I know this is from October, but it warrants re-reading now. Today, Yahoo announced a hack of 1B accounts. They say they don't know who it is, but we can conclude it's not the US government because Yahoo is willing and legally able to publicly disclose it. Previously, Yahoo willingly assisted an attacker in compromising 1B accounts. In this case, they did not disclose the attack publicly, or even to their own chief i…
Given its government's track record, I would think that data centers in the US should be walled off in much the same way as data centers in China. It is frankly surprising that American companies are blind to their own government's track record for indiscriminately spying on its citizens and people around the world.
Yahoo installed a backdoor for the NSA behind the back of the security team
241–250 of 302 posts
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#242Earlier quoted context omitted.
I wonder how they think this is supposed to work. - CEO gets a Letter. Does the CEO start learning Python/C++/PHP and Cisco configuration? Or does he tell a worker bee "Shhh! And read this Letter" ? - Worker bee starts making changes to production code and systems. Suddenly he starts needing automated code reviews, and reconfiguration alerts go out when he frobs the firewalls. These changes are indistinguishable from…
The easiest way is probably to create a bullshit project with a few people. We are only creating a new dashboard for X, this is cost reduction project, etc. I don't know how Yahoo is organized but if teams works in silos, without any visibility on other teams, it is probably not that hard to introduced changes that are undetected.
Access to critical data should be similarly protected.
These are relatively tame intrusion detection systems that you would have to make changes to in order to remain undetected. That should be really hard to hide.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#243Earlier quoted context omitted.
Save it for the MBAs instead, or even as an onboarding requirement along with other training for new management hires. It's not generally the engineers making these decisions. Sometimes it's an active issue and at the end of the day someone must implement something terrible (knowingly or not -- direct a junior engineer to do some complex task with the expectation they'll leave behind security vulnerabilities, just as…
SCU (my alma mater) does require MBA students to pass an ethics course. https://www.scu.edu/business/mba-degrees/prospective-student...
Then again, it's not particularly surprising that a Jesuit institution would be strong on ethics. More institutions should take their lead, though.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#244Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#245I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#246Earlier quoted context omitted.
> US intelligence activities are actively harmful to American commercial interests because they destroy trust, particularly from customers elsewhere in the world. We already stand as the most powerful country on earth. It's a great testament to ineptitude in government that this is the current reality.
Yes. And dangerous in the long term because the US wont be the most powerfull country forever. High trees catch a lot of wind. People are more likely to hate the US. When the tides change and the power inbalance goes away the hate and mistrust will still be there. But maybe society is wiser this time around.
I honestly find this hard to believe because:
- When there is conflict in the world, countries always come to the US first for military intervention
- When there is a serious disaster of some kind, countries always expect us to send billions in aid (both militarily and financially) to help them
- When a country is trying to obtain nuclear weapons or weapons of mass destruction, they come to us to stop them
Essentially it comes down to everybody comes to the US first for everything. When that starts to change, maybe I would entertain the fact that we won't be the most powerful country. When so many countries and millions of people rely on us for so many things, our position as being a global leader won't change in the near future.
And quite honestly, I know there's large chunks of our population that would welcome some other countries stepping up and taking the lead instead of the US. It would certainly save us thousands of military personnel that have been lost over our involvement in questionable conflicts in the Middle East.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#247I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#248Earlier quoted context omitted.
> Create a climate of "snitches get stitches" and maybe they will think twice before selling out the lives of a billion people. Committing crimes against people who defect is obviously not going to work. They'll just arrest you for it. But suppose we create a certification. To get certified all you have to do is promise not to work on a specific list of things: Mass surveillance, backdoors, etc. To lose certification…
> To lose certification forever all you have to do is work on one of those things and get caught . There, fixed that for you. That small detail is why your attractive idea wouldn't work in real life. How many years it took for the car industry scandal about tampering with emission tests to be revealed? And it only got to ruin the the reputations of the few engineers involved in the forgery.
The same goes for theft and graft and murder. You don't get punished if you don't get caught. But you could get caught, and you don't know ahead of time whether you will or not.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#249Earlier quoted context omitted.
This is why we (as a community/industry) need to have the equivalent of a prison/death threat. The government wins by making it personal, by threatening prison and death for your obedience. It's not an abstract threat. It is directed to a specific person not a company or security team. The people who comply can quit those companies but they don't. I'm not referring to the ones down the chain (e.g the security team wh…
> Create a climate of "snitches get stitches" and maybe they will think twice before selling out the lives of a billion people. Committing crimes against people who defect is obviously not going to work. They'll just arrest you for it. But suppose we create a certification. To get certified all you have to do is promise not to work on a specific list of things: Mass surveillance, backdoors, etc. To lose certification…
I fear you may be making a potentially dangerous assumption about how engineering works in a compartmentalized environment. Engineers do not always know the purpose of the systems on which they work.
Once upon a time in Texas I spent several years working on a system to run a binary sample through a series of plugins that produced analysis of the binary sample. I was told that this was to help detect malware - and it could certainly do that.
Did I know that for certain? No. Were there other possible uses, such as to determine how detectable a given piece of experimental malware was? Yes. Did I have any way, shape, form, manner, or means of finding out what 100% of uses were? No.
A lot of software has more than one possible use.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#250Earlier quoted context omitted.
PRISM (Yahoo joined 2nd in 2008 after Microsoft in 2007) would basically defeat the purpose of doing this without permission... Did Yahoo Mail even use HTTPS? In that case a FISA warrant would just be an extra level of assurance that they got everything from that person's inbox (plus inboxes of 3 hops of everyone they ever emailed). Otherwise they were just an XKeyscore query, probably filtered by US geodata, away fr…
Your understanding of PRISM is entirely wrong. It processes emails these companies send to the FBI for specific accounts that the government has a court order for, not all the emails that these companies handle.
Otherwise they would collect any email ever sent unencrypted via submarine fiber wiretaps. While feeds into XKeyscore.