Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

101–110 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#101
post #71

Earlier quoted context omitted.

It's not US. It's another state actor. Can't say more.

PRISM (Yahoo joined 2nd in 2008 after Microsoft in 2007) would basically defeat the purpose of doing this without permission... Did Yahoo Mail even use HTTPS? In that case a FISA warrant would just be an extra level of assurance that they got everything from that person's inbox (plus inboxes of 3 hops of everyone they ever emailed). Otherwise they were just an XKeyscore query, probably filtered by US geodata, away fr…

I feel like everyone has forgotten about PRISM. All the big companies denied they participated in PRISM. Is it real, and if so, why have Americans been so complacent about its existence?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#102
post #82
post #55

Earlier quoted context omitted.

All that would accomplish is that you and everyone you sent this letter to would now be subject to another NSL with a gag order, and your fix would be undone.

I don't see how a gag order can scale to hundreds of people without the subject matter becoming common knowledge.

Lots of secrets scale to hundreds of people just fine, and are enforced weaker than with a prison sentence. As far as any of those people are concerned, they are now actively monitored in the name of national security (same reasoning as why the NSL was issued).

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#103

I know this is from October, but it warrants re-reading now. Today, Yahoo announced a hack of 1B accounts. They say they don't know who it is, but we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it. Previously, Yahoo willingly assisted an attacker in compromising 1B accounts. In this case, they did not disclose the attack publicly, or even to their own chief i…

Given its government's track record, I would think that data centers in the US should be walled off in much the same way as data centers in China. It is frankly surprising that American companies are blind to their own government's track record for indiscriminately spying on its citizens and people around the world.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#104

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

I think tech people are actually far more likely to be against this stuff than the general population. Also, a significant portion of people in tech don't have many formal qualifications compared to (as a bit of an extreme example) something like medicine or accounting. Also, as an accounting major myself, there was a big push to impress upon students ethics after the series of financial frauds in the 2000s. It involves a lot of telling us that Sarbanes-Oxley exists often, quizzing us on some detail of the act rarely, but never actually giving us ethically questionable situations and having us debate what should be done or covering cases of unethical behavior. Having taken an actually course in ethics, I'm not impressed by it's ability to get people to behave ethically, it was very theoretical and, actually, not very prescriptivist which is actually probably what you want. And the struggle you're up against, too, is that the NSA is a government agency giving you legally binding orders because, they argue, they need it for law-enforcement purposes. It's not even a black-and-white issue where you can expect everyone, even most, to agree on if the article described ethical behavior or not.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#105
post #71

Earlier quoted context omitted.

PRISM (Yahoo joined 2nd in 2008 after Microsoft in 2007) would basically defeat the purpose of doing this without permission... Did Yahoo Mail even use HTTPS? In that case a FISA warrant would just be an extra level of assurance that they got everything from that person's inbox (plus inboxes of 3 hops of everyone they ever emailed). Otherwise they were just an XKeyscore query, probably filtered by US geodata, away fr…

I feel like everyone has forgotten about PRISM. All the big companies denied they participated in PRISM. Is it real, and if so, why have Americans been so complacent about its existence?

What do you think PRISM is?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#106
post #98
post #53

Earlier quoted context omitted.

Wow. This is probably the worst comment I've ever seen on HN. You're suggesting that people who follow the law, which you disagree with, get blacklisted, following the model of criminals killing other criminals who follow the law. If you want to change the government, there are far better ways than retaliating against citizens unwilling to risk life and limb for your ideology. I think you need to learn to direct your…

> Wow. This is probably the worst comment I've ever seen on HN. You're suggesting that people who follow the law, which you disagree with, get blacklisted, following the model of criminals killing other criminals who follow the law. Because everything legal is good. People like you are what Stalin, Hitler, and Mao rely on.

Where did I say anything remotely like that?

You're taking an ideological stance on privacy, one I generally agree with, and forgetting the motivator behind the overreaching laws, which is quite simply to ATTEMPT to do something to make this country safer. Does it work? I don't think so, but a lot of people do. It's pretty hard to quantify since the data isn't open, and by its nature can't be.

It's a pretty severe jump from disagreeing with whether or not this system works, and what liberties can challenge the system, to pulling your godwin card out.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#107

Earlier quoted context omitted.

That's a very good point actually. Though in this case they say the tip-off came from a law enforcement agency (I assume they mean an American one). It's possible however that agency doesn't realise it's a clandestine operation by another US agency. Or they do, but now the operation is complete (this was three years ago) and they want a way of informing yahoo about the breach without admitting who was behind it in th…

It's not US. It's another state actor. Can't say more.

If you can't say more your words are useless. The only thing you need to comment on this website is an email address.

Unverifiable comments like this are harmful.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#108
post #84
post #53

Earlier quoted context omitted.

Wow. This is probably the worst comment I've ever seen on HN. You're suggesting that people who follow the law, which you disagree with, get blacklisted, following the model of criminals killing other criminals who follow the law. If you want to change the government, there are far better ways than retaliating against citizens unwilling to risk life and limb for your ideology. I think you need to learn to direct your…

While I do think the concept of community ostracision is impractical (because there is never only one tech community to start with) - "I just followed the law" is never a moral free pass. Given that what law means actually is daily debated in courtrooms it's not only morally hollow, it's uncomputable to an individual in the general sense. "I just did what the authority figure told me to" is one the oldest excuses in…

To be clear - I am not suggesting that everything on the books should be followed, I am suggesting that punishing people who are following these specific laws in question, which are following NSA letters and gag orders, does not fit what I think is the commonly accepted way we treat each other.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#109
post #46

Earlier quoted context omitted.

When you get a legally-binding order from the government of the United States of America, and exhaust your legal appeals, you either comply or go to prison. An ethics course won't do you any good.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

Or...leave! Mine are Kerala and São Paulo.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#110

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

My alma mater had just that. It was a course named "Ethics in Technology".

The description for the course:

"

TCH301 is designed to introduce students to essential concepts necessary to evaluate the ethical implications and potential impacts of the use of new technology within human society and culture. Students will explore modern ethical dilemmas in technology, looking at multiple aspects of how the introduction of technology redefines law and values.

"

From: http://majors.uat.edu/Tech-Studies/Pages/Core_Curriculum.asp...

It was and still is a required course to graduate with a degree from UAT.

Post reply on HN