Google backs off on previously announced Allo privacy feature
theverge.com
theverge.com
'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?
Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point)
It's extremely hard for a Googler or product team to do something directly nefarious, but you do have to trust Google's privacy infrastructure.
Or compulsion by any government to which Google is responsible (e.g. Russia, if I Googled correctly). Or a suitably clever Googler (as you note, it may be difficult, but 'difficult' ≠ 'cryptographically secure').
As when Facebook didn't think HTTPS made sense until someone sniffed Zuckerberg's password in a coffee shop, I don't think Google (or any other cloud firm) will take security seriously (as opposed to paying lip service to it for marketing purposes) until someone in the C-suite is materially embarrassed by its lack.
The security whitepaper gives only a hint of what's done, such as checks on former employees' accounts and so on:
https://static.googleusercontent.com/media/1.9.22.221/en//en...
I don't think you can accuse Google of not taking security seriously. They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make, and a legitimate thing to criticize them for. Apple makes a different choice, and it's important that we have a debate around which is the right security design.
But making a claim that Google is not serious about security does a disservice to the really good people there who move mountains to secure the service.
I don't think they take my security, and the security of my data, seriously. They seem to care very much about their security.
> They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make
No, at this point I don't believe that it is legitimate, any more than it's legitimate to sell an oven which will explode if the temperature dial is set above 600° ('just don't set it that high!').
Yes, there are people at Google who work very hard to secure Google's data; there are people at Google (e.g. Adam Langley) who care a lot about users' data. There may even be people at Google who are working very hard to change its course on user privacy.
But Google, the company, does not take the security of user data against privacy threats seriously: if it did, it would use a better architecture (note that Apple doesn't take user-data security seriously, either, since they can MITM any time they want; nor does Mozilla, nor does Microsoft: no organization's hands are clean, so far as I can tell).
Just because Google sells something we don't like doesn't mean they're evil, but it means they have a responsibility to limit the attack surface outside attackers use. There is no way to eliminate all attack surface while still allowing third party admins or closed source code (technically, its impossible period, but w/e).
Google and similar companies have a coherent worldview in which they collect user data, protect it from outsiders and inside threats, and do benign and wonderful things for users in return. Within that worldview, they do an excellent and commendable job. Calling their beliefs on data collection a security issue muddies the debate.
I'm curious about your comments on Apple. If I back up my phone to iCloud, how can Apple "MITM any time they want"?
I was referring to iMessage: my understanding is that it Apple is the CA for all iMessage keys, and thus they can issue a certificate to anyone, if they wish to or are compelled to.
But that's not the first concern one would have. Pervasive surveillance programs have penetrated service providers' data centers. Law enforcement can get warrants to access this information too easily, and many service providers turn over information on request, rather than requiring a warrant.
* Protects you (user) from eavesdroppers between you and Google.
* Protects your data from eavesdroppers inside Google's data centers.
* Protects your data at rest (on disk).
* Protects your data from malicious employees.
* Enforces a great deal of scrutiny over who can access your data, and what they are allowed to see.
But, yes, they process and store your data, so there's no 100℅ secure approach to be had here.
---
SSL only handles the first two bullet points.
There are always weaknesses, but think about why a bank employee can't just decide to take your money. Internal controls are a thing.
That's what ACL is...The encryption doesn't improve the security of the data if the keys are not stored securely. Simply put the data security is as good as the ACL of the keys is. For your peace of mind you may want to know the processes(i.e. audits, ISO standards/certifications) rather than a marketing keyword("encryption", "military grade" etc). Encryption may be part of that framework but I don't think it's relevant enough to be advertised as a stand alone 'product'. You can be sure that your account balance is not encrypted. It's the ACL process that protects you from a rough employee.
We already know that Google has a relative good security process in place. However this is not about security in the first place. It's about privacy. And here encryption brings no privacy gain because Google has the keys so as I previously said it's just marketing BS. Most people are not worried that Google gets hacked. They are worried that Google is selling their data to 3rd parties for profit and to governments for political reasons.
Privacy is mostly not about keeping data from the government. Your bank account is private for most practical purposes though I'm sure with a warrant, law enforcement can find out about it. It's not going to show up in the news and your competitors aren't going to see your bank statements.
Also, Google isn't handing your private email over to advertisers - never has, probably never will.
Authentication and authorization (ACL's) are useful for both security and privacy. This is what makes cloud computing possible (along with encryption, too).
Yes, we can talk about weaknesses in our systems, but let's not completely dismiss the security and privacy features that are already there.
The other case which is uglier is that Google gives your data to foreign governments or other agencies. This may have great consequences. Cloud computing is based on trust and it's possible because the main players(i.e. US government, cloud providers such Amazon) are trusted not to spy their clients but I don't see many rushing to a chinese cloud vendor to host critical data(i.e. email) on their servers.
The security and privacy features we have are currently based on the good will of the provider (i.e. Google). If we talk about encryption of personal data I think it's worth to ask a bit more than a buzzword. One such thing is to do not share the encryption keys.
Only the first point. If Google works like every other data center in the world, then SSL stops the moment your data hits their first load balancer.
https://www.washingtonpost.com/business/technology/google-en...
Still, I wouldn't trust that. I can think of enough cases in which algorithms fed with that information would do things not in my interests. (You could easily imagine some internal scoring or profiling a lgorithms taking advantage of the data for example)
Telling "it's only algorithms" doesn't make it secure it I don't know what the algorithms do. (Which of course I can't as it is the core of their busyness)
All that Google has accomplished, is convinced me to steer clear of Allo.
The NSA have already backdoored it.
Unless the user is the only party that can access the keys (i.e. they are only stored locally on the user's device), then I'm sure Google will it very easy to access personal information when a government demands access.
Or did we forget that Google is part[1] of PRISM?
If both you and your correspondents do use 3rd party IM client ([1], [2], etc), then just run OTR2 or OMEMO on top of the protocol, and let google store whatever it pleases - it's not going to be much use for them.
Can we please use technical terms with precision?
You can have data encrypted at rest and in transit that is still accessible to the provider and the fact that the provider can decrypt it for processing doesn't make it any less "encrypted". There is not a total ordering of encryption or security schemes.
If you would like to say that the data isn't end-to-end encrypted such that it is opaque to the service provider -- say that. Don't say it isn't meaningfully encrypted.
https://medium.com/@Numerai/encrypted-data-for-efficient-mar...
So, in order to perform machine learning on terabytes of data, you need to flip terabits for every update of the homomorphic state machine.
That being said, I could imagine someone coming up with a homomorphic encryption algorithm that starts out with a few megabits of excess entropy and leaks entropy at a bounded rate while remaining more efficient at calculation, and where the initial state is set up cleverly such that after a bounded number of steps, the state machine starts making nonsense computations and stops leaking entropy. Though, this just feels very brittle to intentionally leak entropy, and I have no idea how anything remotely like this could be actually constructed.
However, it's better just to encrypt everything and not be tempted by the advertising surveillance dollars.
So, not meaningfully encrypted at all then?
One could also think of it as your private key being with (1) you, (2) Google.It's in safe hands ;-)
Instead of worrying about what "safe hands" mean, just keep it accessible only to me, and each respective conversation with the people I communicate with.
One could also argue that the service is free and the service provider needs a (or yet another) way to monetize it.
If the privacy settings are insecure by default, one shouldn't have high expectations anyways.
True, which is why I pay Apple money. No incentive to mine my data... in fact given that privacy is a big marketing angle Apple's incentives are to make it impossible for them to access your data even if subpoenaed or presented with a warrant.
http://www.theverge.com/2016/5/18/11699122/google-allo-messa...
> First, all conversations are encrypted "on the wire," which means that nobody on the internet can read them as you send your message. They are read by Google's servers, but Kay assures me that the data is stored "transiently," which is to say that Google doesn't keep your chat logs around to be subpoenaed. And Fulay adds that Google doesn't assign identity to the chat logs on those servers even then.
I think this is a misunderstanding -- either on the part of the authors or from the Google employees on understanding the question asked by the authors.
Kay probably meant that in Incognito mode, messages are stored transiently. I don't believe that has changed, has it?
Did Google really say that non-Incognito messages would not be stored server-side? What happens if you lose your phone -- do you lose all your Allo chat history? That would be a really shitty user experience.
This is the same reason even WhatsApp's use of 'end-to-end encryption' cannot be considered secure from WhatsApp.
The main issue here is that people aren't worried about either of those problems :) otherwise Facebook, Google and other advertising companies would only have a handful of users.
> These are two very distinct issues and not everyone is concerned about both equally.
Divide and conquer... not. The issue is the same, we should fight together for more privacy, not disregard other people's reasons for requesting more privacy.
In any case, as you were replying to my previous comment, my point was that if the company has access to your data, Law Enforcement has got it too. Also if Law Enforcement has access to your data it means it wasn't also available for the company. Hence why one implies the other. You might be worried about one, but you've got two :)
It needs to be established as a human right.
I'm personally very disappointed to see the how good intentions of the aware subset of the citizenry are consistently channeled towards technical solutions to a problem that is fundamentally political.
At a meta-level, we saw the same (useless) dissipation of energies in the Occupy-x movement. And it should also be pointed out that the subtext of such approaches is de facto deligitimization of legal governance of societies and (speaking of "kings") establishing corporations as the arbitrators of social norms.
Get congress to pass a comprehensive privacy act and "Alphabets" (of the corporate and governmental variety) will have to toe the law of the land.
[edit:spelling]
It already is. Article 12 of the universal declaration of human rights:
No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.
When marketers collect my personal info, it's far more likely to be distributed widely so I place a greater emphasis on protecting it from them. I don't like the fact that nation-states are spying on the citizenry, but I don't know what I can do about that. I DO know what to do about the surveillance capitalists.
https://en.wikipedia.org/wiki/Martin_Luther_King_Jr.#NSA_mon...
How do you know this is a fact, was a global survey done?
>I am more concerned about A than B" is not a claim that B does not exist, nor is it a claim that "I" am unconcerned about B.
Indeed, however the phrase "100% tinfoil hat mode" does imply being unconcerned about B, and that anyone who is is a lunatic.
Now, to be clear, by "people" I mean "humans" not "abstract sentients including AIs that don't yet exist", and by "concerns" I mean "things that are at least slightly negative to the thinker" and not "things that keep the thinker up at night wetting the bed and driving them to fits of existential madness", etc. etc.
Probably 'yes' for you, 'no' for him.
Sorry, but a random HN commenter is extremely unlikely to be targeted for the level of surveillance and treachery that Dr King was. If he feared it, he had good reason. If you are some random IT worker building the next smart pillow you cannot expect them to prioritize spying on you, that's all I'm saying. Mass surveillance isn't the same as targeted.
How many people here work for Google, Facebook, Apple, etc? What if you could compromise their workstations and get privileged access to the backend of social networks, email systems, etc? We are being actively hunted and there's evidence of that.
It's such a standard and effective method in human intelligence, that it's extremely naive to think an analogue wouldn't be used extensively in signals intelligence too.
Whether the culprits' organizational classification is public or private is of negligible importance.
>Mass surveillance isn't the same as targeted.
Mass surveillance is the first step in the discovery process, targeted surveillance is the second step after a target has been flagged by the dragnet.
A random IT worker building the next smart pillow has no reason to target you...but the creepy pervy sales manager at the same company might have reason to.
That isn't quite accurate. Your information is extremely valuable for identity thieves and for spammers and for running other scams. I guess you've never had your identity stolen or been harassed.
Curious if he'll comment on what happened:
https://news.ycombinator.com/threads?id=moxie
___
If you don't know about Moxie, highly suggest learning more about him:
His "trust us, we checked FB Messenger code and it's all good" pitch made for a very entertaining read.
>> ""F-Droid has received criticism for distributing out-of-date versions of official applications and for its approach to application signing."
Thats not a bug, it's a feature
Ultimately, it's his baby and he can do what he wants with it.
I don't know Moxie, but we've exchange messages before and never got the sense that off the cuff he was discounting any feedback. At a very highly level we agree about what he's doing, though I get the sense that anonymity is something we don't exactly agree about, but do understand a little of why he feels the way he does.
Thanks but no thanks, google. Stay evil.
Wow. Google went a full 180 from being a company that promoted itself by saying "Don't be evil" to something evil. Couldn't Google have made its billions still being not evil, without its privacy issues, without its obnoxious desire for tracking everything. Did they turn to this evil for the money or just because they can do it (or if not someone else will).
No. Google is advertising company and advertisement companies need a lot of user data for targeted ads.
There's even crap like Android not allowing you to selectively turn off the Internet Permission for apps, for which there is no good reason other than Google needing an internet connection to display their ads.
Sigh, I'm not arguing that they don't collect for advertising, I'm not even defending them at all. It's just that the things they do are impossible to do without a huge amount of data, regardless of advertising. Again, if you're so sure that it is “simply not true”, here we are, YC is your oyster. Or any other tech VC fund for that matter.
It's the incognito that are end-to-end encrypted and I expect are secure from Google's prying eyes. And I don't think anything has changed there.
This is a non-issue for me, anyway.
It's clear the public wants some assurances around privacy, or at least transparency where it is lacking. Not to mention, this is the umpteenth product they are planning to deprecate, uh, I meant launch (Grand Central, Voice, Wave, Talk, Hang Outs, etc).
Kind of creepy I say.