Earlier quoted context omitted.
Some data could be captured less, but what about data like email contents, files, contacts, calendar data, chat histories? Retaining those things are part of the whole purpose of having web clients and dwarf logs like the IP address you used to do a web search, which is ephemeral anyway. Can we at least define the "so much data" that we're talking about here? Going to my Google account page, for the most part I see s…
Some data could be captured less, but what about data like email contents, files, contacts, calendar data, chat histories? Retaining those things are part of the whole purpose of having web clients and dwarf logs like the IP address you used to do a web search, which is ephemeral anyway. Can we at least define the "so much data" that we're talking about here? Going to my Google account page, for the most part I see s…
On Confirmed Assumptions or, Not Trusting Google is a Good Idea
201–210 of 230 posts
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#202How, in short, is this shit valid under the U.S. Bill of Rights? I’d really like someone to explain that to me. With a straight face. Preferably without making me want to punch them in the process. Well, he's going to want to punch me, but here's what I think(?) the answer is: (a) He's not a US person, but instead a well-known citizen of Iceland, living abroad, and is thus not protected by the Fourth Amendment, at le…
The legal theory that the bill of rights only applies to US citizens is dangerous and wrong. It applies to actions of the United States government. It is a list of things they may not do.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#203Earlier quoted context omitted.
Some data could be captured less, but what about data like email contents, files, contacts, calendar data, chat histories? Retaining those things are part of the whole purpose of having web clients and dwarf logs like the IP address you used to do a web search, which is ephemeral anyway. Can we at least define the "so much data" that we're talking about here? Going to my Google account page, for the most part I see s…
...but at the expense of basically everything that makes gmail useful. No search, spam filtering, filtering, google now, etc. If you want that, just use IMAP in thunderbird with PGP today.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#204Earlier quoted context omitted.
> the most dangerous aggregation of personal information Speak for yourself.
I think he's right. There's something terrible, here. Google services let us search/share/store data with an efficiency yet unseen at this scale. It's probably not that much of an exaggeration to say google is empowering humanity. But doing so, it handles so much data about so much people that even with good will, it's a danger. How secret services and cops could not be interested in the huge amount of data magically…
I search through Bing. My email is through Hotmail/Outlook. My online cloud sync is through Skydrive. Why am I cowering from Google any more than MS or anyone else that I give huge amounts of my data too?
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#205Earlier quoted context omitted.
...but at the expense of basically everything that makes gmail useful. No search, spam filtering, filtering, google now, etc. If you want that, just use IMAP in thunderbird with PGP today.
Yes, many of the features would be impossible or wouldn't work as well if they actually protected user privacy. But that was still their choice.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#206Earlier quoted context omitted.
"Because , you should really accept the removal of " Hah. Yeah, sure.
Well, how about this one? I would argue that controlling what substances are injected into your own body is pretty fundamental human right. So why do we allow societies to impose a vaccination regimen on people, by even minor coercion?
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#207Earlier quoted context omitted.
The legal theory that the bill of rights only applies to US citizens is dangerous and wrong. It applies to actions of the United States government. It is a list of things they may not do.
No, tptacek is right... if you are a foreigner living abroad, the bill of rights does not apply to you: In 1957, the court changed its position, overturning decades of precedent to declare that American citizens are in fact protected against U.S. government misbehavior by the Bill of Rights even outside the country. Unfortunately for the rest of the world, the court limited its ruling to U.S. citizens. Foreigners rem…
I don't understand this notion that you don't really understand something like the 4th amendment without understanding the whole history of case law interpreting said amendment.
The amendment is short and simple. It says what it says. It is part of the supreme law of the land (the constitution) and thus supersedes any lesser laws which may conflict with it. Any interpretation of it is just that.
If I were to put it in software terms, I'd call interpretations “derived artifacts” and the amendment the “source”. If I start getting weird conflicts and unexpected behavior, as any developer knows, I should “make clean” (clear out all derived artifacts) followed by “make” (rebuild from source).
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#208Earlier quoted context omitted.
Google was perfectly capable of creating a secure browser and propagating it through all manner of mechanisms. There is no reason they couldn't do the same with a secure mail system, for that matter they could just deliver it as a chrome update and smoothly redirect people into it if they wanted to. There is absolutely no reason why users would 'all jump ship' to another provider. All you are really saying is that Go…
> Google was perfectly capable of creating a secure > browser and propagating it through all manner of > mechanisms. Google could easily create a secure email client. There's no need to, since Thunderbird already exists, but they could if they wanted to. That wouldn't help at all with the problem of email security. > There is no reason they couldn't do the same with a > secure mail system, for that matter they could…
Google could easily create a secure email client. There's no need to, since Thunderbird already exists, but they could if they wanted to. That wouldn't help at all with the problem of email security.
False. The problem is not whether or not secure email clients exist. The problem is that people don't use them. Google has massive strength in both marketing and usability that existing secure email clients do not have. What you're asking for is for Google to create its own proprietary communication protocol, then force all Chrome users to have it, then force Gmail users to use it. Can you imagine the reaction? Apart from flagrantly violating "don't be evil", it would lock out every alternative browser and prevent Gmail users from communicating with non-Gmail users. It would be XMPP->Hangouts all over again, except even worse because people actually use email.
False. Nobody said that the protocol had to be proprietary. Nobody said Google couldn't also release it as an open source module that anyone could incorporate to their clients. Indeed these would be prerequisites for the security of the system to be audited. Your position appears to be that companies should not provide communication products for people who don't mind giving up a bit of privacy in exchange for a lot of convenience. That's not a reasonable position.
Why not? If it's unreasonable, you should easily be able to say why. I think it's a question of priorities. After our collective experience with cigarettes, we no longer think it's reasonable for companies to peddle addictive substances. Why shouldn't our attitudes to corporate responsibility for privacy also develop? Google exposes data to the government because it is headquartered in a country where laws require compliance with search warrants. In theory Google could choose to relocate all of its employees to Somalia to avoid warrants, but that seems impractical.
False. Google exposes data because of the law and because it has engineered systems to collect the data for it's own business purposes. Google can't control the first but it can control the second, therefore it is responsible for the outcome (as are the lawmakers and enforcers). This problem is not a technical problem, so no amount of technical expertise could solve it. You could set every single programmer in the world at solving this, but if their solution involves a user having to understand encryption keys then it would never be adopted.
False. Usability and marketing problems can be solved with technical solitions. This is a large part of what Google does. There is no need for users to need to understand encryption keys in order to use encryption, otherwise we wouldn't have ecommerce today.Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#209Earlier quoted context omitted.
You can't separate the two. The reason why foreigners are uploading their data to the NSA when they use Google is because of the way Google makes its money and engineers its services. Compare this to Apple's iMessage or FaceTime - Apple cannot decrypt the contents of the messages, and therefore cannot give the contents to the government. They designed the service this way because their users pay for the service as pa…
Even leaving behind the arguments that Apple was incorrect on iMessage history being inaccessible to them, what about the rest of Apple's services (like all your icloud email, your contacts, calendar, etc) that certainly can be turned over with a warrant? Your conclusion does not follow.
This doesn't affect the conclusion - Apple can make services that don't compromise user privacy because they aren't driven by their business model to collect personal data for behavioral profiling. Google has a vested interest in collecting this data, and persuading us to accept this as normal, that Apple just doesn't have.
Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea
#210Earlier quoted context omitted.
You can't separate the two. The reason why foreigners are uploading their data to the NSA when they use Google is because of the way Google makes its money and engineers its services. Compare this to Apple's iMessage or FaceTime - Apple cannot decrypt the contents of the messages, and therefore cannot give the contents to the government. They designed the service this way because their users pay for the service as pa…
> Compare this to Apple's iMessage or FaceTime - Apple > cannot decrypt the contents of the messages, and > therefore cannot give the contents to the government. This is not correct. First, when you buy a new iPhone, the way you authenticate yourself is by entering your Apple ID and password. Once entered, your new device will begin receiving iMessage data. This means that Apple is capable of provisioning a virtual d…
Wrong. As others who have examined the protocol have noted, your password is used to unlock a keybag on the device itself. Apple doesn't have your password (only a secure hash) and therefore can't unlock the keybag. The security depends on the strength of your password, which is a weakness, but it is in your control, not Apples.
Yes, the binaries of any system can contain arbitrary spyware or be infected with such at any stage from development through to decommissioning. Open source is no absolute protection against that.
At the moment we are trusting that companies are not baldly lying to us, even Google.