Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

101–110 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#101
post #35

Earlier quoted context omitted.

Just to clarify, I think you are irritated with the inaccurate/sensationalist reporting of PRISM, and not that it was leaked to begin with?

My perspective on this is going to sound weird to you. 1. I am very irritated at inaccurate and sensationalized reporting. 2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens. 3. I think leaking details of signals intelligence programs should be a crime. 4. I hope Goog…

3. I think leaking details of signals intelligence programs should be a crime.

I think dealing in absolutes, anywhere, should be a crime.

Re: Asking the U.S. to allow Google to publish more national security request data

#102

So I'm a bit confused. Google has been happily complying with NSA without a care or concern in the world. Now some news leaks that they have been.. Happily complying with NSA without a care or concern in the world. So they release an "open" letter trying to redirect the masses attention, and I'm not a little shocked it's working. People are actually praising Google? WTH? If Google really cared this letter is like 5 y…

The sad thing is that this letter is currently frontpage/top of HN. The #1 most important company implicated in this NSA leak; the very company accused of co-operating & enabling the NSA's intrusive violation of our privacy - is now enjoying this great exposure at the top of HN as 'hackers' eat it up.

Re: Asking the U.S. to allow Google to publish more national security request data

#103
post #11
post #8

I'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroa…

So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.

Harm online security how?

Re: Asking the U.S. to allow Google to publish more national security request data

#104
post #84

Earlier quoted context omitted.

I second this question. I know it seems like it would be against the law...but a lot of things that seem like they would be against the law actually aren't, so I'm interested in specifics.

Employees of the NSA cannot in fact do things that are felonies under federal law and be immune from prosecution.

While you're correct as a matter of legal theory, this doesn't happen in practice. Aside from Felt and Miller who were given small fines and then pardoned, can you name another precedent for prosecuting government employees for overreach in intelligence and security matters? Is there even a single example where a meaningful penalty was dispensed?

Re: Asking the U.S. to allow Google to publish more national security request data

#105
post #69
post #66

Earlier quoted context omitted.

It's not about a few people using those encryption tools. It's about major companies like Google making them mainstream tools , and also making them very easy to use (as easy as it can get).

My point is that Google Mail is an insecure setting from which to deliver PGP.

Because it's a website?

Re: Asking the U.S. to allow Google to publish more national security request data

#107

Earlier quoted context omitted.

> It is a low view of the NSA to think that they do not > have the ability to real-time decrypt SSL certs from > every major SSL cert authority. The technology required to break SSL is sufficiently advanced that any organization possessing it would probably have easier ways to collect data, all of which would grossly outmatch all known security precautions. There would be no need for any of these sneaking-around stuf…

The only thing required to "break" SSL in the absence of some serious protocol flaw is either the ability to MITM connections with a CA-signed certificate, or possession of the private key used by the server.

You should educate yourself on Perfect Forward Secrecy and pinned certificates.

Re: Asking the U.S. to allow Google to publish more national security request data

#109

While I'd like to know how many secret requests are being made to whom, why should I ever believe any numbers? We're living in crazy-town, maybe we always were. What is to stop the A.G. from publicly saying "Yes, disclose away!" and then to privately send one of those magic-do-anything-we-say requests saying, "Don't disclose X, Y, and Z."? Or if we are given an accurate count today, what is to prevent the government…

Good point. If they can force companies to lie about the existence of FISA requests, why wouldn't they force them to lie about the number of such?

Re: Asking the U.S. to allow Google to publish more national security request data

#110
I suppose it would be nice to know how many FISA requests there have been, but what does the number of requests have to do with the core issue? Is the number of FISA requests in proportion to the amount of data being shared? Does it tell us the nature of what is shared or how it is shared? We still know nothing about the contents of legal FISA requests and therefore can't really say whether a single request violates our rights or not. Publishing aggregates tells us essentially nothing because we still don't know the limits of a request, or at least I don't.
Post reply on HN