Live data from Hacker News

Larry Page addresses PRISM

googleblog.blogspot.com

51–60 of 482 posts

Re: Larry Page addresses PRISM

#51

When I worked IT for a medium sized university we were asked by the DOJ to install switches that copied all internet traffic directly to an unspecified government server. We were told all ISPs (anyone providing internet to more than 100 persons) were told to do this as well. We refused to comply obviously as the request was absurd, but in the small print of the request we were told we were not allowed to speak of the…

Why would they bother asking you, when they could simply ask your ISP? Why ask each customer?

Presumably university IT would have been able to provide more precise demographically identifying data than the ISP. It's unlikely the ISP was running the RADIUS server.

Re: Larry Page addresses PRISM

#52
post #26

Why is everyone so suspicious of Google to begin with? Is there a shred of evidence to lend any credibility to the accusations thus far? Given how Google's technology works, I imagine it would be quite an expense to provide the kind of access the govt. would want and Google hasn't been exactly overly enthused with having to comply with BS government requests(e.g. see how they deal with requests to scrub search result…

US government agencies have money available to them for this sort of things.

Re: Larry Page addresses PRISM

#53

Earlier quoted context omitted.

Which is still pretty flexible language. "Oh, it's not open-ended access, it's limited to the conditions in the authorization..." The Verizon order was limited to 3 months, for example, which is hardly open-ended... except that it presumably got re-upped every three months.

Read the NEXT SENTENCE! "Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have required them to hand over millions of users’ call records." AND THE TWO AFTER THAT: "We were very surprised to learn that such broad orders exist. Any suggestion that Google is disclosing information about our users’ Internet activity on such a scale is completely fals…

"NEXT SENTENCE": I don't think they're a telco with millions of users, Goggle Voice is pretty small, right?

The two after that look like a pretty good denial, though.

Re: Larry Page addresses PRISM

#55

Earlier quoted context omitted.

Please throw out an estimate of how big you think a mirror of all Google's network traffic might be.

And this is relevant to what?

It's relevant because some of the things that are being suggested here on HN are clearly infeasible, from an infrastructure standpoint.

Re: Larry Page addresses PRISM

#56
post #26

Why is everyone so suspicious of Google to begin with? Is there a shred of evidence to lend any credibility to the accusations thus far? Given how Google's technology works, I imagine it would be quite an expense to provide the kind of access the govt. would want and Google hasn't been exactly overly enthused with having to comply with BS government requests(e.g. see how they deal with requests to scrub search result…

The President getting on national television and acknowledging that the program exists is a pretty big shred of evidence.

PRISM can exist, AND they cannot have direct access to Google data. Both can be true.

There is another vector of privacy leakage here - there are also the ISPs, who I am pretty sure work alongside the government in a majorly secretive way.

Re: Larry Page addresses PRISM

#57

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

Couldn't agree more. The key terms used are subject to interpretation. Still not feeling comfortable about this.

Re: Larry Page addresses PRISM

#58

I can't understand the repeated use of "direct access". It's the kind of language a lawyer would use to qualify a patent clause. - We do not provide direct access to our servers. - We do not provide direct access nor is there a backdoor. - O, but we do still pipe all of your data to external NSA servers. Every company named (I'm not just picking on Google here) has come out with the same overarching statement. "We do…

They're using the phrase "direct access" because that phrase appeared in the leaked NSA slides.

Re: Larry Page addresses PRISM

#59

When I worked IT for a medium sized university we were asked by the DOJ to install switches that copied all internet traffic directly to an unspecified government server. We were told all ISPs (anyone providing internet to more than 100 persons) were told to do this as well. We refused to comply obviously as the request was absurd, but in the small print of the request we were told we were not allowed to speak of the…

Please throw out an estimate of how big you think a mirror of all Google's network traffic might be.

They don't need to access to all network traffic, just the interesting bits, like e.g. the internal traffic for the storage/backup systems used for GMail or Google Accounts .

Re: Larry Page addresses PRISM

#60

When I worked IT for a medium sized university we were asked by the DOJ to install switches that copied all internet traffic directly to an unspecified government server. We were told all ISPs (anyone providing internet to more than 100 persons) were told to do this as well. We refused to comply obviously as the request was absurd, but in the small print of the request we were told we were not allowed to speak of the…

Why would they bother asking you, when they could simply ask your ISP? Why ask each customer?

The program and requirements were somewhat surreal. The architecture of the plan seemed to make little to no sense.

They considered anyone who provided internet access to 100's of people a provider (mostly universities etc) and requested that they install the pre specified hardware at their own expense (purchase, installation and maintenance).

They may have been concerned specifically with universities due to their foreign students and access to certain backbone lines that normal ISP's dont always have (WWW2?).

I spoke with the EFF and I was told I wasn't alone, but most people were rejecting the 'request' and not suffering any consequences. Our IT director took a hard line on the topic and tried to speak openly to reporters about how much the request offended him. He got as far as the school newspaper as in 2005 most people didn't understand the ramifications of this activity.

Post reply on HN