Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

131–140 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#131
post #67

Earlier quoted context omitted.

That's very unlikely nobody would have noticed them by now, if it were the case.

Do you mean - as unlikely as not spotting the weakening of encryption standards - for example by another branch of the same government (NIST/NSA)?

Those were spotted.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#132
post #112

Earlier quoted context omitted.

Thanks. > And of course, there are VPN tunnels between data centers in addition to the above. Could you please be more specific on the VPN solution that you are using? How do you manage the shared keys? How do you make sure 'system administrators can't easily read the traffic?"

We use Cisco appliances for VPN (a few different models) and indeed there is a shared key that we have to input manually. However, after the key is entered (and configs saved) in order to decrypt the traffic one would need to print Cisco configs which is a very unusual operation that would be logged and then alerts will fire, audits will catch it, etc.

>> in order to decrypt the traffic one would need to print Cisco configs

Which could be done legally via 'Cisco Service Independent Intercept (SII)' built into IOS to comply with CALEA (Communications Assistance for Law Enforcement Act). And not so legally via user-escalation exploits within the same service.

Anyway, props for making the effort. I too am interested in your key exchange methods.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#133
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

The legislative fixes need to create an environment where the technical capabilities and safeguards put in place are considered normal, and companies are not forced to do harm to users. That's the most important part, creating an environment that sets precedence for user's rights.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#134
post #6

This has been asked before, but I'd love to hear from a dev (anonymously of course) who actually helped build this NSA madness. Is it like The Cube, where no one really knew what each piece was for? Is it that they are morally pro the NSA's attitude toward personal and corporate privacy, or do they just not care either way?

It's like being a cop: you get to shoot people (and people's dogs) and break most laws every non-cop has to abide by, with impunity.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#135

It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.

On the whole, I think I'd rather be spied on by an ally rather than a dictatorship.

I live in a "Western", English speaking democracy, with friendly relations with both the US and China.

Our biggest trading partner is China, and we have a free-trade agreement with the US.

Who exactly is our ally again?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#136
post #71

Earlier quoted context omitted.

I can't agree with that, this was on Google's on fiber connections between their own data centers, right? And no other company with multiple data centers encrypts all traffic between them, right? (maybe you'll find a small counterexample but no big one.) So I don't think this is "security 101".

> And no other company with multiple data centers encrypts all traffic between them, right? Indeed they do! From personal experience, Cisco was hawking its TrustSec inter-DC encryption solution five or six years ago, even over dark fibre.

If you believe the threat is a government agency splicing private, unshared fiber to capture your traffic between data centers, why in the world would you trust equipment from Cisco (who lists "Government" as one of the industries they sell to) to protect you from that?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#137
post #62

Earlier quoted context omitted.

China doesn't have agreements with BT, AT&T etc which allow it to tap fibre in our countries at will. I'm sure they try some tapping, but they can't do it on the scale that GCHQ and the NSA have been outside China.

But they could easily have agreements with every chip fab to build back doors into every piece of networking equipment.

You can packet-trace networking equipment you own.

You can't packet-trace a cloned switch port you don't know about.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#138
post #12

Earlier quoted context omitted.

Why do people assume the Chinese government is not able to use similar techniques?

China doesn't have agreements with BT, AT&T etc which allow it to tap fibre in our countries at will. I'm sure they try some tapping, but they can't do it on the scale that GCHQ and the NSA have been outside China.

The Chinese do not need any agreements to tap undersea cables and are more than capable of doing just that.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#139

Earlier quoted context omitted.

On the whole, I think I'd rather be spied on by an ally rather than a dictatorship.

Completely disagree with that. That is like saying you would prefer to have your own brother punch you in your face than a stranger. It hurts a lot more because you are meant to look out for each other, not distrust and stab each others back.

Well I trust what the US does with the information more than China. It's like Tiannamen Square never happened.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#140

It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.

On the whole, I think I'd rather be spied on by an ally rather than a dictatorship.

As a Brazilian that had ti witness the effects of US alliance during cold war... No, hell no. With a friend like that, who needs enemies?
Post reply on HN