Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

151–160 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#151
post #53

Earlier quoted context omitted.

Wow. This is probably the worst comment I've ever seen on HN. You're suggesting that people who follow the law, which you disagree with, get blacklisted, following the model of criminals killing other criminals who follow the law. If you want to change the government, there are far better ways than retaliating against citizens unwilling to risk life and limb for your ideology. I think you need to learn to direct your…

Not everyone is in so privileged of a position to be taking your specific moral high ground over their own well being. "Privilege" doesn't enter into it. Everybody has the option to do the right thing, if they're willing to accept the consequences. Not everybody will of course, but there's nothing truly preventing one from doing so.

The difference is that for some people the "consequence" for doing the right thing is that they'll have to get a new, but similar, job while for other people it's watching their family being tortured to death. Saying that these two people are facing the same or even similar options is disingenuous to say the least.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#152

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

https://news.ycombinator.com/item?id=13169587

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#153
What really upsets me about this is the idea that the security team was bypassed, effectively compromising security for Yahoo and every one of their customers. The idea that a company executive would knowingly bypass their own CSO, and take it upon themselves to understand the risks they are introducing, is mind-bogglingly stupid and egregious.

Marissa Meyer, if she approved this, should be deeply ashamed of herself.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#154

I know this is from October, but it warrants re-reading now. Today, Yahoo announced a hack of 1B accounts. They say they don't know who it is, but we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it. Previously, Yahoo willingly assisted an attacker in compromising 1B accounts. In this case, they did not disclose the attack publicly, or even to their own chief i…

> we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it.

That is the way to bet, but it is also possible (though not very likely) that Yahoo disclosed this publicly before the relevant USG agency could get an NSL out.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#155

I know this is from October, but it warrants re-reading now. Today, Yahoo announced a hack of 1B accounts. They say they don't know who it is, but we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it. Previously, Yahoo willingly assisted an attacker in compromising 1B accounts. In this case, they did not disclose the attack publicly, or even to their own chief i…

> US intelligence activities are actively harmful to American commercial interests because they destroy trust, particularly from customers elsewhere in the world.

I think, they actively harm US corporations because they fundamentally destroy trust of US citizens too.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#156

I know this is from October, but it warrants re-reading now. Today, Yahoo announced a hack of 1B accounts. They say they don't know who it is, but we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it. Previously, Yahoo willingly assisted an attacker in compromising 1B accounts. In this case, they did not disclose the attack publicly, or even to their own chief i…

> US intelligence activities are actively harmful to American commercial interests because they destroy trust, particularly from customers elsewhere in the world. We already stand as the most powerful country on earth. It's a great testament to ineptitude in government that this is the current reality.

Yes. And dangerous in the long term because the US wont be the most powerfull country forever. High trees catch a lot of wind. People are more likely to hate the US. When the tides change and the power inbalance goes away the hate and mistrust will still be there. But maybe society is wiser this time around.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#157

Earlier quoted context omitted.

If you can professionalize a certain set of ethics, you can make it impossible for your employer to find anyone to complete the job. For example, capital punishment is increasingly hard to carry out because anesthesiologists refuse to participate and drug companies won't supply the drug.

I'm not sure the capital punishment part is a good comparison... It's because north american governments are squeamish about solutions that look brutal but efficient. I'm sure that if a state wanted to implement capital punishment via firing squad and advertised for death penalty proponent rifle marksmen they would have no lack of candidates.

Yes but how would that look? The death penalty relies on the "humane" veneer, or it would be abolished very quickly. If there were the slightest hint that the people killing other people in the name of the state are actually enjoying it, there would be a huge outcry.

Similarly for surveillance, if you're only able to implement crude solutions people will be disgusted. "So you're saying Yahoo was compromised because no good engineers wanted to work there due to government interference?" We don't know whether it's true, but the assumption is already damning.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#158

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

They do in Spain, it covered data protection laws & professional ethics and was in the third year of the four year degree

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#159
post #103

Earlier quoted context omitted.

Given its government's track record, I would think that data centers in the US should be walled off in much the same way as data centers in China. It is frankly surprising that American companies are blind to their own government's track record for indiscriminately spying on its citizens and people around the world.

You mean American companies like Apple? Whether you trust them or not they've certainly brought it up. Though they might not label the spying indiscriminate; maybe still 'criminate. Or are Chinese companies doing some interesting walling-off?

(The opposite of indiscriminate is discriminate)

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#160
post #46

Earlier quoted context omitted.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

In a large company, a useful thing to do if something fishy is going on is to go see the company's general counsel.[1] If they didn't know about it, they should be told. Their job is to keep the company out of legal trouble. In many cases they have a legal obligation to do something about it. An attorney will rarely tell you to do something illegal; they can be disbarred for that. If they tell you it's OK, then they'…

In the case of NSLs, or UK orders from the security services, it may be illegal to tell anyone who isn't mentioned in the order. Including the company's general counsel.

In the event that you are asked to do something illegal, it may be illegal or inadmissible to mention that you were ordered to do so by the government (Matrix-Churchill trial passim)

Post reply on HN