Live data from Hacker News

Asking the U.S. to allow Google to publish more national security request data

googleblog.blogspot.com

31–40 of 189 posts

Re: Asking the U.S. to allow Google to publish more national security request data

#31
post #17

>Assertions in the press that our compliance with these requests gives the U.S. government unfettered access to our users’ data are simply untrue. However, government nondisclosure obligations regarding the number of FISA national security requests that Google receives, as well as the number of accounts covered by those requests, fuel that speculation. Sounds suspiciously like they are going to ruin everyone's nerd r…

You really love that phrase, don't you? I'm sure in other communities it is a great way to marginalize those with interests that you do not share.

You're suggesting that the idea of Google as a tool for the NSA is a marginal interest on HN?

Re: Asking the U.S. to allow Google to publish more national security request data

#33
post #9
post #5

Aggregate number of requests is one thing, but perhaps some indication of how much content is provided with the average request would be required to really indicate what is going on here? An API may serve millions of requests per day and return single-integer responses, or it might serve one batch query per day and provide a nested document with many sub-sections.

From the article: "We therefore ask you to help make it possible for Google to publish in our Transparency Report aggregate numbers of national security requests, including FISA disclosures—in terms of both the number we receive and their scope"

Not sure how I missed that on the first read through - good to see though, reassuring as long as the scope descriptions are reasonably clear!

Re: Asking the U.S. to allow Google to publish more national security request data

#34
post #25
post #19

Earlier quoted context omitted.

1. Google probably should offer passive S/MIME on mail. START TLS goes a long way, but providing the same signals about message authenticity to people who IMAP from gmail as who use the web UI would be nice. A non-google-trusting way to do PGP with a better UI/UX would also be a nice feature for gmail. Just indicating "encrypted" at the message-list view or something. I have PGP working quite nicely in mutt, but a lo…

I think I might prefer that world too. Now: how likely are we to be in that world any time soon?

I'd bet "before 2025", absent some major catastrophe. First you build systems which let platform developers centralize trust, then the essential step is letting individuals or organizations pick their own roots of trust (and some kind of crazy web of trust thing for interchange).

We're doing a pretty good job on mobile of "centralized trust", and also sort of with cloud infrastructure, if not apps.

At least, we'll have secure infrastructure on which people can continue writing insecure applications by 2020-2025. The "people writing insecure applications" won't stop until people stop writing applications, hopefully replaced by non-humans writing applications, maybe in 2050+.

Re: Asking the U.S. to allow Google to publish more national security request data

#35
post #13

In expressing his view that Google is being harmed by USG's lack of transparency (combined with the godawful operational security of the contractor-run intelligence agencies), is Google's chief counsel here starting to build the standing to sue the government? If this whole debacle sets up an epic confrontation between Google and the DoJ, I may have to reevaluate how irritated I am at how "Prism" has been reported. M…

Just to clarify, I think you are irritated with the inaccurate/sensationalist reporting of PRISM, and not that it was leaked to begin with?

My perspective on this is going to sound weird to you.

1. I am very irritated at inaccurate and sensationalized reporting.

2. I think the USG should have been much more open and forthcoming, at least in the aggregate, about how foreign signals intelligence was coming into contact with online services used mostly by citizens.

3. I think leaking details of signals intelligence programs should be a crime.

4. I hope Google picks a giant fight with the DoJ and wins it.

Re: Asking the U.S. to allow Google to publish more national security request data

#36
Ok, so its a bit snarky, but I wish Google would invest as much cleverness in evading the letter of these non-disclosure rules as they do in evading the letter of the tax laws in their various jurisdictions. Perhaps they could create Google Panama Ltd which is the official entity to petition for all FISA and NSL requests which is an independently operating subsidiary based in Panama and outside the jurisdiction of the disclosure rules or something. There are a lot of smart people there, you can figure this out.

Re: Asking the U.S. to allow Google to publish more national security request data

#37
post #31
post #17

Earlier quoted context omitted.

You really love that phrase, don't you? I'm sure in other communities it is a great way to marginalize those with interests that you do not share.

You're suggesting that the idea of Google as a tool for the NSA is a marginal interest on HN?

No, I am talking about much less specific interests, as his use of the phrase is similarly broad.

Nor does his attempt to marginalize an interest imply that the interest is marginalized on HN. It concerns me that you are so eager to misread others' comments, and defend comments that contain no substance, only name-calling.

Re: Asking the U.S. to allow Google to publish more national security request data

#38
post #24

The issue here is that Google doesn't know how much data the NSA collects. The NSA has access to the internet backbone that Google uses and can read whatever traffic it wishes that leaves the Google network. Obviously this is not everything but most everything. It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. So while Google can…

>So while Google can claim they do not allow the NSA direct access to it's servers

That is the entire story in this case, direct access to the servers.

Re: Asking the U.S. to allow Google to publish more national security request data

#39
post #17

>Assertions in the press that our compliance with these requests gives the U.S. government unfettered access to our users’ data are simply untrue. However, government nondisclosure obligations regarding the number of FISA national security requests that Google receives, as well as the number of accounts covered by those requests, fuel that speculation. Sounds suspiciously like they are going to ruin everyone's nerd r…

You really love that phrase, don't you? I'm sure in other communities it is a great way to marginalize those with interests that you do not share.

It's one thing to care about privacy issues, it's another to believe (and react to, and soapbox about) a distorted and inaccurate version of reality. A lot of the "nerd rage" has involved people assuming facts that may not in fact be true. People who do this marginalize themselves. In general we call them "conspiracy theorists."

For the facts that do indeed turn out to be true, soapbox away.

Re: Asking the U.S. to allow Google to publish more national security request data

#40
post #11
post #8

I'm only upvoting this not because I have much loyalty or trust left for Google, but because I want many other companies to follow their lead and flood the Administration with such requests. I still feel this does very little, though. They need to be asking them for much more. They need to ask them to end the spying. Until then I'm still hoping Google, Microsoft, Facebook and others will suffer greatly for this abroa…

So you'll be happy when the US ends all foreign signals intelligence? Or makes the Internet a safe haven from signals intelligence? Also: by offering PGP in GMail, Google would harm online security. If you want PGP, install it on your computer. Google won't do anything to stop you.

I wish you wouldn't phrase your questions like that as it invites some to accuse you of implying that it's either the US spies on everybody or ends all foreign signals intelligence.

Also, the fellow you replied to didn't specify what sort of spying needs to be stopped. He could have no issue with foreign signals intelligence (which presumably means spying on non-US folks).

Post reply on HN