This is _not_ end-to-end crypto, that would require users storing the keys to their own emails on their own systems. This is basically TLS on a giant scale but does not prevent email from being intercepted while "at rest" on a gmail server.
Google speeding up end-to-end crypto between data centers worldwide
21–30 of 41 posts
Re: Google speeding up end-to-end crypto between data centers worldwide
#22If Google comes up with a much more sane version of or alternative to IPsec, deployed on all their boxes, it would be an amazing improvement for the world.
Re: Google speeding up end-to-end crypto between data centers worldwide
#23I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.
Re: Google speeding up end-to-end crypto between data centers worldwide
#24Earlier quoted context omitted.
Except of course, as we've learnt over the last few weeks, they're essentially one and the same thing. You can't trust a third party with your data if you want it kept secure. Period.
You can't trust a third party with your data if you want it kept secure. Period. It's impossible to do otherwise, though.
Self hosting is somewhat better, if nothing else because it presents a much less tempting target, and it is a privilege currently only available to the technical.
Well implemented strong encryption is another avenue.
Re: Google speeding up end-to-end crypto between data centers worldwide
#25Earlier quoted context omitted.
You can't trust a third party with your data if you want it kept secure. Period. It's impossible to do otherwise, though.
That is the rub of course. Self hosting is somewhat better, if nothing else because it presents a much less tempting target, and it is a privilege currently only available to the technical. Well implemented strong encryption is another avenue.
Re: Google speeding up end-to-end crypto between data centers worldwide
#26Re: Google speeding up end-to-end crypto between data centers worldwide
#27Earlier quoted context omitted.
That is the rub of course. Self hosting is somewhat better, if nothing else because it presents a much less tempting target, and it is a privilege currently only available to the technical. Well implemented strong encryption is another avenue.
Even with self-hosting, there's a lot of third-party hardware and software that you have to trust.
Re: Google speeding up end-to-end crypto between data centers worldwide
#28Earlier quoted context omitted.
> IPSec didn't exactly take off Oh, jezus. Did you read it on the Internets? IPsec (s is in lowercase) is the standard to securing L2 connectivity and it has been ubiquitously used for site-to-site and client-to-site connectivity for ages. In addition to several mature FOSS implementations, every network equipment vendor ships one. There is also a ton of client software - Windows supported it since Windows 2000, the…
IPsec, which runs at layer 3, secures IP (layer 3) traffic. To protect L2 connectivity with IPsec, you'll need to tunnel the l2 frames inside IP.
Standalone IPsec is supposedly nearly non-existent, but there's a plenty of L2TP/IPsec traffic out there.
Re: Google speeding up end-to-end crypto between data centers worldwide
#29I'm still quite astonished that (according to some of the comments) it's fairly standard that traffic between datacenters is not encrypted. Granted we're talking about extremely large throughput, but I thought Google of all companies would have invested in routers capable of doing this or at least gone to the trouble of designing their own hardware that does it; since Google is no stranger to this already.
I work for TeliaSonera and I can tell you that it's very standard for us to use VPN connections between worldwide datacenters.
Re: Google speeding up end-to-end crypto between data centers worldwide
#30The timing suggests this is supposed to be a PR move. And a cheap/ridiculous one at that.