Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

171–180 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#171

Earlier quoted context omitted.

What a convincing retort.

Yes, i'm going to describe internal security procedures in detail to a stranger. Suffice to say, the idea that random people in some nebulous "network security" group have access to all traffic related PKI (or whatever) is barely worth responding to. Google is not made of idiots. It is not a startup run in a garage where every the "IT guy" has access to all the private keys.

Suffice to say, the idea that random people in some nebulous "network security" group have access to all traffic related PKI (or whatever) is barely worth responding to

Curious sarcasm. Network security is a role, and it's one which Google holds in very high esteem. Yes, if someone is configuring IPSec or new load balancers or any other front-end system, they need the Google certs. This is a simple function of the job.

It is not a startup run in a garage where every the "IT guy"

Here you go again. "IT Guy" when I was talking about network security roles (which despite your laughable sarcasm we know is a role at Google) -- the guys in charge of the coop, protecting the chickens. Maybe they wolves.

I have never, ever, in my life seen checks and controls that weren't laughably insecure. I've worked at a multinational bank, a large insurance company, a national telephone company, among other places. There will always be those people who cluck their mouths and wave their arms about how no way this is super advanced controls...in my experience it never, ever is.

Re: Asking the U.S. to allow Google to publish more national security request data

#172
Asking is far too polite. Every citizen, not just Google, should be demanding the end to these secret orders and secret courts. The government is supposed to be our servant, not our master. We need to start treating it appropriately.

Re: Asking the U.S. to allow Google to publish more national security request data

#173
post #43
post #8

I'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroa…

Here's some background on what's actually going on: http://news.cnet.com/8301-13578_3-57588752-38/google-to-feds...

> And the surveillance process must comply with the Fourth Amendment.

This phrasing seems to suggest that the intended target of FISA 702 - the US cloud data of non-US-resident non-US-citizens - enjoys Fourth Amendment-based protections, such as the probable cause requirement, under FISA 702. But in fact it seems that (IANAL) FISA 702 is compatible with the Fourth Amendment (if it is) only in the sense that slavery was compatible with the Fifth Amendment: simply because the Fifth Amendment does not apply to slaves. If 702 envisaged non-resident aliens' US cloud data as being protected by the Fourth Amendment then it would presumably require the US government to establish probable cause at the FISC (or some other court). But in fact 702 doesn't seem to require the government to claim any kind of cause or suspicion or even state any purpose or motivation for the search to the FISC. The FISA 702 PowerPoints obtained by the ACLU under FOI make it clear that the US government understands FISA 702 as removing the probable cause requirement http://www.aclu.org/files/pdfs/natsec/faafoia20101129/FAAFBI... .

Re: Asking the U.S. to allow Google to publish more national security request data

#174
the first question anyone should ask themselves is - how do you know they will tell the truth? they might be forced by their police state law to pretend the numbers are low and you have no way to be sure. you can not trust any company based in Police State of America, everything they tell you might be because law requires them to.

Re: Asking the U.S. to allow Google to publish more national security request data

#175
post #11
post #8

I'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroa…

So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.

I would. Any secrets we allow the government to keep are a license to be abused. They're barely capable of following their own laws under the microscope. I doubt they even try so long as the citizens aren't aware of their activities.

Re: Asking the U.S. to allow Google to publish more national security request data

#176
post #35

Earlier quoted context omitted.

Just to clarify, I think you are irritated with the inaccurate/sensationalist reporting of PRISM, and not that it was leaked to begin with?

My perspective on this is going to sound weird to you. 1. I am very irritated at inaccurate and sensationalized reporting. 2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens. 3. I think leaking details of signals intelligence programs should be a crime. 4. I hope Goog…

3 surprises me. I don't think leaking should ever be a crime. Making leaking a crime is an invitation for the government to engage in more illegal activities.

Leaking should get you fired, of course. Realistically, it will and you'll be blackballed from working in security forever. I think that's more than enough incentive not to leak unless there is real abuse going on.

Re: Asking the U.S. to allow Google to publish more national security request data

#177
post #109

Earlier quoted context omitted.

Good point. If they can force companies to lie about the existence of FISA requests, why wouldn't they force them to lie about the number of such?

[citation needed]. Again, i have seen this in argument after argument. Nobody has yet provided any legal authority that states it is constitutional or legal for the government to compel forced lies. They can compel silence, for sure. There is plenty of authority in other contexts (IE not national security), that the government cannot compel you to speak misleading or non-truthful information. I wish this idea that ev…

You're interneting wrong. Of course we can't give official links pointing to where this is policy, that's the point of the policy! But from the information we've gathered so far it very much appears to be the case that companies are forced to deny getting requests from the government, not just be silent.

And don't bother trying to work out how the law allows this, we're not even allowed to know what some of the laws even are.

Re: Asking the U.S. to allow Google to publish more national security request data

#178

What are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the…

Disclaimer: I work at Google. I'm working on the client-side (Chrome) and my knowledge in the server area is therefore limited, but from my understanding this would be really hard. 1. Googlers have access to almost all source code. It would be difficult to hide code that just sends data to an outside entity. 2. Google continually monitors its (internal) bandwidth. This is done to optimize traffic, and detect intruder…

>1. Googlers have access to almost all source code.

So what. The world has access to the Linux source code. If I told you there was code in there that sent every byte written to disk to some external entity could you find it? Even if it was clear enough for you to find it, you'd have to be looking for it.

Further, you said yourself that googlers have access to almost all source code. How do you know something else isn't injected in before deployment. Honestly, the vast majority of googlers would have no idea and no way to have any idea if something like this were going on. Especially if people's jobs/freedom depending on no one knowing.

Re: Asking the U.S. to allow Google to publish more national security request data

#179
post #29

What are the legal ramifications if employees at Google also work at the behest of the NSA/FBI/CIA (unbeknownst to Google)? It is one thing to compel the organization to reveal information, but what are the legal questions around essentially spies within the various corporations? This very blog post mentions that Google hires some of the best security engineers in the world. I'm sure having "prior" employment at the…

It would be a felony for anyone at NSA to attempt to "turn" an employee of Google and get them to leak secret information from Google's systems.

You mean a felony in the way that assassinating people is against US and international law, it's illegal to hold someone more than 24 hours without charging them and so on? I'm not sure how much laws like that matter at this point.

Re: Asking the U.S. to allow Google to publish more national security request data

#180
post #142
post #118

Earlier quoted context omitted.

What lies have companies told?

From the news I've read, my understanding about FISA is that if someone asks you whether you've been subject to one, you're legally obligated to lie and say no. Right, or am I missing something?

They're compelled to lie, or they're compelled not to answer?
Post reply on HN