Live data from Hacker News

Google encrypts data amid backlash against NSA spying

washingtonpost.com

51–60 of 153 posts

Re: Google encrypts data amid backlash against NSA spying

#51
post #4

A salient bit: [Eric] Grosse echoed comments from other Google officials, saying that the company resists government surveillance and has never weakened its encryption systems to make snooping easier — as some companies reportedly have, according to the Snowden documents detailed by the Times and the Guardian on Thursday. “This is a just a point of personal honor,” Grosse said. “It will not happen here.” Some folks a…

But do all of them? In my personal experience, such tasks will be given to employees who are likely to perform them.

For example, at a past sysadmin job, I was asked about the technical feasibility of monitoring a certain employees computer use, whom management suspected of some minor infringement. I refused to assist in the matter on moral grounds and was reprimanded. The task was given to a colleague of mine who had no qualms about it. Next time, they went straight to him.

And the more complex, distributed and large a system is, the more people are in positions where they can compromise it. It takes only one person to break the whole system (which is basically what just happened to the NSA). Do you trust everyone who has or can gain access to your SSL private key? Everyone who manages your network?

Re: Google encrypts data amid backlash against NSA spying

#52
post #4

A salient bit: [Eric] Grosse echoed comments from other Google officials, saying that the company resists government surveillance and has never weakened its encryption systems to make snooping easier — as some companies reportedly have, according to the Snowden documents detailed by the Times and the Guardian on Thursday. “This is a just a point of personal honor,” Grosse said. “It will not happen here.” Some folks a…

has never weakened its encryption systems to make snooping easier Up until today, Google didn't even encrypt the data. So it's kind of hard to weaken something you weren't even using. And then to go on to equate it as a "personal honor".. you've got to be kidding me.

> Up until today, Google didn't even encrypt the data.

That's not what the article says. The new encryption is specifically for backend datacenter-to-datacenter traffic over leased lines. But even before that project, there was lots of strong encryption being used all over Google: to encrypt user data on servers' hard drives, to encrypt data going between browsers and servers, encrypting tape backups before sending them to offsite storage facilities...

Re: Google encrypts data amid backlash against NSA spying

#53
post #30

Earlier quoted context omitted.

Since Google is able (and willing, when asked by the government) to decrypt everybody's email at will, and continues to build software that maintains their absolute power to do this, I really don't give a f@#k whether they promise to use 256 bit encryption, 512 bit encryption or 23439287239 bit encryption.

There's still a gigantic difference between the government being able to "vacuum up" everything (weak/no encryption) from everyone, versus the government having to ask for communications from specific users.

Yes, but (as others have already pointed out) the takeaway point from this press release shouldn't be "Google is doing great things to prevent spying" and should instead be "Google admits they have been sending sensitive customer data between data centers in plaintext."

Re: Google encrypts data amid backlash against NSA spying

#55
post #32

I already moved everything away from Google. There's no way I'm ever going back. Trust is gone.

Who are you trusting now?

I'm using Riseup.net and an offshore email account. I won't recommend the offshore service by name until they upgrade their servers (it's been slow lately).

Re: Google encrypts data amid backlash against NSA spying

#56
post #30

Earlier quoted context omitted.

Since Google is able (and willing, when asked by the government) to decrypt everybody's email at will, and continues to build software that maintains their absolute power to do this, I really don't give a f@#k whether they promise to use 256 bit encryption, 512 bit encryption or 23439287239 bit encryption.

There's still a gigantic difference between the government being able to "vacuum up" everything (weak/no encryption) from everyone, versus the government having to ask for communications from specific users.

Yes.

If you are actually trying to hide something from a targeted government attack, you certainly don't want to use any hosted services like Google's.

If, however, you are merely trying to avoid the government passively sweeping up all of your data, searching through it, and maybe subjecting it to further scrutiny due to it containing the wrong keyword, it helps to know that it's encrypted in transit, and that in order to decrypt it, someone has to actually present a warrant to Google.

Of course, there's the additional problem of National Security Letters, as they aren't really real warrants and they have the secrecy around them.

These problems can be attacked on multiple fronts. We can improve cryptographic security, and work on more decentralized approaches to online services, and reign in the NSA's power at a legal level, and so on.

Re: Google encrypts data amid backlash against NSA spying

#57
post #5

> Encrypting information flowing among data centers will not make it impossible for intelligence agencies to snoop on individual users of Google services, nor will it have any effect on legal requirements that the company comply with court orders or valid national security requests for data. How does this do anything about pervasive NSA spying? The NSA has broken SSL and VPNs by corrupting the CAs and the VPN vendors…

How is ssl broken when many different ciphers can be used?

Do you suppose that a government team "responsible for identifying, recruiting and running covert agents in the global telecommunications industry" might be able to steal a private key from one of Google's many data centers? Without forward secrecy, the theft need not even go undetected for it to be useful for decrypting all the data that has been storing.

Or perhaps the Bullrun project had something to do with Bull Mountain, Intel's random number instruction (RDRAND), which was used by the Linux kernel for a while as a primary source of entropy (causing Matt Mackall to resign as maintainer of /dev/random, later reverted by Ted Ts'o). If RDRAND is indeed compromised, then keys generated on a machine that trusted RDRAND would have very low effective entropy for anyone knowing the secret. How confident are you that proprietary systems do not trust RDRAND or have other backdoors that could compromise their available entropy? (That could be an interesting reverse-engineering project.)

Whether or not there is any truth to either of these scenarios, I think they can no longer be considered conspiracy theory paranoia, and indeed have entered the realm of downright plausible.

https://www.eff.org/deeplinks/2013/08/one-key-rule-them-all-... https://news.ycombinator.com/item?id=6336505 http://thread.gmane.org/gmane.linux.kernel/1173350/focus=117...

Re: Google encrypts data amid backlash against NSA spying

#58
post #46

Earlier quoted context omitted.

Why are you posting this shit on HN? Everyone here knows how contextual advertising in gmail works, and excepting those too young to have been aware back then, have known about it since 2004. If you have a point, make it, but scare quotes specifically made to induce an emotional reaction from those without technical knowledge really have no place here.

Here's your footnote. https://en.wikipedia.org/wiki/Expectation_of_privacy

I'm not sure what your point is. If you don't want your email accessed, don't send it unencrypted from your client, and definitely don't send it via a service that has features (search, spam, google now, etc) and is payed for by a system (contextual advertising) that explicitly accesses the contents of your email.

Download Thunderbird and a PGP client[1]. Boom, done.

Use another email service. Boom, done.

I'm not objecting to the idea that you'd find it objectionable to have your email contents used for advertising. I'm objecting to a useless quote that tries to turn this into a soundbite-off instead of an actual discussion (little hope as this thread has).

[1] https://support.mozillamessaging.com/en-US/kb/digitally-sign...

Re: Google encrypts data amid backlash against NSA spying

#59
post #20
post #5

> Encrypting information flowing among data centers will not make it impossible for intelligence agencies to snoop on individual users of Google services, nor will it have any effect on legal requirements that the company comply with court orders or valid national security requests for data. How does this do anything about pervasive NSA spying? The NSA has broken SSL and VPNs by corrupting the CAs and the VPN vendors…

I would assume Google is big enough and smart enough to competently vet and deploy trusted encryption techniques.

Against the NSA? The same NSA we ask to intercept Russian, Chinese, Japanese, German, and Iranian encrypted Internet traffic? (To name a few. I'm sure the French are in there too.) Russia and China, I am sure, have enough smart people working on their cyber defenses that the NSA would have to be very, very, very good to penetrate those defenses. And if indeed they are, then do you think Google stands a chance?

Re: Google encrypts data amid backlash against NSA spying

#60

It's theoretically impossible for the NSA to decrypt the data. In practice, however, it seems they can. So what's the point of encrypting then? Is Google thinking they are smarter than the NSA at cryptography?

I know what you're trying to say, but your wording is off. Something cannot be theoretically impossible but practically possible.

Don't worry, your wording is also off, something can be theoretically impossible but practically possible. Things can not be impossible but also practically possible, but for every theory disproved, there was a contrarian thing possible :)
Post reply on HN