Live data from Hacker News

Re:publica 15: Google Promotes Privacy, But Not Too Much

tutanota.de

61–70 of 79 posts

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#61

Does this surprise anyone? Google has contradictory interests when it comes to encryption and privacy. It has been at the forefront of pushing SMTP to SMTP encryption and HTTPS everywhere. Google has to spread (and perhaps seriously believes in) the idea that they transfer data securely, unreadable by the Five Eyes. Because the perception that Google is in bed with the NSA et al. is seriously undermining their reputa…

I care about privacy but with some restrictions I still use Google, Twitter, and Facebook.

I did switch off of gmail for general use, but I forward some emails to my old gmail account for experimenting with Google Now on my Android phone. For example, I will forward emails confirming airline reservations and car rentals so that information ends up in Google Calender and Google Now. For the same reason I sometimes will turn on location services on my phone.

I use Firefox for my web browsing, but use Chrome when visiting Google, Facebook, and Twitter web properties. I check cookies set in Firefox to make sure I have not enabled tracking.

I am making some real compromises in privacy and convenience, but for now this 'middle road' works for me.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#62
post #55

Earlier quoted context omitted.

Paper envelopes dating back to 2300 years ago in China at least provides evidence for you being wrong. User-unfriendliness ≠ "not meant for"

Fine. End-to-end crypto requires key authentication. This means that users must have some way of authenticating a key. For the majority of people, this is too much. People should not be expected to spend time manually checking the signatures on a key, and should likewise not be expected to get signatures for their key. They should not have to worry about key revocation. If a solution is not as easy as email is at the…

> Yet, there is seemingly no compelling answer to them that doesn't involve bringing your passport to a key signing party.

The only reason I trust the source of an email by its "from" address is because of the history of correspondence with that person from that address. Yes, if it is compromised, I may not realize it right away, or I may (see: phishing emails from virus/malware infestations), but by and large it works as advertised.

Same thing with usernames in forums. There's a certain cred that is eventually attached to a username over time.

If I use the same public key to represent myself in all my communication "for a while", then there's implicit trust that it's me there, for the same reasons.

Key revocation is admittedly not as simple, if I want to continue to maintain my "trust balance" somehow. What happens if I switch email addresses? "Hi guys, this is my new email address." What if I was compromised and someone else did that? (Well, how often does that happen in real life?)

Perhaps you could keep one key super secret (and offline) and sign all new day-to-day keys with it. I don't know.

What I'm saying is- Treat it like email. Forget trying to centralize who owns what key. Forget trying to exercise absolute control over trust in a given key. The key(s) I use "most of the time" is "me". If I need to revoke it, I will suffer some in the short term, but I will quickly build my cred back up by using a new one.

If it was more widespread then perhaps we could centralize SOME third-party signing. Say I could go to a bank and they could sign my key saying "this key definitely belongs to lectrick", and it would work because the bank's public key is known-trusted.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#63
post #41

Earlier quoted context omitted.

What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?

At least in the US, 'ex post facto' laws are specifically forbidden by the Constitution: http://en.wikipedia.org/wiki/Ex_post_facto_law

True, but the US government doesn't even pretend to follow the Constitution anymore.

Also, the Constitution can be amended. We can't guarantee that ex post facto laws will remain unconstitutional for the duration of your lifetime.

Also, states are technically not obliged to abide by the US constitution.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#64
post #63

Earlier quoted context omitted.

At least in the US, 'ex post facto' laws are specifically forbidden by the Constitution: http://en.wikipedia.org/wiki/Ex_post_facto_law

True, but the US government doesn't even pretend to follow the Constitution anymore. Also, the Constitution can be amended. We can't guarantee that ex post facto laws will remain unconstitutional for the duration of your lifetime. Also, states are technically not obliged to abide by the US constitution.

The first and last paragraphs are incorrect; you may disagree that the federal government actually follows the Constitution, but that's a different issue. And while many provisions of the Constitution address only the federal government, States are still bound by it to the extent it addresses them, as it does, among other places, in the 14th Amendment.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#65
Just brainstorming here. Here are a few ways in which you can get in trouble with the law because of unencrypted online communications (these are ordered from most likely to occur within 1 human lifetime to least likely to occur within 1 human lifetime, IMO):

1. You could travel to another country where they arrest you for something unencrypted you did online in a country where it was legal. This has already happened. [1]

2. Your communications could become evidence in court that you "always had radical leanings." So while you're not convicted for what you did online, it still becomes evidence against you. I suspect this has already happened.

3. You could travel to another country where retroactive laws are allowed, and get caught because of something you said in the past in the US.

4. The US could eventually allow retroactive laws, and catch you for something you did before retroactive laws were allowed.

Note: these are just ways you could get in trouble with the law; not mentioned are things like your reputation being destroyed, death threats, identity theft, or malware due to lack of encryption. I also have not mentioned ways in which your friends could get in trouble because of something unencrypted you did online.

[1] http://www.cnn.com/2015/03/05/middleeast/american-arrested-i...

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#66
post #48

Earlier quoted context omitted.

Same here. But I also pay Google for various services, and the lack of privacy bothers me enough that I would readily pay Google the relatively small amount I'm worth to them as a data source in order to get privacy. THAT's where Google's position, or at least this Google spokesman's position is wrong: I'll give up both some convenience and some money to get more privacy.

But that's exactly the conflict: Google doesn't want your money, they want your data. Paying for more privacy is not and probabably will never be an option.

Ehhhhh. "Google, would you trade ad revenue for the same or larger subscription revenue?" I think the answer would be yes.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#67
post #63

Earlier quoted context omitted.

True, but the US government doesn't even pretend to follow the Constitution anymore. Also, the Constitution can be amended. We can't guarantee that ex post facto laws will remain unconstitutional for the duration of your lifetime. Also, states are technically not obliged to abide by the US constitution.

The first and last paragraphs are incorrect; you may disagree that the federal government actually follows the Constitution, but that's a different issue. And while many provisions of the Constitution address only the federal government, States are still bound by it to the extent it addresses them, as it does, among other places, in the 14th Amendment.

The first paragraph is correct because I clearly meant it in figurative language, not literal language. Regardless, my point is this: the US government does not obey the US constitution.

The last paragraph is correct in context. Specifically, with regards to encryption, states are allowed to do whatever they want because the Constitution doesn't mention encryption and because of the 10th amendment, which states:

The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people.

The last paragraph is also correct because the ex post facto law clause of the Constitution only applies to Congress, not the states [1]

[1] https://en.wikipedia.org/wiki/Article_One_of_the_United_Stat...

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#68
post #55

Earlier quoted context omitted.

Fine. End-to-end crypto requires key authentication. This means that users must have some way of authenticating a key. For the majority of people, this is too much. People should not be expected to spend time manually checking the signatures on a key, and should likewise not be expected to get signatures for their key. They should not have to worry about key revocation. If a solution is not as easy as email is at the…

> Yet, there is seemingly no compelling answer to them that doesn't involve bringing your passport to a key signing party. The only reason I trust the source of an email by its "from" address is because of the history of correspondence with that person from that address. Yes, if it is compromised, I may not realize it right away, or I may (see: phishing emails from virus/malware infestations), but by and large it wor…

I'm afraid that fundamentally doesn't work (though at first glance it does). Email is not a forum - it's person to person. When someone emails me, I might not know anyone else who has also had a conversation with them.

In order for anyone to trust your key at all you need to make it available out of band.

This is because otherwise, your email provider could simply man-in-the-middle you (or them); and they have no way of working out.

The first time they email you, their key is already compromised. You then build up your trust for them; but you've trusted an attacker. The system is worse than useless.

This is worse than (say) TLS because TLS, you generally do not connect through a single access point. Email is far more centralised.

So, they need to get your key from outside the communication system, somehow.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#69

I don't need the extra security provided by end-to-end encryption for the vast majority of emails I receive and send. I value that ability to search/filter these emails far more than I value the security. For the few emails I send where the value of the security provided exceeds the lost value due to being unable to search I can, using their extension, enable end-to-end encryption. This system suits my needs perfectl…

Would you share your mails with us then?

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#70
post #69

I don't need the extra security provided by end-to-end encryption for the vast majority of emails I receive and send. I value that ability to search/filter these emails far more than I value the security. For the few emails I send where the value of the security provided exceeds the lost value due to being unable to search I can, using their extension, enable end-to-end encryption. This system suits my needs perfectl…

Would you share your mails with us then?

I am so tired of this response.

Claiming that I don't personally feel the need for a fully enclosed, solid steel cubicle to get changed in doesn't mean I'm happy to get naked in public. I feel that whilst the changing cubicle you find at a public swimming pool wouldn't prevent a determined actor from invading your privacy it provides adequate privacy for me.

Yes, servers at Google can read my email - I'm willing to accept the risk of a Googler committing a fireable offence and going through my emails.

Post reply on HN