Besides, they haven't exactly replaced their supply chain and brought everything in house. Much of their hardware is coming from the same sources as their competitors.
This a reasonable thing to outsource: let someone qualified build their own.
What about building silicon and have the project zero level security experts in house?
Disclosure: also work at G.
Samsung has a project zero team that secures their smart TVs for obvious reasons.
A friend of mine cracked all their security with his ass on home couch and now works for them as an external security expert.
I can cyte one of those "senior security expert architect" from Samsung during their meeting with my friend:
"It's not possible you found a level zero vulnerability in our software, we are the best of the best".
Few minutes later that security architect was fired..
TL;DR inhouse experts often dont mean much, there is a whole world of even better experts who sit on couch at home and hate corporate world..
I sincerely doubt your entire story, especially the "few minutes later that security architect was fired" portion.
[1]https://www.washingtonpost.com/business/technology/google-en...
The security of Chrome is astounding (and certainly far better than Apple or Microsoft).
The only black stain is Android... (Edit: disclaimer: I use Android)
Google has a very fundamental conflict of interest w.r.t. privacy that stems both from revenue (advertising) and product development (e.g., labelling personal data acquired from consumers). Google will almost certainly act against their data product producers (individuals) best interests based on its very deep requirements to obtain private benefits from not protecting them.
* I have no way of knowing if they actually delete any personal data when I ask them. I suspect that they just don't show it to me anymore.
This is the kind of thing that you go over laborious detail in over privacy design docs at Google to make sure you have it covered.
Source: I'm a Xoogler.
How would you rate Google's use of Location History to tell advertisers when you visit their store in terms of "very good privacy controls"?
"The AP learned of the issue from K. Shankari, a graduate researcher at UC Berkeley who studies the commuting patterns of volunteers in order to help urban planners. She noticed that her Android phone prompted her to rate a shopping trip to Kohl’s, even though she had turned Location History off.
“So how did Google Maps know where I was?” she asked in a blog post ."
"At a Google Marketing Live summit in July, Google executives unveiled a new tool called “local campaigns” that dynamically uses ads to boost in-person store visits. It says it can measure how well a campaign drove foot traffic with data pulled from Google users’ location histories."
"Google also says location records stored in My Activity are used to target ads. Ad buyers can target ads to specific locations — say, a mile radius around a particular landmark — and typically have to pay more to reach this narrower audience." [1]
It is virtually impossible to certify that any given disclosure, no matter how grouped, anonymized, fuzzed, etc. is incapable of being re-associated given other data and time.
I also do not subscribe to the rather expedient definition that your privacy hasn't been violated as long as no human has seen the data. That's an unsupportable claim. As long as my privacy is only a millisecond away from anyone's view on whim, mistake, or trivial disclosure, or some automated system has made some decision that affects me based on my private data I have been violated.
Unfortunately, not a lot of it is public.
I just correct it when i see it, and don't worry about it otherwise.
I'm really disappointed, but I have hopes Kurian will shake it all up and move things up and to the right.
I know they lay down their own network cables.
I cant readily find a link, but their rack-mount servers are I believe "custom" designs just for them (presumably done in-house too), although from what I know they use off-the-shelf CPUs from Intel and AMD (there was an announcement very recently that they were using Epyc now for example) & GPUs etc.
It would not surprise me if only the x86 CPUs & GPUs were the only external things they use, and I bet they're looking at their own custom ARM chips for certain workloads (like they use their custom TPUs for certain workloads).
1 - https://www.wired.com/2015/06/google-reveals-secret-gear-con... 2 - https://www.theregister.co.uk/2018/07/18/google_dunant_cable...
But they probably use standard chipsets.
This statement holds water only to a handful of companies that can actually afford to build their own silicon.
OTOH, the intended message could be “you can't fully understand the issues without the insight gained by building your own silicon”, in which case it would be just as true of companies without the resources to build their own silicon.
Building your own silicon is the last thing you do to ensure security even if you are Google, you only do that when it’s the last broad viable attack vector left for your adversaries to exploit.
As I’ve stated already it’s the last thing you do when you think about security not the first.
When the security posture of your code, configuration, facilities, supply chain etc. is so good that the only attack vector left for adversaries to exploit to compromise your organization in a sufficiently broad manner is the hardware is when you start thinking about building your own silicon.
Or when ofc there are actual business needs for this e.g. you want to be independent of other SoC/ASIC designers or there aren’t any solutions that meet your needs.
Which also comes to the actual point other than the Google key/hsm solutions that look more of a rebadge than a home grown design Google is focusing on things like the TPU due to business reasons aka $$$ not security.
Google isn’t going away from Xeon/EPYC or x86 any time soon, and I find it very questionable if anyone would make a security argument against NVIDIA GPUs as far as Google goes since Google even wrote their own driver stack and CUDA compiler.
As in relying on logical separation of client traffic rather than physical one so they don’t need as many physical ports, switches and most importantly network cables(often the highest actual cost in many data centers as far as networking goes)?
Buying gold plated cables?
I’m not sure if anyone actually uses VXLAN yet.
You didn’t actually made a point because you haven’t provided proof that what Amazon did for AWS wasn’t done because of operational requirements.
But that was not the message, is about understanding risks.