Live data from Hacker News

Staying at the forefront of email security and reliability

googleenterprise.blogspot.com

21–30 of 42 posts

Re: Staying at the forefront of email security and reliability

#21
post #4

Encryption is irrelevant when one party will give out the info for a price.

Google does not, nor have they ever, as far as I'm aware, sell personal user information to third parties. Google sells ads targeted at keywords and other interests, and while in an indirect way, this is profiting from user behavior, it is not the same as claiming they give out your personal info. Using third party hosted mail is a trade off, especially webmail. Unless you are using end-to-end encryption, intermediar…

>Google is taking steps to ensure all data is encrypted-at-rest

Are there any references or details regarding this?

Re: Staying at the forefront of email security and reliability

#23
post #17

Earlier quoted context omitted.

Google has long since implemented other measures to safeguard against internal bad actors.

So if Larry Page wants to read my email, he cannot? I somehow doubt that.

He has greater disincentives than anyone else, and 3rd party hosts have the ability to read your email no matter where you host it.

Re: Staying at the forefront of email security and reliability

#24
So how does this work when the CA's are less than reputable, Google has to comply with various homeland security acts, they didn't notice people tapping their fibre, have had numerous problems with their own staff and they have done evil before?

Sounds like marketing fluff to me.

Re: Staying at the forefront of email security and reliability

#25
post #4

Encryption is irrelevant when one party will give out the info for a price.

Google does not, nor have they ever, as far as I'm aware, sell personal user information to third parties. Google sells ads targeted at keywords and other interests, and while in an indirect way, this is profiting from user behavior, it is not the same as claiming they give out your personal info. Using third party hosted mail is a trade off, especially webmail. Unless you are using end-to-end encryption, intermediar…

For money, one could have Google provide ads to users who vote for specific party. After a few days, you look at the logs and create a database of people and their voting habits. Thus you will now have a database of personal information, created by the action of giving money to Google. When you pay money for a product, its called bought.

So I will call it bought personal user information, regardless if it has been laundered by advertisement clicks.

Re: Staying at the forefront of email security and reliability

#28
post #24

So how does this work when the CA's are less than reputable, Google has to comply with various homeland security acts, they didn't notice people tapping their fibre, have had numerous problems with their own staff and they have done evil before? Sounds like marketing fluff to me.

They have addressed and/or solved some of those issues:

>So how does this work when the CA's are less than reputable

Chrome has been using certificate pinning for Gmail for quite some time. Not sure what has been implemented in other browsers yet.

>Google has to comply with various homeland security acts

That's a legislative issue, and not something Google can fix. I would argue their track record on pushing for new legislation in that area is quite okay.

>they didn't notice people tapping their fibre

Traffic passing between their DCs is now being encrypted (well, it's been confirmed for Gmail.)

>have had numerous problems with their own staff

I can think of two cases from the top of my head. There's always going to be a small group of people who need full access to production data to do their job. All they can do is keep that group as small as possible and audit everything.

>they have done evil before?

please elaborate.

Re: Staying at the forefront of email security and reliability

#29
> In 2013, Gmail was available 99.978% of the time, which averages to less than two hours of disruption for a user for the entire year.

Does anyone understand why they use the term "averages" in this statement? What is being averaged? Isn't it just 0.022% * minutes in a year.

Re: Staying at the forefront of email security and reliability

#30
post #25

Earlier quoted context omitted.

Google does not, nor have they ever, as far as I'm aware, sell personal user information to third parties. Google sells ads targeted at keywords and other interests, and while in an indirect way, this is profiting from user behavior, it is not the same as claiming they give out your personal info. Using third party hosted mail is a trade off, especially webmail. Unless you are using end-to-end encryption, intermediar…

For money, one could have Google provide ads to users who vote for specific party. After a few days, you look at the logs and create a database of people and their voting habits. Thus you will now have a database of personal information, created by the action of giving money to Google. When you pay money for a product, its called bought. So I will call it bought personal user information, regardless if it has been la…

How is Google going to know what party you voted for, when votes are by secret ballot? Voter registration databases, which are public information available for a small fee from state governments, are far more likely to yield a profile of your voting behavior than your gmail contents.

Not only that, but anyone can opt-out of interest based ads for Gmail. Just go to Ad Settings (https://support.google.com/ads/answer/2662922?hl=en)

You have the choice of not seeing targeted and relevant ads, or of not using gmail at all. Try Fastmail for instance. I don't see the need to bash Google for doing the right thing on security.

Post reply on HN