Ok, so its a bit snarky, but I wish Google would invest as much cleverness in evading the letter of these non-disclosure rules as they do in evading the letter of the tax laws in their various jurisdictions. Perhaps they could create Google Panama Ltd which is the official entity to petition for all FISA and NSL requests which is an independently operating subsidiary based in Panama and outside the jurisdiction of th…
Asking the U.S. to allow Google to publish more national security request data
41–50 of 189 posts
Re: Asking the U.S. to allow Google to publish more national security request data
#42What are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the…
It would be a felony for anyone at NSA to attempt to "turn" an employee of Google and get them to leak secret information from Google's systems.
- NSA 2013
Re: Asking the U.S. to allow Google to publish more national security request data
#43I'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroa…
Re: Asking the U.S. to allow Google to publish more national security request data
#44Earlier quoted context omitted.
So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.
1. Google probably should offer passive S/MIME on mail. START TLS goes a long way, but providing the same signals about message authenticity to people who IMAP from gmail as who use the web UI would be nice. A non-google-trusting way to do PGP with a better UI/UX would also be a nice feature for gmail. Just indicating "encrypted" at the message-list view or something. I have PGP working quite nicely in mutt, but a lo…
And as you mention, you would still have to trust Google.
Re: Asking the U.S. to allow Google to publish more national security request data
#45What does "unfettered access" mean? What are "valid legal requests"?
While there is an implication of spirit in their words, I know deep down that everyone involved is focused on the letter of their words.
This has nothing to do with my personal trust and confidence in Google, but in my trust and confidence in this entire charade. Google is part of it, whether they're on the right side or not. I simply cannot tell.
Re: Asking the U.S. to allow Google to publish more national security request data
#46In expressing his view that Google is being harmed by USG's lack of transparency (combined with the godawful operational security of the contractor-run intelligence agencies), is Google's chief counsel here starting to build the standing to sue the government? If this whole debacle sets up an epic confrontation between Google and the DoJ, I may have to reevaluate how irritated I am at how "Prism" has been reported. M…
Re: Asking the U.S. to allow Google to publish more national security request data
#47Earlier quoted context omitted.
So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.
I wish you wouldn't phrase your questions like that as it invites some to accuse you of implying that it's either the US spies on everybody or ends all foreign signals intelligence. Also, the fellow you replied to didn't specify what sort of spying needs to be stopped. He could have no issue with foreign signals intelligence (which presumably means spying on non-US folks).
(Even worse, as the transport security part gets better, you either need to add a bunch of active-attacker MITM or somehow compromise endpoints. At some point, even if you thought purely passive SIGINT collection was fine, the level of prior restraint on service providers/developers becomes absurd and probably no one would support it; witness the key escrow crypto wars of the 1990s.)
Generally NSA seems to put a good amount of effort into minimization post-collection. But, that only works if you trust them to be 1) forever competent and 2) forever equally ethical.
Re: Asking the U.S. to allow Google to publish more national security request data
#48The issue here is that Google doesn't know how much data the NSA collects. The NSA has access to the internet backbone that Google uses and can read whatever traffic it wishes that leaves the Google network. Obviously this is not everything but most everything. It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. So while Google can…
No it isn't.
Re: Asking the U.S. to allow Google to publish more national security request data
#49Earlier quoted context omitted.
Just to clarify, I think you are irritated with the inaccurate/sensationalist reporting of PRISM, and not that it was leaked to begin with?
My perspective on this is going to sound weird to you. 1. I am very irritated at inaccurate and sensationalized reporting. 2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens. 3. I think leaking details of signals intelligence programs should be a crime. 4. I hope Goog…
I think there's a world of difference between Bradley Manning and Edward Snowden. And while I think Manning's treatment has been harsh, I do think he should be prosecuted because he was reckless and untargeted. Snowden clearly has a much more focused goal and surgical approach.
Re: Asking the U.S. to allow Google to publish more national security request data
#50This is the kind of response I was expecting from tech companies. The mistrust of the government has extended to this industry and we can't simply rest on a simple denial of the accusations. Many people now believe that companies like Google send a complete copy of their entire customer records to the NSA. That is a dangerous belief and like discussed on other threads here, it could really damage the long term viabil…
The NSA just killed the goose that lays the golden egg and not much is going change that.