Live data from Hacker News

Google Chief Architect: we only respond to specific orders about individuals

plus.google.com

41–50 of 107 posts

Re: Google Chief Architect: we only respond to specific orders about individuals

#41
post #39
post #31

His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…

A target's phone call, e-mail or chat will take the cheapest path, not the physically most direct path - you can't always predict the path Dates When PRISM Collection Began For Each Provider This is complete conjecture, but this reads to me like the NSA set up its own backhauls and set up peering agreements at artifically low prices to get traffic going over their pipes. Is there historical data for route announcemen…

This is expounded upon in some news articles, particularly that data is routed not by the most efficient geographic route but by the cheapest by dollar price.

It's a very important tidbit of information that divulges the heart of the matter -- the NSA is a backbone operator[1]. It's a tall claim to make, however their involvement in internet exchange points (and other regional network access points) would be far more difficult to conceal.

[1] http://en.wikipedia.org/wiki/Tier_1_network#List_of_tier_1_n...

Re: Google Chief Architect: we only respond to specific orders about individuals

#42
post #31

His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…

Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have really clammed up the past few days are the telecoms in all this.

Re: Google Chief Architect: we only respond to specific orders about individuals

#43
post #39
post #31

His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…

A target's phone call, e-mail or chat will take the cheapest path, not the physically most direct path - you can't always predict the path Dates When PRISM Collection Began For Each Provider This is complete conjecture, but this reads to me like the NSA set up its own backhauls and set up peering agreements at artifically low prices to get traffic going over their pipes. Is there historical data for route announcemen…

OK, so when did Google push SSL everywhere? How does that fit with the graph at http://cdn.theatlantic.com/static/mt/assets/science/assets_c... ?

It's possible Google come out as good guys in this...?

Re: Google Chief Architect: we only respond to specific orders about individuals

#44
post #42
post #31

His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…

Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have real…

It has been well known that they already do the beam splitting portion, so it's really just up to the keys.

Re: Google Chief Architect: we only respond to specific orders about individuals

#45
post #42
post #31

His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…

Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have real…

That's why IMHO secret sharing[1] algorithms are so important

We store only parity of data in one data center, and some in another on a different continent. Any data intercepted or lost does not damage the integrity of the whole, plus this makes ISP can not discriminate raw binary data.

[1] http://en.wikipedia.org/wiki/Secret_sharing, invented by Adi Shamir, the S of RSA

Re: Google Chief Architect: we only respond to specific orders about individuals

#46
post #40

Two things that cannot be true at the same time: this Google+ post, and the idea that Google coughed up their TLS keys to the government.

You're one of the few whose opinion I would trust on this: how much data would the NSA need to derive TLS encryption keys from encrypted data? I feel like I read once that you could possibly use statistical methods to derive the key if you had enough encrypted source data.

Re: Google Chief Architect: we only respond to specific orders about individuals

#47
post #42
post #31

His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…

Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have real…

This is exactly the conclusion I came to. My guess is they have the SSL/TLS keys.

That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.

Re: Google Chief Architect: we only respond to specific orders about individuals

#48
post #32
post #16

What I don't get is: from US government, we got confirmations - half-ass confirmations, but still confirmations - that PRISM is real, we maybe have some information wrong and we should stop asking and talking about it, but it's real. While the companies and its architects all oppose the claims in a way that's very convincing. I don't know what to believe anymore.

I can't tell you want to believe, but maybe a place to start is: the world is a confusing place, full of miscommunication and gray areas. Why should we expect the world to be as it is in the movies, in which bad guys are obviously bad and that there is an "ending" in which things are clear? For starters, I just re-skimmed the Washington Post report and noticed that it has since been amended: > It is possible that the…

Well it's pretty clear now

https://news.ycombinator.com/item?id=5843352

They don't have direct backdoor, but they have a system in place for a fast and effortless data sharing.

Re: Google Chief Architect: we only respond to specific orders about individuals

#49
post #16

What I don't get is: from US government, we got confirmations - half-ass confirmations, but still confirmations - that PRISM is real, we maybe have some information wrong and we should stop asking and talking about it, but it's real. While the companies and its architects all oppose the claims in a way that's very convincing. I don't know what to believe anymore.

Don't believe. Ever. Agnosticism is a philosophy that extends well beyond religion.

Instead, focus on what you want to be true and figure out how to make that true. You probably don't want PRISM to exist, or more generally, you probably don't want an extensive surveillance program of PRISM's caliber or greater to exist. In America, or anywhere? Be specific. Figure out exactly why each component is problematic. Understand that.

Then start going about making it harder to exist. Learn about and teach ways to circumvent. Talk to people and convince them of your well-founded views. Turn the world into a place where PRISM won't exist. It's a project that can easily exceed your lifetime.

But it's better than belief.

Re: Google Chief Architect: we only respond to specific orders about individuals

#50
post #46
post #40

Two things that cannot be true at the same time: this Google+ post, and the idea that Google coughed up their TLS keys to the government.

You're one of the few whose opinion I would trust on this: how much data would the NSA need to derive TLS encryption keys from encrypted data? I feel like I read once that you could possibly use statistical methods to derive the key if you had enough encrypted source data.

The technique they'd be using to do that would be new to science.

Here it is worth pointing out that Google did something awhile ago to make NSA's job much harder (if their goal is to read everyone's mail): they became aggressive advocates for TLS forward secrecy.

http://googleonlinesecurity.blogspot.com/2011/11/protecting-...

TLS forward secrecy involves the ephemeral Diffie Hellman ciphersuites (which your browser supports). Instead of deriving a session key and using the server's RSA key to convey it, the DHE ciphersuites run the DH protocol to derive a session key between the client and the server, and then use the RSA key to sign the exchange ("breaking the tie" if there was a MITM). The RSA key is never used to convey a session key; if you got all of Google's TLS keys, you would not be able to go back in time and decrypt old sessions that used a DHE ciphersuite.

It is also worth pointing out that some of the hardest people working in security show business, including Adam Langley and Michal Zalewski and Justin Schuh, people with unimpeachable reputations in my field, work for Google on these problems.

Post reply on HN