Microsoft Makes Moves To Protect Customers From Government Eyes
securityweek.com
securityweek.com
Here, it's being deployed in the service of a dismissal of one of those providers improving their encryption --- of them making it harder for the USG to monitor comms.
And besides, whatever PRISM may or may not be, it's pretty clear MUSCULAR would fill in any gaps, and dispel your claim of mere theories, in favor of reality.
https://news.ycombinator.com/item?id=6641378
NSA infiltrates links to Yahoo, Google data centers worldwide (washingtonpost.com)
http://www.washingtonpost.com/world/national-security/nsa-in...
I mean, you gave the top comment on that thread, after all.
Meanwhile, illegal direct access to intra-provider communications can be cured by improving operational security at providers, which is exactly what the story we're commenting on is an instance of.
No, I don't think your argument is valid.
MS: We have enabled URL filtering on Skype messages.
Internet: ZOMG you're reading my private messages. You monsters!
Technically, he didn't lie. He did say "unauthorized", after all!
> · Customer content moving between customers and Microsoft will be encrypted by default.
> · All of Microsoft’s key platform, productivity and communications services will encrypt customer content as it moves between Microsoft data centers.
> · Strong cryptography to protect these channels, including Perfect Forward Secrecy and 2048-bit key lengths.
Microsoft already does each of these today (for sure Exchange and SQL, which I know the best), and they have done them for years now. Nothing changes. The more important question is how Microsoft manages the keys for this encryption, because when I was there the keys were still based on NSA-approved root keys...
there was a good article recently that addresses this a bit better https://news.ycombinator.com/item?id=6833267
after a bit of reading about the topic you get more of a sense of how the PR machine is working since many big companies go the "no comment" route or just flat-out lie until they are finally caught red-handed. a statement from Microsoft (or anyone for that matter) doesn't really mean much unless they outline a technical methodology that can be thoroughly tested and verified by crypto experts/community.
Some might argue that it weakens the system by open sourcing it, but that's sortof the only way IMHO to get to a system that is based on actual crypto and information transmission theory and not just companies obscuring data with methods that will eventually be cracked.
Before using any Microsssoft product again, remember the parable of the Indian and the Snake: http://instereo92087.tripod.com/indiansnake.html
btw. oh wow, tripod is still around, nice to see some old websites
edit: Microsoft has been one of the voices calling for legal reform. I respect that. It might be a PR move, but still... I'll take it. :-)
In addition, Microsoft said it would enhance the transparency of its software code, helping to convince customers its products do not contain back doors. The company said it would go as far as opening a network of “transparency centers” designed to provide customers with greater ability to assure themselves of the integrity of Microsoft’s products. The centers will be opened across Europe, the Americas and Asia, Microsoft said."
Transparency centers, eh? Is that like a Microsoftian Ministry of Truth where inquisitors go to be reeducated?
Is that an office where you can sign an NDA and then read source code all day?
Is there a way that a company with closed source and proprietary infrastructure can prove that it's not up to any funny business?
Spideroak can, but only by opening up the client-side source code.
No.
Microsoft is running an anti-Gmail campaign blasting Google for snooping on emails in order to serve ads. http://betanews.com/2013/11/05/microsoft-is-at-it-again-new-...
It is not that complex, it is called "End the Patriot Act" or lobby for that. Until just telling your customer that they are being watched is against the law and they could go to jail for that, nobody should trust ANY American corporation.
And no, not all countries in the world have this kind of totalitarian laws. Yes, companies could give info about you to the government, but under court order, and those are public or private only for a small amount of time.
The funniest Microsoft story for me was the one regarding their former security chief. Nowadays he won't use Microsoft products or anything else where he can't see the source code. Until such time as Microsoft open source the stuff they churn out then all one can do is 'believe' them to be good and, after finding out how in bed they are with the military-industrial-complex, I just do not trust them.
I'm not saying that these customers don't have justification for their paranoia... just saying that there is an extremely high probability that Brazil, or Indonesia, or Statoil are planning to phase out use of American software over time in any case. In fact, it's so plainly evident that surely American tech companies should already be factoring it into their strategic planning???
Why not try to create some new customers? Or do something that doesn't rely on foreign organizations to trust, or use your software?
I don't know what that would look like... but that's why they get paid the big bucks.
Another big change for me would be if Microsoft announced that they stopped giving NSA lists of fresh Windows vulnerabilities before they even start working on them. Until they stop doing that, this is all pointless.
Their policy should be: "either everyone knows about the vulnerability, or nobody does.". Whatever argument they had before about "responsible" disclosure, is all moot now that we know they're disclosing those bugs to NSA in secret anyway.