Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

141–150 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#141

Earlier quoted context omitted.

Because it's a website?

That is one big reason, yes.

I'm curious what the other big reasons are. I send & receive GPG encrypted messages via Gmail occasionally and it's no different than using any other mail provider (of course, I'm using mutt, GnuPG, and SMTP/IMAP and not web-mail).

Re: Asking the U.S. to allow Google to publish more national security request data

#142
post #118
post #109

Earlier quoted context omitted.

Good point. If they can force companies to lie about the existence of FISA requests, why wouldn't they force them to lie about the number of such?

What lies have companies told?

From the news I've read, my understanding about FISA is that if someone asks you whether you've been subject to one, you're legally obligated to lie and say no. Right, or am I missing something?

Re: Asking the U.S. to allow Google to publish more national security request data

#143
post #67

Earlier quoted context omitted.

It's not just snarky, it's preposterously unreasonable. How much work do you, personally, put into making money? At least 40 hours a week, I'm guessing, plus the time you spend on managing your investments, doing your taxes, and so on? How much work do you put into maintaining your own privacy? Is it even 1 hour per week, on average? Really? Note that Google has, allegedly, already put a LOT of work into pushing back…

Not precisely a rebuttal (you missed my point) but an interesting point in it's own right which I read was "Can you evaluate dollar value of privacy using the dollar value of your income stream?" And doing a sort of solve for X thing where you end up with hours invested in maintaining privacy becoming valued at hours invested in generating income. If I misunderstood please let me know, but assuming that I got the gis…

Okay, 80% of your comment is replying to a framing that you chose earlier. You said Google should spend comparable amounts of effort on X and Y. In that context, I pointed out that no one spends even 10% as much effort on X as on Y, so why would you ask Google to, and you're being completely unfair. YOU chose this context.

And I am _highly_ skeptical about this "reconfirm your TOS, as a hint that there's an NSL on you". (I have no inside knowledge of this, and if I did I would lie to you about it.) But if any engineer did that, and got caught, they'd go to jail. Given that 99.9% of users who're NSLed will not have read that blogpost (the crazy tinfoil-hat wild-speculation one that started this rumour), what would be the benefit? No benefit, but one conscientious engineer goes to jail. Yay.

Law, in general, is just as concerned with the spirit of the law as the letter.

My whole reply is that Google is already working harder on privacy, as a fraction of total resources, than nearly anyone you've ever met, and certainly more than nearly any corporation. (Unless Google is lying about basically everything, which I can't/won't prove they/we are not). Your expectations, as originally stated, are unreasonable.

Disclaimer: And yes, I have a vested interest. Hopefully my argument stands on its own merits. Your call to action is insulting.

Re: Asking the U.S. to allow Google to publish more national security request data

#144
post #119
post #54

Earlier quoted context omitted.

I don't know enough about what happened with Snowden to have an opinion about him one way or another; I'm just not of the opinion that leaks are by default heroic.

What if one of Kim Jung Un's subordinates leaks details on "abuses" in the prison camp system? Technically he's breaking the law - North Korea's law - but I think it would be difficult to say that it would be the wrong thing to do. Also, if these reports are accurate, then I wouldn't necessarily consider that analogy too hyperbolic.

The key phrase in tptacek's comment would be "by default."

Re: Asking the U.S. to allow Google to publish more national security request data

#145
post #142
post #118

Earlier quoted context omitted.

What lies have companies told?

From the news I've read, my understanding about FISA is that if someone asks you whether you've been subject to one, you're legally obligated to lie and say no. Right, or am I missing something?

That is the impression that I've been given from reading the stories about the stress of living under a FISA order and lying to everyone about it.

Which is not to say Google or anyone else is lying about the nature or the scope or anything else about the requests they have received. But the problem is that we can't ever know one way or the other, because we have apparently created a system of secrecy and dishonesty. Once you know someone (in this case, the intelligence community, and those they compel) has a history of lying to you, how do you move past that back into a state of trust?

Re: Asking the U.S. to allow Google to publish more national security request data

#146
post #53
post #52

Earlier quoted context omitted.

W3C webcrypto, done in a smart way, is probably one of the most critical pieces of security infrastructure to be built today. I'm not talking about giving the real PGP or S/MIME to Google; just a UI flag saying "this message has special content, click here to download". And some kind of low-assurance S/MIME signature which just says "was downloaded from gmail" to protect from local modification. I'm not sure how mail…

It's not being done in a particularly smart way; Web Crypto has more to do with enabling pure-web plugin-free streaming media than with enabling secure browser-based PGP.

I think you're thinking of Encrypted Media Extensions https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-med...

Re: Asking the U.S. to allow Google to publish more national security request data

#147

Earlier quoted context omitted.

Not precisely a rebuttal (you missed my point) but an interesting point in it's own right which I read was "Can you evaluate dollar value of privacy using the dollar value of your income stream?" And doing a sort of solve for X thing where you end up with hours invested in maintaining privacy becoming valued at hours invested in generating income. If I misunderstood please let me know, but assuming that I got the gis…

Okay, 80% of your comment is replying to a framing that you chose earlier. You said Google should spend comparable amounts of effort on X and Y. In that context, I pointed out that no one spends even 10% as much effort on X as on Y, so why would you ask Google to, and you're being completely unfair. YOU chose this context. And I am _highly_ skeptical about this "reconfirm your TOS, as a hint that there's an NSL on yo…

Fair enough, we've spent a lot of effort at Blekko (also a search engine) at being conscientious designing ways that we can dis-associate data from users in order to protect our users from data that can be tied back to them. Since our taxes are reasonably straight-forward at this point it is entirely possible that we've invested more time in keeping peoples identities protected in our data than we have in minimizing our tax burden. We are a prima facie example of "someone" who has spent more effort on X than Y. But arguing exemplars misses the point.

I am sure that Google is a much different place than when I left it, hell it was different between the time I joined and left. That said ...

The comparison I was trying to make, and I grant you that it is imperfect, is that Google, like Apple, has billions of dollars in free cash flow and in legal testimony lately they have shown great creativity in ways to shuffle that cash around so as to avoid being required to hand it over to various revenue agencies. Google is also has billions of data points about all of the individuals that use its services. If those data points were dollars, and the revenue agencies were intelligence agencies, what creative ways might they come up with to disassociate which data point belongs to which user such that they could still use the data but not be compelled to hand it over. Just like they use those free cash dollars rather than hand some percentage over as tax.

I've got nothing but respect for the smart people at Google, and still have friends that work there (and folks who used to work here and are now working there :-). Perhaps I'm misreading your tone but it sounds like you want to pick a fight.

Re: Asking the U.S. to allow Google to publish more national security request data

#150

Earlier quoted context omitted.

Disclaimer: I work at Google. I'm working on the client-side (Chrome) and my knowledge in the server area is therefore limited, but from my understanding this would be really hard. 1. Googlers have access to almost all source code. It would be difficult to hide code that just sends data to an outside entity. 2. Google continually monitors its (internal) bandwidth. This is done to optimize traffic, and detect intruder…

I see a big potential benefit for the NSA to have a spy within google who simply manually pulls and relays info on people at th nsa's request... It doesn't have to be a full Api

Access to sensitive data is strictly controlled, logged and audited, often on a per-case basis ("I need read access to log X for 60 minutes to investigate bug Y"). Even if your hypothetical spy did manage to worm their way into the very, very select ranks of people who can access (say) Gmail data, he'd be busted as soon as the auditors spotted him accessing the files of people he has no reason to access.
Post reply on HN