Live data from Hacker News

Why We Can No Longer Trust Microsoft

pcmag.com

101–110 of 310 posts

Re: Why We Can No Longer Trust Microsoft

#101
post #61

Earlier quoted context omitted.

It's conjecture, but it's likely. Apple as a company has put a high value on user privacy, which was heavily influenced by Steve. He was also known for maintaining a high degree of personal privacy for such a public figure (for instance, refusing to put plates on his car).

Apple is a company producing consumer devices, while the others are companies offering Internet services, which is what PRISM targets. Apple has only recently had some success in the Internet services space with iCloud.

Curious as to why Amazon isn't on that list then? Perhaps it's true that Bezos has more in common with Jobs.

Re: Why We Can No Longer Trust Microsoft

#102

Actually, why nobody mention anything about Intel and Cisco? I would image it would be much more effective to build backdoor to network appliances if you want to spy someone.

True, but if the network traffic between you and, say Office 365, is encrypted, the NSA would need to decrypt that. It'd be so much easier if Microsoft just handed over the actual, unencrypted, files. I can easily imagine the NSA login screen for Microsoft's PRISM interface with a "Yes, I have a proper court order" checkbox under the password field.

Re: Why We Can No Longer Trust Microsoft

#103
post #51

Windows should be banned in all countries except America. Open source OS is the only way to go. I'm not saying Linux since it's not exactly the most non technical friendly OS for people requiring more than basic usage but windows definitely isn't the OS for the future and it needs to die.

unfortunately, the inertia is too big for any single organization to stop. If you have a business selling software, it would be borderline insane to not target windows as a platform. You may target others, but you _must_ target windows, or basically, get no business. If, or when your resources are limited, you only target windows.

So the problem is perpetuated - windows is the only platform that is basically guarenteed to have a market. So as a user of software, you'd stick to windows, and as a maker of software, you'd stick to making software for windows. Other platform is almost an afterthought. Unless web based software radically changes (i need to unzip a file - what web based software will do that for me?), this will not change.

Re: Why We Can No Longer Trust Microsoft

#104
post #16
post #8

Linux for all the things! That's the only viable solution

One wonders how tainted Linux is, if one considers systems including SELinux. Yes, I realise the point of SELinux is to make it more secure, but the association with the NSA (they created it) makes it very difficult to trust.

Yes - especially when you recall that projects like OpenBSD have previously [0] been accused of having backdoors in its IPsec stack, as an example.

[0] http://marc.info/?l=openbsd-tech&m=129236621626462&w=2

Re: Why We Can No Longer Trust Microsoft

#105
post #81

Earlier quoted context omitted.

What can you possibly mean? It's open source i.e. code is available to anyone's inspection.

But who does inspect it, not me for sure. So, how safe actually is Linux? And how safe is any distribution?

The fact that it is available for everyone to inspect means it can be peer reviewed: http://en.wikipedia.org/wiki/Peer_review

That doesn't mean you're supposed to review it or that it is reviewed at all, but it is a requirement for the open source development model.

About the Linux kernel, see this example: http://kernelnewbies.org/UpstreamMerge

From Quality control section: "Some of the world's best developers will be going over your source code with a fine comb. This may be embarrassing for a few days or weeks, but in the end the code tends to work better and be more easily maintained. In some cases the upstream developers have made network and storage drivers 30% faster, making the hardware more attractive to customers."

Re: Why We Can No Longer Trust Microsoft

#106
post #16
post #8

Linux for all the things! That's the only viable solution

One wonders how tainted Linux is, if one considers systems including SELinux. Yes, I realise the point of SELinux is to make it more secure, but the association with the NSA (they created it) makes it very difficult to trust.

Putting aside the point that it's open source, most distributions don't ship it. Ubuntu / SuSE use AppArmor.

RedHat / Fedora ship with SELinux.

Re: Why We Can No Longer Trust Microsoft

#107
post #61
post #58

Earlier quoted context omitted.

How do you know it was Steve Jobs that prevented Apple from joining earlier? Perhaps Apple just wasn't a priority for the NSA until 2012.

It's conjecture, but it's likely. Apple as a company has put a high value on user privacy, which was heavily influenced by Steve. He was also known for maintaining a high degree of personal privacy for such a public figure (for instance, refusing to put plates on his car).

I thought you were joking about the number plates thing, but it's true (and apparently legal) ...

http://thenextweb.com/apple/2011/10/27/mystery-solved-why-st...

This reminds me of a friend of mine who proxies all his web traffic through something which strips user agents and referrers. It's very easy for me to tell when he visits my website, because the logs show "-" for each of these fields.

Re: Why We Can No Longer Trust Microsoft

#108
post #88
post #83

Earlier quoted context omitted.

Until iCloud/iMessage, all the actual information was transmitted through third party services (i.e. network providers, email services, etc.) Why go after the myriad of handset manufacturers when you could just get the network providers on board?

There are things network providers can't do: activate mic remotely, capture local-only data, keylog apps that use encryption, etc.

The list was about joining PRISM, it doesn't say anything about backdoors in mobile phones. They may very well be present in all iPhone generations.

Re: Why We Can No Longer Trust Microsoft

#109

I don't think native MS apps running on a local machine are a risk, I imagine (with a little nieviety) that if MS apps/OS were phoning home on a regular basis with the content of ones documents - someone would have noticed and raised a flag (or did I miss it). Nor is exchange BCC a copy to the NSA - again someone would have noticed. Cloud services excluded. PS. It's *buntu that spins my propeller. PPS. I'd be interes…

>Nor is exchange BCC a copy to the NSA - again someone would have noticed. True, but what about Windows Phone vs. Android (with Google's apps, not just a FOSS build like Replicant) vs. Apple? Which is the lesser evil for your privacy?

Ah yes, well - OK I'd be thinking, given recent history, Windows Phone would be high on my list of most likely to be evil, but in the back of my mind is always, its the carrier that holds the cards there. But u have a point I had not considered - the mobile arena. What one would you consider the lesser evil?

Re: Why We Can No Longer Trust Microsoft

#110
post #100

Earlier quoted context omitted.

With a public record as a LSD user, I wonder how they could have justified giving him clearance.

I don't think that would effect his chances. All of our latest presidents have admitted or have been proven to do illegal drugs of some sort. Not to mention that the U.S. government has done some crazy things with drugs, especially LSD. https://en.wikipedia.org/wiki/Project_MKULTRA http://www.cracked.com/blog/five-fun-facts-about-the-cia-and...

As I understand it, getting a security clearance doesn't especially care about whether you've done anything illegal, it cares about:

1. Whether you're likely to voluntarily leak any secure information.

2. Whether someone who dug up some dirt on you could blackmail you into leaking secure information.

Or as the saying goes, it's fine to have a mistress, but having a mistress that your wife doesn't know about is a problem...

Post reply on HN