Oh, the hypocrisy.... > "Bypassing that system is illegal for a good reason." Yes, so is invasion of privacy. Yet Google has no problem breaking the law and violating civil rights for profit. > "Unfortunately we live in a world where all too often, laws are for the little people." Yeah, like tax laws and privacy laws... If you want to get on this high horse, you shouldn't be working for Google.
I totally agree. And I was even more stumped by Eric Schmidt's hypocritical blathering.
This from the guy, who blacklisted CNN for reporting on him based on information found on Google.
The only published information is how the values are encoded, not what is encoded (the specifications aren't transported together with the data) so to crack 1622 different protocols only involved in authorization according to the NSA slide is not such a small task, at least if they are interested in more than just recognizing e-mail addresses which can be found using regexps. And just counting the protocols proves th…
The screenshots of the ascii dump of the RPC calls shown in the WaPo article show that there is tons of information to work with, besides just the email account. You're talking about the NSA here, an outfit which has cracked the cryptosystems of foreign governments in a variety of foreign languages, and even cracked a Russian one-time-pad that they had accidental;y used more than once. I don't think it's very hard at…
Of course it's not impossible just reverse engineering the protocols but we now know that these guys also rightly measure their smartness by taking shortcuts wherever they can. It would be stupid to do unnecessary work to "rediscover" easily accessible information. The right approach is using the internal documents describing the protocols. Shouldn't be so hard, "it's all in the cloud."
Oh, the hypocrisy.... > "Bypassing that system is illegal for a good reason." Yes, so is invasion of privacy. Yet Google has no problem breaking the law and violating civil rights for profit. > "Unfortunately we live in a world where all too often, laws are for the little people." Yeah, like tax laws and privacy laws... If you want to get on this high horse, you shouldn't be working for Google.
Erm, what? Which law did they break, and which civil rights did they violate?
Like indiscriminately and illegally sucking up WiFi data with their street view mobiles?
Including account information and passwords on unsecured WiFi connections.
Even if the accusation of "violating laws" may be a tad hyperbolic in the great scheme of things it's not a stretch to deem Google one of the most hypocritical companies around.
I can't agree with that, this was on Google's on fiber connections between their own data centers, right? And no other company with multiple data centers encrypts all traffic between them, right? (maybe you'll find a small counterexample but no big one.) So I don't think this is "security 101".
I work for a company bigger than Google, and we encrypt everything in flight between datacenters. It is security 101.
Does your company have dedicated, unshared, fibre between those datacenters?
I work for a company bigger than Google, and we encrypt everything in flight between datacenters. It is security 101.
Does your company have dedicated, unshared, fibre between those datacenters?
Consider the recent passwords leak from Adobe: they stored passwords in a dedicated unshared datacenter. Does this make a good security decision to encrypt passwords instead of using a hash because nobody should have been able to access these encrypted passwords? I really don't think so.
China doesn't have agreements with BT, AT&T etc which allow it to tap fibre in our countries at will. I'm sure they try some tapping, but they can't do it on the scale that GCHQ and the NSA have been outside China.
But they could easily have agreements with every chip fab to build back doors into every piece of networking equipment.
I can't agree with that, this was on Google's on fiber connections between their own data centers, right? And no other company with multiple data centers encrypts all traffic between them, right? (maybe you'll find a small counterexample but no big one.) So I don't think this is "security 101".
Well, I do :) Moreover, I encrypt all the traffic even inside the same data center.
could you share which technology are you using to encrypt all the traffic?
It's ironic that when the Chinese attack against Google occurred, we thought the Chinese government was the most hostile state actor threat to worry about, but it turned out to be the US and UK government.
no, YOU thought of China as terribly hostile. We in Europe know the deal for a very long time. It's not like there was no cold war and vietnam war and irak war and....