26 ms·
Why We Can No Longer Trust Microsoft
- mtgx 13y ago> "With that said, do you really want to buy a Microsoft product? Do you want to buy anything that gives easy access to snoops poking around at their leisure? If you'd think twice about this, then why would a foreign government rely on Microsoft Office with any confidence? Personally, if I were any foreign government or corporation, I'd stop using all Microsoft products immediately for fear of America spying on me. Nothing can be secret." That's exactly what I'm hoping will happen. It may be the only way to actually roll back most of this shameless and abusive mass spying of everything and everyone. I'm not sure what else would stop it. Americans protesting it? I'm not holding my breath for that one, and even if they do, they'll only try to fix the spying internally, as they couldn't care less what they do to the world as long as the government keeps telling them "it's to keep them safe" (which obviously trumps everyone else' rights).
- josteink 13y ago> "With that said, do you really want to buy a Microsoft product? Do you want to buy anything that gives easy access to snoops poking around at their leisure? You know... Up until this whole NSA/PRISM thing got uncovered, Microsoft had actually rather successfully started to rebuild the perception and image of its cloud-service Azure. It had shown the world that in less than a year, it was well on its way to catch up with Amazon Web Services. It was going from an experiment to serious business. Something the company invested in. Even more so than the traditional parts of the business. As someone who once looked at Azure and laughed it off, I was coming around, actually considering it. I don't have any inside info on this, but I would guess/assume Azure was just about to take off. All those investments, finally about to pay off. Then the whole NSA/PRISM thing came about. Now there's no chance in hell I'm going there. Not that I expect AWS to be any better in that regard either. I'm currently pulling out my data from Google. I trust them even less. Hell, at this point, the only viable option privacy-vice seems to be open-source software, deployed by me, to an account I control, hosted on a service-provider outside the US's reach. It may not be immune to unauthorized, illegal snooping, but it will be off the main grid, take a bit more effort and it wont be done automatically 24/7. If I become paranoid enough to put in the effort, I'll just get a VPS instead and encrypt the shit out of it. (Disclaimer: Not a US citizen.)
- deleted 13y ago[deleted]
- twentyfourseven 13y agoExactly. Microsoft were making a comeback and I moved my email and online storage from Google to Microsoft. Now I feel back-stabbed. I don't use the hate word often, but I HATE Microsoft now. Just for the record, I think Dvorack is bang on with this article. Couldn't agree more.
- yuhong 13y agoPersonally, I would not go that far. I mean, what is the practical risk?
- acqq 13y agoThis is a financial disaster waiting to happen. Microsoft is oblivious if it is not doing something to divorce itself from the NSA. Apple, on the other hand, could have come out smelling like a rose, but following the death of Steve Jobs, who apparently refused to play ball with the NSA, it stupidly jumped on board to join the PRISM club. According to the Prism slides, it really looks so: "Dates when Prism collection began for each provider Microsoft 9/11/07 Yahoo 3/12/08 Google 1/14/09 Facebook 6/3/09 PalTalk 12/07/09 YouTube 9/24/10 Skype 2/6/11 AOL 3/31/11 Apple (added Oct 2012)" Steve Jobs: February 24, 1955 – October 5, 2011. If it's true, it's one reason more to deeply admire him. And can you just imagine how much more sales Apple would get now for not being on that list?
- tl 13y agoWell if we're going to randomly speculate on such things, Scott Forstall resigned on October 29, 2012.
- josephcooney 13y agoIs this just a function of the relative popularity of the services?
- mtgx 13y agoThat reminds me of Putin a little bit. Even if you think some leader is an asshole, sometimes you need an asshole to stand up to an even bigger bully. I just imagine someone like former president Medvedev (and with no Putin in sight) would've offered Snowden to US government on a silver platter, just like France, Spain, Portugal and Italy tried to do (fortunately unsuccessfully). I remember I was very much against Putin when he fought the US' anti-rocket shield, but over the past few years I've started to understand why he would do that. No country should own the whole world.
- fauigerzigerk 13y agoDon't mistake a former KGB guy's taunting for a principled stance. Here's how Putin deals with whistleblowers: https://en.wikipedia.org/wiki/Alexander_Litvinenko_poisoning https://en.wikipedia.org/wiki/Alexander_Litvinenko_poisoning
- polarix 13y ago"Microsoft is oblivious if it is not doing something to divorce itself from the NSA" No John, unfortunately it is not really an option to move 57,000 employees and a headquarters out of the United States. That is what would need to be done. None of the people making statements for these large corporations are lying voluntarily.
- ygra 13y agoI wonder how much pressure the NSA can and does exert on corporations that refuse to coöperate in this manner. And whether those on the list really had an actual choice in that manner. I guess a large government organisation has plenty of leverage if need be.
- yuhong 13y agoI think the FISA court order on Yahoo is a known example.
- deleted 13y ago[deleted]
- dendory 13y agoYou mean would the NSA bring up the CEO of the company on random charges after he says no, put him in jail, and get someone more agreeable to run the company? They've done it before! Look up Qwest.
- toble 13y agoIt's unfortunate that just when companies are considering bringing work on-shore again, that these reasons are starting to appear that encourage them to completely move their operations elsewhere. I am not sure where 'elsewhere' is at the moment though? Iceland?
- mikevm 13y agoDvorak's article is a regurgitation of previous HN discussions on this topic. I have said in the previous HN post and I will say it again here: don't pile on Microsoft alone. These spying policies make every US-based services company untrustworthy to whomever privacy is important. Come to think of it, I'm not sure whether you can rely on European services either because it seems that gov't surveillance is widespread. On the other hand, maybe if we do pile on Microsoft, and stop using their products for this reason alone (even though Google, Apple and others are in the same boat), it will force them and their lobbyists to influence their gov't shills to put a stop to these programs.
- yuhong 13y agoYea, remember that PRISM is designed to target foreign communications, so if you are an American, you might be actually safer.
- disputin 13y agoI don't follow US news - is that what they're telling the voters?
- yuhong 13y agoI think it is documented even in the leaked slides.
- mtgx 13y agoThat's kind of the same argument for European businesses and governments to not use Microsoft/American products. At least if they did it within EU, they would be accountable, and the laws prohibit most of it. But the US spying is unaccountable to Europeans, so they can do whatever they want. The only proper answer to that is to stop using American products (at least until the US government can prove with extreme oversight from Europeans and Latin Americans and others, that they aren't abusing their spying power anymore).
- ygra 13y agoOr they don't have to go to those lengths to intercept national communications ;)
- areski 13y agoLinux for all the things! That's the only viable solution
- rasur 13y agoOne wonders how tainted Linux is, if one considers systems including SELinux. Yes, I realise the point of SELinux is to make it more secure, but the association with the NSA (they created it) makes it very difficult to trust.
- klearvue 13y agoWhat can you possibly mean? It's open source i.e. code is available to anyone's inspection.
- blots 13y agoBut who does inspect it, not me for sure. So, how safe actually is Linux? And how safe is any distribution?
- reidrac 13y agoThe fact that it is available for everyone to inspect means it can be peer reviewed: http://en.wikipedia.org/wiki/Peer_review http://en.wikipedia.org/wiki/Peer_review That doesn't mean you're supposed to review it or that it is reviewed at all, but it is a requirement for the open source development model. About the Linux kernel, see this example: http://kernelnewbies.org/UpstreamMerge http://kernelnewbies.org/UpstreamMerge From Quality control section: "Some of the world's best developers will be going over your source code with a fine comb. This may be embarrassing for a few days or weeks, but in the end the code tends to work better and be more easily maintained. In some cases the upstream developers have made network and storage drivers 30% faster, making the hardware more attractive to customers."
- blots 13y agoIt's definitely better then not open source, but still I'd love to know more about those "world's best" developers and who pays them. Open source is the necessary but not the sufficient condition. It needs to be reviewed by independent people, otherwise the open source part is useless.
- LinaLauneBaer 13y agoA couple of years ago at a Linux conference in Germany I had a discussion with a Microsoft employee at their booth. At that time I was a 'hardcore' linux user with no trust in Microsoft at all. The discussion with the employee went like this: Me: "Hello. Could you tell me what Microsoft is doing at this Linux conference? I honestly want to know that." Him: "We are here to show how our products can work well together with Linux related products." Me: "Why would I as a Linux user use Windows or any other product from you? We all know that you spy on me - at least indirectly." Him: "Oh no. You are misinformed. We have a lot of business customers with very sensitive data. Can you imagine what would happen to us if they found out that we spy on them? Business users are very sensitive in that area. We were screwed. And we do not spy on regular users as well. You may also know that this would be totally illegal according to German law." Me: "So you are saying that you do not spy on businesses or other kind of users of your products?" Him: "Yes! We were screwed otherwise!" *giggle* He had a smile on his face for the whole discussion. Maybe because he had this discussion with those paranoid Linux users for the last couple of days of the conference. Paranoid! Microsoft is so screwed guys. Edit: I was not rude to this guy. We had a beer together later that day. I am sure he did not know anything about PRISM and was just doing his job.
- duiker101 13y agoTo me seems you were just kinda rude to some guy that was getting paid to do his job.
- quantumpotato_ 13y agoTo his job.. and lie?
- hkmurakami 13y agoA random Joe employee isn't going to know the details of a government backdoor (at least I'd hope so)
- robryan 13y ago
- dredmorbius 13y ago/me reads article. /me checks byline. Holy crap. Yeah, I remember when Dvorak was quite the Microsoft fanboi. My how times change.
- yuhong 13y agoI think he wrote about the MS OS/2 2.0 fiasco, including the unethical "Microsoft Munchkins" attacks.
- sounds 13y agoAny serious discussion of moving US businesses off Microsoft stalls when it reaches the "non technical" departments. I put "non technical" in quotes because many of the people in HR, Accounting, Marketing, etc. are very tech-savvy. Marketing folks, for example, would love an all-Mac office setup, but they generally have to have Windows PCs for Powerpoint, Visio, and CRMs, to name a few. HR needs their IE6 in-house apps. Accounting can't even hire anybody who wants to try getting their work done on a Mac. I realize I'm not even talking about Linux here; I think that just underscores my point. Does anyone have a counterexample? Because I would pay top dollar for a Linux solution to these problems, but haven't seen anything worth buying.
- Spearchucker 13y agoYour problem isn't technical, it's financial. Moving away from Windows and Office means converting all the organisation's documents to another format, re-training users in the new OS and productivity suite, re-writing VBA scripts (which often doesn't work well). Then you'd have to de-couple the entire organisation from Active Directory. And refactor (at best) or re-write (at worst) all custom in-house apps that rely on either Windows or Active Directory. It's just too expensive.
- TheAnimus 13y ago>I realize I'm not even talking about Linux here; I think that just underscores my point. I've seen about 10-20% Linux use and about 0% Mac use in industry (Finance - Buy and Sell side). YMMV. Linux is incredibly popular because people claim (rightly or wrongly) that they can have a lower latency setup. R-Project is very popular with people because they can have engineers customise it in ways not possible with Mat Lab. But at the end of the day it all falls back down to MS Excel. Apple don't have any enterprise ready tools for managing a system of 50,000+ client PCs and 30,000+ servers. So they don't get a look in, save the few iPads that are just perks and never used for any work that I've noticed.
- yason 13y agoUh, I might sound like a clichy old grumper but is this really any news since the 90's which is when Microsoft found the internet? It's practically been the operative description of Microsoft for decades that they're interested in profits (and potential profits in certain circles disjoint from the end users), not the privacy or security of their users.
- timbrooke 13y ago> Why We Can No Longer Trust Microsoft LOL. Who was dumb enough to have ever trusted them?
- ksec 13y agoTo be honest I dont blame too much on Microsoft. Being a business they needed to survive. It is not like they have a choice and government could very well bring another antitrust trial. Microsoft refuse to play balls to US government at first and they were nearly spitted into 3 different companies. So like any big cooperation they have to pay money for lobbying to buy them safety. And Microsoft is evil, I mean in Google's sense of evil and even Microsoft admit it. But What about the one who claim them self do no evil and itself being so righteous. Joined Prism on 1/14/09? And I would really love if the Movie could add bits on Prism agents coming in like some fucking retard, and Steve would tell him to Fk off. NewsPaper and Media, intentionally or not trying to diversify the hate and focus on PRISM away from Government. They are ultimately the one to be blamed.
- p37307 13y agoI think it is time to rethink everything, Not just Microsoft. Cloud computing is at risk now too. From Amazon to Google Drive, Gmail, etc. Shared hosting is not even secure any longer. Our connections from our isp can be the source of their spying. People want the ease of computing not secure computing. The polls show it. In the US everyone but the geeks are OK with the NSA. Sad. The system is going to have to change to federated data. Email, Social media, everything. Appliances owned by the individual. Either located in the home or small server appliances "rented" at a colocation facility and every user's info on their appliance. Any warrants are served to the individual not the "processing" or interpreting host that parses the data in their UI or service. The host, whether Facebook, Google, Yahoo, Microsoft, etc would notify the requester that that info is on a server rented solely by the user and they have no standing to grant or honor the warrant as they are the wrong party. Please note I use voice typing due to fine motor control and this comment may contain errors.
- igravious 13y agoI agree, something like this needs to be done. It will take a lot of work. I think the free software/ open-source movement is robust enough that we can turn our attention to this. Copyleft and free software licenses are social hacks that work in tandem with the free software model. We perhaps need a social hack to underpin this federated data model.
- deleted 13y ago[deleted]
- Fuxy 13y agoWindows should be banned in all countries except America. Open source OS is the only way to go. I'm not saying Linux since it's not exactly the most non technical friendly OS for people requiring more than basic usage but windows definitely isn't the OS for the future and it needs to die.
- deleted 13y ago[deleted]
- chii 13y agounfortunately, the inertia is too big for any single organization to stop. If you have a business selling software, it would be borderline insane to not target windows as a platform. You may target others, but you _must_ target windows, or basically, get no business. If, or when your resources are limited, you only target windows. So the problem is perpetuated - windows is the only platform that is basically guarenteed to have a market. So as a user of software, you'd stick to windows, and as a maker of software, you'd stick to making software for windows. Other platform is almost an afterthought. Unless web based software radically changes (i need to unzip a file - what web based software will do that for me?), this will not change.
- domdelimar 13y agoIf you upload a .zip file (don't know about the other formats) to Google Docs, it can access its content. There are probably other services/tools, because technically, there's nothing stopping you from unzipping files in the cloud, or in web based software. It's just the matter of uploading something and then downloading the content after it's been unzipped on the remote server. So it's just more expensive in terms of network traffic. The availability of the tools that do that, other than Google Docs, is another thing. Honestly wouldn't know, don't recall ever needing it before.
- nivla 13y ago>Windows should be banned in all countries except America. Open source OS is the only way to go. That is a very close minded way to look at things. Closed Source does not always = Evil and Opensource does not always = Secure. Competition and choices should always be sought for. Without competition, stagnation is as prevalent in open-source community as in closed source. I rather have the right to choose between a Mac, Windows or a Linux variant than someone making the choice for me.
- tigroferoce 13y agoSo, after SElinux, another big push form NSA to open source community?
- quackerhacker 13y agoI'm a fan of Steve Jobs and Bill Gates, so it's sad to see when a company's founder steps down. I feel like the ambition and drive sometimes disappear...then bottom line and dividends matter over pride.
- stinos 13y agorely on Microsoft Office with any confidence This seems to imply using Office, like in Word/Excel?, somehow poses a privacy risk. Is that true? And how exactly?
- Fice 13y agoNo longer? Like if there were not enough reasons not to trust them (or any other proprietary software vendor) before.
- xiaoma 13y agoThis reminds me of Ken Thompson's famous Turing Award paper from 1984. In that paper, he described a malicious compiler that added security holes to properly written C programs. The real question isn't about whether you can trust Microsoft. It's can you even trust Intel? "The moral is obvious. You can't trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well installed microcode bug will be almost impossible to detect." http://cm.bell-labs.com/who/ken/trust.html http://cm.bell-labs.com/who/ken/trust.html
- skc 13y agoThe more interesting discussion for me would be around which large IT players we actually can trust?
- mbesto 13y agoMicrosoft, despite denials, appears to be in bed with the NSA. Apparently all encryption and other methods to keep documents and discussions private are bypassed and accessible by the NSA and whomever it is working with. With that said, do you really want to buy a Microsoft product? Notice the words appears and apparently. Until there is specific evidence to take those two words away from those sentences, hardly anything will change.
- 69_years_and 13y agoI don't think native MS apps running on a local machine are a risk, I imagine (with a little nieviety) that if MS apps/OS were phoning home on a regular basis with the content of ones documents - someone would have noticed and raised a flag (or did I miss it). Nor is exchange BCC a copy to the NSA - again someone would have noticed. Cloud services excluded. PS. It's *buntu that spins my propeller. PPS. I'd be interested in what RMS has to say, not just about MS in this case but the whole PRISM/NSA thing in general - he has been warning us.
- MSvsGOOG 13y ago>Nor is exchange BCC a copy to the NSA - again someone would have noticed. True, but what about Windows Phone vs. Android (with Google's apps, not just a FOSS build like Replicant) vs. Apple? Which is the lesser evil for your privacy?
- 69_years_and 13y agoAh yes, well - OK I'd be thinking, given recent history, Windows Phone would be high on my list of most likely to be evil, but in the back of my mind is always, its the carrier that holds the cards there. But u have a point I had not considered - the mobile arena. What one would you consider the lesser evil?
- marcosdumay 13y ago> Which is the lesser evil for your privacy? Cyanogen.
- MSvsGOOG 13y agoWith Google's apps? I've already mentioned Replicant (http://replicant.us/ http://replicant.us/) in my original post. Replicant is a fully-FOSS Android distribution based on CyanogenMod.
- belorn 13y agoWindows natively has several data collecting operations on any machine with Windows installed. Each time you visting a page, IE sends the URL over to be "checked" by Microsoft. Each update, a summery of all installed packages are collected and sent to Microsoft in order to "improve the experience". WAT collects your hardware specification, including the serial number of your hard drive. Each time you connect your operative system to the Internet, it calls home to a Microsoft server to check if the connect works. Its doubtful that they throw away the logs from this. Microsoft can forceable push new executable code as updates, regardless if settings has turn of updates. Microsoft word (and Outlook?) do also collect information, but it is supposed to be optional. I don't remember if its on by default, but I am rather sure it is. Then we have semi-native application such as massager or skype. Both has messages being "scanned". Some of the sources: https://office.microsoft.com/en-us/word-help/privacy-statement-for-microsoft-office-2013-HA102750383.aspx https://office.microsoft.com/en-us/word-help/privacy-stateme..., http://redmondmag.com/articles/2010/07/01/what-does-microsoft-know-about-you.aspx http://redmondmag.com/articles/2010/07/01/what-does-microsof...
- jrabone 13y agoBut WHAT, exactly, can't we trust? I've seen NO technical detail to any of these discussions, yet there are a number of sub-systems that might be compromised: - low-level crypto APIs (the 'DLLs' referred to obliquely in the article); these are more interesting. I imagine they could be compromised for weak session key generation or other leakage of key / plaintext, or generate the session key in such a way that the mythical 'NSAKEY' can decrypt it. Huge impact, if so, but only to certain software; AFAIK Mozilla doesn't use the Windows crypto API / certificate key store (but Chrome does). - SSL certificate generation (built-in CA for Windows Server builds); certificates stored and replicated via Active Directory; does anyone actually use this? In fact, does anyone actually use client SSL? It is likely also used for domain peer replication, which could potentially be over an external network (but why would you not use a VPN there?) - Encrypted File System; already contains an escrow key-recovery mechanism to allow administrators (including domain admins) to recover a lost user key. Only likely to be relevant if hard disk or backup images seized, so less impact. - BitLocker drive encryption; similar to EFS but uses a hardware TPM and is per-machine rather than per-user. Fairly sure escrow key recovery at the domain level is possible here too. Again, only likely to be relevant if hardware or backups seized. - Office document encryption; did anyone SERIOUSLY think this was worth using anyway? There are so many key recovery services out there for this (Elcomsoft et al) - Communications applications (Skype et al); again, did anyone SERIOUSLY think this wasn't already being monitored, even before Skype became a Microsoft product? - Some other OS-level 'phoning-home' behaviour. I simply don't believe that no-one has spotted this happening, if it's there - we can do traffic analysis too, and there are plenty of people running Wireshark on their own networks.
- flyinRyan 13y agoHow do you know Wireshark isn't compromised? Further, MS does phone home all the time to check for updates and so on. If something extra was hidden in there would we know?
- jrabone 13y agoBuild it from audited source? As for updates, I imagine if you set up a domain you can run your own WSUS update server, MITM the connection, etc. - and then compare the behaviour with a "regular" home PC. The problem really is how deep the hole goes - as per Ken Thompson "Reflections on Trusting Trust", 1984.
- mathattack 13y ago"So the first news I see regarding Microsoft today is that Ballmer refuses to talk about the company's wearable computing strategy. My first thought was, "This is its priority? Wearable computers? So it can spy on your day-to-day activities?" The next story I read was about how Microsoft is going to reshuffle the organization, which prompted me to wonder, "Re-org? Why? So it can put some intelligence agency folks in charge?"" Seems like Microsoft has a lot of issues to worry about. Doing a reorg when the company is struggling just to put an agency person in charge seems like a lot of work. Why not just put them in charge in a small internally announced move?
- xradionut 13y agoTrust or not, I'm still writing code today for the 95% of people that are running Windows and Office. The irony is that the code interfaces to PGP/GPG...
- jpkeisala 13y agoActually, why nobody mention anything about Intel and Cisco? I would image it would be much more effective to build backdoor to network appliances if you want to spy someone.
- rbanffy 13y agoTrue, but if the network traffic between you and, say Office 365, is encrypted, the NSA would need to decrypt that. It'd be so much easier if Microsoft just handed over the actual, unencrypted, files. I can easily imagine the NSA login screen for Microsoft's PRISM interface with a "Yes, I have a proper court order" checkbox under the password field.
- abdel 13y agoI don't remember last time I used bill's products.
- JohnLBevan 13y agoWhen a company does what's asked of it by a government and people are upset with the company something's seriously wrong. A company's main priority is typically to make money within the bounds of the law. A government's should be to improve the quality of life and uphold the moral values of its citizens. I have a feeling had Apple been first on board rather than last the journalist would argue that Microsoft were evil for not complying with a government request and that Apple clearly had the vision to help the nation's security, but maybe that's just me?
- rmk2 13y agoBe that as it may, I cannot change your government. I can, however, stop relying on any of the companies who are complicit in spying on me. The problem here is the divide between national government and international corporations, where the corporations' actions influence far more people than the direct actions of the national government. I cannot exert any influence over a government that isn't mine, but I can decide which companies I support and entrust with my data and business. Your dichotomy of government vs company is therefore not correct. I can (and should) be upset about both.
- JohnLBevan 13y agoFair point well made. Opinion updated.
- genwin 13y agoHopefully in your thinking there's some limits to what the company would do when asked of it by the gov't. For me it would be anything obviously against the spirit of the Constitution.
- JohnLBevan 13y agoAgreed. My argument was that the government asking the company to do something immoral would be more of a concern to me than the company doing it, since the government is supposed to hold a position of trust with its society whilst the company is generally assumed to represent its owners and/or investors interests.
- leopoldfreeman 13y agoThe reason is obvious in China. Google is blocked by GFW, but Bing is not. So, there must be some dirty business between Microsoft and government of China. If Microsoft can do this in China, they can do this anywhere, even in USA.
- nivla 13y agoSo isn't DuckDuckGo but that doesn't mean anything. Maybe Bing and DuckDuckGo isn't used enough to catch the attention of Chinese officials.
- prewett 13y agoThe dirty business is that Microsoft is willing to cooperate with the Chinese government and censor its search results. Google publicly pulled out of China precisely because it was unwilling to do that. Even so, China did renew Google's Internet license, and they do run ditu.google.cn (un-offsetted maps, possibly only accessible from within China). Google is not actually blocked by the firewall. Gmail is slow, occasionally lots of dropped packets, and other passive-aggressive behavior, but not blocked. Search generally works ok, unless, say, you are a tourist searching for information about a certain popular tourist destination in the center of Beijing. Groups, Docs, and other free exchange of information services are blocked, though.
- leopoldfreeman 13y agoCensor its search results? You mean Microsoft cope with the government to filter the result. Great! Today they filter the results. Tomorrow they will share the user data with government. You are right, Google is not actually blocked by GFW. If you search something the government think it's sensitive (just they think), they will block you from Google for serveal minutes. After that, you can connect to Google again. I say, what the hell is that? Fuck the government.
- josteink 13y agoSomeone on reddit asked a very interesting question with regard to all this information about US snooping... What about UEFI? Should that be assumed fundamentally insecure from this point on?
- joshuaheard 13y agoThe same thing is happening at Facebook, Google, Yahoo, and other tech companies. Why single out Microsoft?
- josteink 13y agoBecause statistically unless you're in a clear minority, Microsoft makes the OS which you do all your work and process all your data on. It's sorta a big deal.
- rxp 13y agoSure, but all the leaks so far are about cases where your data is already going through Microsoft services. If there were any evidence that there was a backdoor in Windows itself, or in any Microsoft software, then you'd have a point.
- bradbenvenuti 13y agoThe fact that the url of this article ends in .asp kind of makes me laugh a little. Although I would love to see movement away from Microsoft products, its clearly much more difficult than the article makes it out to be.
- puma1 13y agoI don't think any large company has any choice in the matter. And this article targeting Microsoft. Apple is doing the same exact thing, who cares if they signed on afterwards? All the major tech companies are, and no one is going to stop using any of them. Get real.
- cs702 13y agoGNU/Linux, and Free software and hardware in general, look to be the BIG winners out of the NSA brouhaha, because all non-US governments, businesses, organizations, and individuals around the planet who need to safeguard their private or confidential information now have reason to mistrust proprietary (unauditable) software and hardware. Free, open software and hardware are less likely to have secret 'back doors' installed or embedded in them because their innards are under constant public review by multiple eyes -- out in the open, not behind closed doors. -- Edit: added last sentence.
- astrodust 13y agoMistrust of commercial solutions does not translate into trust for open-source ones. Have you audited the crypto code of all your packages? Would you even know how?
- Zigurd 13y agoWhich would you trust more?
- acqq 13y agoExactly. Even more interesting, all of the source code can be OK and just some subtle configuration tweaks can be enough to compromise you. Or just some build flag that you don't even see in sources. Often you don't know the build flags of every binary as soon as you use binaries. You also don't know if the compiler is tweaked to do some preprocessing you don't know about (see Reflections on Trusting Trust by Ken Thompson): http://cm.bell-labs.com/who/ken/trust.html http://cm.bell-labs.com/who/ken/trust.html For security conscious the prefect state is the OS which changes very, very slowly, fixing only security bugs and having binaries used by as many people as possible and which change so seldom that more people can even check them by disassembling them. You don't want to only check sources, you want to disassemble the binaries and decide if they match the sources. And only then you want to be sure that all configurations are what they should be. Not easy at all.
- dllthomas 13y ago
- TheCondor 13y agoHubris: http://m.youtube.com/watch?v=v_lrohZ_1rU&desktop_uri=%2Fwatch%3Fv%3Dv_lrohZ_1rU http://m.youtube.com/watch?v=v_lrohZ_1rU&desktop_uri=%2Fwatc...
- diego_moita 13y agoJohn Dvorak sounds like a tech version of those economic & political loudmouths that spread definitive and absolute truths with very little evidence (Rush Limbaugh, Bill O'Reilly, Ann Coulter). That's because their purpose is not to generate light but to generate heat; to cause controversy instead of inform. It is the journalism equivalent of the Rolling Stones and Madonna: scandal as a marketing tactic. These people remind me of the Austrian writer Karl Kraus: "The secret of the demagogue is to make himself as stupid as his audience so that they believe they are as clever as he." The fact is that for almost all big corporations there is so much money, training and culture involved in MS platforms that a shift away from it is just to hard to do, unfortunatelly.
- mikegioia 13y agoNot all businesses are big corporations. There are a great number of small companies that can much more easily implement Linux for their employees to use. I think the point to be made here is that moving forward, (a) a lot of people can really do all of their computing on Linux now, and (b) an increasing amount of software is being written for the modern web so MS/IE lock-in is going away.
- pydanny 13y agoWait a second... they trusted Microsoft? ;-) Seriously though, if you don't play ball with the NSA, they come after you, your business, and your family with the full weight of the US government. Your wealth or status means nothing against it. Which means, as a parent, I can relate. Yes, you and I can sit here on my keyboard and say we would have stood our ground, but when you have a children and a mortgage, suddenly things are very different. Suddenly, you think that maybe fighting this one particular fight isn't worth the damage to you and your family. That, my HN friends, is why the whole NSA PRISM thing is so evil and why it outrages us: Even those normally beyond the law (the rich and famous) are suddenly victims like the rest of us.
- _ak 13y agoWe never really could. NSAKEY, anyone?
- rodolphoarruda 13y agoAFAIK, if you control the layer 1 fiber lines, it doesn't matter the OS, the vendor or the application in question. NSA will intercept your data while on transit. Of course, if you can have DLLs packaging everything the way you like, appending the right file extensions and cleaning all the metadata... that's more than welcome.
- robmclarty 13y agoQuestion: when did we start trusting MS that we now can no longer?
- ferdo 13y agoI want to know who trusted Microsoft to begin with.
- nfoz 13y agoSomeone trusted them before?
- j2d3 13y agoWe can no longer trust Microsoft? Crazy. I've been trusting Microsoft all this time, and now, what to do!?!
- njharman 13y agoTrust no longer!? You shouldn't trust any corporation to do anything other than maximize profits.
- likeclockwork 13y agoWhen could we trust them?
- jmaddox 13y ago"Why We Can No Longer Trust Microsoft" Are you kidding when did anybody trusted microsoft.