Live data from Hacker News

Yahoo scanned customer emails for US intelligence

news.trust.org

121–130 of 417 posts

Re: Yahoo scanned customer emails for US intelligence

#121
post #15

Lets take it a different way: You're knowingly sending your data to a 3rd party. You're not encrypting. It's not through the USPS (special protections). It seems bloody evident that, of course, your email provider can read your emails! Unless you're encrypting with GPG, then they can (and they can still read the signing keys). Yahoo, Google, and friends all scan, dedup, and all sorts of tricks to determine marketing…

I wholeheartedly agree with you, pragmatically. But you also have to take into account why there are special protections on the USPS. Privacy is a quality people generally expect to have. The USPS protections were created after the long social feedback cycle it took for people to realize what they were missing. We're going through another one of those cycles now, where people are finally realizing how surveilled-by-d…

Please, I am absolutely for protections of data privacy even more stringent than what the USPS does with parcels.

I would be for something akin to "Swiss Banking requirements for Data" - where companies are NOT allowed to share data unless given exception in writing/cryptographically. I'm sure we can expound on these ideas collectively.

I'd also be OK with services that DO treat data as a semipermeable membrane. Think of what Google has done with all their free services. They make neural models that they (and others they choose to release) can exploit to great effect. In cases like this, there needs to be a simple chart; think of something like this https://tldrlegal.com/license/apache-license-2.0-(apache-2.0... . I also think of these services as bringing technology to me when I could not afford it... And yes, it has been a wonderful boon for me, and I'm sure as for Google as well.

I also want to be able to request all the data on my account, sent to me in a reasonable format (multiple of: Zip, ftp, file share, mailed DVDs for reasonable price). European Union already has that law, to great effect. I should also be able to legally command a company to remove my content. If copyright is so great, I should be able to revoke their rights to it as well due to copyright.

______________________________

I get privacy. I get how networks work, and how the Internet works. I know how mailservers work, as well as file deduplication. And I see a glaring hole in the technology that allows an action, a-ethical companies that will do anything to get ahead, and a government hell-bent on dismantling privacy and data security all to stop today's big bad monster, terrorism.

I'm also guaranteed on watch lists. I'm a minor Tor developer, and greatly utilizes Tor in many ways. In fact, my network resides in Tor-Space. I've figured out how to get Linux to resolve .onion addresses seamlessly, and have .onion endpoints on all my Linux machines. I also work with IPFS and Zeronet, both technologies that have some very... interesting content as well.

It's my little corner of the Net... And if I help others with my tech, awesome. If enough of us do this, then we can start stemming the tide of data insecurity. But I also remember, parts of these issues are with the Political system, and not of technology. Until these older, technologically ignorant politicians die or retire, and Millenials come in, we're stuck. At least we've grown up with it.

Re: Yahoo scanned customer emails for US intelligence

#122
post #119
post #113

While it is damning that Mayer didn't go to Stamos about this and went straight to the email team, it's hard to say whether she felt it was necessary to tell him, or was even allowed to, since we don't see the court orders and what they entail. It's really easy to be against this and play armchair preacher but this is something she probably had no choice in, in many ways. Also, I'm wondering if this story is bigger b…

> It's not really newsworthy that data from an email provider is sent to NSA under secret court orders and NSA can search the full text of it. It absolutely is newsworthy. We may have suspected it beforehand, we may suspect it happens at other providers, but we have specific proof about Yahoo now. This is new and important and we should be making a fuss. If we play the jaded cynic we are joining the enemies of democr…

No, we had proof back when Snowden released documents about the search engine that NSA has from data siphoned from providers. I'm not being cynical, I'm being realistic in that this isn't newsworthy now because it was extremely newsworthy when it first came to light a few years ago.

I would rather this be newsworthy because it gets people interested in fighting FISC orders again, not against Yahoo and Mayer.

Re: Yahoo scanned customer emails for US intelligence

#124
post #84

I think the attitude here that most tech companies are rolling over and just complying without a single ethical consideration is misplaced. The government has been doing an excellent job of basically extorting these companies into compliance. They threaten the full weight of the US government's wraith and then tie every order up with classifications and gag orders. You aren't legally allowed to talk to other companie…

I wonder what the actual personal consequences are for someone going public that there is an NSL requested. I seriously doubt they'd destroy a major public company with lots of employees/voters/users; fines, maybe, and going after execs, but the Government loses most of its power to threaten things once the act is done and everything is public. I think you win in the court of public opinion if it's a broad program li…

I've been wondering about this myself.

Apple got a mixed response when they pushed back on the FBI, but certainly not a clearly negative one. Lavabit's rather alarming case earned them substantial respect in the tech circles that learned about the matter.

Certainly whistleblowers have faced immense consequences, but they've been government or military employees engaged in major disclosures. To jail a 'captain of industry' for reporting that the government handed her a sheet of paper would be spectacularly bad optics, attacking a respected private citizen over an intuitively absurd legal mandate.

I suppose the details of the account in question would become important. If the public can be persuaded that you blew up an important investigation, you probably lose all support; we've certainly seen the government disclose a surprising amount of formerly-secret material to turn public opinion against whistleblowers. Even there, though, you could test the gag order by disclosing the fact of an NSL without the content.

If they can't show overwhelming importance, though? If it's just a cartel bust or a leaker or something similarly non-terrorist-y? I'm trying to picture the government bringing the hammer down on Cook or Mayer for going up on stage at a conference and unashamedly violating an NSL. It doesn't seem like a good fight to pick.

Re: Yahoo scanned customer emails for US intelligence

#125
Distribute, encrypt, and anonymize. The only way forward doesn't include them.

Congress is up for grabs. You can really change who is in congress this round. If you don't like the guy you have vote in another. Vote for people that want to cut surveillance programs and agencies that request them. We could save or reallocate mountains of money.

Re: Yahoo scanned customer emails for US intelligence

#126
This is unfortunate and something that is very common with all of the companies in the USA. They must comply with the government in one way or another. If the people within the company refuse, they will be replaced one way or another.

It's a sad fact that all of the major companies in the USA are spying or are complicit in the spying of all customers (both US citizen and not)

Ever wonder why Microsoft constantly has holes/glitches/back-doors in all of its operating systems for so long now. They could build a very secure operating system. They hire the best minds, yet year after year we see multiple exploits and issues.

Re: Yahoo scanned customer emails for US intelligence

#127
post #34

Earlier quoted context omitted.

This should forever taint Marissa Meyer's reputation. Failure to save Yahoo is understandable. Disregard for user privacy and safety at this scale is unforgivable.

As the saying, attributed to Burke (but whose precise origins are unknown) goes: "All that is necessary for the triumph of evil is that good [men and women] do nothing." Both Meyer and Stamos made their choices, on this issue.

How did Stamos' action help the cause?

He did better than Meyer but I fail to see how his move bettered the world. It helped him not longer being part of something nefarious. But he left all users he had responsibility for in the unclear.

Re: Yahoo scanned customer emails for US intelligence

#128
post #122
post #119

Earlier quoted context omitted.

> It's not really newsworthy that data from an email provider is sent to NSA under secret court orders and NSA can search the full text of it. It absolutely is newsworthy. We may have suspected it beforehand, we may suspect it happens at other providers, but we have specific proof about Yahoo now. This is new and important and we should be making a fuss. If we play the jaded cynic we are joining the enemies of democr…

No, we had proof back when Snowden released documents about the search engine that NSA has from data siphoned from providers. I'm not being cynical, I'm being realistic in that this isn't newsworthy now because it was extremely newsworthy when it first came to light a few years ago. I would rather this be newsworthy because it gets people interested in fighting FISC orders again, not against Yahoo and Mayer.

Except that the song and dance the US Congress put on pretending that the FREEDOM act made domestic surveillance illegal put an end to the Snowden Documents in many people's minds.

Continued news about domestic surveillance, police surveillance, Federal controlled 'perception management' news media messaging, etc should continue to happen so that citizens understand that the US has clarified that the bulk of these activities are legal, justified and necessary.

Re: Yahoo scanned customer emails for US intelligence

#129
post #79
post #5

Earlier quoted context omitted.

> But as a user, I would never use a service run by Marissa Mayer again. She lost that trust for good. Realistically, this is every American company. Why trust anyone?

It is impossible to live functionally in society without trusting someone on some level.

For sure. But it's prudent to understand and mitigate risk.

Re: Yahoo scanned customer emails for US intelligence

#130
post #100

Earlier quoted context omitted.

How do you slip something like this past a corporate security team? Stamos and @bcrypt never struck me as individuals that were "asleep at the wheel". Surely there was evidence somewhere? If Stamos wasn't briefed as to the situation and a security engineer found the rootkit on their own how could they be bound by the terms of an NSL / gag order?

I don't know any more about this than you do; I'm learning about it from the same Reuters story. But according to the story, the decision to implant the backdoor wasn't discovered by Yahoo security; rather, the backdoor itself was discovered, weeks after it was deployed.

So is the speculation that Stamos' departure was related to this? The timing would seem suspicious otherwise.

If so, one wonders if he would take a similar principled stance a second time at Facebook. Much harder to jump ship for greener pastures while already riding the biggest rocketship in town.

Post reply on HN