Live data from Hacker News

Google speeding up end-to-end crypto between data centers worldwide

arstechnica.com

11–20 of 41 posts

Re: Google speeding up end-to-end crypto between data centers worldwide

#11
post #2

I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.

Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level. That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new cont…

> IPSec didn't exactly take off

Oh, jezus. Did you read it on the Internets?

IPsec (s is in lowercase) is the standard to securing L2 connectivity and it has been ubiquitously used for site-to-site and client-to-site connectivity for ages. In addition to several mature FOSS implementations, every network equipment vendor ships one. There is also a ton of client software - Windows supported it since Windows 2000, the SSH company (you know, the ssh creators) has been selling an IPsec Toolkit since as early as 1999, Cisco has a VPN client that is de-facto software in Cisco-based shops for remote workers, etc.

Re: Google speeding up end-to-end crypto between data centers worldwide

#15
post #4

If Google comes up with a much more sane version of or alternative to IPsec, deployed on all their boxes, it would be an amazing improvement for the world.

Especially if they integrated it with Chrome (a la VPN over SSL). If I have to pick between Google having all my traffic and the NSA, its an easy pick.

Except of course, as we've learnt over the last few weeks, they're essentially one and the same thing.

You can't trust a third party with your data if you want it kept secure. Period.

Re: Google speeding up end-to-end crypto between data centers worldwide

#17
post #11

Earlier quoted context omitted.

Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level. That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new cont…

> IPSec didn't exactly take off Oh, jezus. Did you read it on the Internets? IPsec (s is in lowercase) is the standard to securing L2 connectivity and it has been ubiquitously used for site-to-site and client-to-site connectivity for ages. In addition to several mature FOSS implementations, every network equipment vendor ships one. There is also a ton of client software - Windows supported it since Windows 2000, the…

IPsec, which runs at layer 3, secures IP (layer 3) traffic.

To protect L2 connectivity with IPsec, you'll need to tunnel the l2 frames inside IP.

Re: Google speeding up end-to-end crypto between data centers worldwide

#19

Earlier quoted context omitted.

Especially if they integrated it with Chrome (a la VPN over SSL). If I have to pick between Google having all my traffic and the NSA, its an easy pick.

Except of course, as we've learnt over the last few weeks, they're essentially one and the same thing. You can't trust a third party with your data if you want it kept secure. Period.

You can't trust a third party with your data if you want it kept secure. Period.

It's impossible to do otherwise, though.

Re: Google speeding up end-to-end crypto between data centers worldwide

#20
post #14

The timing suggests this is supposed to be a PR move. And a cheap/ridiculous one at that.

Don't know why you are downvoted, but it's clearly a damage control move.

Damage control yes, but not necessarily external.

Google probably knows even though they're mostly in good terms, this may change.

I guess they got uncomfortable with people knowing too much already and don't trust too much

Post reply on HN