Live data from Hacker News

Microsoft exec: Targeting of Americans’ records ‘routine’

seattletimes.com

31–40 of 56 posts

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#31

Let me see... Microsoft wants me to have a Microsoft account to use a computer that I bought. They nag me every time I log in because I gave them a bogus email address. And then you read something like this. All those abstract privacy concerns just got a bit more concrete...

And yet when they limit their new version of Windows specifically to devices that cant have rootkits installed, everyone freaks out. ...maybe they know that people are installing root kits... because they see first hand what the "good" guys are doing routinely.

I see exactly zero connection between preventing rootkits and demanding that I give them my email address.

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#32
Is there a law that prevents companies from completely encrypting their data at rest? Data should only be decrypted if the person(s) have the private keys. Government entities can request the information all they want but all they will get is an encrypted dump. You will need to ask the person that owns the private keys to decrypt or just pound sand (there are laws preventing self incrimination, so private keys should fall in the same domain)

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#33

The headline is so non-descript that it makes it sound like the Microsoft executive is shrugging this off, but the testimony says otherwise: > Tom Burt, Microsoft’s corporate vice president for customer security and trust, told members of the House Judiciary Committee that federal law enforcement in recent years has been presenting the company with between 2,400 to 3,500 secrecy orders a year, or about seven to 10 a…

If these are from out of state what is to prevent them from just saying no? I'd imagine there is some interstate process that they have to follow in order to make it valid where Microsoft is headquartered.

[deleted]

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#34

Earlier quoted context omitted.

If these are from out of state what is to prevent them from just saying no? I'd imagine there is some interstate process that they have to follow in order to make it valid where Microsoft is headquartered.

> federal law enforcement

So that means if I sue someone in federal court I can just pick a random state? No, of course not. What makes this any different? There is still federal jurisdiction requirement.

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#35

Earlier quoted context omitted.

What it's time for is a change to the laws so that informing the public about what their public servants have been up to can be accomplished without fleeing the country afterwards.

What's the enforcement mechanism for these laws? Who compels who to do what?

I think that they have ultimate power and they even trump the constitution...

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#36
post #25
post #12

Earlier quoted context omitted.

I wonder why the downvotes? This is absolutely correct. I’d be interested to know how many similar requests Apple and Google get.

The subpoenas are for cloud stored data.

And where do you imagine Microsoft stores all of this telemetry they steal from the user?

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#37

Let me see... Microsoft wants me to have a Microsoft account to use a computer that I bought. They nag me every time I log in because I gave them a bogus email address. And then you read something like this. All those abstract privacy concerns just got a bit more concrete...

And yet when they limit their new version of Windows specifically to devices that cant have rootkits installed, everyone freaks out. ...maybe they know that people are installing root kits... because they see first hand what the "good" guys are doing routinely.

Who said you can't have rootkits on newer processors? Microsoft signed a bunch of rootkits and that was news last week? https://news.ycombinator.com/item?id=27640553

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#38

Earlier quoted context omitted.

> federal law enforcement

So that means if I sue someone in federal court I can just pick a random state? No, of course not. What makes this any different? There is still federal jurisdiction requirement.

https://www.fbi.gov/about/faqs/where-is-the-fbis-authority-w...

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#39
post #32

Is there a law that prevents companies from completely encrypting their data at rest? Data should only be decrypted if the person(s) have the private keys. Government entities can request the information all they want but all they will get is an encrypted dump. You will need to ask the person that owns the private keys to decrypt or just pound sand (there are laws preventing self incrimination, so private keys should…

And forget your password and your data is all gone, never to be seen again.

Re: Microsoft exec: Targeting of Americans’ records ‘routine’

#40

Earlier quoted context omitted.

What it's time for is a change to the laws so that informing the public about what their public servants have been up to can be accomplished without fleeing the country afterwards.

What's the enforcement mechanism for these laws? Who compels who to do what?

They are just normal federal laws:

> The United States does not have a British-style Official Secrets Act; instead, several laws protect classified information, including the Espionage Act of 1917, the Atomic Energy Act of 1954 and the Intelligence Identities Protection Act of 1982.[1]

The ALCU has a bunch of work[2] on this if you want to dig deeper.

[1] https://en.wikipedia.org/wiki/Classified_information_in_the_...

[2] https://www.aclu.org/issues/national-security/secrecy

Post reply on HN