Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Apparently, Google didn't encrypt the traffic between > its data centers until news of the NSA undersea > tapping broke out.

I constantly struggle against my colleagues when it comes to internal use of encryption. These are smart people across diverse organizations/markets. I think it comes down to differing cost-benefit analyses---they think that any internal privacy threats either don't exist or already have access, so why pay the price (usually in terms of administrative overhead) to maintain a crypto layer? Compare it to always locking every door inside your house and having to successively lock/unlock doors as you move between rooms---most people (even myself) would think that the inconvenience of such a scheme would drastically outweigh any security benefits. And so it is with the implementation of strong encryption protocols (not just the right algorithms but also the right methods and practices and use cases) at every level of the computing/networking stack. Ultimately, I think this supports your thesis, that if there's a conspiracy when it comes to commsec, it's a confederacy of dunces.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: