8 ms·
Google’s Revamped Gmail Could Take Encryption Mainstream
- rjknight 12y agoI would, quite happily, forgive Google for everything if they do what's described in this article.
- tptacek 12y agoYou would forgive Google for spending millions of dollars over the last decade to work harder than virtually any other tech company on the Internet to resist NSA surveillance, thanklessly and quietly, or, when not quietly, under the duress of thousands of shrill, under-informed detractors? For essentially orchestrating the worldwide deployment of TLS forward secrecy, for more or less inventing browser certificate pinning, for donating high-quality crypto code to NSS and OpenSSL --- by the way, also, for finding Heartbleed and publishing it, rather than holding it as a "competitive advantage" --- and for killing probably several thousand browser RCEs? And, in all of this, for spending god knows how much money on lawyers behind the scenes? That's generous.
- toomuchtodo 12y agoWell said.
- rjknight 12y agoWorking harder than others simply makes them the least bad. They may have struggled valiantly to keep data secured, but they failed often enough. Google did more than many to pioneer the model of centralised information-gathering as a commercial strategy, which is part of what made surveillance so rewarding. I think we expect far too little of companies that manage our data, and Google manages far more than most. Client-side crypto, along a PGP model, would be a welcome admission that Google can't secure everyone's email within their network. It would be a step away from the idea that we simply have to trust utility-scale cloud providers with our data. I see that as putting right a mistake. EDIT: To de-escalate the argument, I should say that we're probably perceiving 'Google' differently. Their security people are excellent people, and Google has undertaken many excellent security initiatives. Many people at Google are on the side of the angels. As you probably know these people and their work much better than I do, I can imagine that your picture of Google's activities is different to mine. But from a consumer's perspective, Google is much more ambiguous. As a matter of corporate strategy they have pooled vast amounts of customer data via the integration of their services, and they have created a security risk by doing so. When faced with a choice between doing something that might make users safer but might harm their ability to gather data on them, I don't believe Google as a company has often chosen the former.
- tptacek 12y agoWorking harder than everyone else does not simply make something "the least bad". It also makes them "the best".
- Zigurd 12y agoThe thing about privacy against a threat like PRISM and other mass-surveillance threats is that there is a threshold below which efforts don't actually protect. End-to-end encryption is a pretty reasonable threshold. Skype proved it could be convenient enough for grandma (and yes I'm aware that user-controlled keys for store and forward is more difficult). So, yeah. Below that threshold the best is just least bad. I don't see why you are so touchy about that. Many people here foresaw that the government would be so intransigent that, unless services implemented open and verifiable tools for enabling end-to-end encryption, anything short of that would be ineffective in restoring trust in the services we use.
- contingencies 12y agoEnd-to-end encryption is a pretty reasonable threshold. Skype proved it could be convenient enough for grandma Err .. are you are aware they give out keys to certain governments and send different code to certain clients (eg. within China)? In privacy terms they are basically the same as Google now with its centralized model and SSL, just using some obfuscated vaguaries of P2P slash centralized communications paths (which they refuse to document openly) instead of centralized store and forward.
- contingencies 12y agoI usually respect your comments tptacek, but the fact is that Google have acted and continue to act to strongly effect a centralization of much personal information on the internet in an unencrypted form accessible to parts of the company and its host governments. That's just not cool, versus the traditional decentralized model. All of their mitigation efforts are only lipstick on the fundamental pig here. Yes, they're not the only ones. Yes, ease of use. But that doesn't change the model.
- kevinh 12y agoSurely he means Google's anti-competitive and anti-employee pacts with other companies in the area, their desire to take away privacy via forcing people to use their real name across all of their products, and their commitment to forcing mobile paradigms into a desktop environment. It would be generous.
- tptacek 12y agoGot it. Internet company. Guilty. Sure thing.
- kevinh 12y agoIt sounds like your interests and focuses differ from others in this area. I'm not sure why you feel it justifies so much snark.
- tptacek 12y agoPerhaps. My interests and focuses are in Internet and application security and privacy; that's been my career for the past 15 years. I'm not sure what the incompatible other interest might be.
- ladzoppelin 12y agoYea but they do all that to secure their services so they can harvest the information. "Rather than holding it as a "competitive advantage"" Doing so gives them the "competitive advantage" by creating the illusion of some "white knight" protector of the internet and its users. I don't even mind Google as much as I mind the weird delusional back-flips people do in order to forget the fact that Google is an advertising/tracking company. They have no business plan if people stop trusting the internet or use browsers that can make tracking/analytic data harder for them to collect.
- pingswept 12y agoI agree that Google's efforts, as you have described, have been exemplary. Have they not also gone along with the NSA in what appear to be violations of the 4th amendment? I'm mostly ignorant of this stuff, but reading the quote below from the Guardian makes them look complicit. I think it's fine to be complicit when you're powerless, but Google is not powerless. What bad thing would have happened to Larry Page if he had said "Uh, we're not handing over the data." Would he actually have been arrested? (Just to be clear, you've probably thought about this for 400 hours more than I have, so if I'm totally wrong, sorry.) From the Guardian [1]: "The senior lawyer for the National Security Agency stated on Wednesday that US technology companies were fully aware of the surveillance agency’s widespread collection of data. Rajesh De, the NSA general counsel, said all communications content and associated metadata harvested by the NSA under a 2008 surveillance law occurred with the knowledge of the companies – both for the internet collection program known as Prism and for the so-called “upstream” collection of communications moving across the internet. Asked during a Wednesday hearing of the US government’s institutional privacy watchdog if collection under the law, known as Section 702 or the Fisa Amendments Act, occurred with the “full knowledge and assistance of any company from which information is obtained,” De replied: “Yes.”" [1]: http://www.theguardian.com/world/2014/mar/19/us-tech-giants-knew-nsa-data-collection-rajesh-de http://www.theguardian.com/world/2014/mar/19/us-tech-giants-...
- rdl 12y agoWow, you hold a grudge over Google killing Reader for a long time :) In general, I'd say Google has done mostly great things for the Internet, and good things for Internet security. They're a huge target -- their biggest sin is that they're inherently centralizing a lot of stuff which used to be decentralized (mail servers, etc.). In general that increases security because Google does a better job in software and operations than virtually anyone else, but it creates a big juicy target. agl alone probably makes up for any negatives Google has brought to security. The other thing I hate them for was Rubin's hatred of security and thus no platform security on Android, but that's being fixed, and ChromeOS is pretty amazing in contrast.
- droob 12y agoBummed that "could" here means "could theoretically", not "might".
- sounds 12y agoI guess I'm going to err on the side of hope, so for me it seems wired does have some sort of inside information. Not very much, apparently. But a pre-product announcement from Google doesn't mean much, since they work on so many products. If they do decide to push it to "beta" (ha ha) I'll happily use it. Either way, I would hope public key crypto does become more mainstream, especially in email.
- mnw21cam 12y agoEven if google does implement this, where is everyone going to get a shiny new PGP key from? Is google going to create it? Is the user going to create it? How about linking it in to the web of trust. Who is going to go around teaching all the users how to securely verify each other's keys, so that the public key part of the system isn't a complete and utter waste of time? Don't get me wrong, I would love it if loads more people were to get a PGP key and enter the PGP web of trust (like, say, paypal). It's just that over the last ten or so years, I have found remarkably few people who both have a PGP key, and care about it.
- 21echoes 12y agoI would love if Google did this, but I see two significant problems. 1. Who stores my private key? Google? Chrome? Both seem troublesome 2. "Also, Google wouldn’t be able to scan and index the text of your e-mails. That’s a problem if you need to search for old emails not stored on your own machine. It could be a real issue for Google’s business model as well, which involves scanning the text of emails in order to place contextual advertising." Unclear that Google would give up arguably their greatest personal data asset (better than search, imo), which of course is the key to their whole business model.
- Thirdegree 12y agoIn response to 2) I would say the best way (from Google's perspective) would be a way to flip a switch on a per-email basis. So by default, emails aren't secure, but if you need it you can activate it. I wonder if the loss of data would be worth the increase in users though.
- higherpurpose 12y ago> I wonder if the loss of data would be worth the increase in users though. I think that's the wrong way for Google to look at it. The question should be "how many users will I lose if I don't enable something like this in my services soon?" The best thing American companies could do right now, especially large ones like Google, to make sure regions like Latina America or Europe don't take a "you have to build your datacenter here" stance and make things much more expensive for them, is to ensure that the data is private, even if it's on American servers, because they've adopted trustless protocols, and even they can't see what's inside. That's what's going to stop users and institutions from other countries from bailing on American corporations like Google. So losing a little data signal from the ad tracking data is hardly a big loss in comparison, and could help Google regain at least some of the trust they lost post-NSA revelations.
- saraid216 12y ago> I think that's the wrong way for Google to look at it. The question should be "how many users will I lose if I don't enable something like this in my services soon?" Since this answer is "an insignificant amount", I think you'd be happier if Google looked at it the wrong way.
- suprgeek 12y agoThis is what happens when you piss-off such a large number of people. Suddenly end-to-end encrypted e-mail not only becomes a differentiator but something that could get regular <gender neutral grand parent> excited. For the hundredth time Thank you Snowden!
- spindritf 12y agoThe way I see Mailpile becoming popular and putting a dent in dragnet surveillance is not by everyone downloading it and running themselves but a trusted third party running it and holding keys for a relatively small group of people. Some will complain that this way the third party can still access the key and mail encrypted for it. That's true but also a massive step up from everyone on the wire being able to read your messages. Now, an intelligence agency can just siphon anything and everything. With a large number of independent e-mail providers, only narrow and targeted surveillance would be feasible. All that without giving up any convenience of webmail.
- higherpurpose 12y agoI'm very wary of upvoting such posts lately, even related to Google. On one hand, we do need a large service provider like Google to adopt end to end encryption in e-mail and popular chat apps, because otherwise it's going to take forever, if we just try to convince people one by one. On the other hand, Google's corporate goals are very much against end-to-end encryption and strong privacy, and they're even lobbying [1] against it. So it remains to be seen if it's an actual useful thing from Google, or just PR. And I realize that even if it's mainly for PR, that PR could lead other companies to want the same kind of PR, too, and implement such measures as well - but hopefully not in a gimmicky/not very useful way. Making something like this available at all in major services would still be a big win, however it's still a far cry from actually being enabled by default (like the way Telegram doesn't enable end to end encryption by default - even though their main marketing message for it is "the most secure chat app in the world" - except for most people using it). [1] - http://www.vice.com/read/are-google-and-facebook-just-pretending-they-want-limits-on-nsa-surveillance http://www.vice.com/read/are-google-and-facebook-just-preten...
- tptacek 12y agoBeyond this comment: https://news.ycombinator.com/item?id=7634928 https://news.ycombinator.com/item?id=7634928 a further question: How does opposition to Rand Paul's "Fourth Amendment Protection Act" even make sense for ITAPS? The federal FAPA says exactly one thing: electronic records held by third parties are inadmissible in criminal proceedings unless obtained under consent or under color of a specific warrant demonstrating cause. What are the business implications of such a law? Google and Facebook have no obvious commercial interest in the outcome of random criminal cases. Isn't it a lot more likely that Vice just doesn't know what it's talking about and has gotten the bill wrong? That rather than opposing the "Fourth Amendment Protection Act", they're opposing individual state FAPAs derived from the 10th Amendment Center's Model State FAPA, which can hold a corporation in violation of state law for honoring a federal subpoena or court order, which would (a) create potentially 50 different new data protection policies and (b) put Internet companies in an absolutely impossible position of needing to choose between violating either a federal law or a state law?
- Zigurd 12y ago
- higherpurpose 12y agoWhat about Adam Langley's own Pond protocol, which last I checked replaced OTR with TextSecure's Axolotl ratchet? But I think someone was saying it's quite a nightmare from a UX point of view for now. Any improvements there lately? And couldn't TextSecure be used effectively as e-mail, since it's async, but just put an email-like UI on top of it? https://pond.imperialviolet.org/ https://pond.imperialviolet.org/
- tptacek 12y agoEven Adam Langley doesn't think that large service providers should roll out Pond, presumably because Langley is serious about cryptography and understands that systems like this can take years to iron out and aren't ready for deployment simply because somebody wrote them up. Axolotl is Trevor Perrin's protocol; it doesn't belong to TextSecure. However: TextSecure procured a pretty significant block of Trevor Perrin's attention to help review and improve their cryptography. TextSecure is also, as I understand it, significantly older than Pond.
- shmerl 12y agoCould? Does the article imply that Google plans to do it? I didn't see anything from Google about such plans. Or it's simply "if Google ever does that it would be great" etc.? Google's approach of harvesting the data from e-mail doesn't fit with end-to-end encryption.
- malkia 12y ago... grypto! ...
- carlob 12y agoHas anyone else noticed they spelled pidgin as pidgeon? It's a really weird typo especially when you consider the link points to the right site and it can't be a spelling correction as both pidgin and pigeon are words but pidgeon is not [1]. It's also weird that a news outlet such as wired would make such a mistake. [1] Though you might say it's a meta-pidgin borne out of the hybridization of pidgin and pigeon.
- shkkmo 12y agoHow would that be a 'meta-pidgin'? A 'meta-pidgin' would be a pidgin formed by combining two separate pidgins. What you are describing in [1] is a language change due to user error, not the creation of a pidgin.
- carlob 12y agoThat was a joke: seeing how a pidgin is a hybrid between two languages pidgeon is a hybrid between two words. Nevermind
- pushedx 12y agoImplying that encryption is not already mainstream. What do you think that lock symbol in your browser means?
- greenpresident 12y agoI means your connection to the server is encrypted and that your browser trusts their certificate, preventing stuff like sniffing and mim attacks. It does not mean that emails on the server are encrypted, which is what this is article is about.
- SilasX 12y agoGoogle: if you wanted to take encryption mainstream, you shouldn't have gone miles out of your way to sabatoge compatibility with web email encryption plugins. https://support.mozilla.org/en-US/questions/831463 https://support.mozilla.org/en-US/questions/831463
- glasz 12y agoeven if they did, i'll call anybody who thinks this would make anything better an idiot. google is in bed with the cia via iqt. lord knows what else is behind this. they even work together: http://www.wired.com/2010/07/exclusive-google-cia/ http://www.wired.com/2010/07/exclusive-google-cia/ ppl like to forget the news of yesterday. all is so shiny. all is so well.
- tripzilch 12y agoQuestion, even if Google were to actually do this, given that GMail runs on server-provided JS code inside the browser, doesn't this carry the same problems as all other in-browser encryption applications? Isn't this type of in-browser encryption code considered broken, no matter what way you go about it?