Live data from Hacker News

Google reveals its servers all contain custom security silicon

theregister.co.uk

81–90 of 129 posts

Re: Google reveals its servers all contain custom security silicon

#81

Earlier quoted context omitted.

This is not really true. Not "once you reach a certain size", but once you move off the lowest-tier starter hardware, cloud quickly becomes much more expensive than owning hardware, and security solutions continue to depend on the individual administrators (most backups do too). Cloud's biggest benefit is really convenience, because you don't need to go to the datacenter and put in another hard drive yourself when yo…

For "convenience" substitute "having the technical sophistication to manage it properly". How many companies know enough to hire and retain top-notch people to run a datacenter and keep upgrading it?

Renting a rack is not the same as running a data center. The technical sophistication is available. It can be hired on the employment market or contracted as an ad-hoc service. Many colos offer a hands fee to have their staff do things like install disks on your behalf, and there is always the traditional managed server.

Chasing the cloud has cost companies a massive amount of money. I'm familiar with companies that would've saved nearly a million bucks a year by staying on bare metal/in-rack hypervisor. They weren't forced into the cloud by a shortage of people who could perform hardware maintenance, they went because it was the hip thing to do.

Re: Google reveals its servers all contain custom security silicon

#82
post #60
post #40

Earlier quoted context omitted.

Exactly, and I think it's worth noting that they likely only apply this level of security because of state actors. Which then shows that they are trying to prevent eavesdropping by NSA & Co., they probably just realized too late how far advanced they were.

Which then shows that they are trying to prevent eavesdropping by NSA & Co. Why would the NSA eavesdrop on Google, they are in bed with them, aren't they?

Snowden revealed the opposite: https://cdn.grahamcluley.com/wp-content/uploads/2013/10/nsa-... NSA actively tries to eavesdrop on Google.

Re: Google reveals its servers all contain custom security silicon

#83

This is another signal of an interesting development on the hardware front. What used to be decoupled, with some companies offering hardware, and different companies buying hardware, is now coupled and hidden within these mega-companies (Google, Amazon, FB). Google is big enough to develop a trusted hardware solution for internal use only, it has no financial need to sell it. Worse, due to competitiveness in the clou…

Looking at what's going on in Shenzhen[1] in regards to hardware hacking, I'm not worried.

[1] https://youtu.be/SGJ5cZnoodY

Re: Google reveals its servers all contain custom security silicon

#84
post #76
post #70

Earlier quoted context omitted.

For me, the whole takeaway of the Snowden leaks was that the NSA can legally force Google (or anyone) to hand over basically anything, am I mistaken? Articles like [1] seems to underline they are indeed working together. [1] http://www.huffingtonpost.com/2014/05/06/nsa-google_n_527343...

The Snowden disclosures did not suggest that Internet companies like Google were coordinating with NSA. The disclosures suggested that NSA was wiretapping all traffic across the Internet, and then parsing it, storing it, and indexing it so as to be able to make sense of what traffic represented e.g. a Google web search, and then search that semantically later. Because at the time Google did not use encryption in thei…

Google was requested large amounts of data by the NSA since ~2007 [1]. They were might or might not ordered to keep silent about it. They only started to address it as a reaction to the Snowden revelations. Additionally, there are letters such as linked above that show they are in fact very friendly with the NSA. One can argue they were caught red handed with little to nothing like an email here and there, but circumstantial evidence shows otherwise.

Personally I would go further, those multi billion dollar companies should have found a way to speak up if a contractor was able to, not just after the fact.

[1] https://en.wikipedia.org/wiki/PRISM_%28surveillance_program%...

Re: Google reveals its servers all contain custom security silicon

#85
post #79
post #70

Earlier quoted context omitted.

For me, the whole takeaway of the Snowden leaks was that the NSA can legally force Google (or anyone) to hand over basically anything, am I mistaken? Articles like [1] seems to underline they are indeed working together. [1] http://www.huffingtonpost.com/2014/05/06/nsa-google_n_527343...

If the NSA could force Google to hand over anything, why were there Snowden slides showing that the NSA was secretly tapping Google's internal networks? https://www.washingtonpost.com/world/national-security/nsa-i...

The infiltration is especially striking because the NSA, under a separate program known as PRISM, has front-door access to Google and Yahoo user accounts through a court-approved process.

I don't know. Maybe it is easier than going to court all the time? Who knows?

Re: Google reveals its servers all contain custom security silicon

#86
post #15
post #10

Earlier quoted context omitted.

It's a sign of changing times indeed, but for the consumer's benefit. It is absolutely in Google's best interests to externalize security for its customers as a differentiator of Google Cloud. The parent article itself links to the white paper that outlines how this is done for Google Cloud. I understand how one may consider this a "closed ecosystem" from one perspective. However, from a customer point of view any st…

> I understand how one may consider this a "closed ecosystem" from one perspective. However, from a customer point of view any startup or mom-and-pop can leverage these very complex and expensive world-class security developments, whereas in the past this access has been reserved to the very select few that could afford it. When the barrier to entry is lowered and access is commoditized, customer wins. I don't unders…

You can't have an open ecosystem when part of the ecosystem is hundreds if not thousands of full-time security experts and 24x7 opsec analysts. It is an integrated software and operations system. The software alone doesn't get you anywhere.

Re: Google reveals its servers all contain custom security silicon

#87
post #75
post #45

Earlier quoted context omitted.

> Didn't also Facebook started some open server hardware initiative? I don't remember what happened with that... It's alive and well, but not newsworthy, thus phased out of public's attention span.

Could you link?

https://en.m.wikipedia.org/wiki/Open_Compute_Project

Re: Google reveals its servers all contain custom security silicon

#88
post #75
post #45

Earlier quoted context omitted.

> Didn't also Facebook started some open server hardware initiative? I don't remember what happened with that... It's alive and well, but not newsworthy, thus phased out of public's attention span.

Could you link?

http://opencompute.org/

Re: Google reveals its servers all contain custom security silicon

#89
post #78
post #72

Earlier quoted context omitted.

An abusive, rapey relationship is not the same thing as being "in bed".

That link is anything but an abusive relationship. Still, I fail to see how silicone is a countermeasure to a court order.

When Google has its networks compromised and is routinely compelled to comply with NSLs, I'd say that counts as abusive.

Re: Google reveals its servers all contain custom security silicon

#90
post #62
post #21

Earlier quoted context omitted.

More ground is lost in the cold[1] civil war[2] for control of the General Purpose Computer. I hope that everyone choosing to centralize computing power likes the future they are creating. [1] https://www.youtube.com/watch?v=nT-TGvYOBpI#t=2824 (sec. 10 - http://geer.tinho.net/geer.blackhat.6viii14.txt ) [2] http://boingboing.net/2012/08/23/civilwar.html

What is different about centralized compute power compared with centralized energy production?

I never read the War On General purpose computing being about centralization as much as DRM restrictions on content and restricted developer support. In other words, it's not about deploying to the cloud versus deploying to a billion individual devices. It's about not deploying anywhere at all.
Post reply on HN