Live data from Hacker News

Google Security Team Member on NSA: "Fuck These Guys"

plus.google.com

351–360 of 420 posts

Re: Google Security Team Member on NSA: "Fuck These Guys"

#351
post #194
post #165

Earlier quoted context omitted.

I'm suggesting you could rebut his argument here instead of just insulting his integrity.

I doubt he's reading this - but for you, sure... His claim is that there aren't any viable anonymous payment systems for the web but that advertising is semi anonymous, so that's better. (1) There are ways to make anonymous payments on the net, I can use cash to buy cash-cards in denominations up to $500 that work just like debit cards online, they are even branded with Visa and/or MasterCard. Until a couple of years…

Thank you for responding in a meaningful way. I appreciate it.

> There are ways to make anonymous payments on the net, I can use cash to buy cash-cards in denominations up to $500 that work just like debit cards online, they are even branded with Visa and/or MasterCard.

This still puts you at greater risk of exposure than creating a Gmail account through an anonymizing proxy. Prepaid cards can be traced to where they are purchased, which at least narrows your location geographically, if not the exact location. From there the NSA could probably catch you buying it in person by reviewing CCTV footage.

> The rise of advertising as the primary source of online funding has choked out development of alternative online payment systems in the same way that an invasive species chokes out native species that occupy the same ecological niche. If it weren't for companies like google we wouldn't be in the situation we are now because a lot more work would have gone into the development of alternative payment systems.

I don't really understand this point. You seem to be positing a world where online advertising didn't become the dominant mechanism for making money on the web, but you don't explain how this could come about. Perhaps if "companies like Google" did not exist? But there were advertising companies before Google and there will be long after Google is gone. Advertising is an inextricable part of the global economy. It would take a revolution to change that.

> So instead of each vendor only knowing about the specific transactions they have with you, there exist multiple databases that amalgamate all of your transactions (online and offline) across multiple vendors into one central record that is for sale.

I think this is deeply wrong and I wouldn't be working for Google if I thought we were heading in this direction. It's not my place to comment further on your other assertions about Google.

> So, in short, his claim was so blindered that it really was quite ridiculously naive/ignorant.

I don't see how your argument supports this claim. Nothing you have said would be news to Mike, who has been thinking about all this stuff longer and more deeply than most people. He just has a different perspective to you, that's all.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#353
post #351
post #194

Earlier quoted context omitted.

I doubt he's reading this - but for you, sure... His claim is that there aren't any viable anonymous payment systems for the web but that advertising is semi anonymous, so that's better. (1) There are ways to make anonymous payments on the net, I can use cash to buy cash-cards in denominations up to $500 that work just like debit cards online, they are even branded with Visa and/or MasterCard. Until a couple of years…

Thank you for responding in a meaningful way. I appreciate it. > There are ways to make anonymous payments on the net, I can use cash to buy cash-cards in denominations up to $500 that work just like debit cards online, they are even branded with Visa and/or MasterCard. This still puts you at greater risk of exposure than creating a Gmail account through an anonymizing proxy. Prepaid cards can be traced to where they…

This still puts you at greater risk of exposure than creating a Gmail account through an anonymizing proxy.

I note that you've specifically gone to the most extreme case of the state looking to track you rather than some other private entity. The NSA/FBI looking at camera footage at the point of purchase for a cash card is just as likely as the NSA de-anonymizing your proxy (well probably less likely given what the NSA has been up to). However, for private databases nobody is going to make those efforts. But what they will do (and do all the time) is cross-reference web activity to minimize anonymity and increasing "targeting."

Advertising is an inextricable part of the global economy. It would take a revolution to change that.

That's circular. My point is that the industry's overwhelming movement toward advertising as a payment system starved out the development of alternative payment systems, micropayments, e-cash, etc. Hell, paypal could be so much more privacy preserving simply by not disclosing your email to the seller but they don't make that trivial effort because they have no competition.

I think this is deeply wrong and I wouldn't be working for Google if I thought we were heading in this direction.

If you think I am specifically talking about Google, you are mistaken. Go install Ghostery and watch how simply visiting a web page like The Verge gets you into the databases of at least 7 different trackers other than Google. If Mike Hearn was arguing that google should have a monopoly on advertising because google currently doesn't deliberately share its secret stash with anyone, then that opens up a whole different line of disagreement.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#354
post #309

Earlier quoted context omitted.

I'vw been thinking about this pretty hard this summer - I've been involved in some local tech activist stuff. My take on it is as runs: Fundamentally, what's needed here is the ability to have confidence that the intelligence system is not overstepping its bounds. The US founders' framework for building that confidence is to have multiple parts of power, whose interest is roughly aligned with countering each other. S…

It's wrong to portray this as a trade-off between more risk or less risk. In reality it's a trade-off between two kinds of risk. Without the NSA snooping there is a higher risk of terrorist attacks, but with the NSA snooping there is more risk of attacks on democracy. Imagine j. edgar hoover or richard nixon able to use all that NSA data for illegitimate purposes. How easy would it have been to supress dissenting pol…

I don't know. What do you think they would've done to suppress dissenting political opinion?

Which is where this whole conversation goes to hell - the trailed off sentences where people assume they actually have a clue what dangers they're talking about.

Because if your problem is "oh, someone might find out about someone's mistress and tell the media..." well - the problem begins and ends with the fact that their voters turn out not to be ok with that. But they're still voters who's votes matter.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#355
post #58

Earlier quoted context omitted.

Maybe you didn't notice the detainment of Greenwald's partner by the GCHQ whereby they demanded him to turn-over/destroy whatever he had. Further, the break-in to Greenwald's residence and theft of his machine. As well as the visit to the Guardian and destrution of machines.... The evidence is crystal.

As much as the UK government would probably love being confused for the US government, at least the visit to the Guardian and detainment of Miranda were both done by the UK. And given how the UK government loves nothing more than to be the lapdog of the US, I have no doubts it was done entirely voluntarily. Eagerly even, as an opportunity to show off just how extra exceedingly loyal minions they are. Frankly, I have…

Except you know, in that case the person actually did have classified documents of an allied nation on a thumbdrive on them.

Which you know - is still illegal to have. Though it's funny how the Guardian thoroughly underreported that fact.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#356
post #290

Earlier quoted context omitted.

Google, and their "geniuses" in opsec, should not be given a pass at all for this. Even if this is a leased private line, non-Internet routed, whatever, it is trivially easy to encrypt the communications and is absolutely a best practice. I see this as great big egg on their face. In fact, it's such a cock-up that one wonders if this is the plausibly deniable ingress that they agreed to provide for the NSA, et. al Th…

Tapping multi-mode dark fiber unnoticed is now considered trivially easy? I must have missed when the bar was shifted this high.

The fiber doesn't run straight into a Google datacenter. It's operated and managed by the company which lays the cable under the sea, which means it goes through their stations at the coast and probably through quite a bit of other non-exclusive routing hardware.

The fact that routing hardware exists means you can pretty easily tap it.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#357

Earlier quoted context omitted.

Google's inter-dc links are way too big for any appliance type of thing to encrypt. Like most things at Google the scale of their network is incomprehensible to most people.

> Google's inter-dc links are way too big for any appliance type of thing to encrypt Frankly, no. There are numerous network devices that can handle AES-256 on 10 Gbps links, as a matter of routine, whilst doing 'mundane' switching for the day job. If you have the money there are dedicated hardware that can handle the same at 100 Gbps. IP Cores is one from memory that produces the circuitry for that. They can throw c…

100Gbps is nothing for a company at the scale of Google. They are probably closer to 10-100Tb/s on there backbones.

You don't need appliances here as they can't handle the load, build the encryption into your application.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#358
post #354
post #309

Earlier quoted context omitted.

It's wrong to portray this as a trade-off between more risk or less risk. In reality it's a trade-off between two kinds of risk. Without the NSA snooping there is a higher risk of terrorist attacks, but with the NSA snooping there is more risk of attacks on democracy. Imagine j. edgar hoover or richard nixon able to use all that NSA data for illegitimate purposes. How easy would it have been to supress dissenting pol…

I don't know. What do you think they would've done to suppress dissenting political opinion? Which is where this whole conversation goes to hell - the trailed off sentences where people assume they actually have a clue what dangers they're talking about. Because if your problem is "oh, someone might find out about someone's mistress and tell the media..." well - the problem begins and ends with the fact that their vo…

"What do you think they would've done to suppress dissenting political opinion?"

Easy. You use government power on them. You "coincidentally" hit them with an IRS audit, one that's incredibly hostile and refuses to resolve itself. You hit their business with every inspection possible, held to the most stringent of standards. Even if, and perhaps especially if, they don't own it, and you find a way to sufficiently hint to the business why exactly they're having these troubles. You have a cop follow them and nail them with every petty infraction in the book. Any government program they may be on, you inspect their compliance to the n-th degree. Layer heavy bureaucratic red tape on at every opportunity. Find ways to make them need a lawyer. Find a petty excuse to claim you suspect them of drug trafficking and inspect everything they own, which basically allows you to take everything they own, and effectively destroy or hold on to everything for years.

And that's if you have a goal of staying plausibly legal. If the mask is off for some reason, there's even more you can do. And these are just examples; if one truly took a survey of what the government could do to you without even stretching the law, I think we could produce a very thick and scary book.

Unfortunately, I don't think the capabilities of the NSA are bounded by your imagination.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#359
The judiciary should always have an adversarial relationship with the Intelligence community in order to have checks and balances. I think FISA could work with more and varied members on it's committee.

Feinstein is a joke and obviously isn't well informed on the subject matter she's supposedly overlooking.

Re: Google Security Team Member on NSA: "Fuck These Guys"

#360
post #356

Earlier quoted context omitted.

Tapping multi-mode dark fiber unnoticed is now considered trivially easy? I must have missed when the bar was shifted this high.

The fiber doesn't run straight into a Google datacenter. It's operated and managed by the company which lays the cable under the sea, which means it goes through their stations at the coast and probably through quite a bit of other non-exclusive routing hardware. The fact that routing hardware exists means you can pretty easily tap it.

I believe my comment is pertaining to the use of the word "easily". James Bamford in The Shadow Factory was talking about how difficult this is, even for government institutions.
Post reply on HN