Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

301–310 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#301

Earlier quoted context omitted.

> And no other company with multiple data centers encrypts all traffic between them, right? Indeed they do! From personal experience, Cisco was hawking its TrustSec inter-DC encryption solution five or six years ago, even over dark fibre.

Google's inter-dc links are way too big for any appliance type of thing to encrypt. Like most things at Google the scale of their network is incomprehensible to most people.

> Google's inter-dc links are way too big for any appliance type of thing to encrypt

Frankly, no.

There are numerous network devices that can handle AES-256 on 10 Gbps links, as a matter of routine, whilst doing 'mundane' switching for the day job.

If you have the money there are dedicated hardware that can handle the same at 100 Gbps. IP Cores is one from memory that produces the circuitry for that. They can throw compression in there as well if you like.

Encrypting data links isn't magic. Google just didn't do it.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#302
post #3

I wondered about that traffic, and getting confirmation from the source that the only way the NSA could have it would be by tapping into the internal network is as quite damning. Google has the best OpSec team I've ever known, it is my hope that they close this 'loophole' as completely as possible.

If you're referring to the Orange team yes, they're pretty good.

Brandon Downey has proved time and time again that his incompetence gets in the way of protecting Google's network. Perhaps if he spent less time posting garbage on eng-misc and more doing his job we could have implemented security measures to prevent this way sooner.

Point your browser at go/privacyboost and search on Moma for Autobahn and the related CLs.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#303

Earlier quoted context omitted.

Except, they didn't explicitly mean to do that, stopped doing that, and paid for the autonomous collection of trash that they threw out.

How do you do that by accident? Somebody had to design, implement, and test a feature to sniff and store data off wireless networks.

As the story goes, the code [library] was written for another, past project at Google and a work in progress; the car project extended or implemented it without looking under the covers.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#305
post #43

Earlier quoted context omitted.

The other half of that equation is that the requirements for a security clearance tend to filter out the people who are mentally predisposed to question authority. It is a very rare person who can see all the things wrong with the various Wars on Dignity (drugs, terror, etc) and yet has a nose so clean as to qualify for a top secret clearance. It's kind of like the saying about walking a mile in someone else's shoes…

Just because someone can see what's wrong doesn't mean they do anything about it. Without that evidence of action, there's nothing for a background check to turn up. Getting a security clearance is not incredibly difficult.

Indeed, there are over 4 MILLION top secret holders. That's almost twice as many people as are in prison.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#306

Earlier quoted context omitted.

Google's inter-dc links are way too big for any appliance type of thing to encrypt. Like most things at Google the scale of their network is incomprehensible to most people.

> Google's inter-dc links are way too big for any appliance type of thing to encrypt Frankly, no. There are numerous network devices that can handle AES-256 on 10 Gbps links, as a matter of routine, whilst doing 'mundane' switching for the day job. If you have the money there are dedicated hardware that can handle the same at 100 Gbps. IP Cores is one from memory that produces the circuitry for that. They can throw c…

Those were very amusing tiny numbers you wrote in your post.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#307
post #290
post #3

I wondered about that traffic, and getting confirmation from the source that the only way the NSA could have it would be by tapping into the internal network is as quite damning. Google has the best OpSec team I've ever known, it is my hope that they close this 'loophole' as completely as possible.

Google, and their "geniuses" in opsec, should not be given a pass at all for this. Even if this is a leased private line, non-Internet routed, whatever, it is trivially easy to encrypt the communications and is absolutely a best practice. I see this as great big egg on their face. In fact, it's such a cock-up that one wonders if this is the plausibly deniable ingress that they agreed to provide for the NSA, et. al Th…

You are of course entitled to your opinion, I know Brandon and I know how dedicated he is, I got to watch him and the OpSec team in action during the Chinese incursion. One of the side effects of being in the platforms group was that I had exceptional access to what was going on everywhere on Google's internal network and machines. And a lot changed after that event, both internally and externally.

I can forgive someone for thinking that if they dug trenches in the street, bought some fiber, and ran it between a couple of buildings, in a country where the rule of law was in effect, they might consider it a reasonable assumption that the fiber is laying in the street unmolested. Even if the distance is such that they can't see the entire length of the ground above the conduit.

Prior to Snowden's disclosures, it was the common belief amongst the security community that in 'safe' countries, the government in power would not subvert your infrastructure through physical access. They might do some network tricks, but not tap your fiber. In 'bad' countries counter measures were taken. And the network setup in say Russia or China was different than it was in the US and the UK. That your own government would illegally subvert your infrastructure [1] through the use of a technicality was not considered a "likely" threat [2]. Given that not it has been exploited it is rewriting a bunch of assumptions. I am not surprised in the least that they are now deploying the same hardening they use in hostile environments world wide.

[1] The NSA cannot legally tap into communications infrastructure in the US (that is the FBI's job) and when the FBI does it they need a warrant. By doing this in the UK they sidestepped those constraints.

[2] In classic vulnerability analysis you deploy your resources against both the probability and damage potential of a given threat. So for example datacenters are vulnerable to being bombed by aircraft, the probability of that is low enough that you don't defend against it, bombed by cars you put a security perimeter around the building.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#308
post #290
post #3

I wondered about that traffic, and getting confirmation from the source that the only way the NSA could have it would be by tapping into the internal network is as quite damning. Google has the best OpSec team I've ever known, it is my hope that they close this 'loophole' as completely as possible.

Google, and their "geniuses" in opsec, should not be given a pass at all for this. Even if this is a leased private line, non-Internet routed, whatever, it is trivially easy to encrypt the communications and is absolutely a best practice. I see this as great big egg on their face. In fact, it's such a cock-up that one wonders if this is the plausibly deniable ingress that they agreed to provide for the NSA, et. al Th…

Please explain how you would "trivially" encrypt an optical line system that is capable of pushing 19TB down a single fiber (for example, http://www.advaoptical.com/en/products/technology/dwdm.aspx)

The only people who think this is "trivially easy" are people who don't have to do it.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#309
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

I'vw been thinking about this pretty hard this summer - I've been involved in some local tech activist stuff. My take on it is as runs: Fundamentally, what's needed here is the ability to have confidence that the intelligence system is not overstepping its bounds. The US founders' framework for building that confidence is to have multiple parts of power, whose interest is roughly aligned with countering each other. S…

It's wrong to portray this as a trade-off between more risk or less risk. In reality it's a trade-off between two kinds of risk. Without the NSA snooping there is a higher risk of terrorist attacks, but with the NSA snooping there is more risk of attacks on democracy. Imagine j. edgar hoover or richard nixon able to use all that NSA data for illegitimate purposes. How easy would it have been to supress dissenting political opinion? The NSA database is a time bomb of political abuse just waiting to explode. Its very existence is a threat to democracy.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#310

How does one "capture" data flowing over a private fiber channel? Does it require a physical tap?

Most likely, yes.

You can tap a fiber optic line without breaking it by bending it such a way that light leaks out: http://www.techrepublic.com/blog/it-security/protect-your-ne...

Post reply on HN