Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

221–230 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#221

Earlier quoted context omitted.

Except, they didn't explicitly mean to do that, stopped doing that, and paid for the autonomous collection of trash that they threw out.

You are very naive if you think that Google does something by mistake (that also happens to fit well into their Big Black Hole of Information).

In your narrative, would Google have self-reported this intrusion? Because, they didn't have to, and they did it anyway.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#222
post #112

Earlier quoted context omitted.

We use Cisco appliances for VPN (a few different models) and indeed there is a shared key that we have to input manually. However, after the key is entered (and configs saved) in order to decrypt the traffic one would need to print Cisco configs which is a very unusual operation that would be logged and then alerts will fire, audits will catch it, etc.

Just out of interest how do you transfer the key between datacentres for setup? Same person travels between them? PGP encrypted email? Or over the phone? Phone is I think an obvious (and now clearly wrong choice) although maybe always suspect if you are concerned with dark fibre . The endpoint security of a device generating and transmitting the key now also being a risk. How far up the chain do you worry? An airgapp…

I think public key encryption with long enough key is a pretty safe bet these days. Of course, NSA might have new non-public discoveries in math/crypto that might make public encryption obsolete. Or they might have a device form Area 51 that breaks any encryption. However, I haven't seen any evidences of this yet.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#223
post #167

Earlier quoted context omitted.

But it doesn't fix §702 fully, does nothing to end BULLRUN (undermining encryption) Nor should it. Undermining the encryption used by legitimate surveillance targets and intercepting their communications is what the NSA is for . The point of legislative solutions isn't to stop having a signals intelligence agency. It's to limit that agency to spying on people it legitimately believes to be terrorists, agents of hosti…

Ok but to agree with that argument is to agree that the NSA and organizations like it are necessary. I'm still waiting for the proof that they are. Everything I see points to them compromising countless people's privacy and having nothing to show for it.

But that's the core of the problem. By the nature of what they do, their successes are never clear.

Not that this is a very robust intellectual defense, but the US is far from the only country to do this. Just two days ago the NYT had an article about Brazil spying on Americans within its borders:

http://www.nytimes.com/2013/11/05/world/americas/brazil-ackn...

If we shut down the NSA tomorrow we would be an an international disadvantage.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#224

Earlier quoted context omitted.

Apparently these data centers were linked via dedicated lines -- there was no traffic or outside access to these fiber lines. They were used solely for communication between the two data centers (so technically still an isolated network).

A pretty good example to smack in the face of all those "Just Air-gap your distributed SCADA system!" devotees.

Such people exist?!

Re: Google Security Team Member on NSA: "Fuck These Guys"

#225
Any data running over a leased or owned fiber between data centers should still be encrypted. Why didn't they have a VPN between the data centers? I don't get it and I personally think it's inexcusable. I believe I would lose my job if I my companies data was stolen and their was something I could have done to prevent it, and rightly so. I personally think that everyone has been far to forgiving of companies like Google, Yahoo, Microsoft, Facebook etc... for having done such a poor job of protecting the data we entrust to them.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#226
post #84

Earlier quoted context omitted.

Well, I feel that encrypting traffic inside the data center is not a bad idea (and we do it at WePay where I serve as CSO). The reasons is that you never know who is listening (big smile here). For example, I don't want our system administrators to have an easy way to look at the traffic: yes, it is still possible to do but it is harder and requires some very unusual actions that will trigger alerts everywhere. If in…

Seriously? If the NSA wanted to own WePay they would have even with your "security best practices". Sorry bud.

Sure. A court order would do it no problem.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#227
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

Legislative fixes aren't going to buy you a lot, though they'll buy you something. The fundamental problem is structural: there are a lot of things the NSA is totally allowed to do, especially when it acts as an agency of the executive outside of the U.S. Technologists tend to ignore national and jurisdictional borders because networks cross those borders, but the powers of the NSA are defined in terms of those borde…

Legal access to a document can't compel the owner of the document to hand over encryption keys. And if the existence of the document can be denied, you can't even prove it exists. This level of protection is within the reach of existing tools. Services like Google can make those tools accessible to the masses.

The law has to observe physics. You can get a court order to "compel" someone to float off the ground, but that doesn't mean it's going to happen.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#228
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

Legislative fixes aren't going to buy you a lot, though they'll buy you something. The fundamental problem is structural: there are a lot of things the NSA is totally allowed to do, especially when it acts as an agency of the executive outside of the U.S. Technologists tend to ignore national and jurisdictional borders because networks cross those borders, but the powers of the NSA are defined in terms of those borde…

[deleted]

Re: Google Security Team Member on NSA: "Fuck These Guys"

#229

It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.

Why did the US jump in priority. Just because it is a problem doesn't mean it is a bigger problem.

I think US journalism is causing us to misprioritize. Everyone is talking about the NSA so everyone assumes it's the biggest problem.

http://mag.newsweek.com/2013/11/01/edward-snowden-escalated-...

Re: Google Security Team Member on NSA: "Fuck These Guys"

#230
post #89

I think it's pretty clear that we need both technical and legislative fixes to NSA surveillance. Just one of the two isn't enough: to get be even vaguely confident that surveillance ends, we need both. The technical fixes I can't speak to, but the legislative ones I've been thinking about for a while. In the last week, there have been two prominent bills announced to deal with surveillance: - Bill 1: The FISA Improve…

Legislative fixes aren't going to buy you a lot, though they'll buy you something. The fundamental problem is structural: there are a lot of things the NSA is totally allowed to do, especially when it acts as an agency of the executive outside of the U.S. Technologists tend to ignore national and jurisdictional borders because networks cross those borders, but the powers of the NSA are defined in terms of those borde…

[deleted]
Post reply on HN