If so, what you are saying is equivalent to Google being more secure than the NSA.
Google encrypts data amid backlash against NSA spying
101–110 of 153 posts
Re: Google encrypts data amid backlash against NSA spying
#102Earlier quoted context omitted.
Meanwhile, Google Argues for Right to Continue Scanning Gmail "This company reads, on a daily basis, every email that's submitted, and when I say read, I mean looking at every word to determine meaning," said Texas attorney Sean Rommel, who is co-counsel suing Google. http://abcnews.go.com/Technology/wireStory/google-argues-con... http://www.mercurynews.com/business/ci_24021944/google-argue...
By your definition of 'reading', our providers router is reading your email as well. Why don't you sue it?
Re: Google encrypts data amid backlash against NSA spying
#103A salient bit: [Eric] Grosse echoed comments from other Google officials, saying that the company resists government surveillance and has never weakened its encryption systems to make snooping easier — as some companies reportedly have, according to the Snowden documents detailed by the Times and the Guardian on Thursday. “This is a just a point of personal honor,” Grosse said. “It will not happen here.” Some folks a…
Re: Google encrypts data amid backlash against NSA spying
#104Earlier quoted context omitted.
Since Google is able (and willing, when asked by the government) to decrypt everybody's email at will, and continues to build software that maintains their absolute power to do this, I really don't give a f@#k whether they promise to use 256 bit encryption, 512 bit encryption or 23439287239 bit encryption.
There's still a gigantic difference between the government being able to "vacuum up" everything (weak/no encryption) from everyone, versus the government having to ask for communications from specific users.
From what was published recently we know NSA has proven methods for bypassing encryption, namely getting the keys used for encryption (so they can decrypt everything) or getting access to the content before encryption or after decryption.
To me this last move by google is a PR attempt at regaining people's trust
Re: Google encrypts data amid backlash against NSA spying
#105As everybody knows: It has been revealed that Google is one of the NSA partner companies (which should have been obvious to begin with, given the fact that Google is probably the biggest data hoover ever built).
This fact terminates even the last tiny little bit of "trust" we could have had in Google.
And that's really all there is to say.
Re: Google encrypts data amid backlash against NSA spying
#106Re: Google encrypts data amid backlash against NSA spying
#107But at least on my part, this doesn't begin to "impress me". So far they're only talking about encrypting data between servers and they've also recently talked about encrypting Drive storage data (why wasn't it encrypted in the first place?!)
They need to implement OTR or some form of end to end encryption with PFS for Hangouts, and it would be nice if they at least gave the option to have encrypted calls and voice calls with ZRTP in Hangouts. The button should be right there and obvious for everyone who wants to use it. But I'm saying it's optional only because I'm not sure how it could impact what they're trying to do with Hangouts, and if ZRTP works with multiple people at once. But if they can do that, then it should be by default for everyone.
I'm also not sure exactly what kind of forward secrecy they are using for Google search - is it really a new key being generated per session - or is it like a few weeks? Because I think I read something about "a few weeks".
I think all SSL/TLS encryption is almost useless without PFS so everyone should use it, when we're talking about the government. A single order from them and they could get your key for everything. That's just completely unacceptable! So every service should be using PFS.
If I were them I'd also seriously evaluate whether RSA 2048 bits is enough, and if there's any doubt that it is, then they should move to more bits, or if the whole RSA algorithm is in danger, then they should be looking for alternatives quickly.
When Google and others start doing that, then I will begin to have some trust in them again. All of these press releases so far, and the lawsuit to fight to only disclose (not stop) the mass requests aren't fooling me, and I hope they aren't fooling many others either.
Until then I'll be on the lookout for any new great service that promises that type of security, and I'll switch to them as soon as they're available, and recommend others to do it, too, both offline and online.
I hope Google and Microsoft and others aren't thinking that because I haven't "ragequit" their services yet, it means the whole NSA thing doesn't bother me. It just means I'm anxiously waiting for the alternatives to appear - which will appear. There is a crypto war (again), and I do believe the security community will win again, so it's only a matter of time.
Re: Google encrypts data amid backlash against NSA spying
#108> Encrypting information flowing among data centers will not make it impossible for intelligence agencies to snoop on individual users of Google services, nor will it have any effect on legal requirements that the company comply with court orders or valid national security requests for data. How does this do anything about pervasive NSA spying? The NSA has broken SSL and VPNs by corrupting the CAs and the VPN vendors…
How does this do anything about pervasive NSA spying? Google clearly suspects the NSA is installing devices on the leased lines they use for inter-datacenter communications. Properly implemented, this will stop that. The NSA has broken SSL and VPNs by corrupting the CAs and the VPN vendors. I suspect Google won't use a commercial VPN implementation. Corrupted CAs can be bypassed by using self-signed certificates, whi…
PRISM program is for collecting intelligence within and with companies that have joined the program (including Google). Upstream is program is for collecting data directly from fiber. Analysts are free to use both.
Re: Google encrypts data amid backlash against NSA spying
#109Earlier quoted context omitted.
There's still a gigantic difference between the government being able to "vacuum up" everything (weak/no encryption) from everyone, versus the government having to ask for communications from specific users.
For sure, but in the case of google this probably doesn't apply. From what was published recently we know NSA has proven methods for bypassing encryption, namely getting the keys used for encryption (so they can decrypt everything) or getting access to the content before encryption or after decryption. To me this last move by google is a PR attempt at regaining people's trust
They crop up in every submission detailing an action taken by Google with regards to the Snowden/Prism/NSA revelations. Is it so ridiculous that a large corporation should seek to ameliorate its image in the eyes of users and shareholders?
PR has become such a dirty word.
Of course it would be best if all these actions were taken earlier, purely as the result of a strongly held principle. However, when presented with the realities of public businesses operating on a global scale - I am glad that such steps as those detailed above are taken: at whatever stage, and for whatever reason.
The tinfoil hat brigade needs to, as the old saying goes, "stop seeing reds under the beds" and occasionally ... just occasionally ... take the facts presented to them.
In times when misinformation and confusion is so wont to proliferate, attempting to discern true motive is almost ridiculous - condemnation on the basis of any such discernment doubly so.
Re: Google encrypts data amid backlash against NSA spying
#110Are they suggesting the NSA is tapping intra-data center communications? I hadn't seen that suggested before. That's interesting. I hadn't considered that could be how Prism works, but it would make sense if these companies weren't encrypting those connections previously. Somehow I assumed they were.
Most companies have historically considered dark fiber (where nobody else's network gear is involved) to be secure enough. Passively decoding dumps of hundreds of gigabits or terabits spread over many colors of light (DWDM) into useful data was generally thought of as prohibitively expensive and therefore not a viable threat. The routers that can handle those speeds don't encrypt the link itself, so the most common s…