Live data from Hacker News

U.S. National Security Agencies Said to Swap Data With Thousands of Firms

bloomberg.com

11–20 of 78 posts

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#12
post #9
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

Or, they have a MAPP[1] subscription. You too could have information about bugs in Microsoft software before the fix has been released, if you could become a MAPP partner or subscriber. 1. http://www.microsoft.com/security/msrc/collaboration/mapp.as...

If you're in the MAPP program, you promise (on application, and presumably contractually upon membership as well), to:

   Do you agree to publish monthly protections derived from MAPP information 
   only after Microsoft’s public security update release?
I'm doubting the NSA / military hackers make, or honor, any such agreement.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#13
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

governments of every other country should shit in their pants after reading this. Stop using MSFT os at this very moment.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#14
post #13
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

governments of every other country should shit in their pants after reading this. Stop using MSFT os at this very moment.

I can't believe there's a government anywhere in the world surprised by this news.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#15
post #5
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

Well, I don't think this is as bad as you make it out to be. This is fairly standard practice for firms, releasing the knowledge of security holes to customers, especially if a patch isn't prepared. See the entire Heroku/Postgres for another, less insidious example.

the information is not released publicly. You need to be their partner.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#16
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

Every foreign government and overseas company handling potentially sensitive information should immediately sue Microsoft, in U.S. and foreign courts, for damages.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#17
-= YOU =- Hi, my name is __________ . I would like a [loan, voter registration, health care check up, et al]

-= THEM =- Ok, ________ . Did you live @ ___________ in _ _ _ _ ? Did you ever have an account at ________ ?

Where do you think they get the info. Connect the dots.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#18
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

Microsoft are running a "Your privacy is our priority" ad campaign at the moment in the UK (Started before the PRISM story broke)

http://www.microsoft.com/en-gb/security/online-privacy/overv...

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#19
post #17

-= YOU =- Hi, my name is __________ . I would like a [loan, voter registration, health care check up, et al] -= THEM =- Ok, ________ . Did you live @ ___________ in _ _ _ _ ? Did you ever have an account at ________ ? Where do you think they get the info. Connect the dots.

that info comes from credit reporting agencies (trans union, experian, equifax)

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#20
post #12
post #9

Earlier quoted context omitted.

Or, they have a MAPP[1] subscription. You too could have information about bugs in Microsoft software before the fix has been released, if you could become a MAPP partner or subscriber. 1. http://www.microsoft.com/security/msrc/collaboration/mapp.as...

If you're in the MAPP program, you promise (on application, and presumably contractually upon membership as well), to: Do you agree to publish monthly protections derived from MAPP information only after Microsoft’s public security update release? I'm doubting the NSA / military hackers make, or honor, any such agreement.

This is very different from your original (hysterical, sensational) claim that MSFT is giving the government "zero days" to "hack people with".
Post reply on HN