Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

41–50 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#41

Ok, so its a bit snarky, but I wish Google would invest as much cleverness in evading the letter of these non-disclosure rules as they do in evading the letter of the tax laws in their various jurisdictions. Perhaps they could create Google Panama Ltd which is the official entity to petition for all FISA and NSL requests which is an independently operating subsidiary based in Panama and outside the jurisdiction of th…

The US needs to close its tax loopholes and stop blaming people for taking advantage of its own terrible laws. As long as the loopholes exist its in everyones best interests to take advantage of everything they can.

Re: Asking the U.S. to allow Google to publish more national security request data

#42
post #29

What are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the…

It would be a felony for anyone at NSA to attempt to "turn" an employee of Google and get them to leak secret information from Google's systems.

That is your interpretation of the law...

- NSA 2013

Re: Asking the U.S. to allow Google to publish more national security request data

#43
post #8

I'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroa…

Here's some background on what's actually going on: http://news.cnet.com/8301-13578_3-57588752-38/google-to-feds...

Re: Asking the U.S. to allow Google to publish more national security request data

#44
post #19
post #11

Earlier quoted context omitted.

So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.

1. Google probably should offer passive S/MIME on mail. START TLS goes a long way, but providing the same signals about message authenticity to people who IMAP from gmail as who use the web UI would be nice. A non-google-trusting way to do PGP with a better UI/UX would also be a nice feature for gmail. Just indicating "encrypted" at the message-list view or something. I have PGP working quite nicely in mutt, but a lo…

Everytime I think about the S/MIME and PGP issue I can't get away from the fact that you need to give your private key to the client-side JS. I'm not sure we've found all the security flaws we'll find in the browser JS model so that just seems risky to me (especially for digital signature purposes).

And as you mention, you would still have to trust Google.

Re: Asking the U.S. to allow Google to publish more national security request data

#45
Unfortunately, the statements from everyone involved have made me skeptical to the point I feel I have to consistently read between the lines and pick a statement apart.

What does "unfettered access" mean? What are "valid legal requests"?

While there is an implication of spirit in their words, I know deep down that everyone involved is focused on the letter of their words.

This has nothing to do with my personal trust and confidence in Google, but in my trust and confidence in this entire charade. Google is part of it, whether they're on the right side or not. I simply cannot tell.

Re: Asking the U.S. to allow Google to publish more national security request data

#46
post #13

In expressing his view that Google is being harmed by USG's lack of transparency (combined with the godawful operational security of the contractor-run intelligence agencies), is Google's chief counsel here starting to build the standing to sue the government? If this whole debacle sets up an epic confrontation between Google and the DoJ, I may have to reevaluate how irritated I am at how "Prism" has been reported. M…

I like the theory, but you don't need to send an open letter for standing. The FISCOR already granted standing exists for providers.

Re: Asking the U.S. to allow Google to publish more national security request data

#47
post #11

Earlier quoted context omitted.

So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.

I wish you wouldn't phrase your questions like that as it invites some to accuse you of implying that it's either the US spies on everybody or ends all foreign signals intelligence. Also, the fellow you replied to didn't specify what sort of spying needs to be stopped. He could have no issue with foreign signals intelligence (which presumably means spying on non-US folks).

The argument is that all meaningful communications (outside military tactical, and even there, a lot of it) is moving to the Internet. Without applying SIGINT to the Internet, you essentially can't have meaningful foreign SIGINT capability anymore. It's very difficult to distinguish between foreign and domestic parts of foreign-origin threats, and even more so on the Internet, at collection time.

(Even worse, as the transport security part gets better, you either need to add a bunch of active-attacker MITM or somehow compromise endpoints. At some point, even if you thought purely passive SIGINT collection was fine, the level of prior restraint on service providers/developers becomes absurd and probably no one would support it; witness the key escrow crypto wars of the 1990s.)

Generally NSA seems to put a good amount of effort into minimization post-collection. But, that only works if you trust them to be 1) forever competent and 2) forever equally ethical.

Re: Asking the U.S. to allow Google to publish more national security request data

#48
post #24

The issue here is that Google doesn't know how much data the NSA collects. The NSA has access to the internet backbone that Google uses and can read whatever traffic it wishes that leaves the Google network. Obviously this is not everything but most everything. It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. So while Google can…

> It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority.

No it isn't.

Re: Asking the U.S. to allow Google to publish more national security request data

#49
post #35

Earlier quoted context omitted.

Just to clarify, I think you are irritated with the inaccurate/sensationalist reporting of PRISM, and not that it was leaked to begin with?

My perspective on this is going to sound weird to you. 1. I am very irritated at inaccurate and sensationalized reporting. 2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens. 3. I think leaking details of signals intelligence programs should be a crime. 4. I hope Goog…

I agree with your perspective, with the exception of a slight modification to #3. I believe that leaking should be a crime, but I also believe that if the court of public opinion judges the original secret worse than the leak, that it should become politically out-of-bounds to actually prosecute the case.

I think there's a world of difference between Bradley Manning and Edward Snowden. And while I think Manning's treatment has been harsh, I do think he should be prosecuted because he was reckless and untargeted. Snowden clearly has a much more focused goal and surgical approach.

Re: Asking the U.S. to allow Google to publish more national security request data

#50
post #7

This is the kind of response I was expecting from tech companies. The mistrust of the government has extended to this industry and we can't simply rest on a simple denial of the accusations. Many people now believe that companies like Google send a complete copy of their entire customer records to the NSA. That is a dangerous belief and like discussed on other threads here, it could really damage the long term viabil…

It could really damage the long term viability of the __US__ tech industry dealing irreparable damage to one of the major assets of the US economy has. I would expect companies that need a strong international security reputation to begin closing up shop and moving away.

The NSA just killed the goose that lays the golden egg and not much is going change that.

Post reply on HN