Live data from Hacker News

Google encrypts data amid backlash against NSA spying

washingtonpost.com

131–140 of 153 posts

Re: Google encrypts data amid backlash against NSA spying

#131

Earlier quoted context omitted.

The revelations that NSA is running a HUMINT program should make it very clear that you can't trust everyone at Google or any other major provider. Those risks are mitigable, but it's expensive and I doubt most places take sufficient steps to prevent it. Even without that, trusting companies because their employees are honest is hard. There are some people at the NSA who really really care about privacy and not spyin…

True, yet I imagine it shouldn't be difficult to signal out those employees that present the greatest HUMINT risk and apply extra scrutiny. Any employee that have any sort of top secret clearance, that has worked for intelligence agencies or contractors and the worked in the military, but not out in the field is potentially a mole. I'd find it hard to believe that there are people that don't fit that profile but are…

People come to Google from all paths of life. For all you know, some 20-something long-haired unix hotshot could have been busted for drugs at some point and "repurposed" as a mole in exchange for leniency. And there's always the classic sex honeytrap for married men, which will never go out of fashion.

Real spooks don't carry a conscience, they'll exploit anything they can to get their grubby hands on the data they need.

Re: Google encrypts data amid backlash against NSA spying

#132

Earlier quoted context omitted.

I'm so bored of hearing the accusations of PR stunts. They crop up in every submission detailing an action taken by Google with regards to the Snowden/Prism/NSA revelations. Is it so ridiculous that a large corporation should seek to ameliorate its image in the eyes of users and shareholders? PR has become such a dirty word. Of course it would be best if all these actions were taken earlier, purely as the result of a…

When Google does something that makes it impossible for them to hand over certain types of data to the NSA, either by not collecting it, or making it so that only the user is able to decrypt it, wake me up. Until then, it's a PR stunt.

IMAP/POP3 has always been a gmail option, which allows local PGP use. Chrome sync allows you to set your own encryption passphrase (provided you trust the binary doing the encrypting...). You've been able to share encrypted files on google docs/drive since they added arbitrary file storage. Etc.

Chrome sync is probably the strongest example that I can think of fitting your criteria, since it's built into the product itself, but a lot of this just comes with the territory of web-based apps.

Re: Google encrypts data amid backlash against NSA spying

#133

I think it's too late. Google has shown that it can't be trusted, especially about privacy.

What do you mean? Care to share more details? AFAICT, Google has been completely transparent about giving users control about how their data is shared. It's been ahead of the pack in protecting its users rights even going to courts to protect users. Disclaimer:I am an Engineer@Google.

Can you provide some insights why the connections between Google's data centers was NOT encrypted until now?

Re: Google encrypts data amid backlash against NSA spying

#134
post #19

Earlier quoted context omitted.

Or so they say. I'm not convinced that this is not Google's version of "trust us". Keep in mind there is no PR loss for Google to adopt a pro-encryption stance now. If they are really serious about this, they would a) stop trawling emails and b) help develop tech for seamlessly encrypting both in-flight and at-rest email.

Meanwhile, Google Argues for Right to Continue Scanning Gmail "This company reads, on a daily basis, every email that's submitted, and when I say read, I mean looking at every word to determine meaning," said Texas attorney Sean Rommel, who is co-counsel suing Google. http://abcnews.go.com/Technology/wireStory/google-argues-con... http://www.mercurynews.com/business/ci_24021944/google-argue...

"Determine meaning?" I'm pretty sure there's no computer software in existence at this point that can read human text and "determine meaning"

Re: Google encrypts data amid backlash against NSA spying

#135
post #131

Earlier quoted context omitted.

True, yet I imagine it shouldn't be difficult to signal out those employees that present the greatest HUMINT risk and apply extra scrutiny. Any employee that have any sort of top secret clearance, that has worked for intelligence agencies or contractors and the worked in the military, but not out in the field is potentially a mole. I'd find it hard to believe that there are people that don't fit that profile but are…

People come to Google from all paths of life. For all you know, some 20-something long-haired unix hotshot could have been busted for drugs at some point and "repurposed" as a mole in exchange for leniency. And there's always the classic sex honeytrap for married men, which will never go out of fashion. Real spooks don't carry a conscience, they'll exploit anything they can to get their grubby hands on the data they…

    "For all you know, some 20-something long-haired unix 
    hotshot could have been busted for drugs at some point and  
    "repurposed" as a mole in exchange for leniency."
Excellent point. Previous comment retracted.

Re: Google encrypts data amid backlash against NSA spying

#136
post #78

Earlier quoted context omitted.

No, this is not correct. The particulars of your agreement with a third-party for storage of your email does not extend government rights to examine that data (the ads in your inbox are as non-public as the email in there too). Even the horribly flawed ECPA recognizes that (it buttresses it, in fact). Moreover, Google[1] is currently standing behind the US v Warshak shield and requiring warrants for email contents. T…

No, this is not correct. Your talking statutes, not the constitution. Obviously the constitution trumps both statute and executive readings. Reasonable is per the constitution, an it is plastic in case law. That's why the questions are important, fundamentally. In any event, its worth keeping in mind the right level of abstraction.

> Your talking statutes, not the constitution

I'm talking both. The ECPA was important in that Congress avoided decades of court cases by making explicit the protections afforded electronically stored media, though they did not extend those protections far enough (which today in practice weakens protections that may have been more clearly delineated by now had the ECPA not been enacted).

Constitutional protection superseding (among other things) the fairly arbitrary 180 day requirement for a warrant set by the ECPA was clearly recognized by the Sixth Circuit in the US v Warshak second (criminal) case, stating that "The government may not compel a commercial ISP to turn over the contents of a subscriber’s emails without first obtaining a warrant based on probable cause."[1]

In both US v Warshak cases, though, the Sixth Circuit emphasized the higher protection afforded content over transactional data just for being content by the the tests established by both Katz v US and Smith v Maryland. They laid out that even the supremely terrible precedent of Smith v Maryland (which is the proud parent of allowing the government to seize "metadata" without a warrant) did not allow the government to "bootstrap" limited access to full access, including the access needed for automated processing of email contents by the email provider:

"The government also insists that ISPs regularly screen users’ e-mails for viruses, spam, and child pornography. Even assuming that this is true, however, such a process does not waive an expectation of privacy in the content of e-mails sent through the ISP, for the same reasons that the terms of service are insufficient to waive privacy expectations. The government states that ISPs “are developing technology that will enable them to scan user images” for child pornography and viruses. The government’s statement that this process involves “technology,” rather than manual, human review, suggests that it involves a computer searching for particular terms, types of images, or similar indicia of wrongdoing that would not disclose the content of the e-mail to any person at the ISP or elsewhere, aside from the recipient. But the reasonable expectation of privacy of an e-mail user goes to the content of the e-mail message. The fact that a computer scans millions of e-mails for signs of pornography or a virus does not invade an individual’s content-based privacy interest in the e-mails and has little bearing on his expectation of privacy in the content. In fact, these screening processes are analogous to the post office screening packages for evidence of drugs or explosives, which does not expose the content of written documents enclosed in the packages. The fact that such screening occurs as a general matter does not diminish the well-established reasonable expectation of privacy that users of the mail maintain in the packages they send."[2]

I have not personally seen a good argument for differentiating between spam filtering and contextual advertising in terms of access. Regardless, this is a clear argument for automated access being immaterial to the question of an expectation of privacy of the contents of an email.

[1] http://www.ca6.uscourts.gov/opinions.pdf/10a0377p-06.pdf

[2] http://www.ca6.uscourts.gov/opinions.pdf/07a0225p-06.pdf

Re: Google encrypts data amid backlash against NSA spying

#137

Are they suggesting the NSA is tapping intra-data center communications? I hadn't seen that suggested before. That's interesting. I hadn't considered that could be how Prism works, but it would make sense if these companies weren't encrypting those connections previously. Somehow I assumed they were.

Some datacenters consider things like MPLS labels as a secure boundary. That isn't an issue at Google scale, but google almost certainly uses public fiber at between many connection points.

Re: Google encrypts data amid backlash against NSA spying

#138
post #78

Earlier quoted context omitted.

No, this is not correct. Your talking statutes, not the constitution. Obviously the constitution trumps both statute and executive readings. Reasonable is per the constitution, an it is plastic in case law. That's why the questions are important, fundamentally. In any event, its worth keeping in mind the right level of abstraction.

> Your talking statutes, not the constitution I'm talking both. The ECPA was important in that Congress avoided decades of court cases by making explicit the protections afforded electronically stored media, though they did not extend those protections far enough (which today in practice weakens protections that may have been more clearly delineated by now had the ECPA not been enacted). Constitutional protection sup…

I have not personally seen a good argument for differentiating between spam filtering and contextual advertising in terms of access.

Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights? So goes my spam filter, so goes the constitution? What's ironic is that the spam guys use 1st amendment to justify the spam (same as junk mail and the credit rating agencies).

Re: Google encrypts data amid backlash against NSA spying

#139
post #133

Earlier quoted context omitted.

What do you mean? Care to share more details? AFAICT, Google has been completely transparent about giving users control about how their data is shared. It's been ahead of the pack in protecting its users rights even going to courts to protect users. Disclaimer:I am an Engineer@Google.

Can you provide some insights why the connections between Google's data centers was NOT encrypted until now?

Unfortunately, I'm not sure I'm the right person to share more insight. I don't work on the network team but data between data centers flow on our own network. Data between a client's machine (machines on external networks) and machines on our networks has been encrypted for a while. Data at rest on servers has been encrypted.

Before these revelations, the tech community in general didn't expect that we needed to encrypt all traffic flowing on our home/office LANs. Like the rest of the world, these spying revelations have taught us that we need to be much more paranoid than we were earlier and are now encrypting data on our own networks.

As a user of a lot of web services that are deployed on the cloud, I'd actually beseech my fellow tech community to do this too. All and any user data passed between any two servers (even on a backend, internal, local network) needs to encrypted.

Re: Google encrypts data amid backlash against NSA spying

#140
post #138

Earlier quoted context omitted.

> Your talking statutes, not the constitution I'm talking both. The ECPA was important in that Congress avoided decades of court cases by making explicit the protections afforded electronically stored media, though they did not extend those protections far enough (which today in practice weakens protections that may have been more clearly delineated by now had the ECPA not been enacted). Constitutional protection sup…

I have not personally seen a good argument for differentiating between spam filtering and contextual advertising in terms of access. Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights? So goes my spam filter, so goes the constitution? What's ironic is that the spam guys use 1st amendment to justify the spam (same as junk mail and the credit rating a…

> Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights?

What? Where are on earth are you getting that from what I'm writing?

I'm saying that the Sixth Circuit has ruled that just because you use an email provider that scans your email contents for things like spam (or ads), you have not given up your 4th amendment right for that content to be secure against searches without a warrant.

What you quote is me arguing that your premise that contextual advertising is somehow distinct compared to scanning for spam both in function and legal implication is flawed. The next statement states that even if such a distinction could be made, the above quote from US v Warshak I is a perfect explanation of why agreeing to automated scanning of your email does not imply consent to an abrogation of your rights.

I really don't see how I can be clearer than "The government also insists that ISPs regularly screen users’ e-mails for viruses, spam, and child pornography. Even assuming that this is true, however, such a process does not waive an expectation of privacy in the content of e-mails sent through the ISP...."

Post reply on HN