(Until we know more about their relationship with the NSA, I also don't condemn them for the PRISM allegations.)
(Until we know more about their relationship with the NSA, I also don't condemn them for the PRISM allegations.)
It doesn't really matter whether the NSA or GCHQ are tapping Google's datacenters, paying off low-level employees, operating under a legal court order, or benefiting from the enthusiastic help of Google executives. The end result is the same: You cannot trust cloud services.
It's "Can you trust them more than the alternatives?"
Yes, you can almost certainly keep your private data more secure in a system you build and monitor yourself(1). Until an NSA or GCHQ-level entity takes interest in you, and uses a 0-day exploit on your system or just physically walks in with a warrant and steals your physical media. How is that functionally different from "If the NSA / GCHQ takes interest in you, they can have the cloud service provider hand your data over?" And that's before you add the overhead of maintaining, securing, and physically protecting your own systems.
(1) Note that even this step is a huge hurdle for most people; "You cannot trust cloud services" basically tells those people "Don't use the Internet."
grab * -ss 834-29-1293
or whatever they do.http://www.socialsecurity.gov/employer/ssns/HGJune2411_final...
Even NSA do not like to invade peoples homes. Its a health risk for agents, its costly, it competes with other agencies, and its bad for PR. The legal steps required are also much smaller when asking a cloud service to hands over information.
It is certain that telecom carriers participated willingly in the massive collection of telephone network CDRs from way back when these were on mag tape.
So far, every time someone has asked "What if the government is using X for surveillance?" the answer has eventually been yes. 100% of the time. Nothing is out of bounds. And that includes making partners victims if it is part of the mission to collect everything. Belgium, for example, is both a partner, somewhere in the hierarchy of partners outside of the Five Eyes, and a victim of GCHQ hacking. Being a partner doesn't spare you and being a victim isn't indicative you're not a partner.
For all we know, PRISM was more-or-less a euphemism for "we had a shallow collaboration that we used to pivot into a larger compromise of their networks".
Conversely, I'm going to have to agree with 'tptacek and his (probably not popular) opinion on Google and their influence on privacy and security at large.
https://news.ycombinator.com/item?id=8949256
So I stand by my decision to not condemn them until we learn more about the nature of their collaboration with the NSA's plot to deteriorate human rights the world over. Not because I love Google and think they can do no evil, but because I believe in charitable debate and skeptical inquiry.
I believe in the odds. And the odds are that any technology that has a high potential to significantly add to surveillance capabilities has been exploited for that purpose either by hacking it or convincing (strong-arming if needed) the technology provider to cooperate.
I don't deny that Google does a lot of great things in general, and in security research specifically. That would be denying the plain facts. But I also do not think that has any impact at all on the relationships the government builds with (or forces upon) large corporations regarding national security.
When the chips are down, the NSA and other TLAs are going to get what they want. Now that tptacek is part of a larger transnational security company, he may find that out firsthand.
It seems much more likely that NSA would lean on your consulting practice: you build telephony and communications software. Obviously, I don't think NSA leans on companies like yours either.
I'll let you know when I scale up to where I get a glimpse into the abyss.
I'd love to hear what you think the NSA might have persuaded us to do?
As I rock back and forth in my chair, silently repeat the serenity prayer, and try to remain charitable; what sort of work do you think Matasano (or NCC, Accuvant, or VerizonBusiness, my former employer) does?
Where did you read that? They're still alive and kicking.
'tptacek left it to start a new company. As far as I can tell, Matasano is quite successful and many of its employees are highly regarded hackers and engineers.
Some of what they do:
* cryptopals.com
* microcorruption.com
* cryptoservices.github.io
See also: the 'whoishiring threads every month.EDIT: You should probably respond to his post instead of mine.
And yes I know what Matasano did. Which is why I say you'd be surprised.
If you had to make a guess, you'd probably guess correctly, but we'll just end this thread here (don't guess). FWIW I'm not supporting Zigurd's statements, which sound crazy.