Microsoft Shuts off HTTPS in Hotmail for Over a Dozen Countries
eff.org
eff.org
Perhaps they're using strong cryptography and those are the nations which are not approved to export crypto to (and hence, perhaps not supported in local versions of IE)?
http://en.wikipedia.org/wiki/United_States_embargoes
http://en.wikipedia.org/wiki/Export_of_cryptography_in_the_U...
Maybe not all governments are Microsoft-friendly...
All in all, it really makes them look bad, even if there's an innocent explanation.
http://www.theregister.co.uk/2011/03/26/microsoft_https_hotm...
Despite EFF's headline, it doesn't sound like this made HTTPS unavailable, but rather the "always-use-HTTPS" setting.
Why those countries?
Here's a guess: it was a localization issue.
I bet changing your country changes your default language. And I also bet that the availability of localized strings (i.e. "Is string 8230 available in language X?") affects what options are shown to the user. After all, if a descriptive string isn't available in the user's current language, how do you show them the option?
So what exactly happened? I don't know. Maybe they whacked some part of a localization table. Or rolled back to a previous localization table. Or mangled mappings from "language" to "current localization table". Software is complex.
All in all, it really makes them look bad, even if there's an innocent explanation.
The timing certainly invites theories of maliciousness.
Also, weirdly enough, the error that got shown was in English. Not that it proves anything, but it makes it seem like the language settings were set to English, in spite of the location.
So, yeah, I'm going to be very curious about the explanation of this one. For the record, I do think that it could be innocent, but this kind of thing really invites people to think the worst.
Could also be to do with geographical regions being on different infrastructure, perhaps with slightly different versions of the code deployed to them. Maybe some broken logic in a proxy or something. All it could take is a couple of bits flipped.
There are many, many possible reasons for glitches like this in a system this large.
http://jilliancyork.com/2011/03/26/microsoft-fixes-bug-re-en...
MSFT has 90,000 employees; surely some of them can speak up about this, and how it jeopardizes the people in those countries who are struggling for freedom?
If MS sells them Windows and Server products, then it is not out of question.
Here's how the logic works: MSFT does business in these countries. These countries have a sudden desire to monitor some citizens' communications (which include Hotmail accounts). HTTPS prevents this monitoring, so these countries lean on MSFT. Ergo, MSFT shuts down HTTPS access to Hotmail.
For a lot of these regimes, it's a matter of survival to crush dissent. MSFT just made that a little bit easier.
Let's say there are two options to consider: 1. There is a localization bug that affects the always-https setting. 2. Microsoft wants to do business with those countries and purposefully created a defect in always-https.
The first case is very plausible (to me at least). Defects happen, some are more visible than others.
The second case is less plausible to me. The current pattern of governments is to request by local-law the ability to monitor/control communications without the citizen knowing. An example similar to this hypothetical that is often in the news is countries that request a Blackberry messaging server in-country.
Q: Why would Microsoft collude with these regimes to crush dissent in such an obviously noticed and easily defeated way?
A: Because their evil regime assistance unit is incompetent.
Q: Why would you choose that over the more simple first case of a localization bug?
Governments buy truckloads of licenses and get to determine how much tax you pay. I'd say it would be completely unlike Microsoft not to have them. Their sales force is not the kind of people who would leave money on the table.
I've seen how government sales are made. There is a lot in common with sausages.
Perhaps with so much to keep up with lately the NSA monitoring equipment is struggling to MITM that many TLS sessions, so MS cut them a break.
(mostly kidding...)
My guess: These are all countries that I would guess have pretty high latency from Microsoft's servers. The SSL handshake requires several roundtrips, as I understand it, which means that high latency would hurt performance significantly.
What if they said "drop HTTPS and, as soon as this turmoil ends, we will modernize our government IT"?
Then the users could choose not to use it if they found it annoying.
I can't come up with any explanation for this other than a ridiculous level of incompetence or malice.
Even if not all of them could be identified, the ones who were will certainly cooperate with authorities.
I dont know what the reason is. But its just unacceptable. Hotmail knows Iranian goverment is after sniffing users data. Iranian cracker tried issuing a certificate for Hotmail. Now they remove https option?
Is it just me, or is there a strong correlation between decisions that seem bureaucratic and politically motivated, and are completely ineffective at achieving their purpose (at least for the technical users)?
(I have the recent India vs. .xxx news in mind as well.)
I bet it was not Microsoft who originated the decision to do this.
It's just like the blackberry decryption keys being turned over.