Live data from Hacker News

Re:publica 15: Google Promotes Privacy, But Not Too Much

tutanota.de

41–50 of 79 posts

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#41

I don't need the extra security provided by end-to-end encryption for the vast majority of emails I receive and send. I value that ability to search/filter these emails far more than I value the security. For the few emails I send where the value of the security provided exceeds the lost value due to being unable to search I can, using their extension, enable end-to-end encryption. This system suits my needs perfectl…

Agreed. The question is. Can you perfectly, always and with regard for potential future changes to what may be sensitive information decide which ones to encrypt? One email sent the wrong way when tired. One change in legislation (to e.g. retrospectively criminalise an activity or legalise a certain type of snooping). Now your company's IP is compromised. Or now your in jail. Or now you can be blackmailed. Furthermor…

What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#42

Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…

Unfortunately their services are too convenient. I use them for almost everything I can, my reason being that they already know enough about me from my google searches, so I might as well use every other service they have.

Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#43

Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…

Google's approach makes sense if you assume that it's trying to sell more seats for its g-things-for-business suite. End-to-end encryption hobbles the search function, which makes gmail-for-business less useful. Transport encryption bothers eavesdroppers while leaving search intact.

FWIW, Wikipedia says Google has five million customers for the gmail-for-business product, each of which pays $50-60 per year per user. If you assume an average of two employees per customer that's a half-billion dollars per year. If you believe the numbers in e.g. http://www.quora.com/How-much-does-Google-earn-from-ads-per-... the ad-supported gmail revenue must be peanuts by comparison.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#44
post #42

Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…

Unfortunately their services are too convenient. I use them for almost everything I can, my reason being that they already know enough about me from my google searches, so I might as well use every other service they have. Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.

If you are fine with giving your life to Google, another thing to consider are others. Anyone who wants to communicate with you via e-mail also surrenders their private communication to you to Google.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#45
post #41

Earlier quoted context omitted.

Agreed. The question is. Can you perfectly, always and with regard for potential future changes to what may be sensitive information decide which ones to encrypt? One email sent the wrong way when tired. One change in legislation (to e.g. retrospectively criminalise an activity or legalise a certain type of snooping). Now your company's IP is compromised. Or now your in jail. Or now you can be blackmailed. Furthermor…

What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?

I think you can start investigating Joe for an email he sent 10 years ago and that your scanning algorithm picked up from the archive only now. Maybe you're searching for matches with different keywords (the X in "war on X" changed). That email and the actions could have been lawful at the time and now, but Joe could be marked as suspicious and all sort of unpleasant things can happen to him and his friends.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#46
post #23

https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html In case anybody hasn't read it yet, Philip Zimmermann's essay on why he wrote PGP is very relevant to this discussion. Google is effectively saying envelopes are not meant for common use. Did you send everything by postcard back in the snail-mail days, only using an envelope when the contents was very-important? If someone saw you mailing an envelope, did the…

Totally agree. The fact we happily send so much data around :/ clear text has always irked me. The only layer of protection is that there's probably no one interested enough to look

"No one" assumes a human. I'd use a COTS textural analyzer and social graph and process all your (and your associates) content in one fell swoop.

And then sell that to the highest bidder.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#47
post #42

Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…

Unfortunately their services are too convenient. I use them for almost everything I can, my reason being that they already know enough about me from my google searches, so I might as well use every other service they have. Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.

> my reason being that they already know enough about me from my google searches

You could.. you know... change that.. https://duckduckgo.com

> Also, I'm not from the US so MY government doesn't have access to their data

Because the US doesn't have any allies that participate in data sharing, and definitely doesn't intercept data in transit over the greater internet and on Google's internal network...

Oh wait..

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#48
post #42

Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…

Unfortunately their services are too convenient. I use them for almost everything I can, my reason being that they already know enough about me from my google searches, so I might as well use every other service they have. Plus they're encrypted so only they know it. Also, I'm not from the US so MY government doesn't have access to their data.

Same here. But I also pay Google for various services, and the lack of privacy bothers me enough that I would readily pay Google the relatively small amount I'm worth to them as a data source in order to get privacy.

THAT's where Google's position, or at least this Google spokesman's position is wrong: I'll give up both some convenience and some money to get more privacy.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#49

I don't need the extra security provided by end-to-end encryption for the vast majority of emails I receive and send. I value that ability to search/filter these emails far more than I value the security. For the few emails I send where the value of the security provided exceeds the lost value due to being unable to search I can, using their extension, enable end-to-end encryption. This system suits my needs perfectl…

Actually, yes you do. Unless encryption is everyday and used for mundane messages, it becomes a label that says: "Target this guy and his encrypted traffic."

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#50
I tried to use PGP (gnupg) but it doesn't seem to be simple even for an advanced user. Since I use Debian already it means that I implicitly trust Debian maintainers. So I explicitly trusted one Debian maintainer in gnupg. From there I thought that verifying other keys would be a breeze since I have a trusted guy in the strong set. While there are online tools (at least one) to find trust paths between IDs I didn't find a tool that does this automatically and verify signatures through this. This should be seamless without manually tracking down trust paths, manually importing keys that I don't want just to verify an ID 2-4 hops away.

Here is my concern with the WOT: it's not clear what signatures mean. It could mean "This guy can give out valid signatures" or "I verified that this guy's name is John Doe" or "This is the key used to sign Debian isos", but these are all implicit. Typically it's the first two which makes it hard to use PGP with pseudonyms. When you verify a signature in PGP you want the following chain:

o--I trust this guy's signatures-->o--I trust this guy's signatures-->o--I know this guy-->o

Other concerns: any way to rotate the master key would be nice. I wouldn't assume that my master key won't be compromised in the next 50 years .Then I would have to rebuild my whole WOT and revoke my previous master key (If I can). Key distributon should be decentralized.

Maybe I'm missing something, but this is my takeaway and I really tried to like PGP and gnupg. Maybe Google will solve some of these concerns on their interface but I wouldn't bet on it. I'm not surprised that PGP isn't widely used. I would really like a safe end-to-end encryption implementation that is easy to use.

Post reply on HN