Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not sure why you're picking on Microsoft. The credibility of pretty much every large US-based tech services company is probably destroyed. The fact that we only saw the big service providers (MS, Google, etc...) on those slides doesn't mean that the other companies are free from the hands of the NSA.

Do you think that the NSA has no access to Dropbox?



I'm not sure why you're picking on Microsoft.

One of the key facets of the the Xbox One is the Kinect as an always on device. As another poster pointed out, Microsoft has been quick to answer the privacy related questions that have been asked about this situation with the claim that the system has been built with privacy as a focus. As such, the reliability of those claims in light of this new leak appears to be relevant.

For example, given a court order, would Microsoft be required to:

1.) Provide law enforcement with Kinect data. (everything from as simple as "there were two people in the room" to "here is a live stream of the room"

2.) Be bound by gag orders not allowing Microsoft to reveal the existence of item 1.

3.) Be forced/coerced/enticed to provide bulk "wiretapping" of Kinect data.

Additionally, there is the question of "expectation of privacy". Many of the current privacy laws are based on this concept. However, could the courts decide that there is no expectation of privacy when a video and audio recording device has been placed in a private area, with full knowledge of the owner, also with knowledge that the data will be sent to a third party?

While these items might seem fringe (and before these leaks, I may have agreed), the scope of the current leaks seems to imply that these questions should at least be considered (even if a person chooses ultimately to accept the risk).


Enterprise relies on companies such as RedHat and Oracle to some extent in lieu of conducting code analysis and to certain types of security testing.

It would be rather surprising if they were not at least approached by Federal agencies such as NSA and FBI.

To put it another way, because Microsoft has a closed source model, the intelligence agencies took the approach described in the article. From that, it may be a mistake to conclude that the strategy pursued with Microsoft was the only strategy pursued. It just happens to be one that would pass across the desk of an analyst, rather than someone on the operations side.

Viewed as an intelligence operation, it would be grossly unprofessional of such agencies not to have placed moles within the open source community, or for those moles to be seen as highly skilled contributors on open source projects. The three letter agencies have decades of experience infiltrating both commercial organizations and those motivated by something other than money.

I suspect it is easier to turn an open source hacker than a diplomat - not just ideologically but because the open source community lacks a state funded organized counter-intelligence apperatus.


If there were backdoors in the distributed Redhat code, how many people would even be able to know this? And that's if the code were blatantly obvious if you were allowed to see what was actually compiled. If the compiler itself is compromised then it would be possible that no one at Redhat would know.


Dropbox was listed as "coming soon"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: