Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

211–220 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#211
post #84

Earlier quoted context omitted.

> Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. The assumption isn't bad - it's a private network line, not a public internet connection. Nobody else had access to that line, at least they weren't supposed to. Splicing a fiber line is a bit out…

Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). The reasons is that you never know who is listening (big smile here). For example, I don't want our system administrators to have an easy way to look at the traffic: yes, it is still possible to do but it is harder and requires some very unusual actions that will trigger alerts everywhere. If in…

Seriously? If the NSA wanted to own WePay they would have even with your "security best practices". Sorry bud.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#212
post #84

Earlier quoted context omitted.

Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). The reasons is that you never know who is listening (big smile here). For example, I don't want our system administrators to have an easy way to look at the traffic: yes, it is still possible to do but it is harder and requires some very unusual actions that will trigger alerts everywhere. If in…

> Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). Do you have your own data center building? And if you don't have your own data center buildings, how are you guarding against physical attacks? Because just saying "encryption" doesn't actually mean anything. Encryption isn't free, and at Google scale that can add up. Useless encryption is jus…

At WePay - no, we don't have our own data centers just yet. In a couple large companies I worked before - yes (and we did encrypt the traffic as much as possible).

Some types of encryption are pretty cheap actually. I used to use special SSL cards in the servers 10-15 years ago but today my laptop would outperform these cards and wouldn't even get hot :) Plus you need to remember that relatively expensive public key encryption needs to be done only for key exchange. After that you run block or stream cyphers and those algorithms tend to be really fast.

So far I haven't seen any evidences that there was cable splicing. Thus using occam's razor I would assume that the hack was much simpler than that. To detect the issue, I would start from reviewing the visitors log to the data center (assuming there is a visitor log).

I'll re-iterate that security should be built on defense-in-depth principle. Every single protection layer will fail or someone will go around it. The assumption that a data center is "safe" is a bad assumption period. You have to play "what-if" game and think for the attacker.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#213
post #167
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

But it doesn't fix §702 fully, does nothing to end BULLRUN (undermining encryption) Nor should it. Undermining the encryption used by legitimate surveillance targets and intercepting their communications is what the NSA is for . The point of legislative solutions isn't to stop having a signals intelligence agency. It's to limit that agency to spying on people it legitimately believes to be terrorists, agents of hosti…

Ok but to agree with that argument is to agree that the NSA and organizations like it are necessary. I'm still waiting for the proof that they are. Everything I see points to them compromising countless people's privacy and having nothing to show for it.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#214

Oh, the hypocrisy.... > "Bypassing that system is illegal for a good reason." Yes, so is invasion of privacy. Yet Google has no problem breaking the law and violating civil rights for profit. > "Unfortunately we live in a world where all too often, laws are for the little people." Yeah, like tax laws and privacy laws... If you want to get on this high horse, you shouldn't be working for Google.

How can Google become a more well behaved company if everyone working for them follows that rule?

Because they'll lose good people to competitors and be forced to improve their behavior if they want to retain talent.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#215
post #205
post #75

Earlier quoted context omitted.

Yes (search for SSAE16 or SAS70). However, I would not feel the same way if US government would have used Area 51 technology to hack 4096 public key encryption. The difference from my perspective is that in "burglary" scenario (and un-encrypted traffic scenario as well) Google failed to protect against well known threats. And in the "alien technology" case Google did everything you can at the known security/technolog…

What if the government kidnapped a Google engineer (or several) and hit them with a wrench until they retrieved the data? That's a known, low-tech threat too.

Absolutely. That's why you have to have logs and regular audits to make sure that employees are not doing things that they are not supposed to do. BTW, one should consider not only kidnapping but just a "rogue" employee. For example, in the Snowden's case the NSA itself put too much trust into system administrators and did not perform audits that should have detected downloads of secure files.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#216
post #73

Earlier quoted context omitted.

Sure but only an idiot uses their personal email account for work, right? Especially if your work can get you killed.

The point being made isn't that they would send sensitive data using gmail, it's that if they were compromised the NSA would most likely be reading the emails, and hacking Google would theoretically let the Chinese know if cover was blown if they could see evidence of the NSA listening in. Of course, that means the joke's on them, because the NSA was listening to everyone...

how would you know whether NSA was listening in (for example by tapping google's links between datacenters) or not even if you successfully hack into Google's infrastructure? Not finding evidence of eavesdropping doesn't exclude that eavesdropping happened, so if that was the only purpose to hack Google, it doesn't seem worth the effort.

On the other hand if you want to read people's mail, then hacking into the provider is certainly an option.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#217

Earlier quoted context omitted.

You had enemies in the cold war. The USSR was much, much worse.

Things US did for Brazil: Sent aircraft carriers, ships and soldiers to help depose a democratically elected president, just because he wanted closer ties with China and wanted to do agrarian reform. Disappeared lots of people (I don't know any personally, because I am too young, but I DO know personally lots of people that still want disappeared people back) Spied on us (erm, that part still applies, no?). Sabotaged…

Things the US did for Europe:

Stopped us getting nuked or invaded by the USSR

Re: Google Security Team Member on NSA: "Fuck These Guys"

#218
post #75

Earlier quoted context omitted.

Yes (search for SSAE16 or SAS70). However, I would not feel the same way if US government would have used Area 51 technology to hack 4096 public key encryption. The difference from my perspective is that in "burglary" scenario (and un-encrypted traffic scenario as well) Google failed to protect against well known threats. And in the "alien technology" case Google did everything you can at the known security/technolog…

> Basically, I think Google's decision to do not encrypt the traffic is a gross negligence and I would love to see how someone would sue Google for it. Wow. Just wow.

I know that people don't like lawsuits. But for security to work there should be consequences for not doing security right. To give you an example, if a company X doesn't have any risks or damages from lack of security, then company X should not be investing in security to save money. However, if there is a monetary (or other) liability from a security breach, then the company X will have to make a choice and hopefully they will invest in security.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#219
post #43

Earlier quoted context omitted.

I asked this question 6 months ago, I liked the reply. ---- Most programmers are very much unlike you or I. Think about those legions of DoD/DoD contractor engineers that trust government implicitly and totally, and really don't give a shit about more "hacker"/"technologist" subjects. ---- https://news.ycombinator.com/item?id=5836416

The other half of that equation is that the requirements for a security clearance tend to filter out the people who are mentally predisposed to question authority. It is a very rare person who can see all the things wrong with the various Wars on Dignity (drugs, terror, etc) and yet has a nose so clean as to qualify for a top secret clearance. It's kind of like the saying about walking a mile in someone else's shoes…

You have it utterly backwards. In my experience, clearance holders have a far more bleak outlook on government than you. If you think people will elect madmen and witch hunters no matter what, which seems to be the case, you might as well make sure the spy-fest is good enough to stop the occassional war. In this view there are not well-meaning plans with collateral damage, but planned crass destruction with collateral benefits.

Incidentally, the U.S. system is strongly anti-authoritarian. There is no wise man or even thug running the show, just a parliament of whores tarting themselves up for the next election. We could really use some authorities in charge. Even a bad plan would be better than what we have if we just stuck to it.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#220

Earlier quoted context omitted.

Except, they didn't explicitly mean to do that, stopped doing that, and paid for the autonomous collection of trash that they threw out.

You are very naive if you think that Google does something by mistake (that also happens to fit well into their Big Black Hole of Information).

You are very paranoid if you think a corporation with thousands of employees never makes mistakes.
Post reply on HN