Live data from Hacker News

Is Google overreaching by forcing me to use TLS?

security.stackexchange.com

11–20 of 37 posts

Re: Is Google overreaching by forcing me to use TLS?

#11

Google and others[Telecoms] are in positions to collect rents on your PI from third parties and G.O.'s. When they[Google] recently learned that the NSA had tapped their unencrypted fiber lines between data centers, they were pissed. Not because they give a fraction of a shit about you, but because the NSA was stealing their product. Now they encrypt everything with [very strong] SSL to force everyone to ask/pay for t…

I don't think we know what the relationship between Google and the NSA actually is. I will say that I operate under the assumption that Google gives the NSA whatever they ask for up to and including access to raw streams of information.

I agree with the decision to require TLS, but I don't know that it does a lot with regard to the NSA, and moreover, I don't trust them anymore not to turn over information in bulk.

Re: Is Google overreaching by forcing me to use TLS?

#13

I suppose it's nice to have the rationale written out somewhere, but does anyone anywhere actually balk at being required to use HTTPS?

http://blogs.computerworld.com/privacy/23698/google-customer... "Since when is removing consumer choice a good thing? Does Google really know better than you do what your security posture should be for your Gmail accounts?" Yeah, what do those Google security engineers know, anyways?

I'm actually more intrigued by this part

    "an encryption methodology that I suspect the NSA can probably defeat anyway."
If the premise is "I don't need security, because the most powerful intelligence agency in the world can break it anyways", then why not go ahead and give us the PIN for your debit card anyway.

Re: Is Google overreaching by forcing me to use TLS?

#14

Google and others[Telecoms] are in positions to collect rents on your PI from third parties and G.O.'s. When they[Google] recently learned that the NSA had tapped their unencrypted fiber lines between data centers, they were pissed. Not because they give a fraction of a shit about you, but because the NSA was stealing their product. Now they encrypt everything with [very strong] SSL to force everyone to ask/pay for t…

You should call up Google and tell them you'd like to buy my personal data, and you'd like to get a price quote.

If you don't think that would work, then perhaps your comment needs to be revised. If it's not an open market, then which third parties do you think Google is selling user data to?

Re: Is Google overreaching by forcing me to use TLS?

#16
post #12

Uh, did this guy answer his own post?

You're encouraged to do that. I wonder why it seems to upset so many people? (I'm honestly curious, I'm not trying to be snarky)

My main objection to it is that since the OP is almost certainly going to accept their own answer before other people can post, there may be other, better answers that arrive late and don't get as much attention.

Re: Is Google overreaching by forcing me to use TLS?

#17
Can anyone explain this line from commenter Darren Cook: "Once this enforcement is in place, browsers will simply refuse to connect to Google over an insecure or compromised connection. By shipping this setting in the browser itself, circumvention will become effectively impossible."

Some browsers are open source, and it seems to me that developers can never definitely rely on their behavior. Surely the enforcement depends ultimately not on the browsers but rather on the server refusing non-TLS connection attempts?

Re: Is Google overreaching by forcing me to use TLS?

#18

Earlier quoted context omitted.

You're encouraged to do that. I wonder why it seems to upset so many people? (I'm honestly curious, I'm not trying to be snarky)

My main objection to it is that since the OP is almost certainly going to accept their own answer before other people can post, there may be other, better answers that arrive late and don't get as much attention.

The moderation system largely mitigates that problem.

Also, the SO/SE people have long maintained that Google is their homepage, and from this view it's easy to see why they would encourage people to answer their own questions: so that SO gets the googlejuice instead of some blog.

On the other hand, to the degree that we believe that individual blogs are good, we absolutely should worry about auto-answering.

Re: Is Google overreaching by forcing me to use TLS?

#19
post #17

Can anyone explain this line from commenter Darren Cook: "Once this enforcement is in place, browsers will simply refuse to connect to Google over an insecure or compromised connection. By shipping this setting in the browser itself, circumvention will become effectively impossible." Some browsers are open source, and it seems to me that developers can never definitely rely on their behavior. Surely the enforcement d…

You can patch the browser to disable HSTS, but if you allow patching the browser to break the security intentionally, then all bets are off I'd say?

Surely the enforcement depends ultimately not on the browsers but rather on the server refusing non-TLS connection attempts?

No, HSTS capable browsers (Firefox and Chrome) will flatly refuse to connect if HSTS is in action. That's the whole idea and the defense against SSLstrip.

Re: Is Google overreaching by forcing me to use TLS?

#20
post #5

I agree with the overall point of the responses that Google isn't in fact evil to be doing this, but I want to disagree somewhat with one point - the idea that Google doesn't have any obligation to respect users wishes just because its a free service that no one is forcing you to use. The problem with this is that Google's very existence makes it harder for similar services to exist. There are a few reasons for this,…

The argument has been made that Google's free products and services are anticompetitive dumping which makes it harder for a competing service to survive.

Only if your privacy is worthless.
Post reply on HN