Live data from Hacker News

Yahoo scanned customer emails for US intelligence

news.trust.org

111–120 of 417 posts

Re: Yahoo scanned customer emails for US intelligence

#111
post #100
post #58

Earlier quoted context omitted.

Knowing Stamos' background, it's possible that she was specifically required not to tell him.

How do you slip something like this past a corporate security team? Stamos and @bcrypt never struck me as individuals that were "asleep at the wheel". Surely there was evidence somewhere? If Stamos wasn't briefed as to the situation and a security engineer found the rootkit on their own how could they be bound by the terms of an NSL / gag order?

In a large pipelined, distributed architecture, there's probably dozens of consumers of the databases that all look rather similar: they do some queries and pack up some reports for internal consumption. Marketing, ab testing, user experience, etc. Yet another consumer sharing 99% of the same code might not stand out.

Re: Yahoo scanned customer emails for US intelligence

#113
While it is damning that Mayer didn't go to Stamos about this and went straight to the email team, it's hard to say whether she felt it was necessary to tell him, or was even allowed to, since we don't see the court orders and what they entail. It's really easy to be against this and play armchair preacher but this is something she probably had no choice in, in many ways.

Also, I'm wondering if this story is bigger because people love to hate on Mayer. I am certain this kind of thing happened/happens at Facebook, Google, Twitter, WhatsApp, etc., so it's confusing why this is so newsworthy. It's not really newsworthy that data from an email provider is sent to NSA under secret court orders and NSA can search the full text of it. Is the newsworthy part that she asked the team to do it without consulting the security team? My question would be, why wouldn't a manager from the email team consult the security team if they had the power to?

Re: Yahoo scanned customer emails for US intelligence

#114
post #113

While it is damning that Mayer didn't go to Stamos about this and went straight to the email team, it's hard to say whether she felt it was necessary to tell him, or was even allowed to, since we don't see the court orders and what they entail. It's really easy to be against this and play armchair preacher but this is something she probably had no choice in, in many ways. Also, I'm wondering if this story is bigger b…

The newsworthy thing was that this was a trigger word or similar ongoing filter that the surveillors wanted copies on sight of, and not a specific email account.

Re: Yahoo scanned customer emails for US intelligence

#115
post #4
post #2

It sounds like Yahoo will fit right in at Verizon... It also sounds like another leak designed to damage Marissa Mayer: > According to the two former employees, Yahoo Chief Executive Marissa Mayer's decision to obey the directive roiled some senior executives and led to the June 2015 departure of Chief Information Security Officer Alex Stamos, who now holds the top security job at Facebook Inc.

Sounds like she was a pretty terrible CEO all-around. But as a user, I would never use a service run by Marissa Mayer again. She lost that trust for good.

> I would never use a service run by Marissa Mayer again.

Surprisingly, stacks of $100 bills make great mattresses. She won't lose a night of sleep.

Re: Yahoo scanned customer emails for US intelligence

#116
post #100
post #58

Earlier quoted context omitted.

Knowing Stamos' background, it's possible that she was specifically required not to tell him.

How do you slip something like this past a corporate security team? Stamos and @bcrypt never struck me as individuals that were "asleep at the wheel". Surely there was evidence somewhere? If Stamos wasn't briefed as to the situation and a security engineer found the rootkit on their own how could they be bound by the terms of an NSL / gag order?

This seems like the more interesting question.

Whether Mayer went around him willingly or by legal requirement is basically unanswerable, except to note that the email team chose to do the same. There's not much to say when we can't tell collusion from compulsion.

The question of accidental discovery, by contrast, is a fascinating one. A gag order couldn't possibly compel someone who made the discovery on their own (for the simple reason that they wouldn't know about it to be compelled). So circumventing the security team, instead of simply including them in the NSL, raises an interesting discussion about the nature of the NSL and why the matter was kept from Stamos' team.

Re: Yahoo scanned customer emails for US intelligence

#117
Anyone remembers this?

> Barack Obama: NSA is not rifling through ordinary people's emails. US president is confident intelligence services have 'struck appropriate balance', he tells journalists in Berlin

edit: link fixed https://www.theguardian.com/world/2013/jun/19/barack-obama-n...

Re: Yahoo scanned customer emails for US intelligence

#118
post #78

Earlier quoted context omitted.

Why would you assume they are? Do you have any proof to backup your theory? And try to provide actual proof.

> Why would you assume they are? Because the odds of Yahoo being exceptionally bad and anyone else being exceptionally good about this are extremely low. The intelligence agency doing this wants 100% coverage - it would be absurd not to. Everyone has been told to do this.

Just like I thought - you have no proof. Come back when you have actual proof to substantiate your bullshit.

Re: Yahoo scanned customer emails for US intelligence

#119
post #113

While it is damning that Mayer didn't go to Stamos about this and went straight to the email team, it's hard to say whether she felt it was necessary to tell him, or was even allowed to, since we don't see the court orders and what they entail. It's really easy to be against this and play armchair preacher but this is something she probably had no choice in, in many ways. Also, I'm wondering if this story is bigger b…

> It's not really newsworthy that data from an email provider is sent to NSA under secret court orders and NSA can search the full text of it.

It absolutely is newsworthy. We may have suspected it beforehand, we may suspect it happens at other providers, but we have specific proof about Yahoo now. This is new and important and we should be making a fuss. If we play the jaded cynic we are joining the enemies of democracy.

Post reply on HN