Live data from Hacker News

U.S. National Security Agencies Said to Swap Data With Thousands of Firms

bloomberg.com

21–30 of 78 posts

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#21
post #12
post #9

Earlier quoted context omitted.

Or, they have a MAPP[1] subscription. You too could have information about bugs in Microsoft software before the fix has been released, if you could become a MAPP partner or subscriber. 1. http://www.microsoft.com/security/msrc/collaboration/mapp.as...

If you're in the MAPP program, you promise (on application, and presumably contractually upon membership as well), to: Do you agree to publish monthly protections derived from MAPP information only after Microsoft’s public security update release? I'm doubting the NSA / military hackers make, or honor, any such agreement.

The NSA is not known to publish things.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#22
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

Further evidence that "responsible disclosure" is not responsible.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#23
I tried to submit this hours ago but nobody upvoted:

https://en.wikipedia.org/wiki/Main_Core

"As of 2008 there were reportedly eight million Americans listed in the database as possible threats, often for trivial reasons, whom the government may choose to track, question, or detain in a time of crisis."

We are more than half way in the road to serfdom and tyranny.

EDIT: Resubmitted now as "http" - https://news.ycombinator.com/item?id=5878571

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#24
`Committing officer`? wtf is this? Subpoena these guys. They have immunity, so why not make them talk?

  If necessary, a company executive, known as a “committing officer,” is given 
  documents that guarantee immunity from civil actions resulting from the 
  transfer of data. The companies are provided with regular updates, which may 
  include the broad parameters of how that information is used.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#25
post #15
post #5

Earlier quoted context omitted.

Well, I don't think this is as bad as you make it out to be. This is fairly standard practice for firms, releasing the knowledge of security holes to customers, especially if a patch isn't prepared. See the entire Heroku/Postgres for another, less insidious example.

the information is not released publicly. You need to be their partner.

  provides intelligence agencies with information about bugs in its popular software before it *publicly* releases a fix
emphasis mine.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#26
post #23

I tried to submit this hours ago but nobody upvoted: https://en.wikipedia.org/wiki/Main_Core "As of 2008 there were reportedly eight million Americans listed in the database as possible threats, often for trivial reasons, whom the government may choose to track, question, or detain in a time of crisis." We are more than half way in the road to serfdom and tyranny. EDIT: Resubmitted now as "http" - https://news.ycombi…

2.5% of the entire US population. Jesus christ...

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#27
post #20
post #12

Earlier quoted context omitted.

If you're in the MAPP program, you promise (on application, and presumably contractually upon membership as well), to: Do you agree to publish monthly protections derived from MAPP information only after Microsoft’s public security update release? I'm doubting the NSA / military hackers make, or honor, any such agreement.

This is very different from your original (hysterical, sensational) claim that MSFT is giving the government "zero days" to "hack people with".

not really

what does msft think they're doing with them?

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#28
How much of a role did the requirement for complete secrecy play in this scenario? Secrecy mean the recipients of such orders were isolated, thinking they were by themselves in this. Such a person will be much less likely to disobey orders.

Now that the dam has sprung a leak, and the full extent is becoming evident, people will begin to realise that they are not alone, and it is safe to talk. There is safety in numbers. One gets the feeling that the whole scheme is unravelling, and this is the trickle before the dam bursts.

I'm looking forward to it.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#29
post #23

I tried to submit this hours ago but nobody upvoted: https://en.wikipedia.org/wiki/Main_Core "As of 2008 there were reportedly eight million Americans listed in the database as possible threats, often for trivial reasons, whom the government may choose to track, question, or detain in a time of crisis." We are more than half way in the road to serfdom and tyranny. EDIT: Resubmitted now as "http" - https://news.ycombi…

We are more than half way in the road to serfdom and tyranny.

This is a good time to re-read Book 8 of the Republic (Socrates by way of Plato). The current political situation of the world is being decribed as if they were teleported 2000+ years, then went back to write what they saw.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#30
post #23

I tried to submit this hours ago but nobody upvoted: https://en.wikipedia.org/wiki/Main_Core "As of 2008 there were reportedly eight million Americans listed in the database as possible threats, often for trivial reasons, whom the government may choose to track, question, or detain in a time of crisis." We are more than half way in the road to serfdom and tyranny. EDIT: Resubmitted now as "http" - https://news.ycombi…

Recently a friend was writing a screenplay for a nuclear terrorism thriller. To help him out, I did a lot of research on nuclear weapons manufacture. Lots of googling, reading particular research papers and so on.

I joked that he'd better appreciate the lists I was willing to put myself on for him, but maybe it wasn't that much of a joke.

Post reply on HN