Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

201–210 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#201

Earlier quoted context omitted.

Except, they didn't explicitly mean to do that, stopped doing that, and paid for the autonomous collection of trash that they threw out.

You are very naive if you think that Google does something by mistake (that also happens to fit well into their Big Black Hole of Information).

Given some of the other revelations, is it too tinfoil-hat to entertain the notion that Google were compelled to make the aforementioned slip-up?

Almost certainly it is, but would I be surprised if it were true? Would anyone be?

I'd be willing to bet the NSA had a good browse of the resulting data, either way.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#202
post #90

Earlier quoted context omitted.

BTW, "at least they weren't supposed to" is not a good enough argument in security :) You have to think about people who are not following the rules or your security is only protecting from a well-behaving 1st grade student.

There is no such thing as perfect security, only good enough security. At some point you have to accept risks, and the risk of physical network attacks is incredibly small compared to all the other attack vectors. Nobody was well prepared for the NSA's physical network attacks.

Everybody who cared knew that the world's governments tap every fiber they can lay their hands on. It has been discussed on HN with great regularity for years before these NSA non-revelations. Physical attacks were and are a certainty. Anybody who ignores this fact has only themselves to blame. A good argument can even be made that they deserved to be pwned as punishment for their utter fecklessness.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#203
post #86

Oh, the hypocrisy.... > "Bypassing that system is illegal for a good reason." Yes, so is invasion of privacy. Yet Google has no problem breaking the law and violating civil rights for profit. > "Unfortunately we live in a world where all too often, laws are for the little people." Yeah, like tax laws and privacy laws... If you want to get on this high horse, you shouldn't be working for Google.

Erm, what? Which law did they break, and which civil rights did they violate?

[deleted]

Re: Google Security Team Member on NSA: "Fuck These Guys"

#204
post #170
post #86

Earlier quoted context omitted.

Erm, what? Which law did they break, and which civil rights did they violate?

Tax evasion in EU/US by Google/Apple is beyond imagination.

Are you claiming they act illegally, or are you claiming that they have some duty to pay more than they do today?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#205
post #75
post #68

Earlier quoted context omitted.

Would you still feel Google had screwed up if the way the US government got the data was to burglarize one of their datacenters and tap directly into the machines' CPUs and memory buses?

Yes (search for SSAE16 or SAS70). However, I would not feel the same way if US government would have used Area 51 technology to hack 4096 public key encryption. The difference from my perspective is that in "burglary" scenario (and un-encrypted traffic scenario as well) Google failed to protect against well known threats. And in the "alien technology" case Google did everything you can at the known security/technolog…

What if the government kidnapped a Google engineer (or several) and hit them with a wrench until they retrieved the data? That's a known, low-tech threat too.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#206
post #6

This has been asked before, but I'd love to hear from a dev (anonymously of course) who actually helped build this NSA madness. Is it like The Cube, where no one really knew what each piece was for? Is it that they are morally pro the NSA's attitude toward personal and corporate privacy, or do they just not care either way?

> Is it like The Cube, where no one really knew what each piece was for?

Not possible. You cannot unwittingly buy a house in Cupertino, fill it with 48 V batteries and wave division multiplexing transceivers, and trench the back yard. The maintenance techs driving the fake pool service van knew exactly what they were doing.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#207
So, this is how it's gonna play out:

Over the next few years it will become more and more common for "in-flight" data to be encrypted. As the "low-hanging fruit" starts to disappear, state-level attackers will increasingly turn their attention from fibre to endpoint; with a corresponding increase in the number of attacks on mobile devices, apps, and embedded systems. This is, to put it mildly, incredibly challenging terrain for passive defence, where complexity all-but-guarantees unknown vulnerabilities and hidden attack vectors.

Now, I am not too sure about the ethics of active defence / networked HIPS, (Too similar by a long shot to the sort of malevolent behaviour it is supposed to defend against) but it might be something that we are going have to have a look at.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#209
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

Legislative fixes aren't going to buy you a lot, though they'll buy you something. The fundamental problem is structural: there are a lot of things the NSA is totally allowed to do, especially when it acts as an agency of the executive outside of the U.S. Technologists tend to ignore national and jurisdictional borders because networks cross those borders, but the powers of the NSA are defined in terms of those borders. Not just statutorily, but as an agency of the executive, Constitutionally.

For example, Mike Hearn says: "Bypassing that system is illegal for a good reason." Illegal under whose law? Obvious things like the Wiretap Act simply don't apply outside the U.S. And this is by design: Congress and the courts are primarily domestic institutions. The executive, by design, has primacy when it comes to activities outside the U.S. Maybe this design made a lot more sense back in the day before the advent of trans-national corporations, but it's the design we have, and we're talking Constitutional-amendment level fixes to change that design.

Internally, you might see fixes without a Constitutional amendment. E.g. the Supreme Court might at some point weaken the third party doctrine, which is what makes a lot of the NSA's data collection not a violation of the 4th amendment. But they won't touch the activities of the NSA internationally.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#210
post #87

Here's one potential cultural snafu - my understanding is US intelligence based almost entirely on SIGINT. I'm not sure how great we are at plain old HUMINT, i.e. using people and relationships to get information and an overall picture of the world. So all the defense community was raised on SIGINT, and anything seen as a curb on this - technical or legal, they will probably view it as some sort of existential threat…

It hasn't always been this way, and I'm sure the State Department and the Office of the President rely on SIGINT far more than direct diplomacy -- even to the point where diplomatic efforts are, universally, a cold formality.

They like to toss words like "Terrorism" around like frisbees hoping someone will catch it and toss it to someone else, however I personally think we can assume that direct diplomacy is dead. SIGINT is more consistent and dependable than engaging another nation's diplomatic apparatus, and all nations are clamoring for their own monitoring solution.

It's a new baseline measurement of international political power -- the cost is so low that it's foolish not to get it.

Post reply on HN