15 ms·
Yahoo scanned customer emails for US intelligence
- ChoHag 10y agoBut continue to find themselves stumped?
- jonknee 10y agoIt sounds like Yahoo will fit right in at Verizon... It also sounds like another leak designed to damage Marissa Mayer: > According to the two former employees, Yahoo Chief Executive Marissa Mayer's decision to obey the directive roiled some senior executives and led to the June 2015 departure of Chief Information Security Officer Alex Stamos, who now holds the top security job at Facebook Inc.
- mtgx 10y agoSounds like she was a pretty terrible CEO all-around. But as a user, I would never use a service run by Marissa Mayer again. She lost that trust for good.
- duaneb 10y ago> But as a user, I would never use a service run by Marissa Mayer again. She lost that trust for good. Realistically, this is every American company. Why trust anyone?
- rodgerd 10y agoMicrosoft and Apple have both been in court during the last 12 months to block US government over-reach. Yahoo joins Amazon in ethusiastically facilitating it. Your assertion isn't realistic, it's nonsense.
- openasocket 10y agoI'm curious, when has Amazon facilitated US government over-reach? I couldn't think of anything off the top of my head, and googling only provided a bunch of documentation for AWS's cloud offerings to government agencies.
- rodgerd 10y agoAmazon chose to boot WikiLeaks immediately after a US senator expressed displeasure with WL's original high-profile tranche of leaks.
- openasocket 10y agoI'll be honest, that doesn't really bother me, assuming AWS wasn't forced or coerced into dropping WikiLeaks. I happen to disagree with a lot of WL's actions, and understand why AWS may not want to host stolen classified documents. I understand that you don't share that opinion, and that my opinion may not be the most popular one on HN. Any other examples?
- spdustin 10y agoI must have missed something, can someone elaborate on how Amazon has enthusiastically facilitated government overreach into citizens' privacy?
- duaneb 10y agoI would have assumed it's referring to this: https://aws.amazon.com/message/65348/ https://aws.amazon.com/message/65348/ I don't really see the point, though, I wouldn't want to host wikileaks either.
- WallowC_33 10y agoSure, as far as we know, MS and Apple have been in the public eye as being against government overreach. I suspect it's less about protecting customers from the government and more about protecting themselves, though. But one needs their hands and toes to count the other areas in which Microsoft and Apple have conducted themselves... poorly? Apple in the poaching employees lawsuit. Spurious lawsuits over "design" (ie rounded corners on rectangles) trademarks. Colluding with music execs to push customers to their streaming music service (instead of ad supported "free" streaming on labels sites). Since this is about a CEO hate, Steve Jobs was a complete asshole by a number of accounts. Horribly abusive. Microsoft... well their track record should be well established. The absolute worst of which was releasing a mass market OS that was egregiously insecure by default (yet, around here, the conversation often is "I wish MS tested like they did back in the day." when webcams break, but I digress). Again, the CEO thing, Ballmer was borderline incompetent, Gates was involved in a number of shady market capture schemes. But you know, because in this one context of government over-reach, they did a bit better than Yahoo!, the parents position that they're all untrustable is complete nonsense. The only thing "wrong" Marissa did was not make a shit ton of money for Yahoo! No one would give this story another thought if Yahoo!'s stock was worth $100 more than it was when she started. That's about all MS and Apple have done "right". That end justified the means.
- duaneb 10y agoCourt isn't likely to solve this. Only a wholesale rejection of terrorism as a realistic threat to, well, anything but our political process is going to do it. I assume the FBI is reading my email. You should, too, or you will be unhappy when you find out they are.
- dimino 10y agoBecause people don't honestly care, they just like to pretend to care. Convenience trumps privacy, every time.
- chc 10y agoIt is impossible to live functionally in society without trusting someone on some level.
- mirimir 10y agoFor sure. But it's prudent to understand and mitigate risk.
- duaneb 10y agoYea--I'm just saying this is a product of being a business, not Meyer. One can fight it and still give information over. You can't take the sign of struggle as a sign your data is safe.
- chc 10y agoIt's not a sign that your data is safe, but I think the point here is the opposite: You can take easy capitulation as a sure sign that your data is compromised. Similarly, the lock on my door doesn't make me safe against everyone who might want to commit any crime against me, but all else being equal, a locked door is still preferable from a security standpoint, and it's very preferable to keeping your valuables in an unlocked room with a known thief.
- M2Ys4U 10y agoYes, but they said every _American_ company, not every company in general.
- piaste 10y agoYou can trust Google/MS/Yahoo!/etc. with your pizza orders and mortgage payments, while switching to self-hosted, GPG email from a RYF-certified machine for organising your secret mattress-tag-removing guerrilla.
- mtgx 10y agoLet's take this one proof of company cooperation with NSA at a time.
- dredmorbius 10y agoThis is an instance of a specific executive, specific betrayal of user interests, and a specific mode of betrayal. Meyer is toast. I'll agree that the general level of trust evinced by corporate America is low, but there is considerable variance within that domain.
- greenyoda 10y agoI'm not a fan of Mayer's, but sounds like she didn't want to fight the order since that hadn't worked in the past: "Yahoo in 2007 had fought a FISA demand that it conduct searches on specific email accounts without a court-approved warrant. Details of the case remain sealed, but a partially redacted published opinion showed Yahoo's challenge was unsuccessful." Her real mistake was going directly to the e-mail team to implement the backdoor without telling the security chief about it: "They were also upset that Mayer and Yahoo General Counsel Ron Bell did not involve the company's security team in the process, instead asking Yahoo's email engineers to write a program to siphon off messages containing the character string the spies sought and store them for remote retrieval, according to the sources. The sources said the program was discovered by Yahoo's security team in May 2015, within weeks of its installation. The security team initially thought hackers had broken in. When Stamos found out that Mayer had authorized the program, he resigned as chief information security officer and told his subordinates that he had been left out of a decision that hurt users' security, the sources said. Due to a programming flaw, he told them hackers could have accessed the stored emails."
- draw_down 10y agoSure, but it's not like they had a non-terrible CEO in... ever? I'm not sure actually.
- ryandrake 10y ago> I would never use a service run by Marissa Mayer again. Surprisingly, stacks of $100 bills make great mattresses. She won't lose a night of sleep.
- meowface 10y agoI'm not remotely rich, but I feel like after a certain amount of wealth, personal and professional reputation (and the success of things you control) matters much more to your overall happiness and well-being than your net worth. I suspect she's not had a good year, from her perspective and for the people around her.
- vermontdevil 10y agoNow gotta wonder if Google has succumbed to government pressure to do the same. I'm really hoping and trusting they haven't.
- finid 10y agoAt this point, it's save to assume that NSA/FBI/CIA/Pentagon has front door access to Google. That cheap-oil-for-your-private-planes deal with Pentagon is one small evidence [1]. The other is Matt Cutts working for (on a temporary basis) the Defense Department's branch of USDS [2] [1]: http://www.wsj.com/articles/SB10001424127887323864604579069730686941454 http://www.wsj.com/articles/SB100014241278873238646045790697... [2]: http://fedscoop.com/former-google-spam-chief-heads-to-usds http://fedscoop.com/former-google-spam-chief-heads-to-usds As for Microsoft, well, no debate there.
- magicalist 10y ago> That cheap-oil-for-your-private-planes deal with Pentagon is one small evidence a perk they apparently shouldn't have been getting and was cut off by the pentagon is evidence the pentagon has front door access to Google? > The other is Matt Cutts working for (on a temporary basis) the Defense Department's branch of USDS What, do you think he really needed a job so the web search spam guy gave access to user accounts in exchange for getting to work in government contracting? Really need to work on your circumstantial evidence.
- MrZongle2 10y agoConsidering the amount of access they have to the White House: why would you assume that they haven't?
- lallysingh 10y agoThe white house is above the NSA and FBI, so wouldn't access to their bosses preclude them being coerced?
- 10y ago
- cheeze 10y agoCan we merge https://news.ycombinator.com/item?id=12637302 https://news.ycombinator.com/item?id=12637302 into this? Same exact headline
- DubiousPusher 10y agoI think the attitude here that most tech companies are rolling over and just complying without a single ethical consideration is misplaced. The government has been doing an excellent job of basically extorting these companies into compliance. They threaten the full weight of the US government's wraith and then tie every order up with classifications and gag orders. You aren't legally allowed to talk to other companies in the same position. Most your legal team probably doesn't get to know what's going on. You can't take your case to the public without being held in contempt. I'm not giving these companies a complete pass for being complicit in the erosion of individual's civil liberties but treating this as if the decision is easy is vastly unfair.
- idlewords 10y agoThe most damning part of this story is that Mayer decided to comply without telling her chief security officer. That really does make it look like Yahoo rolled over without a fight.
- lawnchair_larry 10y agoSince it had a gag order, she likely wouldn't have been allowed to tell him. The government doesn't care about the security implications of these backdoors, they just want the data. Also, Yahoo spent many years fighting similar requests (I think before anyone else did) and won nothing. She also was obviously being advised by Ron Bell, the GC. If she didn't tell Stamos, it was probably based on the guidance of Mr. Bell. I'm not sure we can fault Mayer much on this one.
- NetStrikeForce 10y agoShe's the CEO, she gets paid to be responsible for everything at the company. Of course she is at fault.
- tptacek 10y agoKnowing Stamos' background, it's possible that she was specifically required not to tell him.
- singularity2001 10y agoGoogle overtly scans your emails for anything.
- 0xmohit 10y agoPerhaps you are forgetting Google Now [0]. Google Now displays cards with information pulled from the user's Gmail account ... [0] https://www.google.com/search/about/learn-more/now/ https://www.google.com/search/about/learn-more/now/
- panarky 10y ago> Google overtly scans your emails for anything This is a common argument here. "Company A secretly collaborates with government agency to subvert their users' security." "Yes, but Company B collects user data for their own commercial purposes, fully disclosed to the user. Same thing." Not the same thing.
- kefka 10y agoLets take it a different way: You're knowingly sending your data to a 3rd party. You're not encrypting. It's not through the USPS (special protections). It seems bloody evident that, of course, your email provider can read your emails! Unless you're encrypting with GPG, then they can (and they can still read the signing keys). Yahoo, Google, and friends all scan, dedup, and all sorts of tricks to determine marketing and quality content (spamming). If you're worried, run your own mailserver. It's what I do, along with using gmail. But I know that, at any time, people/scripts/ai are reading everything sent and received. edit: I'd much prefer to hear commentary/how wrong/how right/how crazy I am, rather than -1's.I'd like to hear a discussion about the "Secrecy of text written on postcards"....
- peterkelly 10y agoI've upvoted you, despite disagreeing with you, because I believe it's worth us all discussing the reasoning behind our opinions. What you've just said is the email equivalent to "she deserved to be raped, because she was dressed like a slut". Yes, we should take precautions to protect ourselves. But that in no way justifies the privacy intrusions that happened here.
- Redoubts 10y agoI think it's closer to "you deserved your message to be read, since you put it on the back of a postcard". But ok.
- morganvachon 10y agoThis. Email messages are digital postcards. When it leaves your computer (house) and goes to your ISP (local post office), anyone at that place can pick it up and read it before sending it on its way to the recipient's mail handler. While it's in transit, it's not sealed, it's not obscured or encrypted, it is plain text. Now, that doesn't change the fact that Yahoo rolled over like a puppy when the government came calling, which is reprehensible for any tech company to do. They should have fought it and asked for a warrant for the specific persons of interest, rather than happily fucking over every single Yahoo email subscriber.
- 0xmohit 10y agoYahoo Inc last year secretly built a custom software program to search all of its customers' incoming emails for specific information provided by U.S. intelligence officials, according to people familiar with the matter. Wonder how much of the 4.8 billion can be attributed this custom software program?
- AnimalMuppet 10y agoFrom the article: "Some surveillance experts said this represents the first case to surface of a U.S. Internet company agreeing to a spy agency's demand by searching all arriving messages, as opposed to examining stored messages or scanning a small number of accounts in real time." The first case to surface. Anybody else could have been doing it for just as long, but we don't know yet.
- rdl 10y agoI was honestly a bit unhappy when Stamos left Yahoo in the middle of a bunch of (what seemed like) cool projects for users -- seemed like he was just jumping ship from an objectively pretty crappy company to a continuing-to-accelerate rocketship, presumably for career reasons. However, if it went down like this -- he did probably the least destructive thing possible. I probably would have gone public or done something stupider, but at the very least not being a party to ongoing abuse of users' trust is necessary. I'd like to see what other senior execs at Yahoo! were aware of the program and supported or at least tolerated it, so I can avoid ever working with any of them.
- zmanian 10y agoThis should forever taint Marissa Meyer's reputation. Failure to save Yahoo is understandable. Disregard for user privacy and safety at this scale is unforgivable.
- utefan001 10y agoDon't forget this story. Qwest CEO Joseph Nacchio who <edit> claims to have </edit> resisted NSA spying is out of prison (2013) https://www.washingtonpost.com/news/the-switch/wp/2013/09/30/a-ceo-who-resisted-nsa-spying-is-out-of-prison-and-he-feels-vindicated-by-snowden-leaks/ https://www.washingtonpost.com/news/the-switch/wp/2013/09/30...
- tptacek 10y agoNacchio is no hero. He ran a $50MM pump-and-dump scam that personally netted him millions of dollars in profits at the expense of common shareholders, and he was indicted in a wave of similar prosecutions in the wake of the Enron fiasco. His offenses are there in black and white: with full knowledge that his company faced materially adverse changes unknown to his investors, he not only promoted the company but privately (and illegally) sold his own shares. You do people like Stamos a huge disservice by drawing this comparison. People like Nacchio are exploiting the good work real privacy advocates do, for their own personal enrichment.
- floor__ 10y agoBooooo
- sctb 10y agoPlease comment civilly and substantively on HN or not at all.
- JustSomeNobody 10y agoLet's see a show of hands for those who think Yahoo was the only one?
- johansch 10y agoSo, is this correct, in this context? Pass: Apple, Google Fail: Microsoft, Yahoo Unknown: Facebook, Twitter
- tptacek 10y agoFail: Microsoft?
- johansch 10y agohttps://www.theguardian.com/world/2013/jul/11/microsoft-nsa-collaboration-user-data https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...
- tptacek 10y agoAh, right, of course. Thanks!
- chopin 10y agoMicrosoft has totally crushed any confidence in automatic updates. That would be enough for me to count them in. Why again should I trust them? I liked Windows 7. I set up an AD domain at home to use it. Now I feel forced to move to Linux.
- zzzcpan 10y agoGoogle is definitely in cahoots with the government and probably way deeper than Yahoo. Why would you even assume otherwise, given how much ties to the government they expose to the public these days?
- bitmapbrother 10y agoWhy would you assume they are? Do you have any proof to backup your theory? And try to provide actual proof.
- 10y ago
- Esau 10y agoThe lesson from this is to not trust corporations with out privacy. Sadly, it seems many of us are not learning it.
- zzzcpan 10y agoWould it even be possible to make similar, but privacy centered products without corporations?
- deleted 10y ago[deleted]
- dredmorbius 10y agoThat's what Free Software is about. And it does. The problems are of establishing protocols and standards, and seeing that others adopt them, and of creating self-contained systems that are bulletproof to set up and operate. There are projects working on this, but the hurdle for having Joe Random User operate their own server is fairly high. I'd much rather see a highly, but not entirely distributed system, with pervasive security, and very strong legal protections. I don't know if that can happen.
- mason240 10y agoYes, it's totally the fault of tech companies that the US Federal government forces them to give up access to any information they want, and a non-profit email org would immune US intelligence agencies. /s
- mirimir 10y agoWell, Sigaint is rather immune to this, no? The US government arguably doesn't know where its servers are located, or who operates them.
- lkbm 10y agoNon-profit is not the opposite of corporation. In fact, most non-profits are corporations. The message is obviously to control your own security to the maximum extent practicable. Esau didn't assign fault in their comment. You might disagree with their assertion, but your comment is attacking a straw man, rather than the claim posted.
- ChicagoDave 10y agoI find this hilarious since the only thing I use my yahoo address for is retailer sign-ups and things I know will land me a boat load of junk mail. It is my email landfill.
- rdiddly 10y agoLikewise, although I refer to it as my spam storage.
- josh2600 10y agoI mean, think about the threats from .gov, right? $250k per day doubling every week that can come with a gag order sounds like the sort of thing that could damage a business to the point of extinction, no? https://www.theguardian.com/world/2014/sep/11/yahoo-nsa-lawsuit-documents-fine-user-data-refusal https://www.theguardian.com/world/2014/sep/11/yahoo-nsa-laws...
- Zigurd 10y agoSome people here laud some companies for being good about user privacy and security. This shows they have not yet reached table stakes for privacy and security. This is why no provider can be trusted. Every routine communication should be e2e encrypted. Otherwise this WILL happen.
- josho 10y agoThis is where I remind everyone about S/MIME. A bit awkward to setup for the first time, but with good email clients it is a pretty transparent experience once you have it setup.
- Zigurd 10y agoThat's good, but the correct response from the big internet services/portals should be to make it impossible to comply with such a request without an obvious and public withdrawal of service. And, beyond that, to use their resources to make key exchange and management simple and secure (they do that in some real time communications products) for storage and email. They have your social graph, they can implement web-of-trust features. They can made it both simple to use and exceedingly difficult to subvert. They can provide secure, open endpoint software. They can effectively end dragnet surveillance by providing a refuge from it, AND make burdensome and credibility-destroying requests/orders impossible to implement. And all these years after Snowden, they have not.
- pkaeding 10y agoYahoo was attributing its recently announced data breach to state-sponsored attackers.... Maybe that wasn't so far off the mark after all.
- zmanian 10y agoThis is substantially worse than PRISM which operates on individual targeted persons and the upstream Verizon, AT&T program which collects plaintext over the public Internet. This involved bulk search of data past the decryption layer.
- suprgeek 10y agoThe scariest part of the whole piece answers this question: Why are back doors with secret keys a BAD idea? "... he had been left out of a decision that hurt users' security, the sources said. Due to a programming flaw, he told them hackers could have accessed the stored emails...." The CEO of Yahoo must have known that this kind of scanning and storage puts their users at risk. She choose to do it anyway as being the path of least resistance against a more powerful adversary (US govt.). Bad judgement compounded by zero spine... Verizon looks like the perfect fit.
- markpapadakis 10y agoI imagine Yahoo! Mail engineers being royally pissed about this. Well, I suppose that includes all Yahoo! folks who are still putting real effort into improving Y!'s services. Every odd day something surfaces about Y!'s execs questionable practices and decisions, every even day problems, leaks, bad press. Moral must have hit rock bottom. Maybe the Yahoo! Board should have surveyed the startups scene, looking for founders who bootstrapped successfully and proven their worth, and recruit the best they could get. I am not very familiar with management of people and aspects of running a business, but I believe there is a lot more to it than being a smart person with computers.
- matt4077 10y agoYou may have missed the part where Yahoo engineers implemented this scheme, they are to blame as much as management here, possibly more because they could've walked away and gotten a different job without much trouble, but management had a responsibility to the whole organization. Contrast with the rumors that Apple engineers were prepared to refuse & resign if ordered to share the iPhone's encryption keys.
- codedokode 10y agoWhy should they lose their job and salary to defend someone else? Yahoo users can go to court themselves if they feel that their rights were violated.
- generj 10y agoYahoo users can't go to court if they can't prove their rights were violated. Even with this news story there is no court-admissible evidence of collusion with the government. Also, from the perspective of a civil suit against Yahoo, this program is likely somewhat legal unless it was specifically against their privacy policy and terms of use. That doesn't mean the engineers knew they were performing unethical behavior. A better question is: why should anyone hire someone who aided unethical behavior?
- 10y ago
- zmanian 10y agoSecret URL for deleting your Yahoo account. https://edit.yahoo.com/config/delete_user https://edit.yahoo.com/config/delete_user
- awqrre 10y agoDo you seriously think that it is better elsewhere? I think that the NSA and the FBI are out of control...
- faktorialas 10y agoOf course it's better elsewhere. Many companies are not under US authority. Many provide better security features. Many are not known for having terrible security, or the biggest breach of user data ever. IIRC, Yahoo has always provided more data not even because they shared it, but because they were so lax with security.
- Tepix 10y agoConsider setting up your own mail server. Decentralization is the most effective way of fighting this. Rent a cheap, dedicated server (a VPS provides poor privacy protection), encrypt the root partition and install sovereign (https://github.com/sovereign/sovereign https://github.com/sovereign/sovereign).
- throwawayReply 10y agoAnd (sadly) watch as all your outgoing mail is refused from most mail providers.
- Tepix 10y agoI have been running my own mail server for more than a decade now and haven't had that problem. If you rent a new server check its IP against the RBLs to see if its burned. If it's bad, request a new IP from your ISP. Other than that, adhere to industry best practices and you're good.
- honyock 10y agoThis is not at all surprising! BTW, I don't know a single person that has an email account with yahoo, who is not older than 60!
- En_gr_Student 10y agoIt was part of carnivore and AT&T also supported that. I'm pretty sure all major vendors had hooks into their systems for carnivore.
- thwee 10y agoIt should read "...Yahoo Chief Executive Marissa Mayer's decision to indulge the directive..." indulge, not obey.
- lifeisstillgood 10y agoAnd it did not find any :-) !!!
- yladiz 10y agoWhile it is damning that Mayer didn't go to Stamos about this and went straight to the email team, it's hard to say whether she felt it was necessary to tell him, or was even allowed to, since we don't see the court orders and what they entail. It's really easy to be against this and play armchair preacher but this is something she probably had no choice in, in many ways. Also, I'm wondering if this story is bigger because people love to hate on Mayer. I am certain this kind of thing happened/happens at Facebook, Google, Twitter, WhatsApp, etc., so it's confusing why this is so newsworthy. It's not really newsworthy that data from an email provider is sent to NSA under secret court orders and NSA can search the full text of it. Is the newsworthy part that she asked the team to do it without consulting the security team? My question would be, why wouldn't a manager from the email team consult the security team if they had the power to?
- sesqu 10y agoThe newsworthy thing was that this was a trigger word or similar ongoing filter that the surveillors wanted copies on sight of, and not a specific email account.
- lmm 10y ago> It's not really newsworthy that data from an email provider is sent to NSA under secret court orders and NSA can search the full text of it. It absolutely is newsworthy. We may have suspected it beforehand, we may suspect it happens at other providers, but we have specific proof about Yahoo now. This is new and important and we should be making a fuss. If we play the jaded cynic we are joining the enemies of democracy.
- yladiz 10y agoNo, we had proof back when Snowden released documents about the search engine that NSA has from data siphoned from providers. I'm not being cynical, I'm being realistic in that this isn't newsworthy now because it was extremely newsworthy when it first came to light a few years ago. I would rather this be newsworthy because it gets people interested in fighting FISC orders again, not against Yahoo and Mayer.
- cJ0th 10y agoAnyone remembers this? > Barack Obama: NSA is not rifling through ordinary people's emails. US president is confident intelligence services have 'struck appropriate balance', he tells journalists in Berlin edit: link fixed https://www.theguardian.com/world/2013/jun/19/barack-obama-nsa-people-emails https://www.theguardian.com/world/2013/jun/19/barack-obama-n...
- jamisteven 10y ago^This.
- mtgx 10y agoYup. So that's a complete lie now (not that I actually believed him when he said it then). When you searching through everyone's emails, then you're invading everyone's privacy.
- rando832 10y agoHe's a career politician, it seemed so obvious from the first day I heard him campaign that he was just telling people what they wanted to hear without any intention of implementing the details except for what is needed to keep up his reputation as he campaigns for his next term and then his legacy. It's the same thing from all the presidential candidates in recent history. The system is broken in some ways, and in some ways it's working ok.
- Magnets 10y agoI guess they are using the same justification as GCHQ; they use tools to scan everything and a human doesn't actually read ("rifle through") the majority of material. Is it still an invasion of privacy if a machine reads my emails? Google read my emails to check for spam.
- maxymoos 10y agoTo me, the main difference is that you know about Google's automatic parsing of your emails upfront and it can therefore be a factor in your subscribing/unsubscribing decision.
- deleted 10y ago[deleted]
- lasermike026 10y agoDistribute, encrypt, and anonymize. The only way forward doesn't include them. Congress is up for grabs. You can really change who is in congress this round. If you don't like the guy you have vote in another. Vote for people that want to cut surveillance programs and agencies that request them. We could save or reallocate mountains of money.
- l3m0ndr0p 10y agoThis is unfortunate and something that is very common with all of the companies in the USA. They must comply with the government in one way or another. If the people within the company refuse, they will be replaced one way or another. It's a sad fact that all of the major companies in the USA are spying or are complicit in the spying of all customers (both US citizen and not) Ever wonder why Microsoft constantly has holes/glitches/back-doors in all of its operating systems for so long now. They could build a very secure operating system. They hire the best minds, yet year after year we see multiple exploits and issues.
- deleted 10y ago[deleted]
- hackuser 10y agoNote the attitude toward encryption: Former NSA General Counsel Stewart Baker said email providers "have the power to encrypt it all, and with that comes added responsibility to do some of the work that had been done by the intelligence agencies."
- turc1656 10y agoThis shit needs to stop. Immediately. Like most people, I have no problem with the government using probable cause to get warrants that are in search of something specific (none of these grab-all bullshit orders). If you have a legitimate reason to be looking at someone, then there should be no problem getting a warrant. These secret FISA court orders are a serious violation to the rights of Americans in many cases. At minimum, if we really do need these secret courts to prevent people from finding out they are the subject of surveillance, then there needs to be an expiration on those gag orders. This crap about never being able to mention it FOREVER has to go. There should be a limit, say 5 years, which is well beyond the length of time most investigations take. At that time, those orders should expire so that these government actions can be brought to light if there is any question of wrong-doing on the part of our overzealous law enforcement. "Former NSA General Counsel Stewart Baker said email providers 'have the power to encrypt it all, and with that comes added responsibility to do some of the work that had been done by the intelligence agencies.'" Sorry, but no. That's not how it works. There is no obligation to do the work of government unless it is actually written into law (i.e. record-keeping laws). And it currently is not. This is precisely why everyone should be encrypting all communications on the CLIENT side themselves. It should never leave your device (PC, phone, whatever) unencrypted. That way, if the government wants to go on a fishing expedition or has an actual legitimate reason to look at you, they will have to get a warrant for the device itself, which will at least give you a head's up that they are trying to put you in the clink with a bunkmate named Bubba. The NSA, and the government in general, has completely blown any goodwill they once had with the public. Under no circumstance will I ever advocate for anything that makes their job easier. And it is for no other reason than simply because they have proven time and again they cannot be trusted. Honestly, I'm still not even clear why every employee of project PRISM isn't rotting a jail cell right now after Snowden shed some light on the program for the rest of us peasants. Every single employee of that program had to know the clear violations of the constitution they were helping to partake in. Keep in mind the constitution protects against unreasonable SEIZURE as well as search. Gobbling up communications in the manner they did clearly counts as seizure because they would not have had them otherwise - whether or not they actually search the records is immaterial. I'm not an Apple fan, but when they told the government to go pound sand regarding that terrorist phone encryption case, that was the first time that I can recall I actually approved of Apple's political position on something.
- _audakel 10y agoIf she had wanted to this to get out, I wonder if she could have ordered the email team to go ahead and build out the sniffer so she is not in contempt of the court, but let her security team openly blog about it, without informing her, when they found it - which could lead to an inadvertent release of the info? If the sec team was not under the gag order maybe they would not have gotten in trouble. Or take her to a super boss level, she could have used whisper to talk to guccifer and let him know about some vuln that would allow access to the legal directory.... which would have to gag order. #wikileakitup
- generj 10y agoThe security or email team could also blog about how to "hypothetically" implement real-time scan of email for keywords, and then stay mum about if they ever actually implemented something like their proposed program. Totally protected speech.
- jameshart 10y agoAny chance that this, and the recently announced historical account breach, are coming out as artifacts of Verizon's due diligence?
- Floegipoky 10y agoIgnoring fiduciary responsibility for a minute, what would happen if a publicly-traded company refused to comply with such a court order until they were required to release a financial statement? Wouldn't they be legally required to disclose that multi-million dollar fine? How would a company under such a gag order announce bankruptcy? "Sorry, we lost all the money and we can't tell you why"?
- awt 10y agoThat the usg attempted this is a sign of deeply seated incompetence at a philosophical level.
- trendia 10y agoIn China and Russia, it is well known that all oligarchs are corrupt. However, not all of them will go to prison -- only those who cross the politicians will ever be tried and convicted.
- dEnigma 10y agoWhich reminds me of this great passage in Atlas Shrugged: “Did you really think we want those laws observed?" said Dr. Ferris. "We want them to be broken. You'd better get it straight that it's not a bunch of boy scouts you're up against... We're after power and we mean it... There's no way to rule innocent men. The only power any government has is the power to crack down on criminals. Well, when there aren't enough criminals one makes them. One declares so many things to be a crime that it becomes impossible for men to live without breaking laws. Who wants a nation of law-abiding citizens? What's there in that for anyone? But just pass the kind of laws that can neither be observed nor enforced or objectively interpreted – and you create a nation of law-breakers – and then you cash in on guilt. Now that's the system, Mr. Reardon, that's the game, and once you understand it, you'll be much easier to deal with.” ― Ayn Rand, Atlas Shrugged
- CodeMage 10y ago"There are two novels that can change a bookish fourteen-year old's life: The Lord of the Rings and Atlas Shrugged. One is a childish fantasy that often engenders a lifelong obsession with its unbelievable heroes, leading to an emotionally stunted, socially crippled adulthood, unable to deal with the real world. The other, of course, involves orcs." -- John Rogers
- joeblow9999 10y agoDoesn't mean the quote isn't apt and good.
- fattire 10y agoIt's ridiculously bad mustache-twirling dialogue that compares poorly to the grunts of an orc.
- tkinom 10y agoSince all these companies (Yahoo, Google, FB, MSFT, etc) all operate and with users in other countries, what happen when other countries/governments demand the same "search/access" of info?
- CobrastanJorji 10y agoWell, if you're Google in 2010, the answer was "stop putting any servers in China, and accept getting blocked by China."
- jmadsen 10y agoI'm sorry, but have you used Yahoo Mail? I don't believe they are capable of writing the "siphon" they are accused of. To be honest, I don't think they actually have engineers. I think they just use summer interns.
- deleted 10y ago[deleted]
- Taek 10y agoAnother reason for users and enterprises alike to avoid US companies and services. And another reason for entrepreneurs to start companies outside the US - escape the stigma, escape the potential clash with secret courts.
- taivare 10y agoThis reminds me of what happened to my grandfather in the early 30's. He was employed by a small glassworks in PA, a factory town that owned his home, the town store, post office everything. They opened his mail and fired him for trying to start a union. Three kids under five and a wife thrown out on the street. Seems like the Oligarchs are still reading the spues mail all of these years later.
- feefie 10y agoIs this is the best solution? https://emailselfdefense.fsf.org/en/ https://emailselfdefense.fsf.org/en/ Getting anyone else I know to do this seems like a long shot. Is there something simpler?
- faktorialas 10y agoIM. Signal is, IMO, the most secure one that anyone's likely to convince non-nerds to use.
- dredmorbius 10y agoSetting up and using PGP personally isn't all that hard, though it's got a few twists. Above and beyond any learning-curve issues: 1. It doesn't protect metadata. Who you communicate with, and when, and what subject you specify, are all available to any system which can read the packets. Unless you only accept and transmit TLS (secured-session) transport (HTTPS), this means that your communications patterns are in the clear. If your receiving party are fetching messages via a cleartext protocol (IMAP or POP, say, and in some cases HTTP, rather than the secured variants IMAPS, POPS, and HTTPS), then the headers and possibly mail body will be clear. Cryptography has to be end-to-end to be effective, though attack surfaces exist at many levels. Ultimately the viewing device itself may be compromised, but that's a rather unscalable attack. 2. If you're using PGP but nobody else you're communicating with is then you're not gaining much. Keep in mind, I've been yelled at and/or chided by highly technical people with strong security backgrounds over sending PGP-encrypted emails. Including senior Google technical staff and Gene Spafford, of recent memory. Much of that is due to a wide range of email clients not playing well with PGP, which gets again to vendor issues. I recently posted a long critique of email on HN, and ultimately it's the lack of privacy, security, encryption, authentication, and reputation which make me think it's time to scrap it and start over, although learning from it and taking the best bits along. https://news.ycombinator.com/item?id=12620997 https://news.ycombinator.com/item?id=12620997
- cornchips 10y agoAny large company should openly defy such an order. What will they do??? Fine, court, shut down the company? If that happened would the public not outcry?
- exabrial 10y agoThanks Obama!
- ezoe 10y agoSo, when do Americans exercise the right of the Second and liberate from this totalitarian government?
- gjolund 10y agoGood riddance. I don't understand what is worth scavanging from the carcas.
- GirlsCanCode 10y agoToo bad Yahoo had a leader that was chosen because she was a woman, and not because she was qualified.
- deleted 10y ago[deleted]
- boren_ave11 10y agoFriendly reminder: the FBI and NSA are part of the executive branch of government and report to the President of the United States. Make no mistake -- there absolutely is someone who could stop this. The fact that this clearly unconstitutional activity not only continued after being exposed, but actually appears to has expanded in its scope, leaves us with but one conclusion: the President supports this activity and wants it to continue.
- j1vms 10y ago> (...) are part of the executive branch of government and report to the President of the United States. It's very likely, from what we have observed over the past sixty to seventy years, that the Executive Branch does not operate this way in practice. The actual bureaucratic system has probably morphed to allow for deniability and other measures that offer structural protection against political or legal attacks.
- boren_ave11 10y agoBut we know that he knows about it. Because he has talked about it. He once gave a speech specifically about government spying. Not only was the illegal activity not stopped, it expanded. There simply is no deniability left.
- Tepix 10y agoOr he is being blackmailed by an entity that knows enough of his secrets to destroy him.
- shostack 10y agoAh, I see you too read Influx.
- smsm42 10y agoMost illustrative part: "Yahoo President Marissa Mayer and the company's legal team kept the order secret from the company's security team." If you have to hide things from your own security team, it's pretty clear you're doing something very bad and you know it. And my imaginary hat off to Stamos for resigning when he found his boss betrayed user privacy and undermined security. If everybody had such level of integrity, doing shady stuff would be much harder.
- pseingatl 10y agoThey moved heaven and earth to try to find Snowden.
- zby 10y agoThe interesting part of the news is this: """ The sources said the program was discovered by Yahoo's security team in May 2015, within weeks of its installation. The security team initially thought hackers had broken in. """ this is from Reuters: http://www.reuters.com/article/us-yahoo-nsa-exclusive-idUSK http://www.reuters.com/article/us-yahoo-nsa-exclusive-idUSK I can imagine being in that security team :) But there is also something more profound in this about secrecy in our times.
- jokoon 10y agoTo be frank, the more I hear about those stories, the less I'm shocked. There is nothing to be shocked about. Unless nobody else than intelligence officials are getting access to this, and if the investigations are legit, then what? News like this are trying to ride the whole Snowden train, but that's not what Snowden what whistle blowing about. Snowden was trying to warn about the abuse of those tools. Now people moan and yell each time agencies try to do their job.
- Tepix 10y agoThis is not just another case of surveillance. This is a company betraying its own security chief and programming a backdoor to spy on its own customers on behalf of a bunch of agencies. It is unprecedented, overreaching and must not be tolerated.
- aszantu 10y agohaving my yahoo as spammailaccount for registrations, they probably scanned gigabytes of all sorts of stuff xD
- deleted 10y ago[deleted]
- ArkyBeagle 10y agoSo you really think that a free email service will "protect your privacy?" Any of them? Why would you think that? FWIW, SIGINT is a major part of the present festivities in the Woah on Terruh. It's simply unrealistic to expect anything transmitted through ordinary means to be remotely private.
- VOYD 10y agoTook them long enough ;)