Live data from Hacker News

Spy agency ducks questions about 'back doors' in tech products

reuters.com

1–10 of 272 posts

Re: Spy agency ducks questions about 'back doors' in tech products

#5
"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices."

So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore.

And yes, it has hurt US industry reputation. Many don't trust Intel processors and Cisco routers anymore (among other products). They actually destroyed computers and internet as we knew them in the 1990'ies. It is not fun anymore to own a computer or a phone if you know that NSA can get access to it anytime they want... and you will never know if they accessed it...

Re: Spy agency ducks questions about 'back doors' in tech products

#6
post #3

I can’t tell from this - is Wyden also against back doors for the purpose of FBI/law enforcement use?

Quote from Wyden in the article

>Secret encryption back doors are a threat to national security and the safety of our families – it’s only a matter of time before foreign hackers or criminals exploit them in ways that undermine American national security

Re: Spy agency ducks questions about 'back doors' in tech products

#7
post #3

I can’t tell from this - is Wyden also against back doors for the purpose of FBI/law enforcement use?

He was the one who got James Clapper to lie and state to Congress that he was "not wittingly" collecting American phone records in bulk. Though I do not believe he has ever come out and explicitly stated his views on the matter, his actions do suggest that he is against backdoors in all circumstances.

EDIT: Another reply has provided a quote that shows Wyden's views on backdoors. He appears pretty strongly against them.

Re: Spy agency ducks questions about 'back doors' in tech products

#9
>Three former senior intelligence agency figures told Reuters that the NSA now requires that before a back door is sought, the agency must weigh the potential fallout and arrange for some kind of warning if the back door gets discovered and manipulated by adversaries.

Meaning that before, they were free to plant as many back doors as they pleased without any concern for the consequences. And even now, they just need to think about it a bit and warn somebody, no idea who they tell, if they notice it being used.

>NSA now asserts that it cannot locate this document

This is fairly clear proof of either corruption or complete incompetence.

Re: Spy agency ducks questions about 'back doors' in tech products

#10

Is anyone actually surprised of a "we can neither confirm nor deny" type of answer coming from intelligence agencies?

Yes. After the Snowden leaks and Shadowbrokers/Vault7/WannaCry disasters, the agencies put a lot of effort into reassuring the public that US technology was trustworthy. This included things like making public the Vulnerabilities Equities Process [1], and other work to restore trust in cryptographic standards agencies like NIST [2]. It also included more public engagement with industry to report serious vulnerabilities [3].

The intelligence community didn't open up like this because they wanted to be nice. They did it because there was a very real concern that US industry would be damaged in the eyes of global consumers -- primarily as a result of our intelligence agencies being being too aggressive and, frankly, being sloppy. (It's bad enough to pay for and hoard backdoors, it's another thing entirely when those backdoors are repeatedly stolen and leaked for bad actors to use.)

I guess the news here is that the NSA didn't learn very much from these episodes, or at least, it no longer feels like it needs to repair the damage.

[1] https://en.wikipedia.org/wiki/Vulnerabilities_Equities_Proce... [2] https://www.nist.gov/system/files/documents/2017/05/09/VCAT-... [3] https://www.thesslstore.com/blog/nsa-microsoft-releases-patc...

Post reply on HN