Live data from Hacker News

Larry Page addresses PRISM

googleblog.blogspot.com

91–100 of 482 posts

Re: Larry Page addresses PRISM

#91
post #62

Some of the comments here just shows that people will believe what they want to believe. There's nothing Google, Apple, Facebook, etc can say that some people won't poke holes into.

That's the frustrating state of the law. Gag orders make it very difficult to trust public communications like this. With secret, fairly unaccountable courts that statistically appear to rubber-stamp government requests, it's hard to discount the possibility of the NSA having, say, the authority to say "Google, you will post the following PR release now" as part of one of these orders.

Re: Larry Page addresses PRISM

#93

When I worked IT for a medium sized university we were asked by the DOJ to install switches that copied all internet traffic directly to an unspecified government server. We were told all ISPs (anyone providing internet to more than 100 persons) were told to do this as well. We refused to comply obviously as the request was absurd, but in the small print of the request we were told we were not allowed to speak of the…

Please throw out an estimate of how big you think a mirror of all Google's network traffic might be.

Big. But the NSA has been sucking in ridiculous amounts of data for many many years.

http://en.wikipedia.org/wiki/Room_641A http://en.wikipedia.org/wiki/Carnivore_(software)

Re: Larry Page addresses PRISM

#94

What a lot of people haven't considered is that it's likely that the NSA had a big breakthrough on Integer Factorization and their capable of breaking RSA public key crypto (used everywhere you see HTTPS) Then they can just save all your encrypted traffic and break it on demand. We all need to start considering moving to Elliptic Curve Cryptography.

Why is this at all likely?

Re: Larry Page addresses PRISM

#95
post #47

Earlier quoted context omitted.

I believe Google on this. The language is clear and non-weasel-y. Google does not hand over user data to the government unless specifically requested. There is no open-ended access. But I also believe the government works with ISP's (all major ISPs) so that they can intercept traffic. Which would be a type of MITM attack allowing them to get data from all major web sites.

I think it's completely weaselly. It leaves wide open the possibility that a 3rd party, like Palantir, has access to the data.

"Press reports that suggest that Google is providing open-ended access to our users’ data are false, period."

"Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false."

Those sentences seems straightforward and unambiguous.

Re: Larry Page addresses PRISM

#96
post #49

Earlier quoted context omitted.

Please throw out an estimate of how big you think a mirror of all Google's network traffic might be.

The NSA's Utah data center was designed to host more storage than existed on the entire planet at the time. Sheer volume of data is among the least of their concerns.

According to the Wired story on it, it's four 25,000 square foot data center buildings[1]. That's smaller than one of Apple's smaller data centers. Apple's Oregon one is going to be 500,000 square feet.

It's not going to be able to hold more than an average size datacenter, and there are a lot of data centers out there, each holding more data that would have to be copied. The NSA has huge capabilities, but they're not nearly there yet. Most of what we should be worried about is their legal capabilities.

edit: it's also worth noting that the wikipedia article's source is the wired article, and all the wired article says is that a DoD report says that they need to start designing their network to handle yottabytes, which isn't even related to the NSA's data center. Wired then does some interpolation by using "yottabyte" to make the requirements of the data center sound big, but they never say that it was designed to handle that level of data or that it will ever be able to handle that level of data (in fact, they never even cite any level of data that it was designed to handle). But the Wikipedia article cites the Wired article, and suddenly it's become "a data storage facility for the United States Intelligence Community that is designed to store data on the scale of yottabytes".

[1] http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/al...

[2] http://appleinsider.com/articles/12/08/16/apples_oregon_data...

Re: Larry Page addresses PRISM

#97

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

> It just smells of being rehearsed, and carefully coordinated to select such language.

Next time, hopefully they'll make it less clear so that you have to translate the company-specific jargon and feel better that it's spontaneous and careless.

Re: Larry Page addresses PRISM

#98
post #34

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. I'm not sure how much more strongly you'd like t…

It's exactly the kind of denial you'd expect them to issue if they were legally required to deny any involvement.

Re: Larry Page addresses PRISM

#99

Earlier quoted context omitted.

Read the NEXT SENTENCE! "Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records." AND THE TWO AFTER THAT: "We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely fals…

It is very possible that Google is lying.

Of course it is, but in this conversation that is moving the goalposts. And if we had to address every possibility, very little progress would ever be made in any discussion.

Re: Larry Page addresses PRISM

#100

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

I'm not quite sure how you came to that conclusion, to me it reads like the opposite of slick lawyer talk, it's pretty unambiguous:

"No direct access", "No backdoors".

"Press reports that suggest that Google is providing open-ended access to our users’ data are false, period".

Post reply on HN