Live data from Hacker News

On Confirmed Assumptions or, Not Trusting Google is a Good Idea

anarchism.is

41–50 of 230 posts

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#41

Earlier quoted context omitted.

Maybe "not trusting Google with your data" would be a better fit.

How about "not trusting 3rd party with your (unencrypted) data"?

Why are you trying to deflect attention away from Google?

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#42
post #37

"Google is, however, allowed to tell me what account is involved, and I can do whatever I want with the information Google gave me" So Google was allowed, not required . Looks like they did the right thing by at least telling OP what they were forced to do. Shouldn't the title be "Not trusting your Government"?

It's both. If you are going to use a cloud service, you have to trust both the provider and the government where they operate. (With the exception of things like tarsnap).

>(With the exception of things like tarsnap).

The chain of trust still extends to them. You're trusting that they're actually doing everything they say they're doing.

If you don't own the hardware and the building where the hardware is, you have to trust that they're doing everything you want them to be doing.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#43

I wonder if donating to wikileaks or even sending an email to wikileaks offering to volunteer would be enough to interest someone in government in getting all your 1's & 0's.

> email to wikileaks offering to volunteer

It's hard to imagine anything more interesting to the NSA, but for not just the obvious reason.

Wikileaks set itself up as a nexus of exchange for state secrets of a great many states. Any state with an intelligence operation would want to penetrate that organization to have access to raw data and advance notice of anything interesting about to go down.

I've often wondered if such organizations (not naming names) ever wondered why they get approximately one volunteer from each European nation.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#44

Earlier quoted context omitted.

How about "not trusting 3rd party with your (unencrypted) data"?

Why are you trying to deflect attention away from Google?

Because the problem is not specific to Google. (Not to put words in the gp's mouth, but that seems like an obvious reason to broaden the focus to me.)

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#45

Google should invent a distributed, encrypted email protocol and make that network an option in GMail for storage and message sending. That would be a great PR move - if there is no central server, and no central message pipe, it's a little hard for anyone to think Google wants to be complicit in spying.

That would be the antithesis of what Google does - they give away services for free in exchange for access to personal information that they use to sell more precise targeting to advertisers. Google's business relies on them being able to examine your personal data. That's how Gmail is paid for. Perhaps someone who has a different business model e.g. Samsung, Microsoft, or Apple should do this.

Google already offers paid email accounts that don't show ads.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#46

Earlier quoted context omitted.

Why are you trying to deflect attention away from Google?

Because the problem is not specific to Google. (Not to put words in the gp's mouth, but that seems like an obvious reason to broaden the focus to me.)

True, but Google is by far the most dangerous aggregation of personal information, and the topic of this conversation. It's also a company that spends a lot of effort telling people to trust them when that is clearly unjustified.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#47
post #28

Earlier quoted context omitted.

Maybe engineer a service that is harder to wiretap? It is not easy, but they have some of the best computer scientists on this planet working for them. If I were them, I would start somewhere around here: http://crypto.stanford.edu/adnostic/adnostic.pdf

It's not directly apropos this particular thread, but Google has engineered an email service that is particularly difficult to wiretap. To wit: (a) They're the Internet's foremost adopter and proponent of DHE ciphersuites, which drastically reduce the impact of losing the RSA key that underpins most site's TLS security, and, just as importantly, forces adversaries to actively MITM every connection in order to decrypt…

In these particular instances, though, information is much more valuable than money.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#48
post #24

How, in short, is this shit valid under the U.S. Bill of Rights? I’d really like someone to explain that to me. With a straight face. Preferably without making me want to punch them in the process. Well, he's going to want to punch me, but here's what I think(?) the answer is: (a) He's not a US person, but instead a well-known citizen of Iceland, living abroad, and is thus not protected by the Fourth Amendment, at le…

The legal theory that the bill of rights only applies to US citizens is dangerous and wrong.

It applies to actions of the United States government. It is a list of things they may not do.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#49

Earlier quoted context omitted.

Maybe "not trusting Google with your data" would be a better fit.

How about "not trusting 3rd party with your (unencrypted) data"?

Yes, you are certainly right. But the submitted article is mainly about Google and my post was intended as a better title/headline.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#50
post #47
post #28

Earlier quoted context omitted.

It's not directly apropos this particular thread, but Google has engineered an email service that is particularly difficult to wiretap. To wit: (a) They're the Internet's foremost adopter and proponent of DHE ciphersuites, which drastically reduce the impact of losing the RSA key that underpins most site's TLS security, and, just as importantly, forces adversaries to actively MITM every connection in order to decrypt…

In these particular instances, though, information is much more valuable than money.

No, I don't believe that's true. The information in your mail is not more valuable to Google than the integrity of a bank account is to a bank.

Google has a financial interest in having access to the content of mail messages, but (a) it's an interest "in the large", not in any specific account, and (b) it's a nonrivalrous interest.

Post reply on HN