Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

81–90 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#81

Well that's ok. But what really needs to happen is this to come from the top management - and most of all, they need to ACT accordingly. Until then, all this "fuck them" exclamations aren't worth a dime.

You mean like working on projects to encrypt all of their data center links, which started, incidentally, before the Snowden revelations. Or the fact that David Drummond and Eric Schmidt have publicly said the diplomatic equivalent of 'fuck these guys'?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#82
post #71
post #52

Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. Basically, this is security 101: protect data at rest and protect data in flight. So, sorry but I think the better subject for discussion would be how badly Google screwed up, not how evil is NSA. M…

I can't agree with that, this was on Google's on fiber connections between their own data centers, right? And no other company with multiple data centers encrypts all traffic between them, right? (maybe you'll find a small counterexample but no big one.) So I don't think this is "security 101".

I work for a company bigger than Google, and we encrypt everything in flight between datacenters. It is security 101.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#83

I can understand using unencrypted network within a data center (unless you are doubly paranoid), but why wouldn't they encrypt data between data centers?

They buy the lines in the ground. It is suppose to be 100% private. It is like having a wire from one room of your house to another. Wikileaks has a list of vendors/products who allow these types of things to happen. What I want to know is how they tapped the actual line. I would assume these lines are going directly into Google owned (or controlled) buildings.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#84
post #52

Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. Basically, this is security 101: protect data at rest and protect data in flight. So, sorry but I think the better subject for discussion would be how badly Google screwed up, not how evil is NSA. M…

> Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. The assumption isn't bad - it's a private network line, not a public internet connection. Nobody else had access to that line, at least they weren't supposed to. Splicing a fiber line is a bit out…

Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). The reasons is that you never know who is listening (big smile here). For example, I don't want our system administrators to have an easy way to look at the traffic: yes, it is still possible to do but it is harder and requires some very unusual actions that will trigger alerts everywhere.

If indeed Google does not know then it's just another sign of security failures at the company. Nobody is perfect and security incidents do happen. A good security will have in-depth defense and built-in monitoring/audit measure that would at the very least allow you to determine what have happened post-factum.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#85
post #14
post #12

Earlier quoted context omitted.

Why do people assume the Chinese government is not able to use similar techniques?

More importantly, whats the difference between Chinese and American government when it comes to privacy?

The Chinese are honest about it !

Re: Google Security Team Member on NSA: "Fuck These Guys"

#86

Oh, the hypocrisy.... > "Bypassing that system is illegal for a good reason." Yes, so is invasion of privacy. Yet Google has no problem breaking the law and violating civil rights for profit. > "Unfortunately we live in a world where all too often, laws are for the little people." Yeah, like tax laws and privacy laws... If you want to get on this high horse, you shouldn't be working for Google.

Erm, what? Which law did they break, and which civil rights did they violate?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#87
Here's one potential cultural snafu - my understanding is US intelligence based almost entirely on SIGINT. I'm not sure how great we are at plain old HUMINT, i.e. using people and relationships to get information and an overall picture of the world.

So all the defense community was raised on SIGINT, and anything seen as a curb on this - technical or legal, they will probably view it as some sort of existential threat. They would then fight tooth and nail to block any sort of reform. And the military industrial complex has quite a lot of legislative muscle....

Re: Google Security Team Member on NSA: "Fuck These Guys"

#88
post #62

Earlier quoted context omitted.

China doesn't have agreements with BT, AT&T etc which allow it to tap fibre in our countries at will. I'm sure they try some tapping, but they can't do it on the scale that GCHQ and the NSA have been outside China.

But they could easily have agreements with every chip fab to build back doors into every piece of networking equipment.

This is exactly why Australia is very leery of letting the Chinese telecom hardware manufacturer Huawei have any of the contracts for networking hardware on the nascent National Broadband Network -- they are suspected of having ties to the Chinese government / army: https://en.wikipedia.org/wiki/Huawei#Security_concerns

Re: Google Security Team Member on NSA: "Fuck These Guys"

#89
I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance:

- Bill 1: The FISA Improvements Act, from Feinstein and the Senate Intelligence Committee. In short it legalizes most of what the NSA has been done.

- Bill 2: The USA FREEDOM ACT, from Sensenbrenner and Leahy, currently being considered by the House/Senate Judiciary committees. It amends §215 of FISA to end bulk phone metadata collection and fixes some of the problems with §702 of the FISA Amendments Act (under which PRISM is run). But it doesn't fix §702 fully, does nothing to end BULLRUN (undermining encryption) nor the surveillance that happens outside FISA (MUSCULAR, for example, and god knows what else).

Obviously the Feinstein bill can't be allowed to pass. But some really big names (ACLU, CDT) have thrown strong support behind the Freedom Act. I'm wondering what we as the Taskforce(.is) should do. It's clear to me that it doesn't go nearly far enough. And there's some chance that if it passes, Congress will view this whole thing as "dealt with" and not revisit the issue for years to come. But unfortunately the Freedom Act barely has the votes to get out of the judiciary committee, and getting it to pass through both houses requires a lot of momentum.

We've been working on a campaign asking folks to call and oppose Feinstein, and potentially to support the Freedom Act. But I'm not sure if that's a right move. Unfortunately, the public doesn't understand why privacy is important, and Americans aren't nearly angry enough for Congress to do anything more substantial than the Freedom Act. We might be able to push for amendments, but it's a long shot.

tl;dr - We've got two bills in Congress. One is terrible, one is mediocre. But we don't have the political momentum to do anything better than the mediocre bill. What do we do? Tech advocate conundrum.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#90
post #52

Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. Basically, this is security 101: protect data at rest and protect data in flight. So, sorry but I think the better subject for discussion would be how badly Google screwed up, not how evil is NSA. M…

> Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. The assumption isn't bad - it's a private network line, not a public internet connection. Nobody else had access to that line, at least they weren't supposed to. Splicing a fiber line is a bit out…

BTW, "at least they weren't supposed to" is not a good enough argument in security :) You have to think about people who are not following the rules or your security is only protecting from a well-behaving 1st grade student.
Post reply on HN