Earlier quoted context omitted.
I can't agree with that, this was on Google's on fiber connections between their own data centers, right? And no other company with multiple data centers encrypts all traffic between them, right? (maybe you'll find a small counterexample but no big one.) So I don't think this is "security 101".
> And no other company with multiple data centers encrypts all traffic between them, right? Indeed they do! From personal experience, Cisco was hawking its TrustSec inter-DC encryption solution five or six years ago, even over dark fibre.
Google Security Team Member on NSA: "Fuck These Guys"
231–240 of 420 posts
Re: Google Security Team Member on NSA: "Fuck These Guys"
#232Earlier quoted context omitted.
Consider the recent passwords leak from Adobe: they stored passwords in a dedicated unshared datacenter. Does this make a good security decision to encrypt passwords instead of using a hash because nobody should have been able to access these encrypted passwords? I really don't think so.
There are problems with your analogy. 1. Data at rest (Adobe) vs data in travel (Google). 2. Software Hack vs Hardware hack The Adobe data was sitting on a server in a datacenter, it was accessible from the internet on some level. The Google data was taken, apparently, from a dedicated, google owned, unshared link (quite likely a fibre-optic tap) The methodologies, skill levels and required hardware for the penetrati…
Re: Google Security Team Member on NSA: "Fuck These Guys"
#233Re: Google Security Team Member on NSA: "Fuck These Guys"
#234I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…
Re: Google Security Team Member on NSA: "Fuck These Guys"
#235Earlier quoted context omitted.
Legislative fixes aren't going to buy you a lot, though they'll buy you something. The fundamental problem is structural: there are a lot of things the NSA is totally allowed to do, especially when it acts as an agency of the executive outside of the U.S. Technologists tend to ignore national and jurisdictional borders because networks cross those borders, but the powers of the NSA are defined in terms of those borde…
Legal access to a document can't compel the owner of the document to hand over encryption keys. And if the existence of the document can be denied, you can't even prove it exists. This level of protection is within the reach of existing tools. Services like Google can make those tools accessible to the masses. The law has to observe physics. You can get a court order to "compel" someone to float off the ground, but t…
[1] I think as it is it might be a 4th amendment violation, but it's not contrary to any statute that I'm aware of, at least not any American statute.
Re: Google Security Team Member on NSA: "Fuck These Guys"
#236Re: Google Security Team Member on NSA: "Fuck These Guys"
#237Something along these lines:
"Look at the horrible way NSA treated our customers... We're gonna make sure the NSA can't get our data in the future, and protect everyone's data. Come use our services where we treat you right!"
It was always just a matter of time before a corporation had the ability to compete in the total information awareness arena with the three letters. Google is probably the primary candidate that has the capability, besides MS/Apple.
Of course the three letters win on the data side, but the company wins on the customer side. Win win. For them. Lose for us.
Re: Google Security Team Member on NSA: "Fuck These Guys"
#238Earlier quoted context omitted.
What if the government kidnapped a Google engineer (or several) and hit them with a wrench until they retrieved the data? That's a known, low-tech threat too.
Absolutely. That's why you have to have logs and regular audits to make sure that employees are not doing things that they are not supposed to do. BTW, one should consider not only kidnapping but just a "rogue" employee. For example, in the Snowden's case the NSA itself put too much trust into system administrators and did not perform audits that should have detected downloads of secure files.
Re: Google Security Team Member on NSA: "Fuck These Guys"
#239Earlier quoted context omitted.
You had enemies in the cold war. The USSR was much, much worse.
Things US did for Brazil: Sent aircraft carriers, ships and soldiers to help depose a democratically elected president, just because he wanted closer ties with China and wanted to do agrarian reform. Disappeared lots of people (I don't know any personally, because I am too young, but I DO know personally lots of people that still want disappeared people back) Spied on us (erm, that part still applies, no?). Sabotaged…
Re: Google Security Team Member on NSA: "Fuck These Guys"
#240Earlier quoted context omitted.
Ok but to agree with that argument is to agree that the NSA and organizations like it are necessary. I'm still waiting for the proof that they are. Everything I see points to them compromising countless people's privacy and having nothing to show for it.
But that's the core of the problem. By the nature of what they do, their successes are never clear. Not that this is a very robust intellectual defense, but the US is far from the only country to do this. Just two days ago the NYT had an article about Brazil spying on Americans within its borders: http://www.nytimes.com/2013/11/05/world/americas/brazil-ackn... If we shut down the NSA tomorrow we would be an an intern…
Look, my eyes are open. I'm spying on you. Everybody spies!