Live data from Hacker News

Microsoft helped the NSA bypass encryption, new Snowden leak reveals

rt.com

101–110 of 118 posts

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#101
post #30

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…

Why not just a backdoor in the OS? I mean...if we're seriously considering that apple would put a backdoor into FileVault, why not just put one in the OS proper?

FileVault could be some hypothetical magic uncrackable encryption with a keyspace bigger than the known universe...and it would never matter if there was a backdoor in the OS.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#102
post #57

Earlier quoted context omitted.

In addition to that, you can purchase smart power strips that detect the drop/increase in power on one plug and turn off/on the other plugs. I've been using one of these for several years now for our entertainment center. You just have to be sure you turn off any devices you don't want the power hard cut from before you turn off the television.

I wonder if there's a market for a power strip of this type that also presents a standard serial/USB UPS interface to the hardware, giving it a grace period to shutdown before the hard kill.

HDMI-CEC is probably the more appropriate interface for something like this.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#103
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

This is exactly, literally the device imagined by Orwell in 1984, which he called a telescreen.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#104
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

The photons look about the same to me. At the other end of the data hose, someone is using information about me for their benefit. Governments are one form of enterprise by which individuals may strive to accumulate and express power, corporations are another. I am ambivalent in regards to ranking one over the other because I cannot file a FOI request with Microsoft or Google or Apple or HP or Yahoo, etc. Microsoft j…

The threat is to democracy. If corporations violate your privacy, democracy is not in serious danger.

If the government does, democracy is.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#105
post #88
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

It's a low level, hardware only capability. It'll even work when the Xbox isnt connected to the internet. You're making an unfounded statement that simply because the XO can listen for an "on" command while hibernating that it's being used to listen and transmit everything it sees and hears. This is explicitly not true and again, just your personal unfounded fear-mongering assertion.

How can you call it a "fear-mongering assertion" given everything that's been revealed recently? It's certainly well within the realm of possibility even if some might find it unlikely.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#106
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

On the bright side, the government might actually start taking the NSA concerns seriously if it starts having a detectable effect on the profitability of one of the country's most important growth industries. It seems like it's already becoming a reality in terms of foreign markets, but a reasonably large domestic boycott of a marquee next generation console would be bigger.

This is probably the most important point in the whole thread. Honestly, the debate about whether the new X-box will spy on you or not is irrelevant. In fact, it would be even better if there were a massive boycott and Microsoft weren't even guilty. They'd be in the position of knowing it isn't true and having no way to prove it. I'm sure they'd have a very large interest in getting things like PRISM shut down at that point.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#107

going to try for devil's advocate angle. could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption? it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head…

>could there be a case where the parties in a conversation are legitimate suspects?

It doesn't matter if they are. No one expects coffee shops to put microphones at every table on the off chance that a terrorist plot is planned there (how many mob hits could have been prevented back in the day).

We shouldn't accept the government listening in on digital communication just because it's easy.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#108
post #73

Earlier quoted context omitted.

correct. i'm just having a hard time with the point (or lack there of) in this post.. as far as i can tell it's something like: NSA = PRISM, therefore any company doing work for NSA = evil.

The NSA is skating on very thin constitutional ice, but honestly they haven't really done anything that even qualifies as evil. The KGB did this kind of spying, but they did for the express purpose of sending dissenters to gulag. I haven't seen so much as a credible accusation that the NSA are doing anything other than their duly authorized mission.

They're not skating on thin ice, they fell through some time ago. I'd also call the way they claim to bypass checks and balances by "storing" instead of "reading" data (assuming that's even true which seems unlikely).

And the NSA might not have sent anyone to the gulag but the Obama administration has gone after whistle-blowers at an unprecedented level. Hard to imagine the NSA wasn't helping them out some.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#109
post #2

The sad thing about all of this is that Microsoft were pretty much forced into this position (so we're told) by the authorities. In the process these leaks have just destroyed pretty much any credibility Microsoft's online services had, which form large parts of their strategy (according to the recent Ballmer memo). It also makes you wonder about the OS and other software they produce, which isn't a good place for MS…

Good. Big companies are the only thing in the US with even the remotest of hopes of stopping or slowing this down. And they're not going to bother unless it's actually costing them money.

So I hope it hurts them, I hope it makes them and all the other companies bleed until they do something.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#110
post #5

Earlier quoted context omitted.

I'm not sure why you're picking on Microsoft. The credibility of pretty much every large US-based tech services company is probably destroyed. The fact that we only saw the big service providers (MS, Google, etc...) on those slides doesn't mean that the other companies are free from the hands of the NSA. Do you think that the NSA has no access to Dropbox?

Enterprise relies on companies such as RedHat and Oracle to some extent in lieu of conducting code analysis and to certain types of security testing. It would be rather surprising if they were not at least approached by Federal agencies such as NSA and FBI. To put it another way, because Microsoft has a closed source model, the intelligence agencies took the approach described in the article. From that, it may be a m…

If there were backdoors in the distributed Redhat code, how many people would even be able to know this? And that's if the code were blatantly obvious if you were allowed to see what was actually compiled. If the compiler itself is compromised then it would be possible that no one at Redhat would know.
Post reply on HN