Edit: it appears the NSA has google's ssl keys. That would explain all the talk about "direct access".
Edit: it appears the NSA has google's ssl keys. That would explain all the talk about "direct access".
It is also possible they just got the keys from spies. In my company, anyone with sudo access to front end machines can get the keys. I have no idea how to keep these keys secure from the NSA.
[1] http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-se...
Sure it could. First, it would be accurate: TLS keys give you the ability to decrypt communications, which is distinct from direct access to the servers (though, obviously, it can easily substitute for it.) Second, even if it wasn't an accurate distinction, people can (and do) argue positions on unsound bases, and Google doesn't seem to be especially incapacitated in that regard.
This is the only explanation that makes sense. Some secret court compels Google to provide their TLS keys, which is a a few kb of data. No one at Google has to know, and no one at Google can accidentally detect the leak.
Also, can you clarify for me why you think giving someone access to eavesdrop overlaps with "direct access to servers"?
If what I say is correct, Larry Page's statement is 100% defensible.
The slide about how traffic is routed through the US is really telling. This program works because there is access to the packets.
This would require them to have to know, and be kept up-to-date, with how every one of their applications sends data across the wire.
It is the only way to get access to the data without requiring a vast conspiracy. If they had direct access, thousands of employees would know something was up. If they MITM, then lots of people would notice. If they had a way to actually break TLS, then there would be no slide about "providers".
All you have to do is read session cookies. Once you have that, you are done.