Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

251–260 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#251
post #227

Earlier quoted context omitted.

Legal access to a document can't compel the owner of the document to hand over encryption keys. And if the existence of the document can be denied, you can't even prove it exists. This level of protection is within the reach of existing tools. Services like Google can make those tools accessible to the masses. The law has to observe physics. You can get a court order to "compel" someone to float off the ground, but t…

Sure, there are certain things that can be achieved by technological means. My point is that when it comes to certain areas of NSA activity, you're dealing with more than just simple legislative fixes. The specific example mentioned by Mike Hearn, the NSA tapping into international leased lines, is really illustrative. Our whole government is structured around the assumption that the executive branch is supreme when…

It is beyond even that. Even if you get legislation making illegal for the NSA to spy outside the US you also have to pass a law saying they can't receive data from the GHCQ who were the ones who tapped Google and Yahoo in Europe and then shared the data with the US.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#252

Earlier quoted context omitted.

Sure, there are certain things that can be achieved by technological means. My point is that when it comes to certain areas of NSA activity, you're dealing with more than just simple legislative fixes. The specific example mentioned by Mike Hearn, the NSA tapping into international leased lines, is really illustrative. Our whole government is structured around the assumption that the executive branch is supreme when…

And in doing so Congress would run up against separation of powers issues, because in our system, it's not really Congress's place to dictate to the President how he carries out foreign security activities. I agree with you completely, but when the political will is there, Congress can dive head first into separation of powers fights. Look at the War Powers Resolution. It's almost certainly unconstitutional in a stri…

Those are both excellent points. A treaty would be a good idea, but first we need a President willing to negotiate such a treaty.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#253
post #169
post #12

Earlier quoted context omitted.

Why do people assume the Chinese government is not able to use similar techniques?

Why on Earth are you comparing a suppressive regime to the a western democracy? Of course the Chinese gov is able to do so without any repercussions. The difference should be that in a democracy you can't abuse your power without repercussions.

Maybe it "should" but democracy and domestic popular opinion doesn't traditionally have a significant impact on US foreign policy. Except for big wars.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#254
post #73

Earlier quoted context omitted.

The point being made isn't that they would send sensitive data using gmail, it's that if they were compromised the NSA would most likely be reading the emails, and hacking Google would theoretically let the Chinese know if cover was blown if they could see evidence of the NSA listening in. Of course, that means the joke's on them, because the NSA was listening to everyone...

how would you know whether NSA was listening in (for example by tapping google's links between datacenters) or not even if you successfully hack into Google's infrastructure? Not finding evidence of eavesdropping doesn't exclude that eavesdropping happened, so if that was the only purpose to hack Google, it doesn't seem worth the effort. On the other hand if you want to read people's mail, then hacking into the provi…

I'm not sure I necessarily buy that explanation either, but I don't know enough of the facts of this particular story to know where it falls down or is supported.

On the other hand, we don't really know what the Chinese knew, or thought they knew, about Google and how it functioned WRT government surveillance. If they had reason to believe that Google would be cooperating with authorities and would have infrastructure in place to monitor email accounts that they could look for and identify if it was monitoring the accounts they were looking for, then this explanation makes a bit more sense.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#255
post #223

Earlier quoted context omitted.

Ok but to agree with that argument is to agree that the NSA and organizations like it are necessary. I'm still waiting for the proof that they are. Everything I see points to them compromising countless people's privacy and having nothing to show for it.

But that's the core of the problem. By the nature of what they do, their successes are never clear. Not that this is a very robust intellectual defense, but the US is far from the only country to do this. Just two days ago the NYT had an article about Brazil spying on Americans within its borders: http://www.nytimes.com/2013/11/05/world/americas/brazil-ackn... If we shut down the NSA tomorrow we would be an an intern…

I understand the line "By the nature of what they do, their successes are never clear." but I would think that will all of the bad "publicity" the NSA is receiving they would at least pull one example out where they prevented an attack. They have only release vague numbers on the number of incidents prevented and when put under a microscope they weren't a very big part of the plots they claimed to have foiled. I understand the "international disadvantage" but I don't think we can allow everything the NSA does with "Everyone else is doing it" defence.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#256

It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.

I wonder why people aren't using calling the current unpleaseantness attacks (or war).

Re: Google Security Team Member on NSA: "Fuck These Guys"

#257
Global security sure is easy if you're an engineer working for a large tech company. I say that with as much sarcasm as possible.

Day after day I see post after post around the tech web about how horrible the actions are of the NSA but few if any propose a workable solution to balancing both securing and obscuring actions taken to protect a nation, with the public's need for privacy and protection from abuse.

Oversight, oversight, oversight is all we hear yet nothing concrete to describe how the US (or any nation) is supposed to provide security and keep the enemy from monitoring the techniques and actions taken by intelligence services.

Maybe I'm naive but I don't see a way to keep spying (something all nations do and have done for centuries) with the public's need for complete disclosure.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#258
post #240
post #223

Earlier quoted context omitted.

But that's the core of the problem. By the nature of what they do, their successes are never clear. Not that this is a very robust intellectual defense, but the US is far from the only country to do this. Just two days ago the NYT had an article about Brazil spying on Americans within its borders: http://www.nytimes.com/2013/11/05/world/americas/brazil-ackn... If we shut down the NSA tomorrow we would be an an intern…

Can we please try not to equate a diplomat's car being followed around a city's public areas with the indiscriminate collection of private communications from every man, woman and child on the planet? Look, my eyes are open. I'm spying on you. Everybody spies!

can we please try not to equate reality with "indiscriminate collection of private communications from every man, woman and child on the planet"

Re: Google Security Team Member on NSA: "Fuck These Guys"

#259
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

Legislative fixes aren't going to buy you a lot, though they'll buy you something. The fundamental problem is structural: there are a lot of things the NSA is totally allowed to do, especially when it acts as an agency of the executive outside of the U.S. Technologists tend to ignore national and jurisdictional borders because networks cross those borders, but the powers of the NSA are defined in terms of those borde…

U.S. law follows U.S. citizens around the world. For example if a U.S. citizen rob a bank in the U.S. and then flees to the UK, when the UK police catch him, he will be extradited and prosecuted in a U.S. court. He's not stuck into a UK jail without a trial.

That's the minimum issue here--Google ships the data of U.S. citizens around the world, and the NSA knows it. They are trying to play a cute game by pretending to assume that if the GCHQ collects the data in the UK, the NSA can safely treat it as foreign data. We need to call them on it.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#260
post #196

Earlier quoted context omitted.

Who do you think the lobbyists are? Them is us.

No, them is some of us. Example: I used to work for BigCorp. BigCorp had a PAC to which they would gently encourage employees contribute. They ran an annual contribution campaign, sent emails, made phone calls, etc. It was not mandatory, just encouraged . Many employees did so. The PAC in turn contributed to any politician who supported BigCorp. So the net result is a bunch of people who ended up contributing to poli…

OK to clear up some muddy thinking here, there's lobbying and then there's campaign finance.

Lobbyists are unregulated employees or contractors, whose budget is only limited by the largesse of the sponsor. Its goal is to affect legislation and regulation through swaying the votes and actions of elected officials, political appointees and to a lesser extent career bureaucrats. In this regard they are limited by anti-corruption and bribery laws.

Campaign finance is a highly regulated system through which politicians amass money to fund campaign to sway the votes of the public. PACs and other organizations channel money to candidates whom they believe will be sympathetic to their causes.

Regardless, forget about the PAC money and the campaign finance. I assume BigCorp has lobbyists, and those lobbyists look out for BigCorps interests. As an employee of Big Corp, you are a beneficiary of those lobbyists.

Post reply on HN