Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

371–380 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#371

Earlier quoted context omitted.

China is a much more hostile state actor in how it would use any information it gathers up, especially to a free-enterprise company like Google.

That's quite a claim. Right now the NSA holds privileged information for millions of Americans. What happens if one of those people becomes some populist political entity. It would be trivial for the NSA to leak dirt of any kind (sexual fetishes, hangups, private emails to wife, other private things that when taken to the public would look bad, trash talking others, etc) to help discredit this person. Imagine that th…

They don't have a dog in that fight because you specifically chose the fight to make that true. If the same person ran on a different platform that argued for, say, boycotting or tariffing Chinese green energy products in order to build up local industries, the Chinese would care but the NSA would not.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#372
post #366
post #353

Earlier quoted context omitted.

This still puts you at greater risk of exposure than creating a Gmail account through an anonymizing proxy. I note that you've specifically gone to the most extreme case of the state looking to track you rather than some other private entity. The NSA/FBI looking at camera footage at the point of purchase for a cash card is just as likely as the NSA de-anonymizing your proxy (well probably less likely given what the N…

The industry moved to advertising because it works. When something more compelling comes along, people will move to that. So far it doesn't exist, but many people are trying. PayPal are not a monopoly, by the way. I would not be surprised to see them unseated from their current position in the next few years. I do have Ghostery installed. I'm glad it exists, and wish more people would use it so that they could see th…

The industry moved to advertising because it works.

That's really overly simplistic. It's a complex system and to assume that its the best system (as Mike Hearn stated) is to ignore the fact that there are competing interests at work and the ones who value privacy have significantly less clout than the ones that don't.

PayPal are not a monopoly, by the way.

That's just wordplay. Paypal has not faced significant competitive pressure for over a decade, if ever.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#373

Oh, the hypocrisy.... > "Bypassing that system is illegal for a good reason." Yes, so is invasion of privacy. Yet Google has no problem breaking the law and violating civil rights for profit. > "Unfortunately we live in a world where all too often, laws are for the little people." Yeah, like tax laws and privacy laws... If you want to get on this high horse, you shouldn't be working for Google.

I totally agree. And I was even more stumped by Eric Schmidt's hypocritical blathering. This from the guy, who blacklisted CNN for reporting on him based on information found on Google . http://money.cnn.com/2005/08/05/technology/google_cnet/

Wow, it's been a long time since CNN wrote news. I wonder if they've been coopted and the new owners are trying to piece them out by devaluing the brand.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#374
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

If HHS Feinstein bill passes, then it should be assumed to make all surveillance legal, thus any following of her personal actions: location, where-abouts, transactions, conversations etc are fair game. We should post cameras outside her Presidio Terrace San Francisco home watching every ingress/egress action by anyone visiting the place.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#375
post #290

Earlier quoted context omitted.

Google, and their "geniuses" in opsec, should not be given a pass at all for this. Even if this is a leased private line, non-Internet routed, whatever, it is trivially easy to encrypt the communications and is absolutely a best practice. I see this as great big egg on their face. In fact, it's such a cock-up that one wonders if this is the plausibly deniable ingress that they agreed to provide for the NSA, et. al Th…

You are of course entitled to your opinion, I know Brandon and I know how dedicated he is, I got to watch him and the OpSec team in action during the Chinese incursion. One of the side effects of being in the platforms group was that I had exceptional access to what was going on everywhere on Google's internal network and machines. And a lot changed after that event, both internally and externally. I can forgive some…

No, but they should take some precaution if someone unseemly (rogue employee, hacker, etc) has network access. You don't need a NSA level fiber taps under the ocean to do packet sniffing. Passing all of their service calls, database replications/connections, etc. in clear text over the wire is just plain lazy, bad security for an operation of their scale and (supposed) sophistication. I am sure it saved them some money on server/load balancers however.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#376
post #309

Earlier quoted context omitted.

I'vw been thinking about this pretty hard this summer - I've been involved in some local tech activist stuff. My take on it is as runs: Fundamentally, what's needed here is the ability to have confidence that the intelligence system is not overstepping its bounds. The US founders' framework for building that confidence is to have multiple parts of power, whose interest is roughly aligned with countering each other. S…

It's wrong to portray this as a trade-off between more risk or less risk. In reality it's a trade-off between two kinds of risk. Without the NSA snooping there is a higher risk of terrorist attacks, but with the NSA snooping there is more risk of attacks on democracy. Imagine j. edgar hoover or richard nixon able to use all that NSA data for illegitimate purposes. How easy would it have been to supress dissenting pol…

>Without the NSA snooping there is a higher risk of terrorist attacks, but with the NSA snooping there is more risk of attacks on democracy.

Bullshit! This is the exact thing we have been demanding proof of. There is none.

Not a single event has been proven to be thwarted by these activities.

Boston? Sandy hook? Aurora? Lax? Mall?

All actual attacks, he'll they took days to ID Boston guys and even then couldn't do a decent job in tracking locating them after they found them out!

The NSA is a criminal organization. Period. Tyre is no grey or legal area here. They need to be shut down.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#377
post #290

Earlier quoted context omitted.

Google, and their "geniuses" in opsec, should not be given a pass at all for this. Even if this is a leased private line, non-Internet routed, whatever, it is trivially easy to encrypt the communications and is absolutely a best practice. I see this as great big egg on their face. In fact, it's such a cock-up that one wonders if this is the plausibly deniable ingress that they agreed to provide for the NSA, et. al Th…

Tapping multi-mode dark fiber unnoticed is now considered trivially easy? I must have missed when the bar was shifted this high.

You don't need to tap dark fiber for this to be poor security. They were passing all internal data around in clear text. It would have been trivial for any data center employee to gain significant amounts of open data this way. Why wouldn't you have services, db connections, etc. encrypted internally? Its certainly possible and done within many companies, it is surprising how lax google was in their assumption that once inside the network everything is going to be a-ok.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#378
post #151

Earlier quoted context omitted.

Maybe there are some good programmers and engineers who agree with the NSA's goals and methods? There are some politicians, judges and journalists who agree with what they do - why should any other field be different? Plenty of good engineers work on weapons systems, despite the use those systems are put to. The fact the systems are also used for national defence is often used as self-justification. More directly: ma…

A few of my school friends worked for GCHQ and I questioned their reasons for doing so around ten years or so ago (a lot has changed in the world since then, but a lot hasn't). Back then there were three reasons beyond 'I need an income': 1) terrorists - someone has got to stop them blowing up innocent babies and children 2) kiddie porn - someone has got to take the war on paedophiles seriously 3) organised crime - w…

All these reasons for breaking network neutrality were discussed in congress and engineers spoke about how this undermines the foundation of the internet. So, a lot of good that does. There is no more regulation from the government unless it's protecting business. The government has failed time and time again, it's just another business at this point. This is why we can't have nuclear power, it would would be a boondoggle of lax safety and kickbacks.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#379
post #271
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

Leahy is the author of CALEA, a surveillance law that is one big reason we're in this situation to begin with. He introduced portions of the Patriot Act under the name EPPSCA a year before the Sep. 11 attacks ( http://thomas.loc.gov/cgi-bin/query/R?r106:FLD001:S58859 ). Leahy has sat on modest surveillance reform (requiring search warrants for email, cell phone location) for over three and a half years without advanc…

There is no technical solution that works when the federal government can seize/inspect/hack into any computer located in the United States or in friendly countries, as well as hack into computers anywhere in the world. They can then access the decryption private keys of anyone, and thus all encryption can be defeated, along with any other means of attempting to hide information from prying eyes. If Google itself is unable to protect its own network from NSA intrusion, what makes you think anyone else is able to?

Remember, the NSA is tasked with spying on Russian, Chinese, (and everybody else's) systems, and given that the Russians and Chinese have great mathematical and computing minds, is should be assumed that the NSA is employing equally great minds in the USA in order to penetrate the military (including nuclear and biological weapons systems), government, commercial, and individual systems of these foreign powers.

That the NSA turned the sophisticated looking glass inward to spy on the citizenry, in such an insecure manner, is the problem.

The other problem is that, well, citizens of the United States can be terrorists. If the NSA is tasked with stopping terrorism, then they, of necessity, need to monitor everyone, including US citizens.

So the answer lies in the terrorism part: Everyone went bonkers wondering why the government agencies were not able to stop the Boston bombers, yet when they do try to collect information and analyze it in a manner consistent with stopping this threat, they are then denounced as violators of the Constitution.

I have a sobering proposal: We tell the NSA to not worry about terrorism.

On the other hand, we come to terms with the notion that terrorists do what they do because it does terrorize us, and we make a conscious decision that we are going to not care anymore and accept a certain amount of casualties in exchange for the government not spying on us.

We accept that 30,000 Americans die on our roads each year in car accidents. We accept that another 30,000 Americans die of gun violence every year. Could we not accept that 30,000 Americans die of terrorism related incidents every year?

I lived in France in the 1980's. We had a lot of terrorism. Bombs in malls, bombs in restaurants, bombs in the street in front of synagogues. After a while, callous as this may seem, the French just stopped caring anymore. It had become routine. Then the terrorists stopped. There was no reason for them to keep doing this, because the French would just put it on page 4 of the paper, next to the political scandal section. The police would close the street, clean up, etc.

Yes, these were tragedies for the families, but not more than the tragedies for victims of gun violence, drug overdose, and horrible car accidents that mangled the bodies of children beyond recognition.

Taking away everyone's car is not the solution to car accidents. Taking away everyone's guns, swords, pick-axes, chainsaw, power drill, kitchen knives, and banning boxing, wrestling, and martial arts is not the solution to murder. Likewise, taking away everyone's freedom is not the solution to terrorism.

Because taking away everyone's freedom's been tried before, and the human spirit of freedom asserts itself, and people die on both sides as they rebel and attempt to overthrow the oppressors.

And that is why the NSA and other agencies that spy on Americans must be muzzled.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#380

Has it ever occurred to anyone that, just maybe, the whole NSA thing is a cover-up to distract the attention from the fact that it's actually the megacorporations that want to spy on you? This is a good way for Google, Microsoft, etc. to look innocent. Let's not forget that it was us who decided to trust these corporations with all our personal data.

This is absolutely true. DPI was used by corporations first. NSA et. al. have to use it to stay in the game. Of course, you'll never hear this because the multinational media decides who you root for.
Post reply on HN