Live data from Hacker News

Google backs off on previously announced Allo privacy feature

theverge.com

131–133 of 133 posts

Re: Google backs off on previously announced Allo privacy feature

#131
post #122
post #101

Earlier quoted context omitted.

Homomorphic encryption isn't currently practical, even for small-ish problems. It needs to use constant space, and every operation needs to flip on average half of the bits. There aren't obvious ways around these restrictions, though off hand I can only come up with a quick hand-wavy "proof" that this must always be so if less than one bit of the unencrypted state is to be lost with every state update. So, in order t…

That is only true for fully homomorphic encryption. There are simpler cryptosystems (e.g. ElGamal for a trivial example) that have more constrained homomorphisms that theoretically could be used here.

The OP was talking about encrypting the chat data and performing machine learning on encrypted data without decrypting it. I really wouldn't know where to begin to construct such a thing using a simpler cryptosystem, such as ElGamal. Do you have any hints as to where to begin?

Re: Google backs off on previously announced Allo privacy feature

#132
post #25
post #2

>Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms. 'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

Probably stored under the same security infrastructure as Gmail and hangouts messages. Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point) It's extremely hard for a Googler or product team…

In order to receive government protection and favors, they have to play their game. Its not like their advertisement profiling algorithms isn't useful for intelligence gathering and profiling.

Re: Google backs off on previously announced Allo privacy feature

#133
post #99

Earlier quoted context omitted.

That's easy, TLS is great for Google as ISPs and wifi providers can't replace ads with their own in transit.

That is some Alex Jones level reasoning. There's no end-user security you can provide that can't be reframed that way.

Belatedly seen this. For the record I just want to note that I claimed that Google have sound business reasons to promote TLS, i.e. that their ads can't be MITMed. I have no clue why tptacek would go ballistic at that suggestion.
Post reply on HN