12 ms·
This seems like much ado about nothing. I certainly appreciate the effort is better than nothing, however, how often are those notices served to US/European ci
by codelitt 11y ago
This seems like much ado about nothing.
I certainly appreciate the effort is better than nothing, however, how often are those notices served to US/European citizens? It's one thing to stand up to government overreach in foreign countries, but how about the country where you (and a large percentage of your users) reside? They specify attackers, but I'm assuming this notice to the end user does not apply to the US/EU governments requesting your data and them complying?
Another gripe I have is that TLS has probably been broken by the NSA^1. It's better than nothing to alert us about the other party not using it, but really provides limited protection. PGP/GPG is really the only assurance you have and the plugins for different desktop apps are nearly always buggy. I end up just manually encrypting/decrypting with GPG because a buggy encryption integration is not a comforting thought. If they really cared about keeping your privacy safe, they'd have an end-to-end encryption tool/integration.
[1]: http://blog.cryptographyengineering.com/2013/12/how-does-nsa-break-ssl.html http://blog.cryptographyengineering.com/2013/12/how-does-nsa...
- tibbon 11y agoAgreed; bake easy PGP into Gmail.
- nxzero 11y agoIf they had end-to-end encryption, then Google wouldn't be able to read the emails; meaning to gain value, Google would have to charge for the service.
- dorfsmay 11y agoGoogle does charge for email services, for anybody using gmail with their own domain, which is a lot of small companies and probably a few medium size one.
- nxzero 11y agoRight, though my guess is that doing custom domains and end-to-end encryption as a service are not comparable services or markets.
- dave2000 11y agoThey could mine for keywords on the client. They'd not need to store those against who you are sending the message to. It would be less intrusive than is the case now, but not as secure as then knowing nothing about what you're sending. Where would draft emails be stored in an end to end encrypted system? They'd need to store the information on their servers in a way that they can recover it for subsequent editing.
- sp332 11y agoHow is sending "keywords" back to a central server more secure than just mining them on the server?
- delroth 11y agoIt's not (only?) a question of "gaining value". End-to-end encryption is fundamentally incompatible with many features that Gmail users rely on. I would recommend reading https://moderncrypto.org/mail-archive/messaging/2014/000780.html https://moderncrypto.org/mail-archive/messaging/2014/000780.... from an ex Gmail anti-abuse tech lead. And for 99.99% of Gmail users, protecting automatically against untargeted phishing and malware attacks is a larger security improvement than having e2e encryption.
- ikeboy 11y ago>The third problem is that spam filters rely quite heavily on security through obscurity, because it works well. Hm.
- Zigurd 11y agoPermission-based email. It's an established solution. IM works this way because it doesn't have spam filters.
- macns 11y agoA quick google search on 'permission based email service' shows email lists- marketing related results, do you know any of such service provider? Maybe some day email will fade away giving its place to an IM, though I'm not sure it will always be spam-filter free.
- Zigurd 11y agoBoxbe is one that I have encountered people using: http://www.boxbe.com/help http://www.boxbe.com/help It's a little surprising this was never a standard part of email. It's the same workflow as granting permission to be contacted by IM. Based on a quick search, you are right that the phrase "permission based email" has been SEO'ed into uselessness by email marketing services. What should it be called? Screening? But the spam filtering services have almost SEO'ed that into uselessness.
- chflags 11y agoThe way they word these releases certainly makes it sound like they have users' best interests in mind. But honestly, as you have highlighted, these announcements should be insulting to users' intelligence. "Dear Users: Please allow us to store copies of all your sensitive data, including every email ever sent or received, in perpetuity. In return, to the extent the law permits us to do so, we'll let you know (_ex post facto_) when some other third party is having a look at it." The solution to the problem if indeed there is a problem here is not going to come from Google. The problem _is_ Google. The only parties who need a copy of an email are the sender and the recipient. If you really care about privacy, security, whatever, then "store and forward" and "POP" via some third party (Google, etc.) is not the proper way to implement email. Hypothesis: Google does not charge for Gmail because, quite simply, no one would pay.
- LeifCarrotson 11y ago> The only parties who need a copy of an email are the sender and the recipient. Emphasis on "need". Most recipients also like to have a third-party anti-spam service also have a copy of their email. Assuming the encryption costs are low enough, spammers and virus senders would like nothing better than to cripple anti-spam learning tools by having each recipient recieve a cryptographically unique opaque blob. This would force users to develop their own training corpus and react to new spam and virus outbreaks individually. You may argue that you could still use anti-spam locally, but it wouldn't be as good. While I wouldn't mind sending decrypted spam out to a server and getting updates to my local anti-spam program, no one would want to send legitimate mail, so the service would have no "ham" to train against. I suppose encryption could help in the fight against spam by requiring CPU time to encrypt the email. 10 seconds per email would be hard to notice for a real human responding to messages, but might make spam unprofitable.
- NoGravitas 11y agoI wonder if it would be good enough to use a public spam corpus built on volunteer contributions, while using only a private ham corpus.
- massemphasis 11y agoIt is just naive or dumb to think Google is left alone when they don't give access to the government. Of course they give access, but in the interest of being a vital source of intelligence and data they put on an act.
- 1123581321 11y agoI don't see why Gmail has to be all-or-nothing. I would like to see Google continue their free/cheap service as is, and offer a more expensive service with better security. I think Google would be able to greatly improve the interface for end-to-end encryption if they chose to. However, the company seems disinterested in cooperating less with law enforcement and spy agencies.
- thomasthomas 11y agoI would suspect this is because when 99% of users hear of an upgraded gmail service that costs money, they will start asking questions as to what's wrong with their current gmail service. They get so much synergy across products from users data it's probably not worth it to point out current gmail drawbacks to 100% of customers: even if x% switch to premium, 1-x are now aware of drawbacks of using google across all products and could unpredictably hurt top line rev.
- thomasahle 11y ago> It's on thing to stand up to government overreach in foreign countries, but how about the country where you (and a large percentage of your users) reside? I'm not sure I catch your drift. Users in any country may get targeted by governments of any country. You might say that governments should be allow to do whatever they like to their own citizens, but in this day and age, that's hardly an easy distinction to make.
- codelitt 11y agoYou're right. Governments of any country could target any user. My point was, they make a point of saying "attackers" which is not synonymous with the data they release due to government requests (which is likely a more worrisome concern). They're alerting you of "attacks" to obtain your data, but not necessarily government requests for your data.
- huntsman 11y agoCorrect this is about attacks against user accounts not legal requests. We do notify users wherever possible about legal requests and statistics are in the transparency report: https://www.google.com/transparencyreport/userdatarequests/legalprocess/ https://www.google.com/transparencyreport/userdatarequests/l...
- codelitt 11y agoThank you for the link. That's good to know, however, as you alluded to sometimes it's not possible to alert users. In that vein, end-to-end would protect those users even if you can not alert them. Your hands are tied with something like PGP because you couldn't access it even if you wanted to. Someone mentioned your end-to-end extension. Will you be releasing end-to-end to the Web Store soon? Or some other killer end-to-end solution?
- dave2000 11y agoNobody (really, a vanishing small percentage of the total number of people who use online services) uses PGP because it's a user interface disaster.
- adrianN 11y agoEverybody claims that GPG is unusable, but I just don't think that is the case. Thunderbird+Enigmail works perfectly hassle-free. You just enter your passphrase and everything else just works. The hard part about using GPG is convincing your peers that it's worth the minimal effort to set up. "I've got nothing to hide" is the common response.
- niij 11y agoYes, for the technologically literate echo chamber of HN and most of our immediate peers, GPG may seem trivial to install. But the real people that have something important that needs to be encrypted (journalists, entire countries full of suppressed people, business secrets, etc) will NOT think this is trivial and most people will simply take their chances. That doesn't mean that GPG is bad or that it isn't a strong tool, it means that for mass adoption then we need to make the tools easier to use.
- kuschku 11y agoMy 60 dad, who has never managed to work well with computers (and has 4+ toolbars in IE, and likes them) managed to install GPG and Engimail in his Thunderbird, and managed to actually get them to work. Without help. If he can do it, anyone can.
- dave2000 11y agoYour last statement is just not true. My mother struggles to log into Facebook. "It works on the other computer". Yes, because the password is cached on the browser there; it's not on my laptop. "I'm putting the right password in but it's not working". No, you're not. Etc.
- rawfan 11y agoI don't know about Google, but when Twitter recently sent out such notices, a lot of US and European privacy advocats received them.
- codelitt 11y agoI do remember reading about that with Twitter, however, I have not read about it with Google.
- notatoad 11y agoThey do have an end to end tool: https://github.com/google/end-to-end https://github.com/google/end-to-end
- codelitt 11y agoAnd you'll notice it's conveniently not in the Chrome Web Store (where the average user can easily install it). It's better than nothing, but it is a bit transparent to have this tool yet not release it into their Web Store (or even better standard in Chrome).
- sp332 11y agoIt's not finished yet.
- Zigurd 11y agoMaybe I'm too demanding, but it seems like all the main web portal/social network providers have the tools at hand to make email secure against the state actor threat: Protocol standards that enable use of open clients, and a social graph and real-time communication tools that would enable a web-of-trust and key signing to prevent MITM. Their ad revenue per user is small and easily replaced by a subscription fee for using their web-of-trust and storage infrastructure.
- Laaw 11y agoBut I don't want end to end encryption. Why are you forcing me to use encryption if I don't want it? I'm getting a little annoyed by the folks demanding I do something I don't think is necessary. I'd rather have all the features Google gives me by not enabling end to end encryption, why must everyone have the highest possible level of security on every single thing they do? You may think it's stupid, but I genuinely don't care if the government reads my emails (with a warrant), or if Google indexes them. I still fundamentally trust the government, and I believe that any incidental processing of my emails that the NSA might be doing is searching for what we currently consider to be terrorist activity. If the definition of "terrorist" shifts beyond reasonability, then my habits will shift as well, but we're not anywhere near that.
- Chlorus 11y agoWell, the theme of the comments is: if google adds protection against certain adversaries (coffee shop wifi, MITMs, etc) via stricter TLS, but not all adversaries (nation-state attackers) via end-to-end, then the former protection is useless, I guess. It doesn't make sense to me, either.
- codelitt 11y agoNot completely useless. Just doesn't go far enough.
- codelitt 11y agoWe disagree in opinion. I'm advocating for what I feel to be important in security and privacy and you are advocating for ease of use and features. It's not stupid, just we have different priorities.
- nxzero 11y agoYou're right, next time you want to send your credit card data, do me a favor and email it to the company and let them know want you'd like to buy. As for warrants, forget email, possible your local police are already listening to your calls with a warrants. I'd go on, but don't see the point. I mean, for someone with nothing to hide, unclear why your don't list your full name and zip code; or for that matter, any affiliation you might have to the topics being commented on.
- massemphasis 11y agoThere is no such thing as privacy in a surveillance state.
- felipeerias 11y agoIf you really need secure communications, email+GPG is still a very poor solution. The body of the message is encrypted but a staggering amount of metadata will be transmitted in the open: sender, receiver, crypto used, date, subject, approximate size, etc. Furthermore, it doesn't provide forward secrecy: if somebody gets access to your key, they will be able to open everything you've ever sent.
- daveidol 11y agoWould you recommend a service other than email then? Which one?
- nailer 11y agoSignal (open whisper systems) is highly regarded and has verifiable source. People who know more about this: does Signal have verifiable builds too?
- nickpsecurity 11y agoNone of them have verifiable builds. There are some doing reproducible builds with untrustworthy compilers. Verifiable builds are a larger problem they're ignoring because it's not a fad yet. Lots of prior work in CompSci and even industry on that, though. Links below on subversion and build-related stuff. My description of subversion-resistant build: https://news.ycombinator.com/item?id=10182282 https://news.ycombinator.com/item?id=10182282 Subversion-resistance in systems and builds in general: https://news.ycombinator.com/item?id=10478742 https://news.ycombinator.com/item?id=10478742
- simoncion 11y ago> Verifiable builds are a larger problem they're ignoring because it's not a fad yet. Or because... oh, wait. You alluded to it yourself: > There are some doing reproducible builds with untrustworthy compilers. I expect that the bar required to verify (or design and build from scratch) a high-performance optimizing compiler [0] is substantially higher than the bar to rework your build system to give the same outputs for the same source code. [0] And -in the case of systems with VMs- a high-performance VM.
- deleted 11y ago[deleted]
- skybrian 11y agoIt seems like this has an implicitly libertarian slant that not everyone's going to buy into. If you look at the U.S. Constitution it's more nuanced. The fourth amendment forbids searches without a search warrant. If judges are involved and they're doing their jobs properly then it's okay. If you're not a libertarian, it matters that law enforcement has to get a search warrant, rather than breaking the encryption and snooping on whatever they want.
- nickpsecurity 11y agoCurrently, it's more along the lines of physics, math, trust issues, and malicious insiders threatening safe escrow or backdoors. A recent paper by top cryptographers, breakers, and policy makers showing there's no known method to apply to digital devices what we have with physical: https://www.schneier.com/cryptography/paperfiles/paper-keys-under-doormats-CSAIL.pdf https://www.schneier.com/cryptography/paperfiles/paper-keys-... Note that all the techniques they have allow stealthy, persistent access with ability to forge evidence with write access. I don't have to be libertarian to be concerned about that given all the corruption cases of local and federal law enforcement. Just know human nature & scope of technical problem.
- skybrian 11y agoNot seeing how that paper applies here since it seems to be about peer-to-peer encryption which is entirely different. In the case of a cloud service provider, putting the company (and a judge) in the loop is a procedural speedbump. The government doesn't have write access unless the company allows it. Of course if they collaborate all bets are off, but that's the best that separation of powers can give you.
- nickpsecurity 11y agoIt depends on what the company promises its customers about security, privacy, and recoverability. The paper's point is that methods for adding lawful intercept for one party tend to result in intercepts by other parties. Far as write or collaborate, you should look up the Lavabit case records or summaries. The FBI and court demanded that he hand over the master key compromising all users then lie to them about it. FBI also wanted to put a black box in a privileged position that could probably be used to compromise the service. They've used 0-days before in ops. So, a backdoor with enough privilege to read everything in the system, install updates with their spyware, and be unnoticeable to OS must be both (a) enormous technical risk and (b) have write access that could enable corrupt officials to frame dissidents. I've worked on potential counters to A but B is unacceptable given fed's and spook's track records.
- DINKDINK 11y agoI was in country with an oppressive regime and a friend got that notice on their gmail account.