Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

171–180 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#171
post #46

Earlier quoted context omitted.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

In a large company, a useful thing to do if something fishy is going on is to go see the company's general counsel.[1] If they didn't know about it, they should be told. Their job is to keep the company out of legal trouble. In many cases they have a legal obligation to do something about it. An attorney will rarely tell you to do something illegal; they can be disbarred for that. If they tell you it's OK, then they'…

I'm in a right to work state, so they'll just find something else to fire me for.

Edit: But seriously, I'd take the job loss in a heart beat if my company was doing this crap.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#172
post #46

Earlier quoted context omitted.

When you get a legally-binding order from the government of the United States of America, and exhaust your legal appeals, you either comply or go to prison. An ethics course won't do you any good.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

>Options: - Refuse to take action.

I realize this stuff is easier said than done, but there's a lot of tough talk about the ethics of many things on HackerNews. How many people here work for companies like Yahoo or Facebook or many smaller shops that are legitimately harming people with these sorts of things?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#174
post #18

Earlier quoted context omitted.

I'm not sure that people are getting 'used' to it. I was talking to a non-techie over the weekend, and although they were aware about Snowden's NSA revelations, they were quite perturbed to think someone could be reading their email. I don't think people have stopped caring, they just feel helpless. This means that normal people may be willing to adopt new protocols (end-to-end encryption), something they wouldn't do…

Nothing in Snowden's leaks suggests that the government has access to your friend's email, let alone is reading it. Stop exaggerating to your non-techie friends.

Next, people on HN are going to deny the holocaust. 3... 2... 1...

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#175
> [Update (12/14/16): Reuters has specified that the rootkit was implemented as a Linux kernel module. Wow.]

Hm.. One more proof to avoid using non-free binary blobs in Linux kernel. Be safe. Use Debian GNU/Linux without non-free repo or any better[0] one.

[0] https://www.gnu.org/distros/free-distros.html

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#176

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

Save it for the MBAs instead, or even as an onboarding requirement along with other training for new management hires. It's not generally the engineers making these decisions.

Sometimes it's an active issue and at the end of the day someone must implement something terrible (knowingly or not -- direct a junior engineer to do some complex task with the expectation they'll leave behind security vulnerabilities, just as good as getting someone to intentionally leave an issue). Ethical engineers can and probably should quit -- who knows how much a required, dull ethics course would influence that though?

Other times at the end of the day it's just lack of engineers doing something -- typically due to management not signing off/budgeting. Ethical management won't even necessarily help here, the incentives don't change. Some sort of stronger corporate liability for negligence is needed, probably, but the problem is not generally the engineers -- engineers, with an ethics course or not, are typically the only people who care about these sorts of things in the first place! What's the largest dip in stock price due to a password leak? How about shady government collusion? Have any groups of shareholders demanded more care to avoid such issues at any company?

I'll wrap up with a joke: "It should be noted that no ethically-trained software engineer would ever consent to write a "DestroyBaghdad" procedure. Basic professional ethics would instead require him to write a "DestroyCity" procedure, to which "Baghdad" could be given as a parameter." --Nathaniel Borenstein

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#178

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

You think a course will teach someone ethics who does not have any? Or they do have ethics, but theirs are simply different than yours. Plenty of people believe assisting with government surveillance is the ethical thing to do to 'keep people safe.'

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#179
post #155

I know this is from October, but it warrants re-reading now. Today, Yahoo announced a hack of 1B accounts. They say they don't know who it is, but we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it. Previously, Yahoo willingly assisted an attacker in compromising 1B accounts. In this case, they did not disclose the attack publicly, or even to their own chief i…

> US intelligence activities are actively harmful to American commercial interests because they destroy trust, particularly from customers elsewhere in the world. I think, they actively harm US corporations because they fundamentally destroy trust of US citizens too.

Yea but they're still going to buy the products.

Foreigners, especially foreign corporations, are the portion of the market whose buying decision is most sensitive towards these issues.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#180
post #71

Earlier quoted context omitted.

It's not US. It's another state actor. Can't say more.

PRISM (Yahoo joined 2nd in 2008 after Microsoft in 2007) would basically defeat the purpose of doing this without permission... Did Yahoo Mail even use HTTPS? In that case a FISA warrant would just be an extra level of assurance that they got everything from that person's inbox (plus inboxes of 3 hops of everyone they ever emailed). Otherwise they were just an XKeyscore query, probably filtered by US geodata, away fr…

Aka MUSCULAR

https://en.m.wikipedia.org/wiki/MUSCULAR_(surveillance_progr...

Post reply on HN