Live data from Hacker News

U.S. National Security Agencies Said to Swap Data With Thousands of Firms

bloomberg.com

71–78 of 78 posts

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#71
post #38

"AT&T, Verizon Before they agreed to install the system on their networks, some of the five major Internet companies -- AT&T Inc. (T), Verizon Communications Inc (VZ)., Sprint Nextel Corp. (S), Level 3 Communications Inc (LVLT). and CenturyLink Inc (CTL). -- asked for guarantees that they wouldn’t be held liable under U.S. wiretap laws. Those companies that asked received a letter signed by the U.S. attorney general…

I don't understand how the executive branch can guaranty immunity from civil action in the judicial branch.

> I don't understand how the executive branch can guaranty immunity from civil action in the judicial branch.

The letters from the AG are protection from criminal action, and probably government civil action, that extend beyond the term of the administration issuing them (wiretap laws have criminal as well as civil provisions, and there are cases where the government can bring civil prosecutions.) For criminal laws, ignorance of the law is not a defense, but reasonable reliance on an interpretation provided by the public authority responsible for enforcing the law usually is a defense. For civil actions, reliance on the representation of the party bringing the action likewise can be a defense.

For civil action by a third party, unless there is a specific provision that makes this a defense for the particular offense at issue (which there may be, but I'm not aware of one), I don't think this would be particularly useful under any generally applicable principal.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#72
post #38

Earlier quoted context omitted.

I don't understand how the executive branch can guaranty immunity from civil action in the judicial branch.

> I don't understand how the executive branch can guaranty immunity from civil action in the judicial branch. The letters from the AG are protection from criminal action, and probably government civil action, that extend beyond the term of the administration issuing them (wiretap laws have criminal as well as civil provisions, and there are cases where the government can bring civil prosecutions.) For criminal laws,…

Thanks for the breakdown.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#73
post #70
post #42

Earlier quoted context omitted.

Playing devil's advocate, keep in mind that domestic computer security is part of the NSA's charter. Remember the rainbow books? It would be completely legitimate for MSFT to warn NSA about vulnerabilities in the most common desktop operating systems in the USA if the warning were intended to aid in preventing a larger attack. It's a write-only bugtraq. :-)

The head of NSA is also the head of the US military's cybercommand and offensive operations are definitely part of their bottom line. This intersection between protecting civilians and attacking our military enemies should absolutely worry you, the worst nightmare of 'responsible disclosure' has just been revealed: security updates aren't being rolled out as a matter of official policy, for the explicit purpose of mi…

Since the head of the NSA is a senior military officer, they are likely to be the most qualified to head the military's computer offense capabilities.

Theoretically, there is presidential and congressional oversight to prevent them from overstepping their bounds. Unfortunately, we've largely squandered the threat of congressional inquiry on blue dresses and cigars.

What I find confusing is that, ultimately, you have to follow the money. How has MSFT been benefiting from a conspiracy to exploit their own software in overseas markets?

They know that embarrassing information will get out eventually. They also have a distant planning horizon regarding continued existence. Whatever they get in return has to have been perceived as worth the loss of any trust and goodwill as a result of the eventual disclosure.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#74
post #43
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

You know what surprisingly I am not that outraged by it. Why? Because I was expecting far worse. Installing backdoor for the govt and purposefully leaving an exploit open.. etc. So the govt get a head start with the vulnerabilities that Microsoft knows? Okay.. I am guessing there are far more undisclosed ones in the black market that they can buy off.

It has been alleged that the WMF vulnerability was deliberate: http://en.wikipedia.org/wiki/Windows_Metafile_vulnerability#...

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#75

Well, there's the smoking gun for the reason behind CISPA. I'm sure tptacek still won't admit he was wrong though.

What is up with tptacek anyway? He seems to vehemently deny any wrongdoing on the government's or tech giant's part.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#76
To me, this is the scariest part though not that surprising:

    "That metadata includes which version of the operating system, browser and
    Java software are being used on millions of devices around the world,
    information that U.S. spy agencies could use to infiltrate those computers
    or phones and spy on their users."
A database that contains the specific versions of installed software for millions of computers world-wide is a very powerful tool. For any given target--if their machine is in the database--compromising their system is a trivial matter! It's a "what exploit would you like to use today?" situation.

Assuming they gather this information from Internet backbones--I'm OK with that. Good for them for skimming data off the public Internet and shame on the software that makes it too easy.

On the other hand, if they're obtaining this data from the likes of Microsoft (or McAfeee or any other incredibly popular vendor with an item in everyone's systray) that is an incredibly scary proposition. No target stands a snowball's chance in hell at not being (trivially) compromised. It's one of those situations where, "you'd better not use that company's products!"

I can't even imagine the sheer destruction that could occur if such information fell into the wrong hands. Imagine if some "fuck the world" anarchist hacker got his hands on a database that contained precisely the information he needed to, say, compromise (and just plain erase; 'rm -rf *') just about every banking computer that happened to be listed. It would be like, ARMAGEDDON.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#77
post #23

I tried to submit this hours ago but nobody upvoted: https://en.wikipedia.org/wiki/Main_Core "As of 2008 there were reportedly eight million Americans listed in the database as possible threats, often for trivial reasons, whom the government may choose to track, question, or detain in a time of crisis." We are more than half way in the road to serfdom and tyranny. EDIT: Resubmitted now as "http" - https://news.ycombi…

We are more than half way in the road to serfdom and tyranny. This is a good time to re-read Book 8 of the Republic (Socrates by way of Plato). The current political situation of the world is being decribed as if they were teleported 2000+ years, then went back to write what they saw.

There's never a bad time to re-read this classic. Here's one link to the entire book:

http://classics.mit.edu/Plato/republic.html

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#78
post #13
post #3

Holy shit. Microsoft Corp. (MSFT), the world’s largest software company, provides intelligence agencies with information about bugs in its popular software before it publicly releases a fix, according to two people familiar with the process. That information can be used to protect government computers and to access the computers of terrorists or military foes. Microsoft gives US military hackers and the NSA zero days…

governments of every other country should shit in their pants after reading this. Stop using MSFT os at this very moment.

I have not seen any statement that MS does not also provide this same info to other governments.
Post reply on HN