Live data from Hacker News

Larry Page addresses PRISM

googleblog.blogspot.com

201–210 of 482 posts

Re: Larry Page addresses PRISM

#202

Earlier quoted context omitted.

Couldn't agree more. The key terms used are subject to interpretation. Still not feeling comfortable about this.

Is there any statement that would actually make you feel comfortable? If you're going to choose to disbelieve someone's statements, there's very little they can say to change that.

Larry's post was designed to quickly assuage our knee-jerk fears about a giant like google having anything to do with "PRISM". In that, it is effective.

I think for a lot of folks complaining, his language (i.e. "direct access") is just overly precise enough to leave too much room in the margins for technical loopholes concerning "who" has access to "what" data. When Larry defends their general policies stating google "pushes back on requests", I am not convinced when terms like "overly broad" and "correct process" are left undefined.

But it's a 4 paragraph blog post- what do I expect?

Re: Larry Page addresses PRISM

#203
>Second, we provide user data to governments only in accordance with the law.

This is problematic when the government decides the law means you have to give them your data, you can't say no, you can't say anything about it, and if asked you must deny it.

In this day and age, who knows who's telling the truth. When lying becomes law, truth no longer exists.

Re: Larry Page addresses PRISM

#204

Earlier quoted context omitted.

Consider the NSA having MITM capabilities before the data reaches google: 1) This is exactly what you would need to do, to consider it realtime 2) None of the denials cover this

They'd have to MITM SSL traffic largely. Also, that's what they were doing for more traditional wiretaps and you should be sure that they have access to siphon off live traffic for analysis if they want.

"They'd have to MITM SSL traffic largely."

To be fair, if anyone can do this it's precisely these people.

... still not likely, though, I agree.

Re: Larry Page addresses PRISM

#205
post #34

Earlier quoted context omitted.

Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. I'm not sure how much more strongly you'd like t…

Consider the NSA having MITM capabilities before the data reaches google: 1) This is exactly what you would need to do, to consider it realtime 2) None of the denials cover this

Would the NSA list Google as a "partner" that it needs to keep protected in these leaked slides if this were the case?

Re: Larry Page addresses PRISM

#206
post #195

Earlier quoted context omitted.

There is another explanation: https://financialcryptography.com/mt/archives/001431.html

I guess the question then, is: how big of a cabal of "rogue" employees would it take to put evil code into production at a place like Google. I seriously doubt one person could do it, no matter how highly placed.

one person, maybe not, but if you're a intelligence agency with a multi-million dollar budget to tap Google, you'd probe the organisation and bribe those with access, and anyone in the chain those employees could credibly report to.

this isn't difficult or particularity far-fetched!

Re: Larry Page addresses PRISM

#207
post #41

Earlier quoted context omitted.

OK, in an alternate reality, what would a clear, flat-out denial look like? I mean, how could we tell such a thing differently than what was in the OP? First, we have not joined any program that would give the U.S. government—or any other government—direct access to our servers. Indeed, the U.S. government does not have direct access or a “back door” to the information stored in our data centers. We had not heard of…

Instead of enumerating what they don't do, which leads one to wonder what's left out, they could exhaustively enumerate the ways that they do cooperate. To a certain extent that's what they do with the transparency report. But I saw no strong claim that the report was complete, on the contrary the "whenever possible" language outright suggests the report is incomplete. I'm sympathetic to being caught between a rock a…

See http://www.google.com/transparencyreport/userdatarequests&#x...;

Argh. Hacker News refuses to save the URL. Replace %xF; with "/"

Re: Larry Page addresses PRISM

#208
post #34

Earlier quoted context omitted.

Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. I'm not sure how much more strongly you'd like t…

It's exactly the kind of denial you'd expect them to issue if they were legally required to deny any involvement.

No, it's not. Gag orders can also be satisfied by saying "no comment" or just not saying anything at all, which is differently then actively denying something.

Re: Larry Page addresses PRISM

#209
post #187
post #48

For all those complaining about the language of this and other denials, what could possibly satisfy you? This seems as blanket as possible. "Second, we provide user data to governments only in accordance with the law. Our legal team reviews each and every request, and frequently pushes back when requests are overly broad or don’t follow the correct process." "We were very surprised to learn that such broad orders exi…

Obama confirmed in a press conference that PRISM exists, so concluding the program is imaginary would seem to require a fair lack of critical thinking.

Could you quote/link to Obama's confirmation that Prism exists, and also the claim that it is imaginary?

Re: Larry Page addresses PRISM

#210
post #181
post #63

I don't want any more fluff "no direct access" emails. I just want these questions to be answered with a YES/NO: 1. Is there any way that someone outside of Google, can get a copy of an email I sent from my gmail to my own gmail, without a warrant that specifies my exact gmail address? 2. If I delete my Google search history, is there any way for anyone to access this history, with or without a warrant? 3. If I make…

Get a VPN anonymously, pay in Bitcoin and never expect third party companies to adhere to any policy they can potentially break. Anything else involves trust.

That's not the point. The point is if we have to resort to such measures, we have already lost.
Post reply on HN