Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

51–60 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#51

Wow, a guy working for Google said "fuck you" to the NSA. All my doubts and worries are gone now.

Are you being sarcastic?

For months Google's only public response was to lobby the government for permission to release stats(?) to prove that they complied with the law - nary a word of criticism for the law itself.

So now that Google's own autonomy has been breached by the NSA (all above-board and legal according to the NSA's legions of loop-hole seeking lawyers) instead of just Google's users, now they are mad?

I just made another post about how a lot of people are unable to imagine what its like for others to be in a situation until they themselves are in the same situation. But... I'm not so sure Google, as an organization, has fully recognized the scope of the problem here.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#52
Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. Basically, this is security 101: protect data at rest and protect data in flight. So, sorry but I think the better subject for discussion would be how badly Google screwed up, not how evil is NSA. Moreover, it is not clear if other governments or criminals also had access to the users' data (e.g. in Google's data centers located outside of the US). So far Google did not produce any public post-mortem thus we have no clue how bad was the problem.

P.S. I am sure I will get smashed in the comments, so let me say right away that NSA actions should be controlled and audited by the public (e.g. through our representatives in Congress). I think that the biggest "evil" here are the members of Congress who either approved NSA actions or failed to do their job and monitor/audit NSA properly. In particular, I would point my finger at Sen. Dianne Feinstein [D-CA] who should have been ousted from the office long time ago.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#53

How do we know the Chinese or someone else hasn't hacked into the NSA and is using that data to gain access to secure systems that would otherwise be almost impossible to break into. Wasn't there a Google break in not so long ago?

Considering the track record of Governments and technology, I pretty much assume that whatever systems the NSA (and friends) had made are so ridden with holes that any/all people who really want access to it, already do, and that all our (worldwide citizens) access is basically out in the open now.

If anything, I'm actually pretty impressed it has gone on this long without seeing posts on underground forums offering access via cracked/leaked accounts and 0days, in exchange for money. Or maybe it has?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#54
post #51

Wow, a guy working for Google said "fuck you" to the NSA. All my doubts and worries are gone now.

Are you being sarcastic? For months Google's only public response was to lobby the government for permission to release stats(?) to prove that they complied with the law - nary a word of criticism for the law itself. So now that Google's own autonomy has been breached by the NSA (all above-board and legal according to the NSA's legions of loop-hole seeking lawyers) instead of just Google's users, now they are mad? I…

I was being sarcastic, yes.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#55

Cussing is all fine and understandable, but I missed the part where the Google opsec team was searching for and plugging the holes the NSA is exploiting, or switching to another carrier, or suing the NSA for illegal wiretapping.

The problem is that it's not the NSA doing it. It's GCHQ, in the UK.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#56

Earlier quoted context omitted.

The Chinese were targeting specific journalists and critics. Presumably to harass them. I'm not saying the US doesn't do that, but the evidence is not as clear.

They weren't actually. Google lied about that. It came out later that the real reason for the Chinese hacking gmail was to see which accounts had "lawful intercept" on them so they would know if their own spies had their cover blown. If the US knew about their spies, it was assumed that they would see the US sniffing the spies gmail accounts. http://articles.washingtonpost.com/2013-05-20/world/39385755...

I was referring to the NYT attacks,

http://www.nytimes.com/2013/01/31/technology/chinese-hackers...

Also, what kind of spy uses gmail? Sheesh.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#57

Earlier quoted context omitted.

The Chinese were targeting specific journalists and critics. Presumably to harass them. I'm not saying the US doesn't do that, but the evidence is not as clear.

They weren't actually. Google lied about that. It came out later that the real reason for the Chinese hacking gmail was to see which accounts had "lawful intercept" on them so they would know if their own spies had their cover blown. If the US knew about their spies, it was assumed that they would see the US sniffing the spies gmail accounts. http://articles.washingtonpost.com/2013-05-20/world/39385755...

> Google lied about that

Huh? There's nothing in the Post's information that would preclude both from having happened, so it's would be a stretch to call it a lie even from that article. But in fact, the original blog post[1] talks about multiple goals of the main attack, including listing the targeted attack that the GP is probably referencing as independent from the attack that "resulted in the theft of intellectual property from Google". I think it's you that's confusing incidents.

> Third, as part of this investigation but independent of the attack on Google, we have discovered that the accounts of dozens of U.S.-, China- and Europe-based Gmail users who are advocates of human rights in China appear to have been routinely accessed by third parties. These accounts have not been accessed through any security breach at Google, but most likely via phishing scams or malware placed on the users' computers.

edit: ah, and the GP wasn't even talking about the gmail accounts.

[1] http://googleblog.blogspot.com/2010/01/new-approach-to-china...

Re: Google Security Team Member on NSA: "Fuck These Guys"

#58

Earlier quoted context omitted.

The Chinese were targeting specific journalists and critics. Presumably to harass them. I'm not saying the US doesn't do that, but the evidence is not as clear.

Maybe you didn't notice the detainment of Greenwald's partner by the GCHQ whereby they demanded him to turn-over/destroy whatever he had. Further, the break-in to Greenwald's residence and theft of his machine. As well as the visit to the Guardian and destrution of machines.... The evidence is crystal.

As much as the UK government would probably love being confused for the US government, at least the visit to the Guardian and detainment of Miranda were both done by the UK.

And given how the UK government loves nothing more than to be the lapdog of the US, I have no doubts it was done entirely voluntarily.

Eagerly even, as an opportunity to show off just how extra exceedingly loyal minions they are.

Frankly, I have little doubt that the UK government participates so eagerly that just occasionally some of their US counterparts must be a little bit embarrassed on their behalf over seeing their total lack of self respect in trying to impress.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#59
post #51

Earlier quoted context omitted.

Are you being sarcastic? For months Google's only public response was to lobby the government for permission to release stats(?) to prove that they complied with the law - nary a word of criticism for the law itself. So now that Google's own autonomy has been breached by the NSA (all above-board and legal according to the NSA's legions of loop-hole seeking lawyers) instead of just Google's users, now they are mad? I…

I was being sarcastic, yes.

OK.

I had laugh-snort reading the discussion on that page - at one point the original author, Mike Hearn, tries to argue that ad-based services are actually a good thing for privacy. Does Kool-Aid have a google flavor now?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#60

Earlier quoted context omitted.

They weren't actually. Google lied about that. It came out later that the real reason for the Chinese hacking gmail was to see which accounts had "lawful intercept" on them so they would know if their own spies had their cover blown. If the US knew about their spies, it was assumed that they would see the US sniffing the spies gmail accounts. http://articles.washingtonpost.com/2013-05-20/world/39385755...

I was referring to the NYT attacks, http://www.nytimes.com/2013/01/31/technology/chinese-hackers... Also, what kind of spy uses gmail? Sheesh.

Also, what kind of spy uses gmail? Sheesh.

The kind that is trying to maintain cover as a non-spy so uses the same email services as everybody else.

Post reply on HN