Live data from Hacker News

Yahoo scanned customer emails for US intelligence

news.trust.org

101–110 of 417 posts

Re: Yahoo scanned customer emails for US intelligence

#101
post #56

Earlier quoted context omitted.

Google is definitely in cahoots with the government and probably way deeper than Yahoo. Why would you even assume otherwise, given how much ties to the government they expose to the public these days?

As a European I have to I assume all major US companies in this area are either infiltrated or willingly participating in pervasive surveillance. It's still interesting to know which companies have been actually exposed for this kind abuse of their customers' trust.

[deleted]

Re: Yahoo scanned customer emails for US intelligence

#102
post #47

Earlier quoted context omitted.

Nacchio is no hero. He ran a $50MM pump-and-dump scam that personally netted him millions of dollars in profits at the expense of common shareholders, and he was indicted in a wave of similar prosecutions in the wake of the Enron fiasco. His offenses are there in black and white: with full knowledge that his company faced materially adverse changes unknown to his investors, he not only promoted the company but privat…

This misses the point of the Nacchio story. There is nothing to suggest that Qwest's refusal to cave in to NSA demands was motivated by Nacchio's desire for personal enrichment instead of a principled stance. At worst, Qwest was motivated by the risk of fines of up to $130,000 per violation per day for breaching Section 222 of the Communications Act, according to Qwest legal [1]. We would do well to stop focusing on…

I don't understand your point. I was responding to this:

Qwest CEO Joseph Nacchio who resisted NSA spying is out of prison

Nacchio's imprisonment has nothing to do with NSA spying; it has to do with his efforts to bilk Qwest shareholders out of their money. Those efforts are well-documented.

Re: Yahoo scanned customer emails for US intelligence

#103
post #100
post #58

Earlier quoted context omitted.

Knowing Stamos' background, it's possible that she was specifically required not to tell him.

How do you slip something like this past a corporate security team? Stamos and @bcrypt never struck me as individuals that were "asleep at the wheel". Surely there was evidence somewhere? If Stamos wasn't briefed as to the situation and a security engineer found the rootkit on their own how could they be bound by the terms of an NSL / gag order?

I don't know any more about this than you do; I'm learning about it from the same Reuters story. But according to the story, the decision to implant the backdoor wasn't discovered by Yahoo security; rather, the backdoor itself was discovered, weeks after it was deployed.

Re: Yahoo scanned customer emails for US intelligence

#104
post #84

I think the attitude here that most tech companies are rolling over and just complying without a single ethical consideration is misplaced. The government has been doing an excellent job of basically extorting these companies into compliance. They threaten the full weight of the US government's wraith and then tie every order up with classifications and gag orders. You aren't legally allowed to talk to other companie…

I wonder what the actual personal consequences are for someone going public that there is an NSL requested. I seriously doubt they'd destroy a major public company with lots of employees/voters/users; fines, maybe, and going after execs, but the Government loses most of its power to threaten things once the act is done and everything is public. I think you win in the court of public opinion if it's a broad program li…

[deleted]

Re: Yahoo scanned customer emails for US intelligence

#105

I think the attitude here that most tech companies are rolling over and just complying without a single ethical consideration is misplaced. The government has been doing an excellent job of basically extorting these companies into compliance. They threaten the full weight of the US government's wraith and then tie every order up with classifications and gag orders. You aren't legally allowed to talk to other companie…

>You can't take your case to the public without being held in contempt.

I don't know about that, Yahoo has a pretty big platform they could use against the government.

Not that I'd really expect anyone to pick up that fight, but Yahoo is far from powerless here.

Re: Yahoo scanned customer emails for US intelligence

#106
post #34

Earlier quoted context omitted.

This should forever taint Marissa Meyer's reputation. Failure to save Yahoo is understandable. Disregard for user privacy and safety at this scale is unforgivable.

Did they really have a choice? It's pretty much a given now that 3-letter agencies get firehose access to any data they want.

If they did, they wouldn't be issuing these court orders.

Re: Yahoo scanned customer emails for US intelligence

#107

I think the attitude here that most tech companies are rolling over and just complying without a single ethical consideration is misplaced. The government has been doing an excellent job of basically extorting these companies into compliance. They threaten the full weight of the US government's wraith and then tie every order up with classifications and gag orders. You aren't legally allowed to talk to other companie…

Yes. It's worth noting that the former CEO of now-defunct telco Qwest claims that he spent 4 years in prison because he refused to comply with illegal NSA demands. [0]

[0] https://www.popularresistance.org/former-qwest-ceo-says-refu...

Re: Yahoo scanned customer emails for US intelligence

#108
post #15

Lets take it a different way: You're knowingly sending your data to a 3rd party. You're not encrypting. It's not through the USPS (special protections). It seems bloody evident that, of course, your email provider can read your emails! Unless you're encrypting with GPG, then they can (and they can still read the signing keys). Yahoo, Google, and friends all scan, dedup, and all sorts of tricks to determine marketing…

I wholeheartedly agree with you, pragmatically. But you also have to take into account why there are special protections on the USPS.

Privacy is a quality people generally expect to have. The USPS protections were created after the long social feedback cycle it took for people to realize what they were missing. We're going through another one of those cycles now, where people are finally realizing how surveilled-by-design modern technology is.

I'm unsure what will be quicker - groupwise societal understanding leading to legal privacy protection, or individual adoption of specific better technology. Given that social protections only work for those in "average" society, I personally hope it's the latter. But the two viewpoints are not conflicting, and are actually complementary - privacy preserving tools educate society as to what is possible, and a person has to value privacy before they can seek out tools to preserve it,

Re: Yahoo scanned customer emails for US intelligence

#109
post #100
post #58

Earlier quoted context omitted.

Knowing Stamos' background, it's possible that she was specifically required not to tell him.

How do you slip something like this past a corporate security team? Stamos and @bcrypt never struck me as individuals that were "asleep at the wheel". Surely there was evidence somewhere? If Stamos wasn't briefed as to the situation and a security engineer found the rootkit on their own how could they be bound by the terms of an NSL / gag order?

[deleted]
Post reply on HN