Live data from Hacker News

Google encrypts data amid backlash against NSA spying

washingtonpost.com

121–130 of 153 posts

Re: Google encrypts data amid backlash against NSA spying

#121
post #4

A salient bit: [Eric] Grosse echoed comments from other Google officials, saying that the company resists government surveillance and has never weakened its encryption systems to make snooping easier — as some companies reportedly have, according to the Snowden documents detailed by the Times and the Guardian on Thursday. “This is a just a point of personal honor,” Grosse said. “It will not happen here.” Some folks a…

I think it is fair to assume that the guys who set up and run Google, Apple, MS, Yahoo, Facebook, etc, all started with great honorable intentions. Yes, even the hated Bill Gates. I chose to believe that is true. I believe these people were once us. Up till recently, its been a cat and mouse game of how they can get money from customers and how customers can mitigate that. This to me is fine, it is business and they all need financial structures to survive.

Of course what has happened now is that the jack boot of government has poisoned the well, and I cant believe there is no group of people more upset and angry than these pioneers. I bet if we could talk to any of them off record they would be as annoyed as "we" are, if not more. After all, its their baby being ruined, not ours.

I would add to that the corporate high finance thing as a poison too, but again, that's just money. It does soil the, er, purity of things, but doesn't not threaten freedom and liberty.

Re: Google encrypts data amid backlash against NSA spying

#122
post #4

A salient bit: [Eric] Grosse echoed comments from other Google officials, saying that the company resists government surveillance and has never weakened its encryption systems to make snooping easier — as some companies reportedly have, according to the Snowden documents detailed by the Times and the Guardian on Thursday. “This is a just a point of personal honor,” Grosse said. “It will not happen here.” Some folks a…

I think it is fair to assume that the guys who set up and run Google, Apple, MS, Yahoo, Facebook, etc, all started with great honorable intentions. Yes, even the hated Bill Gates. I chose to believe that is true. I believe these people were once us. Up till recently, its been a cat and mouse game of how they can get money from customers and how customers can mitigate that. This to me is fine, it is business and they…

Am I the only one who noticed that Apple didn't appear on the PRISM timeline list until after Steve Jobs died?

Re: Google encrypts data amid backlash against NSA spying

#123
post #53

Earlier quoted context omitted.

There's still a gigantic difference between the government being able to "vacuum up" everything (weak/no encryption) from everyone, versus the government having to ask for communications from specific users.

Yes, but (as others have already pointed out) the takeaway point from this press release shouldn't be "Google is doing great things to prevent spying" and should instead be "Google admits they have been sending sensitive customer data between data centers in plaintext."

When email passes between providers, 90% of the time it's plaintext.

How many here encrypt replication data between data centers?

Re: Google encrypts data amid backlash against NSA spying

#124
post #83
post #74

I can't believe traffic between data centers wasn't already encrypted.

Eh. If you own the whole fiber from place to place, you might be lulled into thinking the data never leaves your premises.

It's also computationally nontrivial to encrypt tens of gigabits in real-time. Quite do-able, but nontrivial enough to make it the sort of nice-to-have you'd back-burner if you were confident that you controlled the line.

Re: Google encrypts data amid backlash against NSA spying

#125

Earlier quoted context omitted.

If you own the entire datacenter (like I'm sure Google does in most scenarios) and you're having racks compromised, then you probably have much larger issues that crypto won't solve.

Datacenters aren't poofed into existence. The networking hardware could be compromised at the factory, which would compromise the datacenter's network security without compromising its physical security or any of the servers.

By that logic, the networking hardware on the NIC could be compromised as well, giving an attacker DMA capabilities on a server, too.

Re: Google encrypts data amid backlash against NSA spying

#127

Earlier quoted context omitted.

I'm so bored of hearing the accusations of PR stunts. They crop up in every submission detailing an action taken by Google with regards to the Snowden/Prism/NSA revelations. Is it so ridiculous that a large corporation should seek to ameliorate its image in the eyes of users and shareholders? PR has become such a dirty word. Of course it would be best if all these actions were taken earlier, purely as the result of a…

When Google does something that makes it impossible for them to hand over certain types of data to the NSA, either by not collecting it, or making it so that only the user is able to decrypt it, wake me up. Until then, it's a PR stunt.

I am not disputing the fact that a major motivation for their actions is PR. I am suggesting that action as a result of PR pressure is still action - vastly preferable to meek acceptance of the status quo.

That being so - dismissing something as "just PR" misrepresents the actual benefits something like this may confer.

Re: Google encrypts data amid backlash against NSA spying

#128
post #4

A salient bit: [Eric] Grosse echoed comments from other Google officials, saying that the company resists government surveillance and has never weakened its encryption systems to make snooping easier — as some companies reportedly have, according to the Snowden documents detailed by the Times and the Guardian on Thursday. “This is a just a point of personal honor,” Grosse said. “It will not happen here.” Some folks a…

I was always curious how HUMINT would look if you were inside the organization as a worker-bee.

In my experience at a certain large SW company in the pacific northwest, I do know that core crypto code, the actual workhorse functionality, is typically walled off from the general developer population. The rationale given is that there are foreign nationals on staff who are not permitted to look at that stuff. That makes sense given the export laws in place.

All the security-like code I saw above that layer was good, to my non-security-trained eyes: Honest use of crypto algorithms, responsible bug fixes and regular and nitpicky reviews of protocols, file formats, APIs, and the code itself. For several shipping products I had confidence that the code we checked in was the actual code that shipped.

For the lower layers (an ideal place to introduce weaknesses):

- The general developer population never sees them

- Even if the sources are utterly honest, the build process might hide the introduction of weaknesses (a variant on "Reflections on Trusting Trust"), or the build machines might ship different bits, or weaknesses might be patched-in later (even after customers get machines) by the OS update infrastructure.

This is the kind of thing I'd HUMINT if I had a mind to.

Re: Google encrypts data amid backlash against NSA spying

#129
post #4

A salient bit: [Eric] Grosse echoed comments from other Google officials, saying that the company resists government surveillance and has never weakened its encryption systems to make snooping easier — as some companies reportedly have, according to the Snowden documents detailed by the Times and the Guardian on Thursday. “This is a just a point of personal honor,” Grosse said. “It will not happen here.” Some folks a…

The revelations that NSA is running a HUMINT program should make it very clear that you can't trust everyone at Google or any other major provider. Those risks are mitigable, but it's expensive and I doubt most places take sufficient steps to prevent it. Even without that, trusting companies because their employees are honest is hard. There are some people at the NSA who really really care about privacy and not spyin…

True, yet I imagine it shouldn't be difficult to signal out those employees that present the greatest HUMINT risk and apply extra scrutiny. Any employee that have any sort of top secret clearance, that has worked for intelligence agencies or contractors and the worked in the military, but not out in the field is potentially a mole.

I'd find it hard to believe that there are people that don't fit that profile but are moles for governmental intelligence agencies even exist.

Post reply on HN