At least we know beyond a shadow of a doubt that Skype has a backdoor now. Not really surprising although they did have some security people analyze the protocol and state that it was e2e secure. FTA: "According to a separate “User’s Guide for PRISM Skype Collection,” that service can be monitored for audio when one end of the call is a conventional telephone and for any combination of “audio, video, chat, and file t…
US intelligence mining data from 9 US Internet companies in broad secret program
31–40 of 420 posts
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#32Or other open source alternatives?
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#33I just emailed Tim Cook that imho iCloud is dead. He is welcome to add options to use my own cloud storage while using clientside encryption, and I might reconsider. You're welcome to send him your opinion as well. It's tcook@youknowntherest.
Clientside crypto will only possibly be mass-adopted when there's some easy system for common folks to store their keys.
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#34Earlier quoted context omitted.
How does this stuff work? Would someone at the NSA contact dropbox and ask them to build in a backdoor or are they just able to access whatever the fuck they want and simply do?
The spineless, reprehensible CEOs are doing it willingly.
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#35Earlier quoted context omitted.
How does this stuff work? Would someone at the NSA contact dropbox and ask them to build in a backdoor or are they just able to access whatever the fuck they want and simply do?
I don't believe they need backdoors, they probably just ask for the data and it's provided to them by those companies to comply with the current laws (or at least their interpretation of it.) I'm pretty sure dropbox can reverse any encryption they use for the files they store. Or do they even encrypt the data?
There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good job of misrepresenting how their security worked for the past ~4 years to mislead people into trusting it, though.
This is mostly why I don't use Dropbox whenever I have a choice.
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#36Wasn't it always just a rumor going around that the U.S. Government "made" Microsoft buy Skype for spying purposes?
Well: "10 May 2011, Microsoft Corporation acquired Skype Communications"
and on 2/6/11 Skype was added to the US spy program [1]
They were so eager to spy on Skype users that they implemented that "feature" even before the deal was officially done. Considering that Skype had been around since 2003 the events don't appear very accidental.
Wouldn't surprise to find out one day that the Skype acquisition was indirectly tax-payer funded.
[1] http://www.washingtonpost.com/wp-srv/special/politics/prism-...
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#37will be exciting to see how soon these servers become compromised and massive amounts of private information leaked. I would give it a year tops!
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#38What sort of threats does the NSA give to these companies so they participated without any leaks? Just curious what the penalty would be if the NSA approached me about sucking down my user data and I refused.
I suspect just getting a request from a three letter agency is enough to make most CTOs and CEOs wet themselves and roll over. (Standing up against the government is not usually part of the business plan.)
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#39Dropbox.... “coming soon.” Time to look at Bittorrent Sync again? Or other open source alternatives?
Re: US intelligence mining data from 9 US Internet companies in broad secret program
#40I just emailed Tim Cook that imho iCloud is dead. He is welcome to add options to use my own cloud storage while using clientside encryption, and I might reconsider. You're welcome to send him your opinion as well. It's tcook@youknowntherest.
Be serious. This is Apple. How on earth does clientside encryption fit into easy-to-use? Lost your password? Lost your files. That's entirely against the scenario Apple wants to sell. Clientside crypto will only possibly be mass-adopted when there's some easy system for common folks to store their keys.
If the common forgetful folks like to trade ease-of-use with being spied upon, I'm fine with that.
But me, I'm not willing to do that trade-off.