Live data from Hacker News

Larry Page addresses PRISM

googleblog.blogspot.com

111–120 of 482 posts

Re: Larry Page addresses PRISM

#111
post #87

When I worked IT for a medium sized university we were asked by the DOJ to install switches that copied all internet traffic directly to an unspecified government server. We were told all ISPs (anyone providing internet to more than 100 persons) were told to do this as well. We refused to comply obviously as the request was absurd, but in the small print of the request we were told we were not allowed to speak of the…

You're not allowed to talk about NSLs, i recommend you change your post. Whats really bad about NSLs is they last forever, even a decade after receiving one you still can't talk about it without risking prosecution. NSLs issued in 2002 have no bearings on any active case yet we can't talk about them publicly. This makes it really hard to have a public debate on their usage.

Was not an NSL as that would be turning over data on a specific individual.

This was a request to install hardware to collect all data at any time.

Re: Larry Page addresses PRISM

#112
Wow, so many weasel words.

So what would satisfy me?

"We minimize intrusions into our users' privacy by encrypting their data on the client side with good crypto algorithms and secure keys that assuming a secure client system are under the full control of our users."

Followed by a list of types of data, and which types are or are not encrypted in this way.

That comes close. It's not exactly PR-speak, but captures the spirit I would hope for.

Google could at least try harder to be proactive about protecting privacy.

Re: Larry Page addresses PRISM

#113
post #63

I don't want any more fluff "no direct access" emails. I just want these questions to be answered with a YES/NO: 1. Is there any way that someone outside of Google, can get a copy of an email I sent from my gmail to my own gmail, without a warrant that specifies my exact gmail address? 2. If I delete my Google search history, is there any way for anyone to access this history, with or without a warrant? 3. If I make…

You don't need google to answer some of these.

2. If I delete my Google search history, is there any way for anyone to access this history, with or without a warrant?

I would think google has historical backups they could refer to to pull out data that you've recently deleted.

3. If I make a Google search from an incognito window, is there any way for Google to connect it to my Google account via my IP address? I know I've done this in the past to prevent spambots from creating fake accounts. Can Google connect these dots if someone sends them an NSL?

Why not? You should already assume that google and pretty much any site logs your IP whether you are using incognito or not. You should also assume that any time you log in to gmail your IP is noted. It's extremely basic to do a db search for all gmail accounts that have been accessed by a given IP.

Re: Larry Page addresses PRISM

#114

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

They can't say "we don't provide access", because depending on the law, they are forced to. They say "we do not provide direct access", because as explained, any access goes through proper legal channels. I'm not sure what you'd call it? Remember language matters, and these are actionable public communications.

[deleted]

Re: Larry Page addresses PRISM

#115
post #41

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

OK, in an alternate reality, what would a clear, flat-out denial look like? I mean, how could we tell such a thing differently than what was in the OP? First, we have not joined any program that would give the U.S. government—or any other government—direct access to our servers. Indeed, the U.S. government does not have direct access or a “back door” to the information stored in our data centers. We had not heard of…

"We would never do this, not because the government hasn't asked us to, but because it's morally abhorrent. It goes against everything we personally believe in and stand for. Even if we were legally required to cooperate, we would resist and suffer incarceration if necessary. We believe in freedom more strongly than we fear the consequences of not cooperating with an oppressive government."

That kind of thing.

Re: Larry Page addresses PRISM

#116
post #65

Earlier quoted context omitted.

He said nothing about Google, which is the topic of the OP.

In case you missed it, this is the program he acknowledged - Note the three Google products whose logos feature prominently in the leaked doc: http://www.guardian.co.uk/world/2013/jun/06/us-tech-giants-n...

I missed the pictures of the slides. That said, there are ways to target these services without involving the companies directly. Up to and including espionage itself.

Re: Larry Page addresses PRISM

#117

Earlier quoted context omitted.

It's not "direct" access, it's access through a one-way live xml feed

Please ... it will be binary format. Even the government isn't so wasteful to transmit data as xml. And if it did you could easily find where the servers were located by the 5 nuclear power plants needed to power such parsing.

HUR DUR XML IS BAD HUR DUR

Re: Larry Page addresses PRISM

#118
post #114

Earlier quoted context omitted.

They can't say "we don't provide access", because depending on the law, they are forced to. They say "we do not provide direct access", because as explained, any access goes through proper legal channels. I'm not sure what you'd call it? Remember language matters, and these are actionable public communications.

[deleted]

[deleted]

Re: Larry Page addresses PRISM

#119
If Google is forced to turn over data to the government, but precluded from discussing it due to national security laws then the denial really doesn't mean anything. Right?

Re: Larry Page addresses PRISM

#120
post #34

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records. We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. I'm not sure how much more strongly you'd like t…

The Verizon order explicitly applies to calls within America between American citizens, which is why it was so novel. PRISM, as described, only incidentally collects information about Americans. This statement does not preclude the direct access to user data that the PRISM reports describe.
Post reply on HN