Live data from Hacker News

How Microsoft handed the NSA access to encrypted messages

guardian.co.uk

121–130 of 164 posts

Re: How Microsoft handed the NSA access to encrypted messages

#121

Earlier quoted context omitted.

Give me 12 (a dozen) reasons to break the encryption and security of your users that could be acceptable to a non brain dead engineer and exclude surveillance and government snooping?

You're missing the fact that if a middleman does the encryption or has access to the decryption key, then encryption is already broken. A service provider is the middleman in this case and encryption only serves the purpose of you making sure that communications are with this service provider and not with another middleman. " Breaking the encryption " is not accurate. They don't need to break anything as your data is…

> "Breaking the encryption" is not accurate. They don't need to break anything as your data is in plain text on their servers.

While this is true, I don't think it was his point. His point, I believe, was that the software should protect the data, and the engineer should not install or create APIs that allow someone to circumvent the security and privacy of the user — for any reason. He was replying to someone saying that higher ups could lie about the reason or need for such an API; his reply was saying that even the lie should be so obviously privacy-breaking as to be unacceptable. (Hence, he asked for examples.)

That said: legitimate law enforcement requests, i.e., warrants, would be an acceptable reason to me to implement such an API. That said, it should be auditable, so that you can verify it isn't being abused.

Re: How Microsoft handed the NSA access to encrypted messages

#122
post #56

Earlier quoted context omitted.

Google isn't above doing things that harm people to make them more money. Like the steadily decreasing background contrast and lack of borders separating ads from search results. Older people are far less cognizant of borders and thus would click on ads thinking they're search results. http://blumenthals.com/blog/2012/01/31/is-google-intentional... They recently got rapped by the FTC for it. http://wallstcheatsheet.c…

Actually, the "they" that got "rapped" by the FTC were "AOL, Ask, Bing, Blekko, Duck Duck Go, Google and Yahoo as general purpose search engines and 17 'of the most heavily trafficked' shopping, travel and local search engines"[1]. These were reissued rules that clarified and enhanced the rules issued by the FTC in 2002 to make advertising clear. It likely came out of Danny Sullivan's letter to the FTC[2] showing how…

[deleted]

Re: How Microsoft handed the NSA access to encrypted messages

#123
post #25

Earlier quoted context omitted.

The peculiar part for me with Google is that they seem to be somehow immune from all the revelations. People keep stand by it and get annoyed when reminded of their wrong-doings. I suspect at this point, they're not much different than Microsoft. But the "don't be evil" brand is still strong in the mind of many.

I might be just a single data point, but PRISM is the primary cause of my slow but persistent move away from Google services. Oh, btw, I know many people over here in Europe who never use any Google service other than search out of general mistrust towards the company. Might not help them much, as the search history combined with the IP-address logs of all the G+ buttons is already a pretty encompassing profile, but…

Not just G+ buttons either. How many websites these days _arent_ running Google Analytics?

Re: How Microsoft handed the NSA access to encrypted messages

#124
post #2

Microsoft's June 7th statement: "We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don’t participate in it." One down, several to go. If I were Google/Fac…

Honest question: how does that article contradict that statement? Everyone is bouncing off the walls about this but I honestly can't see where the story is. Microsoft + others enable NSA to access customer data when presented with court order. You can agree or not agree but is it really a shock?

I'm probably overly sensitive to this, being a "non-US person", but I'm constantly reading "with a court order" as "either with a court order, or with a 51% suspicion that one of the two parties to the communication is not a US citizen - in which case we can do what we like"

Re: How Microsoft handed the NSA access to encrypted messages

#125

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

Protest. Lobby. Seek publicity. Take the government to court. Put up a fight. Note that when the EU data retention directive (which is often used here under the header "see, others are doing it to", even though it doesn't even come close to what the NSA does) was initiated, that's exactly what many telecom providers and ISP's did, before and after this came into affect. It didn't stop it, but it least it has brought…

"Protest. Lobby. Seek publicity. Take the government to court. Put up a fight."

I'll let you know how that goes from here in Sydney, Australia.

Yeah,I'm not a US citizen. None of the "with a valid court order" weasel-words apply to me.

Re: How Microsoft handed the NSA access to encrypted messages

#126
post #41

Earlier quoted context omitted.

> Microsoft often "competes" by trying to strangle competitors revenue streams even when it's outside their core business, where they will happily lose billions on Bing and their online division if it can reduce Googles revenues: This is true as you point out. However it's worth pointing out that Google is the exact same. They release free products that Microsoft charges for loosing money to reduce Microsoft's primar…

Except Google's "free services" helps their strategy of keeping users on Google's services, enriches their Google profile and helps create targeted ads.

Couldn't that also be said when Microsoft started bundling Internet Explorer with Windows? Does it make it right? NO!

The truth is the tech industry politics is becoming as nasty as real politics. Smear campaigns by Microsoft against Google. Google trying to sabotage Windows mobile platform by actively excluding their core products. Apple and Samsung at copycat wars. Once the open world of computing is now turning into a war of ecosystems and we the consumers are the only ones standing to lose.

Re: How Microsoft handed the NSA access to encrypted messages

#127
post #22
post #4

Marketing: "Your privacy is our priority." Meaning: "Microsoft and the FBI had come up with a solution that allowed the NSA to circumvent encryption on Outlook.com chats" "For Prism collection against Hotmail, Live, and Outlook.com emails will be unaffected because Prism collects this data prior to encryption." "analysts will no longer have to make a special request to SSO", "this new capability will result in a much…

Well, did you expect "privacy" to imply that your data would not be released to the government following legal requests for it? I always assumed it meant that they wouldn't share it with other businesses, but maybe that's just me. Analogously, if one of the major phone providers started selling information to marketers, including what times of day I made phone calls, would it be inappropriate for a competitor to crea…

That implication is exactly what Colin provides with my tarsnap backups. He (or Amazon) can respond to legal requests with my strongly encrypted data, and Neither Colin/tarsnap nor Amazon can provide them with my private keys.

You can design your systems this way. It appears you're allowed under US law. It seems there's companies jumping through hoops on behalf of the NSA and/or FBI to build systems that _dont_ provide that guarantee.

Note that Colin _could_ conspire with / be compelled by the NSA to attempt to convince me to "upgrade" my local tarsnap code with a backdoored version - and I'm OK with that, if the NSA is looking for me specifically, I fully expect them to find out _everything_ - that's their job and I expect them to be world-class at it. What I _dont_ accept, is that they have any "right" to record and archive permanently anything I ever do online "just in case". And I can and am taking steps to make that harder for them, and I'm noticing which companies are apparently working agains my wishes. I'm curious to know if Dropbox are noticing an drop in de-dup rates lately? My Dropbox storage is now all encfs encrypted - including the folders full of grabbed funny-cat-pics and Internet meme images. My versions are no longer the same as the other several million of them stored on Dropbox. Same for my SkyDrive/GDrive/Jotta accounts.

Re: How Microsoft handed the NSA access to encrypted messages

#128

I must be in the minority here, but I'm no more concerned now than before reading this, and I'm still not super concerned if it works the way I think it does. It doesn't answer the main question of HOW MANY USERS are being watched like this. We already knew from Prism that Microsoft is providing data to the NSA, and we already knew that it included real time video, emails, messages, etc. So this is more of a behind-t…

On April 5, according to this slide, there were 117,675 active surveillance targets in PRISM's counterterrorism database. The slide does not show how many other Internet users, and among them how many Americans, have their communications collected "incidentally" during surveillance of those targets.

http://www.washingtonpost.com/wp-srv/special/politics/prism-...

Re: How Microsoft handed the NSA access to encrypted messages

#129
post #103
post #92

Earlier quoted context omitted.

CALEA does NOT require Microsoft to provide decryptable communications services; in fact it ensures Microsoft can do exactly the opposite. http://paranoia.dubfire.net/2010/09/calea-and-encryption.htm...

A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication. Note " unless the encryption was provided by the carrier." Skype is the one that provides encryption here (a car…

There's readily available examples of crypto software generating key pairs on the client end, and never exposing the private key to the server - GPG/PGP, OpenSSL, tarsnap - and the OpenSSL libraries are used by a whole bunch of other software too (encfs, browsers, web servers, CSR generation…)

Any "crypto" which doesn't do secure keygen on the client for "at rest" data storage is now significantly more suspect than before these revaluations. You can explain away whatever you like in terms of "usability" or "most users don't care", but now manyof us are going to read any excuses as "Yeah, the US government has got to our CEO… And he's not gonna be the next Qwest guy…"

Re: How Microsoft handed the NSA access to encrypted messages

#130
post #50

Earlier quoted context omitted.

You asked: "Are major companies based or operating in the US allowed to provide secure email and/or data storage without options for lawful surveillance from law enforcement?" Compare 47 USC §1002(b)(3): A telecommunications carrier shall not be responsible for decrypting, or ensuring the government’s ability to decrypt, any communication encrypted by a subscriber or customer, unless the encryption was provided by th…

Microsoft is not a telecom carrier.

I agree that the pure VoIP parts of Skype should not be interpreted as telecommunications services under CALEA. I think we agree; I'm quoting these provisions to argue that Microsoft does not have any interception capability mandates for IP-to-IP calls under CALEA.
Post reply on HN