Live data from Hacker News

Google Chief Architect: we only respond to specific orders about individuals

plus.google.com

31–40 of 107 posts

Re: Google Chief Architect: we only respond to specific orders about individuals

#31
His comments are actually the most insightful points I've seen about the discussion regarding PRISM:

I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PRISM slides [1], especially the second and fourth ones shown there. The subtleties of phrasing are important, I suspect, not because they were trying to be elliptical but because they reveal what was obvious to the people who were giving that presentation.

And like I said, I have both some reason to believe that there aren't such devices inside Google, and that the PRISM slides are actually talking about a somewhat different kind of data collection -- one that's done from outside the companies.

Any ideas what he could be thinking?

1. http://www.washingtonpost.com/wp-srv/special/politics/prism-...

Re: Google Chief Architect: we only respond to specific orders about individuals

#32
post #16

What I don't get is: from US government, we got confirmations - half-ass confirmations, but still confirmations - that PRISM is real, we maybe have some information wrong and we should stop asking and talking about it, but it's real. While the companies and its architects all oppose the claims in a way that's very convincing. I don't know what to believe anymore.

I can't tell you want to believe, but maybe a place to start is: the world is a confusing place, full of miscommunication and gray areas. Why should we expect the world to be as it is in the movies, in which bad guys are obviously bad and that there is an "ending" in which things are clear?

For starters, I just re-skimmed the Washington Post report and noticed that it has since been amended:

> It is possible that the conflict between the PRISM slides and the company spokesmen is the result of imprecision on the part of the NSA author. In another classified report obtained by The Post, the arrangement is described as allowing “collection managers [to send] content tasking instructions directly to equipment installed at company-controlled locations,” rather than directly to company servers.

edit: Here's the link: http://www.washingtonpost.com/investigations/us-intelligence...

I think I'm wrong that that was one of the actual changes since yesterday...either way, the Post is allowing for the possibility of a miscommunication/misinterpretation by its source. Business Insider also alleges of other hedging by the WaPo here: http://www.businessinsider.com/washington-post-updates-spyin...

At this moment in time, we still do not know two things: who the leaker is, beyond a "career intelligence officer" and the contents of this 41-slide presentation other than the 3 or 4 slides that the Post and the Guardian have published. The identity or motives of the leaker isn't necessary to know, but it's kind of problematic when we are missing context to the so-far published slides that explain the PRISM program. For example, it kind of changes things if the first two slides say "PROPOSAL" or the last slide says "APRIL FOOLS"

Re: Google Chief Architect: we only respond to specific orders about individuals

#33
post #13

Earlier quoted context omitted.

Something like this? https://plus.google.com/+BradleyHorowitz/posts/SM5RjubbMmV

No, that says you can't use a pseudonym without proving to Google that it is one a lot of people know you by.

Nothing in the names policy prohibits pseudonyms. If your given name is "Jason Ramirez", you're welcome to have a separate Google+ account with the name "Nancy Young".

You only have to prove people know you by a name if you want to go by "#RS", "Albert Einstein", or "GreenLife Rx"; all three of those are likely name violations for reasons that have absolutely nothing to do with knowing who you are.

Re: Google Chief Architect: we only respond to specific orders about individuals

#34
post #25

It sounds like this employee was not even aware that Google's "Transparency Report" specifically does not include the number of FISA orders that they have received: "Update 2013-06-07: at the time that we wrote this post, we asked Google whether its Transparency Report included data about secret FISA court orders that would send data to the NSA. The response we received was extremely vague, but seemed to possibly be…

> It sounds like this employee was not even aware that Google's "Transparency Report" specifically does not include the number of FISA orders that they have received Are you concluding that from this statement? > "I'm not sure what the details of this PRISM program are, but I can tell you that the only way in which Google reveals information about users are when we receive lawful, specific orders about individuals --…

Ah, you are right on the PRISM distinction, I mixed up details with the "metadata" thing, which I'm sure is not accidental. A lot of the responses from government officials are to the effect of "these aren't a concern, because to get the metadata we need to go through FISA courts for every individual", which is just a red herring now.

So, there are:

1. NSLs, published on the transparency report

2. FISA orders, which are "through a court", but is by all accounts just rubber stamping, not on the transparency report

3. PRISM, which is intended to bypass FISA entirely, according to the Guardian article. Either Google is lying, the NSA is doing it without Google's knowledge, or there is subtle wordplay involved (so, lying). Or, that it's been grossly misreported.

Re: Google Chief Architect: we only respond to specific orders about individuals

#35

For clarity, he's currently chief architect for Social/Google+ not Google as a whole, but he's still a very senior, longtime engineer.

Yeah, I saw the headline and thought "We have a chief architect?", but then I saw who it was, and he really does have a longtime track record of critical contributions to both G+ and Search before it.

Re: Google Chief Architect: we only respond to specific orders about individuals

#36
post #14

>"Google had no involvement in the PRISM program and the first we heard of it was when Greenwald's article hit the press." Greenwald broke the story about the Verizon FISA warrant, not the PRISM story. These are (ostensibly) different things.

I think he broke both stories.

From http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-n...

> The Guardian has verified the authenticity of the document, a 41-slide PowerPoint presentation

Re: Google Chief Architect: we only respond to specific orders about individuals

#37
post #11
post #7

> "the only way in which Google reveals information about users are when we receive lawful, specific orders about individuals -- things like search warrants." Things like search warrants? What has been described in the PRISM slides is an interface in which a NSA agent can access a subject's data at will, in a few clicks and an affirmation that "yes, this person is a terrorist". Also the US government has confirmed th…

> Things like search warrants? What has been described in the PRISM slides is a interface in which a NSA agent can access a subject's data at will, in a few clicks and an affirmation that "yes, this person is a terrorist". Google has officially denied being a part of PRISM. The way you phrased this statement makes it sound like the OP is sneakily leaving out the PRISM implementation, which would be sneaky if Google w…

Google merely stated that they had not heard of PRISM--probably because they were told it was called something else.

Re: Google Chief Architect: we only respond to specific orders about individuals

#38
post #28

Earlier quoted context omitted.

> Google has officially denied being a part of PRISM. They have denied knowledge of the use of the word "PRISM" to describe anything that they are participating in. So, they've denied nothing in that regard. It just means PRISM is the NSA codename.

Which statement are you referring to? I'm referring to the one that Larry Page issued this afternoon: http://googleblog.blogspot.com/2013/06/what.html > First, we have not joined any program that would give the U.S. government—or any other government—direct access to our servers. Indeed, the U.S. government does not have direct access or a “back door” to the information stored in our data centers. We had not heard of…

"Any program" would be broad enough, but he didn't say that at all. He said they are not part of "any program that would give any government direct access to their servers." I could drive a truck through the holes left in that wording.

Do they have indirect access? Some API perhaps? Do they have any means by which they can automate the export of data for whoever they want, perhaps after clicking a checkbox that says that the target is officially under surveillance? Is there some form of data sharing that is brokered through a trusted non-government entity?

He also goes on to say that they follow the law (meaningless if the law says to hand over the data), and they frequently push back (which orders do they push back on? Probably not the orders that they aren't allowed to legally push back on).

He states that they don't follow "broad orders for all data", but this is easily satisfied by the description in the Guardian article that says an analyst simply has to certify each request by saying they believe that there is a 51% probability that the request is legitimate. Obviously, no one at Google even could challenge such requests.

Re: Google Chief Architect: we only respond to specific orders about individuals

#39
post #31

His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…

A target's phone call, e-mail or chat will take the cheapest path, not the physically most direct path - you can't always predict the path

Dates When PRISM Collection Began For Each Provider

This is complete conjecture, but this reads to me like the NSA set up its own backhauls and set up peering agreements at artifically low prices to get traffic going over their pipes. Is there historical data for route announcements available anywhere? There are a lot of specific dates that could confirm/disprove this.

Post reply on HN