Live data from Hacker News

Google encrypts data amid backlash against NSA spying

washingtonpost.com

141–150 of 153 posts

Re: Google encrypts data amid backlash against NSA spying

#141
post #138

Earlier quoted context omitted.

I have not personally seen a good argument for differentiating between spam filtering and contextual advertising in terms of access. Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights? So goes my spam filter, so goes the constitution? What's ironic is that the spam guys use 1st amendment to justify the spam (same as junk mail and the credit rating a…

> Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights? What? Where are on earth are you getting that from what I'm writing? I'm saying that the Sixth Circuit has ruled that just because you use an email provider that scans your email contents for things like spam (or ads), you have not given up your 4th amendment right for that content to be secure a…

What you quote is me arguing that your premise that contextual advertising is somehow distinct compared to scanning for spam both in function and legal implication is flawed.

Its flawed because that premise is at once irrelevant and falsely asserted. Neither a spam filter nor contextual advertising are inherent to private communication.

What is relevant to private communication is that it is private. If I CC larry page on a "private and confidential" e-mail to my lawyer, Mr page is a party to the conversation. It is no longer "private" nor "confidential". If every e-mails sent to a g-mail account is by default cc'd to Mr page, none of those communications are "confidential". By (statute) law, the senders are forfeiting attorney client privledge...by "opening" the communication to a thrid party. Its google's stated position that person sending an e-mail to a g-mail account has a no "reasonable expectation of privacy". And this is what that means. This means that google (wants to) treat your mail like Mr page is reading it, and it believes that users are in fact waiving their expectation of privacy by using or communicating with g-mail recipients. That includes presumably senders of mail who have not agreed to g-mails T&Cs (ie, who presumably do not have reason to know what they entail).

It is the insertion of an active third party into the communication which is a problem. Its a problem because it damages the inherent idea of 'mail' as a sender-recipient private relation (post office =/= an active recipient). And from here, the problems start.

In any event, I think you are missing the legal abstraction at the core of the analysis. Its not a problem you can wish away, nor is it one you can trust current statutes of case law to protect into the future. That is the nature of 'reasonable' modifiers; they are ultimately contextual. And here, we have self-interested parties strategically eroding the context of the 4th amendment, to the detriment of the the public at large.

Re: Google encrypts data amid backlash against NSA spying

#142
post #141

Earlier quoted context omitted.

> Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights? What? Where are on earth are you getting that from what I'm writing? I'm saying that the Sixth Circuit has ruled that just because you use an email provider that scans your email contents for things like spam (or ads), you have not given up your 4th amendment right for that content to be secure a…

What you quote is me arguing that your premise that contextual advertising is somehow distinct compared to scanning for spam both in function and legal implication is flawed. Its flawed because that premise is at once irrelevant and falsely asserted. Neither a spam filter nor contextual advertising are inherent to private communication. What is relevant to private communication is that it is private . If I CC larry p…

You are off in the weeds.

> What is relevant to private communication is that it is private

This is not the basis for 4th amendment protections. You are also confusing things: attorney-client privilege comes to us from Common Law, not the 4th amendment and is not a good basis for discussing what is private, as there are many more restrictions on it (a warrant can almost never compel your attorney to testify against you, for instance, which is not the case for almost all normal communications).

The mere existence of a third party does not negate the reasonable expectation of privacy, otherwise no third party communication system would be safe from warrantless searches. What has long mattered is the reasonable expectation of privacy, which under current case law does not always but in many situations does override any details like the extent that a third party is involved in that communication (for instance, cc-ing Larry Page on an email does not make a message suddenly have no expectation of privacy any more than sending it to anyone else, as the limited list of recipients makes it on its face not for publication or public posting).

> It is the insertion of an active third party into the communication which is a problem. Its a problem because it damages the inherent idea of 'mail' as a sender-recipient private relation (post office =/= an active recipient). And from here, the problems start.

Again, this is wrong. The fact that there are people at the post office, people that could open your mail, people that do actively examine your mail for things like drugs or bombs does not negate your 4th amendment protections. Are you reading anything I'm writing? That's directly addressed in the quote three posts above this one.

> In any event, I think you are missing the legal abstraction at the core of the analysis.

This is just silly. What you are suggesting is that the third party doctrine has overruled all, and that merely using an email provider that scans for spam or looks for abuse has left you open for warrantless searches (which is almost all of them except ones your run yourself since open mail relays are virtually extinct). Not only have you provided no evidence for this belief, the ECPA says you are wrong for emails newer than 180 days, and it looks increasingly unlikely that the courts will agree with you for emails that are older.

You appear to be confusing Google saying that people sending email to users of gmail expect their emails to be handled by the machines that run gmail (or they should, because that's the only way it can physically work) with an argument about the 4th amendment. Breathe easy. That is not the case. Whether or not Google is breaching the plaintiff's expectation of privacy (and it would, again, be bad news for every email provider out there if they are found to), scanning your email is not publicly posting your email, and this tort case has no bearing on your 4th amendment protections from searches by the government. This was established in Katz v US 46 years ago, and remains true today.

Re: Google encrypts data amid backlash against NSA spying

#143

Earlier quoted context omitted.

When Google does something that makes it impossible for them to hand over certain types of data to the NSA, either by not collecting it, or making it so that only the user is able to decrypt it, wake me up. Until then, it's a PR stunt.

IMAP/POP3 has always been a gmail option, which allows local PGP use. Chrome sync allows you to set your own encryption passphrase (provided you trust the binary doing the encrypting...). You've been able to share encrypted files on google docs/drive since they added arbitrary file storage. Etc. Chrome sync is probably the strongest example that I can think of fitting your criteria, since it's built into the product…

They haven't done anything there though... They've just provided a standard IMAP service, and a standard file syncing service...

When they provide an option in GMail for people to upload their public PGP keys, and then start encrypting email on the way in, and don't store any non-encrypted versions of those emails, and build PGP support into Chromium for accessing those emails. Then they will have done something worth noticing.

Re: Google encrypts data amid backlash against NSA spying

#144
post #133

Earlier quoted context omitted.

Can you provide some insights why the connections between Google's data centers was NOT encrypted until now?

Unfortunately, I'm not sure I'm the right person to share more insight. I don't work on the network team but data between data centers flow on our own network. Data between a client's machine (machines on external networks) and machines on our networks has been encrypted for a while. Data at rest on servers has been encrypted. Before these revelations, the tech community in general didn't expect that we needed to enc…

Thank you for providing your insights, it is important to know that the data on the disks is encrypted. I know about the encryption (https) between the browsers and Google's services - Google was one of the first actually to switch the services to https.

But I have to say that I am still quite surprised that there is no encryption between data centres. Working from time to time for industrial customers, on business critical software, most of the time it is required to encrypt data between servers, even when the hardware is in the same building, because they are afraid of leaks/attacks from inside.

I think Google has to do some explanation to the public about their security. Though I do not know if it is not too late for some google users.

Re: Google encrypts data amid backlash against NSA spying

#146
post #107

I upvoted this because I want it to kickstart a movement among companies, so everyone increases their security, end to end. But at least on my part, this doesn't begin to "impress me". So far they're only talking about encrypting data between servers and they've also recently talked about encrypting Drive storage data (why wasn't it encrypted in the first place?!) They need to implement OTR or some form of end to end…

Includes in the output: Server public key is 2048 bit ... Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES128-GCM-SHA256 (ie: not RC4, as long as your client supports non RC4 ciphers, uses ECDHE for PFS) and: TLS session ticket lifetime hint: 100800 (seconds) (session keys are discarded by the client every 1d4h, so presumably the server rotates them every 24 hours or so (4hrs to allow for clock skew, I assume, or to allow for the fact that people might be slightly late on something they check every 24 hours (eg when the wake up each morning)))

Nobody is going to make the change from 1024 bit keys to something else without first verifying that the new bit length is "secure enough" for a reasonable enough time (if nothing else, you don't want to have to go through the expense of the process of getting everything upgraded more often than you have to). Although you're right, it would be nice if they published their reasoning.

I don't know how to verify the security of hangouts. Looking at the webrtc standard, it doesn't appear to support encryption. There is also a lot of opposition to standardising encryption for webRTC because of "DRM" concerns. So I guess it's probably not encrypted, but don't quote me on that.

Disclaimer: I'm a Google employee.

Re: Google encrypts data amid backlash against NSA spying

#147

Earlier quoted context omitted.

IMAP/POP3 has always been a gmail option, which allows local PGP use. Chrome sync allows you to set your own encryption passphrase (provided you trust the binary doing the encrypting...). You've been able to share encrypted files on google docs/drive since they added arbitrary file storage. Etc. Chrome sync is probably the strongest example that I can think of fitting your criteria, since it's built into the product…

They haven't done anything there though... They've just provided a standard IMAP service, and a standard file syncing service... When they provide an option in GMail for people to upload their public PGP keys, and then start encrypting email on the way in, and don't store any non-encrypted versions of those emails, and build PGP support into Chromium for accessing those emails. Then they will have done something wort…

How would spam filtering or searching work in such a service?

Re: Google encrypts data amid backlash against NSA spying

#148
post #74

I can't believe traffic between data centers wasn't already encrypted.

Ah, but convincing folks to run SSL inside the corporate firewall leads me to believe that Google may have treated the fiber between datacenters as not actually leaving the property.

(Yes, it is a tough sell to get folks to run SSL inside.)

Re: Google encrypts data amid backlash against NSA spying

#149
post #67
post #19

Earlier quoted context omitted.

Meanwhile, Google Argues for Right to Continue Scanning Gmail "This company reads, on a daily basis, every email that's submitted, and when I say read, I mean looking at every word to determine meaning," said Texas attorney Sean Rommel, who is co-counsel suing Google. http://abcnews.go.com/Technology/wireStory/google-argues-con... http://www.mercurynews.com/business/ci_24021944/google-argue...

Um, you do realize that pretty much every single mail service provider is "scanning" their customer's email to screen out spam, right? That's also an algorithmic analysis of the body of the e-mail, and it's providing a service that most customers appreciate (since the generally don't want to swamped by hundreds of Viagra and "make money fast" emails every day)

Spam scanning can be thought of a continuous stream without a given email assigned to a user whereas contextual scanning for the purpose of advertisement necessarily ties emails to you.

Maybe it's just a semantic difference but I would argue that that is a sufficiently big differentiator.

Re: Google encrypts data amid backlash against NSA spying

#150

Earlier quoted context omitted.

They haven't done anything there though... They've just provided a standard IMAP service, and a standard file syncing service... When they provide an option in GMail for people to upload their public PGP keys, and then start encrypting email on the way in, and don't store any non-encrypted versions of those emails, and build PGP support into Chromium for accessing those emails. Then they will have done something wort…

How would spam filtering or searching work in such a service?

Spam filtering:

  Step 1. Spam filter
  Step 2. Encrypt
Searching:

Client side tool which builds a local index as messages are decrypted to be read for the first time. The index is it's self encrypted and incrementally synced between clients.

That took me less than 5 seconds to think up. Google can spend time and money thinking up better solutions if they want to actually do something.

Post reply on HN