7 ms·
I'm sure Ms. Meckfessel is a lovely person, but this is clearly a PR driven piece pumped out of Google for recruitment purposes. Throughout this entire NSA sca
by tippytop 13y ago
I'm sure Ms. Meckfessel is a lovely person, but this is clearly a PR driven piece pumped out of Google for recruitment purposes.
Throughout this entire NSA scandal people lament there's nothing we can do, but these tech companies are vulnerable to talent shortages. A simple action for a conscientious hacker is to simply not work for PRISM collaborators. Apply your talents to companies willing to make privacy assurances.
- rryan 13y ago> PRISM collaborators You mean companies that comply with US law? So your advice is to work outside of the US?
- EthanHeilman 13y ago>You mean companies that comply with US law? So your advice is to work outside of the US? 1. Or work in areas which do not handle data that the US requires by law. You can find software jobs in the US that do not require collaboration with governmental domestic spying. For instance many people choose not to work for companies that build weapons of war for a variety of reasons. These people can still work inside the US. 2. Additionally non-US residents work for Google. Being outside the US doesn't really have much relevance to the discuss. 3. I also reject the notion that Google had no choice. Google may have been able to comply with the letter of the law without giving up user data by using e2e cryptography. One can support or question their actions, but they are not powerless victims in this drama but active agents that can be held responsible for what they do.
- fpgeek 13y ago> Google may have been able to comply with the letter of the law without giving up user data by using e2e cryptography. Only at the cost of not providing the service that users want, which includes such things as fast, full-text email search, recovering accounts after passwords (and other security tokens, if any) have been lost. Once Google can extract the unencrypted email for any purpose, the practical consequences of their legal obligations make all cryptography Google provides useless against this sort of attack. Yes, Google has a choice. But let's be clear on what that choice is: They can choose whether or not to offer a mass-market email service. Once they've decided to offer that service, the practical consequences are inevitable, given the current, relevant legal framework.
- EthanHeilman 13y agoI don't think you or I, or even Google knows the total set of their options, but we can sit here and come up with some alternatives. >Only at the cost of not providing the service that users want, which includes such things as fast, full-text email search, e2e encryption is completely compatible with fast, full-text email search. There are several companies that currently offer such services, that is webbased, fast searchable email, that is e2e encrypted such that no plaintext arrives on the server side (unfortunately I am under an NDA or I would tell you more but you can read the papers if you like). Stuff like this: http://www.forbes.com/sites/andygreenberg/2011/12/19/an-mit-magic-trick-computing-on-encrypted-databases-without-ever-decrypting-them/ http://www.forbes.com/sites/andygreenberg/2011/12/19/an-mit-... It's not just databases it's search engines as well. I think gmail probably loses some enterprise clients because they don't do this, but I expect "enterprise level" features like this from gmail in ~2-3 years by my guess. Probably sooner due to the nosedive in trust they just took. Google has a monopoly on new email account creation so they don't need to innovate to get new customers (hell android locks everyone in). It isn't outlandish to suggest that they could have chosen to innovate and done what has been in the research literature for some time now. Secure e2e encrypted cloud email. >recovering accounts after passwords (and other security tokens, if any) have been lost. Have you tried to get gmail accounts back because I know people that have lost all their email. Are they better at this now (maybe they are, I hope so)? Even with this as a requirement, it is achievable. The user's client just sends a copy of the key to a foreign key escrow service that will unlock their account if anything happens once they prove they are who they say they are with various forms of ID and proofs of knowledge. Paranoid users can elect not to do this. Or ask people in your circles that you have marked as trusted to attest to your identity. You could do some clever threshold cryptography with your closest family and friends. They big trick is making money off ads while not learning about the contents of the email. One way could be a bounded leakage strategy whereby the encryption scheme allows some ad matches without giving up more than one or two popular words per email. All of this is a sideshow though. The NSA wasn't going to throw the Google execs in jail for not towing the line. Google is an extremely powerful company with a strong lobby in Washington. Not to mention that just pressing the charges would be a major embarrassment for the NSA. Twitter fought and won. Likely they just offered Google some nice contracts with the US government.
- tippytop 13y agoThere is something these companies allowed that went beyond others, Twitter is not listed for example. As Snowden pointed out [1], these companies need to make some kind of technical assurances for privacy, otherwise customers (and potential employees) should look elsewhere. [1] "The [telcom] companies should write enforceable clauses into their terms, guaranteeing their clients that they are not being spied on. And they should include technical guarantees. If you could move even a single company to do such a thing, it would improve the security of global communications. And when this appears to not be feasible, you should consider starting one such company yourself."
- fpgeek 13y ago> You mean companies that comply with US law? So your advice is to work outside of the US? What makes you think you don't have to comply with US law if you work outside of the US? If you're a US citizen living and working abroad, it will quickly become painfully clear exactly how much work you have to do to comply with US law (and how severe the penalties are if you don't). And US citizen or not, you might be surprised at how many non-US companies elect to comply with various aspects of US law for business reasons.
- infrec 13y agoWhat do you mean by PRISM collaborators? I am genuinely curious because I feel like I missed when/where that was established. To my understanding, and please correct me if I am wrong, PRISM isn't a system that companies subscribe to, but more of a government portal for requesting information from a number of companies in a legal fashion. Is this not correct? I admit I have not kept up with all of the bits of information released due to the high volume of speculations generated by just about everyone that talks about it.
- EthanHeilman 13y agoWe still don't really know what PRISM is or how it functions. It does appear that US companies did provide overly broad information to the US government using the following logic. 1. The US government gets massive amounts of information from these companies and can get this information in real time with no oversight, 2. none of these companies seem upset about it, which one imagines they would be if the US government was just stealing it without their permission, 3. and these companies have cooperated with the governments misinformation campaign (denials of "direct access" and such). If they aren't responsible for initially giving them access, they are now responsible the governments continuing access since they have learned that the government does have access and they have not attempted to prevent the government from maintaining access and furthermore they have aided the government ability to maintain access by stifling public outcry about this access by lying to their users.
- infrec 13y agoYour reasoning is not very convincing. Point one is pretty much the entire question so claiming it as proof seems circular. If you have evidence proving that claim I would be satisfied. Point two is simply wrong as there was a lot of writing from CEO's and engineers that seemed quite upset about the claims. And for point three, uh... what? How are their denials proven to be lies? Or are you implying that companies using the phrase "direct access" is proof? Honestly your post, combined with a lot of others' on this site, would seem to belong quite nicely in /r/circlejerk. I'm not saying that as an insult but rather how all of these speculations kept alive through echo genuinely come off as. If you have actual proof please provide a better reasoned argument.
- codex 13y agoGiven the secrecy surrounding PRISM, is there any way to know whether a company has been recently forced to comply with a PRISM-like program? Snowden's data is already stale, and only covered the largest companies.
- jimzvz 13y ago>...this is clearly a PR driven piece pumped out of Google for recruitment purposes. Agreed, can someone point me in the direction of some tech writers that aren't afraid of journalism?