6 ms·
Google was letting information flow between its data centers completely unencrypted until last month. http://www.washingtonpost.com/business/technology/google-e
by mapgrep 13y ago
Google was letting information flow between its data centers completely unencrypted until last month. http://www.washingtonpost.com/business/technology/google-encrypts-data-amid-backlash-against-nsa-spying/2013/09/06/9acc3c20-1722-11e3-a2ec-b47e45e6f8ef_story.html http://www.washingtonpost.com/business/technology/google-enc... Last month!
Think about that for a second. Most people on HN wouldn't send a single file to their own backup provider in the clear. Google was sending gushing torrents of data, presumably including email, IMs, etc, over long distances that way.
That's very nice that the company that encouraged all of us to put all our email and documents in its data centers "pushed harder than anyone on the whole internet" for some basic security well after the NSA compromised their shit, but it doesn't excuse their irresponsible practices.
- ori_b 13y ago> Google was letting information flow between its data center completely unencrypted until last month. http://www.washingtonpost.com/business/technology/google-enc.. http://www.washingtonpost.com/business/technology/google-enc.... Last month! Over their own private WAN. The analogy would be sending things in the clear over your LAN. [Citation: http://www.eecs.berkeley.edu/~rcs/research/google-onrc-slides.pdf http://www.eecs.berkeley.edu/~rcs/research/google-onrc-slide...]
- mapgrep 13y agoThe likelihood miles and miles of cabling, much of it presumably leased, will be compromised is nowhere near comparable to the likelihood a normal, single-location office/home ethernet LAN will be compromised. (And if you think both are easily compromised, that only adds to my original point.)
- SkyMarshal 13y agoFwiw Micheal Crighton wrote about this ("piggyback slurp") in Congo: http://goo.gl/KSf78p http://goo.gl/KSf78p
- DannyBee 13y ago"much of it presumably leased," This is a very interesting assumption http://www.howstuffworks.com/tech-myths/5-myths-about-google5.htm http://www.howstuffworks.com/tech-myths/5-myths-about-google... http://www.lightreading.com/document.asp?doc_id=633236 http://www.lightreading.com/document.asp?doc_id=633236
- outworlder 13y agoFiber optic links are not so easily compromised. Not without service interruption, which will raise quite a few eyebrows.
- ck2 13y agoThe US has submarines which are entirely designed to splice fiber optics without interruption. They literally bring part of the cable into the sub and work on it from there.
- chubot 13y agoCitation for that? Seems plausible but I'm interested in any details.
- jellicle 13y agohttp://cryptome.org/eyeball/mmp/jimmy-carter.htm http://cryptome.org/eyeball/mmp/jimmy-carter.htm Apparently the procedure is to position the USS Jimmy Carter over the cable, send out a remote vehicle to grab the cable and pull it up to the sub, splice in tapping equipment, and then drop the cable. Intercontinental cables are less than one inch in diameter in deep water. If the sub plants the tap in deep water, it's extremely unlikely that anyone would ever discover it. There are a few cable repair ships that pull broken cables to the surface and fix them, but other than that... No one can reach it and no one will bother it. The most interesting thing is actually getting the data back to the U.S. Do they run a separate cable alongside the existing cable? Getting SMALL bits of data back to the U.S. is easy, can just broadcast it. But LARGE amounts of data? Tricky.
- jlgreco 13y ago> There are a few cable repair ships that pull broken cables to the surface and fix them, but other than that... No one can reach it and no one will bother it. Even if you pull the cable up to repair it, it is unlikely that you would discover the tap. The device used in Operation Ivy Bells was designed to detach from the cable if the cable was lifted. Non-intrustive tapping might not be possible with fiber (it isn't, as far as I know), but I expect they have other mechanisms to avoid discovery. Perhaps lifting the cable would cause the cable to "snap" on either side of the tap, before the device could be lifted. http://en.wikipedia.org/wiki/Operation_Ivy_Bells http://en.wikipedia.org/wiki/Operation_Ivy_Bells http://www.fas.org/irp/eprint/ic2000/ivy_bells_pod.jpg http://www.fas.org/irp/eprint/ic2000/ivy_bells_pod.jpg
- zachrose 13y agoGoogle doesn't actually own the underwater cables though. So isn't the analogy more like sending things through a LAN in a building that you're renting?
- DannyBee 13y agohttp://gigaom.com/2008/02/25/googlenet-update-google-buys-a-piece-of-transpacific-cable/ http://gigaom.com/2008/02/25/googlenet-update-google-buys-a-...
- dsl 13y agoFrom the link: > Google is buying a piece of a new transpacific fiber optic cable Only a half dozen or so companies actually own undersea fiber. It requires a huge amount of effort to lay and maintain including hundred million dollar cable ships. Everyone (even Google) leases, or in this case buys, capacity on shared cables.
- generj 13y agoGoogle has the cash to lay their own now though. Or just buy a company which does. I wouldn't be surprised if they do so in the future.
- crucifiction 13y agoWhat is the point? If they can tap the cables it seems like owning your own just causes a false sense of security.
- generj 13y agoIt provides better legal grounds to sue.
- Moral_ 13y agohttp://www.cs.uccs.edu/~xzhou/teaching/CS522/Projects/SIGCOMM13-SNDExp.pdf http://www.cs.uccs.edu/~xzhou/teaching/CS522/Projects/SIGCOM... There's the actual paper google wrote. It's very good. OpenFlow is a terrific piece of technology.
- brown9-2 13y agoDo they actually own and operate all of the wires between various datacenters? That sounds like a huge undertaking.
- mindcrime 13y agoI doubt they own all of the links they use worldwide, but Google did go on a buying binge a few years ago, acquiring large amounts of "dark fiber". There's some discussion about that whole topic here: http://www.howstuffworks.com/tech-myths/5-myths-about-google5.htm http://www.howstuffworks.com/tech-myths/5-myths-about-google... http://news.cnet.com/Google-wants-dark-fiber/2100-1034_3-5537392.html http://news.cnet.com/Google-wants-dark-fiber/2100-1034_3-553... http://www.lightreading.com/document.asp?doc_id=633236 http://www.lightreading.com/document.asp?doc_id=633236
- blablabla123 13y agoAssuming that the fiber end points only touch Google data centers, this would be ok, I guess.
- ams6110 13y agoDo not trust that your internal networks are secure. Any links carrying business or customer data should be encrypted. I remember over a decade ago talking with the security head of a university where I was working, about a new system design. I made some comment like "well this is all on the machine room network" and his response was "I wouldn't trust the machine room network." Pretty eye-opening since he was the person responsible for its security.
- deleted 13y ago[deleted]
- tiziano88 13y agointer-datacentre communication most likely happens on dedicated networks "outside" the internet