Live data from Hacker News

Is Google overreaching by forcing me to use TLS?

security.stackexchange.com

1–10 of 37 posts

Re: Is Google overreaching by forcing me to use TLS?

#3
post #2

A comment on the answer perfectly encapsulates this post: Did you just troll security.SE and then reasonably answer your own question? – Stephen Touset

If you continue on reading you'll find OPs comment below it:

"@StephenTouset -- indeed. That's actually a feature; see Its OK to Ask and Answer Your Own Questions. As [it was] pointed out, the question was prompted by the computerworld article [1]."

[1] - http://blogs.computerworld.com/privacy/23698/google-customer...

Re: Is Google overreaching by forcing me to use TLS?

#4
post #2

A comment on the answer perfectly encapsulates this post: Did you just troll security.SE and then reasonably answer your own question? – Stephen Touset

I like that SO lets you answer your own questions, it makes good references for other people to link to. (And if you saw the background from this[1] blog post it makes sense to have made it).

[1] - http://blogs.computerworld.com/privacy/23698/google-customer...

Re: Is Google overreaching by forcing me to use TLS?

#5
I agree with the overall point of the responses that Google isn't in fact evil to be doing this, but I want to disagree somewhat with one point - the idea that Google doesn't have any obligation to respect users wishes just because its a free service that no one is forcing you to use.

The problem with this is that Google's very existence makes it harder for similar services to exist. There are a few reasons for this, including:

1. Google benefits from economies of scale

2. Google benefits from having massive amounts of data to crunch through (for example, its hard to build a span filter as good as Gmail's without a training dataset as big as Gmail's)

Its kind of like the argument for the minimum wage - conservatives would say its not needed because you can just choose not to work for a company that isn't offering enough money, but sometimes you don't really have an alternative.

Re: Is Google overreaching by forcing me to use TLS?

#7
post #5

I agree with the overall point of the responses that Google isn't in fact evil to be doing this, but I want to disagree somewhat with one point - the idea that Google doesn't have any obligation to respect users wishes just because its a free service that no one is forcing you to use. The problem with this is that Google's very existence makes it harder for similar services to exist. There are a few reasons for this,…

The argument has been made that Google's free products and services are anticompetitive dumping which makes it harder for a competing service to survive.

Re: Is Google overreaching by forcing me to use TLS?

#8
Google and others[Telecoms] are in positions to collect rents on your PI from third parties and G.O.'s. When they[Google] recently learned that the NSA had tapped their unencrypted fiber lines between data centers, they were pissed.

Not because they give a fraction of a shit about you, but because the NSA was stealing their product.

Now they encrypt everything with [very strong] SSL to force everyone to ask/pay for their info.

Re: Is Google overreaching by forcing me to use TLS?

#9

I suppose it's nice to have the rationale written out somewhere, but does anyone anywhere actually balk at being required to use HTTPS?

http://blogs.computerworld.com/privacy/23698/google-customer...

"Since when is removing consumer choice a good thing? Does Google really know better than you do what your security posture should be for your Gmail accounts?"

Yeah, what do those Google security engineers know, anyways?

Post reply on HN