Microsoft: U.S. Constitution is 'suffering' from NSA secrecy
news.cnet.com
news.cnet.com
Also.
>The company said it responds only to orders for "specific accounts and identifiers," and never provides "blanket or indiscriminate access to Microsoft's customer data"
Does not mean they did not provide the mechanism to access encrypted data in transit.
Microsoft doesn't do end-to-end encryption so it can be forced to turn over the cleartext. (Skype calls go through MS servers in unencrypted form, and Outlook/Hotmail messages are stored in cleartext.)
There are still legitimate questions to ask Microsoft, though: https://twitter.com/declanm/status/357229483666837505
Microsoft's deputy general counsel and VP John Frank has a top secret security clearance. So do at least three of its attorneys -- all those clearences were granted by FedGov precisely so the company could respond to legal requests.
To be clear, I'm not saying anything is true or not. I'm just saying we shouldn't rule anything out. It's possible that some of the tech companies are themselves partially or fully in the dark.
I suppose anything's possible, in some abstract sense, but we're talking about reality here, which excludes some more creative theories. And, alas for screenwriters, there is precisely zero evidence to support your "in the dark" theory. :)
they are required , by the law , to deny any involvement with the NSA if caught. They are required to lie ,by the law. So at this point you cant believe anything they say.
Otherwise they're just disingenuous at this point, because they know that while they say that in public, they give access to spy agencies all over the world to a lot of those accounts, that probably have nothing to do with "terrorists". Even if they think all the requests the US government is doing are "legitimate", do they really want to make it just as easy for the Saudi Arabian government or others to do the same?
Come to think of it though, if the service is free (i.o.w. you are the data and advertisers are the actual customers wouldn't Google/Facebook or whoever be more concerned with the security and privacy of those paying the bills rather than the data-points generating harvestable content.
So it really does seem that we need to move ultimately to federated, paid-for services for communication at least, like POTS but for email and chat and whatever.
† (To assume otherwise would be odd, wouldn't it? It's like taking someone saying "I like ice-cream" to mean "I would allow you to shoot me in exchange for some ice-cream." We assume people have an implicit preference for staying living. We should probably assume companies do too.)
>> When we are legally obligated to comply with demands, we pull the specified content from our servers where it sits in an unencrypted state...
Why would the public's private data sit in unencrypted state on Microsoft's servers? What would be the point of encryption if corporation servers can see what you think you are securing via assumed privacy?
You just create a search index before encrypting the data. Then you encrypt the index. Each time you need to search, you decrypt the index, get a reference to one or more results, fetch those, and decrypt them.
That's trivialising what can become a pretty complex scenario, but it illustrates the point.
I wasn't saying it's impossible, just that it's pretty hard.
That said, I did it in a native client app, where state is easier to maintain.
http://nakedsecurity.sophos.com/2013/05/05/ibm-takes-big-new...
(caveat: I'm not a security expert) Encryption is used for data 'in flight' as well as 'at rest'. As far as I know, very few companies/services go out of their way to encrypt your stuff at rest (it's within their systems/firewall/etc at that point). Even if they did, they hold the encryption keys so can 'see' it anyway.
If you want a situation where a company cannot see your data, you have to hold the encryption keys yourself (nb: knowing the password != holding the encryption key. My rule of thumb for this is if I can do a password reset on a service, then that service can see everything I put into it.)
http://slashdot.org/comments.pl?sid=3891677&cid=44076497
An important information from the "confidential" studies here for example would be what kind of monitors were tested.
The actions always speak louder than the words.
The people making this campaign probably knew nothing about PRISM anyhow.
And unfortunate or not, I think they deserve to lose customers. Actually, I am surprised their stock is not plummeting right now.
EDIT: To clarify, maybe this SHOULD cause a mass exodus in an ideal world. But I don't think that matches up with reality, and therefore I don't think a mass exodus/stock meltdown is really an expected outcome.
But what about the people in charge of buying software or services for their company? These are the people that Microsoft should worry about.
Why focus just on tech what about all those financial transactions flowing through Wall Street. Is everyone going to start banking in Antarctica now?
What has happened with American tech companies wrt the NSA can happen to any company anywhere in the world holding data. If the government walks in one day, and says give me the keys, lives are on the line, most people I know will hand over the keys.
Most big "enterprisey" customers who use MS servers or exchange or office etc. aren't even remotely contemplating about switching to anything else. That's a pretty safe business for MS at this moment. That will likely change, but it's hard to predict when.
Unfortunate for MSoft as I used to be a fanboy, but no more.