Live data from Hacker News

How Microsoft handed the NSA access to encrypted messages

guardian.co.uk

91–100 of 164 posts

Re: How Microsoft handed the NSA access to encrypted messages

#91
post #43

Earlier quoted context omitted.

Do you think the government would jail someone of Steve Ballmer's stature if he talked openly about what the government has asked of Microsoft. Absolutely, but even if they didn't, if you were Steve Ballmer, would you take that risk? They certainly could prosecute you for leaking secret information. That's even assuming that Ballmer knew about it. It could have been that they approached people who were in some positi…

> if you're served a lawful court order ... you challenge it, pulling out from campaign contributions, and making noise in the press. Microsoft (and Google, and Yahoo, and and and) have billions of dollars they could use to resist pretty much any law they wanted to. Every day we complain that modern democracies are captive to moneyed commercial interests, and now we should believe that actually, they're completely po…

Except that you can't make noise in the press because doing so could get you arrested for leaking classified information. You can't ignore it, either, because that could also get you arrested. So what do you do? You follow it, probably.

Granted, Microsoft et. al could attempt to lobby politicians to get these sorts of laws reversed, but that's not the position I was arguing against. Specifically, the GP said, "Do you think the government would jail someone of Steve Ballmer's stature if he talked openly about what the government has asked of Microsoft." That's an argument that Ballmer clearly could've talked about these programs because they wouldn't arrest him, but that assumes two things: a) Ballmer knew about this, and b) Ballmer was willing to take the risk that he wouldn't go to prison if he talking about that. Neither of those are a given.

Talking about lobbying is attacking an argument I didn't make, but I'll address it anyway.

From the standpoint of the big companies, lobbying only makes sense before the law is passed if you have no interest in following it. Alternatively, you follow it while lobbying to get it changed. You now have companies attempting to get the government to allow them to talk more openly about what they do with regards to PRISM and so forth. To put it in perspective, if SOPA had've passed, do you think Google et. al would've just ignored it?

Re: How Microsoft handed the NSA access to encrypted messages

#92

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

CALEA does NOT require Microsoft to provide decryptable communications services; in fact it ensures Microsoft can do exactly the opposite.

http://paranoia.dubfire.net/2010/09/calea-and-encryption.htm...

Re: How Microsoft handed the NSA access to encrypted messages

#94
A perfect lesson on how to write "denials" that are accurate but aren't what most of the public can understand:

http://blogs.skype.com/2012/07/26/what-does-skypes-architect...

"It has been suggested that as a result of recent architecture changes Skype now monitors and records audio and video calls of our users.

False.

The move to in-house hosting of “supernodes” does not provide for monitoring or recording of calls. .."

There are more paragraphs that follow, but they can honestly say they didn't lie, since obviously they had the functionality to monitor and record the calls even before they introduced the supernodes so it is false that they introduced the supernodes for that, but it is not false that the Skype conversations can and are monitored by authorities.

Note that it's by law the job of FBI to do such monitoring, when it's about US citizens, and it's NSA's job for non-US citizens. Microsoft is definitely not breaking any laws. So when they say that it's all lawful what they do it's also true.

Re: How Microsoft handed the NSA access to encrypted messages

#95
post #89

Earlier quoted context omitted.

In Microsoft defense, consequences could include threatening government contracts...

that's not defense, that's corruption.

It's leverage.

(In the US, corruption is hidden by punishing whistleblowers.)

Re: How Microsoft handed the NSA access to encrypted messages

#96
post #52
post #49

Earlier quoted context omitted.

I think the confirmation that NSA and FBI have direct and unfettered access to all communication streams, is pretty huge. As you say, all calm-down-dear interpretations are now proven false. We are facing the worst possible scenario.

If you haven't seen the Binney video made in 2012 by the same author that made the Snowden video, first note the date the video was published, then watch it. Then try to identify the claims already public to those that watched the video then which most of us first became aware of just now by following the story about Snowden. http://www.nytimes.com/2012/08/23/opinion/the-national-secur... For me it starts around 3:20…

For me it starts around 3:20. A lot of it was presented before Snowden but almost nobody noticed.

The "nobody noticed" part is key -- documents carry more weight than statements made by whistleblowers. Whistleblowers can be discredited in the public eye more easily than documents.

Re: How Microsoft handed the NSA access to encrypted messages

#97
I'm sure the NSA can hardly wait for XBone's to start showing up in people's houses. "The telescreen recieved and transmitted simultaneously. Any sound Winston made, above the level of a very low whisper, would be picked up by it; moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard. There was of course no way of knowing whether you were being watched at any given moment. How often, or on what system, the Thought Police plugged in on any individual wire was guesswork. It was even conceivable that they watched everybody all the time. But at any rate they could plug in your wire whenever the wanted to. You had to live- did live, from habit that became instinct- in the assumption that every sound you made was overheard, and, except in darkness, every movement scrutinized." -1984, Book 1, Chapter One, George Orwell

Re: How Microsoft handed the NSA access to encrypted messages

#98
post #50

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

You asked: "Are major companies based or operating in the US allowed to provide secure email and/or data storage without options for lawful surveillance from law enforcement?" Compare 47 USC §1002(b)(3): A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by th…

Microsoft is not a telecom carrier.

Re: How Microsoft handed the NSA access to encrypted messages

#99
post #2

Microsoft's June 7th statement: "We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don’t participate in it." One down, several to go. If I were Google/Fac…

What's sad that I'm neither surprised nor shocked about Microsoft doing this. If we hear the same about Facebook or Apple I'm not likely to be surprised either. If/when we hear the level of Google's involvement, that will be very interesting, because although a lot of people suspect that Google invades people's privacy, we've never really had any concrete proof or examples of it.
Post reply on HN