Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

121–130 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#121
post #108
post #84

Earlier quoted context omitted.

While I do think the concept of community ostracision is impractical (because there is never only one tech community to start with) - "I just followed the law" is never a moral free pass. Given that what law means actually is daily debated in courtrooms it's not only morally hollow, it's uncomputable to an individual in the general sense. "I just did what the authority figure told me to" is one the oldest excuses in…

To be clear - I am not suggesting that everything on the books should be followed, I am suggesting that punishing people who are following these specific laws in question, which are following NSA letters and gag orders, does not fit what I think is the commonly accepted way we treat each other.

Yes. I agree with this sentiment fully.

The main connotation which invoked my response was equalling the resentment of following the law unilaterally to the mindset of a criminal organization.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#122
post #46

Earlier quoted context omitted.

When you get a legally-binding order from the government of the United States of America, and exhaust your legal appeals, you either comply or go to prison. An ethics course won't do you any good.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

Take it up with the people who thought it was a good idea. All the above is sneaky. Just talk with people up the chain if someone is following orders from someone else. If that means you end up in the white house, so be it.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#123
post #46

Earlier quoted context omitted.

When you get a legally-binding order from the government of the United States of America, and exhaust your legal appeals, you either comply or go to prison. An ethics course won't do you any good.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

Be found in contempt and go to jail... you first?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#124

This is an old story that was discussed extensively when it was new (in October): https://news.ycombinator.com/item?id=12637126

Good point.

I assumed it was a direct development in the other day's story re: the largest hacking to date for YHOO.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#125
post #46

Earlier quoted context omitted.

When you get a legally-binding order from the government of the United States of America, and exhaust your legal appeals, you either comply or go to prison. An ethics course won't do you any good.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

In a large company, a useful thing to do if something fishy is going on is to go see the company's general counsel.[1] If they didn't know about it, they should be told. Their job is to keep the company out of legal trouble. In many cases they have a legal obligation to do something about it. An attorney will rarely tell you to do something illegal; they can be disbarred for that. If they tell you it's OK, then they've given you legal advice as an employee, which gives you some protection when things come unglued. You're also unlikely to be fired for talking to the company's general counsel.

[1] http://www.slu.edu/Documents/law/Law%20Journal/Archives/Dugg...

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#126
post #53
post #50

Earlier quoted context omitted.

This is why we (as a community/industry) need to have the equivalent of a prison/death threat. The government wins by making it personal, by threatening prison and death for your obedience. It's not an abstract threat. It is directed to a specific person not a company or security team. The people who comply can quit those companies but they don't. I'm not referring to the ones down the chain (e.g the security team wh…

Wow. This is probably the worst comment I've ever seen on HN. You're suggesting that people who follow the law, which you disagree with, get blacklisted, following the model of criminals killing other criminals who follow the law. If you want to change the government, there are far better ways than retaliating against citizens unwilling to risk life and limb for your ideology. I think you need to learn to direct your…

1/ For the most part, this is not the "law". We're talking about instructions that have not been legally challenged, that are issued by a government agency, ie civil servants that are not responsible to the people.

2/ In any case "the law" is only the result of a very imperfect process; it's not the word of God: it can be changed (it often is) and it doesn't have any special moral value. Your moral code is yours, it's dictated by your conscience and should not be taken whole from texts written by other people.

In the 20th century, many crimes have been committed by people following the law, and not just in Nazi Germany. French Jews were arrested and delivered to the German authorities by members of the French police who were simply following orders. The ones giving the orders have indeed been tried after the war, but not the ones following them; in fact they never had to suffer any consequence for their actions. But the truth is, had there been no cops willing to participate, there would have been no deportations.

"I'm just doing my job" or "I was just following orders" is NOT a valid excuse. It's a cop out (pun intended).

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#127

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

In Canada all engineering students are required to take an ethics course.

Granted since it is taught to all engineering disciplines the material is quite broad, mostly focusing on topics like bribery and negligence, but it does also cover whistle blowing.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#128

This is an old story that was discussed extensively when it was new (in October): https://news.ycombinator.com/item?id=12637126

Good point. I assumed it was a direct development in the other day's story re: the largest hacking to date for YHOO.

It was linked in the comments thread of that story, probbly why it was re-submitted.

Personally, I missed this story when it was first posted, but regardless reposting now definitely adds an interesting additional perspective to the recent announcement, especially as we all wait for more information to be released about how the hack was executed and what the broader implications are. Combined the two stories are more insightful than seperate IMO.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#129
post #76

If they are doing this at Yahoo, what proof do we have they are not doing this at Google...right at this moment?

One would have to be really naive to believe that Google, Apple and the other big ones aren't backdoored by the three letter agencies by now.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#130
post #46

Earlier quoted context omitted.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

If you want to quit to refuse to help, fine, but I take serious issue with what you're suggesting beyond that. These are the legal actions of the United States government, executing the authority given to them to the people's elected representatives, and overseen by a judiciary duly selected according the constitutional procedures. Their legal and democratic authority is unassailable. Further, you don't know what mot…

> You could be impeding the investigation into a deadly plot. That's the "think of the children" of security agencies. You think they are so clueless that they need to read all mail of Yahoo or only follow some accounts?.
Post reply on HN