Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

191–200 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#191
post #160

Earlier quoted context omitted.

In a large company, a useful thing to do if something fishy is going on is to go see the company's general counsel.[1] If they didn't know about it, they should be told. Their job is to keep the company out of legal trouble. In many cases they have a legal obligation to do something about it. An attorney will rarely tell you to do something illegal; they can be disbarred for that. If they tell you it's OK, then they'…

In the case of NSLs, or UK orders from the security services, it may be illegal to tell anyone who isn't mentioned in the order. Including the company's general counsel. In the event that you are asked to do something illegal, it may be illegal or inadmissible to mention that you were ordered to do so by the government (Matrix-Churchill trial passim)

If you're the CEO or some other exec in receipt of such an order, you're not going to be able to single-handedly implement a backdoor without anyone noticing, even if you possessed the skill to do so in the first place.

The nature of such an order requires you to be able to tell the people who need to do it what it is that you need them to do, even if you can't tell them why.

Additionally, anybody with the power to veto such a change also must be provided with a good reason why they can't veto this one. Your legal counsel needs to understand why the change must happen, so he can respond appropriately to questions from pissed off developers and ensure that your company is complying with the letter of the demand (and no more).

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#192
post #46

Earlier quoted context omitted.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

I think it's reasonable to expect a reasonable level of (legal) pushback from service providers against government warrants or mandates. It's unreasonable to expect of them to risk their entire business.

But they're doing that anyway, in bits and bobs, when they erode the trust of their customers.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#193
post #46

Earlier quoted context omitted.

Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…

> Options: - Refuse to take action. I realize this stuff is easier said than done, but there's a lot of tough talk about the ethics of many things on HackerNews. How many people here work for companies like Yahoo or Facebook or many smaller shops that are legitimately harming people with these sorts of things?

I've worked on products with tens of millions of customers, in a position to know if something nefarious was going on, and also in a position to be able to do something about it.

This is why I've given it some thought. This is something that you probably need to spend a little time thinking about if you're in a similar situation, because things are not going to get better.

It's a personal decision. I can't tell you it's worthwhile to quit your job or risk legal action. But if you're responsible for the privacy and rights of millions of people, you should consider what your actions will be.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#194
post #176

Earlier quoted context omitted.

Save it for the MBAs instead, or even as an onboarding requirement along with other training for new management hires. It's not generally the engineers making these decisions. Sometimes it's an active issue and at the end of the day someone must implement something terrible (knowingly or not -- direct a junior engineer to do some complex task with the expectation they'll leave behind security vulnerabilities, just as…

I disagree strongly. If you from an engineering perspective are the only one who truly recognizes the implications of a management decision, you need to speak up about it.

Engineers do speak up, frequently. For a famous example, see the Challenger disaster. Again, engineers aren't generally the problem. Still disagree?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#195
post #47

Earlier quoted context omitted.

People have the option to quit. The company is legally bound to obey, but individual employees can chose for themselves whether they want to be a party to it. Yahoo may still be court ordered to implement it, just hopefully not with their best and brightest developers. I also have a theory that a lot of the recent terrible news coming out of Yahoo is due to staff complying with the letter of the legal order but not t…

The other point to be made is that you probably want your best developers implementing back doors (if you are compelled to do so), so at least the back door is as secure as possible (and not trivially bipassed)

All the more reason that you should take pause when your best developers refuse to do so.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#196
post #50

Earlier quoted context omitted.

This is why we (as a community/industry) need to have the equivalent of a prison/death threat. The government wins by making it personal, by threatening prison and death for your obedience. It's not an abstract threat. It is directed to a specific person not a company or security team. The people who comply can quit those companies but they don't. I'm not referring to the ones down the chain (e.g the security team wh…

> Create a climate of "snitches get stitches" and maybe they will think twice before selling out the lives of a billion people. Committing crimes against people who defect is obviously not going to work. They'll just arrest you for it. But suppose we create a certification. To get certified all you have to do is promise not to work on a specific list of things: Mass surveillance, backdoors, etc. To lose certification…

> To lose certification forever all you have to do is work on one of those things and get caught.

There, fixed that for you. That small detail is why your attractive idea wouldn't work in real life. How many years it took for the car industry scandal about tampering with emission tests to be revealed? And it only got to ruin the the reputations of the few engineers involved in the forgery.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#197
post #50

Earlier quoted context omitted.

This is why we (as a community/industry) need to have the equivalent of a prison/death threat. The government wins by making it personal, by threatening prison and death for your obedience. It's not an abstract threat. It is directed to a specific person not a company or security team. The people who comply can quit those companies but they don't. I'm not referring to the ones down the chain (e.g the security team wh…

> Create a climate of "snitches get stitches" and maybe they will think twice before selling out the lives of a billion people. Committing crimes against people who defect is obviously not going to work. They'll just arrest you for it. But suppose we create a certification. To get certified all you have to do is promise not to work on a specific list of things: Mass surveillance, backdoors, etc. To lose certification…

CanaryCertified (TM).

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#198
post #160

Earlier quoted context omitted.

In a large company, a useful thing to do if something fishy is going on is to go see the company's general counsel.[1] If they didn't know about it, they should be told. Their job is to keep the company out of legal trouble. In many cases they have a legal obligation to do something about it. An attorney will rarely tell you to do something illegal; they can be disbarred for that. If they tell you it's OK, then they'…

In the case of NSLs, or UK orders from the security services, it may be illegal to tell anyone who isn't mentioned in the order. Including the company's general counsel. In the event that you are asked to do something illegal, it may be illegal or inadmissible to mention that you were ordered to do so by the government (Matrix-Churchill trial passim)

My understanding is that US requests explicitly include a clause that exempts your counsel from the NDA requirement, in that you're permitted to show it to and discuss it with them.

(They, of course, are bound to not share it further.)

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#199

I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…

And if there is any class of people known for their impeccable ethics it is lawyers.

I'm not sure that class is having the intended effect.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#200
post #87
post #66

Earlier quoted context omitted.

Let's say an unaffiliated third party (white-hat hacker) found the exploit and reported it to you under a Bug Bounty program. Let's also say that that third-party was someone who followed "responsible disclosure" rules, and said that they'd publicize the vulnerability if you didn't do so yourself within a short time-frame. You investigate (by asking your team, your boss, looking at the bug tracker, etc.) and figure o…

You talk to your boss. Your boss talks to the NSA. The NSA will find a way to silence the white-hat. Problem solved. Philosophical dilemmas are fun to talk about, but only as long as you take the premises as granted. People who carry swords tend not to waste time trying to disentangle knots that they can simply cut in half. Most "technical" solutions to "human" problems suffer this vulnerability.

> You talk to your boss. Your boss talks to the NSA. The NSA will find a way to silence the white-hat. Problem solved.

Seems you're assuming the white hat hacker is from USA. I'm not so sure the NSA is going to be able to silence a white hat hacker from say Russia, or anywhere out of USA for that matter.

Post reply on HN