Google encrypts data amid backlash against NSA spying
washingtonpost.com
washingtonpost.com
[Eric] Grosse echoed comments from other Google officials, saying that the company
resists government surveillance and has never weakened its encryption systems to
make snooping easier — as some companies reportedly have, according to the Snowden
documents detailed by the Times and the Guardian on Thursday.
“This is a just a point of personal honor,” Grosse said. “It will not happen here.”
Some folks are inclined to distrust Google, but there are people here who really, really care about security.I'm not convinced that this is not Google's version of "trust us". Keep in mind there is no PR loss for Google to adopt a pro-encryption stance now. If they are really serious about this, they would a) stop trawling emails and b) help develop tech for seamlessly encrypting both in-flight and at-rest email.
"This company reads, on a daily basis, every email that's submitted, and when I say read, I mean looking at every word to determine meaning," said Texas attorney Sean Rommel, who is co-counsel suing Google.
http://abcnews.go.com/Technology/wireStory/google-argues-con...
http://www.mercurynews.com/business/ci_24021944/google-argue...
I didn't come here to be propogandized at, so, yes, I will object to the dumbing down of debate to appeals to emotion (especially on a subject that's obviously already so emotionally charged).
http://www.nola.com/business/index.ssf/2013/09/google_argues...
http://news.yahoo.com/google-argues-continue-scanning-gmail-...
http://www.nbcnews.com/business/google-argues-right-continue...
http://www.mercurynews.com/business/ci_24021944/google-argue...
Download Thunderbird and a PGP client[1]. Boom, done.
Use another email service. Boom, done.
I'm not objecting to the idea that you'd find it objectionable to have your email contents used for advertising. I'm objecting to a useless quote that tries to turn this into a soundbite-off instead of an actual discussion (little hope as this thread has).
[1] https://support.mozillamessaging.com/en-US/kb/digitally-sign...
[1] http://www.nytimes.com/2013/09/07/us/politics/legislation-se...
“This has been the stuff of wild-eyed accusations for years. A lot of people are heartbroken to find out it’s not just wild-eyed accusations.”
The problems with the third-party doctrine are much more fundamental than the ways in which that third-party is storing and displaying your data, activities that continue for any webmail client even in the absence of ads when doing spam filtering, searching, etc. Merely the fact that a third-party is involved at all is enough for the outdated sections of the ECPA to rear their ugly heads. Here's hoping the Supreme Court takes up a case like US v Warshak soon.
[1] http://arstechnica.com/tech-policy/2013/01/google-stands-up-...
Your talking statutes, not the constitution. Obviously the constitution trumps both statute and executive readings. Reasonable is per the constitution, an it is plastic in case law. That's why the questions are important, fundamentally. In any event, its worth keeping in mind the right level of abstraction.
I'm talking both. The ECPA was important in that Congress avoided decades of court cases by making explicit the protections afforded electronically stored media, though they did not extend those protections far enough (which today in practice weakens protections that may have been more clearly delineated by now had the ECPA not been enacted).
Constitutional protection superseding (among other things) the fairly arbitrary 180 day requirement for a warrant set by the ECPA was clearly recognized by the Sixth Circuit in the US v Warshak second (criminal) case, stating that "The government may not compel a commercial ISP to turn over the contents of a subscriber’s emails without first obtaining a warrant based on probable cause."[1]
In both US v Warshak cases, though, the Sixth Circuit emphasized the higher protection afforded content over transactional data just for being content by the the tests established by both Katz v US and Smith v Maryland. They laid out that even the supremely terrible precedent of Smith v Maryland (which is the proud parent of allowing the government to seize "metadata" without a warrant) did not allow the government to "bootstrap" limited access to full access, including the access needed for automated processing of email contents by the email provider:
"The government also insists that ISPs regularly screen users’ e-mails for viruses, spam, and child pornography. Even assuming that this is true, however, such a process does not waive an expectation of privacy in the content of e-mails sent through the ISP, for the same reasons that the terms of service are insufficient to waive privacy expectations. The government states that ISPs “are developing technology that will enable them to scan user images” for child pornography and viruses. The government’s statement that this process involves “technology,” rather than manual, human review, suggests that it involves a computer searching for particular terms, types of images, or similar indicia of wrongdoing that would not disclose the content of the e-mail to any person at the ISP or elsewhere, aside from the recipient. But the reasonable expectation of privacy of an e-mail user goes to the content of the e-mail message. The fact that a computer scans millions of e-mails for signs of pornography or a virus does not invade an individual’s content-based privacy interest in the e-mails and has little bearing on his expectation of privacy in the content. In fact, these screening processes are analogous to the post office screening packages for evidence of drugs or explosives, which does not expose the content of written documents enclosed in the packages. The fact that such screening occurs as a general matter does not diminish the well-established reasonable expectation of privacy that users of the mail maintain in the packages they send."[2]
I have not personally seen a good argument for differentiating between spam filtering and contextual advertising in terms of access. Regardless, this is a clear argument for automated access being immaterial to the question of an expectation of privacy of the contents of an email.
[1] http://www.ca6.uscourts.gov/opinions.pdf/10a0377p-06.pdf
[2] http://www.ca6.uscourts.gov/opinions.pdf/07a0225p-06.pdf
Are you seriously proposing free e-mail and/or a spam filter is a good trade for one of the major pillar Bill of Rights? So goes my spam filter, so goes the constitution? What's ironic is that the spam guys use 1st amendment to justify the spam (same as junk mail and the credit rating agencies).
What? Where are on earth are you getting that from what I'm writing?
I'm saying that the Sixth Circuit has ruled that just because you use an email provider that scans your email contents for things like spam (or ads), you have not given up your 4th amendment right for that content to be secure against searches without a warrant.
What you quote is me arguing that your premise that contextual advertising is somehow distinct compared to scanning for spam both in function and legal implication is flawed. The next statement states that even if such a distinction could be made, the above quote from US v Warshak I is a perfect explanation of why agreeing to automated scanning of your email does not imply consent to an abrogation of your rights.
I really don't see how I can be clearer than "The government also insists that ISPs regularly screen users’ e-mails for viruses, spam, and child pornography. Even assuming that this is true, however, such a process does not waive an expectation of privacy in the content of e-mails sent through the ISP...."
Its flawed because that premise is at once irrelevant and falsely asserted. Neither a spam filter nor contextual advertising are inherent to private communication.
What is relevant to private communication is that it is private. If I CC larry page on a "private and confidential" e-mail to my lawyer, Mr page is a party to the conversation. It is no longer "private" nor "confidential". If every e-mails sent to a g-mail account is by default cc'd to Mr page, none of those communications are "confidential". By (statute) law, the senders are forfeiting attorney client privledge...by "opening" the communication to a thrid party. Its google's stated position that person sending an e-mail to a g-mail account has a no "reasonable expectation of privacy". And this is what that means. This means that google (wants to) treat your mail like Mr page is reading it, and it believes that users are in fact waiving their expectation of privacy by using or communicating with g-mail recipients. That includes presumably senders of mail who have not agreed to g-mails T&Cs (ie, who presumably do not have reason to know what they entail).
It is the insertion of an active third party into the communication which is a problem. Its a problem because it damages the inherent idea of 'mail' as a sender-recipient private relation (post office =/= an active recipient). And from here, the problems start.
In any event, I think you are missing the legal abstraction at the core of the analysis. Its not a problem you can wish away, nor is it one you can trust current statutes of case law to protect into the future. That is the nature of 'reasonable' modifiers; they are ultimately contextual. And here, we have self-interested parties strategically eroding the context of the 4th amendment, to the detriment of the the public at large.
> What is relevant to private communication is that it is private
This is not the basis for 4th amendment protections. You are also confusing things: attorney-client privilege comes to us from Common Law, not the 4th amendment and is not a good basis for discussing what is private, as there are many more restrictions on it (a warrant can almost never compel your attorney to testify against you, for instance, which is not the case for almost all normal communications).
The mere existence of a third party does not negate the reasonable expectation of privacy, otherwise no third party communication system would be safe from warrantless searches. What has long mattered is the reasonable expectation of privacy, which under current case law does not always but in many situations does override any details like the extent that a third party is involved in that communication (for instance, cc-ing Larry Page on an email does not make a message suddenly have no expectation of privacy any more than sending it to anyone else, as the limited list of recipients makes it on its face not for publication or public posting).
> It is the insertion of an active third party into the communication which is a problem. Its a problem because it damages the inherent idea of 'mail' as a sender-recipient private relation (post office =/= an active recipient). And from here, the problems start.
Again, this is wrong. The fact that there are people at the post office, people that could open your mail, people that do actively examine your mail for things like drugs or bombs does not negate your 4th amendment protections. Are you reading anything I'm writing? That's directly addressed in the quote three posts above this one.
> In any event, I think you are missing the legal abstraction at the core of the analysis.
This is just silly. What you are suggesting is that the third party doctrine has overruled all, and that merely using an email provider that scans for spam or looks for abuse has left you open for warrantless searches (which is almost all of them except ones your run yourself since open mail relays are virtually extinct). Not only have you provided no evidence for this belief, the ECPA says you are wrong for emails newer than 180 days, and it looks increasingly unlikely that the courts will agree with you for emails that are older.
You appear to be confusing Google saying that people sending email to users of gmail expect their emails to be handled by the machines that run gmail (or they should, because that's the only way it can physically work) with an argument about the 4th amendment. Breathe easy. That is not the case. Whether or not Google is breaching the plaintiff's expectation of privacy (and it would, again, be bad news for every email provider out there if they are found to), scanning your email is not publicly posting your email, and this tort case has no bearing on your 4th amendment protections from searches by the government. This was established in Katz v US 46 years ago, and remains true today.
Encryption keys are like car keys - you need to own them, not Google.
Maybe it's just a semantic difference but I would argue that that is a sufficiently big differentiator.
I, and many others, would appreciate it if they fought such things. And if they would fight the good fight on the policy fronts. But ultimately Google does not make or interpret the law.
How many here encrypt replication data between data centers?
If you are actually trying to hide something from a targeted government attack, you certainly don't want to use any hosted services like Google's.
If, however, you are merely trying to avoid the government passively sweeping up all of your data, searching through it, and maybe subjecting it to further scrutiny due to it containing the wrong keyword, it helps to know that it's encrypted in transit, and that in order to decrypt it, someone has to actually present a warrant to Google.
Of course, there's the additional problem of National Security Letters, as they aren't really real warrants and they have the secrecy around them.
These problems can be attacked on multiple fronts. We can improve cryptographic security, and work on more decentralized approaches to online services, and reign in the NSA's power at a legal level, and so on.
From what was published recently we know NSA has proven methods for bypassing encryption, namely getting the keys used for encryption (so they can decrypt everything) or getting access to the content before encryption or after decryption.
To me this last move by google is a PR attempt at regaining people's trust
They crop up in every submission detailing an action taken by Google with regards to the Snowden/Prism/NSA revelations. Is it so ridiculous that a large corporation should seek to ameliorate its image in the eyes of users and shareholders?
PR has become such a dirty word.
Of course it would be best if all these actions were taken earlier, purely as the result of a strongly held principle. However, when presented with the realities of public businesses operating on a global scale - I am glad that such steps as those detailed above are taken: at whatever stage, and for whatever reason.
The tinfoil hat brigade needs to, as the old saying goes, "stop seeing reds under the beds" and occasionally ... just occasionally ... take the facts presented to them.
In times when misinformation and confusion is so wont to proliferate, attempting to discern true motive is almost ridiculous - condemnation on the basis of any such discernment doubly so.
That being so - dismissing something as "just PR" misrepresents the actual benefits something like this may confer.
Chrome sync is probably the strongest example that I can think of fitting your criteria, since it's built into the product itself, but a lot of this just comes with the territory of web-based apps.
When they provide an option in GMail for people to upload their public PGP keys, and then start encrypting email on the way in, and don't store any non-encrypted versions of those emails, and build PGP support into Chromium for accessing those emails. Then they will have done something worth noticing.
Step 1. Spam filter
Step 2. Encrypt
Searching:Client side tool which builds a local index as messages are decrypted to be read for the first time. The index is it's self encrypted and incrementally synced between clients.
That took me less than 5 seconds to think up. Google can spend time and money thinking up better solutions if they want to actually do something.
Search indexes are very large -- you don't want to double or triple the amount of storage your email client uses. Also, being able to search only mail that you've downloaded and decrypted is a terrible user experience. I'd estimate over 60% of the mail to my personal inbox is from some automated system, rather than directly from a human, and I typically don't look at them unless a search hits them.
It takes 5 seconds to think of solutions with terrible security and usability characteristics. Thinking of a system that will be a measurable improvement in security and will actually be used by people is much more difficult.
The fact that you can't identify any ways in which they could, or refuse to acknowledge them, or think they're too difficult for a multi-billion dollar company makes no difference to the point under discussion.
Up until today, Google didn't even encrypt the data. So it's kind of hard to weaken something you weren't even using.
And then to go on to equate it as a "personal honor".. you've got to be kidding me.
That's not what the article says. The new encryption is specifically for backend datacenter-to-datacenter traffic over leased lines. But even before that project, there was lots of strong encryption being used all over Google: to encrypt user data on servers' hard drives, to encrypt data going between browsers and servers, encrypting tape backups before sending them to offsite storage facilities...
'We just sent data in the clear over leased lines so the NSA could read whatever they wanted. But the encryption we never used was never weakened.'
This is nonsense.
Not only that, but when the data is transmitted, that is exactly when Google has the least amount of control over it... ie: that's when encryption is the most important. Yet, they chose not to encrypt the data, and then give everyone a story about their 'personal honor' of keeping things secure. This is a joke.
Bottom line is, if a capability exists, it can be exercised, willingly or not, coerced or through oversight. Anyone willing to put data in the cloud should be conscious of this no matter what the provider says.
Even without that, trusting companies because their employees are honest is hard.
There are some people at the NSA who really really care about privacy and not spying on US Citizens and believed we didn't do so. In fact, most of the ones I've met. However, with sufficient compartmentalization, they don't know what they or others are truly doing. Same can be true for any company.
Are you working on Google's data liberation system to not trap users in your system or are you working on NSA's data exfiltration system for Google's data. I's not always clear.
Encrypting it and securing it very well at a technology level means that the human element (I'd argue) becomes the easiest way to get access to it - i.e. someone with sysadmin access, DB access, or just working on a project where the APIs and/or tools available can produce valuable information. This is true even if the 'player' (with system access) has to be 'recruited' by the attacking or defending team some time after taking up the job.
Couple this with the fact that even the security agencies themselves are prone to corruption, malfeasance, human error, (no-one is perfect), and insiders, and you could easily end up with a confusing mess. Bear in mind that everyone wants their agents to operate and be able to communicate back without detection, again regardless of which team.
Compartmentalization must also come into conflict with inter-agency sharing rules -- at some level, people need to know what is going on and make decisions -- and trust must be a big issue for many of these groups - they probably spend a ton of time watching themselves and others, and watching for information leaks / canaries / spread of misinformation.
I'm certain there'll be some fascinating stories eventually from all of this - it all continues to make me believe that concentration of power and information (which I think are continuing as a trend) only end up in creating dangerous situations, and that decentralization is ultimately the preferable way to go (in that it prevents a small number of people from having too much power/influence/control, and equally protects those same people from being targets themselves).
I'd find it hard to believe that there are people that don't fit that profile but are moles for governmental intelligence agencies even exist.
Real spooks don't carry a conscience, they'll exploit anything they can to get their grubby hands on the data they need.
"For all you know, some 20-something long-haired unix
hotshot could have been busted for drugs at some point and
"repurposed" as a mole in exchange for leniency."
Excellent point. Previous comment retracted.For example, at a past sysadmin job, I was asked about the technical feasibility of monitoring a certain employees computer use, whom management suspected of some minor infringement. I refused to assist in the matter on moral grounds and was reprimanded. The task was given to a colleague of mine who had no qualms about it. Next time, they went straight to him.
And the more complex, distributed and large a system is, the more people are in positions where they can compromise it. It takes only one person to break the whole system (which is basically what just happened to the NSA). Do you trust everyone who has or can gain access to your SSL private key? Everyone who manages your network?
Some folks are inclined to distrust Google, but there are people here who really, really care about security.
You bringing us to tears Mr Googler. I remember the "personal honor" or whatever about being adamant in providing the best results (now full of Google crap and advertiser sites) about not mixing ads with content (need I show examples?) and in many pages everything is ads, trying to trick the users in clicking them. Oh and all that crap about doing the right thing, "not evil" or whatever.
Google as a corporation is a just as scummy, if not more, as other corporations and will do anything for a dollar. So I trust them. Not. Sure they are decent people there, just as they are at Oracle or IBM but most will go with the flow and even defend the new policy.
The problem is that the NSA presumably gets access to the information before it is encrypted, so this does not limit what the NSA can get from Google. What it does do though is possibly cloud the traffic to some extent regarding cracking stuff, but then the NSA could probably just disregard the traffic between data centers.
The real victory is that other companies are more likely to follow Google and this may have an impact.
Of course what has happened now is that the jack boot of government has poisoned the well, and I cant believe there is no group of people more upset and angry than these pioneers. I bet if we could talk to any of them off record they would be as annoyed as "we" are, if not more. After all, its their baby being ruined, not ours.
I would add to that the corporate high finance thing as a poison too, but again, that's just money. It does soil the, er, purity of things, but doesn't not threaten freedom and liberty.
In my experience at a certain large SW company in the pacific northwest, I do know that core crypto code, the actual workhorse functionality, is typically walled off from the general developer population. The rationale given is that there are foreign nationals on staff who are not permitted to look at that stuff. That makes sense given the export laws in place.
All the security-like code I saw above that layer was good, to my non-security-trained eyes: Honest use of crypto algorithms, responsible bug fixes and regular and nitpicky reviews of protocols, file formats, APIs, and the code itself. For several shipping products I had confidence that the code we checked in was the actual code that shipped.
For the lower layers (an ideal place to introduce weaknesses):
- The general developer population never sees them
- Even if the sources are utterly honest, the build process might hide the introduction of weaknesses (a variant on "Reflections on Trusting Trust"), or the build machines might ship different bits, or weaknesses might be patched-in later (even after customers get machines) by the OS update infrastructure.
This is the kind of thing I'd HUMINT if I had a mind to.
-- off topic rant --
Such a weird discontinuity in all this ... Google was prosecuted and paid a fine, despite self-disclosing, falling on its own sword and issuing an abject apology, for accidentally sniffing some unencrypted data as they drove past. This was condemned at every level by government.
Now the government is openly sniffing and capturing everything, including our encrypted traffic and deliberately trying to crack the encryption, ... and they don't think it is the slightest bit unreasonable?
How can there be moral outrage about Google's offense and not about what the government is doing that is ten times worse?
I really don't know how much of it is self delusion, how much of it is just perfectly logical mental gymnastics from their perspective, and how much is just the "this is what we have to do, even if it doesn't match what's in the law" perspective on display in the nytimes piece.
And more precisely, it's the NSA, who has the job to break encryption. There was outrage when Carnivore was made public (late 90s?), then that AT&T room the NSA tapped that was leaked in 2006. By now, it's just taken for granted (by technical people anyways) that unencrypted communications are going to be recorded. You don't even need a state-level adversary to achieve this on a limited scale.
Legal requests to Google for user data are not affected by this change. Neither is private data at rest, which is still presumably encrypted. Neither are other extralegal avenues the NSA has to infiltrate Google (employee co-operation or intimidation, exploiting zero days to get into corporate networks, hijacking security protocol construction, etc).
How does this do anything about pervasive NSA spying? The NSA has broken SSL and VPNs by corrupting the CAs and the VPN vendors.
What would really help is for Google to create a zero-knowledge tier of service and to charge users for using it to replace their ad revenue.
Yes, they should be a lot more security conscious. But you might surprised how many trusted commercial vendors.
Or perhaps the Bullrun project had something to do with Bull Mountain, Intel's random number instruction (RDRAND), which was used by the Linux kernel for a while as a primary source of entropy (causing Matt Mackall to resign as maintainer of /dev/random, later reverted by Ted Ts'o). If RDRAND is indeed compromised, then keys generated on a machine that trusted RDRAND would have very low effective entropy for anyone knowing the secret. How confident are you that proprietary systems do not trust RDRAND or have other backdoors that could compromise their available entropy? (That could be an interesting reverse-engineering project.)
Whether or not there is any truth to either of these scenarios, I think they can no longer be considered conspiracy theory paranoia, and indeed have entered the realm of downright plausible.
https://www.eff.org/deeplinks/2013/08/one-key-rule-them-all-... https://news.ycombinator.com/item?id=6336505 http://thread.gmane.org/gmane.linux.kernel/1173350/focus=117...
Google clearly suspects the NSA is installing devices on the leased lines they use for inter-datacenter communications.
Properly implemented, this will stop that.
The NSA has broken SSL and VPNs by corrupting the CAs and the VPN vendors.
I suspect Google won't use a commercial VPN implementation. Corrupted CAs can be bypassed by using self-signed certificates, which will be fine for communication within the same company.
PRISM program is for collecting intelligence within and with companies that have joined the program (including Google). Upstream is program is for collecting data directly from fiber. Analysts are free to use both.
That's interesting. I hadn't considered that could be how Prism works, but it would make sense if these companies weren't encrypting those connections previously. Somehow I assumed they were.
The routers that can handle those speeds don't encrypt the link itself, so the most common solution is to do per-connection encryption between hosts with SSL or SSH or similar. Do you run SSL when talking to all of your internal APIs, databases, etc?
What about between nodes in EC2, particularly between availability zones? Those are potentially subject to the same sort of sniffing without Amazon's involvement.
Not to mention that at the very heart of the NSA spying story is the allegation that Google e.a. provides access to said data willingly. And the only denial from both parties has been a mixture of partial admission ("but we're using proper procedure") and carefully crafted lawyer-speak (the infamous "no direct access" boilerplate denials).
This is just internal security enhancements being abused as a PR exercise. Google is trying use the latest revelations about the NSA to deflect attention away from it's own complicity.
Google does not sell data to anybody. They sell advertising slots.
http://www.huffingtonpost.com/bob-bowdon/why-has-google-been...
yeah, the are clever when is about getting your info.
Programmatic algorithms on some Google properties are processing your data to show you the most relevant content (search, G+ posts, mail, news etc) and advertisements. There is a big difference between this "tracking" and the kind of snooping that spy organizations do.
By the way I'll be surprised if all spy organizations and not just NSA aren't trying their best to get more information on certain people from wherever they can.
Between two servers in the same rack? Between two racks in the same datacenter? Between two datacenters in the same physical complex? Between two complexes connected by fiber you installed yourself?
If the security state keeps on keeping on, I expect companies which care about privacy to keep tightening it in. One day not long from now it might be considered ludicrous to transfer data from one server to another server within the same datacenter unencrypted. One day not long after that we may perfect secure multi-party computation, and a server might perform meaningful computation upon an encrypted dataset without any ability to decrypt it.
The goalposts are moving.
(Yes, it is a tough sell to get folks to run SSL inside.)
Their constant tweaking of the textbox led FireGPG's developers to throw in the towel.
I understand that Google wants to read your emails to power their ads. I doubt the fraction of power-users that would enable FireGPG would put a fraction of a dent in their systems.
AFAICT, Google has been completely transparent about giving users control about how their data is shared. It's been ahead of the pack in protecting its users rights even going to courts to protect users.
Disclaimer:I am an Engineer@Google.
Before these revelations, the tech community in general didn't expect that we needed to encrypt all traffic flowing on our home/office LANs. Like the rest of the world, these spying revelations have taught us that we need to be much more paranoid than we were earlier and are now encrypting data on our own networks.
As a user of a lot of web services that are deployed on the cloud, I'd actually beseech my fellow tech community to do this too. All and any user data passed between any two servers (even on a backend, internal, local network) needs to encrypted.
But I have to say that I am still quite surprised that there is no encryption between data centres. Working from time to time for industrial customers, on business critical software, most of the time it is required to encrypt data between servers, even when the hardware is in the same building, because they are afraid of leaks/attacks from inside.
I think Google has to do some explanation to the public about their security. Though I do not know if it is not too late for some google users.
As everybody knows: It has been revealed that Google is one of the NSA partner companies (which should have been obvious to begin with, given the fact that Google is probably the biggest data hoover ever built).
This fact terminates even the last tiny little bit of "trust" we could have had in Google.
And that's really all there is to say.
But at least on my part, this doesn't begin to "impress me". So far they're only talking about encrypting data between servers and they've also recently talked about encrypting Drive storage data (why wasn't it encrypted in the first place?!)
They need to implement OTR or some form of end to end encryption with PFS for Hangouts, and it would be nice if they at least gave the option to have encrypted calls and voice calls with ZRTP in Hangouts. The button should be right there and obvious for everyone who wants to use it. But I'm saying it's optional only because I'm not sure how it could impact what they're trying to do with Hangouts, and if ZRTP works with multiple people at once. But if they can do that, then it should be by default for everyone.
I'm also not sure exactly what kind of forward secrecy they are using for Google search - is it really a new key being generated per session - or is it like a few weeks? Because I think I read something about "a few weeks".
I think all SSL/TLS encryption is almost useless without PFS so everyone should use it, when we're talking about the government. A single order from them and they could get your key for everything. That's just completely unacceptable! So every service should be using PFS.
If I were them I'd also seriously evaluate whether RSA 2048 bits is enough, and if there's any doubt that it is, then they should move to more bits, or if the whole RSA algorithm is in danger, then they should be looking for alternatives quickly.
When Google and others start doing that, then I will begin to have some trust in them again. All of these press releases so far, and the lawsuit to fight to only disclose (not stop) the mass requests aren't fooling me, and I hope they aren't fooling many others either.
Until then I'll be on the lookout for any new great service that promises that type of security, and I'll switch to them as soon as they're available, and recommend others to do it, too, both offline and online.
I hope Google and Microsoft and others aren't thinking that because I haven't "ragequit" their services yet, it means the whole NSA thing doesn't bother me. It just means I'm anxiously waiting for the alternatives to appear - which will appear. There is a crypto war (again), and I do believe the security community will win again, so it's only a matter of time.
Includes in the output: Server public key is 2048 bit ... Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES128-GCM-SHA256 (ie: not RC4, as long as your client supports non RC4 ciphers, uses ECDHE for PFS) and: TLS session ticket lifetime hint: 100800 (seconds) (session keys are discarded by the client every 1d4h, so presumably the server rotates them every 24 hours or so (4hrs to allow for clock skew, I assume, or to allow for the fact that people might be slightly late on something they check every 24 hours (eg when the wake up each morning)))
Nobody is going to make the change from 1024 bit keys to something else without first verifying that the new bit length is "secure enough" for a reasonable enough time (if nothing else, you don't want to have to go through the expense of the process of getting everything upgraded more often than you have to). Although you're right, it would be nice if they published their reasoning.
I don't know how to verify the security of hangouts. Looking at the webrtc standard, it doesn't appear to support encryption. There is also a lot of opposition to standardising encryption for webRTC because of "DRM" concerns. So I guess it's probably not encrypted, but don't quote me on that.
Disclaimer: I'm a Google employee.
If so, what you are saying is equivalent to Google being more secure than the NSA.
Makes me wonder. Is RC4 strong enough? Is it their professional conclusion? Or something else?
Is Google thinking they are smarter than the NSA at cryptography?
In this case the NSA didn't even do anything theoretically impossible. They did a workaround. They added backdoors, which violates the conditions of the theory. It's like saying I got through your unbreakable door by coming in through the window.