Live data from Hacker News

Google's end-to-end key distribution proposal

code.google.com

81–90 of 95 posts

Re: Google's end-to-end key distribution proposal

#81
post #40
post #27

Earlier quoted context omitted.

As I just posted as a comment to the proposal: In the EU, e-mail addresses are personally identifiable information. It's not clear that an append-only log with no expiration or means for individuals to delete the content will even be legal in many EU countries.

What do you mean? When users sign up to a Key Registry, they are explicitly acknowledging that their emails and public keys can be used in the way described by the protocol. AFAIK, that's perfectly legal.

This assumes all requests are made by the owner of the e-mail address, with sufficient understanding to give consent vs. e.g. an e-mail provider that fails to understand the privacy concerns.

Even then, as pointed out by others, this does not preclude the user from withdrawing consent to continued use of the information.

It may or may not become a legal problem. But they really need to consider the privacy implications and have lawyers that actually know the relevant national laws throughout the EU member states to evaluate it.

Re: Google's end-to-end key distribution proposal

#82
post #63

How will the Key Directories and third party Monitors verify that I'm the real owner of my self-hosted email address user@myowndomain.com, uploading my real public key to the directory?

Depends on what you mean by "verify the real owner". They can verify that whoever has control of what gets uploaded to myowndomain.com also has control of the user@myowndomain.com email account and can prove they have the private key corresponding to the public key that was posted. Is that what you meant?

Re: Google's end-to-end key distribution proposal

#84
post #80

Earlier quoted context omitted.

The whole point is ease of key exchange. Of course if you don't want any hint of your email details out in the world you shouldn't use it.

Ease of key exchange does not justify publishing what is effectively a public ledger of who I start communicating with when.

I think you're misunderstanding the gossip protocol, but, regardless, that was not the claim I was responding to, it was that the disclosure of email addresses (or a hash of them) with no way to remove them from the Key Directory is somehow beyond the pale for a public (and automated) key exchange system.

Re: Google's end-to-end key distribution proposal

#85
post #11

Earlier quoted context omitted.

The blockchain (as most people understand it atleast) is an implementation of a Merkle tree. Which is why Git/Bitcoin are eerily similar - they both utilize Merkle trees for integrity. The real innovation in the "blockchain" was using proof of work in combination with the Merkle tree in order to enforce a single history. Take that away and yes, it looks alot like Git. :)

And if you consider that a git commit is actually "proof of work" and find a way to quantify the value of that commit (fixes issue x which was worth y points, passes all regression tests), you would have... gitcoin.

Git commits can not serve as "proof of work" as the term is normally used, because they are not much easier to verify than they are to generate.

Proof of work is used to limit behavior by adding artificial cost - in hashcash they are used to make spamming more expensive, and in Bitcoin for controlling block creation.

It's not a desirable feature in a protocol if you can avoid it. In the case of coding contributions, it's easier and more reliable to have a central maintainer that accepts patches and pays out bounties.

Re: Google's end-to-end key distribution proposal

#86
Wouldn't proper compartmentalization dictate that email providers be explicitly eliminated from the end-to-end encryption process?

Apart from being able to inspect email and recognize that it contains content that looks like an encrypted form of something, I think we wouldn't want them to be explicitly informed that encryption was used, or know anything about the encryption algorithm, or know anything about how keys were distributed, or see any keys even public ones.

I think this would apply to the general case where someone uses an email service that is run by another party. In the common cases of major email providers with business models that conflict with privacy and security in various ways, the risks would higher. Even before factoring in their being high priority targets for hacking, government surveillance of questionable legality, etc.

Re: Google's end-to-end key distribution proposal

#87

Earlier quoted context omitted.

Thats how google works. Piecemeal. You think loon was about internet for the poor and oppressed ? Thats just how they get their foot in the door. Im sure google just wanted to write a draft spec for the fun of it. Google is a front for US intelligence. We should give no quarter. Shun them.

At the risk of sounding like a fanboy apologist, I must say you're making a lot of serious accusations against a one of the most benevolent company in the history of mankind. Some serious evidence should follow. Picking on Project Loon... come on, is there anything Google could do that you wouldn't immediately label as evil forefront of US intelligence?

Sorry, but google are the furthest thing from benevolent. It's all about data collection to spew more adverts at people.

"Don't be evil... to our shareholders."

Re: Google's end-to-end key distribution proposal

#88
post #59

Earlier quoted context omitted.

Google responds to legal requests for information. The whole PRISM scandal was indicating that the NSA had some kind of direct link into the databases themselves. This assertion is what Google denied, and still denies. There's been a bit of a wandering definition for PRISM, from "they have NSA software with root access to all machines!" to "they receive LEO requests for information, which they review, and sometimes f…

Go look at the slides. The NSA isn't lying in its own internal documents. Of course google is in on it. Do you get how huge this infrastructure is ? Its a massive engineering effort to manage that kind of information flow. What has happened here is google has got scared. Because without trusting users all their business models fall apart. So they are lying. Its that simple.

> Do you get how huge this infrastructure is ? Its a massive engineering effort to manage that kind of information flow.

Which is why it could never happen without it being well known inside Google.

Re: Google's end-to-end key distribution proposal

#89

Earlier quoted context omitted.

At the risk of sounding like a fanboy apologist, I must say you're making a lot of serious accusations against a one of the most benevolent company in the history of mankind. Some serious evidence should follow. Picking on Project Loon... come on, is there anything Google could do that you wouldn't immediately label as evil forefront of US intelligence?

Sorry, but google are the furthest thing from benevolent. It's all about data collection to spew more adverts at people. "Don't be evil... to our shareholders."

Yes, the fact that they're doing nothing bad to their customers today is an evil conspiracy to hide the fact that they want to do something bad to their customers. Makes sense.

> It's all about data collection to spew more adverts at people.

The way they do this is the single most ethical way of doing advertisements. Non-intrusive and trying to predict what you actually need. They're pursuing the ultimate goal of good advertising, i.e. connecting your needs to the best way to satisfy them, but hell, they're evil.

We can discuss side effects and externalities of their data collection, but that's a completely different thing than assuming malice.

Re: Google's end-to-end key distribution proposal

#90

Earlier quoted context omitted.

At the risk of sounding like a fanboy apologist, I must say you're making a lot of serious accusations against a one of the most benevolent company in the history of mankind. Some serious evidence should follow. Picking on Project Loon... come on, is there anything Google could do that you wouldn't immediately label as evil forefront of US intelligence?

The do no evil line is bullshit. This is not a benevolent company by any standard. The services are not free, you are just paying in a different currency. Here is more on loon and look further up for links to the PRISM slides and documentation showing the companies involved including google were compensated financially by the NSA. The evidence is damning. http://m.slashdot.org/story/194413 Look the bottom line here i…

> The do no evil line is bullshit. This is not a benevolent company by any standard.

From the linked Slashdot article - Google patented Loon-related technology, describing it "as just the ticket for those well-to-do enough to pay a tiered-pricing premium to get faster internet access while attending concerts, conferences, air shows, music festivals, and sporting events where a facility's overtaxed Wi-Fi simply won't do."

Picking on this is like saying that Elon Musk is an evil liar, because if he really cared about good of humanity and electric transport for the masses he surely wouldn't start with an superexpensive car for ultra rich, and then move to expensive car for moderatly-rich. Obviously, the whole argument about "Roadster bankrolling Model S bankrolling $35k Sedan" is just a bunch of lies trying to hide how evil he is.

That's basically what I'm reading from your argument.

You know, altruism involves money, and quite often the best way to do something good is to make it profitable.

> Look the bottom line here is these guys betrayed us. They are traitors, and we need to cut them out of our future.

If so, then long, long before Google you need to get rid of GoDaddy, Amazon, Facebook, Microsoft, Apple, BMW, General Motors, General Electric, Coca Cola, Nestle, Walmart, every other mom and pop store and pretty much 90% of other companies who betrayed us in many more ways, heavily documented and not alleged. Seriously, saying that Google Is Bad is nothing but a signalling game around here.

Post reply on HN