Microsoft helped the NSA bypass encryption, new Snowden leak reveals
rt.com
rt.com
Even when ostensibly not functioning, the Xbox One can run in a low-powered state, ready to be snapped on at a moment's notice. That's something Microsoft was showing off last week as an asset. The only on-switch Microsoft showed for waking the machine from its low-power state was a voice command... "Xbox On." The Xbox One could only hear that if the Kinect was already, always listening. The idea that the Kinect might always be listening got people reaching for their tin foil or vowing to not let an Xbox One into their home.
Microsoft is now seeking to calm concerns that the new Kinect might spy. "We are designing the new Kinect with simple, easy methods to customize privacy settings, provide clear notifications and meaningful privacy choices for how data will be used, stored and shared," the Microsoft rep told me.
"We know our customers want and expect strong privacy protections to be built into our products, devices and services, and for companies to be responsible stewards of their data. Microsoft has more than ten years of experience making privacy a top priority. Kinect for Xbox 360 was designed and built with strong privacy protections in place and the new Kinect will continue this commitment. We’ll share more details later."
http://kotaku.com/xbox-ones-kinect-can-turn-off-microsoft-sa...
Not sure I'd want the Xbox One in my house after this fiasco.
Do you want your information to be given to the NSA?
[ ] Yes
[X] Yes Do you agree that your information will given to the NSA?
[ ] Yes, I agree
[X] No, I don't mind.Frankly I'd be more concerned about the microphones contained in ubiquitous and nearly unexaminable devices such as cell phones, and to a lesser degree laptops. (I imagine that many laptop mics are USB devices, so their traffic should be visible to drivers, the drawback being that once the traffic is on the mainboard, where it goes is less traceable).
So you will [again, this is speculation] be seeing constant traffic flowing across the USB cable.
Not that we should have to do this....
I've been using one of these for several years now for our entertainment center. You just have to be sure you turn off any devices you don't want the power hard cut from before you turn off the television.
It's a telescreen. (http://en.wikipedia.org/wiki/Telescreen)
http://consumerist.com/2013/07/08/the-xbox-one-will-use-kine...
http://bgr.com/2012/06/12/microsoft-xbox-kinect-targeted-adv...
I am ambivalent in regards to ranking one over the other because I cannot file a FOI request with Microsoft or Google or Apple or HP or Yahoo, etc.
Microsoft just makes great headlines, particularly in the tech community where people such as myself, who very likely never planned on purchasing an Xbox One can express outrage over its design. I thought the architecture was crap from the beginning.
If the government does, democracy is.
I mean what's next, they're going to make these things small enough that we can carry them everywhere?
Grab the source, build it and install it yourself. If your device doesn't support it, buy one that does. If you can't do it yourself, get used to be screwed in this brave new Orwelian world.
He was right all along, it was us who didn't care enough to understand what he was saying and its importance.
It is a basic principle of security to assume that any power an adversary has, will be used against one's interests. People misunderstand this; I have seen it called a fallacy. But it's not a claim that it's always true, rather that it's what one must assume in order to have the best practicable assurance of security /privacy.
I also used to get arguments like "MS/GOogle/$_BIG_TECH_CO wouldn't use their power against customers, it would be bad for business" or "...it would be illegal" or similar. The correct answer is that prudence dictates assuming the worst. Well, maybe I was too cynical, but it's hard to keep up with how bad things really are.
Not many like that left. I know I sold out already.
http://www.schneier.com/blog/archives/2012/08/an_analysis_of...
Paper here:
http://eprint.iacr.org/2012/374.pdf
Currently, there seem to be three vectors:
1) Weak passwords
2) If you opt-in to store a recovery key with Apple
3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) (Edit: seems like this is not the case, see below)
But no backdoor has been found (yet!)
3) If attacker has physical access to machine, and
machine is powered on (direct memory access via
Thunderbolt or Firewire)
This may have changed, but turning on FileVault used to disable DMA in many situations (laptop had been suspended being a key one) until the user logged back in. Not that this isn't a vector, but it's actually a very narrow one; you basically need the person to already be logged in at the time you want to steal the keys.http://www.frameloss.org/wp-content/uploads/2011/09/Lion-Mem...
Though apparently there was a company offering a commercial solution for getting FileVault passwords using this method so...
http://privacycast.com/filevault-vulnerability-how-to-protec...
There's also a really interesting pdf from Apple containing more details on FileVault 2:
http://training.apple.com/pdf/WP_FileVault2.pdf
which suggests turning on firmware passwords to prevent DMA.
He specifically mentions he could access the FileVault key of a machine by having physical access, and discovered two secret keys (KPPW and KPST) one of which is enabled when the input buffer is "SpecialisRevelio" [2].
It's a very interesting deck to read through.
[1] http://www.nosuchcon.org/talks/D1_02_Alex_Ninjas_and_Harry_P... [2] http://harrypotter.wikia.com/wiki/Specialis_Revelio
FileVault could be some hypothetical magic uncrackable encryption with a keyspace bigger than the known universe...and it would never matter if there was a backdoor in the OS.
I'm curious if this could be addressed with software protections somehow? Something that triggers memory wipes and automatic shutdowns?
* Source http://security.stackexchange.com/questions/18720/how-secure...
> If you enable LUKS root, DMA attack mitigation is also enabled(boot.initrd.luks.mitigateDMAAttacks ). It consists of blacklisting firewire drivers.
Edit: still at risk of the "Evil Maid Attack" http://www.aspecrypt.com/evil_maid_attack.html
Though that specifically obviously requires hardware.
If you want your data to be reasonably secure against someone who casually steals it then they're fine but if you want to be secure against government employees, or even well connected corporations, then Apple & Microsoft solutions are not very useful.
[1] https://en.wikipedia.org/wiki/NSAKEY [2] http://news.cnet.com/8301-13578_3-57583843-38/apple-deluged-...
[3] http://www.informationweek.com/security/encryption/apple-iph...
Edit : the site seems to have some difficulties, here's the google cache http://webcache.googleusercontent.com/search?q=cache:JZEtYXR... The description of the decryption suite is in the module tab.
You can find the Torrent at Wikileaks: https://wikileaks.org/wiki/Microsoft_COFEE_%28Computer_Onlin...
[1] https://en.wikipedia.org/wiki/Computer_Online_Forensic_Evide...
2) It provides Apple a fallback when some idiot loses 6 figures worth of IP. “We understand sir, you see, if you had chosen to backup your recovery key with us we would be able to help you”
* or would be, if the NSA wasn't spying on everything.
And if you want to be safe from the government, just select "No".
from http://www.infolaw.co.uk/newsletter/2012/01/microsoft-office...
However, the Patriot Act, introduced to protect US national security, can require that any US company (wherever data is held) must disclose data on demand to the US Government without the knowledge of the owner of the data, which is contrary to the UK Data Protection Act. Microsoft has been up-front in acknowledging that they cannot give that guarantee and this applies to data held in all their hosted solutions. As a result, in December 2011, BAE ditched plans to adopt Office365 because Microsoft could not guarantee the company’s data would not leave Europe, in spite of operating a data centre in Dublin.
In the process these leaks have just destroyed pretty much any credibility Microsoft's online services had, which form large parts of their strategy (according to the recent Ballmer memo).
It also makes you wonder about the OS and other software they produce, which isn't a good place for MS to be in.
Do you think that the NSA has no access to Dropbox?
One of the key facets of the the Xbox One is the Kinect as an always on device. As another poster pointed out, Microsoft has been quick to answer the privacy related questions that have been asked about this situation with the claim that the system has been built with privacy as a focus. As such, the reliability of those claims in light of this new leak appears to be relevant.
For example, given a court order, would Microsoft be required to:
1.) Provide law enforcement with Kinect data. (everything from as simple as "there were two people in the room" to "here is a live stream of the room"
2.) Be bound by gag orders not allowing Microsoft to reveal the existence of item 1.
3.) Be forced/coerced/enticed to provide bulk "wiretapping" of Kinect data.
Additionally, there is the question of "expectation of privacy". Many of the current privacy laws are based on this concept. However, could the courts decide that there is no expectation of privacy when a video and audio recording device has been placed in a private area, with full knowledge of the owner, also with knowledge that the data will be sent to a third party?
While these items might seem fringe (and before these leaks, I may have agreed), the scope of the current leaks seems to imply that these questions should at least be considered (even if a person chooses ultimately to accept the risk).
It would be rather surprising if they were not at least approached by Federal agencies such as NSA and FBI.
To put it another way, because Microsoft has a closed source model, the intelligence agencies took the approach described in the article. From that, it may be a mistake to conclude that the strategy pursued with Microsoft was the only strategy pursued. It just happens to be one that would pass across the desk of an analyst, rather than someone on the operations side.
Viewed as an intelligence operation, it would be grossly unprofessional of such agencies not to have placed moles within the open source community, or for those moles to be seen as highly skilled contributors on open source projects. The three letter agencies have decades of experience infiltrating both commercial organizations and those motivated by something other than money.
I suspect it is easier to turn an open source hacker than a diplomat - not just ideologically but because the open source community lacks a state funded organized counter-intelligence apperatus.
CALEA seems to say that companies don't have to decrypt data for authorities. I guess it's very convenient that they give it to them before they encrypt it then:
http://paranoia.dubfire.net/2010/09/calea-and-encryption.htm...
And this seems to be a "team sport", and that implies willing collaboration, not being forced to do it. More like something "fun" they're doing together.
Well, we can't really know (they won't answer FOIA requests!). We can only make guesses.
Could be they were just asked. Western Union gave telegrams to the NSA just for the asking.
Some people would argue that Microsoft has enjoyed favorable treatment by the courts. Maybe there was a quid pro quo somewhere along the way.
NSA has strategically placed employees/agents in other companies. Why not Microsoft?
Think about the impact of the NSA leaks on Microsoft's business. Globally, every customer or potential customer of Microsoft needs to ask whether they can trust Micrsoft as a business partner. Not a good place to be on for a software company transitioning to a cloud services company.
So I hope it hurts them, I hope it makes them and all the other companies bleed until they do something.
http://www.networkworld.com/community/blog/project-chess-hel...
If these media outlets are holding on to them to dribble and drab them out to make a buck, there's a huge problem with that. Everything should be out on a torrent or wikileaks for all to see.
could there be a case where the parties in a conversation are legitimate suspects? in such a case, why does it matter if it's Microsoft or some other private company that the NSA hires to break encryption?
it seems that the article is presenting the Microsoft / NSA relationship, and later states “If you look at what happened when Bush, Cheney and General Hayden – who was head of the NSA at the time – deliberately violated the law to eavesdrop on Americans without a warrant" which hints at a vague conclusion that Microsoft is helping to spy on citizens without a warrant.
possibly i missed something, so is the point that Microsoft (or any private company) should not do any work for NSA, or that it should not do it without a warrant, or that we can't trust it with anything because it did some work for the NSA? Or is that the details are still not disclosed so it's pure speculation?
NSA needs no warrant to wiretap me as a European and I'm not going to send my money to Microsoft so they can use that money to help a foreign government agency , that I or any of my fellow citizens have no oversight over, to spy on me.
That would be totally absurd.
Firstly, how can we be certain?
Suppose, for a moment, I had the data that the NSA has. To whom could I sell that data? If I could prove to questioners that I had such data, to what ends might they go to get it from me(Ans. there are entities that would take it by force and then kill me and my family to remove the traces)?
NSA is sitting on a goldmine. Many, if not most, large corporations, businessmen, academics, organized crime members, politicians, or bureaucrats would sell their home (and possibly their family into slavery) to obtain that information. How can the NSA possibly ensure that it is safe ? How can they ensure that their employees do not pass some of that data to the above? What if a significant chunk of that data is copied and enters the black market? How could it possibly be recaptured?
Snowden has, by example, shown that all the above can and indeed did occur.
As we speak there are undoubtedly hundreds, if not thousands, of individuals who are attempting to gain access to the NSA's treasure vaults. Some groups are smarter and better organized than the NSA. It's merely a matter of time before huge leaks occur. They may or may not be leaked publicly.
Neglect can be criminal too.
And the NSA might not have sent anyone to the gulag but the Obama administration has gone after whistle-blowers at an unprecedented level. Hard to imagine the NSA wasn't helping them out some.
I guess my only option now is to rebel.
But sure for those living in the US they can do that. And they did that with Obama. However that just increased the surveillance.
It doesn't matter if they are. No one expects coffee shops to put microphones at every table on the off chance that a terrorist plot is planned there (how many mob hits could have been prevented back in the day).
We shouldn't accept the government listening in on digital communication just because it's easy.
I think it squares quite nicely. Set your standards low enough...
My apologies, for some reason the only sites google showed on this issue were .co.uk.
Fortunately they now have a worldwide setting. At one point you could select only 5 (or was it 7?) languages for which Google would show you results. They fortunately fixed that.
I mean, who would want to search _all_ the internet?
Because they ordered him to give it, and he elected not to go to jail.
rimantas is referring to using open source in a cloud service, not authoring and distributing it.
By law they would have to get a warrant... ie: actually obtain some real proof that you are up to no good. A lot better than this current blanket case scenario.