Live data from Hacker News

Google Chief Architect: we only respond to specific orders about individuals

plus.google.com

91–100 of 107 posts

Re: Google Chief Architect: we only respond to specific orders about individuals

#91
post #86

Earlier quoted context omitted.

Don't believe. Ever. Agnosticism is a philosophy that extends well beyond religion. Instead, focus on what you want to be true and figure out how to make that true. You probably don't want PRISM to exist, or more generally, you probably don't want an extensive surveillance program of PRISM's caliber or greater to exist. In America, or anywhere? Be specific. Figure out exactly why each component is problematic. Unders…

> Be specific. Figure out exactly why each component is problematic. Understand that. Totally agree. > But it's better than belief. As someone dealing with what might be called a mild epistemological crisis, I can sympathize with the advice to apply agnosticism liberally, but I'm not sure belief can be avoided. If you want to take action for or against something, you have to ask: what if your information about that t…

> I'm not sure belief can be avoided

No, it can't. You will always believe something, positively (X exists; X is true) or negatively (X does not exist; X is false). The point is, however, is that your final resting point should never be "I don't know what to believe anymore."

> If you want to take action for or against something, you have to ask: what if your information about that thing is malformed or incomplete, due to human error (either your own or somewhere in your chosen network of cognitive authority) or even malice? The answer is that you'll never know for sure. You could always be the victim of your own or someone else's bias.

This is precisely why it's useful to apply agnosticism liberally. What you've described here is agnosticism. You don't know. You never know. If you have the fortitude for it, it is usually reliable to say that you're always wrong in some respect. But you should still act. Paralysis is worse than misjudgment.

Or to use the words of a now famous movie, "There is no certainty, only opportunity." The only reason he turned out to be right was movie magic, and nevertheless, in the movie, he admitted that he didn't know what the right action was after all.

Re: Google Chief Architect: we only respond to specific orders about individuals

#92
post #31

His comments are actually the most insightful points I've seen about the discussion regarding PRISM: I have my own suspicions -- which I won't go into here -- about what PRISM was actually about. I'll just say that there are ways to intercept people's Google, Facebook, etc., traffic in bulk without sticking any moles into the org -- or directly tapping their lines. You may find some interesting hints in the leaked PR…

There are two features in the slides that need to be accounted for in any explanation.

1. The second slide, which implies that the fact that the internet traffic passes through the US is relevant.

This implies that either some physical interception was necessary, either from outside the companies, or from the inside with their cooperation, or that it was legally necessary (on order to require the companies to deliver the information. And yet it would seem like the issue of what the NSA could require US companies to reveal, is orthogonal from which traffic passes through the US, since in that case the issue would be what was stored on US servers.

2. The implied cooperation from the companies in the slides. According to the Washington Post, the "Special Source Operations" in the logo refers to "the NSA term for alliances with trusted U.S. companies". Given this, and the use of the terms "providers", it seems unlikely that no cooperation from the companies is involved.

From the above, I would propose that the PRISM scheme must involve some combination of physical interception, and cooperation from the companies involved.

For example, the NSA may be intercepting traffic then asking the companies for private keys for some of the traffic they intercept. This would fit the above facts in that it requires the traffic to pass through the US, and also requires cooperation from the companies.

Re: Google Chief Architect: we only respond to specific orders about individuals

#93
post #78
post #42

Earlier quoted context omitted.

Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have real…

Ok so they split and copy all the packets, nobody else is concerned with the complexity of tagging, filtering, rebuilding and contextualizing this conceptual volume of packet data? Beam splitters are not enough, they would need something to interpret this traffic. Something is missing here.

Like the huge number crunching center in utah?

Re: Google Chief Architect: we only respond to specific orders about individuals

#94
post #66

Earlier quoted context omitted.

How are they getting the DH keys without cooperation from at least one of the SSL endpoints involved? They're newly generated at every SSL handshake, you can't just get a mole to hand you the keys once and be done with it. If you had the certificate private key, you could do a MITM, but this requires a LOT more resources and would be much more easily detectable.

I was clearly wrong. But I am still lost on how it would be detectable? From Google's end, some client just disconnected. From the client's end, the internet just got a tiny bit more latency.

If you had Google's certificate private key, you can pretend to be Google. It's undetectable from the user's perspective. I think we should trust Google to keep their private keys safe, although it would help a lot if the published in general terms how they accomplish this.

Re: Google Chief Architect: we only respond to specific orders about individuals

#95
post #42

Earlier quoted context omitted.

Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have real…

This is exactly the conclusion I came to. My guess is they have the SSL/TLS keys. That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.

If you hold the theory that the traffic is being intercepted and the parties have compromised the TLS keys: The test for complicity is obvious: failing to rotate out the TLS keys, failure to HSTS, and failure to switch to EDH ciphersuites everywhere.

These are all moderately 'cheap' steps if you believe you're being compromised in this manner.

Re: Google Chief Architect: we only respond to specific orders about individuals

#97
post #32
post #16

What I don't get is: from US government, we got confirmations - half-ass confirmations, but still confirmations - that PRISM is real, we maybe have some information wrong and we should stop asking and talking about it, but it's real. While the companies and its architects all oppose the claims in a way that's very convincing. I don't know what to believe anymore.

I can't tell you want to believe, but maybe a place to start is: the world is a confusing place, full of miscommunication and gray areas. Why should we expect the world to be as it is in the movies, in which bad guys are obviously bad and that there is an "ending" in which things are clear? For starters, I just re-skimmed the Washington Post report and noticed that it has since been amended: > It is possible that the…

Yeah, but you'd need a Dynamic Tasking Control Protocol. A big mirror makes a big beam.

Re: Google Chief Architect: we only respond to specific orders about individuals

#98
post #42

Earlier quoted context omitted.

Beam splitters (prisms?) inside the backbone providers. All traffic goes to its destination unharmed, but the NSA gets all the packets. SSL is harder, but all you need is the private keys. Those are hard to get but not impossible for someone with the resources of the government. This is the only scalable way to do what they are supposed to be doing and not involve lots of outsiders. Note that the people who have real…

This is exactly the conclusion I came to. My guess is they have the SSL/TLS keys. That being said, tptacek thinks we are wrong, and he is a subject matter expert, so I am not sure.

Indeed, I'm highly inclined to defer to tptacek's experience here.

Re: Google Chief Architect: we only respond to specific orders about individuals

#99
post #94

Earlier quoted context omitted.

I was clearly wrong. But I am still lost on how it would be detectable? From Google's end, some client just disconnected. From the client's end, the internet just got a tiny bit more latency.

If you had Google's certificate private key, you can pretend to be Google. It's undetectable from the user's perspective. I think we should trust Google to keep their private keys safe, although it would help a lot if the published in general terms how they accomplish this.

The signing key for Gmail's certificate is a 1024-bit RSA key. That key size is simply not safe against an attacker like the NSA today, so we may as well assume they have the private key even if Google didn't voluntarily give it to them.

But while the signing key may allow them to impersonate Google in some circumstances, it doesn't really help decrypting passively recorded TLS traffic to the real Google. For that, they would need to break the ECDH key exchange, and if Google uses reasonable elliptic curve parameters, that's presumably much harder than factoring a 1024-bit RSA modulus, at least with known cryptanalytic techniques.

Re: Google Chief Architect: we only respond to specific orders about individuals

#100
post #78

Earlier quoted context omitted.

Ok so they split and copy all the packets, nobody else is concerned with the complexity of tagging, filtering, rebuilding and contextualizing this conceptual volume of packet data? Beam splitters are not enough, they would need something to interpret this traffic. Something is missing here.

Like the huge number crunching center in utah?

[deleted]
Post reply on HN