Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

381–390 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#381
post #336
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

You'll need to change the us constitution so that us foreigners are covered by the 4th amendment ban on warentless searches.

As a dual citizen (US, and French) am I protected by the 4th amendment, or not?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#382

Earlier quoted context omitted.

Everybody who cared knew that the world's governments tap every fiber they can lay their hands on. It has been discussed on HN with great regularity for years before these NSA non-revelations. Physical attacks were and are a certainty. Anybody who ignores this fact has only themselves to blame. A good argument can even be made that they deserved to be pwned as punishment for their utter fecklessness.

No, what was discussed was the NSA tapping in at ISP points, not digging up cables to splice them. And "discussed" is not accurate. It was proposed by a few but rejected by most as paranoid.

Wait a minute... "It was proposed by a few but rejected by most as paranoid." and yet is most likely what happened? so the most in "rejected by most" were wrong. Wrong!

So when someone says: "You're just being paranoid", my reply will be: "Better paranoid than wrong."

Re: Google Security Team Member on NSA: "Fuck These Guys"

#384

Earlier quoted context omitted.

There is no such thing as perfect security, only good enough security. At some point you have to accept risks, and the risk of physical network attacks is incredibly small compared to all the other attack vectors. Nobody was well prepared for the NSA's physical network attacks.

Everybody who cared knew that the world's governments tap every fiber they can lay their hands on. It has been discussed on HN with great regularity for years before these NSA non-revelations. Physical attacks were and are a certainty. Anybody who ignores this fact has only themselves to blame. A good argument can even be made that they deserved to be pwned as punishment for their utter fecklessness.

[deleted]

Re: Google Security Team Member on NSA: "Fuck These Guys"

#385
post #309

Earlier quoted context omitted.

It's wrong to portray this as a trade-off between more risk or less risk. In reality it's a trade-off between two kinds of risk. Without the NSA snooping there is a higher risk of terrorist attacks, but with the NSA snooping there is more risk of attacks on democracy. Imagine j. edgar hoover or richard nixon able to use all that NSA data for illegitimate purposes. How easy would it have been to supress dissenting pol…

> Without the NSA snooping there is a higher risk of terrorist attacks, but with the NSA snooping there is more risk of attacks on democracy. Bullshit! This is the exact thing we have been demanding proof of. There is none. Not a single event has been proven to be thwarted by these activities. Boston? Sandy hook? Aurora? Lax? Mall? All actual attacks, he'll they took days to ID Boston guys and even then couldn't do a…

Don't understand why you list unthwarted attacks. The real question is how many attacks were thwarted. That is the point of disagreement.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#386
post #363

Earlier quoted context omitted.

In the context of the comment he was replying to, and the allusion to "cultural differences" it doesn't seem to be just about technical proficiency. Otherwise, the second the part of his reply is meaningless, and the entire comment seems out of context.

Living in a country where wars with immediate neighbors and rocket attacks are frequent over 10 year time spans, especially in one much smaller and more culturally diverse than the US (at least among relatively antagonistic cultures), sounds like enough of a "cultural difference" to give some engineers a more "us or them" lens on morality and drive them to passionately work on defense driven technologies. Combine tha…

[deleted]

Re: Google Security Team Member on NSA: "Fuck These Guys"

#387

Earlier quoted context omitted.

Yes. It's fixable the moment the public realizes that it is within their power to fix.

How? Voting and protesting haven't worked so far.

Who are you, Wile E. Coyote? Just because something hasn't worked "so far" doesn't mean it needs to be abandoned. There are a shit ton of problems in our world and with our political system right now. But that's the historical norm. Even in the "good times" it's the historical norm.

Today there are so many people who have this weird belief that somehow the lack of change due to their extreme apathy is a justification for that apathy. It's not. If more people spent the time to educate themselves deeply on issues and candidates. If more people spent the effort to have legitimately worthwhile political discussions instead of merely agreeing with those who already agree with them and shouting down those who don't. If more people decided to take the risk and enter politics. Things would be a whole lot different.

Today the biggest problem isn't entrenched power structures, or gobs of money in political campaigns, or the lack of good candidates. All of those are symptoms. The biggest problem is that the primary ways that people learn about and discuss political issues are horribly broken. Most major news media outlets are horrid, only a few steps away from outright tabloid journalism. People decry fox news all the time but CNN and even the New York Times are, on the whole, little better, just different flavored output from fundamentally the same machinery. And people don't tend to realize this because every once in a while there will be something of legitimate quality that leaks through, and that event will serve as a rationalization for continuing to feed from those sources of information. These are precisely the same processes that keep people attached to religious institutions as well.

Ask yourself, how much effort do you, personally, put into researching political issues and candidates? What about your friends? Do you hold them to account for being low information voters? Do you ever have serious, non-shouting, political discussions with people who have different views than your own?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#388
post #82

Earlier quoted context omitted.

I work for a company bigger than Google, and we encrypt everything in flight between datacenters. It is security 101.

Does your company have dedicated, unshared, fibre between those datacenters?

Yes we do. Still use encryption.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#389
post #320

Earlier quoted context omitted.

Google's inter-dc links are way too big for any appliance type of thing to encrypt. Like most things at Google the scale of their network is incomprehensible to most people.

In addition to the numbers already posted, you can remember that Google decided to add encryption to the data links in September.

This is not true. Quoting from http://www.washingtonpost.com/business/technology/google-enc...

"Google’s encryption initiative, initially approved last year, was accelerated in June as the tech giant struggled to guard its reputation as a reliable steward of user information amid controversy about the NSA’s PRISM program,"

Re: Google Security Team Member on NSA: "Fuck These Guys"

#390
post #355

Earlier quoted context omitted.

Except you know, in that case the person actually did have classified documents of an allied nation on a thumbdrive on them. Which you know - is still illegal to have. Though it's funny how the Guardian thoroughly underreported that fact.

When I last checked, in the US, it's actually not illegal for someone without a clearance to possess classified material. This is why newspapers can print unredacted classified documents and not immediately go to jail. It is , however illegal for someone with a clearance to mishandle classified material. "Mishandling" includes "Permitting access to classified material to non-cleared personnel.". If you mishandle clas…

It's also illegal to traffic it across international borders, which is why what foreign spies do is prosecutable. Which is the exact thing they were doing.
Post reply on HN