Live data from Hacker News

Google speeding up end-to-end crypto between data centers worldwide

arstechnica.com

1–10 of 41 posts

Re: Google speeding up end-to-end crypto between data centers worldwide

#2
I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted.

Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.

Re: Google speeding up end-to-end crypto between data centers worldwide

#3
post #2

I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.

Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level.

That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new context, the statements on Prism ("we do not give them direct access!") certainly seem misleading. Right, you do not give them direct access, you just sync your databases over fibers that you know they have access to, without encrypting the data.

Re: Google speeding up end-to-end crypto between data centers worldwide

#5
post #2

I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.

Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level. That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new cont…

> Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections?

To protect users on questionable public WiFi, or traveling through a country known for spying on its telecommunications, or who might be using an ISP with untrustworthy employees, or working for a company with a nosy IT department.

Until recently, the USA wasn't generally considered part of that second category, and private leased lines were generally considered secure -- at Google and elsewhere -- for the same reason a LAN transmission within a datacenter is / was generally considered secure.

Re: Google speeding up end-to-end crypto between data centers worldwide

#6
post #2

I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.

Yes, this seems like a huge man-in-the-middle vulnerability.

Re: Google speeding up end-to-end crypto between data centers worldwide

#7
post #5

Earlier quoted context omitted.

Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level. That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new cont…

> Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? To protect users on questionable public WiFi, or traveling through a country known for spying on its telecommunications, or who might be using an ISP with untrustworthy employees, or working for a company with a nosy IT department. Until recently, the USA wasn't generally…

Speaking of untrustworthy employees, and HUMINT, the NSA/CIA could just have agents infiltrated at Google, to get access to a lot of that data.

This is what's so striking about this. I thought Google already encrypted all data, and only a few people had access to it. Didn't they say this many years ago?

Re: Google speeding up end-to-end crypto between data centers worldwide

#8
post #4

If Google comes up with a much more sane version of or alternative to IPsec, deployed on all their boxes, it would be an amazing improvement for the world.

Especially if they integrated it with Chrome (a la VPN over SSL). If I have to pick between Google having all my traffic and the NSA, its an easy pick.

Re: Google speeding up end-to-end crypto between data centers worldwide

#10
post #7
post #5

Earlier quoted context omitted.

> Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? To protect users on questionable public WiFi, or traveling through a country known for spying on its telecommunications, or who might be using an ISP with untrustworthy employees, or working for a company with a nosy IT department. Until recently, the USA wasn't generally…

Speaking of untrustworthy employees, and HUMINT, the NSA/CIA could just have agents infiltrated at Google, to get access to a lot of that data. This is what's so striking about this. I thought Google already encrypted all data, and only a few people had access to it. Didn't they say this many years ago?

"Encrypt all data" is a vague term. For example, would that include encrypting it while a CPU is processing it? What about when the CPU is writing it to RAM? What if the RAM is on some other computer in the rack? What if it's in some computer on the other side of the world?

I'm not sure what Google's public statements on this have been, but if you want to research it, be sure to distinguish statements regarding user data at rest from those regarding user data in transit.

Post reply on HN