Live data from Hacker News

NSA infiltrates links to Yahoo, Google data centers worldwide

washingtonpost.com

111–120 of 614 posts

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#111

Earlier quoted context omitted.

> It's hard not to come to the conclusion that these activities were essentially criminal. I don't see how the administration can fail to disavow them, investigate them fully, and hold their instigators accountable. It feels like Special Prosecutor time. The government takes the position that their agents are almost completely unconstrained by law when it comes to actions taken abroad aimed at non-US persons. Even we…

> actions taken abroad aimed at non-US persons. And there is an interesting counterpoint to that, e.g. > "If the Americans eavesdropped on cellphones in Germany, they broke German law on German soil, and those responsible must be held accountable." http://www.japantimes.co.jp/news/2013/10/28/world/obama-unaw...

The problem is that the people who were actually in Germany breaking German law were (likely) on diplomatic passports and so have plenary immunity. Meanwhile, under international law, which German courts take seriously even if US courts do not, senior state officials have functional immunity for actions taken in an official capacity with a disputed exception for violations of jus cogens+.

While there may be some room between the people on the ground who are immune and the senior officials who are immune to prosecute mid-level functionaries, that's not terribly satisfying and there still remains the problem of getting them in front of the court.

See generally: http://www.lawfareblog.com/2013/10/the-nsa-affair-goes-crimi...

+The most serious types of international norms: things like genocide, slavery, torture, and piracy.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#112
post #15
post #9

Earlier quoted context omitted.

Even with everything you say, Google was still defeated by the NSA. Will Google ever catch up in this arms race? "95% encrypted" == "100% compromised"

Google might have an easier time recruiting edge producing developers than the NSA after the leaks.

I used to work in the antivirus industry, and, as I recall, anything that even hinted at a history of hacking or virus-writing would lead to instant dismissal and black-listing (from pretty much the entire computer security industry). I imagine that the same prohibition would now apply to former government employees also.

The sad fact of the matter is that we cannot trust individuals that have ever worked with these agencies, nor with the private contractors that supply them. The risk of insider attacks is too high. Equally, we cannot trust companies that employ those individuals.

If silicon valley is to recover the confidence of it's customers, it must go through the painful and heart-rending exercise of dismissing all employees with any connection whatsoever to government espionage. Many innocent people will lose their jobs, and will face the prospect of being excluded from high-tech employment in the private sector, but I cannot see any other way of regaining trust in our fundamental infrastructure.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#113
post #26

Earlier quoted context omitted.

When your opponent uses Navy submarines to tap undersea cables right under the Soviets' noses, you probably shouldn't trust your leased fiber with unencrypted data. This interception could occur where undersea cables make landfall without any datacenter antics.

I've seen no indication that Google considers the NSA any sort of opponent.

I think they do now. There has to be some sort of sense of personal professionalism of the many highly qualified security experts working at Google, that is hurt by the revelations that the NSA basically fucked them over and drew a slide with a smiley face on it about how they fucked them over.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#114
post #99
post #26

Earlier quoted context omitted.

When your opponent uses Navy submarines to tap undersea cables right under the Soviets' noses, you probably shouldn't trust your leased fiber with unencrypted data. This interception could occur where undersea cables make landfall without any datacenter antics.

Why would NSA agents go through all the trouble of tapping cables when they could probably just gain employment at Google and do whatever they want. I don't think encryption would make a difference here.

There's greater risk of facing problems of all sorts when you have rogue agents on the inside (what if they get found out? how will that be met by news journals? people who find out about it? the trust dynamics between CEOs and government agencies that request access in a legal way, when needed?).

The risk of things going wrong when you're tapping cables is much less pronounced as far as I can see.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#115
post #55

Earlier quoted context omitted.

I imagine anyone with a line on their resume that says "NSA - Software Developer - 2009:Present" is going to have a hard time finding a new job at many companies (although certainly not all).

I would expect Google and similarly enormous companies to have a process in place to keep rogue agents from inserting backdoors and malicious code.

You have to trust your developers. You can do audits, but the problem is intractably difficult. Developers have a TREMENDOUS amount of power. Trust is absolutely, utterly, irreconcilably fundamental to the job. If you cannot trust your developers, you are screwed every which way to Sunday. If your developers are compromised, you have to assume that your whole business is compromised.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#116

Earlier quoted context omitted.

> actions taken abroad aimed at non-US persons. And there is an interesting counterpoint to that, e.g. > "If the Americans eavesdropped on cellphones in Germany, they broke German law on German soil, and those responsible must be held accountable." http://www.japantimes.co.jp/news/2013/10/28/world/obama-unaw...

The problem is that the people who were actually in Germany breaking German law were (likely) on diplomatic passports and so have plenary immunity. Meanwhile, under international law, which German courts take seriously even if US courts do not, senior state officials have functional immunity for actions taken in an official capacity with a disputed exception for violations of jus cogens +. While there may be some roo…

Typically, if a diplomat constantly breaks the laws of the nation they're sent to in this manner, they get kicked out, and if the sender country in question keeps sending this sort of diplomat, the embassy would eventually be closed.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#117
It's interesting that there's been little attention paid to what this genre of backbone/infrastructure tapping means for companies using content accelerators (or whatever they're called).

Considering what we now know about tailored access operations, I find it hard to imagine they've not used these abilities to subvert the auto-update functionality of virtually every product there is out there.

Ie. client requests auto-update from front-end server, update is switched and replaced before hitting the front-end server & being delivered.

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#118
post #88
post #65

Earlier quoted context omitted.

> What matters is that large cloud systems are fundamentally incapable of protecting data. I don't believe that's true. 1. Google (and others?) is already aggressively increasing the amount of encryption it does on traffic between its datacenters. So they have been addressing this problem before it was even brought to light. 2. We easily have the encryption abilities to do many more things than we do with secure clou…

If you would use one-time-pad before storing to the cloud you'd either need to store the very same pad on the cloud, then effectively not needing encryption, or you wouldn't need the cloud, as the amount of the encrypted data would match the amount of the pad data one to one. And homomorphic encryption is still far from being practical.

Sure, one would more realistically use any standard encryption scheme. Agreed on homomorphic encryption as mentioned in my previous comment. But "impractical" is a far cry from "fundamentally impossible".

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#119
post #55

Earlier quoted context omitted.

I imagine anyone with a line on their resume that says "NSA - Software Developer - 2009:Present" is going to have a hard time finding a new job at many companies (although certainly not all).

I would expect Google and similarly enormous companies to have a process in place to keep rogue agents from inserting backdoors and malicious code.

http://xkcd.com/898/

Re: NSA infiltrates links to Yahoo, Google data centers worldwide

#120
post #97
post #75

Earlier quoted context omitted.

On the flip side of that, maybe you do want ex-NSA staff with the inside knowledge so you can protect yourself against their tactics. Isn't that the same reasoning for hiring ex-black hat hackers?

If someone is willing to divulge inside knowledge of his last employer you have to assume that in the future he will be willing to divulge your inside knowledge.

Very true. Trust is important -- hard to win, easy to lose. Once lost, it never comes back.
Post reply on HN