Keeping secrecy the exception, not the rule
blogs.microsoft.com
blogs.microsoft.com
I think we should also remember those that took a stand early and paid the price, such as former Quest CEO Joseph Nacchio who was run under the bus for not being an accomplice to the NSA [1].
Yeah, a link to one of Putin's propaganda sites. Stuff like that happens in Russia, but the following doesn't often happen here:
- Co-opt the SEC into bringing charges of financial fraud[1]
- convince a federal judge to go along with that, and convict him
- convince a majority of a US Appeals court to go along with that
Or, alternatively, and probably closer to the truth: Mr. Nacchio was convicted in 2007 on 19 counts of insider trading for illegally selling $52 million worth of stock six years earlier, after insiders warned him that Qwest could not meet its targets. [2]
Edit: even better than that was Nacchio's excuse. It's one for the ages: Nacchio claimed that he was not in a rightful state of mind when he sold his shares because of problems with his son, and the imminent announcement of a number of government contracts. [1]
[1] https://en.wikipedia.org/wiki/Joseph_Nacchio#Insider_trading... [2] http://www.nytimes.com/2009/02/26/business/26qwest.html
Since the other CEOs (those whose companies wilfully broke the law), weren't investigated, it's a little difficult to be sure so long after the facts. As far as I know, none of them have been indited for helping the US government break the law - arguably a more serious crime than insider trading.
The argument is that it's an instance of: "You bring me the man, I'll find you the crime."[1]
Now, it could be that in the telecom industry at the time, in the US, there was little or no corruption and insider trading, and Nacchio was an exception. I certainly don't think he was framed. But there are at least some indications that it could have been a "tit for tat" that landed him in prison.
[1] (reportedly stated by Stalin's chief of secret police, Lavrentiy Beria -- but I've been able to find a source).
> If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.
A similar quote with disputed origins
So, to say a story is bunk because it appears in RT as a source demonstrates a wilful ignorance, or incredible naiveté.
I trust/distrust all media sources in equal measure, but the fun thing is that by reading a lot of them at the same time across the globe, you can more easily see the biases, and get to the root of the stories.
> to say a story is bunk because it appears in RT as a
> source demonstrates a wilful ignorance, or incredible
> naiveté
I didn't. I said an argument that relies upon RT due to the story not being carried elswhere is "bunk". > All news sites carry a bias
But few are sanctioned by Ofcom for regularly broadcasting "materially misleading" content, called out by all manner of former employees for being propaganda machines, or widely derided by virtually every other serious media outlet. Attempting to cover that with a general statement of all media bias - having substantially misrepresented (or just not properly read) the comment you're replying to - "demonstrates a wilful ignorance, or incredible naiveté". All news sites carry a bias - all of them.
A little off-topic, is there a name for this kind of rhetoric? I've seen it used a lot, for example:- When pointed to government corruption they would reply "all the other governments have corruption too", implying there's no difference.
- When asked about low level of life, they would reply something like "15% of your own people are living below the poverty line", implying nothing out of normal is going on.
It's like, one guy has his boot covered in shit and the second is covered in it fully, the first says "you have problem of being in shit" and the second responds "you have that problem too (pointing to his boot) so it's ok".
This argument basically implies something like "we must not discriminate on the grounds of this problem because it is normal for everyone to have it", avoiding the possibly disadvantageous discussion of what is level of the problem and whether this level is normal.
For something to an example of the ad-hominem fallacy, it has to be discarded purely on the basis of the claimant. If something is being rejected on the basis that the claimant is unreliable and contradicts generally reliable sources, that is something quite different.
Should I start discounting RTs weather report for NYC based on their political reporting feel free to call me out on fallacious thinking.
And this is an appeal to numbers (http://www.nizkor.org/features/fallacies/appeal-to-popularit...)...
You may be right, but your logic is fallacious. If there's only one news source and that news source is biased, then it doesn't follow that anything they say is untrue.
You are calling something false based on the source. This is simply illogical: a broken clock is right twice a day. Following your reasoning it would be wrong even when right.
Either the news is true or it isn't. Judge it based on its own merits, not from its source.
[1] https://www.schneier.com/blog/archives/2013/08/more_on_the_n...
[2] http://www.businessinsider.com/the-story-of-joseph-nacchio-a...
[3] http://usatoday30.usatoday.com/news/washington/2006-05-10-ns...
Any real, public court of law would hopefully release someone of such orders once they are no longer in a position to obey it.
Also, their TOS said they'd give data to the government of legally required, so no contract was broken.
People need to get their head around the back that this is a political problem and requires political solutions.
I think we should try to get from a 4 to 5, even if we can't get all the way to 10 right away. We shouldn't just punt on the problem because it's not possible to have an immediately perfect solution. 4 to 5 might mean using keys that only the customer has access to. 7 through 10 might all be political, sure, but let's keep moving.
You could probably get around one, too, by selling pieces of the system and having the customer use OSS for the rest. That is, sell storage and key dongles while pointing your customer to front end software. The same way they used to sell crushed grapes during prohibition.
If the provider doesn't encrypt anything (which is the case with end-to-end encryption), then it doesn't have to hand over anything.
In theory that judge is supposed to make sure the law is being followed. My impression, though, is that some judges have a much more expansive view of government power than I think is warranted.
France? Much worse history on encryption than the US.
Germany? Officially better, but the intelligence services have been revealed to be essentially ignoring German law when it gets in the way of working with their US counterparts.
And so on and so forth.
Governments can be limited by legal constructs. Non-governmental actors, or government actors from other jurisdictions, cannot.
Crypto and legislative reform are mutually reinforcing bulwarks.
People think there's no point to hardware drive encryption, because they look at it wrong; they think it's meant to protect your data in the same way that OS-level user-passphrase-derived-master-key drive encryption is. But it's not about "unlocking" the drive at all; it's really about this exact command, where you can change the key and thus, in an instant, permanently garble all the data on the drive.
(It's is also extremely necessary if you want computer refurbishers to be able to reuse SSDs. Trying to "securely overwrite" all the blocks on an SSD is both impossible at an OS level—some blocks are just unaddressible overprovisioned blocks that only come online when other blocks fail—and devastating at a physical level: the write multiplication of running e.g. DBaN on an SSD would completely burn out the disk. Overwriting the key, meanwhile, is a single write.)
This technique isn't just for SSDs. Something similar can be used with normal hard disks. Just store the true key as metadata on a hard disk. Erase the few sectors of metadata and the disk is no longer readable.
Apple's FileVault 2 does something like this. https://www.lightbluetouchpaper.org/2012/08/06/analysis-of-f...
How do we know that the firmware is actually erasing the block containing the encryption key?
Maybe it just leaves the block/key intact and alters the NVRAM key-address to point to another block or key-location, resulting in a history of every key used on the storage device.
In which case no matter how many times the device was secure-erased a well-equipped adversary could have ways to extract previous keys, either whilst the device is 'online' via undocumented commands, or whilst 'offline' with dedicated equipment.
The same 'destroy-the-key-not-the-data' procedure can be used from the user-controlled software level - Linux with LUKS/dm_crypt uses the same approach via the LUKS header, which can also be 'detached' - only stored on a different (possibly removable) device entirely.
As a bonus it is secure even against malicious (snooping) drive firmware since only encrypted data is seen by the I/O controller and storage device.
With drive-level encryption, the drive effectively acts as its own TPM: the drive's encryption keys never leave the drive (and there's no API to ask for them), so—excepting drives that allow their firmware to be upgraded—there's no possibility of some other untrusted component of your system pulling off a record of the drive keys for later offline recovery.
The best procedure is to combine the two, of course. There's no added cost to disk-firmware-level encryption, since each disk-block is going through a rather complex transformation anyway to protect it from the vagaries of flash array storage. And CPU time for doing OS-level encryption is cheap. Turning both on—and telling the OS to secure-erase its key before telling the disk to secure-wipe—protects you from both attackers.
---
If, for some reason, you only have one or the other available to you, though, I'd honestly prefer the disk-firmware-level encryption, with a foreign-made drive. (This is going to be a bit of a tangent.)
Both CPUs and disks can do encryption. Both CPUs and disks can keep the key locked inside themselves, basically acting as TPMs. And both CPUs and disks can have been suborned at the design or manufacturing stage by a state actor.
My main choices of CPU (Intel, AMD, ARM), regardless of where they end up being manufactured, were all designed by either US or British firms—that is, firms within the jurisdiction of the Five Eyes SIGINT-sharing agreement. I have many choices of disks, though, and many of those options are both designed and manufactured outside of that jurisdiction, in e.g. China.
Now, while I might not trust foreign state-level SIGINT any more than domestic, the incentives are different. Even if Chinese drives have suborned firmware, China has no reason to care what's on my drives—because I'm not a Chinese citizen—or any way to force me to hand the drive over—because I'm not physically in China—and no way to make me be in China, because Canada (where I live) has no extradition treaty with China.
Meanwhile, if I relied on a US-designed/manufactured drive, the NSA would care what's on my drives (because Canada's NSA-equivalent, the CSE, asks them to)—and, because Canada and the US do have an extradition treaty, I could get extradited to the US for a US law the NSA says I broke—and I then would be forced to hand the drive over, where the backdoored keys could be extracted and used to recover the drive's contents.
All these arguments are reversed, of course, if you deal in state secrets, or industrial trade-secrets, that foreign state-actors would actively target you for. The military has every reason to only want domestic CPUs and domestic drives. But I'm not a spy, or a diplomat, or a military officer, or an electrical-utility tycoon; I'm just a private citizen. The only country that cares about me, for better or worse, is my own (and, y'know, those other ones that they attend SIGINT club with on Friday nights.)
c.f. Lavabit and "Reflections on Trusting Trust"
Even if the perfect technical solution existed, it wouldn't fix this problem.
To really protect the right to free speech we need both technical tools that are easy for everyone to verify, and a society who believes laws banning encryption are worthless.
Anything short of that is a risk that we flop into a state that is afraid of words.
https://en.wikipedia.org/wiki/Windows_10#Privacy_and_data_co...
or:
https://en.wikipedia.org/wiki/Skype#Security_and_privacy
(I agree that it is good that Microsoft makes this move now.)
Microsoft has simply discovered that a previous business strategy - monopolistic embrace, extend and extinguish-is no longer a good one in today's open, networked world. Hence they have moved to new strategies which are more palatable to the tech community. Slightly late, but still in time to remain relevant.
Mostly, I'm referring to Ballmer.
Easy web access etc don't work without the service provider being able to get the data.
And this is good for the public.
Perhaps they do not have to, but they should if they want to retain and grow customers in the future.
Anyone who's been bitten by data theft will tune into this. I imagine that includes any major business. MS is jumping on the bandwagon before it falls behind in the PR campaign. This could be the next campaign similar to environmental friendliness or human rights. It's not enough for tech companies to be "green" or have good factory conditions. Now that they hold so much user data, they must also demonstrate their commitment to security and transparency.
Do not believe their lies. Microsoft is a harmful entity.
There were reasonable explanations offered.
I just would like to have some sources / explanations to your statement.
*while looking to buy some more of their stuff.
If something does go to court the government will probably just stop doing it and try something else (the government loses in this sense but only very narrowly).
A lot of these "tools" won't stand up to scrutiny by the Supreme Court because they are so broadly applied, and then the game would stop. Easier just to lose dmall battles but to keep the game going.
"This morning we filed a new lawsuit in federal court against the United States government to stand up for what we believe are our customers’ constitutional and fundamental rights – rights that help protect privacy and promote free expression." (my emphasis)
"The lawsuit, filed on Thursday in federal court in Seattle, argues that the government is violating the U.S. Constitution by preventing Microsoft from notifying thousands of customers about government requests for their emails and other documents."
http://www.reuters.com/article/us-microsoft-privacy-idUSKCN0...
Consider charges of conspiracy, or of access to classified material. If the suspect destroys the evidence, and commits/have not already committed any other crimes -- should we really use the resources to investigate and prosecute such thought crimes?
We risk loosing sight of the fact that punishment is not a goal, it's a means to an end. Hopefully that end is a free and safe society.
edit: where thought = imaginary
I've long held that "conspiracy to X" charges were just a way for the government to throw the book at someone they otherwise wouldn't be able to.
It is one thing for me to say "let's kill Bill". It is an entirely different thing for me and you to surveil his movements, his schedule, to develop code names, to discuss scenarios for action, to procure means to assassinate him. You can show evidence of serious intent in a conspiracy.
A woman breaks up with her abusive husband and he threatens to kill her. There's some record of him saying this. Should society do nothing to protect her? Men are known to be physically stronger. What kind of society would we be if we did not provide her some protection by putting space between her and the husband? Presumably courts would decide if it's necessary to jail him or just use a restraining order. And ultimately his punishment wouldn't be the same as if he actually committed the murder.
This becomes a real problem in the case of a repeat offender. The offender realizes he can deliver some "light" abuse and threats. Officials try to lock him up, but he only stays behind bars for so long, and unless the wife agrees to press charges and testify, there is little law enforcement can do. The wife is often terrified and won't testify.
It is situations like these that authoritarian regimes like China and North Korea will point to to suggest that democracy is nuts. Under their authority, they could easily jail or kill such an individual.
In real life, there is a balance struck between laws and rights in the interest of furthering a trustful society. Different cultures draw the line in different places. I'm not familiar with what countries do not have laws against threatening someone's life but you could try to find one and see if you might like to live there. My guess is there aren't many and the bigger a country gets, the more likely they have this kind of law.
Not a rhetorical question.
http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...
I still think MS should pursue their case but I wonder why they have not set up the system you're describing, given that another commenter's link suggests it is legal [1]
https://letsencrypt.org/2016/04/12/leaving-beta-new-sponsors...
What Let's Encrypt does against state-level actors is let people easily use HTTPS instead of HTTP without subjecting their users to self-signed certificate warnings.
A government could still MITM the connection but that requires an active attack rather than passive surveillance. And active attacks are subject to detection. So it protects against undetectable mass surveillance.
Our blog posts in particular:
https://paragonie.com/blog/category/security-engineering
A reading list we maintain for application security (and some crypto stuff):
For example, developers know not to roll their own cryptography, but how can someone who has never rolled their own crypto evaluate existing libraries? There are a lot of bad ones out there, and "I didn't roll my own crypto" doesn't equate to "I used a well-studied library thought to be secure by industry experts".
Consequently, we delved into specific recommendations and explained why we include them in our list.
https://paragonie.com/blog/2015/11/choosing-right-cryptograp...
(Historical context, this was published after I discovered CVE-2015-7503 in Zend Framework 2. A lot of my peers said it was good, but I don't recommend code until I've audited it. Lo and behold, I found a problem with their RSA implementation.)
For our reading list: We focus on application security, not physical security (e.g. data center security, full disk encryption), social engineering (e.g. phishing, scamming), or system security (e.g. malware and OS-level exploit mitigation).
Application security can encompass cryptography, information theory, etc. but the target audience is programmers.
Material for any programming language will be considered for inclusion, but some absurd ones (e.g. Brainfuck) will probably be declined.
As to windows-only software, make a Windows VM on a Mac and fence it off with a firewall.
So should Outlook.com be considered insecure if the US government can access it at any time without you knowing? Microsoft should be able to inform you whether or not your information has been leaked. I hope Microsoft wins.
So, like, every criminal investigation of a person who uses email?
On the other, I wonder if they would if Apple hadn't already stood up to the government?
Edward Snowden says, "Courage is contagious." I'm just wondering if this is an example of that, or if they would have done this regardless.
"The Microsoft case is believed to be the first time that an American company has fought against a domestic search warrant for data stored overseas."
I think you'll find that's not the case.