Live data from Hacker News

Microsoft helped the NSA bypass encryption, new Snowden leak reveals

rt.com

91–100 of 118 posts

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#91
post #88
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

It's a low level, hardware only capability. It'll even work when the Xbox isnt connected to the internet. You're making an unfounded statement that simply because the XO can listen for an "on" command while hibernating that it's being used to listen and transmit everything it sees and hears. This is explicitly not true and again, just your personal unfounded fear-mongering assertion.

He never said it -does- transit data, and is just implying that it -can-.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#92
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

Holy cow. I can just imagine having one for the kids, then trying to avoid talking about anything important in the living room, then...

It's a telescreen. (http://en.wikipedia.org/wiki/Telescreen)

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#93

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

Microsoft has a free program (for Law Enforcement) called COFFEE which, among other things, bypasses Bitlocker full-disk encryption. You can find the Torrent at Wikileaks: https://wikileaks.org/wiki/Microsoft_COFEE_%28Computer_Onlin...

I have come across COFFEE before, its just a forensic tool. It doesn't do anything more than what 3rd party tools can do. It looks like a toolkit put together for investigators. Do you have any source to support that it can decrypt/bypass Bitlocker encryption? I couldn't find any information online.

[1] https://en.wikipedia.org/wiki/Computer_Online_Forensic_Evide...

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#94
post #86

Earlier quoted context omitted.

This is the same as the British Stamp Act from the American Revolutionary War. If the Stamp Act was an argument for revolution because it was evil, this is too.

The difference is that the colonists had no recourse. "No taxation without representation" and all that. Without sending delegates to parliament, they had no channels to complain through, so rebellion was the only option. We could end the NSA completely by voting for candidates who support that.

I can't vote in the US as a resident in Sweden, so I'm in the exact same positions as the first colonists in America.

I guess my only option now is to rebel.

But sure for those living in the US they can do that. And they did that with Obama. However that just increased the surveillance.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#95
post #73

Earlier quoted context omitted.

correct. i'm just having a hard time with the point (or lack there of) in this post.. as far as i can tell it's something like: NSA = PRISM, therefore any company doing work for NSA = evil.

The NSA is skating on very thin constitutional ice, but honestly they haven't really done anything that even qualifies as evil. The KGB did this kind of spying, but they did for the express purpose of sending dissenters to gulag. I haven't seen so much as a credible accusation that the NSA are doing anything other than their duly authorized mission.

"...honestly they haven't really done anything that even qualifies as evil."

Firstly, how can we be certain?

Suppose, for a moment, I had the data that the NSA has. To whom could I sell that data? If I could prove to questioners that I had such data, to what ends might they go to get it from me(Ans. there are entities that would take it by force and then kill me and my family to remove the traces)?

NSA is sitting on a goldmine. Many, if not most, large corporations, businessmen, academics, organized crime members, politicians, or bureaucrats would sell their home (and possibly their family into slavery) to obtain that information. How can the NSA possibly ensure that it is safe ? How can they ensure that their employees do not pass some of that data to the above? What if a significant chunk of that data is copied and enters the black market? How could it possibly be recaptured?

Snowden has, by example, shown that all the above can and indeed did occur.

As we speak there are undoubtedly hundreds, if not thousands, of individuals who are attempting to gain access to the NSA's treasure vaults. Some groups are smarter and better organized than the NSA. It's merely a matter of time before huge leaks occur. They may or may not be leaked publicly.

Neglect can be criminal too.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#96
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

Holy cow. I can just imagine having one for the kids, then trying to avoid talking about anything important in the living room, then... It's a telescreen. ( http://en.wikipedia.org/wiki/Telescreen )

Welcome to Brave New 1984.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#97
post #91
post #88

Earlier quoted context omitted.

It's a low level, hardware only capability. It'll even work when the Xbox isnt connected to the internet. You're making an unfounded statement that simply because the XO can listen for an "on" command while hibernating that it's being used to listen and transmit everything it sees and hears. This is explicitly not true and again, just your personal unfounded fear-mongering assertion.

He never said it -does- transit data, and is just implying that it -can-.

Why mod the parent down? There is no proof that it won't, is there? If Microsoft come out with a clear statement (no doublespeak), then I'll believe them. Until then, burden of proof required from Microsoft. As of today, I trust none of the big players, and your venacular of "scare mongering" won't change the burden of proof either.

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#98
post #19
post #11

I find it interesting that no USA-based news source is covering this.

Among US-based news sources covering this: The New York Times, NBC News, New York Daily News, CBS News, NPR, Chicago Tribune, ABC.

It isn't on their front page...

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#99
post #30

This whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.

Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…

Take a look at Alex Ionescu's "Ninja's and Harry Potter" talk from NoSuchCon this year [1].

He specifically mentions he could access the FileVault key of a machine by having physical access, and discovered two secret keys (KPPW and KPST) one of which is enabled when the input buffer is "SpecialisRevelio" [2].

It's a very interesting deck to read through.

[1] http://www.nosuchcon.org/talks/D1_02_Alex_Ninjas_and_Harry_P... [2] http://harrypotter.wikia.com/wiki/Specialis_Revelio

Re: Microsoft helped the NSA bypass encryption, new Snowden leak reveals

#100
post #7
post #4

Puts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was al…

Since the Xbox camera is connected to the console via a cable, you can verify whether data going over the wire. If the Xbox is off, you shouldn't see traffic. It's a /bunch/ different from traffic in a data center, which is essentially untraceable and can be cloned at many points. Frankly I'd be more concerned about the microphones contained in ubiquitous and nearly unexaminable devices such as cell phones, and to a…

Not quite. You activate the xbox using a voice command. Unless the kinect has a speech processor in it (which is incredibly unlikely), then it is very probably sending the sound to the xbox.

So you will [again, this is speculation] be seeing constant traffic flowing across the USB cable.

Post reply on HN