Live data from Hacker News

Larry Page addresses PRISM

googleblog.blogspot.com

191–200 of 482 posts

Re: Larry Page addresses PRISM

#191
post #145

Personally, I'm really glad that Google published such a clear, plain-spoken post to tackle this issue head on. This whole issue makes me want to donate a bunch of money to the EFF. If anyone else feels the same way, you can donate to the EFF here: https://supporters.eff.org/donate and I believe a lot of employers will match contributions.

EFF is certainly doing a great job right now, so donations are definitely going to help. Let me ask you this - do you feel 100% comfortable that nobody outside of Google can read your personal gmail?

Me personally? I do. I still want Google to up the number of key bits on our SSL connections, plus explore how to make the connection even more secure though. But yes, I'm quite confident.

Re: Larry Page addresses PRISM

#192
post #166

Earlier quoted context omitted.

"We would never do this, not because the government hasn't asked us to, but because it's morally abhorrent. It goes against everything we personally believe in and stand for. Even if we were legally required to cooperate, we would resist and suffer incarceration if necessary. We believe in freedom more strongly than we fear the consequences of not cooperating with an oppressive government." That kind of thing.

So, you'd feel more comfortable if the company threw in some rhetoric about morals and freedom that are, as assertions, impossible to verify, but would make people feel more warm and fuzzy? So, basically, what politicians put into their speeches? Read over your statement again. There's very little of substance in there. For example, what does "this" in "We would never do 'this'" mean? And I'm not being pedantic, beca…

> "So, you'd feel more comfortable if the company threw in some rhetoric about morals and freedom that are, as assertions, impossible to verify, but would make people feel more warm and fuzzy?"

If Google was actually taking a moral/ethical stance that being an accessory to unconstitutional warrantless searches is something that they find to be morally wrong, yes, I would be more comfortable. My reading of this was Larry saying, "I enjoy being a billionaire and will say whatever it takes to continue being one."

Re: Larry Page addresses PRISM

#193
post #101
post #34

Earlier quoted context omitted.

Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. I'm not sure how much more strongly you'd like t…

Well, I guess he will have to find a proper way to prove it, because if you are satisfied with just a blog post maybe you should think again.

I'm curious why we're satisfied with an anonymous leaker and some shoddy looking powerpoints.

I'm not going to comment on what's true or what's not, but I know a few things:

1. Having been "in the news" or when I've had firsthand knowledge of an event in the news, I'm always shocked by how inaccurate the news is. Usually not in broad strokes, but in lots of details. I have learned to take everything I read in the media with a healthy grain of salt. I'm not dissing journalists here, but that's what they are: journalists. They are not tech experts. What we are reading could very well be inaccurate. We've not vetted their source either. At least Google is known entity.

2. This whole "we scan everything" business just seems farfetched. That's a lot of data to just double.

3. This program has been subject to oversight. I haven't lost that much faith in my elected officials, or government employees for that matter.

Re: Larry Page addresses PRISM

#194

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

Are you alleging they are trying to avoid making untrue statements in this blog post? Then what about "Press reports that suggest that Google is providing open-ended access to our users' data are false, period."?

The first sentence of the WPo article which started this is "The NSA and the FBI are tapping directly into the central servers of nine leading U.S. Internet companies". I think saying "we do not provide direct access" is a reasonable response.

Re: Larry Page addresses PRISM

#195

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

There is another explanation: https://financialcryptography.com/mt/archives/001431.html

I guess the question then, is: how big of a cabal of "rogue" employees would it take to put evil code into production at a place like Google. I seriously doubt one person could do it, no matter how highly placed.

Re: Larry Page addresses PRISM

#196
A few thoughts: It's unlikely that he cannot deny or admit giving data to NSA /FBI, because he both admitted and denied, albeit with weasel words. No "backdoor" and "no direct access" but maybe from the front door and indirect access :). I suspect that NSA has live access to Google /FB / MS for certain cases, tracking every online move for certain individuals. That's why it costs just $20 million, maybe they created a portal from which they track Person A going from site to site, what he searches for, who he calls, and what he types.

Larry smells the end of his company's "trust us with all your data...all your life on cloud...search while logged in...visit pages with Google Analytics...it's secure" etc. etc etc. While NSA might not catalog everything you do, Google does and everything is there for NSA's and FBI's asking. The more information Google and Facebook (to pick two of the largest) have stored, the worst it is for us. They know EVERYTHING about pages you visit, how long you stay there, what you searched for, what places you went to (Android) what you emailed, foods you liked, what your ordered from ebay, and so on. A treasure trove for NSA, a nightmare for us.

Start thinking! Stay logged out of Google and FB, use hosts file, Ghostery etc to block and make NSA's and FBI's life as hard as possible.

What's good for Google is good for NSA, but not necessarily for you. NSA would love Google Now, wouldn't they?

Re: Larry Page addresses PRISM

#197
post #48

For all those complaining about the language of this and other denials, what could possibly satisfy you? This seems as blanket as possible. "Second, we provide user data to governments only in accordance with the law. Our legal team reviews each and every request, and frequently pushes back when requests are overly broad or don’t follow the correct process." "We were very surprised to learn that such broad orders exi…

Larry Page wants to live. And he wants Google to keep functioning as a company, and not e.g., to have sudden tax issues crop up with the IRS. He has plenty of incentive to tell an out-and-out lie in this case.

[deleted]

Re: Larry Page addresses PRISM

#198
Could the NSA have recruited Google employees as moles? The company might not be providing "direct access", but an individual employee might be able to.

What kind of security do companies like Google and Facebook have to protect private user data from employees? I remember reading that Facebook used to (?) allow unfettered access to all private user data until (surprise!) some creepy employees began stalking people.

Re: Larry Page addresses PRISM

#199

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

They can't say "we don't provide access", because depending on the law, they are forced to. They say "we do not provide direct access", because as explained, any access goes through proper legal channels. I'm not sure what you'd call it? Remember language matters, and these are actionable public communications.

Sure, but the statement as worded does not rule out the possibility that a third party contractor (Palantir) has access, and feeds it to the government. So Google has the motive (some theoretical secret law they need to abide) and they haven't denied a potential means (third party mediation). That's enough for people to convict in this situation.

Re: Larry Page addresses PRISM

#200
post #22

In his remarks today Obama said "Now, with respect to the Internet and emails, this does not apply to U.S. citizens, and it does not apply to people living in the United States." He's clearly stating that they do read non-American's emails. So how do they do it if they don't have access to Google's servers? BTW, if you run a company outside of America you'd be crazy to rely on Google since the US could be reading you…

> BTW, if you run a company outside of America you'd be crazy to rely on Google since the US could be reading your emails for corporate espionage purposes. The US could be spying on activities, including email transmissions, that happen wholly outside of the US, as well. The only reason PRISM, et al., are newsworthy is that there are expectations and widely-perceived legal/constitutional limitations of US government…

If my company is outside the US I can try to use infrastructure that at least makes it harder for the US to gain access. If, for example, the US is spying on European allies' infrastructure it would be a diplomatically damaging revelation and the European governments would try to fight it off. If I use a Silicon Valley service I know for a fact that the US can read my data at will without any recourse on my part.

It makes no sense to use Google which is why I'm saying this is threatening to Silicon Valley. Think of it this way, do you think a Chinese email service could become trusted enough to become globally competitive?

Post reply on HN