"When Redmond determined its authenticity, investigators looked through the blogger's Hotmail account and instant messenger, where they found incriminating emails and chat logs."
"When Redmond determined its authenticity, investigators looked through the blogger's Hotmail account and instant messenger, where they found incriminating emails and chat logs."
The blog post's source here is this Seattle P-I article : http://www.seattlepi.com/local/article/Ex-Microsoft-employee...
This article provides more color::
"""" The code was later confirmed to be authentic, prompting corporate investigators to dredge the Hotmail account the blogger used to contact the Microsoft worker. While the blogger took pains to protect his identity – he claimed falsely to be in Quebec and used an assumed name online – a Microsoft team dubbed Trustworthy Computing Investigations attempted to track the blogger down.
While searching the blogger’s account, Microsoft investigators found an email from Kibkalo in which he shared Windows 8 “hot fixes” through an online hosting system, the FBI agent continued. Windows 8 had not been released to the public at the time, and was the subject of much speculation in the industry.
Investigators claim to have recovered instant messages Kibkalo exchanged with the blogger showing Kibkalo was sharing trade secrets illegally.
“I would leak enterprise today probably,” Kibkalo told the blogger during an Aug. 2, 2012 exchange, according to charging papers.
“Hmm,” the blogger replied. “Are you sure you want to do that? Lol.”
Told the leak would be “pretty illegal,” Kibkalo is alleged to have responded “I know :)” """"
Hmm. So there are "charging papers" that provide an FBI statement which is the primary source here, but the P-I has not posted a link to those papers; I guess someone could dig up the complaint/affidavits if they want to see the full original text unfiltered by the P-I.
Here's a LinkedIn description of this group at Microsoft: http://www.linkedin.com/jobs2/view/10230290
"""" Job Category: Legal & Corporate Affairs Location: Redmond, WA, US Job ID: 852070-123363 Division: Advanced Strategy and Research
The Trustworthy Computing Investigations & Forensics team is a core unit within Microsoft’s Trustworthy Computing organization and is responsible for investigating escalated compliance violations, employee misconduct, and threats to the company and the corporate network. We provide technical expertise and investigative services to a variety of groups including: Legal and Corporate Affairs, Human Resources, Physical Security Investigations, the Financial Integrity Unit, and many others. In addition, the group provides more traditional subject matter and design expertise in a number of areas related to network security matters, investigative process, and digital evidence. This position is based at Microsoft headquarters in Redmond, Washington.
Travel: Periodic short notice/emergency travel may be required, primarily within North and South America.
Primary Responsibilities: - Conduct global IT-oriented security compliance investigations regarding breaches of policy, violations of standards of business conduct, hacks, leaks, and other escalated information security cases. - Provide expert technical guidance to other Microsoft groups and senior management regarding the technical and forensic aspects of major incidents and sensitive cases. Provide feedback and recommendations for remediation and policy changes - Develop, implement and refine industry leading procedures and methodologies for the conducting of forensic review of Microsoft platforms, applications, and information technology infrastructures - Perform forensic media acquisition and analysis - Communicate complex technical or evidentiary information and findings with internal customers and law enforcement agencies, if necessary - Maintain detailed and extensive documentation on all work performed. - Develop investigative plans, derive root causes from case facts and prepare executive level briefings - Proactively research new forensic technologies applicable across the enterprise, as well as the latest malicious technologies. Research includes the continuous assessment of the forensic implications of evolving and new Microsoft technologies, platforms, applications and data structures - Devise and drive remediation steps for affected internal clients after an incident has occurred - Keep abreast of developments in the areas of privacy and legal issues affecting corporate investigations and employee privacy.
Desired Background & Skillsets: - Strong familiarity with applicable local region domestic and international laws and regulations pertaining to information asset protection - Solid understanding of forensic methodologies, including in-depth knowledge of computer incident response processes, Microsoft file internals, as well as 'live' incident response techniques - Extensive host forensic analysis skills including strong hardware knowledge and skills, particularly with media and data storage, forensic imaging, and detailed file system level analysis - Strong experience with common forensic tools such as Encase, FTK, Winhex, etc. - Strong experience with electronic discovery tooling and indexing/keyword searching technology - Demonstrable knowledge of monitoring mechanisms, remote control services - Excellent written and verbal skills, including the ability to effectively communicate complex technical information to non-technical audiences. Must be able to lead presentations to senior management, and maintain detailed technical and investigative documentation. - Prior corporate, private, or law enforcement investigative experience preferred - Minimum of 5 years of demonstrated, relevant Information Security or related technical experience - Must be able to obtain necessary work permits and travel visas where applicable - Ability to be available “on call” on a 24 / 7 basis
Successful applicants will be subject to a satisfactory background check. """"
IANAL and I'm not based in US but I would guess the only way to do this legally would be for MS to go to a law-enforcement agency, the agency would need to get a warrant and then the agency would be able to look into it, not MS itself.
contracts are not above the law, if a contracts stipulates something illegal it doesn't matter that both parties agreed to it
This seems to disagree with you, seems you are required to litigate to get your rights. The blogger was french also, so that probably has a bearing on what rights he has.
Does Microsoft disclose my personal information outside of Microsoft? You consent and agree that Microsoft may access, disclose, or preserve information associated with your use of the services, including (without limitation) your personal information and content, or information that Microsoft acquires about you through your use of the services (such as IP address or other third-party information) when Microsoft forms a good faith belief that doing so is necessary (a) to comply with applicable law or to respond to legal process from competent authorities; (b) to enforce this agreement or protect the rights or property of Microsoft or our customers; or (c) to help prevent a loss of life or serious physical injury to anyone.
Notice the bit about "protect the rights or property of Microsoft or our customers".
[0] http://windows.microsoft.com/en-us/windows-live/microsoft-se...
http://arstechnica.com/tech-policy/2014/03/arrest-of-secret-...
"Select id from attachments where introspective_function(part) contains 'LPCSTR'" as a scheduled task?
It's possible the events went like this:
1) MS get suspicious and investigate, (legally) find things which point to the suspect.
2) They confront the suspect who confesses.
3) They take it to the authorities who as part of their investigation get court orders to access his hotmail accounts.
But based on what is here there is nothing that says MS did anything illegal. That's not to say they didn't, just that that's not what these posts say.
- "prompting corporate investigators to dredge the Hotmail account the blogger"
- "While searching the blogger’s account, Microsoft investigators found an email"
Obviously the guy was massively stupid using an e-mail service run by the people he was screwing over but it'll be interesting to see how this plays out (whether his employment contract covers it, whether that's legal and so on).
The blogger approached MS, so once they determined the code was authentic they could have easily got the FBI involved who then requested the information from the blogger's account.
But it doesn't read that way, it suggests that MS looked into it because it just says "investigators" and it's up to the reader to surmise what that means. My first thought it meant MS did the looking into the account mainly because there's no mention of a timeline of the actions taken. If it said something like "after MS authenticated the code the FBI was contacted who then requested a warrant to search through the blogger's account" then it would far more clear as to what was going on.
Makes me wonder if anyone bothered to ask the blogger if he would cooperate, as he did approach MS first, or if they just start looking through the person's account?
Later in the article they mention investigators again after the mention of criminal charges and then you can likely assume they mean criminal investigators.