Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

81–90 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#81
post #72
post #70

Earlier quoted context omitted.

It's a good thing secret courts can, then.

The actual filings before FISA are secret; they're signals intelligence cases. The laws the FISA court uses to authorize surveillance are not secret.

The interpretation of the Law rests on judicial opinions. Many of those decisions are indeed secret, rendering the interpretation of the law itself secret. I think it's reasonable to say that this makes the laws 'secret', since it is impossible to know whether you are in violation without knowing the interpretation.

Source: https://www.eff.org/deeplinks/2013/06/government-says-secret...

Re: Asking the U.S. to allow Google to publish more national security request data

#82
post #29

Earlier quoted context omitted.

It would be a felony for anyone at NSA to attempt to "turn" an employee of Google and get them to leak secret information from Google's systems.

Really? What law is that covered under? (genuinely interested, because I did not know this)

I second this question. I know it seems like it would be against the law...but a lot of things that seem like they would be against the law actually aren't, so I'm interested in specifics.

Re: Asking the U.S. to allow Google to publish more national security request data

#83
post #67

Ok, so its a bit snarky, but I wish Google would invest as much cleverness in evading the letter of these non-disclosure rules as they do in evading the letter of the tax laws in their various jurisdictions. Perhaps they could create Google Panama Ltd which is the official entity to petition for all FISA and NSL requests which is an independently operating subsidiary based in Panama and outside the jurisdiction of th…

It's not just snarky, it's preposterously unreasonable. How much work do you, personally, put into making money? At least 40 hours a week, I'm guessing, plus the time you spend on managing your investments, doing your taxes, and so on? How much work do you put into maintaining your own privacy? Is it even 1 hour per week, on average? Really? Note that Google has, allegedly, already put a LOT of work into pushing back…

On your last point, I would argue that the more power and information an organization or individual has, the higher the standard should be.

Re: Asking the U.S. to allow Google to publish more national security request data

#84

Earlier quoted context omitted.

Really? What law is that covered under? (genuinely interested, because I did not know this)

I second this question. I know it seems like it would be against the law...but a lot of things that seem like they would be against the law actually aren't, so I'm interested in specifics.

Employees of the NSA cannot in fact do things that are felonies under federal law and be immune from prosecution.

Re: Asking the U.S. to allow Google to publish more national security request data

#85
post #51
post #35

Earlier quoted context omitted.

My perspective on this is going to sound weird to you. 1. I am very irritated at inaccurate and sensationalized reporting. 2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens. 3. I think leaking details of signals intelligence programs should be a crime. 4. I hope Goog…

> 3. I think leaking details of signals intelligence programs should be a crime. This one surprised me. Wouldn't the strongest signals intelligence program be one that doesn't need to depend on obfuscation?

Can you expand on this idea?

I would think that one of the main points of signals intelligence and their efficacy is if the emitter is not aware that you are collecting their signal.

Re: Asking the U.S. to allow Google to publish more national security request data

#86

What are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the…

In order for this to be an option, it would have to mean that all of the internal security and audit controls at Google were bullshit, wouldn't it?

Re: Asking the U.S. to allow Google to publish more national security request data

#87
post #24

The issue here is that Google doesn't know how much data the NSA collects. The NSA has access to the internet backbone that Google uses and can read whatever traffic it wishes that leaves the Google network. Obviously this is not everything but most everything. It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. So while Google can…

> It is a low view of the NSA to think that they do not > have the ability to real-time decrypt SSL certs from > every major SSL cert authority. The technology required to break SSL is sufficiently advanced that any organization possessing it would probably have easier ways to collect data, all of which would grossly outmatch all known security precautions. There would be no need for any of these sneaking-around stuf…

The only thing required to "break" SSL in the absence of some serious protocol flaw is either the ability to MITM connections with a CA-signed certificate, or possession of the private key used by the server.

Re: Asking the U.S. to allow Google to publish more national security request data

#88

You have to think, that with the limited data they are allowed to release, this must be extremely frustrating! A true rock and a hard place. The general public are led to believe, that they are willing to conspire secretly together with the government, to spy on their customers, must not only be infuriating, but brand damaging! Then you are required by law not to defend yourself ;) p.s. I'm taking google at their wor…

As a Google employee I find it extremely frustrating. I'm sure it's even more so for the executives and founders who created the brand and are being personally questioned and attacked on top of it.

Re: Asking the U.S. to allow Google to publish more national security request data

#89

What are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the…

In order for this to be an option, it would have to mean that all of the internal security and audit controls at Google were bullshit, wouldn't it?

Security and audit controls are almost always bullshit. We're discussing a story that arose because a three-month tenure employee for an external contractor had wide ranging access to tonnes of stuff in the NSA. Previously Bradley Manning demonstrate the same with the armed forces.

Are all internal Google communications encrypted? Probably not, but even if they are if you work in network security you likely hold the keys to that encryption regardless. You probably have access to their PKI keys as well.

Re: Asking the U.S. to allow Google to publish more national security request data

#90
post #7

This is the kind of response I was expecting from tech companies. The mistrust of the government has extended to this industry and we can't simply rest on a simple denial of the accusations. Many people now believe that companies like Google send a complete copy of their entire customer records to the NSA. That is a dangerous belief and like discussed on other threads here, it could really damage the long term viabil…

It could really damage the long term viability of the __US__ tech industry dealing irreparable damage to one of the major assets of the US economy has. I would expect companies that need a strong international security reputation to begin closing up shop and moving away. The NSA just killed the goose that lays the golden egg and not much is going change that.

[deleted]
Post reply on HN