Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

181–189 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#181

Earlier quoted context omitted.

[citation needed]. Again, i have seen this in argument after argument. Nobody has yet provided any legal authority that states it is constitutional or legal for the government to compel forced lies. They can compel silence, for sure. There is plenty of authority in other contexts (IE not national security), that the government cannot compel you to speak misleading or non-truthful information. I wish this idea that ev…

You're interneting wrong. Of course we can't give official links pointing to where this is policy, that's the point of the policy! But from the information we've gathered so far it very much appears to be the case that companies are forced to deny getting requests from the government, not just be silent. And don't bother trying to work out how the law allows this, we're not even allowed to know what some of the laws…

"And don't bother trying to work out how the law allows this, we're not even allowed to know what some of the laws even are. " This is false. You may not be allowed to know some internal agency regulations, but that's always been the case.

What laws do you think you can't know of, exactly?

Re: Asking the U.S. to allow Google to publish more national security request data

#182
post #53

Earlier quoted context omitted.

It's not being done in a particularly smart way; Web Crypto has more to do with enabling pure-web plugin-free streaming media than with enabling secure browser-based PGP.

I think you're thinking of Encrypted Media Extensions https://dvcs.w3.org/hg/html-media/raw-file/tip/encrypted-med...

No, I'm thinking about the design decisions the Web Crypto team made and the mailing list posts that supported them.

Re: Asking the U.S. to allow Google to publish more national security request data

#183
post #166
post #161

Earlier quoted context omitted.

First, you know full well that security is a matter of degree, and not binary thing. It's tradeoff against convenience that can be made more easily when there's a trusted third party. We're already willing to trust webmail providers with all our email -- how can it possibly be worse than the status quo if suddenly everyone can use PGP transparently, too?

After this past week, how can you possibly suggest that webmail providers like GMail are trusted third parties?

Well, they are trusted 3rd parties, regardless of whether or not you happen to trust them. Anyone who has a private Gmail account necessarily trusts Gmail.

In any case, the argument isn't that webmail is perfect for implementing PGP. The argument is that

1) no one uses PGP now because no on else uses PGP

2) if webmail providers deployed PGP, everyone would be using PGP

3) some use of PGP is better than no use of PGP

It really seems like some people are cutting off their PGP noses to spite their PGP faces. I remember when the assumption with vegetarianism was that you were either a vegetarian (and never ate meat) or you were a meat eater (and ate meat regularly). So people kept eating meat regularly because they "couldn't give up meat", thus believing in a false choice. If vegetarians had been pragmatic, they'd have realized that would have been much easier, and would save more animals, if you convinced 95% of people to give up meat 95% of the time.

Dear privacy advocates: stop wanting everything yesterday, because it's keeping you from getting something tomorrow. Most change takes place gradually. Webmail providers deploying PGP will instantly create millions of PGP users, which will at the very least serve a valuable educational and awareness purpose. These users will gradually become more concerned with the implementation details, triggering a gradual increase in overall privacy and security.

Re: Asking the U.S. to allow Google to publish more national security request data

#184

Earlier quoted context omitted.

Yes, i'm going to describe internal security procedures in detail to a stranger. Suffice to say, the idea that random people in some nebulous "network security" group have access to all traffic related PKI (or whatever) is barely worth responding to. Google is not made of idiots. It is not a startup run in a garage where every the "IT guy" has access to all the private keys.

Suffice to say, the idea that random people in some nebulous "network security" group have access to all traffic related PKI (or whatever) is barely worth responding to Curious sarcasm. Network security is a role, and it's one which Google holds in very high esteem. Yes, if someone is configuring IPSec or new load balancers or any other front-end system, they need the Google certs. This is a simple function of the jo…

if someone is configuring IPSec or new load balancers or any other front-end system, they need the Google certs. This is a simple function of the job.

There is more than one way to skin a cat. Google employs lots of smart people who are adept at developing cat-skinning algorithms.

Re: Asking the U.S. to allow Google to publish more national security request data

#185

Earlier quoted context omitted.

I wouldn't say the NSA killed the goose any more than I would say any other organizations that request warrants for user data did. What killed the goose was mass hysteria caused by a mistaken belief that Google let NSA see any user's data at the touch of a button. Poor journalism killed the golden goose.

How can you blame journalism when the nature of those data requests is such that in some cases companies (and even politicians) cannot talk about them, cannot fight them in court and they do not have to be approved by a judge? This leaves a lot of space for speculation, how can somebody possibly know if they didn't request a bulk copy of all Facebook data? Or issue a billion seperate requests when by law nobody can t…

Because the fact that there were secret requests for user data was already known since FISA came into being in 2005. This had nearly zero effect on the cloud companies. It took the clearly ridiculous assertions of The Guardian to kill the golden goose.

Re: Asking the U.S. to allow Google to publish more national security request data

#186
post #8

I'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroa…

"if Google cares that much about encryption and their users' privacy, they should show me they are willing to implement OTR, ZRTP and PGP"

That would only make sense if they wouldn't be required to become your key escrow service (=custodians of your private keys). PGP is also a pretty bad choice for private communication, as it offers no forward-secrecy. Something like client-side OTR implementation would be better.

Re: Asking the U.S. to allow Google to publish more national security request data

#187
post #142
post #118

Earlier quoted context omitted.

What lies have companies told?

From the news I've read, my understanding about FISA is that if someone asks you whether you've been subject to one, you're legally obligated to lie and say no. Right, or am I missing something?

I think you may be able to get away with saying "we aren't allowed to divulge information regarding FISA requests". If you say that to everyone who asks.

Re: Asking the U.S. to allow Google to publish more national security request data

#188
post #24

The issue here is that Google doesn't know how much data the NSA collects. The NSA has access to the internet backbone that Google uses and can read whatever traffic it wishes that leaves the Google network. Obviously this is not everything but most everything. It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. So while Google can…

> It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. No it isn't.

Well, think again. You really think the NSA can't make the SSL cert vendors turn over the keys? I wouldn't count on it. https://news.ycombinator.com/item?id=5933784

Re: Asking the U.S. to allow Google to publish more national security request data

#189

Earlier quoted context omitted.

You can use things like Duplicity which locally encrypt backups and then store them to arbitrary cloud services. The problem is, if the data is opaque to the cloud service, it is very hard for it to do anything other than passively store and retrieve it, at which point it is not really a cloud service at all. And even then: they can give logs to authorities showing what you accessed when and from where, they probably…

I have an 8gb truecrypt file on dropbox, pretty much regardless of what they're compelled to do, it's secure. That's the model I think should be standard for cloud ops. However, you do bring up an interesting point, it is indeed harder to do "useful stuff" when the store is untrusted and has no idea what it's holding, string searches et al become pretty much impossible generally speaking, big bummer there. Perhaps th…

'Visions of a fully homomorphic cryptosystem have been dancing in cryptographers' heads for thirty years. I never expected to see one. It will be years before a sufficient number of cryptographers examine the algorithm that we can have any confidence that the scheme is secure.' -- Bruce Schneier

Even without PRISM, the rise of cloud computing is a strong incentive for people to try to develop practical homomorphic encryption. Until there's a practical algorithm adoption will be limited.

Post reply on HN