Live data from Hacker News

Gmail security warnings for suspected state-sponsored attacks

googleonlinesecurity.blogspot.com

91–100 of 123 posts

Re: Gmail security warnings for suspected state-sponsored attacks

#91
post #89
post #39

Earlier quoted context omitted.

'haberman's comment includes actual information. Can we not punish people for posting information? I doubt very much that 'haberman approves of NSLs, especially since he said as much. Moreover, your comment may actually be incorrect; a good chunk of all the mail Gmail handles is never on the wire in a format that can be decrypted with any known attack without access to Google's (often pinned) secret keys. The NSA's a…

From a wired article: http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/al... "Before yottabytes of data from the deep web and elsewhere can begin piling up inside the servers of the NSA’s new center, they must be collected. To better accomplish that, the agency has undergone the largest building boom in its history, including installing secret electronic monitoring rooms in major US telecom facilities. Contr…

Well, if Wired says so, I guess I'll stop encrypting my email.

Re: Gmail security warnings for suspected state-sponsored attacks

#92
post #44

Earlier quoted context omitted.

I understand as a hacker that you want to provide the truth, but the way to stop these letters isn't to downplay their danger, but to make people scared to death of them.

I don't wish to open a whole separate thread, but... The strategy you advocate is what many environmentalists, notably Al Gore, have been employing. It turns out that most people aren't as dumb as you think. They pick up on the fact that they're being misled. And that tends to turn them against your mission. Thus, many people are now desensitized to warning of climate change. They've seen the scientists lying and con…

Before I looked at your comment history I honestly thought you were trying to do this: http://xkcd.com/966/

Re: Gmail security warnings for suspected state-sponsored attacks

#93
post #89
post #39

Earlier quoted context omitted.

'haberman's comment includes actual information. Can we not punish people for posting information? I doubt very much that 'haberman approves of NSLs, especially since he said as much. Moreover, your comment may actually be incorrect; a good chunk of all the mail Gmail handles is never on the wire in a format that can be decrypted with any known attack without access to Google's (often pinned) secret keys. The NSA's a…

From a wired article: http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/al... "Before yottabytes of data from the deep web and elsewhere can begin piling up inside the servers of the NSA’s new center, they must be collected. To better accomplish that, the agency has undergone the largest building boom in its history, including installing secret electronic monitoring rooms in major US telecom facilities. Contr…

Try reading critically. To process 1 yottabyte of data assuming you have 128 bit registers you would need 100,000,000 petaflops.(See http://www.wolframalpha.com/input/?i=%2810%5E24+bytes+%2F+12...) Therefore, there must be a great deal of preprocessing using classifiers to basically eliminate a great deal of useless information. Just because you store it doesn't mean you will listen to it.

Re: Gmail security warnings for suspected state-sponsored attacks

#94
Since New York Times recently reported that Stuxnet is a US State Sponsored Cyber virus - which if you recall was accidentally released into the wild and affected and attacked innocent end-user machines as collateral damage, and with the ongoing US-Israeli state sponsored cyber warfare weapons of mass destruction (operation Olympic Games) including the more recent releases of Duqu and Flame virus.... can Google clarify if through its detailed analysis as well as victim reports if Google will apply the same exacting standards and warn end-users (both in the US and abroad, example: Iranian users) of these domestic (US) state sponsored attacks as well? Even if Google was to choose to go the higher route, wouldn't this kind of undermining and subterfuge (however unintentional) really go unnoticed by its host nation? Or are exceptions of convenience made in these cases due to the close ties that Google has with the US intelligence agencies and the confirmed but secret and classified collaboration that the Google has with the CIA and NSA in regards to GMail and Google Accounts? No doubt there is a clear conflict of interest going on here. To me this smells more like Google catering to State Sponsored Propaganda than really caring about the security and privacy of their end-users.

Re: Gmail security warnings for suspected state-sponsored attacks

#95
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

I'm a privacy researcher, specifically focusing on government access to data held by Internet companies.

Google, your employer, will not confirm, on the record, what they will or will not disclose when they get an NSL. The NSL statute does not authorize the disclosure of transactional records.

18 USC 2709(b)(1) states that the government can only get "the name, address, length of service, and local and long distance toll billing records"

Furthermore, a 2008 opinion from the Office of Legal Counsel at DOJ specifically confirmed that the FBI cannot use NSLs to get email to/from data, even though the government has asked for it in the past. See: http://www.justice.gov/olc/2008/fbi-ecpa-opinion.pdf

NSLs are gagged, and so Google cannot confirm when it gets NSLs, or for which customers the government is seeking data. However, Google could very easily provide information to the public confirming what it will and will not deliver to the FBI when it receives an NSL. I have asked Google's legal and DC policy team for this info, repeatedly, and hit a brick wall.

Re: Gmail security warnings for suspected state-sponsored attacks

#96
post #63

Earlier quoted context omitted.

> Dissent in China will get you a prison sentence or worse. Dissent in America will get your karma modded down. I think Julian Assange, Bradley Manning, and Dmitry Sklyarov may disagree with you.

Sklyarov - charges dropped. Manning - U.S. soldier deliberately mishandled diplomatic cables. Assange - I'm aware of no official charges or actions by the U.S.

Would you hire someone who was facing charges of abusing children to look after your children? I probably wouldn't. The charges sometimes stick, no matter what happens after they are filed. As for Assage, I assume you're aware of the way some US politicians have behaved. http://abcnews.go.com/blogs/politics/2010/11/does-palin-want...

Re: Gmail security warnings for suspected state-sponsored attacks

#97
post #89
post #39

Earlier quoted context omitted.

'haberman's comment includes actual information. Can we not punish people for posting information? I doubt very much that 'haberman approves of NSLs, especially since he said as much. Moreover, your comment may actually be incorrect; a good chunk of all the mail Gmail handles is never on the wire in a format that can be decrypted with any known attack without access to Google's (often pinned) secret keys. The NSA's a…

From a wired article: http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/al... "Before yottabytes of data from the deep web and elsewhere can begin piling up inside the servers of the NSA’s new center, they must be collected. To better accomplish that, the agency has undergone the largest building boom in its history, including installing secret electronic monitoring rooms in major US telecom facilities. Contr…

NSA ability to sniff traffic at major telecom exchanges is real. NSA ability to break $cipher or $hash based on the hearsay journalism involving an interview of (ex-)NSA employees (who would certainly be barred from talking about any real non-public attacks) is not real [1]. It's possible the NSA is setting up real systems that will brute force or factor or find collisions for known borderline algorithms/keysizes. Maybe they have a collection of old DES-encrypted traffic and they are building enough computing resources to do large-scale cracking of DES keys.

The idea that they can create collisions for hashes or crack ciphers believed to be relatively secure in the near to mid future is paranoid speculation.

However, if you're going to be paranoid, direct your attention to RSA and DH (plain, not ECDH). In Suite B, which the NSA recommends for use by government, RSA and DH are absent. If the NSA knows of a weakness in anything currently believed to be secure (I think that's unlikely), I would bet that it's RSA and DH, because the NSA no longer recommends them. I think RSA and DH are superseded by ECDSA/ECDH simply because of speed at comparable key strengths, not because the NSA knows something the public doesn't. As an aside, it indicates that the NSA has a fair amount of confidence in ECDSA/ECDH.

I do not think the NSA is stupid enough to play chicken with the public crypto community by recommending encrypting classified information with ciphers NSA knows to be weak. The public could discover those weaknesses tomorrow. The most sensitive information inside the U.S. government and military is presumably protected by the NSA's Suite A algorithms, but other important information is not, notably military communications between U.S. allies, for which Suite B is recommended.

[1] https://www.schneier.com/blog/archives/2012/03/can_the_nsa_b...

Re: Gmail security warnings for suspected state-sponsored attacks

#98
post #90

Earlier quoted context omitted.

The difference between rights in America and China are vast. Criticizing legitimate American counter-terrorism and counter espionage and suggesting that it's equivalent to China's suppression of thought of its citizens (and people in occupied zones like Tibet) are disingenuous. Dissent in China will get you a prison sentence or worse. Dissent in America will get your karma modded down. (Q.E.D) Want more relevant wiki…

> Criticizing legitimate American counter-terrorism and counter espionage and suggesting that it's equivalent to China's suppression of thought of its citizens (and people in occupied zones like Tibet) are disingenuous. However, what is not disingenuous is characterizing American behavior vis-a-vis the propaganda it espouses. That is a good test for any institution or country. Don't even need China here. Compare what…

This.

The philosopher Zizek has a great bit about the "unknown knowns" (the quadrant Rumsfeld wasn't smart enough to articulate). Meaning, of course, the unperceived fabric of Western ideology -- that works far better than explicit propaganda ever could.

Here is exactly when he starts talking about it in his Authors@Google talk: http://youtu.be/_x0eyNkNpL0?t=3m18s

Re: Gmail security warnings for suspected state-sponsored attacks

#99
post #63

Earlier quoted context omitted.

> Dissent in China will get you a prison sentence or worse. Dissent in America will get your karma modded down. I think Julian Assange, Bradley Manning, and Dmitry Sklyarov may disagree with you.

There are certainly examples of persecuted dissidents in both countries. What I'm missing in China is any examples of dissidents who've achieved any success, comparable to American examples of dissidents in prominent, even state-sponsored roles. And, in particular, any ability of ordinary people to read and discuss what dissidents write. You and I can discuss Bradley Manning here. And I'll agree he is not being treat…

Not directly relevant, but one should also recognize that there are examples of modern-day American academics who do suffer censure for being outspoken dissidents -- Norman Finkelstein being an example (http://www.americanradicalthefilm.com/).

Re: Gmail security warnings for suspected state-sponsored attacks

#100
post #74

Earlier quoted context omitted.

Sklyarov - charges dropped. Manning - U.S. soldier deliberately mishandled diplomatic cables. Assange - I'm aware of no official charges or actions by the U.S.

I have a friend who's life was completely ruined by a federal criminal case before charges were ever even filed. I'm not sure you understand the implications of "charges dropped". Sometimes that can consume 5+ years of one's life, sometimes part or all of that imprisoned. It always costs a fortune, too. If you aren't aware of what the US is planning for Assange, you're not paying attention. This is the same governmen…

This is the same government that thinks that people at the New York Times should be indicted for espionage.

... at the same time as they feed the New York Times the leaks and favored access it needs to adequately serve its propaganda function, http://www.nytimes.com/2012/06/01/world/middleeast/obama-ord... being one recent example.

Chomsky likens the NYT to a court stenographer, which I think is such a delicious phrase. Fun documentary version of one of his most famous books: http://www.hulu.com/watch/118171/manufacturing-consent

Post reply on HN