Live data from Hacker News

Re:publica 15: Google Promotes Privacy, But Not Too Much

tutanota.de

71–79 of 79 posts

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#71
Is Google's Eric Grosse familiar with anonymous authentication techniques over Tor?

Because there are at least two projects which address this: FAUST and Fair Anonymity:

http://arxiv.org/pdf/1412.4707v1.pdf

https://gnunet.org/node/1704

I very strongly encourage Eric to have his team look at these, or other options, and back the motherluving frell out of whatever seems viable.

Listening to his Re:publica conversation with EFF's Jillian York, the topic comes up, but best I can tell he doesn't know of these.

At 17m 50s in the presentation, the question of using Google services over Tor is raised.

That's ... an issue I've had some experience with:

"How to kill your Google account: Access it via Tor"

https://www.reddit.com/r/dredmorbius/comments/2w618r/how_to_...

First off, I totally get the abuse angle. Most of my specific complaint with my own experience wasn't over Google's challenge process to my attempted Tor access. Rather, it was over the company's policies and procedures for account recovery. Multi-factor auth is well and good, but I've yet to find a way to activate an option other than phone-based auth without providing Google with a phone number. Which for a number of valid reasons I cannot or will not do.

(Grosse states that "you should not even have to give us a phone number", and that there are internal debates on the subject. Yay.)

More specifically, the problem is that the question "Who are you?" is proving to be the most expensive operation in all of computing. Because you're fucked either way you get it wrong. Lock someone out when you should let 'em in, and you're fucked. Let someone in when you should've locked 'em out, and you're fucked. And all you get to look at is 1s and 0s on the wire.

I detail that in more length in this comment to my dreddit post:

https://www.reddit.com/r/dredmorbius/comments/2w618r/how_to_...

(I'll also note that Grosse specifically notes that PKI works great, ahem, Yonatan Zunger....)

So: first, Google's really got to revise and fix its account recovery processes.

But that identity thing: Grosse goes on at length noting that Tor exit nodes aggregate a lot of traffic activity, and that Google effectively relies strongly on IP address as an indicator of identity.

The fair, and anonymous, reputation systems mentioned above are specifically intended to work over Tor. Which is to say, people are tackling the problem. Nothing in Grosse's presentation gave any indication that he's aware of this fact. For sheer technical competence reasons, he should be.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#72
post #41

Earlier quoted context omitted.

Agreed. The question is. Can you perfectly, always and with regard for potential future changes to what may be sensitive information decide which ones to encrypt? One email sent the wrong way when tired. One change in legislation (to e.g. retrospectively criminalise an activity or legalise a certain type of snooping). Now your company's IP is compromised. Or now your in jail. Or now you can be blackmailed. Furthermor…

What insane law system makes an action retrospectively criminal ? Does the US law system allows this ?

Jurisdictions change.

"Ukraine’s Parliament Votes To Open Soviet-Era KGB Archives To Public" http://www.ibtimes.com/ukraines-parliament-votes-open-soviet...

In "The Internet With a Human Face", Maciej Cegłowski asks:

"What happens if Facebook goes out of business, like so many of the social networks that came before it? Or if Facebook gets acquired by a credit agency? How about if it gets acquired by Rupert Murdoch, or taken private by a hedge fund?

"What happens to all that data?"

http://idlewords.com/bt14.htm

That's just one of the problems we're facing.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#73
post #69

Earlier quoted context omitted.

Would you share your mails with us then?

I am so tired of this response. Claiming that I don't personally feel the need for a fully enclosed, solid steel cubicle to get changed in doesn't mean I'm happy to get naked in public. I feel that whilst the changing cubicle you find at a public swimming pool wouldn't prevent a determined actor from invading your privacy it provides adequate privacy for me. Yes, servers at Google can read my email - I'm willing to a…

It's not just Googlers who might do that.

Google's been attacked by national intelligence agents. Notably from China, targeting emails of Tibetian activists. With potentially life-ending condequences.

Hackers and theives. Corporate takeovers. The NSA, or GRU, or Mossad, or MI6, ore any of the other various state intelligence agencies throughout the world. Drugs gangs throughout Central and South America. Rogue contractors have been known to walk out of Google with gigabytes of highly secure information. Oh, my error, that was the fucking National Security Agency.

If Google can read your email, anyone can. The only question is how the dice roll.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#75
post #18

Earlier quoted context omitted.

Why not encrypt the routing separately?

Remember that those were different times. Computer science itself was born by trying to break that crypto, and modern cryptography wasn't available. A different key for each vessel would mean several passes through the encryption machine, key tables distributed through several places, and the requirement of specialized workforce where otherwise just typing stuff in a machine would do. And all the errors that come wit…

Computer science itself was born by trying to break that crypto, and modern cryptography wasn't available.

^^^ That.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#76
post #17

From my perspective, what I miss with decryption only in the client (where the mail database is stored encrypted) is search. That's also the primary value of Google Apps for me. Easy encryption across the Internet would be more valuable to me than encrypted storage, but the option to have encrypted storage for things that are really private would make sense. I tend to opt for alternate channels with no storage in tho…

> what I miss with decryption only in the client ... is search Yet another casualty of "software as a service". There could be better search tools on the client, but the fad for the last decade has been to push vendor lock-in and data mining instead of installable client apps. So now the full consequences of those choices are starting to be recognized.

Installable client apps just don't work from me. I need to access the same email database from 4 different devices, including some I don't own and don't want the data on.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#77
post #66

Earlier quoted context omitted.

But that's exactly the conflict: Google doesn't want your money, they want your data. Paying for more privacy is not and probabably will never be an option.

Ehhhhh. "Google, would you trade ad revenue for the same or larger subscription revenue?" I think the answer would be yes.

Most companies, yes. Google, no.

It's completely against their current models. They're basically telling advertisers: You know that product we were selling you, that made us billions of dollars together? We're not selling it to you anymore, but it's still making us money.

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#78
post #17

Earlier quoted context omitted.

> what I miss with decryption only in the client ... is search Yet another casualty of "software as a service". There could be better search tools on the client, but the fad for the last decade has been to push vendor lock-in and data mining instead of installable client apps. So now the full consequences of those choices are starting to be recognized.

Installable client apps just don't work from me. I need to access the same email database from 4 different devices, including some I don't own and don't want the data on.

Then your requirements are in conflict with security. You cannot trust the network to do your encryption for you, and you can't trust a a computer you don't own to handle your private key.

You may want to reconsider either dedicating some sort of portable device to be your email that you carry with you, a multi-account system the separates private email from the the email you can access remotely, or resigning yourself and those communicate with to sending using only postcards (non-end-to-end-encrypted email).

Re: Re:publica 15: Google Promotes Privacy, But Not Too Much

#79

Earlier quoted context omitted.

I am so tired of this response. Claiming that I don't personally feel the need for a fully enclosed, solid steel cubicle to get changed in doesn't mean I'm happy to get naked in public. I feel that whilst the changing cubicle you find at a public swimming pool wouldn't prevent a determined actor from invading your privacy it provides adequate privacy for me. Yes, servers at Google can read my email - I'm willing to a…

It's not just Googlers who might do that. Google's been attacked by national intelligence agents. Notably from China, targeting emails of Tibetian activists. With potentially life-ending condequences. Hackers and theives. Corporate takeovers. The NSA, or GRU, or Mossad, or MI6, ore any of the other various state intelligence agencies throughout the world. Drugs gangs throughout Central and South America. Rogue contra…

I'm happy to accept that risk
Post reply on HN