Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. I Built Non-Autoregressive Decision Models with RL a Year Ago(convaiinnovations.com ↗)
    158comments
  2. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    522comments
  3. Human brain is two separate organs, Stanford Medicine-led research finds(stanford.edu ↗)
    194comments
  4. Tin: full-text search for Postgres(planetscale.com ↗)
    52comments
  5. A graphical desktop for the ZX Spectrum(github.com/mindbox77 ↗)
    79comments
  6. “The Secret Life of Circuits” is here(coredump.cx ↗)
    58comments
  7. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    571comments
  8. Supabase (YC S20) Is Hiring for OrioleDB(supabase.link ↗)
    discuss
  9. Black Holes or Black Hole Stars? Astronomers Spar over 'Little Red Dots'(quantamagazine.org ↗)
    20comments
  10. New evidence for hidden chambers beyond Tutankhamun's tomb(nature.com ↗)
    9comments
  11. GPT-6 Astra Solves a WWI German Radio Cipher(prinzai.com ↗)
    140comments
  12. San Francisco Onion Futures Company(onionfutures.com ↗)
    125comments
  13. Almost Never Use AI to Write Anything Substantive(erichgrunewald.substack.com ↗)
    21comments
  14. What Zig felt like, coming from Rust(besok.github.io ↗)
    134comments
  15. If math is more than proof, we need to better celebrate the rest of it(terrytao.wordpress.com ↗)
    202comments
  16. Cloudflare Quick Tunnels(cloudflare.com ↗)
    301comments
  17. People who know the most often sound the least certain(vrash.substack.com ↗)
    discuss
  18. How to Write with an LLM(sockpuppet.org ↗)
    364comments
  19. Adventures in Microcontroller Circuit Debugging(bigmessowires.com ↗)
    1comments
  20. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    28comments
  21. Saving another 100TB of RAM(cloudflare.com ↗)
    93comments
  22. Asking Authors About Their Own Papers(medium.com/tmlrorg ↗)
    46comments
  23. Communication by means of modulated Johnson noise(pnas.org ↗)
    21comments
  24. SDCC – Small Device C Compiler(sourceforge.net ↗)
    25comments
  25. Science Is Open Software(jepedersen.dk ↗)
    51comments
  26. Ray Ozzie and the Optimism of Being Early(reproof.app ↗)
    16comments
  27. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    50comments
  28. OpenJev(openjev.com ↗)
    283comments
  29. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    128comments
  30. How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip(ieee.org ↗)
    123comments

Google backs off on previously announced Allo privacy feature

219 pointsby 10y agotheverge.com
128 comments
10y agoHN ↗

Allo messages will still be encrypted between the device and Google servers, and stored on servers using encryption that leaves the messages accessible to Google’s algorithms.

'using encryption that leaves the messages accessible to Google’s algorithms' So, not meaningfully encrypted at all then?

10y agoHN ↗

Perhaps it's some kind of homeomorphic encryption scheme. Hey it technically leaves the original message encrypted!

10y agoHN ↗

Ifmeaningful homomorphic encryption was an option, then we'd be living in a quite different world.

10y agoHN ↗

Very true. I was just making a tongue-in-cheek conjecture about the justification/rationalization that might be employed.

10y agoHN ↗

This reads like fake smoke and mirrors to trick investors/data providers/participants instead of anything that's real cryptographically.

10y agoHN ↗

As rad as it would be if Google started doing privacy-friendly-ish datamining on user data by homomorphically encrypting it, you and I both know that's not what they're doing. You forgot the `/s`, sadly.

10y agoHN ↗

  So, not meaningfully encrypted at all then?

One could also think of it as your private key being with (1) you, (2) Google.

It's in safe hands ;-)

10y agoHN ↗

Sure, whatever safe hands mean. Safe in an NSA datacenter. Safe in the hands of the Chinese government. Safe with whatever sysadmin has access to it.

Instead of worrying about what "safe hands" mean, just keep it accessible only to me, and each respective conversation with the people I communicate with.

10y agoHN ↗

just keep it accessible only to me

One could also argue that the service is free and the service provider needs a (or yet another) way to monetize it.

If the privacy settings are insecure by default, one shouldn't have high expectations anyways.

10y agoHN ↗

And that's a little scary, you sell a bit of yourself to get access to a service. It's not really the best case scenario I would want.

10y agoHN ↗

One could also argue that the service is free and the service provider needs a (or yet another) way to monetize it.

True, which is why I pay Apple money. No incentive to mine my data... in fact given that privacy is a big marketing angle Apple's incentives are to make it impossible for them to access your data even if subpoenaed or presented with a warrant.

10y agoHN ↗

And that is exactly why open IM protocols and 3rd party clients are so important.

If both you and your correspondents do use 3rd party IM client ([1], [2], etc), then just run OTR2 or OMEMO on top of the protocol, and let google store whatever it pleases - it's not going to be much use for them.

[1] https://pidgin.im/

[2] https://conversations.im/

10y agoHN ↗

Probably stored under the same security infrastructure as Gmail and hangouts messages.

Which, IIRC, means no human is given direct access without the account holder's permission. Algorithms are allowed access, but only if they emit data that is similarly secured, or emits data in aggregate (where, I think, aggregate was defined as 100k+ users per aggregate data point)

It's extremely hard for a Googler or product team to do something directly nefarious, but you do have to trust Google's privacy infrastructure.

10y agoHN ↗

I don't think that is enough. Here we are relying on Google being magnanimous enough to not use the data to increase their profitability. And even beyond that, your opinion is a little naive to hold in a post-snowden world.

10y agoHN ↗

Right - their policies may be perfect today but they may not even exist tomorrow.

10y agoHN ↗

How is it necessarily wrong if Google uses the data to increase their profitability?

10y agoHN ↗

That's fine as far as trusting Google keeping their employees from doing bad things.

But that's not the first concern one would have. Pervasive surveillance programs have penetrated service providers' data centers. Law enforcement can get warrants to access this information too easily, and many service providers turn over information on request, rather than requiring a warrant.

10y agoHN ↗

Well if you trust Google you don't need on-disk encryption in the first place. SSL already solved the transport issue.

10y agoHN ↗

My point that you have no control over the data once you send it to Google. You don't even know if they even encrypt it on their disk/server anyway.

10y agoHN ↗

Extremely hard. I am so sick of hearing this. It all boils down to hand waving and assumptions instead of verification and scrutiny.

10y agoHN ↗

That's really just BS. What's the point of encryption if both the keys and the content is known by Google? They could as well use just SSL and that wouldn't make it safer than this kind of "encryption".

10y agoHN ↗

The benefits of this sort of encryption & privacy infrastructure:

* Protects you (user) from eavesdroppers between you and Google.

* Protects your data from eavesdroppers inside Google's data centers.

* Protects your data at rest (on disk).

* Protects your data from malicious employees.

* Enforces a great deal of scrutiny over who can access your data, and what they are allowed to see.

But, yes, they process and store your data, so there's no 100℅ secure approach to be had here.

---

SSL only handles the first two bullet points.

10y agoHN ↗

The rest of points are not addressed by this sort of encryption because the keys are on disk too. Google employees have access to the keys. It's like leaving the keys into the lock and claiming it's more secure because it has a lock. In practice the data is protected only by ACL. Encryption is just a marketing keyword in this case.

10y agoHN ↗

On disk somewhere (encrypted, with a different key) is not the same as "leaving the keys into the lock" in a large distributed system designed to avoid single points of failure.

There are always weaknesses, but think about why a bank employee can't just decide to take your money. Internal controls are a thing.

10y agoHN ↗

> Internal controls are a thing.

That's what ACL is...The encryption doesn't improve the security of the data if the keys are not stored securely. Simply put the data security is as good as the ACL of the keys is. For your peace of mind you may want to know the processes(i.e. audits, ISO standards/certifications) rather than a marketing keyword("encryption", "military grade" etc). Encryption may be part of that framework but I don't think it's relevant enough to be advertised as a stand alone 'product'. You can be sure that your account balance is not encrypted. It's the ACL process that protects you from a rough employee.

We already know that Google has a relative good security process in place. However this is not about security in the first place. It's about privacy. And here encryption brings no privacy gain because Google has the keys so as I previously said it's just marketing BS. Most people are not worried that Google gets hacked. They are worried that Google is selling their data to 3rd parties for profit and to governments for political reasons.

10y agoHN ↗

SSL only handles the first two bullet points.

Only the first point. If Google works like every other data center in the world, then SSL stops the moment your data hits their first load balancer.

10y agoHN ↗

Most datancenters are lost once the internal network is hacked so I think that's a different issue. Encryption wouldn't help either because the attacker could get the keys too.

10y agoHN ↗

Encrypted links between processes inside a data center is still a good thing: It protects against malicious actors sniffing traffic (without compromising the machines in the data center)

10y agoHN ↗

So again... how is this better than end to end SSL?

10y agoHN ↗

Google does not work like every other data center in the world. All internal services communicate over SSL (or similarly encrypted links)

10y agoHN ↗

Though only because they discovered their internal unencrypted links were being systematically compromised on a truly massive scale for years.

10y agoHN ↗

I think the load-balancers do not communicate over SSL. At least not the ones in front of Appengine applications. Perhaps only inter-services communication is encrypted(i.e. app service with database service).

10y agoHN ↗

extremely hard for a Googler or product team to do something directly nefarious

Unless the user is the only party that can access the keys (i.e. they are only stored locally on the user's device), then I'm sure Google will it very easy to access personal information when a government demands access.

Or did we forget that Google is part[1] of PRISM?

[1] https://en.wikipedia.org/wiki/File:Prism_slide_5.jpg

10y agoHN ↗

I actually trust Google. And I believe they do their best to make it work this way. What I don't trust is the government. :(

10y agoHN ↗

but you do have to trust Google's privacy infrastructure.

The NSA have already backdoored it.

10y agoHN ↗

Which, IIRC, means no human is given direct access without the account holder's permission.

Or compulsion by any government to which Google is responsible (e.g. Russia, if I Googled correctly). Or a suitably clever Googler (as you note, it may be difficult, but 'difficult' ≠ 'cryptographically secure').

As when Facebook didn't think HTTPS made sense until someone sniffed Zuckerberg's password in a coffee shop, I don't think Google (or any other cloud firm) will take security seriously (as opposed to paying lip service to it for marketing purposes) until someone in the C-suite is materially embarrassed by its lack.

10y agoHN ↗

"Russia, if I Googled correctly." You clearly trust Google to some extent, since you search with it.

I don't think you can accuse Google of not taking security seriously. They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make, and a legitimate thing to criticize them for. Apple makes a different choice, and it's important that we have a debate around which is the right security design.

But making a claim that Google is not serious about security does a disservice to the really good people there who move mountains to secure the service.

10y agoHN ↗

I don't think you can accuse Google of not taking security seriously.

I don't think they take my security, and the security of my data, seriously. They seem to care very much about their security.

They are making a security tradeoff that allows governments and insiders access to private data. This is a legitimate tradeoff to make

No, at this point I don't believe that it is legitimate, any more than it's legitimate to sell an oven which will explode if the temperature dial is set above 600° ('just don't set it that high!').

Yes, there are people at Google who work very hard to secure Google's data; there are people at Google (e.g. Adam Langley) who care a lot about users' data. There may even be people at Google who are working very hard to change its course on user privacy.

But Google, the company, does not take the security of user data against privacy threats seriously: if it did, it would use a better architecture (note that Apple doesn't take user-data security seriously, either, since they can MITM any time they want; nor does Mozilla, nor does Microsoft: no organization's hands are clean, so far as I can tell).

10y agoHN ↗

Google's business is based on destroying what you and I consider to be privacy, so I don't see how you could expect them to change their minds about that.

Google and similar companies have a coherent worldview in which they collect user data, protect it from outsiders and inside threats, and do benign and wonderful things for users in return. Within that worldview, they do an excellent and commendable job. Calling their beliefs on data collection a security issue muddies the debate.

I'm curious about your comments on Apple. If I back up my phone to iCloud, how can Apple "MITM any time they want"?

10y agoHN ↗

I'm curious about your comments on Apple. If I back up my phone to iCloud, how can Apple "MITM any time they want"?

I was referring to iMessage: my understanding is that it Apple is the CA for all iMessage keys, and thus they can issue a certificate to anyone, if they wish to or are compelled to.

10y agoHN ↗

Theoretically, just like they could prepare a broken version of iOS that disables security and push it to targeted users. In reality, such a software/infrastructure does not exist today, and we've been shown what happens when Apple is asked to write it.

10y agoHN ↗

Exactly how does almost singlehandedly transitioning the global Internet to forward-secure curve-based TLS help their security and not yours? All I can see in that work is cost for them.

10y agoHN ↗

That's easy, TLS is great for Google as ISPs and wifi providers can't replace ads with their own in transit.

10y agoHN ↗

Additionally: The google of tomorrow != the google of today. Even if you assume that google currently has the best security/privacy setup in place, they could suddenly turn around tomorrow and hand that to whoever they wanted.

10y agoHN ↗

A "suitably clever Googler", an insider threat, is something that Google actively defends against, at multiple levels. The general assumption is that you can't blindly trust internal users, devices, etc. See the BeyondCorp paper for an example. The internal security infrastructure (monitoring, logging, auditing, analysis) probably consumes more CPU cycles than what's needed to run a large number of entire business out there, especially after the China incident -- remember who alerted the 30+ companies that got infiltrated.

The security whitepaper gives only a hint of what's done, such as checks on former employees' accounts and so on:

https://static.googleusercontent.com/media/1.9.22.221/en//en...

10y agoHN ↗

It doesn't matter how well its designed. Once they get an NSL, they would need to make compromises, unless the messages are not in a readable form.

All that Google has accomplished, is convinced me to steer clear of Allo.

10y agoHN ↗

This is the first time I'm reading about that sort of restrictions at Google. What are your sources? Or did/do you work there?

Still, I wouldn't trust that. I can think of enough cases in which algorithms fed with that information would do things not in my interests. (You could easily imagine some internal scoring or profiling a lgorithms taking advantage of the data for example)

Telling "it's only algorithms" doesn't make it secure it I don't know what the algorithms do. (Which of course I can't as it is the core of their busyness)

10y agoHN ↗

In order to receive government protection and favors, they have to play their game. Its not like their advertisement profiling algorithms isn't useful for intelligence gathering and profiling.

10y agoHN ↗

I've seen this sentiment in a couple of places now -- and the news media and non-technical folks seem to refer to "encryption" very loosely to mean "protected in the way I want it to be protected at the times I want it to be protected".

Can we please use technical terms with precision?

You can have data encrypted at rest and in transit that is still accessible to the provider and the fact that the provider can decrypt it for processing doesn't make it any less "encrypted". There is not a total ordering of encryption or security schemes.

If you would like to say that the data isn't end-to-end encrypted such that it is opaque to the service provider -- say that. Don't say it isn't meaningfully encrypted.

10y agoHN ↗

They could be using some form of homomorphic encryption here, in which case it would still be meaningfully encrypted.

10y agoHN ↗

Homomorphic encryption isn't currently practical, even for small-ish problems. It needs to use constant space, and every operation needs to flip on average half of the bits. There aren't obvious ways around these restrictions, though off hand I can only come up with a quick hand-wavy "proof" that this must always be so if less than one bit of the unencrypted state is to be lost with every state update.

So, in order to perform machine learning on terabytes of data, you need to flip terabits for every update of the homomorphic state machine.

That being said, I could imagine someone coming up with a homomorphic encryption algorithm that starts out with a few megabits of excess entropy and leaks entropy at a bounded rate while remaining more efficient at calculation, and where the initial state is set up cleverly such that after a bounded number of steps, the state machine starts making nonsense computations and stops leaking entropy. Though, this just feels very brittle to intentionally leak entropy, and I have no idea how anything remotely like this could be actually constructed.

10y agoHN ↗

That is only true for fully homomorphic encryption. There are simpler cryptosystems (e.g. ElGamal for a trivial example) that have more constrained homomorphisms that theoretically could be used here.

10y agoHN ↗

The OP was talking about encrypting the chat data and performing machine learning on encrypted data without decrypting it. I really wouldn't know where to begin to construct such a thing using a simpler cryptosystem, such as ElGamal. Do you have any hints as to where to begin?

10y agoHN ↗

There is actually some research work on this front because it is highly valuable to analyze some data but not have access to it.

However, it's better just to encrypt everything and not be tempted by the advertising surveillance dollars.

10y agoHN ↗

Was anybody actually planning to use Allo for encrypted communications? I was under the impression it was written off at its announcement.

10y agoHN ↗

Yep, I'm with you. At least I know I've written it off.

10y agoHN ↗

There is always a way to inject malicious code in a codebase you control. The Allo apps are closed-source and their code is solely controlled by Google. Doesn't matter which protocols they claim to be using, when they could simply push an update which silently uploads your private keys to their server (or breaks the claim in any of the many different ways).

This is the same reason even WhatsApp's use of 'end-to-end encryption' cannot be considered secure from WhatsApp.

10y agoHN ↗

Not sure TBH, I just remember a lot of negative discussion around it and the privacy picture when it was announced. Perhaps bad on me for not doing all the due diligence when it came out but I'm generally biased against the assumption of security or privacy in online chat anyway so didn't bother going further with it.

10y agoHN ↗

These privacy articles make a big deal about law enforcement being able to access messages. Surely a much bigger concern is Google being able to access the content?

10y agoHN ↗

A fair percentage of people (myself included) are far more concerned about protecting our data from marketers, advertisers, and data brokers, than we are about going 100% 'tinfoil hat' mode and worrying whether the NSA is monitoring my messages for thought crimes. These are two very distinct issues and not everyone is concerned about both equally.

10y agoHN ↗

And how many "Kings" do you know personally?/s What me (and presumably, OP) trying to say is, that an ordinal person should be much more worried about their private data being collected and used (virtually) unconstrained by the shady companies than three letter agencies. This doesn't imply that mass surveillance isn't wrong and evil, these two things are orthogonal.

10y agoHN ↗

How is that relevant to the fact that many people are more worried about marketers than the NSA? Nobody's questioning that some people are in fact so monitored. "I am more concerned about A than B" is not a claim that B does not exist, nor is it a claim that "I" am unconcerned about B.

10y agoHN ↗

the fact that many people are more worried about marketers than the NSA?

How do you know this is a fact, was a global survey done?

I am more concerned about A than B" is not a claim that B does not exist, nor is it a claim that "I" am unconcerned about B.

Indeed, however the phrase "100% tinfoil hat mode" does imply being unconcerned about B, and that anyone who is is a lunatic.

10y agoHN ↗

You seem to have a problem with adjectives. "Many" is not most. I don't need a "survey" to establish the "many" when I can just read many people expressing their concerns on HN. That's "many" enough for me.

Now, to be clear, by "people" I mean "humans" not "abstract sentients including AIs that don't yet exist", and by "concerns" I mean "things that are at least slightly negative to the thinker" and not "things that keep the thinker up at night wetting the bed and driving them to fits of existential madness", etc. etc.

10y agoHN ↗

Ah, my mistake. I misread it as "many more people..."

10y agoHN ↗

Dr. King was monitored by the NSA for "thought crimes". Is that "100% tinfoil hat mode"?

Probably 'yes' for you, 'no' for him.

Sorry, but a random HN commenter is extremely unlikely to be targeted for the level of surveillance and treachery that Dr King was. If he feared it, he had good reason. If you are some random IT worker building the next smart pillow you cannot expect them to prioritize spying on you, that's all I'm saying. Mass surveillance isn't the same as targeted.

10y agoHN ↗

Fair enough. Though my concern is not for myself, but rather for any potential great leader who could be silently neutralized/blackmailed/extorted by mass surveillance techniques.

Whether the culprits' organizational classification is public or private is of negligible importance.

Mass surveillance isn't the same as targeted.

Mass surveillance is the first step in the discovery process, targeted surveillance is the second step after a target has been flagged by the dragnet.

10y agoHN ↗

Actually, I'd say a random HN commenter is extremely likely to be targeted for surveillance and exploitation compared to general population at least. Not because they personally are important, but because of their jobs. So many administrators, programmers, etc. with access to relevant data.

10y agoHN ↗

Yes, I almost mentioned the Belgacom sysadmins in one of my responses.

How many people here work for Google, Facebook, Apple, etc? What if you could compromise their workstations and get privileged access to the backend of social networks, email systems, etc? We are being actively hunted and there's evidence of that.

10y agoHN ↗

Some years ago FreeBSD had an intrusion via one of the commiter's machine or stolen SSH key, I don't remember which any more, but I do remember that it took months for the package building infrastructure to get fully operational again. I think they never got to the bottom of that (who did it or why). Linux had a very similar incident if I'm not mistaken.

It's such a standard and effective method in human intelligence, that it's extremely naive to think an analogue wouldn't be used extensively in signals intelligence too.

10y agoHN ↗

Actually a random HN commenter is precisely the person to target, they're more likely to have technical skills and access to servers. It isn't just about surveillance it's about increased attack vectors when your information is distributed.

A random IT worker building the next smart pillow has no reason to target you...but the creepy pervy sales manager at the same company might have reason to.

10y agoHN ↗

A fair percentage of people (myself included) are far more concerned about protecting our data from marketers, advertisers, and data brokers, than we are about going 100% 'tinfoil hat' mode and worrying whether the NSA is monitoring my messages for thought crimes.

The main issue here is that people aren't worried about either of those problems :) otherwise Facebook, Google and other advertising companies would only have a handful of users.

These are two very distinct issues and not everyone is concerned about both equally.

Divide and conquer... not. The issue is the same, we should fight together for more privacy, not disregard other people's reasons for requesting more privacy.

In any case, as you were replying to my previous comment, my point was that if the company has access to your data, Law Enforcement has got it too. Also if Law Enforcement has access to your data it means it wasn't also available for the company. Hence why one implies the other. You might be worried about one, but you've got two :)

10y agoHN ↗

Thanks, that's clearer to me now.

When marketers collect my personal info, it's far more likely to be distributed widely so I place a greater emphasis on protecting it from them. I don't like the fact that nation-states are spying on the citizenry, but I don't know what I can do about that. I DO know what to do about the surveillance capitalists.

10y agoHN ↗

we should fight together for more privacy

It needs to be established as a human right.

I'm personally very disappointed to see the how good intentions of the aware subset of the citizenry are consistently channeled towards technical solutions to a problem that is fundamentally political.

At a meta-level, we saw the same (useless) dissipation of energies in the Occupy-x movement. And it should also be pointed out that the subtext of such approaches is de facto deligitimization of legal governance of societies and (speaking of "kings") establishing corporations as the arbitrators of social norms.

Get congress to pass a comprehensive privacy act and "Alphabets" (of the corporate and governmental variety) will have to toe the law of the land.

[edit:spelling]

10y agoHN ↗

It needs to be established as a human right.

It already is. Article 12 of the universal declaration of human rights:

No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.

10y agoHN ↗

One of those things can kill you, or imprison you. The other one can send you mildly annoying ads.

10y agoHN ↗

The other one can send you mildly annoying ads.

That isn't quite accurate. Your information is extremely valuable for identity thieves and for spammers and for running other scams. I guess you've never had your identity stolen or been harassed.

10y agoHN ↗

Yeah, I found tone of these articles distasteful as well. It looks like only criminals are worried about their privacy. I'm pro-privacy, but not so much worried that police gets a warrant and wires my chat as I'm concerned about Google and all kind of 3rd party companies circulating and selling my personal data around for who-knows what purposes and that stays around indefinitely.

10y agoHN ↗

Unlike law enforcement however, Google has a much higher level of trust in the public eye.

10y agoHN ↗

Who needs yet another messaging app? Aren't the 10 I have installed enough already?

10y agoHN ↗

Don't worry, running by Google, it won't stay around long./s

10y agoHN ↗

The best new friend of Facebook Moxie?

His "trust us, we checked FB Messenger code and it's all good" pitch made for a very entertaining read.

10y agoHN ↗

Aware of that issue (asked moxie about it on HN) and other issues too, but it doesn't change that there's zero reason to believe Moxie's intent is malicious and it's a stretch by any means to claim his contributions are anything but positive in sum.

10y agoHN ↗

I'm not sure why Moxie gets so much grief on some of these issues. To his credit, he's released just about everything under a free software license -- with reproducible builds and all.

Ultimately, it's his baby and he can do what he wants with it.

10y agoHN ↗

While speculation, Moxie's projects appear to have gotten (deservedly) a lot of attention, which brings a lot of feedback that's unfounded and potential malicious; for example, the f-droid comment about in my opinion fails to reflect both sides of the issue, and build security is VERY IMPORTANT and often ignored.

I don't know Moxie, but we've exchange messages before and never got the sense that off the cuff he was discounting any feedback. At a very highly level we agree about what he's doing, though I get the sense that anonymity is something we don't exactly agree about, but do understand a little of why he feels the way he does.

10y agoHN ↗

Do you feel f-droid's build security should be trusted, an if so, why?

> ""F-Droid has received criticism for distributing out-of-date versions of official applications and for its approach to application signing."

https://en.m.wikipedia.org/wiki/F-Droid

10y agoHN ↗

F-Droid has received criticism for distributing out-of-date versions of official applications

Thats not a bug, it's a feature

10y agoHN ↗

First thing I thought when saw the release of this app is that it will record everything I do because it's google.

Thanks but no thanks, google. Stay evil.

10y agoHN ↗

Stay evil.

Wow. Google went a full 180 from being a company that promoted itself by saying "Don't be evil" to something evil. Couldn't Google have made its billions still being not evil, without its privacy issues, without its obnoxious desire for tracking everything. Did they turn to this evil for the money or just because they can do it (or if not someone else will).

10y agoHN ↗

Couldn't Google have made its billions still being not evil

No. Google is advertising company and advertisement companies need a lot of user data for targeted ads.

10y agoHN ↗

How does it benefit by keeping data forever though? Of what use is aged data?

10y agoHN ↗

It doesn't. They need a constant stream of new data for their business model to work. Thus, they benefit from continuously collecting data on users.

10y agoHN ↗

So why do they store indefinitely? If they stated a retention period openly they'd get much less criticism over privacy.

10y agoHN ↗

I'd assume for machine learning developments, specifically as training data and back testing. Build a new model with 3x the data you had before or be able to retrospectively see how a model would have performed over 3 years rather than 1.

10y agoHN ↗

Don't forget that they're also entirely complicit to NSA demands for live access to data as well, per the somewhat-recent leaks. That's another level of evil above regular profit motivations.

10y agoHN ↗

Even if they weren't (mainly) an advertising company, even if they charged for all the free things, they'd still need all the data they suck in to provide services they provide.

10y agoHN ↗

That's simply not true. They collect a ton of data which they wouldn't have to collect, if they wouldn't run advertisements or could even just delete this data much earlier.

There's even crap like Android not allowing you to selectively turn off the Internet Permission for apps, for which there is no good reason other than Google needing an internet connection to display their ads.

10y agoHN ↗

It's not true that machine learning and AI needs a lot of data to do what it does with Google's services? I guess you know something their engineers don't, so I'm looking forward to Sylos' Dataless AI & Co. I bet a lot of us would even pay good money for such a thing.

Sigh, I'm not arguing that they don't collect for advertising, I'm not even defending them at all. It's just that the things they do are impossible to do without a huge amount of data, regardless of advertising. Again, if you're so sure that it is “simply not true”, here we are, YC is your oyster. Or any other tech VC fund for that matter.

10y agoHN ↗

Google is a company that uses algorithms to sell ad space to you. How is a company not evil when you are the product?

10y agoHN ↗

This seems to be where the "backing off" claim is coming from:

http://www.theverge.com/2016/5/18/11699122/google-allo-messa...

First, all conversations are encrypted "on the wire," which means that nobody on the internet can read them as you send your message. They are read by Google's servers, but Kay assures me that the data is stored "transiently," which is to say that Google doesn't keep your chat logs around to be subpoenaed. And Fulay adds that Google doesn't assign identity to the chat logs on those servers even then.

I think this is a misunderstanding -- either on the part of the authors or from the Google employees on understanding the question asked by the authors.

Kay probably meant that in Incognito mode, messages are stored transiently. I don't believe that has changed, has it?

Did Google really say that non-Incognito messages would not be stored server-side? What happens if you lose your phone -- do you lose all your Allo chat history? That would be a really shitty user experience.

10y agoHN ↗

That basically happens with WhatsApp if you don't back it up somewhere.

10y agoHN ↗

I lost all my WhatsApp chat history after a phone upgrade went wrong, and it didn't cause me any problems at all. I recognise that my use case is not the same as everyone's, but if I want to save something from WhatsApp, I put it somewhere else.

10y agoHN ↗

Yeah, and I normally don't bother to copy over my SMSes. I can, and I appreciate that, but they're really so ephemeral that it's not worth the bother.

10y agoHN ↗

Was it really expected in the first place that the ordinary messages don't get saved on Google's servers? As someone with a passive interest in Allo but who hasn't been following it closely, I never assumed the "smart AI" messages were anything other than simple hangouts-type messages that get stored on Google's servers. I'd even expect (/hope) them to be someday accessible on the web or transferable to a new phone.

It's the incognito that are end-to-end encrypted and I expect are secure from Google's prying eyes. And I don't think anything has changed there.

This is a non-issue for me, anyway.

10y agoHN ↗

And just yesterday someone on HN didn't understand why the recent Google messaging apps weren't being more widely adopted.

It's clear the public wants some assurances around privacy, or at least transparency where it is lacking. Not to mention, this is the umpteenth product they are planning to deprecate, uh, I meant launch (Grand Central, Voice, Wave, Talk, Hang Outs, etc).

10y agoHN ↗

You either want encryption, security and privacy or you want other things like history. Allo choosing the latter makes it useless for anyone who really cares about security or privacy.

10y agoHN ↗

There's no reason that the history couldn't be encrypted in a way that's only accessible to the client. There are even techniques for encrypted indexing and keyword search.

10y agoHN ↗

Wow, they could generate stylometric profiles and sell that for mega-bucks.

Kind of creepy I say.