get the keys too.

Encrypted links between processes inside a data center is still a good thing: It protects against malicious actors sniffing traffic (without compromising the machines in the data center)

So again... how is this better than end to end SSL?

Re: Google backs off on previously announced Allo privacy feature

#130
post #56

Earlier quoted context omitted.

Aware of that issue (asked moxie about it on HN) and other issues too, but it doesn't change that there's zero reason to believe Moxie's intent is malicious and it's a stretch by any means to claim his contributions are anything but positive in sum.

I'm not sure why Moxie gets so much grief on some of these issues. To his credit, he's released just about everything under a free software license -- with reproducible builds and all. Ultimately, it's his baby and he can do what he wants with it.

While speculation, Moxie's projects appear to have gotten (deservedly) a lot of attention, which brings a lot of feedback that's unfounded and potential malicious; for example, the f-droid comment about in my opinion fails to reflect both sides of the issue, and build security is VERY IMPORTANT and often ignored.

I don't know Moxie, but we've exchange messages before and never got the sense that off the cuff he was discounting any feedback. At a very highly level we agree about what he's doing, though I get the sense that anonymity is something we don't exactly agree about, but do understand a little of why he feels the way he does.

Post reply on HN