Hacker News new | ask | show | jobs
by dragonwriter 3667 days ago
> It's never been clear to me whether this is superstition or if there's truth to it. Google is fully HTTPS-- how could your searches be monitored unless google was handing them over to the government?

They could be monitored if the government had surreptitiously gained access to Google servers or internal data transfers by compromising infrastructure such as Google's datacenter-to-datacenter links.

I use that example because I recall a leak (IIRC, either as part of or contemporaneous to early rounds of the Snowden leaks) that the NSA had done exactly that with unencrypted inter-data-center links of Google and other entities with multiple datacenters, and reports shortly after that that Google and several others had taken action to secure and encrypt those links afterwards.

1 comments

The name of that program was MUSCULAR:

https://en.wikipedia.org/wiki/MUSCULAR_%28surveillance_progr...

That was the famous slide that showed where Google took off SSL with a little smiley face--which reportedly caused Google engineers to "explode with profanity."

The NSA actually did not do the actual hacking. The British GCHQ did, with technical assistance from the NSA. Thus the NSA could pretend that since the GCHQ collected all the information, it was foreign-sourced and therefore not subject to FISA court jurisdiction.

That should make anyone explode with profanity