Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

91–100 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#91

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

What engineering program doesn't require ethics as a standard freshmen engineering introduction?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#92
post #66
post #9

Earlier quoted context omitted.

I think it's irrelevant in practice. (In theory, that's an interesting question) You're not making the decision to make this public. If you're on the security team, you're going to notify the boss, and at that scale of the system compromise this goes all the way to the top. At that point someone who knows about the gag order is in the chain. The only scenario where I think the question matters is if you do something…

Let's say an unaffiliated third party (white-hat hacker) found the exploit and reported it to you under a Bug Bounty program. Let's also say that that third-party was someone who followed "responsible disclosure" rules, and said that they'd publicize the vulnerability if you didn't do so yourself within a short time-frame. You investigate (by asking your team, your boss, looking at the bug tracker, etc.) and figure o…

Whether or not the company is doing everything they can to resist the order, I think that NSL's are always accompanied by a clear communication channel between a company's counsel and the agency.

So, after someone under the gag realizes the situation, they get the company's lawyers in contact with the agency to see what to do. The agency would then gag the white hat.

IMO, that's a huge part of why NSL's are scary. You are in an absolute strangle-hold and are at the mercy of the agency for your every move.

If I remember correctly, people even had to argue for the ability to talk to a lawyer about receiving an NSL. So, the feds are really not messing around here and will do absolutely everything to ruin you if you don't cooperate fully. Any perceived resistance is crushed.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#93
post #83
post #62

Earlier quoted context omitted.

So now, quitting your job (because you're asked to do something unethical) is the equivalent of losing your life and limbs? Let me guess, you believe all government actions are lawful. All lawful actions are righteous and justified. The only permissible way to change the system is through the system. Did I get the gist of your morality? In which case, keep voting and I'm sure you will see the changes you want reflect…

> So now, quitting your job (because you're asked to do something unethical) is the equivalent of losing your life and limbs? It's an expression. How about "Losing your livelyhood." It's a real thing for some people. > Let me guess, you believe all government actions are lawful. All lawful actions are righteous and justified. The only permissible way to change the system is through the system. Did I get the gist of y…

[deleted]

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#94
post #41

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

Undergraduate ethics courses usually just go over the big historically-important ethical analysis systems (utilitarianism, Kantian deontology, veil of ignorance, social contract, etc.) Unlikely to touch on trickier issues such as why you ought to act ethically at all, or even what it means to act ethically - why, for instance, are you so certain writing backdoors for the NSA is unethical? This is certainly something…

Even worse though, is that these sorts of courses are almost always derided by the majority of the student base as a waste of time, and "common sense stuff".

I actually really enjoyed the one I did, although it had just gone through a major rewrite to improve it a lot. And yet, I don't think I ever heard any of my peers mention the course with anything but contempt.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#95

I would be surprised if anyone was using Yahoo for anything but a spam account when this occurred. I guess a really good indicator that things were not right was when the CSO left the company with no real reason. He was like I want no part of this shit.

yahoo groups is still very big. it was big before yahoo acquired it (egroups), remained almost unchanged throughout the years, and is now in maintenance mode, but there are still millions of users who continue to sign up.

I regularly dream about being involved in the creation of a project that lasts this long. News groups, IRC, etc. I would love to look back on my career and think that I contributed to something that user's would simply not let die. The feels to be a creator of something of that magnitude has to change a person.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#96

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

I had to take a full term length ethics course to get my Software Engineering degree -- at what post-secondary institutions does this not hold true?

How do we make all the unregulated ways of learning how to code (e.g. coding bootcamps) include ethics in their curriculum?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#97

There is no moral dilemma here. If you blow the whistle on the NSA you are a traitor to your own country. How can this not be clear to people.

"My country, right or wrong; if right, to be kept right; and if wrong, to be set right ." - Carl Schurz Also, by that logic, any H1B worker that refuses to spy on his company on behalf of his country of citizenship would be a traitor. Do you really want that to be the operative ethics when most S.V. companies are made from people from all over the world? Because I certainly do not.

You don't have to be part of it. If you find out that you are part of it then just quit. But by blowing the whistle you endanger thousands of lives, and you think that just because you're some sort of freedom fighter then it's OK.

It's not OK. You want to fight the freedom fight? Go work in politics. Don't screw your own country.

BTW - I'm not from the US.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#98
post #53
post #50

Earlier quoted context omitted.

This is why we (as a community/industry) need to have the equivalent of a prison/death threat. The government wins by making it personal, by threatening prison and death for your obedience. It's not an abstract threat. It is directed to a specific person not a company or security team. The people who comply can quit those companies but they don't. I'm not referring to the ones down the chain (e.g the security team wh…

Wow. This is probably the worst comment I've ever seen on HN. You're suggesting that people who follow the law, which you disagree with, get blacklisted, following the model of criminals killing other criminals who follow the law. If you want to change the government, there are far better ways than retaliating against citizens unwilling to risk life and limb for your ideology. I think you need to learn to direct your…

> Wow. This is probably the worst comment I've ever seen on HN. You're suggesting that people who follow the law, which you disagree with, get blacklisted, following the model of criminals killing other criminals who follow the law.

Because everything legal is good. People like you are what Stalin, Hitler, and Mao rely on.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#99
post #62
post #53

Earlier quoted context omitted.

Wow. This is probably the worst comment I've ever seen on HN. You're suggesting that people who follow the law, which you disagree with, get blacklisted, following the model of criminals killing other criminals who follow the law. If you want to change the government, there are far better ways than retaliating against citizens unwilling to risk life and limb for your ideology. I think you need to learn to direct your…

So now, quitting your job (because you're asked to do something unethical) is the equivalent of losing your life and limbs? Let me guess, you believe all government actions are lawful. All lawful actions are righteous and justified. The only permissible way to change the system is through the system. Did I get the gist of your morality? In which case, keep voting and I'm sure you will see the changes you want reflect…

> So now, quitting your job (because you're asked to do something unethical) is the equivalent of losing your life and limbs?

In a capitalist system, where your alternatives are "work or stave", yes.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#100

I know this is from October, but it warrants re-reading now. Today, Yahoo announced a hack of 1B accounts. They say they don't know who it is, but we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it. Previously, Yahoo willingly assisted an attacker in compromising 1B accounts. In this case, they did not disclose the attack publicly, or even to their own chief i…

> They say they don't know who it is, but we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it.

I would assume, like most announcements, the reason that it's being announced is because the data is available out there and been seen in the wild.

Post reply on HN