Live data from Hacker News

U.S. National Security Agencies Said to Swap Data With Thousands of Firms

bloomberg.com

31–40 of 78 posts

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#32
post #12

Earlier quoted context omitted.

If you're in the MAPP program, you promise (on application, and presumably contractually upon membership as well), to: Do you agree to publish monthly protections derived from MAPP information only after Microsoft’s public security update release? I'm doubting the NSA / military hackers make, or honor, any such agreement.

The NSA is not known to publish things.

Don't forget their internal 'zine, Cryptolog. There was a story here(1) about how it was recently declassified. Heavily redacted, but still very cool.

http://www.nsa.gov/public_info/declass/cryptologs.shtml

(1) https://news.ycombinator.com/item?id=5407036

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#33
post #27
post #20

Earlier quoted context omitted.

This is very different from your original (hysterical, sensational) claim that MSFT is giving the government "zero days" to "hack people with".

not really what does msft think they're doing with them?

"The Government" is a huge employer with a massive installation base of Windows systems, many of which contain sensitive information wanted by well motivated attackers. They would be keenly interested in new threats to those systems, the same way that any large corporation with a similar installation base and threat model would.

Ask yourself, if you receive information via MAPP, you have some information which could be turned into an exploit, but it will not be useful towards a goal of hacking other peoples computers for long because, by definition, it is going to be patched soon. "Make hay while the sun shines" perhaps? The same window of opportunity is open to governments and corporations around the world (many Chinese companies are MAPP subscribes, the one leak of a MAPP exploit happened perhaps because of a Chinese company).

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#35
"AT&T, Verizon

Before they agreed to install the system on their networks, some of the five major Internet companies -- AT&T Inc. (T), Verizon Communications Inc (VZ)., Sprint Nextel Corp. (S), Level 3 Communications Inc (LVLT). and CenturyLink Inc (CTL). -- asked for guarantees that they wouldn’t be held liable under U.S. wiretap laws. Those companies that asked received a letter signed by the U.S. attorney general indicating such exposure didn’t meet the legal definition of a wiretap and granting them immunity from civil lawsuits, the person said."

This will make the ACLU's law suit 1000% more interesting as a legal battle.

Verizon doesn't just sit around and think to themselves "hey, if we're going to work with the NSA we should do some CYA". They have entire legions of smart lawyers who mulled this whole NSA business over (substantially I hope) and came to the conclusion that "this is most certainly a violation of the law and we need complete documented assurance from the government that our actions can never be prosecuted in court".

And they got it. But will it hold up?

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#36
Wow, this scandal just keeps getting bigger and bigger. Good to see some light finally being shined into what had been darkness. A free and open society, based on classical liberal / Enlightenment ideals of individual freedom, is NOT compatible with secret governments, secret laws, secret courts, mass surveillance of the public and all of the things the US government is doing. Now we know, and now - if the people have any spine or backbone left - we can force some change.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#38

"AT&T, Verizon Before they agreed to install the system on their networks, some of the five major Internet companies -- AT&T Inc. (T), Verizon Communications Inc (VZ)., Sprint Nextel Corp. (S), Level 3 Communications Inc (LVLT). and CenturyLink Inc (CTL). -- asked for guarantees that they wouldn’t be held liable under U.S. wiretap laws. Those companies that asked received a letter signed by the U.S. attorney general…

I don't understand how the executive branch can guaranty immunity from civil action in the judicial branch.

Re: U.S. National Security Agencies Said to Swap Data With Thousands of Firms

#40
post #31

Well, there's the smoking gun for the reason behind CISPA. I'm sure tptacek still won't admit he was wrong though.

What was tptacek wrong about?

I'm not sure exactly what the parent comment is referring to, but here's one instance.

tptacek: "Someone on Twitter (sorry) said that Google and Facebook "looked like angels" compared to Verizon. That sounds about right to me, too."

https://news.ycombinator.com/item?id=5876734

Post reply on HN