Live data from Hacker News

How Microsoft handed the NSA access to encrypted messages

guardian.co.uk

161–164 of 164 posts

Re: How Microsoft handed the NSA access to encrypted messages

#161
post #25

Earlier quoted context omitted.

The peculiar part for me with Google is that they seem to be somehow immune from all the revelations. People keep stand by it and get annoyed when reminded of their wrong-doings. I suspect at this point, they're not much different than Microsoft. But the "don't be evil" brand is still strong in the mind of many.

What surprises me is that for example Apple and Google don't simply ignore the gag orders, and just release what and how much they have handed over. Google/Apple are not going to get shut down over this. They can afford lawsuits and penalties. So why not take a stand? Are they really that timid? Or is what they would reveal actually so grim they just sit by and hope they're somehow going to escape this? This is the t…

It's easy to suggest that someone else should go to prison.

Re: How Microsoft handed the NSA access to encrypted messages

#162
post #25

Earlier quoted context omitted.

The peculiar part for me with Google is that they seem to be somehow immune from all the revelations. People keep stand by it and get annoyed when reminded of their wrong-doings. I suspect at this point, they're not much different than Microsoft. But the "don't be evil" brand is still strong in the mind of many.

What surprises me is that for example Apple and Google don't simply ignore the gag orders, and just release what and how much they have handed over. Google/Apple are not going to get shut down over this. They can afford lawsuits and penalties. So why not take a stand? Are they really that timid? Or is what they would reveal actually so grim they just sit by and hope they're somehow going to escape this? This is the t…

While I would not bet money on it, it might be possible that the NSA has dirt on these companies, or on their high-ranking employees, keeping them from taking a stand.

Re: How Microsoft handed the NSA access to encrypted messages

#163
U don't consider PRISM such a big deal, to be honest.

Yes, they spy on innocent people, in an attempt to flush out (or whatever the term is) the dangerous or potentially dangerous ones. However, I genuinely doubt my privacy is very compromised, because I refuse to believe someone is getting paid to sit and read through Facebook posts or messages about my obsession with Supernatural (great TV show on CW), or read through "IF YOU DONT SEND THIS TO 7 OTHER PEOPLE A PIANO FROM THE HEAVENS WILL CRUSH YOU INTO THE PAVEMENT" emails my neighbour is forwarding.

Also, I have a friend who talks in acronyms most of the time (over Skype chat) and I have a file called deectionary.txt (her name is Dee) with around 200 lines, I find it very amusing to think some analyst spent hours trying to decode her message because it contained "bomb" in what looks like "mtwbi bombing m/i shc play asg ol" which means (used near-real example) "my twat brother is lagging my Internet so he can play a stupid game online". She has no disability, she's just very "efficient," I guess!

Besides, I don't have anything to hide, so I don't really care. If I had some top secret business I needed to attend and would care to keep secret from the NSA or CIA, I would probably (as would many of you here, too I believe) make my own thing to do the job, because I wouldn't take someone's word that they give a rat's furry bottom about my privacy.

Re: How Microsoft handed the NSA access to encrypted messages

#164
post #2

Microsoft's June 7th statement: "We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don’t participate in it." One down, several to go. If I were Google/Fac…

The interesting conflict to me is that Google et al don't appear to be fighting this battle. When it comes to other things, they are in the streets, funding lobbyists, building protest websites, and so on. But this, which threatens their entire business model (essentially trust-based), they haven't made a peep about. It may just be a gag order thing, sure. But with the level of access required for stuff like this, I…

It's possible companies run an NSA module on their servers and let backdoor hacks happen based on an understanding the NSA will get pissed if they investigate.

This provides full PRISM access and allows for deniability of direct access.

Oh what's that? There is an NSA module most big companies run on their servers? Right, it's called SE Linux. The question that remains how do you build a backdoor that cannot easily be spotted in the source code. Maybe a weakness in a random number generator used for encryption. Oh what's that? The NSA does that too?

On Backdoor in encryption standard: http://www.wired.com/politics/security/commentary/securityma...

On SE Linux: http://www.businessweek.com/articles/2013-07-03/security-enh...

Post reply on HN