Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

131–140 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#131
post #72
post #70

Earlier quoted context omitted.

It's a good thing secret courts can, then.

The actual filings before FISA are secret; they're signals intelligence cases. The laws the FISA court uses to authorize surveillance are not secret.

The laws the FISA court uses to authorize surveillance are not secret.

Well, so far as we know anyway. There is still, AFAIK, an open question about the existence and/or exact nature of "secret laws" in the US. See John Gilmore's struggle to travel without offering up identity documents[1], for example.

[1]: http://en.wikipedia.org/wiki/Gilmore_v._Gonzales

Re: Asking the U.S. to allow Google to publish more national security request data

#133
post #126
post #69

Earlier quoted context omitted.

My point is that Google Mail is an insecure setting from which to deliver PGP.

For heaven's sake: there's a compromise to be reached between sending postcards and using a Brink's truck.

No, there isn't. Protecting secrets cryptographically is an engineering problem. There are right answers and wrong answers, and having Google Mail deliver PGP to you directly is a wrong answer.

Re: Asking the U.S. to allow Google to publish more national security request data

#134
post #62

Earlier quoted context omitted.

It could really damage the long term viability of the __US__ tech industry dealing irreparable damage to one of the major assets of the US economy has. I would expect companies that need a strong international security reputation to begin closing up shop and moving away. The NSA just killed the goose that lays the golden egg and not much is going change that.

I disagree that this is a problem limited to US companies. With the global nature of the tech industry, I think a product's or service's country of origin has seen a reduced importance over the years. I don't think the average consumer knows that Waze is based in Israel. I don't foresee anyone considering the NSA and choosing a Canadian designed Blackberry phone over a US designed Apple one. Instead I think this will…

Agreed - the Netherlands is terrible, for instance. http://www.thehollandbureau.com/2010/03/07/the-netherlands-c...

Re: Asking the U.S. to allow Google to publish more national security request data

#135
post #19
post #11

Earlier quoted context omitted.

So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.

1. Google probably should offer passive S/MIME on mail. START TLS goes a long way, but providing the same signals about message authenticity to people who IMAP from gmail as who use the web UI would be nice. A non-google-trusting way to do PGP with a better UI/UX would also be a nice feature for gmail. Just indicating "encrypted" at the message-list view or something. I have PGP working quite nicely in mutt, but a lo…

STARTTLS is supported on both IMAP/SMTP. Email from Google outgoing uses TLS encryption (at least to my mail server), email from my server to Google also uses TLS encryption.

IMAP is already TLS encrypted.

The biggest missing puzzle piece is making it simpler for people to get S/MIME set up (or PGP for that matter), and having it work with all major mail clients (yes, Mail.app is a major mail client).

Right now S/MIME still requires too many steps to get the lay person to set it up, same with PGP, we need something that is secure from the get-go with very minimal effort required on the users part.

The downside is that S/MIME and PGP don't really fit into the online world, no longer will it be simple to open the browser and go look at your email, you will be required to have your keys with you. Securing those keys becomes the second problem, one that has partially been solved with smart cards and other devices that will do signing/encrypting/decrypting on the card without giving up the private key... but loss is still an issue so key escrow becomes a big thing.

It is an interesting problem, with interesting challenges and I look forward to seeing how we as a group of technologists solve them. Once it becomes easy enough for grandma and grandpa to use secure encrypted communication it will become much harder to do wide-scale snooping on data.

Re: Asking the U.S. to allow Google to publish more national security request data

#136

Earlier quoted context omitted.

In order for this to be an option, it would have to mean that all of the internal security and audit controls at Google were bullshit, wouldn't it?

Security and audit controls are almost always bullshit. We're discussing a story that arose because a three-month tenure employee for an external contractor had wide ranging access to tonnes of stuff in the NSA . Previously Bradley Manning demonstrate the same with the armed forces. Are all internal Google communications encrypted? Probably not, but even if they are if you work in network security you likely hold the…

You are seriously confused on both points.

Re: Asking the U.S. to allow Google to publish more national security request data

#137

Earlier quoted context omitted.

Security and audit controls are almost always bullshit. We're discussing a story that arose because a three-month tenure employee for an external contractor had wide ranging access to tonnes of stuff in the NSA . Previously Bradley Manning demonstrate the same with the armed forces. Are all internal Google communications encrypted? Probably not, but even if they are if you work in network security you likely hold the…

You are seriously confused on both points.

What a convincing retort.

Re: Asking the U.S. to allow Google to publish more national security request data

#138

What are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the…

Disclaimer: I work at Google. I'm working on the client-side (Chrome) and my knowledge in the server area is therefore limited, but from my understanding this would be really hard. 1. Googlers have access to almost all source code. It would be difficult to hide code that just sends data to an outside entity. 2. Google continually monitors its (internal) bandwidth. This is done to optimize traffic, and detect intruder…

I see a big potential benefit for the NSA to have a spy within google who simply manually pulls and relays info on people at th nsa's request... It doesn't have to be a full Api

Re: Asking the U.S. to allow Google to publish more national security request data

#139
Googles lost my trust. To my newly discovered emabarassment I naively and passionately defended them amongst my friends for several years. Seems like if a company gets big enough it's ethical demise is a certain inevitability (yes, I'm a little late to the party). What a pathetic untrustworthy world I find myself now living in.

Re: Asking the U.S. to allow Google to publish more national security request data

#140
post #19

Earlier quoted context omitted.

1. Google probably should offer passive S/MIME on mail. START TLS goes a long way, but providing the same signals about message authenticity to people who IMAP from gmail as who use the web UI would be nice. A non-google-trusting way to do PGP with a better UI/UX would also be a nice feature for gmail. Just indicating "encrypted" at the message-list view or something. I have PGP working quite nicely in mutt, but a lo…

STARTTLS is supported on both IMAP/SMTP. Email from Google outgoing uses TLS encryption (at least to my mail server), email from my server to Google also uses TLS encryption. IMAP is already TLS encrypted. The biggest missing puzzle piece is making it simpler for people to get S/MIME set up (or PGP for that matter), and having it work with all major mail clients (yes, Mail.app is a major mail client). Right now S/MIM…

The lowest hanging fruit is probably a simple way to get S/MIME certs for mail.app (osx/ios). There isn't really an easy way to get a cert right now as an individual. A "real" cert is around $20-30 from top companies, and maybe $5-10 for others. Obviously someone could do their own for free.
Post reply on HN