Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

231–240 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#231
post #71

Earlier quoted context omitted.

I can't agree with that, this was on Google's on fiber connections between their own data centers, right? And no other company with multiple data centers encrypts all traffic between them, right? (maybe you'll find a small counterexample but no big one.) So I don't think this is "security 101".

> And no other company with multiple data centers encrypts all traffic between them, right? Indeed they do! From personal experience, Cisco was hawking its TrustSec inter-DC encryption solution five or six years ago, even over dark fibre.

Google's inter-dc links are way too big for any appliance type of thing to encrypt. Like most things at Google the scale of their network is incomprehensible to most people.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#232
post #95

Earlier quoted context omitted.

Consider the recent passwords leak from Adobe: they stored passwords in a dedicated unshared datacenter. Does this make a good security decision to encrypt passwords instead of using a hash because nobody should have been able to access these encrypted passwords? I really don't think so.

There are problems with your analogy. 1. Data at rest (Adobe) vs data in travel (Google). 2. Software Hack vs Hardware hack The Adobe data was sitting on a server in a datacenter, it was accessible from the internet on some level. The Google data was taken, apparently, from a dedicated, google owned, unshared link (quite likely a fibre-optic tap) The methodologies, skill levels and required hardware for the penetrati…

I hear what you are saying but I think there are similarities. In both cases there was an assumption "X is safe" and then the thinking have stopped. I've heard different version of how the data was taken from the google's link and some ideas were pretty low-tech. The data links have been compromised in the past not only by NSA (search for "Operation Ivy Bells" if you haven't heard this story before) but also by criminals or even competitors.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#233
I think that we also forget in this age of reduced crime, that it doesn't matter whether or not something is illegal if you have no means of preventing someone from doing it or holding them responsible when they do. We discovered this situation not by uncovering the intrusion, but from leaked documents. The government has a lot of employees and likes to document its operations, which can lead to whistleblowing... organized crime has few employees, tight lips, and doesn't offer the same protection of whistleblowers. The problem here is not the NSA.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#234
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

[deleted]

Re: Google Security Team Member on NSA: "Fuck These Guys"

#235
post #227

Earlier quoted context omitted.

Legislative fixes aren't going to buy you a lot, though they'll buy you something. The fundamental problem is structural: there are a lot of things the NSA is totally allowed to do, especially when it acts as an agency of the executive outside of the U.S. Technologists tend to ignore national and jurisdictional borders because networks cross those borders, but the powers of the NSA are defined in terms of those borde…

Legal access to a document can't compel the owner of the document to hand over encryption keys. And if the existence of the document can be denied, you can't even prove it exists. This level of protection is within the reach of existing tools. Services like Google can make those tools accessible to the masses. The law has to observe physics. You can get a court order to "compel" someone to float off the ground, but t…

Sure, there are certain things that can be achieved by technological means. My point is that when it comes to certain areas of NSA activity, you're dealing with more than just simple legislative fixes. The specific example mentioned by Mike Hearn, the NSA tapping into international leased lines, is really illustrative. Our whole government is structured around the assumption that the executive branch is supreme when it comes to activities outside the U.S. To make it illegal,[1] for the NSA to tap into foreign leased lines would require more than just legislation, it would require Congress to decide to regulate the NSA's activity abroad in the first place. And in doing so Congress would run up against separation of powers issues, because in our system, it's not really Congress's place to dictate to the President how he carries out foreign security activities.

[1] I think as it is it might be a 4th amendment violation, but it's not contrary to any statute that I'm aware of, at least not any American statute.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#237
My bet, especially with the rumors of a secret google data ship, is that google is getting ready to make a data power play.

Something along these lines:

"Look at the horrible way NSA treated our customers... We're gonna make sure the NSA can't get our data in the future, and protect everyone's data. Come use our services where we treat you right!"

It was always just a matter of time before a corporation had the ability to compete in the total information awareness arena with the three letters. Google is probably the primary candidate that has the capability, besides MS/Apple.

Of course the three letters win on the data side, but the company wins on the customer side. Win win. For them. Lose for us.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#238
post #215
post #205

Earlier quoted context omitted.

What if the government kidnapped a Google engineer (or several) and hit them with a wrench until they retrieved the data? That's a known, low-tech threat too.

Absolutely. That's why you have to have logs and regular audits to make sure that employees are not doing things that they are not supposed to do. BTW, one should consider not only kidnapping but just a "rogue" employee. For example, in the Snowden's case the NSA itself put too much trust into system administrators and did not perform audits that should have detected downloads of secure files.

In my scenario, the log maintainers and the auditors were among the people being hit with wrenches.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#239

Earlier quoted context omitted.

You had enemies in the cold war. The USSR was much, much worse.

Things US did for Brazil: Sent aircraft carriers, ships and soldiers to help depose a democratically elected president, just because he wanted closer ties with China and wanted to do agrarian reform. Disappeared lots of people (I don't know any personally, because I am too young, but I DO know personally lots of people that still want disappeared people back) Spied on us (erm, that part still applies, no?). Sabotaged…

nice propaganda. cold war was about influence. the super powers would do any and everything to gain a foothold in another country. feel free to ask any polish citizen about the friendliness of Soviet Russia, they may welcome your speech with a punch in the face for the sake of those who suffered and died because their brethren spread similar idiotic notions of "the Soviets are our friends look at these free Russian texts and cars and..."

Re: Google Security Team Member on NSA: "Fuck These Guys"

#240
post #223

Earlier quoted context omitted.

Ok but to agree with that argument is to agree that the NSA and organizations like it are necessary. I'm still waiting for the proof that they are. Everything I see points to them compromising countless people's privacy and having nothing to show for it.

But that's the core of the problem. By the nature of what they do, their successes are never clear. Not that this is a very robust intellectual defense, but the US is far from the only country to do this. Just two days ago the NYT had an article about Brazil spying on Americans within its borders: http://www.nytimes.com/2013/11/05/world/americas/brazil-ackn... If we shut down the NSA tomorrow we would be an an intern…

Can we please try not to equate a diplomat's car being followed around a city's public areas with the indiscriminate collection of private communications from every man, woman and child on the planet?

Look, my eyes are open. I'm spying on you. Everybody spies!

Post reply on HN