Live data from Hacker News

U.S. National Security Agencies Said to Swap Data With Thousands of Firms

bloomberg.com

1–10 of 78 posts

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#3
Holy shit.

   Microsoft Corp. (MSFT), the world’s largest software company, provides 
   intelligence agencies with information about bugs in its popular software 
   before it publicly releases a fix, according to two people familiar with the 
   process. That information can be used to protect government computers and to 
   access the computers of terrorists or military foes.
Microsoft gives US military hackers and the NSA zero days to go hack people with.

I think this helps explain Google's 7-day disclosure. Also, fuck microsoft. Running your mouth and trying to blackball people who don't give you 60 days while (presumably selling) those exploits to governments? Just amazing.

Edit: here [1] is discussion of Tavis Ormandy / Google's new 7 day policy. I really wonder if this was partially driven by eg Microsoft's abhorrent behavior.

[1] http://www.theverge.com/2013/5/30/4379004/google-to-make-cri...

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#4
post #2

This keeps getting worse.

Baffle them with bullshit or dazzle them with details.

I think we are against an effort to tranquilize us with tyranny!

Where we are just overwhelmed with outrageous actions such as to desensitize us to the fact that "well, holy shit, this is so pervasive and so entrenched, what is there to be done? I mean, my life was great for the last three years and this has been going on, at such great lengths, for so many years -- how bad can it be??"

This is a test as to how much we will take. They want action - they want an excuse to really show us what debt slaves we are.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#5
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

Well, I don't think this is as bad as you make it out to be. This is fairly standard practice for firms, releasing the knowledge of security holes to customers, especially if a patch isn't prepared.

See the entire Heroku/Postgres for another, less insidious example.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#6
> While companies are offered powerful inducements to cooperate with U.S. intelligence, many executives are motivated by patriotism or a sense they are defending national security, the people familiar with the trusted partner programs said.

Their fervent patriotism certainly didn't stop them from demanding immunity as a prerequisite.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#7
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

Now we know, I would presume, exactly how Stuxnet and Duqu were born...

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#9
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

Or, they have a MAPP[1] subscription. You too could have information about bugs in Microsoft software before the fix has been released, if you could become a MAPP partner or subscriber.

1. http://www.microsoft.com/security/msrc/collaboration/mapp.as...

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#10

> While companies are offered powerful inducements to cooperate with U.S. intelligence, many executives are motivated by patriotism or a sense they are defending national security, the people familiar with the trusted partner programs said. Their fervent patriotism certainly didn't stop them from demanding immunity as a prerequisite.

Patriotism is a flimsy, BS, defense.
Post reply on HN