Earlier quoted context omitted.
Why does the NSA have full access to your servers? Even if they manually wiretap your server it would require manual intervention, and is thus a good protection against blanket surveillance.
"Why does the NSA have full access to your servers?" Because they ordered him to give it, and he elected not to go to jail.
Microsoft helped the NSA bypass encryption, new Snowden leak reveals
71–80 of 118 posts
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#72I feel so stupid and so ashamed of myself for all the time I have thought of everything Richard Stallman had to say about privacy and security concern as a "neck-beard, tin-foil hat, nutjob". He was right all along, it was us who didn't care enough to understand what he was saying and its importance.
It is a basic principle of security to assume that any power an adversary has, will be used against one's interests. People misunderstand this; I have seen it called a fallacy. But it's not a claim that it's always true, rather that it's what one must assume in order to have the best practicable assurance of security /privacy.
I also used to get arguments like "MS/GOogle/$_BIG_TECH_CO wouldn't use their power against customers, it would be bad for business" or "...it would be illegal" or similar. The correct answer is that prudence dictates assuming the worst. Well, maybe I was too cynical, but it's hard to keep up with how bad things really are.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#73Earlier quoted context omitted.
Of course. If you are a legitimate suspect, any local police department can get a warrant to go inside your house and put your underpants in plastic bags and take them away. For that matter, they can cuff you and put you in jail. The question is what is the NSA doing without a warrant or rubber-stamped, secret, blanket warrants.
correct. i'm just having a hard time with the point (or lack there of) in this post.. as far as i can tell it's something like: NSA = PRISM, therefore any company doing work for NSA = evil.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#74Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#75Earlier quoted context omitted.
Of course. If you are a legitimate suspect, any local police department can get a warrant to go inside your house and put your underpants in plastic bags and take them away. For that matter, they can cuff you and put you in jail. The question is what is the NSA doing without a warrant or rubber-stamped, secret, blanket warrants.
correct. i'm just having a hard time with the point (or lack there of) in this post.. as far as i can tell it's something like: NSA = PRISM, therefore any company doing work for NSA = evil.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#76Earlier quoted context omitted.
"Why does the NSA have full access to your servers?" Because they ordered him to give it, and he elected not to go to jail.
He means "how". Open-source protects against software backdoors (though obviously not against key-sharing et alii)
rimantas is referring to using open source in a cloud service, not authoring and distributing it.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#77Earlier quoted context omitted.
correct. i'm just having a hard time with the point (or lack there of) in this post.. as far as i can tell it's something like: NSA = PRISM, therefore any company doing work for NSA = evil.
The NSA is skating on very thin constitutional ice, but honestly they haven't really done anything that even qualifies as evil. The KGB did this kind of spying, but they did for the express purpose of sending dissenters to gulag. I haven't seen so much as a credible accusation that the NSA are doing anything other than their duly authorized mission.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#78Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…
I am ambivalent in regards to ranking one over the other because I cannot file a FOI request with Microsoft or Google or Apple or HP or Yahoo, etc.
Microsoft just makes great headlines, particularly in the tech community where people such as myself, who very likely never planned on purchasing an Xbox One can express outrage over its design. I thought the architecture was crap from the beginning.
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#79Earlier quoted context omitted.
> 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) I'm curious if this could be addressed with software protections somehow? Something that triggers memory wipes and automatic shutdowns?
FileVault 2 is supposed to be secure against this* when the machine is powered on and locked or sleeping. * Source http://security.stackexchange.com/questions/18720/how-secure...
> If you enable LUKS root, DMA attack mitigation is also enabled(boot.initrd.luks.mitigateDMAAttacks ). It consists of blacklisting firewire drivers.
Edit: still at risk of the "Evil Maid Attack" http://www.aspecrypt.com/evil_maid_attack.html
Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals
#80Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…