Hacker News new | past | comments | ask | show | jobs | submit login

Do you have details of China's hack that show Google as being stupid in security, or does being compromised by a nation famous for hacking prove incompetence. Seriously, with the amount of value stored inside Google's computers, it seems like they are doing a pretty good job with their security systems.



Well not properly securing the system the us law enforcement used to legaly get info from google - that should have been locked down properly with hardware cypto gear so that it could only talk one way to approved system in the FBI or better still via an air gap.

Its blindingly obvious to any one with even a basic knowledge of computer security best practice.


Can you be more specific. From your post I am assuming that China hacked into Google by using a direct line the FBI has into Google's servers. Even assuming such a link exists (which I do not), 'hardware crypto gear' is still a far way away from a complete secure system. And it seems like an air gap would also inhibit the intended functionality of the system.

Security is hard, and it is even harder when any device on the internet is intended to be able to work with the system, and it is even harder when you operate one of the most valuable networks in the world.


They spearfished a pc apparently.

And systems used by your TLA's to handle law enforcement access are not available to "any device on the internet"

As I said they should be set up to only talk over a private circuit to one other end point and also have proper hardware crypto gear that is external to the systems.

separating the extraction of data and applying the decoding probably should have been done on separate systems.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: