Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

281–290 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#281

Earlier quoted context omitted.

U.S. law does follow U.S. citizens around the world, but only in certain circumstances does it apply to conduct abroad. For example, there is a law against U.S. citizens engaging in underage sex tourism abroad. But such laws are the exception. If you, e.g., murder someone in England, the U.S. can't hold you accountable under American law. Your example is a bad one, because in your example the law is broken by conduct…

The conduct in this case is not the fiber tapping, but the possession and use of U.S. citizen data by the NSA. It does not matter how they gather it, their restrictions are the same--they must limit and justify it.

The Google+ comment objects to the fiber tapping. It doesn't say anything about the use of U.S. citizen data, and the NSA asserts it has safeguards in place to filter out such data from foreign taps.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#282
post #52

Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. Basically, this is security 101: protect data at rest and protect data in flight. So, sorry but I think the better subject for discussion would be how badly Google screwed up, not how evil is NSA. M…

I wrote my thoughts on the subject in a blog post as well:

http://www.aleksey.com/2013/11/06/why-google-engineers-got-i...

Re: Google Security Team Member on NSA: "Fuck These Guys"

#283
"Unfortunately we live in a world where all too often, laws are for the little people."

This is sort of the crux of it. We are degenerating into a true oligarchy and/or gangster state in which there are two different systems of law: one for the politically connected and one for the plebs.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#284

Earlier quoted context omitted.

Like indiscriminately and illegally sucking up WiFi data with their street view mobiles? Including account information and passwords on unsecured WiFi connections. Even if the accusation of "violating laws" may be a tad hyperbolic in the great scheme of things it's not a stretch to deem Google one of the most hypocritical companies around.

Except, they didn't explicitly mean to do that, stopped doing that, and paid for the autonomous collection of trash that they threw out.

How do you do that by accident? Somebody had to design, implement, and test a feature to sniff and store data off wireless networks.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#285
post #3

I wondered about that traffic, and getting confirmation from the source that the only way the NSA could have it would be by tapping into the internal network is as quite damning. Google has the best OpSec team I've ever known, it is my hope that they close this 'loophole' as completely as possible.

We still don't know if that was really a loophole or rather access given by Google (of course, they will decline that).

My personal opinion is that it's more likely that the access was given by a telecom that Google leased from than from Google itself.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#286
post #136

Earlier quoted context omitted.

> And no other company with multiple data centers encrypts all traffic between them, right? Indeed they do! From personal experience, Cisco was hawking its TrustSec inter-DC encryption solution five or six years ago, even over dark fibre.

If you believe the threat is a government agency splicing private, unshared fiber to capture your traffic between data centers, why in the world would you trust equipment from Cisco (who lists "Government" as one of the industries they sell to) to protect you from that?

Well I certainly understand your point, but the question was 'are big companies encrypting their inter-DC traffic' and the answer is 'yes', even if it's backdoored without their knowledge.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#288
post #86

Earlier quoted context omitted.

Erm, what? Which law did they break, and which civil rights did they violate?

Like indiscriminately and illegally sucking up WiFi data with their street view mobiles? Including account information and passwords on unsecured WiFi connections. Even if the accusation of "violating laws" may be a tad hyperbolic in the great scheme of things it's not a stretch to deem Google one of the most hypocritical companies around.

Who in their right mind broadcasts account information and passwords unencrypted and expects it to not be recorded? That would be akin to using a megaphone and yelling your credit card numbers and expecting your neighbours to pretend they didn't hear you.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#289

Earlier quoted context omitted.

There is no such thing as perfect security, only good enough security. At some point you have to accept risks, and the risk of physical network attacks is incredibly small compared to all the other attack vectors. Nobody was well prepared for the NSA's physical network attacks.

Everybody who cared knew that the world's governments tap every fiber they can lay their hands on. It has been discussed on HN with great regularity for years before these NSA non-revelations. Physical attacks were and are a certainty. Anybody who ignores this fact has only themselves to blame. A good argument can even be made that they deserved to be pwned as punishment for their utter fecklessness.

No, what was discussed was the NSA tapping in at ISP points, not digging up cables to splice them.

And "discussed" is not accurate. It was proposed by a few but rejected by most as paranoid.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#290
post #3

I wondered about that traffic, and getting confirmation from the source that the only way the NSA could have it would be by tapping into the internal network is as quite damning. Google has the best OpSec team I've ever known, it is my hope that they close this 'loophole' as completely as possible.

Google, and their "geniuses" in opsec, should not be given a pass at all for this.

Even if this is a leased private line, non-Internet routed, whatever, it is trivially easy to encrypt the communications and is absolutely a best practice. I see this as great big egg on their face.

In fact, it's such a cock-up that one wonders if this is the plausibly deniable ingress that they agreed to provide for the NSA, et. al

This is akin to using telnet to access your home server because you're "on your own network". Nobody does that and I can't believe they would have either.

Post reply on HN