Also, in other countries, I assume those g-men have access to those cages.
This is a threat to Google's international business. They have a vested financial interest in reducing the hacking against their systems.
“It’s an arms race,” said Eric Grosse, vice president for security engineering at Google, based in Mountain View, Calif. “We see these government agencies as among the most skilled players in this game.”
The risk of things going wrong when you're tapping cables is much less pronounced as far as I can see.
How can that guy be trusted with anything?
http://www.dailymail.co.uk/news/article-2347047/Former-Faceb...
1. Has the technical credentials and interviewing skills to get hired at Google (not easy). 2. Has a security clearance. 3. Wants to be a spy. 4. Can get themselves assigned to the team working on datacenter interconnects. 5. Can set up a tap on the interconnect without getting caught.
That sounds both hard and expensive to me.
Before the Snowden revelations came out, I'd have strongly considered Sally Smith to be a good fit for a position dealing with data center security. Who wouldn't have?! Years of experience at high levels securing data centers? Letters from generals and senior government officials attesting to her qualifications? Sign me up right away!
Post-Snowden, I'd start believing that Sally Smith is far more likely to be Sally Spook, an active NSA employee experienced in data center infiltration and with an impeccable cover story.
The only thing that keeps Sally Spook away from our data centers is Google's hiring processes & internal security, and is that really enough to stop a determined adversary with all the advantages of the NSA? I doubt it.
The NSA can do this. They have the resources and the time to try. The only question is if they want a mole inside Google. Hell, I'd be shocked if large internet companies (Google, Yahoo, etc.) don't have agents from foreign and domestic intelligence agencies working there right now.
Betting on a companies hiring process to catch agents of an advanced persistent attacker is betting against house money in Vegas. You aren't going to win in the long run.
It's the same reason why security through obscurity doesn't work: if you chain together 5 obfuscation layers that each keep out 80% of competent hackers, in total they probably keep out 85% or 90% of competent hackers if you're lucky, but certainly not 99.99%, because everyone who bypasses the first layer has a much higher probability of having the skills to bypass the other layers as well.
As for the internal mole, I'd imagine that any such individual's role would be highly focused. They'd be used to tackle specific target information rather than the wholesale siphoning tapped cables would provide. Aside from the simple logistic issues with the sheer amount of data they're tapping, I can't imagine how anyone could be in a physical position to do so across the entire Google network without tripping at least <i>one</i> internal safeguard?
For bulk collection, the taps enable surveillance without the possibility of detection unless the NSA screws the proverbial pooch. And if there's one thing history can tell us, it's that surveillance agencies will spend obscene amounts of money in pursuit of that undetectability. From the Project Azorian with the Glomar Explorer to the Berlin tunnels in Operation Gold, the Cold War alone proves the point.
Or even your own fiber (Google owns tens of thousands of miles of it). There's nothing to prevent the black-hat guys from digging down to a cable in the middle of nowhere and installing an optical tap. Especially if they did it before commissioning, after which signal levels would start being monitored.
If this haven't already I imagine they will be hiring security forces to patrol and inspect.
Sometimes employers are willing to take that risk.
Do you think Ed Snowden is now more or less employable now?
Now, if they decided they wanted out, well ... good luck with that in the manner you describe. I suspect that it won't be too hard, though. They deal with "Big Data" problems at a scale that few do, so being an NSA engineer likely is bound to be a similarly prestigious resume line as working for Google. Aside from the working for an evil entity part, that is, but some employers will not care as much about that.
This is unfortunate--in a just world everyone doing this would be imprisoned for many years and have all their ill-gotten gains stripped from them--but a real fact. And the typical NSA software developer is certainly highly qualified and very, very smart. Going purely by business concerns, if you have a need for someone with the skill set that'd come from working for the NSA, you can't afford to pass them up just because they worked with the NSA.
You can also be sure that, even if the NSA were disbanded fully and all its employees hated so much that they could not get domestic employment anywhere, many international actors would be extremely excited to pay top dollar for their talent. And by top dollar, we're not talking piddling six figure salaries.
The sad fact of the matter is that we cannot trust individuals that have ever worked with these agencies, nor with the private contractors that supply them. The risk of insider attacks is too high. Equally, we cannot trust companies that employ those individuals.
If silicon valley is to recover the confidence of it's customers, it must go through the painful and heart-rending exercise of dismissing all employees with any connection whatsoever to government espionage. Many innocent people will lose their jobs, and will face the prospect of being excluded from high-tech employment in the private sector, but I cannot see any other way of regaining trust in our fundamental infrastructure.
Wouldn't it be the people that used to be blackhat and have transitioned to gray or white-hat hacking that would be the best people to provide their services for pen-testing/anti-virus writing/etc?
Is the probability of an so-called ex-virus-writer writing in exploits into the system higher than someone else?
Is their knowledge worth the chance?
From our parent: I used to work in the antivirus industry, and, as I recall, anything that even hinted at a history of hacking or virus-writing would lead to instant dismissal and black-listing (from pretty much the entire computer security industry). I imagine that the same prohibition would now apply to former government employees also.
They used the world "hacking", which I took to mean any form of hacking. We'd need the parent to respond to which one was meant, of course; but if it means any sort of hacking, from xbox modding to submitting bug and exploit reports to Google (which, how do you know if there's an exploit without trying to find it?), then hacking would include all of those people, including the people who you define as "ethical hackers".
If you're a known, aggressive and clearly unreformed cyber-saboteur, then it's pretty much a given that you shouldn't be hired to an anti-virus company since you probably are in there to commit insider attacks (I can't know for sure, I'm not in your brain) and it's reasonable to not hire you; however, if you're a tinkerer and inspector of things and dismantler of technology, then you would know how systems work and where issues are and could even be an asset, especially if you're very good at it. Depending on the author, both of those people could be seen as 'hackers'.
A number of notable, convicted hackers have done additional work (whether employment or successful entrepreneurship or both) in the computer industry (in security-related or other subfields) after conviction. Kevin Mitnick, Julian Assange -- long before WikiLeaks -- and YC's cofounder Robert Tappan Morris are among the more notable examples.
Having a spouse, kids, and a nice house in a nice neighbourhood makes any kind of anti-social behaviour that much harder to justify from a purely pragmatic, never mind ethical point of view.
I.e. young men often have nothing much to lose and act accordingly.
Without trust, the antivirus vendor has no business whatsoever. As a result, they are (or jolly well should be) ultra-careful to earn that trust. This includes subjecting their employees to a certain degree of vetting.
In the age of cloud computing, the same relationship dynamics are observed between businesses and the cloud vendors to whom they entrust their data.
See? There it is again: Trust.
Important stuff.
I'm not sure where you got that from. A large percentage of the security industry is made up of people who got their start as blackhats.
Well, actually, per the article, by GCHQ. Who, as well as using the data themselves, also allows the NSA access to it.