Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

61–70 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#61
post #5

Aggregate number of requests is one thing, but perhaps some indication of how much content is provided with the average request would be required to really indicate what is going on here? An API may serve millions of requests per day and return single-integer responses, or it might serve one batch query per day and provide a nested document with many sub-sections.

"millions of requests per day"?! the number of FISA requests since 1979 is just short of 34,000: http://www.motherjones.com/mojo/2013/06/fisa-court-nsa-spyin... Let's try and keep the speculation to a minimum.

As others have stated, it's fairly apparent that the parent poster wasn't talking about actual numbers, and was painting an example where the number of requests is meaningless without the scope (i.e. does each request specify one individual, or 20 individuals?). That said, this includes NSLs (National Security Letters) which do not have to go through a court, and which I don't believe there are any published numbers for (either in number of NSLs or their scope).

Re: Asking the U.S. to allow Google to publish more national security request data

#62
post #7

This is the kind of response I was expecting from tech companies. The mistrust of the government has extended to this industry and we can't simply rest on a simple denial of the accusations. Many people now believe that companies like Google send a complete copy of their entire customer records to the NSA. That is a dangerous belief and like discussed on other threads here, it could really damage the long term viabil…

It could really damage the long term viability of the __US__ tech industry dealing irreparable damage to one of the major assets of the US economy has. I would expect companies that need a strong international security reputation to begin closing up shop and moving away. The NSA just killed the goose that lays the golden egg and not much is going change that.

I disagree that this is a problem limited to US companies. With the global nature of the tech industry, I think a product's or service's country of origin has seen a reduced importance over the years. I don't think the average consumer knows that Waze is based in Israel. I don't foresee anyone considering the NSA and choosing a Canadian designed Blackberry phone over a US designed Apple one. Instead I think this will just instill a general distrust of technology and the cloud. I doubt people will be discerning enough to focus their suspicions.

Re: Asking the U.S. to allow Google to publish more national security request data

#63
post #42
post #29

Earlier quoted context omitted.

It would be a felony for anyone at NSA to attempt to "turn" an employee of Google and get them to leak secret information from Google's systems.

That is your interpretation of the law... - NSA 2013

And the NSA is not the one that ultimately decides the interpretation of the law.

Re: Asking the U.S. to allow Google to publish more national security request data

#64

Earlier quoted context omitted.

I really doubt Google is going to play chicken about something so serious as giving away all their user data. Is it incomprehensible to you that they are telling the truth?

The problem Google has is that a huge number of their users -- those in foreign countries -- have (finally) realised what has been public knowledge for years: they have no legal protection at all from the US government examining data Google holds about them and that Google readily comply with such requests and aren't really in a position to do much else. 'Telling the truth' involves restating this truth in the full g…

> "employ crypto on the users side but that undermines the economics of much of their business"

This is true, at least in Google's situation. However I think there is an untapped market of people that want to be advertised to, provided the advertising is relevant.

Surprisingly I think traditional print magazines actually have this figured out. The advertisements for designer clothing, watches, and booze get a lot of readership in "gentleman/bachelor/whatever" magazines (not sure what the correct term there is, not trying to refer to porn (well, except Playboy)) and I suspect that removing them would actually damage their subscription rates. Now, these adverts obviously are not targeted to the individual, but I think they nevertheless demonstrate the concept.

Re: Asking the U.S. to allow Google to publish more national security request data

#65
post #29

What are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the…

It would be a felony for anyone at NSA to attempt to "turn" an employee of Google and get them to leak secret information from Google's systems.

Really? What law is that covered under?

(genuinely interested, because I did not know this)

Re: Asking the U.S. to allow Google to publish more national security request data

#66
post #11
post #8

I'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroa…

So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.

It's not about a few people using those encryption tools. It's about major companies like Google making them mainstream tools, and also making them very easy to use (as easy as it can get).

Re: Asking the U.S. to allow Google to publish more national security request data

#67

Ok, so its a bit snarky, but I wish Google would invest as much cleverness in evading the letter of these non-disclosure rules as they do in evading the letter of the tax laws in their various jurisdictions. Perhaps they could create Google Panama Ltd which is the official entity to petition for all FISA and NSL requests which is an independently operating subsidiary based in Panama and outside the jurisdiction of th…

It's not just snarky, it's preposterously unreasonable.

How much work do you, personally, put into making money? At least 40 hours a week, I'm guessing, plus the time you spend on managing your investments, doing your taxes, and so on? How much work do you put into maintaining your own privacy? Is it even 1 hour per week, on average? Really?

Note that Google has, allegedly, already put a LOT of work into pushing back on ensuring that due process is followed. Many engineers, many lawyers, lots of executive-decision-effort.

Maybe you don't believe anything Drummond or Page say? Maybe you think google.com/transparencyreport is purely fabricated? Maybe you think Google should violate the law and get shut down (that's what you said, actually, with "evade the letter of the law", but I find that position so laughable that I assume I misunderstood you)? Maybe you yourself actually DO spend the same time on privacy that you spend on pecuniary gain, or maybe you expect Google to hew to a higher standard than you yourself do?

Re: Asking the U.S. to allow Google to publish more national security request data

#68

Earlier quoted context omitted.

I really doubt Google is going to play chicken about something so serious as giving away all their user data. Is it incomprehensible to you that they are telling the truth?

The problem Google has is that a huge number of their users -- those in foreign countries -- have (finally) realised what has been public knowledge for years: they have no legal protection at all from the US government examining data Google holds about them and that Google readily comply with such requests and aren't really in a position to do much else. 'Telling the truth' involves restating this truth in the full g…

>Telling the truth' involves restating this truth in the full glare of worldwide publicity. The more they try to reassure americans that everything they did was 'legal'[1] and only targeted foreigners, the more foreigners they alienate

I'm sorry but where are you getting this from? Google has categorically stated that they do not share data without court approved mandates. There is no mass "targeting" that is going on, no matter what the nationality.

Re: Asking the U.S. to allow Google to publish more national security request data

#69
post #66
post #11

Earlier quoted context omitted.

So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.

It's not about a few people using those encryption tools. It's about major companies like Google making them mainstream tools , and also making them very easy to use (as easy as it can get).

My point is that Google Mail is an insecure setting from which to deliver PGP.

Re: Asking the U.S. to allow Google to publish more national security request data

#70
post #63
post #42

Earlier quoted context omitted.

That is your interpretation of the law... - NSA 2013

And the NSA is not the one that ultimately decides the interpretation of the law.

It's a good thing secret courts can, then.
Post reply on HN