does it do that? Or does it just show you times that Google is willing to tell you Google employees snooped on your files?
does it do that? Or does it just show you times that Google is willing to tell you Google employees snooped on your files?
The truth is twofold.
One: if the barrier can be melted according to magic rules, then it is no real barrier. It is a sweet candy coating that melts in your mouth, not in your hands.
Two: if a corporation is made of many incidental strangers who happen to share an employer for overlapping moments in time, and the system has at least one authorization bypass, then so does the audit trail.
If you don't think corporations implode, suffer from disgruntled criminal employees, sell out to rivals, go completely bankrupt, or land themselves in jail, then bet all of your secrets on the idea that what they tell you is 100% truth.
* Strong identity: employees must be strongly identified before acting.
* Multi-party authz: nobody ever acts alone. One person can't be trusted, two people might be, M of N effectively represents the company.
* Noisy security: making a change to security parameters notifies all relevant parties in a way that intentionally avoids notification fatigue. You can't sneak a change through.
* Full auditability: even after the fact you can readily unravel what was done, seeing what the old state was, what was changed, who made the change, and who approved it.
Get those points, and a few other minor details, and this larger problem actually becomes tractible.
The following isn't about Google as such: Thing with a disgruntled criminal employee is that they don't usually come in bunches and don't collude because they can't easily identify each other. Which means they can't generally commit such acts and then also corrupt a whole 'nother department to cover it up.
This doesn't protect against government action, and not at Google leadership specifically targetting you. But it does prevent the (rather common) abuse of such access by regular employees.
Could’ve fooled me. Or maybe your standards are just particularly low. Do you mind explaining where surveillance capitalism fits into your principled worldview?
https://www.theregister.co.uk/2019/10/08/fbi_spying_abuse/
I'm not entirely sure the old generic answers apply these days...
SOC seems to be the gold standard in terms of what enterprises are asking for, these days. Not that it addresses all the concerns as discussed here, but it does probably start to answer your question.
E&Y does (apparently), and Google is compliant with some ISO standard for software security. See "Does giving Google access to my data create a security risk? How does Google ensure that its employees do not pose a threat?"
As a security person I really can't think of any service (or piece of hardware) which I think satisfies the threat model where the provider is both clever and truly hostile.
You personally might not be able to do that (but then, you personally might not be able to spot a defective authenticated key exchange either), but people can. Once someone spots the "Signal Backdoor", that's it for Signal. There's a lot of incentive to do that legwork.
In contrast, G Suite could be comprehensively backdoored, and you'd have no way of knowing, no matter what your level of systems programming competence. I'm not saying they are backdoored; I rather doubt that they are, and I myself trust G Suite more than most other applications I use. But the point is, the trust you have to have in G Suite is different and more demanding than the trust you have to have in Signal.
Even if we can trust the binary (and I agree, with Signal as the example we probably can), the application distribution mechanism and the underlying OS and its update mechanisms are still a problem.
That's moving the goalposts to individual targeting, though. The individual targeting scenario is not that interesting because, as the winged quote from the technical literature goes, "YOU’RE STILL GONNA BE MOSSAD’ED UPON".
If you truly cared you wouldn't download it from Play Store and you wouldn't use a stock Android ROM.
Of course that moves the problem up to the firmware level but the attack space is getting narrower.
With G Suite you rely on trust from the ground up.
...I can. Disconnect from the internet.
It's a pain, and it won't be useful advice in many cases, but if you're a newsroom doing sensitive investigations on powerful individuals? I could make a case for it. Although, you'd want to ditch G Suite.
(You can certainly think up clever attacks that work without internet, but disconnecting really does remove most vectors.)
Instead of "trust us to keep your data", what if Google said "we don't have your data." That would give me more confidence, since it both makes the hostile actor's job much harder and it's also easier to verify.
We shouldn't start saying it for things that prove nearby but entirely different things just because we won't ever be able to say it definitively.
A lot of effort goes in to ensuring that audit trails are non-optional.