Yahoo installed a backdoor for the NSA behind the back of the security team
131–140 of 302 posts
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#132Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#133Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#134Earlier quoted context omitted.
When you get a legally-binding order from the government of the United States of America, and exhaust your legal appeals, you either comply or go to prison. An ethics course won't do you any good.
People have the option to quit. The company is legally bound to obey, but individual employees can chose for themselves whether they want to be a party to it. Yahoo may still be court ordered to implement it, just hopefully not with their best and brightest developers. I also have a theory that a lot of the recent terrible news coming out of Yahoo is due to staff complying with the letter of the legal order but not t…
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#135Earlier quoted context omitted.
Good point. I assumed it was a direct development in the other day's story re: the largest hacking to date for YHOO.
It was linked in the comments thread of that story, probbly why it was re-submitted. Personally, I missed this story when it was first posted, but regardless reposting now definitely adds an interesting additional perspective to the recent announcement, especially as we all wait for more information to be released about how the hack was executed and what the broader implications are. Combined the two stories are more…
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#136Earlier quoted context omitted.
Do you think? Seems to me people are getting used to accounts being hacked, it's not such a big deal any more, in fact it may be even an expectation. And as for government NSA hacking, well that's just old news and a given isn't it?
I'm not sure that people are getting 'used' to it. I was talking to a non-techie over the weekend, and although they were aware about Snowden's NSA revelations, they were quite perturbed to think someone could be reading their email. I don't think people have stopped caring, they just feel helpless. This means that normal people may be willing to adopt new protocols (end-to-end encryption), something they wouldn't do…
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#137Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#138Earlier quoted context omitted.
Options: - Refuse to take action. They want engineering done, they can bloody well do it themselves. Don't type a single keystroke in the direction of helping them. - Announce what is going on anonymously. Plenty of avenues for this. - Announce what is going on, publicly. See if they do indeed want to take you to court. - Quit. - Take down the service. Much easier if the service is only a part of your company. Helps…
If you want to quit to refuse to help, fine, but I take serious issue with what you're suggesting beyond that. These are the legal actions of the United States government, executing the authority given to them to the people's elected representatives, and overseen by a judiciary duly selected according the constitutional procedures. Their legal and democratic authority is unassailable. Further, you don't know what mot…
This is imho the untold truth about why most communist / socialist regimes failed: people at all levels of society started doing their work gradually worse and worse, pissed off and stressed out by the lack of freedom and constant interference from state organs, until everything collapsed, and people now live in better economies and freer because they've destroyed their previous systems. Yeah, most of the people who performed such "low level sabotage" will not even recognize to themselves that they did it. And yeah, bad governments were also helped to fail by external interference and external sabotage, but imho a "socialist regime where the people would truly believe in socialism/communism" could have worked out and had good economic performance, problem is that when "good economic performance" can only be had at too high of a cost of "individual personal freedom", people will start, even subcounsciously motivated, without admitting even to themselves what they are doing, and with insect-like non-communicative coordination, to slowly and methodically weaken the system they live in from within, until it crumbles, even at the cost of their own lives sometimes.
This was America's secret weapon that helped "win the cold war" - people's inner "instinct for freedom or death" - thank god we all have it and a race of subhumans lacking it has not yet been engineered! It might also be the reason why so many Americans "voted for Trump", though this was probably engineered by some really smart "puppet masters" - the guy is clearly a "man of the establishment" despite it's clown persona...
Of course, there is no "monument to the lazy and drunk soviet worker that helped take down communism". And there will be no monument for the Google employee that writes a subtle bug in the "government reporting module XYZ" :) Of course, if the gov doesn't abuse its power and asks for too much, that poor programmer might not be so "overwhelmed" by it's duties so as to make stupid "mistakes" with dire consequences...
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#139Earlier quoted context omitted.
It's not US. It's another state actor. Can't say more.
PRISM (Yahoo joined 2nd in 2008 after Microsoft in 2007) would basically defeat the purpose of doing this without permission... Did Yahoo Mail even use HTTPS? In that case a FISA warrant would just be an extra level of assurance that they got everything from that person's inbox (plus inboxes of 3 hops of everyone they ever emailed). Otherwise they were just an XKeyscore query, probably filtered by US geodata, away fr…
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#140I seriously think that to get a CS or EE degree (or similar) B.Sci degree, you should be required to take at least one full term length ethics course. Same idea as the ethics courses taught to junior law students. The internet is already fucked up enough with governments and rogue corporations messing with its AS-adjacency topology in non-free ways at OSI layers 1-3 , before you even get into stuff like writing backd…