4 ms·
Abit harsh on Google. I mean what are they to do?
by rasterizer 13y ago
Abit harsh on Google. I mean what are they to do?
- betterunix 13y agoMaybe engineer a service that is harder to wiretap? It is not easy, but they have some of the best computer scientists on this planet working for them. If I were them, I would start somewhere around here: http://crypto.stanford.edu/adnostic/adnostic.pdf http://crypto.stanford.edu/adnostic/adnostic.pdf
- walls 13y agoWire tapping is completely irrelevant to the question.
- betterunix 13y agoWiretapping in this context refers to both getting information on the wire and getting information stored on Google's servers. At this point the distinction between the two is completely pedantic.
- tptacek 13y agoIt's not directly apropos this particular thread, but Google has engineered an email service that is particularly difficult to wiretap. To wit: (a) They're the Internet's foremost adopter and proponent of DHE ciphersuites, which drastically reduce the impact of losing the RSA key that underpins most site's TLS security, and, just as importantly, forces adversaries to actively MITM every connection in order to decrypt them. (b) They're a pioneer in key pinning, which bakes the identity of their key into the Chrome browser binary, meaning that when your Chrome browser talks to Google's mail service, it's unlikely to trust any otherwise- valid- looking certificate presented by a MITM attacker. Google's mail service is better encrypted than most banks.
- grinich 13y agoIn these particular instances, though, information is much more valuable than money.
- tptacek 13y agoNo, I don't believe that's true. The information in your mail is not more valuable to Google than the integrity of a bank account is to a bank. Google has a financial interest in having access to the content of mail messages, but (a) it's an interest "in the large", not in any specific account, and (b) it's a nonrivalrous interest.
- embolism 13y agoDifficult to wiretap in the sense of intercepting communications to and from Google, yes. But it's also engineered to give Google itself access to your data so they can improve their behavioral profile of you. I think what people are suggesting is that if end user privacy was Google's priority rather than gaining access to user data for their own use, they could engineer a service that didn't place themselves as a man-in-the middle.
- jkn 13y agoAm I right that a) applies only to direct communications between the end user and Google's servers? Actually if someone sends an email to my Gmail account using his ISP SMTP server, is the connection between the two SMTP servers likely to be encrypted?
- icebraining 13y agoEven if it is encrypted, I doubt it's authenticated.
- sneak 13y agoWiretaps almost never involve active MITM. This is a red herring.
- andor 13y agoThey're a pioneer in key pinning, which bakes the identity of their key into the Chrome browser binary, meaning that when your Chrome browser talks to Google's mail service, it's unlikely to trust any otherwise- valid- looking certificate presented by a MITM attacker. Chrome doesn't pin actual certificates, just public keys of CAs. If some organization had access to Verisign, Equifax or Geotrust keys, they could just create new certificates for *.google.com, which Chrome would accept.
- embolism 13y agoGoogle's business model is to tap your communications and use the profile they create of you to target advertising. They are constantly pushing for access to more of your personal information, not less.
- betterunix 13y agoSee the link in my post.
- acdha 13y ago> Maybe engineer a service that is harder to wiretap? You can't solve a legal problem with engineering. We're talking about the same agencies who had the ability to get all of the major phone carriers to install wiretapping services – there's no reason to believe they wouldn't do the same to anyone else of interest.
- betterunix 13y agoYeah, but if you read the linked paper, there are things Google could do to protect its users' privacy. That paper is about privacy-preserving targeted advertising, which would not give Google anything for the government to subpoena or search while still allowing them to conduct their business. There is no reason Google has to make itself an easy target.
- embolism 13y agoYou're making the assumption that that proof-of-concept behavioral tracking solution is anywhere near as effective as what google already does. Google doesn't want the profile to be stored privately in your browser because then they can't use it to target you in other situations.
- betterunix 13y agoWhich is why I said they should start there. I did not say it was a completed solution. Right now, Google is not even trying to protect their users by any technical means, relying instead on the courts.
- embolism 13y agoI absolutely agree that they aren't even trying, but starting there would reduce the effectiveness of their ad business and hence reduce revenue, so I don't see that happening.
- jwr 13y agoDie. Lose to a competitor that is based in a free country and/or offers a paid service and therefore does not need access to the entirety of people's data to serve ads.