Except, we never learned that they added backdoors, sidedoors, or firehose access for the NSA. The most probable and likely thing that happened is that the NSA simply tapped their inter-datacenter fiber just like the NSA tapped Soviet undersea fiber, and that the NSA scooped up any non-encrypted SMTP traffic. The NSA may even be able to tap internal networks without entering the building through TEMPEST like techniques.
There has never once been presented a single shred of evidence that they knowingly cooperated with the NSA in any manner other than the normal court approved processes via warrant or NSL that they've already alluded to and are petitioning the government to give more transparent details of.
On top of that, Google has been adding security for years on the front end that the NSA won't like, for example, using SSL for everything, doing SSL on mail traffic whenever possible, using forward-secrecy with Chrome, adding Channel-ID support to Chrome. All indications are that they are trying their best to secure things as much as possible, but with a state actor with virtually limitless resources and a half century of experience of penetrating tough adversaries, it's not enough.
Rather than breaking out the pitchforks for these companies, people should be breaking out the pitchforks for the NSA. Technical solutions are not going to solve the problem when the government is against you.
There has never once been presented a single shred of evidence that they knowingly cooperated with the NSA in any manner other than the normal court approved processes via warrant or NSL that they've already alluded to and are petitioning the government to give more transparent details of.
As we saw with the first Snowden leak, the Verizon Business court order, those "warrant[s] or NSL[s]" can be incredibly far reaching.
SSL doesn't help if the endpoints are compromised, is the point of Snowden's latest revelations. As is much crypto compromised if your adversary can predict your PRNG.
There has never once been presented a single shred of evidence that they knowingly cooperated with the NSA in any manner other than the normal court approved processes via warrant or NSL that they've already alluded to and are petitioning the government to give more transparent details of.
On top of that, Google has been adding security for years on the front end that the NSA won't like, for example, using SSL for everything, doing SSL on mail traffic whenever possible, using forward-secrecy with Chrome, adding Channel-ID support to Chrome. All indications are that they are trying their best to secure things as much as possible, but with a state actor with virtually limitless resources and a half century of experience of penetrating tough adversaries, it's not enough.
Rather than breaking out the pitchforks for these companies, people should be breaking out the pitchforks for the NSA. Technical solutions are not going to solve the problem when the government is against you.