Hacker News new | ask | show | jobs
by angulardementia 2517 days ago
When was this?
1 comments

Snowden leaks confirmed that gmail was compromised under PRISM https://en.wikipedia.org/wiki/PRISM_(surveillance_program)

They now claim its secure again because they are encrypting internal traffic. It's such a high priority and centralized target with so much valuable intelligence that any such claims have to be taken with a grain of salt.

PRISM was the one with FISA warrants, where the government lawfully acquired data from Google via formal processes.

MUSCULAR was the the one where the NSA tapped Google's inter-datacenter fiber lines in order to spy on their internal traffic.

https://www.washingtonpost.com/world/national-security/nsa-i...

naturally its hard to keep track of all their cute code names, at the end of the day all the data ends up queryable by analysts with nothing resembling a warrant process
PRISM wasnt a vulnerability, Google (et al) was basically forced to build a system to automatically handle FISA warrants data requests. For example, a single warrant signed in a secret court would request all data for a person of interest plus one or more hops of every person they communicated with which got funnelled through the PRISM system to multiple tech companies in the US simultaneously which then got fed back into XKeyScore for agents to go through the data and do graph analysis.

Which is still really bad but not the same as these software vulnerabilities.

Not only is it encrypted -- in transit and at rest -- Google uses its own silicon and has its own fiber.