Live data from Hacker News

Project Shield

jigsaw.google.com

101–110 of 116 posts

Re: Project Shield

#101
post #93
post #74

Earlier quoted context omitted.

That's the part I took least issue with. >while google is the master of spreading consumer propaganda and spying on people. Equating automated behavioral analysis or ad targeting with willful communications-spying, like NSA does, is retarded. Yes, Google has been guilty of many invasive tactics and holds too much power right now, but claims that they're doing that to "suppress dissent and unpopular opinion" or "sprea…

> Equating automated behavioral analysis or ad targeting with willful communications-spying, like NSA does, is retarded. Implying my two statements, one about spying and the other about consumer propaganda are the same is pretty dishonest bullshit. We know google spies on its users for the NSA and other agencies and we know Google makes its money from consumer propaganda. It's pretty simple. > Equating automated beha…

>We know google spies on its users for the NSA and other agencies

No we don't. For one, every publicly-known piece of evidence suggests that after the Snowden leaks revealed the NSA illegally tapped Google's network connections, they immediately began implementing full transport encryption both between and within their own data centers. You could say they just did that to save face, but no evidence has ever suggested Google has ever wittingly provided the NSA or other agencies with intelligence (excluding responding to NSLs and similar orders).

>Google makes its money from consumer propaganda

Could you elaborate? That's very vague.

>Of course google is responsible for what content it shows in its search engine and other products, and which content providers they reward.

Google claims their news-ranking algorithm is 100% algorithmic and that humans are never involved. Is this true? Who knows. But, again, no one has provided evidence to the contrary yet.

>You seem to have one goal here - defend Google. Somehow other corporations doing wrong is what absolved google (and probably all other corporations) in your eyes. Nice try.

Most private corporations in the US lack transparency. They create tax havens, keep proprietary algorithms secret, and don't tell the public that much about their internal structure and processes. Sometimes lack of transparency is the right of the company, sometimes it's an ethical violation, sometimes both sometimes neither. Again, you'll need to cite specific examples of Google skullduggery for this accusation to hold any weight.

>Nope, they participate in censorship and will remove and website or content from their results if some government (like the US government) asks them to.

Examples?

Re: Project Shield

#102
post #74

Earlier quoted context omitted.

That's the part I took least issue with. >while google is the master of spreading consumer propaganda and spying on people. Equating automated behavioral analysis or ad targeting with willful communications-spying, like NSA does, is retarded. Yes, Google has been guilty of many invasive tactics and holds too much power right now, but claims that they're doing that to "suppress dissent and unpopular opinion" or "sprea…

I mean, if you want to go all out on the "propaganda" and "alongside the NSA" claims, don't just look at advertising. Google Ideas is pretty explicitly about political and government-linked activity. Any tech company can operate alongside the NSA (they don't have much choice), but most of them don't employ Jared Cohen and send their executives to tour Iraq's green zone. I don't want to veer into conspiracy territory…

I haven't read the book and was not aware of some of Google Ideas' more shady activities. Thank you, because otherwise I wouldn't have heard of any of this.

https://en.wikipedia.org/wiki/Jared_Cohen#Involvement_on_Syr...

>In an email addressed to the deputy Secretary of State under Hillary Clinton dated on July 25, 2012, Cohen revealed that Google Ideas was working on a project, together with Al Jazeera, to track defectors of the Syrian Army with the explicit goal of "encouraging more to defect and giving confidence to the opposition."

That is pretty frightening.

Re: Project Shield

#103
post #67

So, does that mean Google (and thus the American State) MitM your website traffic to protect free speech? I am thrilled! I am so happy that at least large corporations that cooperate with the ever-more pervasive surveillance state care about our privacy. /s That's how you defeat HTTPS.

It does mean Google is MitMing you, but this is a service they're providing to organizations that are already at serious risk of DDoS or have been DDoS'd. Like Krebs' site, which was just hit with a 600+ Gbps DDoS.

Plus, I mean, Google Analytics and various Google-owned ads are already present on tons of HTTPS sites. That's enough to nullify HTTPS due to the XSS potential.

How are you getting Google = American State, though?

Re: Project Shield

#104
post #31

Of course I'm not blaming Google or Cloudflare, but it is kind of sad that larger and larger part of the Internet is moving behind their networks. I don't think this kind of centralization is good for the Internet.

It's the feudalism age of the internet. Everyone needs a lord for protection.

The problem is that governments services and organized police and military are effectives solution to many of the problems faced in medieval times.

It's fairly easy to evade attribution, let alone apprehension, if you're a ne'er-do-weller with a broadband connection. You have no option left but to hide inside rich people's castles.

Re: Project Shield

#105
post #70

Earlier quoted context omitted.

The advertised bandwidth for the whole network is much lower than the 600+GBps that's attacking Kerbs it's a little under 200 GBps. https://metrics.torproject.org/bandwidth.html

Tor has too many friends. I dislike the trend of Tor being used to control botnets, but the upside is that an entire underworld now sees tor as an asset. Any non-state attacking Tor would make some very interesting enemies.

Without the particular bot net/what have you taking credit for it do we generally know who is running a DDOS?

Re: Project Shield

#106
post #67

So, does that mean Google (and thus the American State) MitM your website traffic to protect free speech? I am thrilled! I am so happy that at least large corporations that cooperate with the ever-more pervasive surveillance state care about our privacy. /s That's how you defeat HTTPS.

It does mean Google is MitMing you, but this is a service they're providing to organizations that are already at serious risk of DDoS or have been DDoS'd. Like Krebs' site, which was just hit with a 600+ Gbps DDoS. Plus, I mean, Google Analytics and various Google-owned ads are already present on tons of HTTPS sites. That's enough to nullify HTTPS due to the XSS potential. How are you getting Google = American State,…

There is barely a company that visits the white house more than Google. I wouldn't be surprised if the American state has direct access right into Google's data center - it wouldn't be the first company whose server building included a government surveillance room.

Re: Project Shield

#107

Earlier quoted context omitted.

So... Tor?

A network like Freenet would be more appropriate for a situation like this. Its peer to peer nature is like bittorrent, so the more popular content is, the more it is replicated, and thus becomes easier to access. It shouldn't be impossible to design a distributed network that has a positive feedback loop that makes a DDOS counterproductive, by actually boosting the targeted materials.

> so the more popular content is, the more it is replicated, and thus becomes easier to access.

Self censorship.

Re: Project Shield

#108

Earlier quoted context omitted.

I mean, if you want to go all out on the "propaganda" and "alongside the NSA" claims, don't just look at advertising. Google Ideas is pretty explicitly about political and government-linked activity. Any tech company can operate alongside the NSA (they don't have much choice), but most of them don't employ Jared Cohen and send their executives to tour Iraq's green zone. I don't want to veer into conspiracy territory…

I haven't read the book and was not aware of some of Google Ideas' more shady activities. Thank you, because otherwise I wouldn't have heard of any of this. https://en.wikipedia.org/wiki/Jared_Cohen#Involvement_on_Syr... >In an email addressed to the deputy Secretary of State under Hillary Clinton dated on July 25, 2012, Cohen revealed that Google Ideas was working on a project, together with Al Jazeera, to track def…

I'm glad you found it interesting.

I started from Assange's scathing review and decided I had to read the thing for myself. From an inside view, it's just terrible futurism (who wants to read the news on a transparent screen facing a window?), but from an outside view it's a fascinating position paper from Schmidt/Cohen.

I'm usually unimpressed with the "tech companies are all government conspirators!" paranoia, but I do have the sense that Google has chosen a way more active role in international politics than others.

Re: Project Shield

#109
post #48

Earlier quoted context omitted.

At the end, if nation states are helpless on preventing this, and only being part of the problem, I say this - our benevolent feodal overlords - is the preferable solution.

That's what the "benevolent feudal overlords" want everyone to think. From all the defeatist DDoS comments I'd say they're doing a good job at it. As Brian Krebs, myself and numerous other people have pointed out, Cloudflare could end almost all of the DDoS-for-hire attacks in an hour if they actually wanted to https://news.ycombinator.com/item?id=12577289

Sadly, not really true.

* Cloudflare has a growing number of competitors, like Incapsula.

* These services only protect the front-end of the booter websites. These are barebones CRUD apps for managing accounts and typing the IPs you want DDoS'd. It'd be pretty easy to throw that template up on any other server or domain. Most of that whole workflow could be replaced by IRC, Slack, Discord, Skype along with Bitcoin or similar payment methods. As proof, booter sites do still regularly get DDoS'd (usually by exposing their origin server IP or otherwise fucking up configuration) and breached (often exposing the entire user DB and source code) yet pop back up within a few days and still retain most of their customer base.

* They could just move everything to a Tor hidden service, or the equivalent to I2P.

It's the botnet and/or list of IPs and URLs (scripts and shells on compromised servers they planted or paid for access to) that serves the foundation of booter services. If that remains untouched, then the booter can stick around indefinitely.

Cloudflare's CEO reiterates the same points here: https://news.ycombinator.com/item?id=12577690

As for whether they have a moral obligation to stop reverse proxying these sites... I think he makes a pretty good argument for why they should be considered a common carrier. They do forward all abuse reports to the respective hosting providers.

Re: Project Shield

#110
post #48

Earlier quoted context omitted.

At the end, if nation states are helpless on preventing this, and only being part of the problem, I say this - our benevolent feodal overlords - is the preferable solution.

That's what the "benevolent feudal overlords" want everyone to think. From all the defeatist DDoS comments I'd say they're doing a good job at it. As Brian Krebs, myself and numerous other people have pointed out, Cloudflare could end almost all of the DDoS-for-hire attacks in an hour if they actually wanted to https://news.ycombinator.com/item?id=12577289

Yeah, that's pretty simplistic. There's no evidence at all that somehow removing DDOS protection for the payment part of blackmailers web presence will somehow make them go away.

Sure, chase down how they do payment. But ultimately a web front end isn't the thing that makes the payment happen.

Post reply on HN