Live data from Hacker News

Microsoft helped the NSA bypass encryption, new Snowden leak reveals

rt.com

31–40 of 118 posts

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#31

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

Of course there are back doors, like the well known NSAKEY one [1] in Windows. Apple also seem to have backdoors into encryption on both Mac and iOS [2].

If you want your data to be reasonably secure against someone who casually steals it then they're fine but if you want to be secure against government employees, or even well connected corporations, then Apple & Microsoft solutions are not very useful.

[1] https://en.wikipedia.org/wiki/NSAKEY [2] http://news.cnet.com/8301-13578_3-57583843-38/apple-deluged-...

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#32

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

The best part is when OS X asks you if you want to store the encryption 'recovery key' on Apple's servers ...

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#33

Earlier quoted context omitted.

> We are designing the new Kinect with simple, easy methods to customize privacy settings, provide clear notifications and meaningful privacy choices Do you want your information to be given to the NSA? [ ] Yes [X] Yes

Answer "Yes" to send information to the NSA or "No" if you have something to hide.

*Answering "No" will flag your account for review by the NSA.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#34
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

> We are designing the new Kinect with simple, easy methods to customize privacy settings, provide clear notifications and meaningful privacy choices Do you want your information to be given to the NSA? [ ] Yes [X] Yes

No no. It is like this:

  Do you agree that your information will given to the NSA?
    [ ] Yes, I agree
    [X] No, I don't mind.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#35
post #31

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

Of course there are back doors, like the well known NSAKEY one [1] in Windows. Apple also seem to have backdoors into encryption on both Mac and iOS [2]. If you want your data to be reasonably secure against someone who casually steals it then they're fine but if you want to be secure against government employees, or even well connected corporations, then Apple & Microsoft solutions are not very useful. [1] https://e…

Regarding [2], it's not clear yet what Apple does here: it looks like they bruteforce the iPhones when requested by the relevant authorities (possibly using a custom bootrom) and specifically not via a backdoor. If there was a backdoor, presumably Apple wouldn't have a backlog of requests[3]. Though no one really knows, and presumably it's always possible Apple will intentionally compromise their security in future if they get tired of having to bruteforce all these phones.

[3] http://www.informationweek.com/security/encryption/apple-iph...

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#37
post #3
post #2

The sad thing about all of this is that Microsoft were pretty much forced into this position (so we're told) by the authorities. In the process these leaks have just destroyed pretty much any credibility Microsoft's online services had, which form large parts of their strategy (according to the recent Ballmer memo). It also makes you wonder about the OS and other software they produce, which isn't a good place for MS…

On what legal grounds was Microsoft "forced" to provide access to unencrypted data before encryption (effectively nullifying the security that they promised to their customers)? So how were they forced? Legally? Illegally/blackmail? CALEA seems to say that companies don't have to decrypt data for authorities. I guess it's very convenient that they give it to them before they encrypt it then: http://paranoia.dubfire.n…

A company doesn't have to decrypt to meet their CALEA obligations. If CALEA is the sole legal authority for a particular communications interception, that would be the end of it. However, I've seen nothing that indicates that CALEA is the legal authority behind the NSA interceptions.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#38
I feel so stupid and so ashamed of myself for all the time I have thought of everything Richard Stallman had to say about privacy and security concern as a "neck-beard, tin-foil hat, nutjob".

He was right all along, it was us who didn't care enough to understand what he was saying and its importance.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#39
post #33

Earlier quoted context omitted.

Answer "Yes" to send information to the NSA or "No" if you have something to hide.

*Answering "No" will flag your account for review by the NSA.

The joke is that that's probably not a joke.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#40
going to try for devil's advocate angle.

could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption?

it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head of the NSA at the time – deliberately violated the law to eavesdrop on Americans without a warrant" which hints at a vague conclusion that Microsoft is helping to spy on citizens without a warrant.

possibly i missed something, so is the point that Microsoft (or any private company) should not do any work for NSA, or that it should not do it without a warrant, or that we can't trust it with anything because it did some work for the NSA? Or is that the details are still not disclosed so it's pure speculation?

Post reply on HN