Live data from Hacker News

Gmail security warnings for suspected state-sponsored attacks

googleonlinesecurity.blogspot.com

31–40 of 123 posts

Re: Gmail security warnings for suspected state-sponsored attacks

#31
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

In other news: I offer 50 bitcoins to anyone who can get me at least 5 or 10 good screenshots of the features and UI of the (presumably web) interface that Google provides to the feds for NSL/PATRIOT (un)"lawful intercept". 10 bitcoins for each of any other Alexa-top-50 provider (e.g. hotmail, FB, etc).

Anonymous mails accepted at sneak@datavibe.net. Include bitcoin address for payment. Don't bother with fakes - I've seen quite a few 'shops in my time, and can tell from some of the pixels.

Re: Gmail security warnings for suspected state-sponsored attacks

#33
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

The difference between rights in America and China are vast. Criticizing legitimate American counter-terrorism and counter espionage and suggesting that it's equivalent to China's suppression of thought of its citizens (and people in occupied zones like Tibet) are disingenuous. Dissent in China will get you a prison sentence or worse. Dissent in America will get your karma modded down. (Q.E.D) Want more relevant wikipedia links? click here : http://en.wikipedia.org/wiki/September_11_attacks AND here http://en.wikipedia.org/wiki/Internet_censorship_in_the_Peop...

Re: Gmail security warnings for suspected state-sponsored attacks

#34
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

> USA reading your mail: Business as usual.

According to the first paragraph of the article you linked:

"NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from."

According to the sample NSL from the article you linked:

"We are not directing that you provide, and you should not provide, information pursuant to this letter that would disclose the content of any electronic communication. [...] Subject lines of emails and message content are content information and should not be provided pursuant to this letter."

So NSL is not the USA "reading your email."

I'm not defending the NSL, but I am opposed to misinformation, as well as the frequent attempts to paint the USA as being just as bad as China.

Re: Gmail security warnings for suspected state-sponsored attacks

#35
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

> NSLs can only request non-content information

NSLs can't legally request ANYTHING. They are UNCONSTITUTIONAL. The government has NO AUTHORITY to issue them. The fact that they are presently limiting themselves to illegal request x instead of illegal request y is not relevant.

Let's skip the abuses of the FBI et al and talk about the government as a whole for a minute.

Are you aware that the NSA monitors _all_ traffic at major exchanges in the US?

http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_co...

The USA reads your mail and messages at several different steps along the way.

See also: recent changes in Skype to allow for wiretapping at the request of the US government.

Re: Gmail security warnings for suspected state-sponsored attacks

#36
post #23
post #16

Why the emphasis on state sponsored attacks? (I am aware of stuxnet/flame/sanger's book) If google knows I am being targeted by a non-state actor are they choosing not to notify me? Are we going back to a cold war mentality where the only credible attacks are state sponsored?

State-sponsored attackers have access to much better resources. I do wonder how they determine who gets these things; do they look for keywords in your email, or do they monitor where login attempts are happening, or do they look at phishing messages that arrive at your account?

State-sponsored attackers also likely choose different targets. I'm not afraid to be a victim of such attack, but if I worked eg. as a diplomat, or as a defence contractor, or any government agency, I might actually be worried. There were some examples of attacks lately that targeted US government officials. So I guess Google shows this warning primarily to people who might be probable targets of state-sponsored attacks in the first place.

Re: Gmail security warnings for suspected state-sponsored attacks

#37
post #31
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

In other news: I offer 50 bitcoins to anyone who can get me at least 5 or 10 good screenshots of the features and UI of the (presumably web) interface that Google provides to the feds for NSL/PATRIOT (un)"lawful intercept". 10 bitcoins for each of any other Alexa-top-50 provider (e.g. hotmail, FB, etc). Anonymous mails accepted at sneak@datavibe.net. Include bitcoin address for payment. Don't bother with fakes - I've…

Wasn't the core of the ThinkSecret lawsuit related to enticing people to break confidentiality agreements? Maybe this offer should be restricted to legally obtained and propagated screenshots.

Re: Gmail security warnings for suspected state-sponsored attacks

#38
post #8

Earlier quoted context omitted.

How about the steps noted in the post? Make sure you have a good password, use two-factor authentication, and be careful about clicking on any login links? It could also be incentive to change accounts, or change to a different communication mechanism. As long as this warning is triggered by actual data, I am not sure how you could categorize it as "FUD" or even political activism. Hacking into accounts should not be…

> Here are some things you should do immediately: create a unique password that has a good mix of capital and lowercase letters, as well punctuation marks and numbers; enable 2-step verification as additional security; and update your browser, operating system, plugins, and document editors. Attackers often send links to fake sign-in pages to try to steal your password, so be careful about where you sign in to Google…

Don't forget that government officials, defense contractors, etc. also use Google products. Not all hacking is criminal or local. Some of it is geopolitical in nature.

Re: Gmail security warnings for suspected state-sponsored attacks

#39
post #35

Earlier quoted context omitted.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

> NSLs can only request non-content information NSLs can't legally request ANYTHING. They are UNCONSTITUTIONAL. The government has NO AUTHORITY to issue them. The fact that they are presently limiting themselves to illegal request x instead of illegal request y is not relevant. Let's skip the abuses of the FBI et al and talk about the government as a whole for a minute. Are you aware that the NSA monitors _all_ traff…

'haberman's comment includes actual information. Can we not punish people for posting information? I doubt very much that 'haberman approves of NSLs, especially since he said as much.

Moreover, your comment may actually be incorrect; a good chunk of all the mail Gmail handles is never on the wire in a format that can be decrypted with any known attack without access to Google's (often pinned) secret keys. The NSA's ability to snarf it off the wire, stipulated, does not connote their ability to read it.

Re: Gmail security warnings for suspected state-sponsored attacks

#40
Live from the scene: my partner just found that she wasn't able to log in to her Gmail account because her password was suddenly invalid. Luckily she was able to reset it quickly and regain control of the account. When she checked the recent activity, though, it showed that all logins in the past 12 hours came from her IP.
Post reply on HN