5 ms·
Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions
by nkw 10y ago
Big corporations are, by definition, large complex organizations. There is legal, executive management, developers, ops, etc. Hypothesizing about their actions as a singular entity can over simplify things. I don't know about the specifics in the article, but as a general rule there are a number instances where an intelligence agency may approach only a developer, an ops person, or someone in legal to obtain what they want instead of showing up and serving the corporate entity with a NSL. Saying the organization as a whole could provide data exfiltration much more efficiently by other means, does not rule out the possibility that other techniques could be used instead for various non-technical reasons.
- linkregister 10y agoCan you give an example of one of these instances? I've heard of this sort of thing outside of the U.S. (James Bond bribes East German clerk to get the microfilm), but I haven't heard of domestic agencies doing this in the U.S. Isn't it already disclosed in the Snowden documents that Skype has received NSLs?
- nkw 10y agoHere is a recent article discussing the DEA doing this: https://www.washingtonpost.com/news/powerpost/wp/2016/09/30/want-to-make-a-million-become-a-dea-informant/ https://www.washingtonpost.com/news/powerpost/wp/2016/09/30/... $600k to a particular airline employee, $1 million for a single parcel worker (this was over a few years). Also there is the various NSA efforts to insert people into the encryption standards process, as well as use cooperative sources within companies to insert vulnerabilities in the commercial encryption systems: http://www.nytimes.com/interactive/2013/09/05/us/documents-reveal-nsa-campaign-against-encryption.html?_r=1& http://www.nytimes.com/interactive/2013/09/05/us/documents-r... Also the FBI/Yahoo email program was apparently done by just the CEO, a lawyer, and a few members of the email team. The security team wasn't informed, nor the board. https://www.theguardian.com/technology/2016/oct/04/yahoo-secret-email-program-nsa-fbi https://www.theguardian.com/technology/2016/oct/04/yahoo-sec...
- linkregister 10y agoThe DEA program is pretty shocking and a great example, thanks for sharing! The second one sounds more like an interdiction program, where vulnerabilities are inserted into the devices (this is a thing that was in the Snowden documents). The document gives no details. The highlights on the side are from an NYT journalist, not source material. I disagree that the last example is an example of that. It's still unclear what the scanning was doing.
- Spooky23 10y agoThe Yahoo thing is a huge deal. Email providers do interception all of the time and have strong procedural controls. The idea that people could bypass those processes and controls is a tremendous liability that no board would ever approve.
- __jal 10y agoNKW gave a nice summary of some recent actions. For more historical examples, I highly suggest any of James Bamford's excellent books on the NSA. _The Puzzle Palace_ is a massive tomb, but a very good read. I haven't had a chance to read _Shadow Factory_ yet, but it is in my pile.
- imglorp 10y agoFirst of all, Skype is Microsoft. Second, they're well known to collaborate already. If NSA wanted a Skype feed, they could have it server or client side. https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-collaboration-user-data https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...
- linkregister 10y agoThat collaboration looks like the same mechanism used to adhere to warrants, subpoenas, and NSLs. Do you think that any internet service in the world doesn't have similar mechanisms to comply with law enforcement requests in their home country? I think you are misleadingly using the word "collaboration". I also think you have failed to understand the article correctly; there is no reference to client side collection. Take another look.
- imglorp 10y agoAgreed. I'm just suggesting if someone were to ask for a client backdoor they could have one, just like they could ask for a server feed.
- jlgaddis 10y agoOriginally, and perhaps at the time this "backdoor" was created, Skype wasn't Microsoft. Skype was around for along time before Microsoft bought it and changed its architecture and design.
- toyg 10y agoThis. It could well have been a backdoor that predates the "superpeer" change MS introduced right after acquisition. Skype was already under pressure from European authorities at the time, to provide intercept capabilities; European criminal networks (mafia etc) were early adopters and everybody knew it.
- Spooky23 10y agoHow do you think that Juniper VPN compromise got inserted into the code?
- tptacek 10y agoYou didn't respond to the substance of his objection. The problem with the "NSA backdoor" hypothesis is that it doesn't make logistical sense: it requires the NSA to already have installed software on the victim's computer. If the NSA has installed software on your machine that it can control, you are going to, in the parlance of our times, "get Mossad'd".
- benevol 10y ago> it doesn't make logistical sense: it requires the NSA to already have installed software on the victim's computer. Well, if you have any of the closed-source companies' software on your system (and by definition, that is +/- 310mio citizens, in the US alone), you are sure to have NSA backdoors on your system. Such backdoors certainly do not require manual intervention for them to be exploited on large scale.
- tptacek 10y agoExplain?
- jonathankoren 10y agoNo one outside of the software provider can audited the code, and presumably even they haven't audited the code. Recently there was the source code backdoor that was suspected to had been placed inside Juniper routers by the NSA. If I remember correctly, it wasn't found because it was hidden on a high right column.
- simonh 10y agoThe Juniper backdoor was a bit particular in that it was known that the code in question had been developed and distributed by the NSA. It's more of a stretch to accuse every single vendor of proprietary code in the USA of building NSA back doors into their products. It would require the knowing assistance of tens of thousands of people across those companies.
- deleted 10y ago[deleted]