Live data from Hacker News

US intelligence mining data from 9 US Internet companies in broad secret program

washingtonpost.com

31–40 of 420 posts

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#31

At least we know beyond a shadow of a doubt that Skype has a backdoor now. Not really surprising although they did have some security people analyze the protocol and state that it was e2e secure. FTA: "According to a separate “User’s Guide for PRISM Skype Collection,” that service can be monitored for audio when one end of the call is a conventional telephone and for any combination of “audio, video, chat, and file t…

I'm not sure when the security people you are talking about did their audit, but when Microsoft bought Skype a few years ago they changed it from P2P communications to routing everything through a central server. After that it would be child's play to put in a backdoor.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#33
post #13

I just emailed Tim Cook that imho iCloud is dead. He is welcome to add options to use my own cloud storage while using clientside encryption, and I might reconsider. You're welcome to send him your opinion as well. It's tcook@youknowntherest.

Be serious. This is Apple. How on earth does clientside encryption fit into easy-to-use? Lost your password? Lost your files. That's entirely against the scenario Apple wants to sell.

Clientside crypto will only possibly be mass-adopted when there's some easy system for common folks to store their keys.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#34

Earlier quoted context omitted.

How does this stuff work? Would someone at the NSA contact dropbox and ask them to build in a backdoor or are they just able to access whatever the fuck they want and simply do?

The spineless, reprehensible CEOs are doing it willingly.

This is unsubstantiated speculation.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#35
post #23

Earlier quoted context omitted.

How does this stuff work? Would someone at the NSA contact dropbox and ask them to build in a backdoor or are they just able to access whatever the fuck they want and simply do?

I don't believe they need backdoors, they probably just ask for the data and it's provided to them by those companies to comply with the current laws (or at least their interpretation of it.) I'm pretty sure dropbox can reverse any encryption they use for the files they store. Or do they even encrypt the data?

Dropbox has every encryption key used with Dropbox, so they can decrypt any file. Both transport keys and storage keys. Dropbox does at least (allegedly) encrypt stuff for storage, so they can RMA hard drives without having to destroy them first, but that's pretty meaningless.

There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good job of misrepresenting how their security worked for the past ~4 years to mislead people into trusting it, though.

This is mostly why I don't use Dropbox whenever I have a choice.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#36
What really saddens me is that this confirms all the conspiracy rumors.

Wasn't it always just a rumor going around that the U.S. Government "made" Microsoft buy Skype for spying purposes?

Well: "10 May 2011, Microsoft Corporation acquired Skype Communications"

and on 2/6/11 Skype was added to the US spy program [1]

They were so eager to spy on Skype users that they implemented that "feature" even before the deal was officially done. Considering that Skype had been around since 2003 the events don't appear very accidental.

Wouldn't surprise to find out one day that the Skype acquisition was indirectly tax-payer funded.

[1] http://www.washingtonpost.com/wp-srv/special/politics/prism-...

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#37

will be exciting to see how soon these servers become compromised and massive amounts of private information leaked. I would give it a year tops!

There's no upside to this happening. Governments will still collect data. Your personal details, however, will be publicly available.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#38
post #9

What sort of threats does the NSA give to these companies so they participated without any leaks? Just curious what the penalty would be if the NSA approached me about sucking down my user data and I refused.

I suspect just getting a request from a three letter agency is enough to make most CTOs and CEOs wet themselves and roll over. (Standing up against the government is not usually part of the business plan.)

That's the point of CISPA. They didn't want to fight the government, but they pushed back asking for more legal protections, especially after the AT&T warantless spying scandal broke. So, they've been trying hard to pass CISPA in order to give these CEOs more peace of mind.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#39
post #32

Dropbox.... “coming soon.” Time to look at Bittorrent Sync again? Or other open source alternatives?

My thoughts exactly. I'm certainly going to be looking at other options, including BitTorrent Sync. As useful as Dropbox may be, it's something I'd be willing to do without if this is true.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#40
post #13

I just emailed Tim Cook that imho iCloud is dead. He is welcome to add options to use my own cloud storage while using clientside encryption, and I might reconsider. You're welcome to send him your opinion as well. It's tcook@youknowntherest.

Be serious. This is Apple. How on earth does clientside encryption fit into easy-to-use? Lost your password? Lost your files. That's entirely against the scenario Apple wants to sell. Clientside crypto will only possibly be mass-adopted when there's some easy system for common folks to store their keys.

I'm not asking for exclusive client-side encryption. I'm asking to have it as an option. Which is a totally legit wish.

If the common forgetful folks like to trade ease-of-use with being spied upon, I'm fine with that.

But me, I'm not willing to do that trade-off.

Post reply on HN