Live data from Hacker News

US intelligence mining data from 9 US Internet companies in broad secret program

washingtonpost.com

61–70 of 420 posts

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#61
post #29

Yes, this is bad. Yes, you are right to be upset. Yes you (not not really me, I'm not American and i avoid american hosting and hosting companies like amazon for exactly this reason) should change that. But honestly, are you surprised? Are you really? Government agencies have be building large datacenters, the EU loves data retention. There was no tin foil head required to see this.

When people wanted to talk about this kind of massive wiretapping program years ago, they were called paranoid nutcases. Now that the truth is coming out, people who want to talk about it are called out for belaboring the obvious.

I see this "are you so naive as to be surprised?" reaction in almost every thread about this. It's some kind of defense mechanism.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#62
post #31

Earlier quoted context omitted.

I'm not sure when the security people you are talking about did their audit, but when Microsoft bought Skype a few years ago they changed it from P2P communications to routing everything through a central server. After that it would be child's play to put in a backdoor.

Not to be too conspiracy theorist but maybe just maybe this was why Skype was bought by Microsoft in the first place? The thought crossed my mind at the time of purchase but I sent it away skuttling because I deemed it too tinfoil hatty. My main regret at the time as a Linux enthusiast was that Skype's Linux offering was sure to suffer, so I had that angle more on my mind than government aiding and abetting.

Why would Microsoft buy Skype to make government easedropping easier?

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#63
post #31

At least we know beyond a shadow of a doubt that Skype has a backdoor now. Not really surprising although they did have some security people analyze the protocol and state that it was e2e secure. FTA: "According to a separate “User’s Guide for PRISM Skype Collection,” that service can be monitored for audio when one end of the call is a conventional telephone and for any combination of “audio, video, chat, and file t…

I'm not sure when the security people you are talking about did their audit, but when Microsoft bought Skype a few years ago they changed it from P2P communications to routing everything through a central server. After that it would be child's play to put in a backdoor.

This is widely misunderstood; it's possible that Skype is end-to-end secure and everything flows through MS servers. It's possible that there were backdoors in the old pre-MS versions. One really has little to do with the other.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#64
post #31

At least we know beyond a shadow of a doubt that Skype has a backdoor now. Not really surprising although they did have some security people analyze the protocol and state that it was e2e secure. FTA: "According to a separate “User’s Guide for PRISM Skype Collection,” that service can be monitored for audio when one end of the call is a conventional telephone and for any combination of “audio, video, chat, and file t…

I'm not sure when the security people you are talking about did their audit, but when Microsoft bought Skype a few years ago they changed it from P2P communications to routing everything through a central server. After that it would be child's play to put in a backdoor.

It has been claimed by many smart people that skype is still p2p and e2e (for the record I disagree with them). Skype does claim to be p2p sometimes for some values of p2p http://liliputing.com/2012/05/skype-abandons-peer-to-peer-te...

>I'm not sure when the security people you are talking about did their audit

The security audit was done in 2005 by Tom Berson of Anagram Laboratories. This was well before Skype was bought by microsoft but Skype links to it off their home page http://www.skype.com/en/security/#review

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#65
post #48
post #35

Earlier quoted context omitted.

Dropbox has every encryption key used with Dropbox, so they can decrypt any file. Both transport keys and storage keys. Dropbox does at least (allegedly) encrypt stuff for storage, so they can RMA hard drives without having to destroy them first, but that's pretty meaningless. There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good…

What alternative do you suggest?

Private server with sync software of your choice. Sparkleshare is a quite Dropbox-like git front end. Con: Uses Mono. Pro: Uses Mono.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#66
post #35
post #23

Earlier quoted context omitted.

I don't believe they need backdoors, they probably just ask for the data and it's provided to them by those companies to comply with the current laws (or at least their interpretation of it.) I'm pretty sure dropbox can reverse any encryption they use for the files they store. Or do they even encrypt the data?

Dropbox has every encryption key used with Dropbox, so they can decrypt any file. Both transport keys and storage keys. Dropbox does at least (allegedly) encrypt stuff for storage, so they can RMA hard drives without having to destroy them first, but that's pretty meaningless. There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good…

This is a reply to gknoy:

I would suggest Spider Oak, however, their support is not timely and there's currently a bug in the Windows 8 client that doesn't let it work. But if they get those issues sorted it could be a decent service.

Could someone please tell me why I can't reply to any comments that are below the third level? The reply link simply disappears!

Edit: Now that I've made this statement there's a reply to gknoy, but not the ones below him or to o0-0o. This is really weird.

Edit 2: Upon refreshing, there's now a reply link to o0-0o but not the other ones below gknoy.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#67
post #29

Yes, this is bad. Yes, you are right to be upset. Yes you (not not really me, I'm not American and i avoid american hosting and hosting companies like amazon for exactly this reason) should change that. But honestly, are you surprised? Are you really? Government agencies have be building large datacenters, the EU loves data retention. There was no tin foil head required to see this.

No, but now there is proof, which should make a difference. How are all of these not cases for impeachment? If Fox News thought Obama should be impeached over Benghazi, they should love this.

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#68

I'm saddened to see Dropbox on the list. Did they choose to participate or is it mandatory? In any case, we've moved several projects to BTSync recently from Dropbox (for no other reason than to free up space on Dropbox for our personal files) and have been enjoying the service. As a p2p encrypted protocol, I imagine it's much more difficult to eavesdrop on your files and would actually require a warrant to obtain. I…

I've read somewhere that it's voluntary edit: read it here http://mobile.theverge.com/2013/6/6/4403868/nsa-fbi-mine-dat...

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#69
post #48
post #35

Earlier quoted context omitted.

Dropbox has every encryption key used with Dropbox, so they can decrypt any file. Both transport keys and storage keys. Dropbox does at least (allegedly) encrypt stuff for storage, so they can RMA hard drives without having to destroy them first, but that's pretty meaningless. There are some (flimsy) reasons for Dropbox to have copies of all storage keys (a web UI, which only some users use). Dropbox has done a good…

What alternative do you suggest?

use Tonido (http://www.tonido.com)

Re: US intelligence mining data from 9 US Internet companies in broad secret program

#70
post #68

I'm saddened to see Dropbox on the list. Did they choose to participate or is it mandatory? In any case, we've moved several projects to BTSync recently from Dropbox (for no other reason than to free up space on Dropbox for our personal files) and have been enjoying the service. As a p2p encrypted protocol, I imagine it's much more difficult to eavesdrop on your files and would actually require a warrant to obtain. I…

I've read somewhere that it's voluntary edit: read it here http://mobile.theverge.com/2013/6/6/4403868/nsa-fbi-mine-dat...

Source.
Post reply on HN