Live data from Hacker News

How Microsoft handed the NSA access to encrypted messages

guardian.co.uk

101–110 of 164 posts

Re: How Microsoft handed the NSA access to encrypted messages

#101
>In a joint statement, Shawn Turner, spokesman for the director of National Intelligence, and Judith Emmel, spokeswoman for the NSA, said:

>The articles describe court-ordered surveillance – and a US company's efforts to comply with these legally mandated requirements. The US operates its programs under a strict oversight regime, with careful monitoring by the courts, Congress and the Director of National Intelligence. Not all countries have equivalent oversight requirements to protect civil liberties and privacy.

>They added: "In practice, US companies put energy, focus and commitment into consistently protecting the privacy of their customers around the world, while meeting their obligations under the laws of the US and other countries in which they operate."

Does anyone else get the impression that this is an attempt by the government to limit commercial damage to these companies that may result from the revelations and subsequent exodus of customers? I imagine that, while they're certainly lobbying for increased transparency, tech companies are putting a great deal of pressure on the government to take the blame for the programs and emphasize that the companies had no choice.

Re: How Microsoft handed the NSA access to encrypted messages

#102
post #43

Earlier quoted context omitted.

> if you're served a lawful court order ... you challenge it, pulling out from campaign contributions, and making noise in the press. Microsoft (and Google, and Yahoo, and and and) have billions of dollars they could use to resist pretty much any law they wanted to. Every day we complain that modern democracies are captive to moneyed commercial interests, and now we should believe that actually, they're completely po…

Except that you can't make noise in the press because doing so could get you arrested for leaking classified information. You can't ignore it, either, because that could also get you arrested. So what do you do? You follow it, probably. Granted, Microsoft et. al could attempt to lobby politicians to get these sorts of laws reversed, but that's not the position I was arguing against. Specifically, the GP said, "Do you…

Except that you can't make noise in the press because doing so could get you arrested for leaking classified information. You can't ignore it, either, because that could also get you arrested. So what do you do? You follow it, probably.

The standard some have applied to Snowden should also apply to corporate executives: companies should oppose the orders publicly, and "face the music." Ballmer might be arrested, or his family harassed, but he would go from dancing developer monkey to public hero overnight.

Re: How Microsoft handed the NSA access to encrypted messages

#103
post #92

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

CALEA does NOT require Microsoft to provide decryptable communications services; in fact it ensures Microsoft can do exactly the opposite. http://paranoia.dubfire.net/2010/09/calea-and-encryption.htm...

A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication.

Note "unless the encryption was provided by the carrier." Skype is the one that provides encryption here (a carrier) as far as I understand. No user can influence it. You are right that they are allowed to make the systems where users would provide keys themselves and that then the carrier wouldn't be required to assist in the decryption.

Re: How Microsoft handed the NSA access to encrypted messages

#104
post #4

Marketing: "Your privacy is our priority." Meaning: "Microsoft and the FBI had come up with a solution that allowed the NSA to circumvent encryption on Outlook.com chats" "For Prism collection against Hotmail, Live, and Outlook.com emails will be unaffected because Prism collects this data prior to encryption." "analysts will no longer have to make a special request to SSO", "this new capability will result in a much…

I think the best part is that Microsoft has been bragging about how they care about privacy so much more than Google therefore you should use their products/services, and now they just got caught red handed doing the worst possible privacy violations in the book.

Re: How Microsoft handed the NSA access to encrypted messages

#105
post #87

Earlier quoted context omitted.

The interesting conflict to me is that Google et al don't appear to be fighting this battle. When it comes to other things, they are in the streets, funding lobbyists, building protest websites, and so on. But this, which threatens their entire business model (essentially trust-based), they haven't made a peep about. It may just be a gag order thing, sure. But with the level of access required for stuff like this, I…

http://www.newyorker.com/online/blogs/johncassidy/2013/06/go... "Google Lawsuit Challenges N.S.A. Domestic-Spying Apparatus" the first hit on google for "google nsa lawsuit"

> the first hit on google for "google nsa lawsuit"

[emphasis mine]

...and for you!

[filter bubble anyone?!]

Re: How Microsoft handed the NSA access to encrypted messages

#106
post #50

Earlier quoted context omitted.

You asked: "Are major companies based or operating in the US allowed to provide secure email and/or data storage without options for lawful surveillance from law enforcement?" Compare 47 USC §1002(b)(3): A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by th…

Microsoft is not a telecom carrier.

Actually, it is. Microsoft provides VOIP services, and the FCC and courts have held that that makes it a telecom carrier for the purposes of CALEA.

Re: How Microsoft handed the NSA access to encrypted messages

#107

Earlier quoted context omitted.

Oh, come on. Developers only need to build some APIs - those APIs can be multi-purpose. They don't need to know that one such purpose is NSA spying - you can come up with dozens of other reasons for wanting a "back door". The actual interface that's used for responding to legally binding orders or subpoenas and that uses the APIs in question can be built by people on NSA's payroll. Besides executives, the only people…

Give me 12 (a dozen) reasons to break the encryption and security of your users that could be acceptable to a non brain dead engineer and exclude surveillance and government snooping?

You're missing the fact that if a middleman does the encryption or has access to the decryption key, then encryption is already broken.

A service provider is the middleman in this case and encryption only serves the purpose of you making sure that communications are with this service provider and not with another middleman.

"Breaking the encryption" is not accurate. They don't need to break anything as your data is in plain text on their servers.

Re: How Microsoft handed the NSA access to encrypted messages

#108
post #3

I don't get Microsoft. Are they really that hypocritical to the core and so shameless? Why in the world would they launch a "privacy" campaign against Google when they're in a glass house themselves, and so vulnerable? Why the hell would they even put themselves on the spotlight like that? Or are they really that comfortable with lying, that they have no problem attacking others over something, even though they are j…

I would imagine that very few people in high levels of the company knew about this.

I can't exactly blame them for the marketing campaign... just imagine you work for Microsoft's marketing division... Apple/Google are completely destroying you and your company has missed the boat almost every major technological revolution of the last decade (internet, mobile, etc).

How would you exactly convince people to switch to your companies products? At the time, there was a lot of fear around Google's data collection and what they might do with it, so it's unsurprising this is the route they took (although anyone sensible would assume that Microsoft of all companies would be just as bad if not worse).

Re: How Microsoft handed the NSA access to encrypted messages

#109
I must be in the minority here, but I'm no more concerned now than before reading this, and I'm still not super concerned if it works the way I think it does. It doesn't answer the main question of HOW MANY USERS are being watched like this.

We already knew from Prism that Microsoft is providing data to the NSA, and we already knew that it included real time video, emails, messages, etc. So this is more of a behind-the-scenes of how it's done, but if you stopped to consider before what Prism meant then it sort of implies everything here.

BUT, I still don't know whether this tapping of Skype calls, providing of decrypted messages, etc, applies only to a few specific people who the government has warrants for, or for all of Microsoft's users. I still think it's the former based on that Prism slide that said it cost $10M/yr, which is clearly not enough to handle ALL of Microsoft's and Google's and Apple's data.

If anything, I applaud Prism in that it's just a more efficient way of doing what the NSA is already cleared to do.

I'm MORE concerned about the warrantless Verizon metadata tracking for millions of subscribers, Clapper's lies before Congress about said data, the DoJ classifying the FISC's rulings that something or other is unconstitutional, the inability of companies to discuss NSLs.

But this release is just clarification on what we already knew, and we still don't know whether PRISM is oh-my-god-the-government-is-tapped-into-everything or just a convenient front-end on the government's warrant-obtained data (which is a good thing, AFAICT).

Re: How Microsoft handed the NSA access to encrypted messages

#110
post #87

Earlier quoted context omitted.

The interesting conflict to me is that Google et al don't appear to be fighting this battle. When it comes to other things, they are in the streets, funding lobbyists, building protest websites, and so on. But this, which threatens their entire business model (essentially trust-based), they haven't made a peep about. It may just be a gag order thing, sure. But with the level of access required for stuff like this, I…

http://www.newyorker.com/online/blogs/johncassidy/2013/06/go... "Google Lawsuit Challenges N.S.A. Domestic-Spying Apparatus" the first hit on google for "google nsa lawsuit"

This lawsuit was filed after NSA was found with its hand in the cookie jar. I think devindotcom means, why were these tech companies not fighting this years ago. I guess you cannot fault Eric Schmidt, because he has been dropping lines like these [1] for years.

  We know where you are. We know where you’ve been.
  We can more or less know what you’re thinking about

  Just remember when you post something, the computers
  remember forever
[1] http://www.stateofsearch.com/top-15-of-eric-schmidts-remarka...
Post reply on HN