Live data from Hacker News

Larry Page addresses PRISM

googleblog.blogspot.com

331–340 of 482 posts

Re: Larry Page addresses PRISM

#331
post #181

Earlier quoted context omitted.

Get a VPN anonymously, pay in Bitcoin and never expect third party companies to adhere to any policy they can potentially break. Anything else involves trust.

That's not the point. The point is if we have to resort to such measures, we have already lost.

We have AFAICS.

Resort to that and fight back from there.

Re: Larry Page addresses PRISM

#332
post #181

Earlier quoted context omitted.

Get a VPN anonymously, pay in Bitcoin and never expect third party companies to adhere to any policy they can potentially break. Anything else involves trust.

That's not the point. The point is if we have to resort to such measures, we have already lost.

[deleted]

Re: Larry Page addresses PRISM

#333

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

Possibly no direct access because the NSA has copies of Facebook, Google and Apple SSL private keys? Just sniffing the backbone...

Re: Larry Page addresses PRISM

#334
post #222
post #124

Earlier quoted context omitted.

Unless you can MITM SSL, having ISP access isn't enough. Remember, Google's the company that discovered that Turktrust had issued rogue CA certificates through Chrome's cert pinning.

unless you assume the NSA has the root SSL certs.

Root certs don't let you decrypt content encrypted with a descending cert. They just let you issue new certs that'll be considered valid. So, a MITM could send a client a compromised cert in the hopes that the client will encrypt content with it (after accepting it as valid due to it validating up the cert chain to root), but Chrome's certificate pinning is specifically designed to detect this class of attack - it is how the compromised Turkcert certs were discovered.

Even if you hold the root certs and can issue attack certs that validate up the cert chain, you can't MITM a cert-pinned client. In order to attack a cert-pinned site, the NSA would have to inject their own certs into Chrome's cert store, or have Google's private cert keys. Either would require compliance from Google.

Re: Larry Page addresses PRISM

#335
post #248

Earlier quoted context omitted.

Did you read Larry's blog post? He didn't rule out the NSA, he did rule out the USgovernment period. Quote: > Indeed, the U.S. government does not have direct access or a “back door” to the information stored in our data centers.

I did read it, with the dozens of other articles and such it's blurred together. He did rule out the US Government, does that rule out contractors? Does that rule out Verizon? What if Google has data in someone else' datacenter? That's specifically what they said the US government doesn't have direct access to. Do they give carte blanch access to their data to ANYONE? Regardless of the datacenter. If they don't they…

No one gets carte blanch access. Even Googlers don't get carte blanch access.

Re: Larry Page addresses PRISM

#336
post #284

Earlier quoted context omitted.

I don't buy it. What I quoted above doesn't say anything about US persons or non-US persons, about content or metadata, about this law or that one. It just says, Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely false. Now, Page may well be lying , but he definitely isn't weaseling. I'm pretty sure that denial covers both of the possibilities you're…

But if they were give similar court order terms as under the Verizon court order wouldn't he legally have to lie or violate the court order? Or just not give a comment, but no comment on this would implies guilt to a lot of people so lying could seem like the correct path.

I don't believe he can be forced to lie. If he was in that situation, I imagine he would simply not respond.

Re: Larry Page addresses PRISM

#337
post #248

Earlier quoted context omitted.

Did you read Larry's blog post? He didn't rule out the NSA, he did rule out the USgovernment period. Quote: > Indeed, the U.S. government does not have direct access or a “back door” to the information stored in our data centers.

And yet this still misses more important issues. While it is fantastic that Google does not give the USG a free pass to the whole enchilada, Google still collects and stores this data, and gives it when compelled, if they truly had the users best interests in mind they would reduce the data collected to only what they MUST have to do what they do, and not use Vacuum cleaner like methods to get and keep everything the…

What do you consider to be "what they do"?

Re: Larry Page addresses PRISM

#338
post #199

Earlier quoted context omitted.

They can't say "we don't provide access", because depending on the law, they are forced to. They say "we do not provide direct access", because as explained, any access goes through proper legal channels. I'm not sure what you'd call it? Remember language matters, and these are actionable public communications.

Sure, but the statement as worded does not rule out the possibility that a third party contractor (Palantir) has access, and feeds it to the government. So Google has the motive (some theoretical secret law they need to abide) and they haven't denied a potential means (third party mediation). That's enough for people to convict in this situation.

> Palantir

Isn't that basically their entire business model?

Re: Larry Page addresses PRISM

#339

Earlier quoted context omitted.

> Careful parsing of the constitution, careful parsing of various laws, very very careful interpretation of the words on the page. There is no "careful parsing" of the Constitution going on. Just people who never read the document very carefully other than what they thought the teacher said in 8th grade. This is the entirety of the 4th amendment: "The right of the people to be secure in their persons, houses, papers,…

You should read about Roe v. Wade, rayiner

Roe v. Wade was a pure exercise in legislating from the bench, and even many of its supporters will admit that.

O'Connor got it right in Casey when she distanced the right to abortion from the right to privacy: "That is because the liberty of the woman is at stake in a sense unique to the human condition and so unique to the law."

From Roe: "The Constitution does not explicitly mention any right of privacy. In a line of decisions, however, going back perhaps as far as Union Pacific R. Co. v. Botsford, 141 U.S. 250, 251 (1891), the Court has recognized that a right of personal privacy, or a guarantee of certain areas or zones of privacy, does exist under the Constitution. In varying contexts, the Court or individual Justices have, indeed, found at least the roots of that right in the First Amendment, Stanley v. Georgia, 394 U.S. 557, 564 (1969); in the Fourth and Fifth Amendments, Terry v. Ohio, 392 U.S. 1, 8-9 (1968), Katz v. United States, 389 U.S. 347, 350 (1967), Boyd v. United States, 116 U.S. 616 (1886), see Olmstead v. United States, 277 U.S. 438, 478 (1928) (Brandeis, J., dissenting); in the penumbras of the Bill of Rights."

That handwave-y language ("does not explicitly mention", "a right of personal privacy, or a guarantee of certain areas or zones of privacy", "at least the roots") doesn't exactly inspire confidence in the existence of a broad, fundamental right to privacy in the Constitution. Also, it uses "privacy" in a somewhat different sense than the surveillance debate. In Roe, it's used more like "liberty."

Re: Larry Page addresses PRISM

#340
There's some undertone about having Drummond listed as the co-author.

When the chief legal officer co-authors a post with a ceo, it means that each word has been carefully chosen, because each of these statements carries serious consequences if they get it wrong.

Post reply on HN