Live data from Hacker News

Larry Page addresses PRISM

googleblog.blogspot.com

211–220 of 482 posts

Re: Larry Page addresses PRISM

#211
post #34

Earlier quoted context omitted.

Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. I'm not sure how much more strongly you'd like t…

It's exactly the kind of denial you'd expect them to issue if they were legally required to deny any involvement.

That's moving the goalposts, though. The initial assertion -- that this is a cleverly-worded non-denial -- doesn't hold up with the text. Page is clearly and unambiguously denying that Google supplies any information to the government on a millions-of-users scale.

Saying that denial is a lie . . . is a completely different charge.

Re: Larry Page addresses PRISM

#212
post #137
post #107

Earlier quoted context omitted.

I agree, but what could Page say to convince us otherwise? Either the government is coercing them, and they have to issue lies as denials, or they are participating voluntarily and are voluntarily lying, or they are not participating. The second option seems unlikely to me.

Well, you can't prove a negative so I'm not sure there's anything Page can say. But at the same time they can't all be right. NSA says it's getting data in some form from Google, Page says no direct access. The truth is probably somewhere in the middle then... but where?

I don't know how many of us served as officers in the military, but the requisite action in this situation is pretty clear. If one is interested in day to day security, speaking from a strictly tactical perspective:

You assume Google is giving the NSA information and act accordingly.

Doubts are like bothersome flies...

until they are crushed...

you will never be comfortable at your current position.

Re: Larry Page addresses PRISM

#213
post #137

Earlier quoted context omitted.

Well, you can't prove a negative so I'm not sure there's anything Page can say. But at the same time they can't all be right. NSA says it's getting data in some form from Google, Page says no direct access. The truth is probably somewhere in the middle then... but where?

I don't know why we'd expect the truth to be in the middle. If the NSA document is genuine, the information the NSA is collecting from Google is part of a Top Secret program as described in the leaked internal document. If that is true, why would we expect that Google officials would be able to make any public confirmation of the Top Secret program? And, given that, why, in that case, would we expect the truth to be…

Did I miss some information? I only saw two slides. One that show the potential data accessible and one that show when the companies were added. It doesn't say exactly that they had access to everything. As far as we know PRISM can simply be there to centralize the information that the NSA got in legals ways. We do know that the government ask about 100 users account information each day to Google, we can guess that they do the same to every company on that list and they were all added to PRISM at the date you can find on the slides. I mean that slide contains one of the most important information that we currently have to guess the magnitude of PRISM, the budget. They only need 20 millions $ every years. True data mining is much more expensive than that.

Re: Larry Page addresses PRISM

#214

Earlier quoted context omitted.

It's not "direct" access, it's access through a one-way live xml feed

Please ... it will be binary format. Even the government isn't so wasteful to transmit data as xml. And if it did you could easily find where the servers were located by the 5 nuclear power plants needed to power such parsing.

No, JSON.

Re: Larry Page addresses PRISM

#215

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

The most interesting thing about Google's repeated use of the phrase 'direct access' is that there are so many nerds that don't comprehend how much wiggle room that phrase implies.

My bet is that Google is under order of some kind of National Security Letter and has to deny involvement here.

Re: Larry Page addresses PRISM

#216
post #195

Earlier quoted context omitted.

I guess the question then, is: how big of a cabal of "rogue" employees would it take to put evil code into production at a place like Google. I seriously doubt one person could do it, no matter how highly placed.

one person, maybe not, but if you're a intelligence agency with a multi-million dollar budget to tap Google, you'd probe the organisation and bribe those with access, and anyone in the chain those employees could credibly report to. this isn't difficult or particularity far-fetched!

Don't you think China/Russia/Israel/etc would have attempted/done the same thing, too?

Re: Larry Page addresses PRISM

#218
post #145

Earlier quoted context omitted.

EFF is certainly doing a great job right now, so donations are definitely going to help. Let me ask you this - do you feel 100% comfortable that nobody outside of Google can read your personal gmail?

Me personally? I do. I still want Google to up the number of key bits on our SSL connections, plus explore how to make the connection even more secure though. But yes, I'm quite confident.

Thanks! Believe it or not, your one statement made me feel more assured than all the press releases I've seen so far.

Re: Larry Page addresses PRISM

#219
post #81

Watch this: http://youtu.be/oYNXVgYhPOc The key phrase is "in the United States" so they just replicate the data outside the United States and you've got yourself a data 'black site' outside the jurisdiction of US law. No direct access. No laws broken. Open access to the NSA.

Ireland?

The dark side of the moon.

Re: Larry Page addresses PRISM

#220

Earlier quoted context omitted.

Oh come on. Google is willing and able to push back on overly broad governmental requests. When the Department of Justice sent subpoenas to 34 companies in 2005 asking for months of user queries, Google was the only company I know of that fought back in court and won. I know because I wrote a declaration for that case. See http://www.mattcutts.com/blog/doj-sent-subpoenas-to-34-compa... ; and http://www.mattcutts.com/…

Matt, I know you really love Google but you need to do a bit more research: http://www.wired.com/threatlevel/2012/05/google-nsa-secrecy-...

like, say, into the actual source of that story[1] instead of the wired blog writeup? For instance, the part that explicitly talks about limiting the share of information to the Chinese intrusion and not user data?

http://online.wsj.com/article/SB1000142405274870404150457504...

Post reply on HN