That's generous.
That's generous.
Client-side crypto, along a PGP model, would be a welcome admission that Google can't secure everyone's email within their network. It would be a step away from the idea that we simply have to trust utility-scale cloud providers with our data. I see that as putting right a mistake.
EDIT: To de-escalate the argument, I should say that we're probably perceiving 'Google' differently. Their security people are excellent people, and Google has undertaken many excellent security initiatives. Many people at Google are on the side of the angels. As you probably know these people and their work much better than I do, I can imagine that your picture of Google's activities is different to mine. But from a consumer's perspective, Google is much more ambiguous. As a matter of corporate strategy they have pooled vast amounts of customer data via the integration of their services, and they have created a security risk by doing so. When faced with a choice between doing something that might make users safer but might harm their ability to gather data on them, I don't believe Google as a company has often chosen the former.
End-to-end encryption is a pretty reasonable threshold. Skype proved it could be convenient enough for grandma (and yes I'm aware that user-controlled keys for store and forward is more difficult).
So, yeah. Below that threshold the best is just least bad. I don't see why you are so touchy about that. Many people here foresaw that the government would be so intransigent that, unless services implemented open and verifiable tools for enabling end-to-end encryption, anything short of that would be ineffective in restoring trust in the services we use.
Err .. are you are aware they give out keys to certain governments and send different code to certain clients (eg. within China)? In privacy terms they are basically the same as Google now with its centralized model and SSL, just using some obfuscated vaguaries of P2P slash centralized communications paths (which they refuse to document openly) instead of centralized store and forward.
All of their mitigation efforts are only lipstick on the fundamental pig here. Yes, they're not the only ones. Yes, ease of use. But that doesn't change the model.
Have they not also gone along with the NSA in what appear to be violations of the 4th amendment?
I'm mostly ignorant of this stuff, but reading the quote below from the Guardian makes them look complicit. I think it's fine to be complicit when you're powerless, but Google is not powerless. What bad thing would have happened to Larry Page if he had said "Uh, we're not handing over the data." Would he actually have been arrested?
(Just to be clear, you've probably thought about this for 400 hours more than I have, so if I'm totally wrong, sorry.)
From the Guardian [1]:
"The senior lawyer for the National Security Agency stated on Wednesday that US technology companies were fully aware of the surveillance agency’s widespread collection of data.
Rajesh De, the NSA general counsel, said all communications content and associated metadata harvested by the NSA under a 2008 surveillance law occurred with the knowledge of the companies – both for the internet collection program known as Prism and for the so-called “upstream” collection of communications moving across the internet.
Asked during a Wednesday hearing of the US government’s institutional privacy watchdog if collection under the law, known as Section 702 or the Fisa Amendments Act, occurred with the “full knowledge and assistance of any company from which information is obtained,” De replied: “Yes.”"
[1]: http://www.theguardian.com/world/2014/mar/19/us-tech-giants-...
It would be generous.