Live data from Hacker News

How Microsoft handed the NSA access to encrypted messages

guardian.co.uk

31–40 of 164 posts

Re: How Microsoft handed the NSA access to encrypted messages

#31

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

I agree that the anger should be directed at the laws, but the problem is that we are so woefully uninformed about those laws. And not just that we're not paying enough attention - these laws are being formed and executed in secret! How can you take action against something you don't know exists?

> And not just that we're not paying enough attention - these laws are being formed and executed in secret! How can you take action against something you don't know exists?

You start by demanding that this process, this subversion of democracy, be made illegal.

This is the root of the problem: secrecy. Secrecy corrupts as much as power, and absolute secrecy corrupts absolutely.

Re: How Microsoft handed the NSA access to encrypted messages

#33
post #22
post #4

Marketing: "Your privacy is our priority." Meaning: "Microsoft and the FBI had come up with a solution that allowed the NSA to circumvent encryption on Outlook.com chats" "For Prism collection against Hotmail, Live, and Outlook.com emails will be unaffected because Prism collects this data prior to encryption." "analysts will no longer have to make a special request to SSO", "this new capability will result in a much…

Well, did you expect "privacy" to imply that your data would not be released to the government following legal requests for it? I always assumed it meant that they wouldn't share it with other businesses, but maybe that's just me. Analogously, if one of the major phone providers started selling information to marketers, including what times of day I made phone calls, would it be inappropriate for a competitor to crea…

I didn't think it meant they would give the NSA an un-encrypted firehose of private user data violating unlawful search and seizure implications that are a constitutionally protected right of American citizens, but maybe that's just me.

Re: How Microsoft handed the NSA access to encrypted messages

#34

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

I agree that the anger should be directed at the laws, but the problem is that we are so woefully uninformed about those laws. And not just that we're not paying enough attention - these laws are being formed and executed in secret! How can you take action against something you don't know exists?

Secret laws are the death of democracy; not just that, they are the death of the Rule of Law itself. The whole point of having written laws was that everybody could know and challenge them in a fair way, without being reliant on the whim of rulers.

"Secret laws" are not laws, they are tyrannical pseudo-rules that belong in the Middle Ages.

Re: How Microsoft handed the NSA access to encrypted messages

#36

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? Do you think the government would jail someone of Steve Ballmer's stature if he talked openly about what the government has asked of Microsoft. Because of his position he is much more protected from criminal actio…

Do you think the government would jail someone of Steve Ballmer's stature if he talked openly about what the government has asked of Microsoft.

Absolutely, but even if they didn't, if you were Steve Ballmer, would you take that risk? They certainly could prosecute you for leaking secret information.

That's even assuming that Ballmer knew about it. It could have been that they approached people who were in some position of power on the particular products they were interested in and served them with the order. Some random middle manager at Microsoft certainly has considerably less political pull than Ballmer and would likely go to jail if he/she came out about this, but could still be in the position to direct their team to build whatever features the government demanded.

I see the law as allowing them to cooperate. It gives them cover for not protecting the privacy of individual citizens.

If it came via a court order, it's definitely a demand. This isn't a marketing gimmick -- if you're served a lawful court order, you either obey it or risk the consequences, up to and including time in jail.

Re: How Microsoft handed the NSA access to encrypted messages

#37

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

> Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US?

Replace "in the US" with "in Nazi Germany" or "in Soviet Russia" and you'll see how chilling that sentence is. They're just following orders. It's the utter banality of evil.

Re: How Microsoft handed the NSA access to encrypted messages

#38
"ACLU technology expert Chris Soghoian said the revelations would surprise many Skype users. "In the past, Skype made affirmative promises to users about their inability to perform wiretaps," he said. "It's hard to square Microsoft's secret collaboration with the NSA with its high-profile efforts to compete on privacy with Google."

I have a feeling the FTC won't go after them for violating truth-in-advertising laws.

Re: How Microsoft handed the NSA access to encrypted messages

#39

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

they're can't be trusted, that's all that matters, how about us that that live outside? MSFT isn't putting a notice on it's homepage for people outside that it can't do anything about our rights, they sell the exact opposite image, and the internet is sold to everyone as a humankind treasure... if they can't do anything about it they could at least be honest, but they all just keep doubling down on the lies

Re: How Microsoft handed the NSA access to encrypted messages

#40
post #3

I don't get Microsoft. Are they really that hypocritical to the core and so shameless? Why in the world would they launch a "privacy" campaign against Google when they're in a glass house themselves, and so vulnerable? Why the hell would they even put themselves on the spotlight like that? Or are they really that comfortable with lying, that they have no problem attacking others over something, even though they are j…

The people making these campaigns may actually be ignorant. When I was at Microsoft (long, long ago), there were portions of some source trees that were covered by security or NDAs and nobody except for the very few people signed on (and builders) could look at or know about them. For example, when Intel had a new chip, the specific developers and testers working on them would be under NDA and the tree secured so that only they could see the work on the code generators until they were released. And that's just for NDAs - I can't imagine what happens for the code or infrastructure support required for the NSA. The only reason I knew about the chip stuff is I owned the source trees in DevDiv for a while.

So, it's entirely possible that the _entire_ Skype team except for a dev, tester, "security coordinator," and one partner-level person were in the dark about this support and actually believed their marketing.

It's still a terrible situation, but it's not necessarily hypocracy/lying/nasty on the part of the people making up the campaigns.

Post reply on HN