Live data from Hacker News

Why We Can No Longer Trust Microsoft

pcmag.com

171–180 of 310 posts

Re: Why We Can No Longer Trust Microsoft

#171
post #169

GNU/Linux, and Free software and hardware in general, look to be the BIG winners out of the NSA brouhaha, because all non-US governments, businesses, organizations, and individuals around the planet who need to safeguard their private or confidential information now have reason to mistrust proprietary (unauditable) software and hardware. Free, open software and hardware are less likely to have secret 'back doors' ins…

Mistrust of commercial solutions does not translate into trust for open-source ones. Have you audited the crypto code of all your packages? Would you even know how?

Re: Why We Can No Longer Trust Microsoft

#172

Earlier quoted context omitted.

Not in the wildest scenario would the US government have jailed the leaders of Apple, Google or Microsoft. That may be naive. Most people have skeletons in their closets. The government would use these to pressure those leaders to acquiesce. I suspect the most dangerous skeletons are ones which seem harmless to you, but cast in the proper light they can be used as a justification for punishment. E.g. Something which…

I can see two sides to this. On one hand, the CEO of Qwest was convicted of insider trading, and he claims it was retaliation by the NSA because Qwest would not participate in warrantless wiretapping. On the other hand, the federal government had a perfect excuse to prosecute Steve Jobs in 2006 with the options backdating scandal, but chose not to. Those would not have been baseless charges--Apple really did backdate…

Maybe they were using it as leverage.

Re: Why We Can No Longer Trust Microsoft

#173

Earlier quoted context omitted.

Not in the wildest scenario would the US government have jailed the leaders of Apple, Google or Microsoft. That may be naive. Most people have skeletons in their closets. The government would use these to pressure those leaders to acquiesce. I suspect the most dangerous skeletons are ones which seem harmless to you, but cast in the proper light they can be used as a justification for punishment. E.g. Something which…

I can see two sides to this. On one hand, the CEO of Qwest was convicted of insider trading, and he claims it was retaliation by the NSA because Qwest would not participate in warrantless wiretapping. On the other hand, the federal government had a perfect excuse to prosecute Steve Jobs in 2006 with the options backdating scandal, but chose not to. Those would not have been baseless charges--Apple really did backdate…

Well, PRISM seems to have been created in '07. Plus Apple didn't matter very much in '06 -- not in the same way Google mattered. Apple didn't have much user data for the government to be interested in, because iPhone didn't launch till June '07.

That's actually a perfect example of leverage that the government would have used against a technology company to pressure them into doing the government's bidding.

Re: Why We Can No Longer Trust Microsoft

#174
post #118

Earlier quoted context omitted.

Apple had internet services since around year 2000. Apple had mac.com emails for a very long time, as well as http://en.wikipedia.org/wiki/MobileMe .Mac: July 17, 2002 – July 9, 2008 MobileMe: July 9, 2008 – June 30, 2012 iCloud was launched on October 12, 2011, one year before Apple entering Prism. http://en.wikipedia.org/wiki/ICloud The main difference before iCloud was that you had to pay for it. I can however rem…

Well, in the NSA's eyes, that main difference is important. Free (and highly pushed by the very popular iPhone and iPad) meant people actually starting using iCloud. The cost-benefit analysis shifted tremendously from .mac/MobileMe. It is fun to think of Steve Jobs as the lone person saying "fuck you" to the NSA. But it isn't realistic. It isn't like the other companies are run by meek people who love bending over to…

I can remember that I've had a free .me account before iCloud, so I believe even .me must have had enough users: it was freely available to every iDevice user. There were millions of them fast.

Re: Why We Can No Longer Trust Microsoft

#175
post #157
post #41

Earlier quoted context omitted.

I keep hearing this on HN and reddit, but I think this is a mainly an echo-chamber effect. I'd say its far more likely that the vast majority of people don't actually care or realise what was happening, or they do realise and still don't care. I'd be surprised if the NSA leaks have any noticable impact on Microsoft's revenue.

Pretty much. The truth is, unless your company serves Internet security careerists or people impassioned about Internet privacy, your customers do not care. The company I work for has absolutely no intent of dropping Microsoft products in lieu of the NSA leaks, even with large amounts of sensitive customer data. I can't imagine many large companies would. It would require such a vast amount of work it's unfathomable…

And serves them only. The other part is most corporations already have the feeling that the government is spying on them, and a public acknowledgement of the fact wont change their implementation details. Now, if you said "Microsoft is spying on you with your direct competition." that would make them sit up and take notice.

Re: Why We Can No Longer Trust Microsoft

#176
post #120
post #3

This is a financial disaster waiting to happen. Microsoft is oblivious if it is not doing something to divorce itself from the NSA. Apple, on the other hand, could have come out smelling like a rose, but following the death of Steve Jobs, who apparently refused to play ball with the NSA, it stupidly jumped on board to join the PRISM club. According to the Prism slides, it really looks so: "Dates when Prism collection…

What amazes me is that among those corporations with revenues in the tens of billions of dollars, not one of them challenged the constitutionality of the decision in court. Not one, not once. Not that it would be necessary in an obvious case like this, but each one of Microsoft/Skype, Google/Youtube, Apple and Facebook could easily have hired the nation's best and brightest one thousand lawyers at $1,000 an hour, ful…

FISA give them the right to install real-time monitoring on premise.

That means if you fight, they put a server in your shop.

It was just not worth it until now. That's going to be the real legacy of the Snowden leaks.

Re: Why We Can No Longer Trust Microsoft

#177
post #3

This is a financial disaster waiting to happen. Microsoft is oblivious if it is not doing something to divorce itself from the NSA. Apple, on the other hand, could have come out smelling like a rose, but following the death of Steve Jobs, who apparently refused to play ball with the NSA, it stupidly jumped on board to join the PRISM club. According to the Prism slides, it really looks so: "Dates when Prism collection…

"And can you just imagine how much more sales Apple would get now for not being on that list?" Barely any change at all, I'd bet. And not worth the legal hassle they could have been up against if it came to a knock-down, drag-out battle with the US Government over .

I'd imagine for Steve Jobs...

everything is worth a fight.

Re: Why We Can No Longer Trust Microsoft

#178
post #169

GNU/Linux, and Free software and hardware in general, look to be the BIG winners out of the NSA brouhaha, because all non-US governments, businesses, organizations, and individuals around the planet who need to safeguard their private or confidential information now have reason to mistrust proprietary (unauditable) software and hardware. Free, open software and hardware are less likely to have secret 'back doors' ins…

Mistrust of commercial solutions does not translate into trust for open-source ones. Have you audited the crypto code of all your packages? Would you even know how?

Which would you trust more?

Re: Why We Can No Longer Trust Microsoft

#179
post #169

GNU/Linux, and Free software and hardware in general, look to be the BIG winners out of the NSA brouhaha, because all non-US governments, businesses, organizations, and individuals around the planet who need to safeguard their private or confidential information now have reason to mistrust proprietary (unauditable) software and hardware. Free, open software and hardware are less likely to have secret 'back doors' ins…

Mistrust of commercial solutions does not translate into trust for open-source ones. Have you audited the crypto code of all your packages? Would you even know how?

Exactly. Even more interesting, all of the source code can be OK and just some subtle configuration tweaks can be enough to compromise you. Or just some build flag that you don't even see in sources. Often you don't know the build flags of every binary as soon as you use binaries. You also don't know if the compiler is tweaked to do some preprocessing you don't know about (see Reflections on Trusting Trust by Ken Thompson):

http://cm.bell-labs.com/who/ken/trust.html

For security conscious the prefect state is the OS which changes very, very slowly, fixing only security bugs and having binaries used by as many people as possible and which change so seldom that more people can even check them by disassembling them. You don't want to only check sources, you want to disassemble the binaries and decide if they match the sources.

And only then you want to be sure that all configurations are what they should be. Not easy at all.

Re: Why We Can No Longer Trust Microsoft

#180
post #146
post #120

Earlier quoted context omitted.

What amazes me is that among those corporations with revenues in the tens of billions of dollars, not one of them challenged the constitutionality of the decision in court. Not one, not once. Not that it would be necessary in an obvious case like this, but each one of Microsoft/Skype, Google/Youtube, Apple and Facebook could easily have hired the nation's best and brightest one thousand lawyers at $1,000 an hour, ful…

Correction: Yahoo did fight, and lost. The details aren't all released, but here's a precis of what's public: http://www.wired.com/threatlevel/2013/06/yahoo-failed-fisa-f... It's possible that there's as-yet undisclosed legal action with some of the others; the secrecy around just about any proceeding in the FISC makes it very hard to tell.

Fighting unconstitutional laws in the phony secret "court" set up by the same laws is not really fighting, is it? It's sort of accepting the terms.

Take the battle to the real courts and ask them to decide on the matter.

Post reply on HN