Live data from Hacker News

Yahoo scanned customer emails for US intelligence

news.trust.org

181–190 of 417 posts

Re: Yahoo scanned customer emails for US intelligence

#182
post #75

Earlier quoted context omitted.

The entangling of the FISA order and the insider trading scandal actually makes things worse. His most significant trades came just months after he refused the FISA order --- after which he claims NSA arranged to have DoD contracts with Qwest terminated. He did something with an obvious material impact on his shareholders, and secretly profited from it. The reality, though, is that his tenure at Qwest appears broadly…

If you know, what was his defense against the fraud case? It could have been retribution (yes, that's completely speculative).

His claims included:

* That he was simply very optimistic about the business he was running that that he believed there would be an uptick in the stock long term after the company weathered the downturn he knew to be coming.

* That he was "set up" by NSA: yes, he sold at a high price anticipating a sector-wide downturn, but he did so because he'd been assured that Qwest would be part of a multi-billion NSA modernization program called "Groundbreaker", led by CSC, which contract would surely rescue Qwest's stock and even out his sale.

* That his board had demanded that he sell his stock, and that such sales were routine at Qwest.

* That he was distraught over the suicide of his son and sold the stock as part of an effort to immediately disentangle himself from the CEO position which he hoped to leave.

Against that, you have the black-and-white record of his trades and the testimony of numerous high-level Qwest executives all saying they'd been urgently warning him to revise Qwest's targets downwards. He not only maintained the unrealistic targets, and participated in channel-stuffing-style schemes to fake up earnings numbers, but profited personally by trading against those bogus numbers.

Re: Yahoo scanned customer emails for US intelligence

#183
post #127

Earlier quoted context omitted.

As the saying, attributed to Burke (but whose precise origins are unknown) goes: "All that is necessary for the triumph of evil is that good [men and women] do nothing." Both Meyer and Stamos made their choices, on this issue.

How did Stamos' action help the cause? He did better than Meyer but I fail to see how his move bettered the world. It helped him not longer being part of something nefarious. But he left all users he had responsibility for in the unclear.

At least he managed to say, if only privately, "I'm not going to be a party to this" (most likely leaving a significant pile of cash and/or equity on the table in doing so). Which is way more than many CIOs/CSOs do in similar situations.

Of course you or I might like to believe we would have taken a more overtly defiant stand (by going public for example). But then again, we weren't there, in his shoes - now were we?

Re: Yahoo scanned customer emails for US intelligence

#184
post #158

Earlier quoted context omitted.

The lesson from this is to not trust corporations with out privacy. I'm as upset about this as anybody, but realistically speaking... they had a gun to their heads. The real problem here isn't Yahoo! (or the other corporations), it's the government.

The thing you quoted doesn't assign blame. It simple says you can't trust that corporations will/can protect your privacy.

It's referring to cause of the symptom. Paraphrased differently: If the government can hold a gun to any organization or individuals' head for information, then the privacy distrust doesn't stop with just corporations.

Re: Yahoo scanned customer emails for US intelligence

#185
post #79
post #5

Earlier quoted context omitted.

> But as a user, I would never use a service run by Marissa Mayer again. She lost that trust for good. Realistically, this is every American company. Why trust anyone?

It is impossible to live functionally in society without trusting someone on some level.

Yea--I'm just saying this is a product of being a business, not Meyer. One can fight it and still give information over. You can't take the sign of struggle as a sign your data is safe.

Re: Yahoo scanned customer emails for US intelligence

#187
post #122
post #119

Earlier quoted context omitted.

> It's not really newsworthy that data from an email provider is sent to NSA under secret court orders and NSA can search the full text of it. It absolutely is newsworthy. We may have suspected it beforehand, we may suspect it happens at other providers, but we have specific proof about Yahoo now. This is new and important and we should be making a fuss. If we play the jaded cynic we are joining the enemies of democr…

No, we had proof back when Snowden released documents about the search engine that NSA has from data siphoned from providers. I'm not being cynical, I'm being realistic in that this isn't newsworthy now because it was extremely newsworthy when it first came to light a few years ago. I would rather this be newsworthy because it gets people interested in fighting FISC orders again, not against Yahoo and Mayer.

What Snowden revelation are you talking about? I remember when everyone was up in arms about PRISM, but that's just a pretty interface on more focused requests of data for specific users.

This is the first instance, to my knowledge, of the government requesting carte blanche realtime search of all incoming and outgoing email for all users.

Re: Yahoo scanned customer emails for US intelligence

#188
post #121

Earlier quoted context omitted.

Please, I am absolutely for protections of data privacy even more stringent than what the USPS does with parcels. I would be for something akin to "Swiss Banking requirements for Data" - where companies are NOT allowed to share data unless given exception in writing/cryptographically. I'm sure we can expound on these ideas collectively. I'd also be OK with services that DO treat data as a semipermeable membrane. Thin…

Well, your original comment lacks the ethical understanding that you clearly do have. My own island of autonomy is tinc/unison. Less scalable namespaces, but more straightforward for now. The only point I disagree on is your last bit. I don't think waiting out the politicians will suffice. Millenial politicians will still be politicians, still desire power in order to "do good", and still pander to the easily-spooked…

Hmm.. I thought I included my project. https://hackaday.io/project/12985-multisite-homeofficehacker... . Look further down on Tor configuration, and I include seamless .onion resolution.

I do agree that a technological solution(s) are needed. I see things like Zero-knowledge Proofs, Homomorphic encryption, plausibility networks, and other types of software are essential for freedom.... But I think this is also a governmental and societal issue as well. Of course, there's no reason to attack both fronts :)

And I'm also very much interested in Government as a Service, ala what Estonia is doing. The US in antiquated... I don't see it thriving much longer, as it's not staying ahead with technology in government. The spying on citizens however.....

Re: Yahoo scanned customer emails for US intelligence

#189
post #173
post #146

Earlier quoted context omitted.

Also committing to a "fuck NSLs, we'll just go public and take it all the way legally" stance upfront might deter NSLs in the first place.

The fact no-one has done this means the consequences must be absolutely devastating. Probably jail time for executives and potential financial collapse. Probably the only time an executive would go to jail for breaking the law in the US...

I remain unclear on the consequences. I don't think they're tested. 18 USC 2709(c) is what the government cites when they invoke nondisclosure. You win a prize if you find the consequences for violating that statute. Also, NSLs can be upgraded to court orders if the recipient is noncompliant. 18 USC 3511 discusses that:

> the Attorney General may invoke the aid of any district court of the United States within the jurisdiction in which the investigation is carried on or the person or entity resides, carries on business, or may be found, to compel compliance with the request. The court may issue an order requiring the person or entity to comply with the request. Any failure to obey the order of the court may be punished by the court as contempt thereof.

So they can upgrade to a court order and then hold you in contempt if you do not fulfill the terms of the court order. I am not clear if that includes the nondisclosure term. This is the closest I've ever come to identifying "what would legally happen if someone published an NSL?" Honestly, and I'm not extremely comfortable saying this and please do not get ideas, after a lot of research I don't think there is a federal punishment defined in legislation for doing it.

Usually laws have a punishment immediately after them. As in, section A is what's illegal, section B is how to punish violations of section A. 18 USC 2709 and 18 USC 3511 don't have that, so I honestly have no idea what would happen, and I half wonder if the federal government doesn't either.

(IANAL, etc)

Re: Yahoo scanned customer emails for US intelligence

#190

I think the attitude here that most tech companies are rolling over and just complying without a single ethical consideration is misplaced. The government has been doing an excellent job of basically extorting these companies into compliance. They threaten the full weight of the US government's wraith and then tie every order up with classifications and gag orders. You aren't legally allowed to talk to other companie…

If that were the case, then Apple would've caved in, too.

Mayer was probably too new and too scared to deal with this, especially when she had to think about her new baby.

My point is it has less to do with "Yahoo being scared about being destroyed by the US government" and more with Mayer's own personal fear of the US government, and easily caving to such threats, whether it was because of her baby, because of weak character, or because she was inexperienced as CEO didn't know how to handle this.

EDIT: Also Yahoo's response to the story is such bullshit:

> “Yahoo is a law abiding company, and complies with the laws of the United States.”

What's the law you're abiding with that says you need to implement such a backdoor? Name it. Even the FBI named the law or laws it thought would help it force Apple to put a backdoor in its phones.

So if Yahoo can't even name the law, then that law or the gag order saying they can't name it are unconstitutional. Period. It also proves once again how easily Yahoo caved.

Post reply on HN