Earlier quoted context omitted.
> Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. The assumption isn't bad - it's a private network line, not a public internet connection. Nobody else had access to that line, at least they weren't supposed to. Splicing a fiber line is a bit out…
Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). The reasons is that you never know who is listening (big smile here). For example, I don't want our system administrators to have an easy way to look at the traffic: yes, it is still possible to do but it is harder and requires some very unusual actions that will trigger alerts everywhere. If in…
Google Security Team Member on NSA: "Fuck These Guys"
211–220 of 420 posts
Re: Google Security Team Member on NSA: "Fuck These Guys"
#212Earlier quoted context omitted.
Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). The reasons is that you never know who is listening (big smile here). For example, I don't want our system administrators to have an easy way to look at the traffic: yes, it is still possible to do but it is harder and requires some very unusual actions that will trigger alerts everywhere. If in…
> Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). Do you have your own data center building? And if you don't have your own data center buildings, how are you guarding against physical attacks? Because just saying "encryption" doesn't actually mean anything. Encryption isn't free, and at Google scale that can add up. Useless encryption is jus…
Some types of encryption are pretty cheap actually. I used to use special SSL cards in the servers 10-15 years ago but today my laptop would outperform these cards and wouldn't even get hot :) Plus you need to remember that relatively expensive public key encryption needs to be done only for key exchange. After that you run block or stream cyphers and those algorithms tend to be really fast.
So far I haven't seen any evidences that there was cable splicing. Thus using occam's razor I would assume that the hack was much simpler than that. To detect the issue, I would start from reviewing the visitors log to the data center (assuming there is a visitor log).
I'll re-iterate that security should be built on defense-in-depth principle. Every single protection layer will fail or someone will go around it. The assumption that a data center is "safe" is a bad assumption period. You have to play "what-if" game and think for the attacker.
Re: Google Security Team Member on NSA: "Fuck These Guys"
#213I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…
But it doesn't fix §702 fully, does nothing to end BULLRUN (undermining encryption) Nor should it. Undermining the encryption used by legitimate surveillance targets and intercepting their communications is what the NSA is for . The point of legislative solutions isn't to stop having a signals intelligence agency. It's to limit that agency to spying on people it legitimately believes to be terrorists, agents of hosti…
Re: Google Security Team Member on NSA: "Fuck These Guys"
#214Oh, the hypocrisy.... > "Bypassing that system is illegal for a good reason." Yes, so is invasion of privacy. Yet Google has no problem breaking the law and violating civil rights for profit. > "Unfortunately we live in a world where all too often, laws are for the little people." Yeah, like tax laws and privacy laws... If you want to get on this high horse, you shouldn't be working for Google.
How can Google become a more well behaved company if everyone working for them follows that rule?
Re: Google Security Team Member on NSA: "Fuck These Guys"
#215Earlier quoted context omitted.
Yes (search for SSAE16 or SAS70). However, I would not feel the same way if US government would have used Area 51 technology to hack 4096 public key encryption. The difference from my perspective is that in "burglary" scenario (and un-encrypted traffic scenario as well) Google failed to protect against well known threats. And in the "alien technology" case Google did everything you can at the known security/technolog…
What if the government kidnapped a Google engineer (or several) and hit them with a wrench until they retrieved the data? That's a known, low-tech threat too.
Re: Google Security Team Member on NSA: "Fuck These Guys"
#216Earlier quoted context omitted.
Sure but only an idiot uses their personal email account for work, right? Especially if your work can get you killed.
The point being made isn't that they would send sensitive data using gmail, it's that if they were compromised the NSA would most likely be reading the emails, and hacking Google would theoretically let the Chinese know if cover was blown if they could see evidence of the NSA listening in. Of course, that means the joke's on them, because the NSA was listening to everyone...
On the other hand if you want to read people's mail, then hacking into the provider is certainly an option.
Re: Google Security Team Member on NSA: "Fuck These Guys"
#217Earlier quoted context omitted.
You had enemies in the cold war. The USSR was much, much worse.
Things US did for Brazil: Sent aircraft carriers, ships and soldiers to help depose a democratically elected president, just because he wanted closer ties with China and wanted to do agrarian reform. Disappeared lots of people (I don't know any personally, because I am too young, but I DO know personally lots of people that still want disappeared people back) Spied on us (erm, that part still applies, no?). Sabotaged…
Stopped us getting nuked or invaded by the USSR
Re: Google Security Team Member on NSA: "Fuck These Guys"
#218Earlier quoted context omitted.
Yes (search for SSAE16 or SAS70). However, I would not feel the same way if US government would have used Area 51 technology to hack 4096 public key encryption. The difference from my perspective is that in "burglary" scenario (and un-encrypted traffic scenario as well) Google failed to protect against well known threats. And in the "alien technology" case Google did everything you can at the known security/technolog…
> Basically, I think Google's decision to do not encrypt the traffic is a gross negligence and I would love to see how someone would sue Google for it. Wow. Just wow.
Re: Google Security Team Member on NSA: "Fuck These Guys"
#219Earlier quoted context omitted.
I asked this question 6 months ago, I liked the reply. ---- Most programmers are very much unlike you or I. Think about those legions of DoD/DoD contractor engineers that trust government implicitly and totally, and really don't give a shit about more "hacker"/"technologist" subjects. ---- https://news.ycombinator.com/item?id=5836416
The other half of that equation is that the requirements for a security clearance tend to filter out the people who are mentally predisposed to question authority. It is a very rare person who can see all the things wrong with the various Wars on Dignity (drugs, terror, etc) and yet has a nose so clean as to qualify for a top secret clearance. It's kind of like the saying about walking a mile in someone else's shoes…
Incidentally, the U.S. system is strongly anti-authoritarian. There is no wise man or even thug running the show, just a parliament of whores tarting themselves up for the next election. We could really use some authorities in charge. Even a bad plan would be better than what we have if we just stuck to it.
Re: Google Security Team Member on NSA: "Fuck These Guys"
#220Earlier quoted context omitted.
Except, they didn't explicitly mean to do that, stopped doing that, and paid for the autonomous collection of trash that they threw out.
You are very naive if you think that Google does something by mistake (that also happens to fit well into their Big Black Hole of Information).