Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

191–200 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#191

It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.

China is a much more hostile state actor in how it would use any information it gathers up, especially to a free-enterprise company like Google.

I used to think much the same. These days however the unchecked secret security apparatus of the United States is a sword over the necks of it's citizens' freedom.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#192
post #33
post #13

Earlier quoted context omitted.

I would assume they use similar techniques within China and perhaps allied countries like North Korea and Cuba, but the US is performing wiretapping in at least the UK, Canada, Australia, and New Zealand. Also, how much non-Chinese Internet traffic passes through China?

> and perhaps allied countries like North Korea and Cuba Nobody is more distrusting of each other than two communist countries.

Disregarding for a moment that a state can not be communist (one defining characteristic of communism being absence of state), only socialist, North Korea has long disassociated itself from communism. Since the 90s at least there has been a systematic removal of any mention of Marxism, communism and related terminology from the constitution, laws and official discourse.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#193

It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.

No way! Do you think 9/11 could have been an inside job? :-)

Re: Google Security Team Member on NSA: "Fuck These Guys"

#194
post #165
post #123

Earlier quoted context omitted.

Can't. I so disbelieve in his argument that I won't sign up for G+. Besides, as Upton Sinclair was fond of saying, "It is difficult to get a man to understand something, when his salary depends upon his not understanding it."

I'm suggesting you could rebut his argument here instead of just insulting his integrity.

I doubt he's reading this - but for you, sure...

His claim is that there aren't any viable anonymous payment systems for the web but that advertising is semi anonymous, so that's better.

(1) There are ways to make anonymous payments on the net, I can use cash to buy cash-cards in denominations up to $500 that work just like debit cards online, they are even branded with Visa and/or MasterCard. Until a couple of years ago you could buy even larger denominations but war on terror hysteria made it illegal to do without providing ID. None of the entrenched powers seemed to mind the new regulations all that much, which leads too...

(2) The rise of advertising as the primary source of online funding has choked out development of alternative online payment systems in the same way that an invasive species chokes out native species that occupy the same ecological niche. If it weren't for companies like google we wouldn't be in the situation we are now because a lot more work would have gone into the development of alternative payment systems.

(3) The entire goal of modern online advertising is to identify and track users as narrowly as possible so as to better "target" them. The more sophisticated online advertising systems become, the less anonymous the users become. Companies like BlueKai and hundreds of others exist to connect your real-life identity (and associated database entries) with your online activity. Even google does it with their real names policy for g+.

So instead of each vendor only knowing about the specific transactions they have with you, there exist multiple databases that amalgamate all of your transactions (online and offline) across multiple vendors into one central record that is for sale. I'm well aware that Google thinks their user records are super proprietary and that they would never make that data openly available outside of Google, but (1) they are far from the only holder of such data and many of the others see selling/renting that database as their main source of profit, (2) sophisticated use of targeted ad-buys can indirectly mine Google's data, it's not as easy as just buying access like you would from a place like Experian but it is feasible under the right circumstances and (3) who can say if Google will have a change in corporate direction tomorrow and start selling access to all that data that they have been collecting for over a decade?

So, in short, his claim was so blindered that it really was quite ridiculously naive/ignorant.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#195
post #12

Earlier quoted context omitted.

Why do people assume the Chinese government is not able to use similar techniques?

China doesn't have agreements with BT, AT&T etc which allow it to tap fibre in our countries at will. I'm sure they try some tapping, but they can't do it on the scale that GCHQ and the NSA have been outside China.

How do you know that?

Re: Google Security Team Member on NSA: "Fuck These Guys"

#196
post #185

Earlier quoted context omitted.

Yes. It's fixable the moment the public realizes that it is within their power to fix.

Until you realize that the public doesn't have as much money as the lobbyists.

Who do you think the lobbyists are? Them is us.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#197
post #196
post #185

Earlier quoted context omitted.

Until you realize that the public doesn't have as much money as the lobbyists.

Who do you think the lobbyists are? Them is us.

No, them is some of us.

Example: I used to work for BigCorp. BigCorp had a PAC to which they would gently encourage employees contribute. They ran an annual contribution campaign, sent emails, made phone calls, etc. It was not mandatory, just encouraged. Many employees did so. The PAC in turn contributed to any politician who supported BigCorp.

So the net result is a bunch of people who ended up contributing to politicians who they otherwise may not have supported, and they did so out of a vague fear that doing so was important for their jobs. There was strong social pressure at work in this situation. I.e., left to themselves, these people would not have given a dime to these politicians.

The PAC in turn, spoke on behalf of these people, but only about issues that BigCorp cared about, not the issues the original donors cared about.

And that's why them is not us.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#198
post #52

Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. Basically, this is security 101: protect data at rest and protect data in flight. So, sorry but I think the better subject for discussion would be how badly Google screwed up, not how evil is NSA. M…

> Lets start from the beginning: the NSA "hack" became possible because Google (and its security team) made bad assumptions about the security of the connection between Google's data centers and did not encrypt the traffic. The assumption isn't bad - it's a private network line, not a public internet connection. Nobody else had access to that line, at least they weren't supposed to. Splicing a fiber line is a bit out…

> You can't blame Google for not anticipating a hostile break-in by the government.

"The" government? The lines were also being tapped by organized crime, China, France, etc. Google severely failed at data protection.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#200
Has it ever occurred to anyone that, just maybe, the whole NSA thing is a cover-up to distract the attention from the fact that it's actually the megacorporations that want to spy on you? This is a good way for Google, Microsoft, etc. to look innocent. Let's not forget that it was us who decided to trust these corporations with all our personal data.
Post reply on HN