Live data from Hacker News

Google’s Secret China Project “Effectively Ended” After Internal Confrontation

theintercept.com

51–60 of 372 posts

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#51
post #24

Earlier quoted context omitted.

The point of end-to-end encryption is that Apple doesn't have any keys to give.

How do you know? Have you audited the source code of the software?

Have you audited the code for Signal's app? Have you built and installed the app from that audited source?

Asking "have you audited the source" is such a meaningless question when you're not building from source (and auditing the compiler...), which practically nobody, not even HN users, are doing.

Please read Reflections on trusting trust and rethink what your threat model is, and what you consider "secure". https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#52

Earlier quoted context omitted.

We are talking about google here.

It's hypocritical to attack Google for moving back to China after pulling out 7 years ago while other companies have been there continuously for years without backlash.

Google's previous stance was much more understandable: Let the Great Firewall do its work and we'll do ours.

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#53
post #46
post #45

Earlier quoted context omitted.

What is DPI equipment? I’m not familiar with the acronym.

Deep Packet Inspection [0] [0]: https://en.wikipedia.org/wiki/Deep_packet_inspection

Doesn't TLS defeat this?

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#54
post #2

Great reporting by Gallagher. He should win a Pulitzer for his reporting on Dragonfly. The fact that Pichai refused to say they wouldn't re-enter China shows this is probably just a pause until things die down.

>just a pause

Exactly. It's the same tactic employed with various authoritarian measures such as the DMCA, TPP, SOPA, etc. Unpalatable to the public is a temporary condition. They overplayed their hand this time, but corporations are slaves to the inexorable demands of "shareholder value", and those who stand to profit will ratchet up the pressure, notch by notch. This will be back in a year, and then a year hence, and by the Nth exposure the public will have been sufficiently desensitized to it.

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#55
post #46

Earlier quoted context omitted.

Deep Packet Inspection [0] [0]: https://en.wikipedia.org/wiki/Deep_packet_inspection

Doesn't TLS defeat this?

Not necessarily. You are correct in that you can't look at the literal messages inside the packets anymore but you can make educated assumptions based on usage patterns and packet sizes combined with data that's already in the header. Just take a look at this almost 3 year old submission detailing someone's experience with the Great Firewall: https://news.ycombinator.com/item?id=10905076

Since that was 3 years ago, I suspect there's much more advanced network wizardry available today.

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#56

Earlier quoted context omitted.

It's hypocritical to attack Google for moving back to China after pulling out 7 years ago while other companies have been there continuously for years without backlash.

Google's previous stance was much more understandable: Let the Great Firewall do its work and we'll do ours.

If that's acceptable, then why was this unacceptable? Isn't this project mostly about figuring out whats blocked and caching that?

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#57
post #46

Earlier quoted context omitted.

Deep Packet Inspection [0] [0]: https://en.wikipedia.org/wiki/Deep_packet_inspection

Doesn't TLS defeat this?

No, the DPI box or another network box should be the one that is actually sending the cert. You are only exchanging a cert with DPI and then the DPI will send it’s cert to your destination.

The client must trust the DPI cert for it to work.

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#59

Earlier quoted context omitted.

Apple has a very significant manufactoring presence in China, so unfortunately they can't cleanly separate from China like Google can without risking retaliation Apple can walk away from China whenever it wants to. Apple is the one company in the entire world best equipped with the cash to make this kind of public stand. But it doesn't want to because doing so will cost a lot of that money. The only thing stopping Ap…

> Apple can walk away from China whenever it wants to. Not unless they've spent the last decade building a secret duplicate supply chain ecosystem.

Complete with access to rare earth metal deposits that are currently secret from the world.

Re: Google’s Secret China Project “Effectively Ended” After Internal Confrontation

#60
post #26

Earlier quoted context omitted.

I assumed that Apple has very similar weight on a resume as Google, is that not correct?

I'm sure there is weight in having Apple on your resume but Google engineers are generally sought after for SE positions. I hear managers pining over Google candidates all the time at my company.

Arguing about which company's name looks better on a resume is an irrelevant distraction that avoids addressing the actual problem: standing up to fight against something may require personal sacrifices. In general, anybody with salary has the opportunity to quit. This is certainly true for most tech jobs.

I understand if someone working variable part time[1] hours for minimum wage cannot afford to lose their job. There isn't any room for sacrifices when you already have to e.g. decide each month if you can afford to pay for both food and utilities, or if you aren't going to have hot water for a while[2]. Yet even though they face far higher risks than the average tech worker, sometimes they still choose to make sacrifices[3].

Yes, you might get fired. You might have to adjust your standard of living. Banding together into larger groups can help to mitigate some of these costs, but regardless, the average tech worker is fortunate enough to be able to make a significant sacrifice.

[ This is why some of us try to warn about growing problems early, when the cost of counteraction is low. Unfortunately, most people decide to ignore the problem because it isn't an obvious, widespread, damaging problem. ~sigh~ ]

[1] different, computer-optimized schedule each week, could be anything that still counts as part time (including 0)

[2] https://medium.com/@sarahkendzior/the-minimum-wage-worker-st...

[3] https://en.wikipedia.org/wiki/Fight_for_$15

Post reply on HN