Live data from Hacker News

Microsoft helped the NSA bypass encryption, new Snowden leak reveals

rt.com

61–70 of 118 posts

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#61
post #52
post #30

Earlier quoted context omitted.

Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…

3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) This may have changed, but turning on FileVault used to disable DMA in many situations (laptop had been suspended being a key one) until the user logged back in. Not that this isn't a vector, but it's actually a very narrow one; you basically need the person to already be logged in at the time y…

Hmm, I didn't know that. It seems you may be right:

http://www.frameloss.org/wp-content/uploads/2011/09/Lion-Mem...

Though apparently there was a company offering a commercial solution for getting FileVault passwords using this method so...

http://privacycast.com/filevault-vulnerability-how-to-protec...

There's also a really interesting pdf from Apple containing more details on FileVault 2:

http://training.apple.com/pdf/WP_FileVault2.pdf

which suggests turning on firmware passwords to prevent DMA.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#62
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

It's almost as if the device was designed with surveillance in mind.

It was, targeted advertising, or at least that's the excuse.

http://consumerist.com/2013/07/08/the-xbox-one-will-use-kine...

http://bgr.com/2012/06/12/microsoft-xbox-kinect-targeted-adv...

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#63

Yet another reason to stick to open source.

Ok, I have full open-source stack and run a cloud service on it. I also give NSA full access to my servers. How does open-source helps there?

You're missing the point completely. You would at least know when someone is "poking around your data".

By law they would have to get a warrant... ie: actually obtain some real proof that you are up to no good. A lot better than this current blanket case scenario.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#64

going to try for devil's advocate angle. could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption? it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head…

Of course. If you are a legitimate suspect, any local police department can get a warrant to go inside your house and put your underpants in plastic bags and take them away. For that matter, they can cuff you and put you in jail. The question is what is the NSA doing without a warrant or rubber-stamped, secret, blanket warrants.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#65
What do they mean by bypass encryption? If I use outlook.com (or gmail.com or whatever) over https, then it's encrypted over the wire, but it's obviously decrypted on their servers. It's the only way that search could work. I assume if you are PGP encrypting your messages or something equivalent, it's still unbreakable.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#67
post #45

Earlier quoted context omitted.

> 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) I'm curious if this could be addressed with software protections somehow? Something that triggers memory wipes and automatic shutdowns?

http://www.intel.com/content/www/us/en/architecture-and-tech... Though that specifically obviously requires hardware.

It seems that only protects against "pre-launch software" and BIOS level stuff. The scenario in question is for a live system where the disk is mounted and decrypted, with the OS running.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#68

Earlier quoted context omitted.

> We are designing the new Kinect with simple, easy methods to customize privacy settings, provide clear notifications and meaningful privacy choices Do you want your information to be given to the NSA? [ ] Yes [X] Yes

No no. It is like this: Do you agree that your information will given to the NSA? [ ] Yes, I agree [X] No, I don't mind.

That would be funny if it weren't true. :(

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#69
post #45
post #30

Earlier quoted context omitted.

Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…

> 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) I'm curious if this could be addressed with software protections somehow? Something that triggers memory wipes and automatic shutdowns?

FileVault 2 is supposed to be secure against this* when the machine is powered on and locked or sleeping.

* Source http://security.stackexchange.com/questions/18720/how-secure...

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#70
post #64

going to try for devil's advocate angle. could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption? it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head…

Of course. If you are a legitimate suspect, any local police department can get a warrant to go inside your house and put your underpants in plastic bags and take them away. For that matter, they can cuff you and put you in jail. The question is what is the NSA doing without a warrant or rubber-stamped, secret, blanket warrants.

correct. i'm just having a hard time with the point (or lack there of) in this post.. as far as i can tell it's something like: NSA = PRISM, therefore any company doing work for NSA = evil.
Post reply on HN