Live data from Hacker News

NSA infiltrates links to Yahoo, Google data centers worldwide

washingtonpost.com

81–90 of 614 posts

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#81
post #12

Gen. Keith Alexander, asked about it at a Bloomberg event, denied the accusations. "I don't know what the report is," Alexander cautioned, adding the NSA does not "have access to Google servers, Yahoo servers." He said the NSA is "not authorized" to do this, and instead, must "go through a court process." http://www.politico.com/story/2013/10/keith-alexander-nsa-re...

while they might not have access to the "Google servers", it now is almost certain they have access to the "Google network" (i.e. fiber cable access). as seen in previous reports, intercepting sea fiber optic traffic between continents seems something the NSA has mastered...

> while they might not have access to the "Google servers", it now is almost certain they have access to the "Google network" (i.e. fiber cable access).

If the article is correct, the NSA does not have that. What they have is an agreement that they can submit search terms and get matching data from a system operated by their British counterpart, GCHQ.

It is GCHQ who, per the article, has a direct tap somewhere inside Google's unencrypted datacenter-to-datacenter communications network.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#82
post #34
post #7

I hope that this finally convinces everyone that it doesn't matter whether Google is "Evil" or Yahoo is more evil or whatever. What matters is that large cloud systems are fundamentally incapable of protecting data. Even the most goodhearted and the most talented teams can't reliably defend against a massively funded adversary. Secrets are for keeping, not sharing.

Well, I don't think it's that easy. If the NSA wanted your data, they could get into your network probably easier than they could get into Google's networks. Companies like Google have way smarter people (and working full time) securing data than most businesses. For us to secure our networks as much as someone like Google would, we'd have to have a team of the best hackers around. And by definition, the best hackers…

Google may have better security, but they're also a much, much larger target. Wiretapping Google gives you access to the private data of Google's millions and millions of users, whereas gaining access to my network gets you access to… me. As long as there's a non-trivial fixed cost to attacking a host or a network, there's an advantage to hosting your own data.

While it's possible that the NSA has a system to automatically detect and wiretap hosts and private networks connected to the internet, it seems unlikely to not have been detected so far. I've taken to assuming that every packet send and received from my servers is being monitored, but that, barring specific interest in me by the NSA, the servers themselves are reasonably private.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#83
post #15

Earlier quoted context omitted.

Google might have an easier time recruiting edge producing developers than the NSA after the leaks.

I imagine anyone with a line on their resume that says "NSA - Software Developer - 2009:Present" is going to have a hard time finding a new job at many companies (although certainly not all).

I suspect that anyone who has been a software developer at the NSA (or FBI) for five years has robust job security. Government employees have some extensive benefits, and these guys get to play with some serious hardware. If they like working there, I would be surprised if they were unable to keep doing so for a Long Time in the future.

Now, if they decided they wanted out, well ... good luck with that in the manner you describe. I suspect that it won't be too hard, though. They deal with "Big Data" problems at a scale that few do, so being an NSA engineer likely is bound to be a similarly prestigious resume line as working for Google. Aside from the working for an evil entity part, that is, but some employers will not care as much about that.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#84
post #56

Earlier quoted context omitted.

You know what would outrage the public? ESPN being shut down. Most people do not actually care about their privacy. Even if everyone had the technical chops needed to understand what has been happening, most people never spend much time contemplating the importance of privacy rights.

> people do not actually care about their privacy This is 100% accurate, I've attempted to aggressively promote privacy tools well before the NSA/Snowden stuff among the people I know. They still don't care to use simple things like OTR with IM. They might use it for one week, and switch back. Journalists/tech sites love making this seem like the biggest deal in society right now, but hardly the case in reality. I'm…

If tools for private communiation weren't 10-20 years behind sending digital postcards on facebook.com, I'd use them more consistently too. I am tech savy yet most crypto tools don't seem to be made for me.

I have seen OTR fail in the most colorful ways, with and without error messages, and mostly with cryptic error messages. I have seen half a dozen IM clients forget messages, forget alerts, fail to deliver messages, disable alerts for other clients, mess up their contact list, mess up the service's contact list and mess up contact groups. Needless to say my experience didn't last more than a week.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#86
Why didn't they release these documents a long time ago when everyone was racing to judgement that Google, Yahoo, et al were secretly in cahoots with the NSA helping to build drag-net surveillance extranet stuff for them? These are very important revelations!

I mean, when Greenwald/Snowden/Guardian released the original PRISM accusations, these slides would have provided a much much more important set of evidence, instead of months of speculation and parsing of meanings of "backdoor", "frontdoor", "side door", in the corporate communications of the tech companies who were struggling to say "we've never heard of PRISM, da fuq is this shit?"

Is the slow dripping out of these slides because they are trying to be responsible in not releasing stuff that is too damaging (e.g. not trying to be a Bradley Manning dump), or is it to preserve traffic by keeping the click-gravy-train going?

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#87
post #55

Earlier quoted context omitted.

I imagine anyone with a line on their resume that says "NSA - Software Developer - 2009:Present" is going to have a hard time finding a new job at many companies (although certainly not all).

I would expect Google and similarly enormous companies to have a process in place to keep rogue agents from inserting backdoors and malicious code.

While this another angle, I was referring to the fact that many people will see these engineers as immoral and spineless. I know that I would not hire the person who drew that smiley face or any of their accomplices.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#88
post #65
post #7

I hope that this finally convinces everyone that it doesn't matter whether Google is "Evil" or Yahoo is more evil or whatever. What matters is that large cloud systems are fundamentally incapable of protecting data. Even the most goodhearted and the most talented teams can't reliably defend against a massively funded adversary. Secrets are for keeping, not sharing.

> What matters is that large cloud systems are fundamentally incapable of protecting data. I don't believe that's true. 1. Google (and others?) is already aggressively increasing the amount of encryption it does on traffic between its datacenters. So they have been addressing this problem before it was even brought to light. 2. We easily have the encryption abilities to do many more things than we do with secure clou…

If you would use one-time-pad before storing to the cloud you'd either need to store the very same pad on the cloud, then effectively not needing encryption, or you wouldn't need the cloud, as the amount of the encrypted data would match the amount of the pad data one to one.

And homomorphic encryption is still far from being practical.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#89

So does this suggest that Google's SSL encryption can be removed just as easily as that smiley face implies? If this is true my next question would be does NSA have access to the keys or are they removing encryption in some other more technically involved way?

> So does this suggest that Google's SSL encryption can be removed just as easily as that smiley face implies?

Well, yes, if you are Google. The removal of SSL is done by Google's own front end servers at the boundary between the public internet and Google's own network, and Google's own network (including its private datacenter-to-datacenter fiber connections) are apparently not encrypted (which saves compute overhead.)

The revelation in the article (assuming it is correct) is that the GCHQ is taking advantage of this fact to evade Google's move to encrypt user-to-Google connections by simply tapping Google's datacenter-to-datacenter connections and (as well as whatever use GCHQ itself makes of the captured data) providing the NSA the ability to provide search terms that are matched against the captured data, with matching data fed from GCHQ to the NSA.

(This neatly also avoids any US legal limits on domestic electronic surveillance by the NSA, since, first, the surveillance isn't conducted by the NSA or any other US agency, and, second, its presumably not physically conducted in the US at all.)

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#90
post #3

"vice president for security engineering Eric Grosse announced that the company is racing to encrypt the links between its data centers. " Isn't this useless? They can serve Google NSL and the court can force the company to release the SSL keys for the encryptions - just like Lavabit. Google CEO/Board can not shutdown the company like Lavabit. What can they do, get out of USA like how they got out of China?

> Isn't this useless? No. > They can serve Google NSL and the court can force the company to release the SSL keys for the encryptions - just like Lavabit. They can't do that without Google knowing about it, knowing what data is covered by the NSL and having the opportunity to challenge the request, or to factor the fact of the requests and the extent of information covered by it in evaluating Google's lobbying priori…

> or, for less duplication, build a fleet of transport vehicles that could hold data centers, and piece by piece transfer their existing US datacenters into those transports.

That must be what they're building in SF bay right now! It all makes sense now. Get Apple involved with their cash hoard and you could put the datacenters in space.

Post reply on HN