Earlier quoted context omitted.
One wonders how tainted Linux is, if one considers systems including SELinux. Yes, I realise the point of SELinux is to make it more secure, but the association with the NSA (they created it) makes it very difficult to trust.
What can you possibly mean? It's open source i.e. code is available to anyone's inspection.
Why We Can No Longer Trust Microsoft
81–90 of 310 posts
Re: Why We Can No Longer Trust Microsoft
#82Dvorak's article is a regurgitation of previous HN discussions on this topic. I have said in the previous HN post and I will say it again here: don't pile on Microsoft alone. These spying policies make every US-based services company untrustworthy to whomever privacy is important. Come to think of it, I'm not sure whether you can rely on European services either because it seems that gov't surveillance is widespread.…
Yea, remember that PRISM is designed to target foreign communications, so if you are an American, you might be actually safer.
That was entirely a lie. From day one their system has been targeting Americans. The proof is overwhelming at this point.
There's often a critical distinction between what gets claimed and what actually occurs in government. With a government that is so undeserving of trust, that's a very important distinction to keep in mind.
Re: Why We Can No Longer Trust Microsoft
#83Earlier quoted context omitted.
Apple is a company producing consumer devices, while the others are companies offering Internet services, which is what PRISM targets. Apple has only recently had some success in the Internet services space with iCloud.
One of those most successful devices is a phone. One that has been selling pretty well for 6 years. That's incitement enough to try to get them on board.
Why go after the myriad of handset manufacturers when you could just get the network providers on board?
Re: Why We Can No Longer Trust Microsoft
#84Windows should be banned in all countries except America. Open source OS is the only way to go. I'm not saying Linux since it's not exactly the most non technical friendly OS for people requiring more than basic usage but windows definitely isn't the OS for the future and it needs to die.
Re: Why We Can No Longer Trust Microsoft
#85Earlier quoted context omitted.
To me seems you were just kinda rude to some guy that was getting paid to do his job.
Indeed the guy most certainly didn't know shit. On the other hand, rude or not, Lina turned out to be right and the MS-guy turned out to be ignorant of the type of company he was working for, as well as defending. Additionally these so-called "paranoid" questions didn't came out of thin air either. 10-15 years ago I also was very distrusting of Microsoft and what they were doing (there was a lot of anti-trust going o…
Senseless bashing - including intentional miss-$pellings and holding one company (Microsoft) to different standards to others (Facebook, Google, Apple) is still childish.
However, not all bashing is senseless - Microsoft has a lot of explaining to do. Sure, so do Facebook, Google and Apple but that doesn't let MS off the hook. It makes the case for installing a Linux instead a lot stronger.
Re: Why We Can No Longer Trust Microsoft
#86- low-level crypto APIs (the 'DLLs' referred to obliquely in the article); these are more interesting. I imagine they could be compromised for weak session key generation or other leakage of key / plaintext, or generate the session key in such a way that the mythical 'NSAKEY' can decrypt it. Huge impact, if so, but only to certain software; AFAIK Mozilla doesn't use the Windows crypto API / certificate key store (but Chrome does).
- SSL certificate generation (built-in CA for Windows Server builds); certificates stored and replicated via Active Directory; does anyone actually use this? In fact, does anyone actually use client SSL? It is likely also used for domain peer replication, which could potentially be over an external network (but why would you not use a VPN there?)
- Encrypted File System; already contains an escrow key-recovery mechanism to allow administrators (including domain admins) to recover a lost user key. Only likely to be relevant if hard disk or backup images seized, so less impact.
- BitLocker drive encryption; similar to EFS but uses a hardware TPM and is per-machine rather than per-user. Fairly sure escrow key recovery at the domain level is possible here too. Again, only likely to be relevant if hardware or backups seized.
- Office document encryption; did anyone SERIOUSLY think this was worth using anyway? There are so many key recovery services out there for this (Elcomsoft et al)
- Communications applications (Skype et al); again, did anyone SERIOUSLY think this wasn't already being monitored, even before Skype became a Microsoft product?
- Some other OS-level 'phoning-home' behaviour. I simply don't believe that no-one has spotted this happening, if it's there - we can do traffic analysis too, and there are plenty of people running Wireshark on their own networks.
Re: Why We Can No Longer Trust Microsoft
#87Seems like Microsoft has a lot of issues to worry about. Doing a reorg when the company is struggling just to put an agency person in charge seems like a lot of work. Why not just put them in charge in a small internally announced move?
Re: Why We Can No Longer Trust Microsoft
#88Earlier quoted context omitted.
One of those most successful devices is a phone. One that has been selling pretty well for 6 years. That's incitement enough to try to get them on board.
Until iCloud/iMessage, all the actual information was transmitted through third party services (i.e. network providers, email services, etc.) Why go after the myriad of handset manufacturers when you could just get the network providers on board?
Re: Why We Can No Longer Trust Microsoft
#89Earlier quoted context omitted.
How do you know it was Steve Jobs that prevented Apple from joining earlier? Perhaps Apple just wasn't a priority for the NSA until 2012.
Steve Jobs went through a background check for a top-level security check in the 80s. I wonder if he ever received it? http://www.wired.com/threatlevel/2012/06/steve-jobs-security... I find it hard to believe that the NSA didn't see one of the most valuable and popular companies in the world as a priority until 2012. I bet they were salivating as soon as the first iPhone launched.
Re: Why We Can No Longer Trust Microsoft
#90This is a financial disaster waiting to happen. Microsoft is oblivious if it is not doing something to divorce itself from the NSA. Apple, on the other hand, could have come out smelling like a rose, but following the death of Steve Jobs, who apparently refused to play ball with the NSA, it stupidly jumped on board to join the PRISM club. According to the Prism slides, it really looks so: "Dates when Prism collection…
How do you know it was Steve Jobs that prevented Apple from joining earlier? Perhaps Apple just wasn't a priority for the NSA until 2012.