Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

121–130 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#121
post #95

Earlier quoted context omitted.

Does your company have dedicated, unshared, fibre between those datacenters?

Consider the recent passwords leak from Adobe: they stored passwords in a dedicated unshared datacenter. Does this make a good security decision to encrypt passwords instead of using a hash because nobody should have been able to access these encrypted passwords? I really don't think so.

There are problems with your analogy.

1. Data at rest (Adobe) vs data in travel (Google).

2. Software Hack vs Hardware hack

The Adobe data was sitting on a server in a datacenter, it was accessible from the internet on some level. The Google data was taken, apparently, from a dedicated, google owned, unshared link (quite likely a fibre-optic tap)

The methodologies, skill levels and required hardware for the penetrating the above two types of setup are wildly different.

I blame adobe for getting a server hacked, it happens a lot and and they ignored a lot of body of knowledge built up over the years. I do not blame Google for getting their inter-datacentre links physically compromised by a security agency of the US government.

Nor do I blame them for (incorrectly, as it turns out) deeming that an unlikely scenario and therefore giving it low priority.

I would blame them for not doing anything about it now that they know it is happening but that does not seem to be the case.

(I fully expect companies to encrypt data between datacentres if they are not on dedicated unshared links)

Re: Google Security Team Member on NSA: "Fuck These Guys"

#122

It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.

On the whole, I think I'd rather be spied on by an ally rather than a dictatorship.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#123
post #111
post #59

Earlier quoted context omitted.

OK. I had laugh-snort reading the discussion on that page - at one point the original author, Mike Hearn, tries to argue that ad-based services are actually a good thing for privacy. Does Kool-Aid have a google flavor now?

You should respond to his argument instead of accusing him of brainwashing. The latter does nothing to advance the conversation.

Can't. I so disbelieve in his argument that I won't sign up for G+.

Besides, as Upton Sinclair was fond of saying, "It is difficult to get a man to understand something, when his salary depends upon his not understanding it."

Re: Google Security Team Member on NSA: "Fuck These Guys"

#124
post #21
post #6

This has been asked before, but I'd love to hear from a dev (anonymously of course) who actually helped build this NSA madness. Is it like The Cube, where no one really knew what each piece was for? Is it that they are morally pro the NSA's attitude toward personal and corporate privacy, or do they just not care either way?

In The Shadow Factory (written after the Klein leaks but before Snowden), Bamford notes that a lot of surveillance equipment comes from Israel. I don't know much about Israeli culture but it may be significantly different from the US.

Some equipment might come from Israel (it's just guessing though), but I do not like your implicit hinting that Israeli developers are somehow less moral than U.S developers (because of "cultural" differences?) - especially since you don't know much about it. You seem to be forgetting which government and agency is at the center of this debacle, don't try to share the blame on other nations or cultures for developing those spying system

Re: Google Security Team Member on NSA: "Fuck These Guys"

#125

Earlier quoted context omitted.

Except, they didn't explicitly mean to do that, stopped doing that, and paid for the autonomous collection of trash that they threw out.

You are very naive if you think that Google does something by mistake (that also happens to fit well into their Big Black Hole of Information).

First of all, the public should do something about their privacy, if they are concerned about their privacy. Parents are teaching their children that anything they do on the internet is never private.

Nonetheless, I doubt I'm naive to believe engineers are not always making mistakes. The trick is always in admitting mistake, learning from them, and fixing the future. In this case, Google acknowledged the -- lawful -- slip in privacy encroachments and assigned a privacy director to oversee engineering and product management efforts. Every Google product now maintains a privacy-design document.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#126

It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.

On the whole, I think I'd rather be spied on by an ally rather than a dictatorship.

Completely disagree with that. That is like saying you would prefer to have your own brother punch you in your face than a stranger.

It hurts a lot more because you are meant to look out for each other, not distrust and stab each others back.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#127
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

Try to find a fix for the ridiculously broken system that is the US government?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#128
They are likely both complicit in - as well as victims of - fiber tapping given GOOG now owns the building housing one of the largest peering exchanges on the Internet [1].

[1] 111 Eight Ave in NYC (housing Hiberia's trans-Atlantic cable, Equinox, Deutsch Telecom, etc)

http://www.datacenterknowledge.com/archives/2010/12/03/wsj-g...

Re: Google Security Team Member on NSA: "Fuck These Guys"

#130
post #112

Earlier quoted context omitted.

Thanks. > And of course, there are VPN tunnels between data centers in addition to the above. Could you please be more specific on the VPN solution that you are using? How do you manage the shared keys? How do you make sure 'system administrators can't easily read the traffic?"

We use Cisco appliances for VPN (a few different models) and indeed there is a shared key that we have to input manually. However, after the key is entered (and configs saved) in order to decrypt the traffic one would need to print Cisco configs which is a very unusual operation that would be logged and then alerts will fire, audits will catch it, etc.

Just out of interest how do you transfer the key between datacentres for setup? Same person travels between them? PGP encrypted email? Or over the phone?

Phone is I think an obvious (and now clearly wrong choice) although maybe always suspect if you are concerned with dark fibre . The endpoint security of a device generating and transmitting the key now also being a risk. How far up the chain do you worry?

An airgapped device to generate the key and a single person travelling between datacentres seems the secure (although costly) solution. Obviously if TSA/customs remove device from them for inspection or connect it to anything it needs to be thrown away (or moved to insecure duties) and the setup process restarted.

Post reply on HN