So how does this work when the CA's are less than reputable, Google has to comply with various homeland security acts, they didn't notice people tapping their fibre, have had numerous problems with their own staff and they have done evil before? Sounds like marketing fluff to me.
They have addressed and/or solved some of those issues: >So how does this work when the CA's are less than reputable Chrome has been using certificate pinning for Gmail for quite some time. Not sure what has been implemented in other browsers yet. >Google has to comply with various homeland security acts That's a legislative issue, and not something Google can fix. I would argue their track record on pushing for new…
Encrypted how? With what keys? There's still a single point of failure to capture a huge amount of GMail traffic and an aggressive adversary who has penetrated Google's networks before. Google could be saying this and still handling over the keys to the gov't. The key is increasing the cost of bulk surveillance. This doesn't help. The only acceptable solution is one where I encrypt my data with my own keys.
> That's a legislative issue, and not something Google can fix.
Yes, but technical architecture changes what it means for Google to comply. If all they have is my encrypted data, that's all they can hand over.