Live data from Hacker News

Gmail security warnings for suspected state-sponsored attacks

googleonlinesecurity.blogspot.com

41–50 of 123 posts

Re: Gmail security warnings for suspected state-sponsored attacks

#41
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

Because this is an attack that doesn't go through the official legal process Google is required to abide by. If Google were to find that the US gov was distributing malware to hack into Gmail accounts without Google or users knowing I hope they would react the same way. I doubt we will ever find out for sure though.

Re: Gmail security warnings for suspected state-sponsored attacks

#42
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

Because this is an attack that doesn't go through the official legal process Google is required to abide by. If Google were to find that the US gov was distributing malware to hack into Gmail accounts without Google or users knowing I hope they would react the same way. I doubt we will ever find out for sure though.

Re: Gmail security warnings for suspected state-sponsored attacks

#43
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

Because this is an attack that doesn't go through the official legal process Google is required to abide by. If Google were to find that the US gov was distributing malware to hack into Gmail accounts without Google or users knowing I hope they would react the same way. I doubt we will ever find out for sure though.

Re: Gmail security warnings for suspected state-sponsored attacks

#44
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

I understand as a hacker that you want to provide the truth, but the way to stop these letters isn't to downplay their danger, but to make people scared to death of them.

Re: Gmail security warnings for suspected state-sponsored attacks

#45
post #39
post #35

Earlier quoted context omitted.

> NSLs can only request non-content information NSLs can't legally request ANYTHING. They are UNCONSTITUTIONAL. The government has NO AUTHORITY to issue them. The fact that they are presently limiting themselves to illegal request x instead of illegal request y is not relevant. Let's skip the abuses of the FBI et al and talk about the government as a whole for a minute. Are you aware that the NSA monitors _all_ traff…

'haberman's comment includes actual information. Can we not punish people for posting information? I doubt very much that 'haberman approves of NSLs, especially since he said as much. Moreover, your comment may actually be incorrect; a good chunk of all the mail Gmail handles is never on the wire in a format that can be decrypted with any known attack without access to Google's (often pinned) secret keys. The NSA's a…

By making them sound less dangerous he is making it more difficult to oppose them.

Re: Gmail security warnings for suspected state-sponsored attacks

#46
post #39
post #35

Earlier quoted context omitted.

> NSLs can only request non-content information NSLs can't legally request ANYTHING. They are UNCONSTITUTIONAL. The government has NO AUTHORITY to issue them. The fact that they are presently limiting themselves to illegal request x instead of illegal request y is not relevant. Let's skip the abuses of the FBI et al and talk about the government as a whole for a minute. Are you aware that the NSA monitors _all_ traff…

'haberman's comment includes actual information. Can we not punish people for posting information? I doubt very much that 'haberman approves of NSLs, especially since he said as much. Moreover, your comment may actually be incorrect; a good chunk of all the mail Gmail handles is never on the wire in a format that can be decrypted with any known attack without access to Google's (often pinned) secret keys. The NSA's a…

This "good chunk" is what? gmail to gmail?

As far as I'm aware the majority of internet users are still using unencrypted plain text email.

Re: Gmail security warnings for suspected state-sponsored attacks

#47
post #44

Earlier quoted context omitted.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

I understand as a hacker that you want to provide the truth, but the way to stop these letters isn't to downplay their danger, but to make people scared to death of them.

If someone appeals to me to care about X but lies about the facts of X, their credibility is damaged in my eyes and I am inclined to think that they are overplaying the danger.

For example, "sneak" replied to my comment with lots of CAPITAL LETTERS and links to other information. But I'm already less inclined to trust sneak, since he/she is already known to play fast and loose with the facts.

Re: Gmail security warnings for suspected state-sponsored attacks

#48
post #44

Earlier quoted context omitted.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

I understand as a hacker that you want to provide the truth, but the way to stop these letters isn't to downplay their danger, but to make people scared to death of them.

I don't wish to open a whole separate thread, but...

The strategy you advocate is what many environmentalists, notably Al Gore, have been employing.

It turns out that most people aren't as dumb as you think. They pick up on the fact that they're being misled. And that tends to turn them against your mission.

Thus, many people are now desensitized to warning of climate change. They've seen the scientists lying and conspiring to gag dissenting views, and cherry-picking studies to highlight the worst possible outcomes. And if those scientists (rogues that they might be) need to gag the dissenters, they must not have very strong arguments.

Please note: I don't mean to take a side here in the climate debate, only to illustrate how one strategy used in that debate is having an effect opposite to what was intended.

Re: Gmail security warnings for suspected state-sponsored attacks

#49
post #44

Earlier quoted context omitted.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

I understand as a hacker that you want to provide the truth, but the way to stop these letters isn't to downplay their danger, but to make people scared to death of them.

I'm sorry if the truth is inconvenient, but that's no excuse for suppressing it and spreading lies in its place. If they really are so bad, you shouldn't need to subvert the truth in order to prove it — because their badness is the truth. If they aren't that bad, I don't see why it's so important to make people scared to death of them that I'd sacrifice my good name to do so.

Re: Gmail security warnings for suspected state-sponsored attacks

#50
post #44

Earlier quoted context omitted.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

I understand as a hacker that you want to provide the truth, but the way to stop these letters isn't to downplay their danger, but to make people scared to death of them.

That attitude is disastrous. You're misleading "people", considering them too stupid for the truth and manipulating them for your own ends.

i.e. exactly what you're (ostensibly) trying to oppose.

Replacing one form of control with another is not progress :)

Post reply on HN