If Google comes up with a much more sane version of or alternative to IPsec, deployed on all their boxes, it would be an amazing improvement for the world.
At this point everything they could come up with, would have the feature to be accessible by the NSA, don't you think?
Google speeding up end-to-end crypto between data centers worldwide
31–40 of 41 posts
Re: Google speeding up end-to-end crypto between data centers worldwide
#32I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.
Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level. That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new cont…
Your only option to secure your mail messages is end-to-end encryption. Do you really trust Google or any other company more than you trust the NSA?
Re: Google speeding up end-to-end crypto between data centers worldwide
#33I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.
Yes, this seems like a huge man-in-the-middle vulnerability.
Quite apart from MITM being an active attack only needed (ish) for manipulation of the transferred data, at the throughputs likely involved here and the fact that leased lines are used, MITM would probably provide far too much hassle for its worth.
Re: Google speeding up end-to-end crypto between data centers worldwide
#34Earlier quoted context omitted.
Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level. That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new cont…
> IPSec didn't exactly take off Oh, jezus. Did you read it on the Internets? IPsec (s is in lowercase) is the standard to securing L2 connectivity and it has been ubiquitously used for site-to-site and client-to-site connectivity for ages. In addition to several mature FOSS implementations, every network equipment vendor ships one. There is also a ton of client software - Windows supported it since Windows 2000, the…
The question wasn't whether the standard exists but whether it's widely used. Your claims don't sound plausible to me as I've yet to work on a network (corporate, .edu, .gov) where IPSec is used – everyone focused on protocol level security like SSH or SSL instead.
Re: Google speeding up end-to-end crypto between data centers worldwide
#35Earlier quoted context omitted.
> Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? To protect users on questionable public WiFi, or traveling through a country known for spying on its telecommunications, or who might be using an ISP with untrustworthy employees, or working for a company with a nosy IT department. Until recently, the USA wasn't generally…
Speaking of untrustworthy employees, and HUMINT, the NSA/CIA could just have agents infiltrated at Google, to get access to a lot of that data. This is what's so striking about this. I thought Google already encrypted all data, and only a few people had access to it. Didn't they say this many years ago?
Re: Google speeding up end-to-end crypto between data centers worldwide
#36Earlier quoted context omitted.
Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level. That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new cont…
Mail messages may go through multiple relays. Even if they are encrypted between relays, all routing mailers see the message unencrypted. Your only option to secure your mail messages is end-to-end encryption. Do you really trust Google or any other company more than you trust the NSA?
Re: Google speeding up end-to-end crypto between data centers worldwide
#37I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.
Why would routers do this? IPSec didn't exactly take off (this weeks news reminded us why), so end-to-end encryption wouldn't really happen on their level. That said, I certainly expected and assumed Google would already encrypt traffic between data centers. Whats the point of forcing HTTPS on gmail when you constantly backup my complete email repository across the world over unencrypted connections? In this new cont…
We have tons of our own stuff moving through the same pipes (proprietary source code, all files in our corp network filesystems...), so it's our best interest to protect these. I suspect most of the unencrypted traffic is actually what the NSA would call "metadata" -- if valuable information can be mined from simple metadata like phone calls, I guess even better stuff can be derived from extremely rich RPCs/protobufs even if the core information was already in encrypted fields. Anyway the more comprehensive encryption support should turn our backbone into a wasteland for spooks.
Re: Google speeding up end-to-end crypto between data centers worldwide
#38Earlier quoted context omitted.
Except of course, as we've learnt over the last few weeks, they're essentially one and the same thing. You can't trust a third party with your data if you want it kept secure. Period.
You can't trust a third party with your data if you want it kept secure. Period. It's impossible to do otherwise, though.
Re: Google speeding up end-to-end crypto between data centers worldwide
#39If Google comes up with a much more sane version of or alternative to IPsec, deployed on all their boxes, it would be an amazing improvement for the world.
What exactly don't you like about IPsec?
General complexity and baroqueness.
IKE and various implementations -- keying in general. True, keying is a hard problem, but I'd prefer a simple default which was secure against passive eavesdroppers, and then progressively better systems.
Re: Google speeding up end-to-end crypto between data centers worldwide
#40If Google comes up with a much more sane version of or alternative to IPsec, deployed on all their boxes, it would be an amazing improvement for the world.
At this point everything they could come up with, would have the feature to be accessible by the NSA, don't you think?
Google needs this kind of stuff not to defend against just NSA but also every other intelligence agency out there. For 0.1% of the IC's annual budget, I could give a third-tier country (Belgium? Nigeria?) about 5% of NSA's capability. That, IMO, is the true risk here.