If this is true my next question would be does NSA have access to the keys or are they removing encryption in some other more technically involved way?
NSA infiltrates links to Yahoo, Google data centers worldwide
71–80 of 614 posts
Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#72Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#73Earlier quoted context omitted.
> Isn't this useless? No. > They can serve Google NSL and the court can force the company to release the SSL keys for the encryptions - just like Lavabit. They can't do that without Google knowing about it, knowing what data is covered by the NSL and having the opportunity to challenge the request, or to factor the fact of the requests and the extent of information covered by it in evaluating Google's lobbying priori…
BTW, a much simpler way to get the SSL keys is to send someone (or teams) to be employed by Google. (Like another big country probably did a while back.) Once inside, put a few webcam, physical/virtual key logger, a few line of code, (checkin code with extra ",", "=" instead of "==" in the right place - just like a post about Linux security Kernel hack a while back.) and the jobs are done.
SSL keys are not the target, the data is the target. SSL keys change over time, and you still need to monitor the actual encrypted data; tapping the data where its sent in cleartext is actually simpler, if you have the capability to do it, than infiltrating a spy into the dev team, having them compromise the system without being detected, getting the SSL keys, and monitoring all the encrypted comms.
Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#74It's hard not to come to the conclusion that these activities were essentially criminal. I don't see how the administration can fail to disavow them, investigate them fully, and hold their instigators accountable. It feels like Special Prosecutor time. That aside, let me re-make a point I keep making: Google had no knowledge of NSA's physical compromise of their data centers. But still, they pushed harder than anyone…
Even with everything you say, Google was still defeated by the NSA. Will Google ever catch up in this arms race? "95% encrypted" == "100% compromised"
Well, actually, per the article, by GCHQ. Who, as well as using the data themselves, also allows the NSA access to it.
Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#75Earlier quoted context omitted.
Google might have an easier time recruiting edge producing developers than the NSA after the leaks.
I imagine anyone with a line on their resume that says "NSA - Software Developer - 2009:Present" is going to have a hard time finding a new job at many companies (although certainly not all).
Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#76Earlier quoted context omitted.
This might be a good time to go back and look at what you said to all those cypherpunks who kept talking about the need to build security into Internet protocols from day 1. Whitefield Diffie had pointed out this problem -- that online services could violate user privacy without any technical barriers -- in the 1970s and pointed to it to motivate public key cryptography. Throughout the 90s and 00s people were saying…
"You cannot acquire experience by making experiments. You cannot create experience. You must undergo it." - Albert Camus The cypherpunk "2.0" generation is here. The adversaries are definitely way more resourceful and ten steps ahead now. So there may be some value in looking back with regret. But it's never too late.
Upvote for hope.
Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#77It's hard not to come to the conclusion that these activities were essentially criminal. I don't see how the administration can fail to disavow them, investigate them fully, and hold their instigators accountable. It feels like Special Prosecutor time. That aside, let me re-make a point I keep making: Google had no knowledge of NSA's physical compromise of their data centers. But still, they pushed harder than anyone…
Think about that for a second. Most people on HN wouldn't send a single file to their own backup provider in the clear. Google was sending gushing torrents of data, presumably including email, IMs, etc, over long distances that way.
That's very nice that the company that encouraged all of us to put all our email and documents in its data centers "pushed harder than anyone on the whole internet" for some basic security well after the NSA compromised their shit, but it doesn't excuse their irresponsible practices.
Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#78Is that an official document with an actual smiley face? What ever happened to the admins / programmers standing up for what is right, or do they just gobble down a paycheck and turn the other way?
>Is that an official document with an actual smiley face? It's only HN that pretends there is no feeling in professional work.
Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#79If that graphic - that taunting smiley face, drawn when it was assumed that no one was watching - isn't enough to outrage the general public, I don't know what it will take. This is not super technical - it's easily explained and should be easily understood by the masses. And it should cause outrage.
You know what would outrage the public? ESPN being shut down. Most people do not actually care about their privacy. Even if everyone had the technical chops needed to understand what has been happening, most people never spend much time contemplating the importance of privacy rights.
No better way to state it. Our government is fucking us with our pants on but we're too distracted (by people getting paid hundreds of millions of dollars to throw a fucking ball around) to care.
Re: NSA infiltrates links to Yahoo, Google data centers worldwide
#80Earlier quoted context omitted.
Google appears to have been so on the ball with this stuff that the NSA literally had to send bag men to their cages in order to retain access.
When your opponent uses Navy submarines to tap undersea cables right under the Soviets' noses, you probably shouldn't trust your leased fiber with unencrypted data. This interception could occur where undersea cables make landfall without any datacenter antics.