US government pushed tech firms to hand over source code
zdnet.com
zdnet.com
A spokesperson ... did not comment further on whether source code had been handed over to a government agency for any other reason. """
I'm glad the author pressed them further ("for any other reason"). So many times we see such statements like this from companies but nobody bothers to ask the obvious (to me) follow-up question.
Trying to list all the circumstances when the Feds get IBM source code, without having it look like the Feds just get everything, might be problematic...
http://www.zdnet.com/article/microsoft-opens-source-code-to-...
http://www.zdnet.com/article/does-microsofts-sharing-of-sour...
However, access to the OS source code does let people search for various yet-undiscovered exploits, and use them for evil.
If the agencies have private keys of the creators of your OS, who then signed the "signed updates" you've got?
Example, recently from Microsoft:
In their forums: "Is Update KB3103709 Fake?"
http://answers.microsoft.com/en-us/protect/forum/protect_oth...
On their site: " Try searching for what you need This page doesn’t exist."
So can the government force companies to assist them and to what extent? From the article it is suggested that Dell, Huawei, and Juniper have already done so.
But how where they compensated, because engineering time is not cheap, or where they given software backdoors and told to integrate them.
I don't think we will ever know. But would be interesting to know how managers had to explain to the bean counters, that limited resources was spent on project "top secret" instead of a real project making money.
They get paid. Telecoms do as well, they actually have billing schedules for wiretaps.
> ...managers had to explain to the bean counters...
You've got it backwards, the lawyers explain to the executives who then explain to the department head who then explains to a manager who then explains to a senior team leader who then assigns the work. At the end of the telephone game it looks like any other incomprehensible contract requirement.
However, it's a little funny that the US gov uses the Lavabit case as an example - Lavabit shut down to avoid giving it the key.
Who you believe is up to you.
https://news.ycombinator.com/item?id=9297787
You also didn't need the source code to find it; you could have found it with "strings".
>This is simply an unfortunate name. The NSA performs the technical review for all US cryptographic export requests. The keys in question are the ones that allow us to ensure compliance with the NSA's technical review. Therefore, they came to be known within Microsoft as "the NSA keys", and this was used as a variable name for one of the keys. However, Microsoft holds these keys and does not share them with anyone, including the NSA.
Wow.. How come nobody is bringing THIS up whenever the FBI tries to assure us that the bypass they want from Apple will never get leaked into the wrong hands?
[1] http://www.sidley.com/news/2015-12-14-investment-funds-updat...
Can always run linux and level the playing field.
That's why there's signing in the first place.