Live data from Hacker News

On Confirmed Assumptions or, Not Trusting Google is a Good Idea

anarchism.is

51–60 of 230 posts

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#51

Earlier quoted context omitted.

How about "not trusting 3rd party with your (unencrypted) data"?

Why are you trying to deflect attention away from Google?

I am not. Google is only doing what it is forced to. I am activly searching for google alternatives. Ghostly app on iphone, ghostly for firefox, duckduck, but a good mail client? With easy encription? Not available...

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#52
post #48
post #24

How, in short, is this shit valid under the U.S. Bill of Rights? I’d really like someone to explain that to me. With a straight face. Preferably without making me want to punch them in the process. Well, he's going to want to punch me, but here's what I think(?) the answer is: (a) He's not a US person, but instead a well-known citizen of Iceland, living abroad, and is thus not protected by the Fourth Amendment, at le…

The legal theory that the bill of rights only applies to US citizens is dangerous and wrong. It applies to actions of the United States government. It is a list of things they may not do.

That's a theory that suggests all spying is unconstitutional.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#53
post #23

Google is spyware. This has been obvious for a long time. Most other "free" web services aren't much better. It's sad that it's taken so long for people to start realizing and caring about this, but better late than never.

>Most other "free" web services aren't much better.

Most non-free web services are equally happy giving away your data to the government. Apple, MS and all the other companies are no better than Google.

And Google is not the problem -- it is just a symptom. The problem is the government that does not respect the rights of people.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#54
post #42
post #37

Earlier quoted context omitted.

It's both. If you are going to use a cloud service, you have to trust both the provider and the government where they operate. (With the exception of things like tarsnap).

>(With the exception of things like tarsnap). The chain of trust still extends to them. You're trusting that they're actually doing everything they say they're doing. If you don't own the hardware and the building where the hardware is, you have to trust that they're doing everything you want them to be doing.

Tarsnap encrypts the data on the client side[0].

The source is open, and signed with PGP.

The data ends up being stored on S3, but the location doesn't matter.

[0] https://www.tarsnap.com/crypto.html

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#55
post #48
post #24

How, in short, is this shit valid under the U.S. Bill of Rights? I’d really like someone to explain that to me. With a straight face. Preferably without making me want to punch them in the process. Well, he's going to want to punch me, but here's what I think(?) the answer is: (a) He's not a US person, but instead a well-known citizen of Iceland, living abroad, and is thus not protected by the Fourth Amendment, at le…

The legal theory that the bill of rights only applies to US citizens is dangerous and wrong. It applies to actions of the United States government. It is a list of things they may not do.

Some of the bill of rights is that, and some clearly refers to things protecting "the people". I am no constitutional scholar, but this does seem to indicate that those specific rights are rights that are intended to apply to citizens of the US.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#56
post #28

Earlier quoted context omitted.

Maybe engineer a service that is harder to wiretap? It is not easy, but they have some of the best computer scientists on this planet working for them. If I were them, I would start somewhere around here: http://crypto.stanford.edu/adnostic/adnostic.pdf

It's not directly apropos this particular thread, but Google has engineered an email service that is particularly difficult to wiretap. To wit: (a) They're the Internet's foremost adopter and proponent of DHE ciphersuites, which drastically reduce the impact of losing the RSA key that underpins most site's TLS security, and, just as importantly, forces adversaries to actively MITM every connection in order to decrypt…

Difficult to wiretap in the sense of intercepting communications to and from Google, yes.

But it's also engineered to give Google itself access to your data so they can improve their behavioral profile of you.

I think what people are suggesting is that if end user privacy was Google's priority rather than gaining access to user data for their own use, they could engineer a service that didn't place themselves as a man-in-the middle.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#57
post #23

Google is spyware. This has been obvious for a long time. Most other "free" web services aren't much better. It's sad that it's taken so long for people to start realizing and caring about this, but better late than never.

I completely agree with you.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#58
post #42
post #37

Earlier quoted context omitted.

It's both. If you are going to use a cloud service, you have to trust both the provider and the government where they operate. (With the exception of things like tarsnap).

>(With the exception of things like tarsnap). The chain of trust still extends to them. You're trusting that they're actually doing everything they say they're doing. If you don't own the hardware and the building where the hardware is, you have to trust that they're doing everything you want them to be doing.

  > The chain of trust still extends to them. You're
  > trusting that they're actually doing everything
  > they say they're doing.
Tarsnap performs encryption in the client, which is distributed only as source code. If you audit the client sufficiently to believe it is properly encrypting your data, then there is no need to trust the server or the hosting provider.

Re: On Confirmed Assumptions or, Not Trusting Google is a Good Idea

#59
post #48
post #24

How, in short, is this shit valid under the U.S. Bill of Rights? I’d really like someone to explain that to me. With a straight face. Preferably without making me want to punch them in the process. Well, he's going to want to punch me, but here's what I think(?) the answer is: (a) He's not a US person, but instead a well-known citizen of Iceland, living abroad, and is thus not protected by the Fourth Amendment, at le…

The legal theory that the bill of rights only applies to US citizens is dangerous and wrong. It applies to actions of the United States government. It is a list of things they may not do.

No, tptacek is right... if you are a foreigner living abroad, the bill of rights does not apply to you:

In 1957, the court changed its position, overturning decades of precedent to declare that American citizens are in fact protected against U.S. government misbehavior by the Bill of Rights even outside the country. Unfortunately for the rest of the world, the court limited its ruling to U.S. citizens. Foreigners remained stuck with the old rule that the Bill of Rights doesn't apply abroad.[0]

So US citizens are protected whether they are within US borders or abroad. And foreigners are protected if they are within US borders... but once they leave, it no longer applies.

[0]. http://articles.latimes.com/2005/dec/16/opinion/oe-raustiala...

Post reply on HN