Live data from Hacker News

How Microsoft handed the NSA access to encrypted messages

guardian.co.uk

51–60 of 164 posts

Re: How Microsoft handed the NSA access to encrypted messages

#51
post #2

Microsoft's June 7th statement: "We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don’t participate in it." One down, several to go. If I were Google/Fac…

The interesting conflict to me is that Google et al don't appear to be fighting this battle. When it comes to other things, they are in the streets, funding lobbyists, building protest websites, and so on. But this, which threatens their entire business model (essentially trust-based), they haven't made a peep about. It may just be a gag order thing, sure. But with the level of access required for stuff like this, I…

Oh, come on.

Developers only need to build some APIs - those APIs can be multi-purpose. They don't need to know that one such purpose is NSA spying - you can come up with dozens of other reasons for wanting a "back door".

The actual interface that's used for responding to legally binding orders or subpoenas and that uses the APIs in question can be built by people on NSA's payroll.

Besides executives, the only people slightly aware of what's going on will be some people from the legal department. And they'll get presented with an interface in which they have to double-check (in bulk) the validity of received orders.

Re: How Microsoft handed the NSA access to encrypted messages

#52
post #49
post #6

Allow me to be surprised this time, I don't see much new here, compared to what we already saw about Prism (all the slides). Maybe the only thing newsworthy this time is that additional documents confirm that Prism exist? I applaud this article of course, as it gives less chance for unnatural interpretations of the slides that we saw by pro-status-quo writers ("it's not really a direct access") -- now we have additio…

I think the confirmation that NSA and FBI have direct and unfettered access to all communication streams, is pretty huge. As you say, all calm-down-dear interpretations are now proven false. We are facing the worst possible scenario.

If you haven't seen the Binney video made in 2012 by the same author that made the Snowden video, first note the date the video was published, then watch it.

Then try to identify the claims already public to those that watched the video then which most of us first became aware of just now by following the story about Snowden.

http://www.nytimes.com/2012/08/23/opinion/the-national-secur...

For me it starts around 3:20. A lot of it was presented before Snowden but almost nobody noticed.

Re: How Microsoft handed the NSA access to encrypted messages

#55
post #41

Earlier quoted context omitted.

Except Google's "free services" helps their strategy of keeping users on Google's services, enriches their Google profile and helps create targeted ads.

> Except Google's "free services" helps their strategy of keeping users on Google's services, enriches their Google profile and helps create targeted ads. I get your point but the same sentence can easily apply to Microsoft. Microsoft wants to do the same thing:)

They wouldn't be spearheading an anti-Google campaign against their strategy if they also wanted to do the same thing.

Re: How Microsoft handed the NSA access to encrypted messages

#56
post #47
post #25

Earlier quoted context omitted.

The peculiar part for me with Google is that they seem to be somehow immune from all the revelations. People keep stand by it and get annoyed when reminded of their wrong-doings. I suspect at this point, they're not much different than Microsoft. But the "don't be evil" brand is still strong in the mind of many.

Speaking for myself, but I'm sure others share the sentiments, its not that i think google is somehow "good". They're obviously not, the difference is that they're still a cool tech company doing cool things on a massive scale (or potentially very disruptive). self-driving cars, balloon network testing in NZ, google fiber, and more mundane things like Golang and angular. I don't give them a pass, its just that in the…

Google isn't above doing things that harm people to make them more money. Like the steadily decreasing background contrast and lack of borders separating ads from search results. Older people are far less cognizant of borders and thus would click on ads thinking they're search results.

http://blumenthals.com/blog/2012/01/31/is-google-intentional...

They recently got rapped by the FTC for it.

http://wallstcheatsheet.com/stocks/ftc-googles-ad-practice-i...

The difference is that the negative Microsoft news tends to float on top of sites like HN more than positive news, and the reverse is true for Google so this alters perceptions of people.

Re: How Microsoft handed the NSA access to encrypted messages

#57

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

As a Microsoft contractor, I'm confused about how to feel and how to move forward. Sometimes I feel like I'll be enabling some of these practices by continuing be a contracted worker, and that this community will in part be blaming me for this situation.

Give it some time, clarify what exactly you're contributing. Then, if you want a clear conscious, work towards it in a practical way. Be as innocent as a dove, as sly as a fox!

That is, you don't need to quit your only mildly, indirectly enabling job right this instance, throwing your family into financial difficulties. But, you do need to work towards untangling yourself as much as your conscious demands.

Re: How Microsoft handed the NSA access to encrypted messages

#58

Earlier quoted context omitted.

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? Do you think the government would jail someone of Steve Ballmer's stature if he talked openly about what the government has asked of Microsoft. Because of his position he is much more protected from criminal actio…

Do you think the government would jail someone of Steve Ballmer's stature if he talked openly about what the government has asked of Microsoft. Absolutely, but even if they didn't, if you were Steve Ballmer, would you take that risk? They certainly could prosecute you for leaking secret information. That's even assuming that Ballmer knew about it. It could have been that they approached people who were in some positi…

if you were Steve Ballmer, would you take that risk?

They don't seem to mind taking risks when it comes to questionable tax deductions.

They certainly could prosecute you for

But they wouldn't. The type of activity the government is engaged in only works when people are passive.

if you're served a lawful court order, you either obey it or risk the consequences, up to and including time in jail.

When was the last time anyone of stature went to jail for defending the public against the government?

Re: How Microsoft handed the NSA access to encrypted messages

#59

To play devil's advocate here, what else would people have Microsoft do? Is there a scenario in which they can successfully resist enabling surveillance features in their products while operating in the US? CALEA applies to telecommunications providers, which is a label that would seem to clearly apply to Skype. http://en.wikipedia.org/wiki/Calea Are major companies based or operating in the US allowed to provide sec…

These are some of the biggest corporations in the world, with resources to push back on behalf of their users---if they wanted to. Heck, at least Yahoo did something. At some point the PRISM collaborators took a calculated risk that their users would not find out, or if they did, it would be of no consequence to their business. Maybe it was the classified assurances, or maybe the whole "direct access" line for deniability. I may not have any say in NSA programs or secret courts, but I'm still a consumer and techie and can vote with my money and time. I'm gonna do my best not to support companies that actively build a surveillance state.

Re: How Microsoft handed the NSA access to encrypted messages

#60

FTA: "Secret files show scale of Silicon Valley co-operation ..." Since when is Redmond considered Silicon Valley?

Mountain View is in SV. It's their second largest campus:

http://www.microsoft.com/en-us/news/features/2009/nov09/11-2...

But Microsoft Research might be more relevant:

"Located in Mountain View, California, Microsoft Research Silicon Valley was founded in August 2001 and now employs about 75 researchers. Our research work focuses on distributed computing and includes privacy, security, protocols, fault-tolerance, large-scale systems, concurrency, computer architecture, Internet search and services, and related theory."

http://research.microsoft.com/en-us/labs/siliconvalley/defau...

Post reply on HN