Live data from Hacker News

Google's end-to-end key distribution proposal

code.google.com

91–95 of 95 posts

Re: Google's end-to-end key distribution proposal

#91

Slightly worrying to see the word "checksum" used to refer to a one-way cryptographic hash function...

Huh? The only mention of a checksum also acknowledges it's possible to brute-force reverse it, aka not one-way.

A checksum is a computationally efficient way to detect unintentional changes in data. But as protection against intentional changes it's quite useless. That's what cryptographic hash functions are for.

Now the proposal described using a "checksum" to tie together two halves of a self-signature, where one half would be a an identity and the second would be an email address, essentially. That would make it trivial to forge a second half with another email address (but the same "checksum").

I understand that's an entirely different problem. All I'm saying is that few cryptographers would use the word "checksum" at all, and even fewer would use it in this context. That's what worries me slightly.

Re: Google's end-to-end key distribution proposal

#92
post #72
post #68

Earlier quoted context omitted.

If you can see your emails on your Android device and Google is admin on your device, why do you say that it is impossible for them to read your emails? I don't mean that they could read them in the cloud but if they can read them locally on your Android device and for example they could send a message back to Google saying "I think this guy should get ads for a new router".... but of course they could do much worst…

End-to-end is a browser extension that doesn't work on Android.

that is probably because end-to-end is not fully implemented yet...

Re: Google's end-to-end key distribution proposal

#93
post #82
post #63

How will the Key Directories and third party Monitors verify that I'm the real owner of my self-hosted email address user@myowndomain.com, uploading my real public key to the directory?

Depends on what you mean by "verify the real owner". They can verify that whoever has control of what gets uploaded to myowndomain.com also has control of the user@myowndomain.com email account and can prove they have the private key corresponding to the public key that was posted. Is that what you meant?

Is that verification process described somewhere in Google's proposal? I don't understand how it would work with third party Monitors. Would I have to prove my identity with some email-callback or DNS/HTTP token separately to them all?

Re: Google's end-to-end key distribution proposal

#94

Earlier quoted context omitted.

Sorry, but google are the furthest thing from benevolent. It's all about data collection to spew more adverts at people. "Don't be evil... to our shareholders."

Yes, the fact that they're doing nothing bad to their customers today is an evil conspiracy to hide the fact that they want to do something bad to their customers. Makes sense. > It's all about data collection to spew more adverts at people. The way they do this is the single most ethical way of doing advertisements. Non-intrusive and trying to predict what you actually need. They're pursuing the ultimate goal of goo…

Data collection isn't for advertising exclusively. It builds profiles that can be sold to third parties who will use that information to redline demographics. For instance health insurance companies and banks.

Re: Google's end-to-end key distribution proposal

#95

Earlier quoted context omitted.

The do no evil line is bullshit. This is not a benevolent company by any standard. The services are not free, you are just paying in a different currency. Here is more on loon and look further up for links to the PRISM slides and documentation showing the companies involved including google were compensated financially by the NSA. The evidence is damning. http://m.slashdot.org/story/194413 Look the bottom line here i…

> The do no evil line is bullshit. This is not a benevolent company by any standard. From the linked Slashdot article - Google patented Loon-related technology, describing it " as just the ticket for those well-to-do enough to pay a tiered-pricing premium to get faster internet access while attending concerts, conferences, air shows, music festivals, and sporting events where a facility's overtaxed Wi-Fi simply won't…

http://www.ibtimes.com/bill-gates-bashes-project-loon-google...
Post reply on HN