Live data from Hacker News

Microsoft helped the NSA bypass encryption, new Snowden leak reveals

rt.com

51–60 of 118 posts

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#51
post #29
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

Easy workaround would be to put it on a power strip or similar, and just switch it hard off whenever you're not using it. No amount of cleverness is going to make it able to spy on you without electricity (assuming any battery would be rapidly spotted by teardowns). As a bonus, you'll save a little electricity too. Not that we should have to do this....

In addition to that, you can purchase smart power strips that detect the drop/increase in power on one plug and turn off/on the other plugs.

I've been using one of these for several years now for our entertainment center. You just have to be sure you turn off any devices you don't want the power hard cut from before you turn off the television.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#52
post #30

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…

    3) If attacker has physical access to machine, and
       machine is powered on (direct memory access via
       Thunderbolt or Firewire)
This may have changed, but turning on FileVault used to disable DMA in many situations (laptop had been suspended being a key one) until the user logged back in. Not that this isn't a vector, but it's actually a very narrow one; you basically need the person to already be logged in at the time you want to steal the keys.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#53
post #18

Then I start thinking about when Microsoft were being dragged through the competition and monopolies commission in the US, was this the US Government showing Microsoft what would happen if they didn't cooperate.

A half-serious conspiracy theory: The feds "encouraged" Microsoft to acquire Skype so as to obtain decrypted access to the communications.

It happened before MS acquired them.

http://www.networkworld.com/community/blog/project-chess-hel...

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#54
Sorry this is news folks? Really? See this from 2011/12

from http://www.infolaw.co.uk/newsletter/2012/01/microsoft-office...

However, the Patriot Act, introduced to protect US national security, can require that any US company (wherever data is held) must disclose data on demand to the US Government without the knowledge of the owner of the data, which is contrary to the UK Data Protection Act. Microsoft has been up-front in acknowledging that they cannot give that guarantee and this applies to data held in all their hosted solutions. As a result, in December 2011, BAE ditched plans to adopt Office365 because Microsoft could not guarantee the company’s data would not leave Europe, in spite of operating a data centre in Dublin.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#55

going to try for devil's advocate angle. could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption? it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head…

It is important for me as a customer of Microsoft. This means I will end all future contracts with them, because I'm not a US citizen.

NSA needs no warrant to wiretap me as a European and I'm not going to send my money to Microsoft so they can use that money to help a foreign government agency , that I or any of my fellow citizens have no oversight over, to spy on me.

That would be totally absurd.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#56

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

The best part is when OS X asks you if you want to store the encryption 'recovery key' on Apple's servers ...

This is fine, since you have the option to decide. For most people it's okay to store the key on Apples servers. You are still protected if your computer is lost/stolen, for example.

And if you want to be safe from the government, just select "No".

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#57
post #29

Earlier quoted context omitted.

Easy workaround would be to put it on a power strip or similar, and just switch it hard off whenever you're not using it. No amount of cleverness is going to make it able to spy on you without electricity (assuming any battery would be rapidly spotted by teardowns). As a bonus, you'll save a little electricity too. Not that we should have to do this....

In addition to that, you can purchase smart power strips that detect the drop/increase in power on one plug and turn off/on the other plugs. I've been using one of these for several years now for our entertainment center. You just have to be sure you turn off any devices you don't want the power hard cut from before you turn off the television.

I wonder if there's a market for a power strip of this type that also presents a standard serial/USB UPS interface to the hardware, giving it a grace period to shutdown before the hard kill.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#58
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

It's almost as if the device was designed with surveillance in mind.

Someone definitely had the telescreen in mind over there. Scary.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#59
post #45
post #30

Earlier quoted context omitted.

Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…

> 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) I'm curious if this could be addressed with software protections somehow? Something that triggers memory wipes and automatic shutdowns?

http://www.intel.com/content/www/us/en/architecture-and-tech...

Though that specifically obviously requires hardware.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#60
post #3
post #2

The sad thing about all of this is that Microsoft were pretty much forced into this position (so we're told) by the authorities. In the process these leaks have just destroyed pretty much any credibility Microsoft's online services had, which form large parts of their strategy (according to the recent Ballmer memo). It also makes you wonder about the OS and other software they produce, which isn't a good place for MS…

On what legal grounds was Microsoft "forced" to provide access to unencrypted data before encryption (effectively nullifying the security that they promised to their customers)? So how were they forced? Legally? Illegally/blackmail? CALEA seems to say that companies don't have to decrypt data for authorities. I guess it's very convenient that they give it to them before they encrypt it then: http://paranoia.dubfire.n…

>So how were they forced?

Well, we can't really know (they won't answer FOIA requests!). We can only make guesses.

Could be they were just asked. Western Union gave telegrams to the NSA just for the asking.

Some people would argue that Microsoft has enjoyed favorable treatment by the courts. Maybe there was a quid pro quo somewhere along the way.

NSA has strategically placed employees/agents in other companies. Why not Microsoft?

Post reply on HN