Microsoft says it's prepared to hand over Skype users' data to Russia
globalpost.com
globalpost.com
How's that different from any other company? Even "secure" companies like Fastmail and others comply if they receive a court order for information on specific users.
Looks like an attempt to capitalize on the recent events by implicitly saying Microsoft will share everything about every user in bulk. What a surprise.
</godwin></thread>
We're not quite Russia bad yet, but we have however run "quick processing overnight courts" to deal with hundreds of people, thrown people in jail over Twitter jokes, kept people in jail for writing articles critical of the state, used extraordinary rendition like soap, murdered people critical of the government, shot unarmed civilians, started big wars, entertained numerous fascist dictators, operate large concentration camps to keep immigrants in, control media interests through the old boys network, force slavery on unemployed people by making them work for nothing and generally act like unsociable arseholes on the world stage.
In 2003 Operation Tiberius found that men suspected of being Britain’s most notorious criminals had compromised multiple agencies, including HM Revenue & Customs, the Crown Prosecution Service, the City of London Police and the Prison Service, as well as pillars of the criminal justice system including juries and the legal profession.
The strategic intelligence scoping exercise – “ratified by the most senior management” at the Met – uncovered jurors being bought off or threatened to return not-guilty verdicts; corrupt individuals working for HMRC, both in the UK and overseas; and “get out of jail free cards” being bought for £50,000.
http://www.independent.co.uk/news/uk/home-news/the-corruptio...
Seriously, I have powers of deduction that Sherlock Holmes himself would be proud of.
;-)
I'll never forget reading in the damn New York Times a week before Snowden leaks came out about how secure Skype was for dissidents and journalists, and I only remember that because it pissed me off to much that mainstream media was so clueless about its security. They still thought Skype was P2P even then. But part of that blame goes to Microsoft for continuing the illusion that they have that kind of security, when they didn't. Even Vice was recommending the use of Skype for secure conversations against governments when the whole McAfee thing happened.
At the very least, I hope people know better now. Also, maybe it is just a little different with Skype. I don't know if anyone else considers allowing the interception of their users' private conversations as a "team sport" [1]. The fact that NSA was willing to pay billions [2] for a Skype eavesdrop solution may or may not have something to do with the fact that Microsoft threw $8.5 billion on the table for Skype, even though the second largest bid from Google only went up to $4 billion (remember when everyone was so confused over why Microsoft would pay that much for Skype?). Also very interesting that Microsoft had a "legal intercept" patent for Skype, before even bidding for it [3]. Who does that?
If we look at when Microsoft added Skype to PRISM we also see it happened just a month after they said they would acquire them (announced in May 2011, ready for PRISM in June 2011), but before the transaction was even official [4]. It's all a very "interesting" series of events, to say the least.
[1] - http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...
[2] - http://www.theregister.co.uk/2009/02/12/nsa_offers_billions_...
[3] - http://www.networkworld.com/community/blog/microsoft-patent-...
[4] - http://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sli...
There was NEVER a time Skype was secure for people going against law of any kind. Unless you were clueless, you could ALWAYS expect your data to be handed to the authorities in case an investigation was ongoing. This is how things work in the real world of companies, government and law.
I think we are confusing "mass surveillance" and "bulk access" (all without probable cause in NSA's case) with lawful information sharing in criminal cases. I don't support the former the least but the later is a requirement. Please try to imagine a world where law enforcement could work efficiently if companies could simply tell a judge to f* off and withhold data that would help in an investigation (a lawful, very specific case... not the ghost hunts that the US/NSA/CIA does).
People have lost perspective with the NSA scandals and want to throw the baby with the bathwater. This is short sighted.
The supernode design isn't compatible with having lots of mobile devices, that's why it was changed. It's only marginally easier to intercept.
If it offered anything at all, it was a false sense of security.
Especially back then, 10 years ago. Even people like Bruce Schneier didn't suspect the NSA would as ruthless as recently revealed.
Even now the majority of non-mobile traffic seems to be direct P2P. I know because I checked using packet sniffers. In fact, even supernode traffic is P2P. Checking my router logs, I can see a number of connections made to Skype even when I'm not using it, which I presume is my machine being used as a supernode.
If a government does intercept all ISP traffic, they can listen in anyway.
The traffic might be encrypted, but the receiving party isn't the only one with the key. At the very least, the Skype service intermediated the key exchange.
We have the same kind of laws in Europe, and I'm pretty sure that the US requires it too.
And not complying with (secret - at least in the US) court orders just isn't an option if you want to keep your business in that country.
Think about it: Everyone is yelling on top of their lungs that Microsoft is giving your data, as if only Microsoft is doing that.
Now your average Joe will think that he would be rather using other services, e.g. Google because he thinks that only Microsoft is giving away your data ergo Google does not.
I'm not even joking, I've heard number of times stuff like "I'm on Ubuntu and it's Linux, suck it NSA!" it's not even funny.
I'd bet the average Ubuntu user doesn't even realise it's possible to turn off the adverts.
Your quotes are appropriate. It is not secure if there is a man in the middle who can turn my mail over to the government, even when they are presented with a court order.
The US isn't exactly the open country many pretend it to be. The primary difference seems to me, many countries openly declare they want the data, the US just does it anyway, denying it until caught.
Companies must balance the needs to customers versus doing business at all in some countries. Do they forgo the revenue because in some areas people are offended? Do they forgo revenue and fire their local workers to appease groups in other countries? As in, where does the process stop? Who is more right?
Profit-oriented organizations will comply rather than leave the country, unless it would lose them more business elsewhere. For this reason (among others), commercial-ware and commercial services are categorically untrustable.
News at 11.
Yet more wiggly phrases made to try to shift the goal posts that is privacy. Let's drop the meta.
I haven't installed Skype on Android because of the permissions it requests and for the reason that I rarely use it. But at least it's not preinstalled as are many Google apps similarly privileged.
Skype made a choice. Other choices were open to them, as they are now to every other provider of communication and storage. There is no excuse.