Live data from Hacker News

Project Shield

projectshield.withgoogle.com

41–50 of 92 posts

Re: Project Shield

#41

Earlier quoted context omitted.

Which Google repeatedly vehemently denied. > I’m not sure I can say this more clearly: we’re not in cahoots with the NSA and there’s is no government program that Google participates in that allows the kind of access that the media originally reported. Note that I say "originally" because you'll see that many of those original sources corrected their articles after it became clear that the PRISM slides were not accur…

Which Google repeatedly vehemently denied. Probably because they're forced to do so by the authorities, like Lavebit was. So it becomes a question of who you are going to trust: Snowden (who has nothing to gain by lying) or Google (who is required by law to lie about it and risks losing a lot of money if their customers lose faith in them). I know who I trust in this case.

Can you please state what law you believe would force them to lie about it?

As i've pointed out in a few discussions, the law does not (and generally cannot constitutionally) require you to actively lie about something (IE compelled inaccurate speech). It can require you to not speak about something, compel you to speak truthful things (as a disclosure or otherwise), and require you to not tell someone something, but cannot require you to tell them something that is a lie.

AFAIK, Lavabit was forced to not disclose something to their customers, which fits in with what I said.

There are actually fairly important distinctions, legally, between different types of speech, and important legal distinctions between compelled speech and lack of disclosure. So you can't really paint all of these things with the same brush.

(note: The above is about the US, someone asked me privately, and I have no idea, about other countries)

Re: Project Shield

#42

Seems like its just a straight up competitor to Cloudflare. There doesn't' appear to be any direct revenue gain from this, maybe this is more of a mafia protection kinda thing (as in protecting its interests, the websites hosting its ads). Does anyone know what it takes to mitigate DDoS, at this kind of scale?

That was my impression too.

The simplest way to mitigate a DDOS is to just have way more resources than your attacker. If you're getting hit with 10Gbps, and your site can handle 100Gbps, you're not going to go down. Google obviously has plenty of capacity.

On top of that there are filtering technologies that can block obviously fake traffic or well-known signatures like the LOIC.

The most sophisticated attacks occur at the application level. A Google service would not be able to help configure your install of Wordpress to resist this. But they could probably serve a static cache of your site. Interactive features like login or search would not work though.

Cloudflare does all of these things and more.

The way I read this, Google would not charge for this service. They would select "worthwhile" sites to protect out of the goodness of their heart.

The cynical take is that it is a PR project to help repair their "defenders of the Internet" brand. They built it up with SOPA, but it's been damaged by PRISM.

Re: Project Shield

#44

I can already see the headlines: "Beginning January 1st 2016 Google will discontinue Project Shield"

Guess this is how it's done in the SaaS world? Watch out for repeat of RSS's story -- market got dominated, then the dominating service got plug pulled.

Microsoft really should have patented the `Embrace, Extend, Extinguish' business method back in the day ;-)

Re: Project Shield

#45
post #40

Earlier quoted context omitted.

Call me cynical Cynicism is warranted when it comes to Google. The fact that they gave NSA direct access to their systems; the fact that their Street View cars collected personal information through wi-fi networks, etc. means that "Don't be evil" is just a facade.

Yeah I mean all those people who were broadcasting unencrypted information loud and clear to literally any device that receives wi-fi packets in the immediate vicinity, they have no culpability in this whatsoever!

Using your argument I could say that if you leave your laptop unattended, it's my right to steal it.

The people who left their wi-fi open didn't do it on purpose, and didn't want Google to access their information.

Re: Project Shield

#46
Based on the wording, technology used is going to be a mixture of IP Anycast (traffic sharding) and cache proxying (serve content through), which is what CF does. Except google has all the cash and resources to throw at the problem without putting a dent on their bottom line.

But the interesting tidbit coming out of this project's going to be the internal packet/traffic scrubbing system they've developed. Will it be commercialized or will it spawn a new startup. So many positive outcomes however it ends up.

Re: Project Shield

#47
post #10

Earlier quoted context omitted.

I see big time indirect revenue - with all of a sites actions/users moving through Google, they can gather way more (potentially private) information about a user - all the better to sell targeted ads on. Call me cynical, but that was the first thing I thought of when I saw this.

Call me cynical Cynicism is warranted when it comes to Google. The fact that they gave NSA direct access to their systems; the fact that their Street View cars collected personal information through wi-fi networks, etc. means that "Don't be evil" is just a facade.

Wow, Google is trying to provide DDoS protection and you figure it must be evil.

Can you think of one thing Google could do for you to think that they are not evil?

Re: Project Shield

#49
post #40

Earlier quoted context omitted.

Yeah I mean all those people who were broadcasting unencrypted information loud and clear to literally any device that receives wi-fi packets in the immediate vicinity, they have no culpability in this whatsoever!

Using your argument I could say that if you leave your laptop unattended, it's my right to steal it. The people who left their wi-fi open didn't do it on purpose, and didn't want Google to access their information.

copying isn't the same as stealing.
Post reply on HN