4 ms·
> PRISM collaborators You mean companies that comply with US law? So your advice is to work outside of the US?
by rryan 13y ago
> PRISM collaborators
You mean companies that comply with US law? So your advice is to work outside of the US?
- EthanHeilman 13y ago>You mean companies that comply with US law? So your advice is to work outside of the US? 1. Or work in areas which do not handle data that the US requires by law. You can find software jobs in the US that do not require collaboration with governmental domestic spying. For instance many people choose not to work for companies that build weapons of war for a variety of reasons. These people can still work inside the US. 2. Additionally non-US residents work for Google. Being outside the US doesn't really have much relevance to the discuss. 3. I also reject the notion that Google had no choice. Google may have been able to comply with the letter of the law without giving up user data by using e2e cryptography. One can support or question their actions, but they are not powerless victims in this drama but active agents that can be held responsible for what they do.
- fpgeek 13y ago> Google may have been able to comply with the letter of the law without giving up user data by using e2e cryptography. Only at the cost of not providing the service that users want, which includes such things as fast, full-text email search, recovering accounts after passwords (and other security tokens, if any) have been lost. Once Google can extract the unencrypted email for any purpose, the practical consequences of their legal obligations make all cryptography Google provides useless against this sort of attack. Yes, Google has a choice. But let's be clear on what that choice is: They can choose whether or not to offer a mass-market email service. Once they've decided to offer that service, the practical consequences are inevitable, given the current, relevant legal framework.
- EthanHeilman 13y agoI don't think you or I, or even Google knows the total set of their options, but we can sit here and come up with some alternatives. >Only at the cost of not providing the service that users want, which includes such things as fast, full-text email search, e2e encryption is completely compatible with fast, full-text email search. There are several companies that currently offer such services, that is webbased, fast searchable email, that is e2e encrypted such that no plaintext arrives on the server side (unfortunately I am under an NDA or I would tell you more but you can read the papers if you like). Stuff like this: http://www.forbes.com/sites/andygreenberg/2011/12/19/an-mit-magic-trick-computing-on-encrypted-databases-without-ever-decrypting-them/ http://www.forbes.com/sites/andygreenberg/2011/12/19/an-mit-... It's not just databases it's search engines as well. I think gmail probably loses some enterprise clients because they don't do this, but I expect "enterprise level" features like this from gmail in ~2-3 years by my guess. Probably sooner due to the nosedive in trust they just took. Google has a monopoly on new email account creation so they don't need to innovate to get new customers (hell android locks everyone in). It isn't outlandish to suggest that they could have chosen to innovate and done what has been in the research literature for some time now. Secure e2e encrypted cloud email. >recovering accounts after passwords (and other security tokens, if any) have been lost. Have you tried to get gmail accounts back because I know people that have lost all their email. Are they better at this now (maybe they are, I hope so)? Even with this as a requirement, it is achievable. The user's client just sends a copy of the key to a foreign key escrow service that will unlock their account if anything happens once they prove they are who they say they are with various forms of ID and proofs of knowledge. Paranoid users can elect not to do this. Or ask people in your circles that you have marked as trusted to attest to your identity. You could do some clever threshold cryptography with your closest family and friends. They big trick is making money off ads while not learning about the contents of the email. One way could be a bounded leakage strategy whereby the encryption scheme allows some ad matches without giving up more than one or two popular words per email. All of this is a sideshow though. The NSA wasn't going to throw the Google execs in jail for not towing the line. Google is an extremely powerful company with a strong lobby in Washington. Not to mention that just pressing the charges would be a major embarrassment for the NSA. Twitter fought and won. Likely they just offered Google some nice contracts with the US government.
- deleted 13y ago[deleted]
- tippytop 13y agoThere is something these companies allowed that went beyond others, Twitter is not listed for example. As Snowden pointed out [1], these companies need to make some kind of technical assurances for privacy, otherwise customers (and potential employees) should look elsewhere. [1] "The [telcom] companies should write enforceable clauses into their terms, guaranteeing their clients that they are not being spied on. And they should include technical guarantees. If you could move even a single company to do such a thing, it would improve the security of global communications. And when this appears to not be feasible, you should consider starting one such company yourself."
- fpgeek 13y ago> You mean companies that comply with US law? So your advice is to work outside of the US? What makes you think you don't have to comply with US law if you work outside of the US? If you're a US citizen living and working abroad, it will quickly become painfully clear exactly how much work you have to do to comply with US law (and how severe the penalties are if you don't). And US citizen or not, you might be surprised at how many non-US companies elect to comply with various aspects of US law for business reasons.