Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

111–120 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#111
post #59

Earlier quoted context omitted.

I was being sarcastic, yes.

OK. I had laugh-snort reading the discussion on that page - at one point the original author, Mike Hearn, tries to argue that ad-based services are actually a good thing for privacy. Does Kool-Aid have a google flavor now?

You should respond to his argument instead of accusing him of brainwashing. The latter does nothing to advance the conversation.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#112
post #106

Earlier quoted context omitted.

* Mid-tier servers: standard HTTPS with nginx * Database: SSL connections for MySQL * Memcached, Gearmand, and other tools that don't have built-in SSL support: simple home grown message level encryption (AES256) And of course, there are VPN tunnels between data centers in addition to the above.

Thanks. > And of course, there are VPN tunnels between data centers in addition to the above. Could you please be more specific on the VPN solution that you are using? How do you manage the shared keys? How do you make sure 'system administrators can't easily read the traffic?"

We use Cisco appliances for VPN (a few different models) and indeed there is a shared key that we have to input manually. However, after the key is entered (and configs saved) in order to decrypt the traffic one would need to print Cisco configs which is a very unusual operation that would be logged and then alerts will fire, audits will catch it, etc.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#113
post #12

Earlier quoted context omitted.

Why do people assume the Chinese government is not able to use similar techniques?

China doesn't have agreements with BT, AT&T etc which allow it to tap fibre in our countries at will. I'm sure they try some tapping, but they can't do it on the scale that GCHQ and the NSA have been outside China.

[deleted]

Re: Google Security Team Member on NSA: "Fuck These Guys"

#114
post #67
post #62

Earlier quoted context omitted.

But they could easily have agreements with every chip fab to build back doors into every piece of networking equipment.

That's very unlikely nobody would have noticed them by now, if it were the case.

Do you mean - as unlikely as not spotting the weakening of encryption standards - for example by another branch of the same government (NIST/NSA)?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#115
post #58

Earlier quoted context omitted.

Maybe you didn't notice the detainment of Greenwald's partner by the GCHQ whereby they demanded him to turn-over/destroy whatever he had. Further, the break-in to Greenwald's residence and theft of his machine. As well as the visit to the Guardian and destrution of machines.... The evidence is crystal.

As much as the UK government would probably love being confused for the US government, at least the visit to the Guardian and detainment of Miranda were both done by the UK. And given how the UK government loves nothing more than to be the lapdog of the US, I have no doubts it was done entirely voluntarily. Eagerly even, as an opportunity to show off just how extra exceedingly loyal minions they are. Frankly, I have…

Exactly my thought. Making me embarrassed to a singel fact that I live in UK, as that happened.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#116
post #84

Earlier quoted context omitted.

> Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. The assumption isn't bad - it's a private network line, not a public internet connection. Nobody else had access to that line, at least they weren't supposed to. Splicing a fiber line is a bit out…

Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). The reasons is that you never know who is listening (big smile here). For example, I don't want our system administrators to have an easy way to look at the traffic: yes, it is still possible to do but it is harder and requires some very unusual actions that will trigger alerts everywhere. If in…

> Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO).

Do you have your own data center building? And if you don't have your own data center buildings, how are you guarding against physical attacks? Because just saying "encryption" doesn't actually mean anything. Encryption isn't free, and at Google scale that can add up. Useless encryption is just wasted power

> For example, I don't want our system administrators to have an easy way to look at the traffic: yes, it is still possible to do but it is harder and requires some very unusual actions that will trigger alerts everywhere.

That can be accomplished in many ways that don't involve encryption. And your servers are all capable of decrypting the data at some point, so you still have to trust your sys admins and/or have alternative systems in place as they still have access to the unencrypted data.

> A good security will have in-depth defense and built-in monitoring/audit measure that would at the very least allow you to determine what have happened post-factum.

How, exactly, do you detect cable splicing? Much less audit said splicing? You seem to be asking for a hell of a lot more than "good security"

Re: Google Security Team Member on NSA: "Fuck These Guys"

#117
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

[deleted]

Re: Google Security Team Member on NSA: "Fuck These Guys"

#118
post #90

Earlier quoted context omitted.

> Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. The assumption isn't bad - it's a private network line, not a public internet connection. Nobody else had access to that line, at least they weren't supposed to. Splicing a fiber line is a bit out…

BTW, "at least they weren't supposed to" is not a good enough argument in security :) You have to think about people who are not following the rules or your security is only protecting from a well-behaving 1st grade student.

There is no such thing as perfect security, only good enough security. At some point you have to accept risks, and the risk of physical network attacks is incredibly small compared to all the other attack vectors. Nobody was well prepared for the NSA's physical network attacks.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#119
I think it's time to also highlight the fact that people enabled the NSA to do these things. A lot of them engineers. In some cases I'm sure the ones building the stuff didn't or couldn't see the end goal. But I guess there have been many who HAVE suspected or known about the use-cases of the products/software that they have been a part of making. This scares me, it is time that engineers take some moral responsibility. Maybe some course in ethical decision making wouldn't hurt to include in engineering colleges?

(Note: All fields should take moral responsibility, but engineers seem to be worse than a lot of others.)

Re: Google Security Team Member on NSA: "Fuck These Guys"

#120

Earlier quoted context omitted.

Like indiscriminately and illegally sucking up WiFi data with their street view mobiles? Including account information and passwords on unsecured WiFi connections. Even if the accusation of "violating laws" may be a tad hyperbolic in the great scheme of things it's not a stretch to deem Google one of the most hypocritical companies around.

Except, they didn't explicitly mean to do that, stopped doing that, and paid for the autonomous collection of trash that they threw out.

You are very naive if you think that Google does something by mistake (that also happens to fit well into their Big Black Hole of Information).
Post reply on HN