Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

161–170 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#161
post #126

Earlier quoted context omitted.

For heaven's sake: there's a compromise to be reached between sending postcards and using a Brink's truck.

No, there isn't. Protecting secrets cryptographically is an engineering problem. There are right answers and wrong answers, and having Google Mail deliver PGP to you directly is a wrong answer.

First, you know full well that security is a matter of degree, and not binary thing. It's tradeoff against convenience that can be made more easily when there's a trusted third party. We're already willing to trust webmail providers with all our email -- how can it possibly be worse than the status quo if suddenly everyone can use PGP transparently, too?

Re: Asking the U.S. to allow Google to publish more national security request data

#162
Smart response. Very smart. Damage control at its best: "How we wish we could tell you that it's not so bad as you think it is... but government won't let us... Government, pretty please?"

They just put the spotlight on Administration, which of course won't allow it. Smart.

Re: Asking the U.S. to allow Google to publish more national security request data

#163
"Assertions in the press that our compliance with these [FISA] requests gives the U.S. government unfettered access to our users’ data are simply untrue."

What about the non-FISA requests, has any of them given the U.S. government unfettered access to user data?

What does unfettered mean? "You only can access all user data for 2 hours" "You need to specify (through tickboxes?) all the user data you wish to download to PRISM" "You only access all user data of all German users"

Re: Asking the U.S. to allow Google to publish more national security request data

#164

I'm more interested in the international numbers, as US politics seems to differentiate between US citizens and non-US citizens when it comes to human rights. Edit: Or is this also including requests for users in other countries? Sorry, English is not my mother tongue, so I might got it wrong.

I believe, if it continues as it is currently, the numbers are government requests, and how many users effected. There is no check or distinguishment in whether the government and the user's country match.

They also publish non-us government requests as well.

Re: Asking the U.S. to allow Google to publish more national security request data

#165
post #7

This is the kind of response I was expecting from tech companies. The mistrust of the government has extended to this industry and we can't simply rest on a simple denial of the accusations. Many people now believe that companies like Google send a complete copy of their entire customer records to the NSA. That is a dangerous belief and like discussed on other threads here, it could really damage the long term viabil…

It could really damage the long term viability of the __US__ tech industry dealing irreparable damage to one of the major assets of the US economy has. I would expect companies that need a strong international security reputation to begin closing up shop and moving away. The NSA just killed the goose that lays the golden egg and not much is going change that.

I wouldn't say the NSA killed the goose any more than I would say any other organizations that request warrants for user data did. What killed the goose was mass hysteria caused by a mistaken belief that Google let NSA see any user's data at the touch of a button. Poor journalism killed the golden goose.

Re: Asking the U.S. to allow Google to publish more national security request data

#166
post #161

Earlier quoted context omitted.

No, there isn't. Protecting secrets cryptographically is an engineering problem. There are right answers and wrong answers, and having Google Mail deliver PGP to you directly is a wrong answer.

First, you know full well that security is a matter of degree, and not binary thing. It's tradeoff against convenience that can be made more easily when there's a trusted third party. We're already willing to trust webmail providers with all our email -- how can it possibly be worse than the status quo if suddenly everyone can use PGP transparently, too?

After this past week, how can you possibly suggest that webmail providers like GMail are trusted third parties?

Re: Asking the U.S. to allow Google to publish more national security request data

#167

From here on in this is the only privacy model I will consider trustworthy for a cloud service; You have the encryption key, the data on our servers is completely useless without that encryption key. We are physically unable to be compelled to comply with any orders to violate your privacy from anyone. The only example of a cloud service I can think of that matches this off the top of my head is spideroak and tarsnap…

You can use things like Duplicity which locally encrypt backups and then store them to arbitrary cloud services. The problem is, if the data is opaque to the cloud service, it is very hard for it to do anything other than passively store and retrieve it, at which point it is not really a cloud service at all. And even then: they can give logs to authorities showing what you accessed when and from where, they probably…

I have an 8gb truecrypt file on dropbox, pretty much regardless of what they're compelled to do, it's secure. That's the model I think should be standard for cloud ops.

However, you do bring up an interesting point, it is indeed harder to do "useful stuff" when the store is untrusted and has no idea what it's holding, string searches et al become pretty much impossible generally speaking, big bummer there.

Perhaps this will be a good accelerant for the adoption of homomorphic encryption algorithms?

Re: Asking the U.S. to allow Google to publish more national security request data

#168

Earlier quoted context omitted.

> mistrust of the government has extended to this industry I'm sorry, are we now taking the opportunity to blame big evil government for this? The mistrust of this industry has always existed as a completely separate issue due to the utter lack of respect for privacy and privacy related laws, an attitude of which Google is one the most prominent exponents. This is a company that lobbies governments against privacy pr…

You have a valid point, but you're overlooking a really crucial difference: data in the hands of a corporations means something entirely different from data in the hands of government. One of them has a monopoly on the use of force and the other doesn't. At least, that's the distinction that is important to me.

Not to mention that one is voluntary* and one isn't. Sheesh, my grandparent comment needs a healthy dose of perspective.

*I'm using voluntary here in the most straightforward sense possible. You can switch services if you'd like, or even turn off ad targeting for most services. You cannot, however, go to a an nsa.gov link and click the "Please don't track me" box.

Re: Asking the U.S. to allow Google to publish more national security request data

#169

So I'm a bit confused. Google has been happily complying with NSA without a care or concern in the world. Now some news leaks that they have been.. Happily complying with NSA without a care or concern in the world. So they release an "open" letter trying to redirect the masses attention, and I'm not a little shocked it's working. People are actually praising Google? WTH? If Google really cared this letter is like 5 y…

> So they release an "open" letter trying to redirect the masses attention > If Google really cared this letter is like 5 years too late doncha think?

You should read the news occasionally. Google has been publishing a Transparency Report since 2010, and has been expanding it since then. Not quite 5 years, but more than long enough to render your comment paranoid nonsense.

Re: Asking the U.S. to allow Google to publish more national security request data

#170

Earlier quoted context omitted.

It could really damage the long term viability of the __US__ tech industry dealing irreparable damage to one of the major assets of the US economy has. I would expect companies that need a strong international security reputation to begin closing up shop and moving away. The NSA just killed the goose that lays the golden egg and not much is going change that.

I wouldn't say the NSA killed the goose any more than I would say any other organizations that request warrants for user data did. What killed the goose was mass hysteria caused by a mistaken belief that Google let NSA see any user's data at the touch of a button. Poor journalism killed the golden goose.

How can you blame journalism when the nature of those data requests is such that in some cases companies (and even politicians) cannot talk about them, cannot fight them in court and they do not have to be approved by a judge?

This leaves a lot of space for speculation, how can somebody possibly know if they didn't request a bulk copy of all Facebook data? Or issue a billion seperate requests when by law nobody can talk about the count and scope of those requests. If I were a journalist, the first thing I would question is if they did exactly this, because they wrote a law that allows exactly this type of behaviour.

Post reply on HN