U.S. National Security Agencies Said to Swap Data With Thousands of Firms
bloomberg.com
bloomberg.com
Microsoft Corp. (MSFT), the world’s largest software company, provides
intelligence agencies with information about bugs in its popular software
before it publicly releases a fix, according to two people familiar with the
process. That information can be used to protect government computers and to
access the computers of terrorists or military foes.
Microsoft gives US military hackers and the NSA zero days to go hack people with.I think this helps explain Google's 7-day disclosure. Also, fuck microsoft. Running your mouth and trying to blackball people who don't give you 60 days while (presumably selling) those exploits to governments? Just amazing.
Edit: here [1] is discussion of Tavis Ormandy / Google's new 7 day policy. I really wonder if this was partially driven by eg Microsoft's abhorrent behavior.
[1] http://www.theverge.com/2013/5/30/4379004/google-to-make-cri...
See the entire Heroku/Postgres for another, less insidious example.
provides intelligence agencies with information about bugs in its popular software before it *publicly* releases a fix
emphasis mine.1. http://www.microsoft.com/security/msrc/collaboration/mapp.as...
Do you agree to publish monthly protections derived from MAPP information
only after Microsoft’s public security update release?
I'm doubting the NSA / military hackers make, or honor, any such agreement.what does msft think they're doing with them?
Ask yourself, if you receive information via MAPP, you have some information which could be turned into an exploit, but it will not be useful towards a goal of hacking other peoples computers for long because, by definition, it is going to be patched soon. "Make hay while the sun shines" perhaps? The same window of opportunity is open to governments and corporations around the world (many Chinese companies are MAPP subscribes, the one leak of a MAPP exploit happened perhaps because of a Chinese company).
http://www.microsoft.com/en-gb/security/online-privacy/overv...
Their stance is that they directly oppose 'green hats' who are selling exploits to customers that don't intend on fixing the flaws (buying a hacker's silence) and selling to governments whom intend on using the exploits for clandestine operations.
[1] https://www.eff.org/deeplinks/2012/03/zero-day-exploit-sales...
It would be completely legitimate for MSFT to warn NSA about vulnerabilities in the most common desktop operating systems in the USA if the warning were intended to aid in preventing a larger attack.
It's a write-only bugtraq. :-)
This intersection between protecting civilians and attacking our military enemies should absolutely worry you, the worst nightmare of 'responsible disclosure' has just been revealed: security updates aren't being rolled out as a matter of official policy, for the explicit purpose of military offensive operations.
Theoretically, there is presidential and congressional oversight to prevent them from overstepping their bounds. Unfortunately, we've largely squandered the threat of congressional inquiry on blue dresses and cigars.
What I find confusing is that, ultimately, you have to follow the money. How has MSFT been benefiting from a conspiracy to exploit their own software in overseas markets?
They know that embarrassing information will get out eventually. They also have a distant planning horizon regarding continued existence. Whatever they get in return has to have been perceived as worth the loss of any trust and goodwill as a result of the eventual disclosure.
http://www.guardian.co.uk/world/2013/jun/09/nsa-whistleblowe...
https://en.wikipedia.org/wiki/Main_Core
"As of 2008 there were reportedly eight million Americans listed in the database as possible threats, often for trivial reasons, whom the government may choose to track, question, or detain in a time of crisis."
We are more than half way in the road to serfdom and tyranny.
EDIT: Resubmitted now as "http" - https://news.ycombinator.com/item?id=5878571
This is a good time to re-read Book 8 of the Republic (Socrates by way of Plato). The current political situation of the world is being decribed as if they were teleported 2000+ years, then went back to write what they saw.
I joked that he'd better appreciate the lists I was willing to put myself on for him, but maybe it wasn't that much of a joke.
is there any overlap with that list and people incarcerated already?
tptacek: "Someone on Twitter (sorry) said that Google and Facebook "looked like angels" compared to Verizon. That sounds about right to me, too."
It was argued that one shouldn't do that; that it was better to call people out directly.
Before they agreed to install the system on their networks, some of the five major Internet companies -- AT&T Inc. (T), Verizon Communications Inc (VZ)., Sprint Nextel Corp. (S), Level 3 Communications Inc (LVLT). and CenturyLink Inc (CTL). -- asked for guarantees that they wouldn’t be held liable under U.S. wiretap laws. Those companies that asked received a letter signed by the U.S. attorney general indicating such exposure didn’t meet the legal definition of a wiretap and granting them immunity from civil lawsuits, the person said."
This will make the ACLU's law suit 1000% more interesting as a legal battle.
Verizon doesn't just sit around and think to themselves "hey, if we're going to work with the NSA we should do some CYA". They have entire legions of smart lawyers who mulled this whole NSA business over (substantially I hope) and came to the conclusion that "this is most certainly a violation of the law and we need complete documented assurance from the government that our actions can never be prosecuted in court".
And they got it. But will it hold up?
The letters from the AG are protection from criminal action, and probably government civil action, that extend beyond the term of the administration issuing them (wiretap laws have criminal as well as civil provisions, and there are cases where the government can bring civil prosecutions.) For criminal laws, ignorance of the law is not a defense, but reasonable reliance on an interpretation provided by the public authority responsible for enforcing the law usually is a defense. For civil actions, reliance on the representation of the party bringing the action likewise can be a defense.
For civil action by a third party, unless there is a specific provision that makes this a defense for the particular offense at issue (which there may be, but I'm not aware of one), I don't think this would be particularly useful under any generally applicable principal.
If necessary, a company executive, known as a “committing officer,” is given
documents that guarantee immunity from civil actions resulting from the
transfer of data. The companies are provided with regular updates, which may
include the broad parameters of how that information is used.Now that the dam has sprung a leak, and the full extent is becoming evident, people will begin to realise that they are not alone, and it is safe to talk. There is safety in numbers. One gets the feeling that the whole scheme is unravelling, and this is the trickle before the dam bursts.
I'm looking forward to it.
Their fervent patriotism certainly didn't stop them from demanding immunity as a prerequisite.
This article runs terribly short on the other half of the question: what did companies really get in exchange?
Call me a cynic, but I can't believe it was just the fuzzy warm feeling of being a patriot.
(My contacts at IRS said they are warned to avoid "poking" into certain institutions actions without highest authorization. So they go after the small fry and leave the big fish alone. Fucking game of life is rigged.)
Frankly I would still assume that anyone who didn't do it out of some stupid patriotic pride definitely got paid, and they likely got paid through a shell company giving special contracts, or help with some government issues (environmental regulation, building approval, etc). Tax breaks or other direct cash methods don't really hide much for publicly traded companies.
Yeah right... Anybody want to dig deeper see what they got for participating?
Industrial espionage plain and simple. It's in the interest of both the US government (to increase domestic economic activity) and said business to share this information.
I think we are against an effort to tranquilize us with tyranny!
Where we are just overwhelmed with outrageous actions such as to desensitize us to the fact that "well, holy shit, this is so pervasive and so entrenched, what is there to be done? I mean, my life was great for the last three years and this has been going on, at such great lengths, for so many years -- how bad can it be??"
This is a test as to how much we will take. They want action - they want an excuse to really show us what debt slaves we are.
"That metadata includes which version of the operating system, browser and
Java software are being used on millions of devices around the world,
information that U.S. spy agencies could use to infiltrate those computers
or phones and spy on their users."
A database that contains the specific versions of installed software for millions of computers world-wide is a very powerful tool. For any given target--if their machine is in the database--compromising their system is a trivial matter! It's a "what exploit would you like to use today?" situation.Assuming they gather this information from Internet backbones--I'm OK with that. Good for them for skimming data off the public Internet and shame on the software that makes it too easy.
On the other hand, if they're obtaining this data from the likes of Microsoft (or McAfeee or any other incredibly popular vendor with an item in everyone's systray) that is an incredibly scary proposition. No target stands a snowball's chance in hell at not being (trivially) compromised. It's one of those situations where, "you'd better not use that company's products!"
I can't even imagine the sheer destruction that could occur if such information fell into the wrong hands. Imagine if some "fuck the world" anarchist hacker got his hands on a database that contained precisely the information he needed to, say, compromise (and just plain erase; 'rm -rf *') just about every banking computer that happened to be listed. It would be like, ARMAGEDDON.
Letters of marque (https://en.wikipedia.org/wiki/Letter_of_marque) of our day
What's so bad about that?
(For big boys)
-= THEM =- Ok, ________ . Did you live @ ___________ in _ _ _ _ ? Did you ever have an account at ________ ?
Where do you think they get the info. Connect the dots.