Live data from Hacker News

Microsoft helped the NSA bypass encryption, new Snowden leak reveals

rt.com

21–30 of 118 posts

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#21
post #19
post #11

I find it interesting that no USA-based news source is covering this.

Among US-based news sources covering this: The New York Times, NBC News, New York Daily News, CBS News, NPR, Chicago Tribune, ABC.

Huh.

My apologies, for some reason the only sites google showed on this issue were .co.uk.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#22
post #7
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

Since the Xbox camera is connected to the console via a cable, you can verify whether data going over the wire. If the Xbox is off, you shouldn't see traffic. It's a /bunch/ different from traffic in a data center, which is essentially untraceable and can be cloned at many points. Frankly I'd be more concerned about the microphones contained in ubiquitous and nearly unexaminable devices such as cell phones, and to a…

They wouldn't need to listen all the time, and how would you know when it's the right time to look? And even then most people won't be able to verify.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#23
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

> We are designing the new Kinect with simple, easy methods to customize privacy settings, provide clear notifications and meaningful privacy choices

    Do you want your information to be given to the NSA?
    [ ] Yes
    [X] Yes

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#24
post #5
post #2

The sad thing about all of this is that Microsoft were pretty much forced into this position (so we're told) by the authorities. In the process these leaks have just destroyed pretty much any credibility Microsoft's online services had, which form large parts of their strategy (according to the recent Ballmer memo). It also makes you wonder about the OS and other software they produce, which isn't a good place for MS…

I'm not sure why you're picking on Microsoft. The credibility of pretty much every large US-based tech services company is probably destroyed. The fact that we only saw the big service providers (MS, Google, etc...) on those slides doesn't mean that the other companies are free from the hands of the NSA. Do you think that the NSA has no access to Dropbox?

Enterprise relies on companies such as RedHat and Oracle to some extent in lieu of conducting code analysis and to certain types of security testing.

It would be rather surprising if they were not at least approached by Federal agencies such as NSA and FBI.

To put it another way, because Microsoft has a closed source model, the intelligence agencies took the approach described in the article. From that, it may be a mistake to conclude that the strategy pursued with Microsoft was the only strategy pursued. It just happens to be one that would pass across the desk of an analyst, rather than someone on the operations side.

Viewed as an intelligence operation, it would be grossly unprofessional of such agencies not to have placed moles within the open source community, or for those moles to be seen as highly skilled contributors on open source projects. The three letter agencies have decades of experience infiltrating both commercial organizations and those motivated by something other than money.

I suspect it is easier to turn an open source hacker than a diplomat - not just ideologically but because the open source community lacks a state funded organized counter-intelligence apperatus.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#26
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

> We are designing the new Kinect with simple, easy methods to customize privacy settings, provide clear notifications and meaningful privacy choices Do you want your information to be given to the NSA? [ ] Yes [X] Yes

Answer "Yes" to send information to the NSA or "No" if you have something to hide.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#27
post #21
post #19

Earlier quoted context omitted.

Among US-based news sources covering this: The New York Times, NBC News, New York Daily News, CBS News, NPR, Chicago Tribune, ABC.

Huh. My apologies, for some reason the only sites google showed on this issue were .co.uk.

Are your google account settings localized to the UK? This issue used to regularly drive me crazy.

Fortunately they now have a worldwide setting. At one point you could select only 5 (or was it 7?) languages for which Google would show you results. They fortunately fixed that.

I mean, who would want to search _all_ the internet?

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#28
post #21
post #19

Earlier quoted context omitted.

Among US-based news sources covering this: The New York Times, NBC News, New York Daily News, CBS News, NPR, Chicago Tribune, ABC.

Huh. My apologies, for some reason the only sites google showed on this issue were .co.uk.

Google personalizes results quite extensively these days, largely based on your location. Google believes based on that, and probably your previous searching and browsing habits, that those .co.uk sites are more relevant to your interests. After all, this is the company that has patented and is developing the idea of "Parameterless Searches", where they assume what you want to know before you even ask... (more info http://www.seobythesea.com/2013/07/google-parameterless-sear...)

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#29
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

Easy workaround would be to put it on a power strip or similar, and just switch it hard off whenever you're not using it. No amount of cleverness is going to make it able to spy on you without electricity (assuming any battery would be rapidly spotted by teardowns). As a bonus, you'll save a little electricity too.

Not that we should have to do this....

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#30

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

Not impossible, but some smart people have been looking, at least for Apple's FileVault 2:

http://www.schneier.com/blog/archives/2012/08/an_analysis_of...

Paper here:

http://eprint.iacr.org/2012/374.pdf

Currently, there seem to be three vectors:

1) Weak passwords

2) If you opt-in to store a recovery key with Apple

3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) (Edit: seems like this is not the case, see below)

But no backdoor has been found (yet!)

Post reply on HN