5 ms·
The issue here is that Google doesn't know how much data the NSA collects. The NSA has access to the internet backbone that Google uses and can read whatever t
by ben_pr 13y ago
The issue here is that Google doesn't know how much data the NSA collects. The NSA has access to the internet backbone that Google uses and can read whatever traffic it wishes that leaves the Google network. Obviously this is not everything but most everything. It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. So while Google can claim they do not allow the NSA direct access to it's servers that is only a small comfort in the big scheme of things.
This sort of response from Tech companies is just a distraction from the real issue.
- youngerdryas 13y ago>So while Google can claim they do not allow the NSA direct access to it's servers That is the entire story in this case, direct access to the servers.
- lawnchair_larry 13y ago> It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. No it isn't.
- ben_pr 13y agoWell, think again. You really think the NSA can't make the SSL cert vendors turn over the keys? I wouldn't count on it. https://news.ycombinator.com/item?id=5933784 https://news.ycombinator.com/item?id=5933784
- kllrnohj 13y ago> It is a low view of the NSA to think that they do not have the ability to real-time decrypt SSL certs from every major SSL cert authority. For most SSL certs this is probably true, but Google uses perfect forward secrecy which makes this very unlikely if not damn near impossible: http://googleonlinesecurity.blogspot.com/2011/11/protecting-data-for-long-term-with.html http://googleonlinesecurity.blogspot.com/2011/11/protecting-...
- jmillikin 13y ago> It is a low view of the NSA to think that they do not > have the ability to real-time decrypt SSL certs from > every major SSL cert authority. The technology required to break SSL is sufficiently advanced that any organization possessing it would probably have easier ways to collect data, all of which would grossly outmatch all known security precautions. There would be no need for any of these sneaking-around stuff because breaking SSL is an instant win condition.
- nitrogen 13y agoThe only thing required to "break" SSL in the absence of some serious protocol flaw is either the ability to MITM connections with a CA-signed certificate, or possession of the private key used by the server.
- packetslave 13y agoYou should educate yourself on Perfect Forward Secrecy and pinned certificates.