Live data from Hacker News

How Microsoft handed the NSA access to encrypted messages

guardian.co.uk

11–20 of 164 posts

Re: How Microsoft handed the NSA access to encrypted messages

#11
post #6

Allow me to be surprised this time, I don't see much new here, compared to what we already saw about Prism (all the slides). Maybe the only thing newsworthy this time is that additional documents confirm that Prism exist? I applaud this article of course, as it gives less chance for unnatural interpretations of the slides that we saw by pro-status-quo writers ("it's not really a direct access") -- now we have additio…

I haven't read the article yet, but if what I'm gathering from the comments is true, what's new here is that Microsoft has been caught in a lie to the public and their shareholders.

Re: How Microsoft handed the NSA access to encrypted messages

#12
post #6

Allow me to be surprised this time, I don't see much new here, compared to what we already saw about Prism (all the slides). Maybe the only thing newsworthy this time is that additional documents confirm that Prism exist? I applaud this article of course, as it gives less chance for unnatural interpretations of the slides that we saw by pro-status-quo writers ("it's not really a direct access") -- now we have additio…

I haven't read the article yet, but if what I'm gathering from the comments is true, what's new here is that Microsoft has been caught in a lie to the public and their shareholders.

Technically they didn't lie, they said they complied to the court orders. I'd say our real worry should be the secret orders and what they demand, not the companies that obey to them? But what's really true is that companies' "denials" were carefully crafted to give the impression that there isn't any API-level access, even if they didn't claim that, and now we have more confirmations that they give it that way and I'm sure Google isn't different in that aspect.

Also note that the "official client" is FBI, so MS can claim they don't know that NSA accesses the data of US citizens. But that "there will be more interagency sharing and cooperation" was publicly announced by G W Bush soon after 9/11.

Re: How Microsoft handed the NSA access to encrypted messages

#13
post #2

Microsoft's June 7th statement: "We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don’t participate in it." One down, several to go. If I were Google/Fac…

The interesting conflict to me is that Google et al don't appear to be fighting this battle. When it comes to other things, they are in the streets, funding lobbyists, building protest websites, and so on. But this, which threatens their entire business model (essentially trust-based), they haven't made a peep about.

It may just be a gag order thing, sure. But with the level of access required for stuff like this, I don't think they could shut the whole team up. How many people worked on this Microsoft back door? It can't have been less than a couple dozen at least. And none of them raised the issue or let someone know, a journalist for instance, or publicly raised the question?

It makes me wonder about the true extent of the programs we're freaking out about. I mean, of course they exist and they're big and threatening, but I don't buy that they could combine complete access with complete secrecy. They need the cooperation of the companies, and the companies, by NSA standards, just aren't trustworthy enough. In fact, they're full of wild cards like Snowden, denizens of newsgroups, IRC, 4chan, etc, who would LOVE to be the one to blow up an NSA attempt to write a back door into Skype.

Maybe they did, and it all faded away. But it just seems strange to me that so little has been said about the elephant that must surely have been in everyone's room for the last few years.

Re: How Microsoft handed the NSA access to encrypted messages

#14
post #2

Microsoft's June 7th statement: "We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don’t participate in it." One down, several to go. If I were Google/Fac…

This latest release does not contradict that. They provide user data for accounts under surveillance in real time. To place an account under surveillance, the government needs a valid court order for that account.

This document just says that surveillance was broken for chats when they did the outlook.com upgrade, but that has since been fixed.

Re: How Microsoft handed the NSA access to encrypted messages

#15
To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US?

CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea

Are major companies based or operating in the US allowed to provide secure email and/or data storage without options for lawful surveillance from law enforcement?

If people do not like these policies and the cooperation from the companies operating them, I think the proper place to direct your anger is at the laws that require them to cooperate.

Re: How Microsoft handed the NSA access to encrypted messages

#16
post #6

Allow me to be surprised this time, I don't see much new here, compared to what we already saw about Prism (all the slides). Maybe the only thing newsworthy this time is that additional documents confirm that Prism exist? I applaud this article of course, as it gives less chance for unnatural interpretations of the slides that we saw by pro-status-quo writers ("it's not really a direct access") -- now we have additio…

[deleted]

Re: How Microsoft handed the NSA access to encrypted messages

#18

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

In this particular instance? I would have had them be less misleading about what ways Skype is and is not secure in the first place.

Re: How Microsoft handed the NSA access to encrypted messages

#19

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

As a Microsoft contractor, I'm confused about how to feel and how to move forward. Sometimes I feel like I'll be enabling some of these practices by continuing be a contracted worker, and that this community will in part be blaming me for this situation.

Re: How Microsoft handed the NSA access to encrypted messages

#20
Skype, which was bought by Microsoft in October 2011, worked with intelligence agencies last year to allow Prism to collect video of conversations as well as audio

This is pretty scary. When you talk about emails, it's sort of "impersonal". But collecting audio and video data from your casual chats on Skype is a fucking break in.

Post reply on HN