8 ms·
Microsoft helped the NSA bypass encryption, new Snowden leak reveals
- iuguy 13y agoThe sad thing about all of this is that Microsoft were pretty much forced into this position (so we're told) by the authorities. In the process these leaks have just destroyed pretty much any credibility Microsoft's online services had, which form large parts of their strategy (according to the recent Ballmer memo). It also makes you wonder about the OS and other software they produce, which isn't a good place for MS to be in.
- mtgx 13y agoOn what legal grounds was Microsoft "forced" to provide access to unencrypted data before encryption (effectively nullifying the security that they promised to their customers)? So how were they forced? Legally? Illegally/blackmail? CALEA seems to say that companies don't have to decrypt data for authorities. I guess it's very convenient that they give it to them before they encrypt it then: http://paranoia.dubfire.net/2010/09/calea-and-encryption.html http://paranoia.dubfire.net/2010/09/calea-and-encryption.htm... And this seems to be a "team sport", and that implies willing collaboration, not being forced to do it. More like something "fun" they're doing together.
- tzs 13y agoA company doesn't have to decrypt to meet their CALEA obligations. If CALEA is the sole legal authority for a particular communications interception, that would be the end of it. However, I've seen nothing that indicates that CALEA is the legal authority behind the NSA interceptions.
- fnordfnordfnord 13y ago>So how were they forced? Well, we can't really know (they won't answer FOIA requests!). We can only make guesses. Could be they were just asked. Western Union gave telegrams to the NSA just for the asking. Some people would argue that Microsoft has enjoyed favorable treatment by the courts. Maybe there was a quid pro quo somewhere along the way. NSA has strategically placed employees/agents in other companies. Why not Microsoft?
- mikevm 13y agoI'm not sure why you're picking on Microsoft. The credibility of pretty much every large US-based tech services company is probably destroyed. The fact that we only saw the big service providers (MS, Google, etc...) on those slides doesn't mean that the other companies are free from the hands of the NSA. Do you think that the NSA has no access to Dropbox?
- testing12341234 13y agoI'm not sure why you're picking on Microsoft. One of the key facets of the the Xbox One is the Kinect as an always on device. As another poster pointed out, Microsoft has been quick to answer the privacy related questions that have been asked about this situation with the claim that the system has been built with privacy as a focus. As such, the reliability of those claims in light of this new leak appears to be relevant. For example, given a court order, would Microsoft be required to: 1.) Provide law enforcement with Kinect data. (everything from as simple as "there were two people in the room" to "here is a live stream of the room" 2.) Be bound by gag orders not allowing Microsoft to reveal the existence of item 1. 3.) Be forced/coerced/enticed to provide bulk "wiretapping" of Kinect data. Additionally, there is the question of "expectation of privacy". Many of the current privacy laws are based on this concept. However, could the courts decide that there is no expectation of privacy when a video and audio recording device has been placed in a private area, with full knowledge of the owner, also with knowledge that the data will be sent to a third party? While these items might seem fringe (and before these leaks, I may have agreed), the scope of the current leaks seems to imply that these questions should at least be considered (even if a person chooses ultimately to accept the risk).
- brudgers 13y agoEnterprise relies on companies such as RedHat and Oracle to some extent in lieu of conducting code analysis and to certain types of security testing. It would be rather surprising if they were not at least approached by Federal agencies such as NSA and FBI. To put it another way, because Microsoft has a closed source model, the intelligence agencies took the approach described in the article. From that, it may be a mistake to conclude that the strategy pursued with Microsoft was the only strategy pursued. It just happens to be one that would pass across the desk of an analyst, rather than someone on the operations side. Viewed as an intelligence operation, it would be grossly unprofessional of such agencies not to have placed moles within the open source community, or for those moles to be seen as highly skilled contributors on open source projects. The three letter agencies have decades of experience infiltrating both commercial organizations and those motivated by something other than money. I suspect it is easier to turn an open source hacker than a diplomat - not just ideologically but because the open source community lacks a state funded organized counter-intelligence apperatus.
- JonFish85 13y agoI think it's wrong to say Microsoft was "forced" into this. In a sense, they made their own bed. I have to believe that the majority of Microsoft's money is based off of serving governments and huge corporations (Windows + Office). It just makes sense that they'll want to keep those relationships.
- Spooky23 13y agoIt's not in Microsoft's interest to function as defacto agents of the US government. They are compelled by law to do what the Feds want -- just like would would be if you we're providing a service. Think about the impact of the NSA leaks on Microsoft's business. Globally, every customer or potential customer of Microsoft needs to ask whether they can trust Micrsoft as a business partner. Not a good place to be on for a software company transitioning to a cloud services company.
- flyinRyan 13y agoGood. Big companies are the only thing in the US with even the remotest of hopes of stopping or slowing this down. And they're not going to bother unless it's actually costing them money. So I hope it hurts them, I hope it makes them and all the other companies bleed until they do something.
- nr0mx 13y agoPuts this in an entirely different light, doesn't it: Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was already, always listening. The idea that the Kinect might always be listening got people reaching for their tin foil or vowing to not let an Xbox One into their home. Microsoft is now seeking to calm concerns that the new Kinect might spy. "We are designing the new Kinect with simple, easy methods to customize privacy settings, provide clear notifications and meaningful privacy choices for how data will be used, stored and shared," the Microsoft rep told me. "We know our customers want and expect strong privacy protections to be built into our products, devices and services, and for companies to be responsible stewards of their data. Microsoft has more than ten years of experience making privacy a top priority. Kinect for Xbox 360 was designed and built with strong privacy protections in place and the new Kinect will continue this commitment. We’ll share more details later." http://kotaku.com/xbox-ones-kinect-can-turn-off-microsoft-says-noting-510100564 http://kotaku.com/xbox-ones-kinect-can-turn-off-microsoft-sa... Not sure I'd want the Xbox One in my house after this fiasco.
- seferphier 13y agoI agree. sadly, i doubt that many people would care about privacy concerns.
- eliasmacpherson 13y agoan always on microphone, with fixed hardware and software, phoning home at regular intervals has a big target sign painted on it.
- walls 13y agoYeah it's insane to think that anyone would own some kind of device that has a microphone and camera accessible by a third party, right? I mean what's next, they're going to make these things small enough that we can carry them everywhere?
- kirualex 13y agoWell that puts their whole "We don't exploit your data like Google do" into perspective.
- insuffi 13y agoI find it interesting that no USA-based news source is covering this.
- tzs 13y agoAmong US-based news sources covering this: The New York Times, NBC News, New York Daily News, CBS News, NPR, Chicago Tribune, ABC.
- insuffi 13y agoHuh. My apologies, for some reason the only sites google showed on this issue were .co.uk.
- sentenza 13y agoAre your google account settings localized to the UK? This issue used to regularly drive me crazy. Fortunately they now have a worldwide setting. At one point you could select only 5 (or was it 7?) languages for which Google would show you results. They fortunately fixed that. I mean, who would want to search _all_ the internet?
- mkhaytman 13y agoGoogle personalizes results quite extensively these days, largely based on your location. Google believes based on that, and probably your previous searching and browsing habits, that those .co.uk sites are more relevant to your interests. After all, this is the company that has patented and is developing the idea of "Parameterless Searches", where they assume what you want to know before you even ask... (more info http://www.seobythesea.com/2013/07/google-parameterless-searches/ http://www.seobythesea.com/2013/07/google-parameterless-sear...)
- anaptdemise 13y agoIt isn't on their front page...
- xedarius 13y agoThen I start thinking about when Microsoft were being dragged through the competition and monopolies commission in the US, was this the US Government showing Microsoft what would happen if they didn't cooperate.
- Sharlin 13y agoA half-serious conspiracy theory: The feds "encouraged" Microsoft to acquire Skype so as to obtain decrypted access to the communications.
- mafribe 13y agoSkype belonged to EBay before. But I agree, acquiring a global communication provider like Skype makes a lot of sense form a snooper's point of view.
- walls 13y agoIt happened before MS acquired them. http://www.networkworld.com/community/blog/project-chess-helped-nsa-snoop-your-skype-communications http://www.networkworld.com/community/blog/project-chess-hel...
- RexRollman 13y agoThis whole thing makes me very suspicious of Apple's and Microsoft's whole disk encryption technologies. I can't help but wonder if back doors have been inserted into the products.
- Osmium 13y agoNot impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of.html http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) (Edit: seems like this is not the case, see below) But no backdoor has been found (yet!)
- dmix 13y ago> 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) I'm curious if this could be addressed with software protections somehow? Something that triggers memory wipes and automatic shutdowns?
- anologwintermut 13y agohttp://www.intel.com/content/www/us/en/architecture-and-technology/trusted-execution-technology/malware-reduction-general-technology.html http://www.intel.com/content/www/us/en/architecture-and-tech... Though that specifically obviously requires hardware.
- dmix 13y agoIt seems that only protects against "pre-launch software" and BIOS level stuff. The scenario in question is for a live system where the disk is mounted and decrypted, with the OS running.
- FridayWithJohn 13y agoYet another reason to stick to open source.
- rimantas 13y agoOk, I have full open-source stack and run a cloud service on it. I also give NSA full access to my servers. How does open-source helps there?
- hypercube 13y agoWhy does the NSA have full access to your servers? Even if they manually wiretap your server it would require manual intervention, and is thus a good protection against blanket surveillance.
- a3n 13y ago"Why does the NSA have full access to your servers?" Because they ordered him to give it, and he elected not to go to jail.
- TsiCClawOfLight 13y agoHe means "how". Open-source protects against software backdoors (though obviously not against key-sharing et alii)
- throwit1979 13y agoWhat? Open source in a cloud service stack means that if the NSA thugs show up and order you to insert intercepts into your software on pain of being "disappeared", it's far EASIER to change the source and recompile than it is with proprietary software. rimantas is referring to using open source in a cloud service, not authoring and distributing it.
- flyinRyan 13y agoWhat are you talking about? Open-source doesn't protect against backdoors even theoretically. Think about it. Have you read every line of every piece of software you run? Would you understand it all if you did? Even if you read the source code, did you actually compile it all from scratch or did you use a binary (like virtually every single OSS user on earth)? Are you certain that the compiler you used wasn't compromised? How exactly?
- pavs 13y agoI feel so stupid and so ashamed of myself for all the time I have thought of everything Richard Stallman had to say about privacy and security concern as a "neck-beard, tin-foil hat, nutjob". He was right all along, it was us who didn't care enough to understand what he was saying and its importance.
- ds9 13y agoNo need to feel bad, I used to get a lot of snarking for being a Stallman fan. It is a basic principle of security to assume that any power an adversary has, will be used against one's interests. People misunderstand this; I have seen it called a fallacy. But it's not a claim that it's always true, rather that it's what one must assume in order to have the best practicable assurance of security /privacy. I also used to get arguments like "MS/GOogle/$_BIG_TECH_CO wouldn't use their power against customers, it would be bad for business" or "...it would be illegal" or similar. The correct answer is that prudence dictates assuming the worst. Well, maybe I was too cynical, but it's hard to keep up with how bad things really are.
- easytiger 13y agoHe was was some might call an extremist in his views. It is slowly becoming common sense. I guess that's why we see him as a visionary. He discarded many chances at fortunes to do what he believed to be right. Not many like that left. I know I sold out already.
- SonicSoul 13y agogoing to try for devil's advocate angle. could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption? it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head of the NSA at the time – deliberately violated the law to eavesdrop on Americans without a warrant" which hints at a vague conclusion that Microsoft is helping to spy on citizens without a warrant. possibly i missed something, so is the point that Microsoft (or any private company) should not do any work for NSA, or that it should not do it without a warrant, or that we can't trust it with anything because it did some work for the NSA? Or is that the details are still not disclosed so it's pure speculation?
- fetbaffe 13y agoIt is important for me as a customer of Microsoft. This means I will end all future contracts with them, because I'm not a US citizen. NSA needs no warrant to wiretap me as a European and I'm not going to send my money to Microsoft so they can use that money to help a foreign government agency , that I or any of my fellow citizens have no oversight over, to spy on me. That would be totally absurd.
- tootie 13y agoOf course. If you are a legitimate suspect, any local police department can get a warrant to go inside your house and put your underpants in plastic bags and take them away. For that matter, they can cuff you and put you in jail. The question is what is the NSA doing without a warrant or rubber-stamped, secret, blanket warrants.
- SonicSoul 13y agocorrect. i'm just having a hard time with the point (or lack there of) in this post.. as far as i can tell it's something like: NSA = PRISM, therefore any company doing work for NSA = evil.
- 13y ago
- Arnor 13y ago"It's hard to square Microsoft's secret collaboration with the NSA with its high-profile efforts to compete on privacy with Google." I think it squares quite nicely. Set your standards low enough...
- peteri 13y agoSorry this is news folks? Really? See this from 2011/12 from http://www.infolaw.co.uk/newsletter/2012/01/microsoft-office-365-for-lawyers/ http://www.infolaw.co.uk/newsletter/2012/01/microsoft-office... However, the Patriot Act, introduced to protect US national security, can require that any US company (wherever data is held) must disclose data on demand to the US Government without the knowledge of the owner of the data, which is contrary to the UK Data Protection Act. Microsoft has been up-front in acknowledging that they cannot give that guarantee and this applies to data held in all their hosted solutions. As a result, in December 2011, BAE ditched plans to adopt Office365 because Microsoft could not guarantee the company’s data would not leave Europe, in spite of operating a data centre in Dublin.
- tootie 13y agoWhat do they mean by bypass encryption? If I use outlook.com (or gmail.com or whatever) over https, then it's encrypted over the wire, but it's obviously decrypted on their servers. It's the only way that search could work. I assume if you are PGP encrypting your messages or something equivalent, it's still unbreakable.
- herf 13y agohttps://en.wikipedia.org/wiki/Telescreen https://en.wikipedia.org/wiki/Telescreen
- deleted 13y ago[deleted]
- geuis 13y agoMaybe I'm missing the source, but where's the source? These people keep writing stories about what's being revealed and "according to secret documents" this and that is shown. So where are these leaked documents? If these media outlets are holding on to them to dribble and drab them out to make a buck, there's a huge problem with that. Everything should be out on a torrent or wikileaks for all to see.