Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Microsoft's June 7th statement:

"We provide customer data only when we receive a legally binding order or subpoena to do so, and never on a voluntary basis. In addition we only ever comply with orders for requests about specific accounts or identifiers. If the government has a broader voluntary national security program to gather customer data we don’t participate in it."

One down, several to go. If I were Google/Facebook/Yahoo executives I would be very worried right now as to what soon-to-be-released revelations say about their NSA cooperation. Sure, they may have only done that which was compelled by FISC order, but that won't preclude them from being perceived as culpable.



The interesting conflict to me is that Google et al don't appear to be fighting this battle. When it comes to other things, they are in the streets, funding lobbyists, building protest websites, and so on. But this, which threatens their entire business model (essentially trust-based), they haven't made a peep about.

It may just be a gag order thing, sure. But with the level of access required for stuff like this, I don't think they could shut the whole team up. How many people worked on this Microsoft back door? It can't have been less than a couple dozen at least. And none of them raised the issue or let someone know, a journalist for instance, or publicly raised the question?

It makes me wonder about the true extent of the programs we're freaking out about. I mean, of course they exist and they're big and threatening, but I don't buy that they could combine complete access with complete secrecy. They need the cooperation of the companies, and the companies, by NSA standards, just aren't trustworthy enough. In fact, they're full of wild cards like Snowden, denizens of newsgroups, IRC, 4chan, etc, who would LOVE to be the one to blow up an NSA attempt to write a back door into Skype.

Maybe they did, and it all faded away. But it just seems strange to me that so little has been said about the elephant that must surely have been in everyone's room for the last few years.


The peculiar part for me with Google is that they seem to be somehow immune from all the revelations. People keep stand by it and get annoyed when reminded of their wrong-doings. I suspect at this point, they're not much different than Microsoft. But the "don't be evil" brand is still strong in the mind of many.


Speaking for myself, but I'm sure others share the sentiments, its not that i think google is somehow "good". They're obviously not, the difference is that they're still a cool tech company doing cool things on a massive scale (or potentially very disruptive).

self-driving cars, balloon network testing in NZ, google fiber, and more mundane things like Golang and angular.

I don't give them a pass, its just that in the bad column they're the same as all the other actors in this drama, on the good column they're a damn cool tech company that can realistically change the world in fundamental and positive ways.

EDIT: also for the most part their interests are selfishly aligned with ours. They want a fast easy open internet. That contrasts pretty sharply with FB/MS/APPLE - who are more about hardware/walled gardens. Though all these lines seem to getting blurred.


Google isn't above doing things that harm people to make them more money. Like the steadily decreasing background contrast and lack of borders separating ads from search results. Older people are far less cognizant of borders and thus would click on ads thinking they're search results.

http://blumenthals.com/blog/2012/01/31/is-google-intentional...

They recently got rapped by the FTC for it.

http://wallstcheatsheet.com/stocks/ftc-googles-ad-practice-i...

The difference is that the negative Microsoft news tends to float on top of sites like HN more than positive news, and the reverse is true for Google so this alters perceptions of people.


Actually, the "they" that got "rapped" by the FTC were "AOL, Ask, Bing, Blekko, Duck Duck Go, Google and Yahoo as general purpose search engines and 17 'of the most heavily trafficked' shopping, travel and local search engines"[1].

These were reissued rules that clarified and enhanced the rules issued by the FTC in 2002 to make advertising clear. It likely came out of Danny Sullivan's letter to the FTC[2] showing how the competitors accusing Google Shopping of not disclosing paid inclusion well enough had no intention of themselves following the FTC's rules.

> The difference is that the negative Microsoft news tends to float on top of sites like HN more than positive news, and the reverse is true for Google so this alters perceptions of people.

You clearly visit a different HN than I do. While there is plenty of positive Google news here, the negative news in the top 10 is almost daily (Reader, account closing, PRISM, etc). Considering your account is 6 hours old (with 196 karma!), maybe stick around for a while before making pseudo-hypotheses about story dynamics?

[1] http://searchengineland.com/ftc-search-engine-disclosure-164...

[2] http://searchengineland.com/a-letter-to-the-ftc-regarding-se...


"maybe stick around for a while before making pseudo-hypotheses about story dynamics?"

Ok I've been around for awhile and can vouch that what he's claiming happens regularly. Some links from the last time I bothered to comment on it can be found in the following:

https://news.ycombinator.com/item?id=5731329


And, as last time this topic was brought up, I feel obliged to point out that HN rank is more than a function of votes, flags, comment total, and time. The quality of the comments, likely determined by the speed and voting patterns, is also used. This, or a similar system, is also reputed to be used to hide the "reply" link during suspected flamewars.

So sure, you could blame some perceived Google bias on Google shills flagging Microsoft articles. You could also blame some perceived Anti-Microsoft bias on Microsoft shills being abrasive and causing comment sections to become toxic (for example, by filling the comment sections with comments complaining about HN rank compared to Google articles).

I see little to no evidence for either, I am not in a position to inspect the complete data to determine what is causing any perceived phenomenon (nor are you, I suspect).


It's pretty clear when an article has been flagged off the frontpage intentionally on hnrankings.info and in my experience every link of the type also "just happened" to be anti-google, pro-ms or pro-apple.


I have seen your links to hnrankings.info and cannot say that they make it clear flagging is the cause (much less organized flagging). Your (and others) assertions are too strong for the data that you have.

With hnrankings.info I believe you could establish a trend (so far I have only seen specific handpicked examples, not a trend. A trend is probably there, but nobody that I have seen has bothered to do the legwork to uncover it.), but there is not enough there to say that (as many have claimed) there are non-organic rings of flaggers targetting pro-Microsoft articles.


I haven't bothered to link many hnrankings I've done personally because (tangent) both HN search & hnrankings.info are blocked by the handsome and intelligent admins at my office (/tangent).

But here's a simple experiment that can be done in a few minutes: search for daringfireball.net links on HN, click on the ones with a decent number of points, put those into hnrankings.info and you'll see a clear pattern of flagging for pretty much every single one.

Now maybe Gruber articles are just terrible (ymmv) but I can say that every other article I've seen flagged down (fairly easy to tell from rank/points/time) falls into the same categories. And I don't see how it's a big conspiracy theory to apply occam's razor to the observation that "hey all these anti-google or pro-apple or pro-ms links have a graph that makes it look like they were flagged off the first page". The same mentality that would abuse this is not hard to find in the comment sections of many tech sites so I'm not sure why anyone would be surprised or think HN is immune.

And again if HN mods want to produce a list of flagged articles I'm confident it would back the assertions that I and others have made.


I might be just a single data point, but PRISM is the primary cause of my slow but persistent move away from Google services.

Oh, btw, I know many people over here in Europe who never use any Google service other than search out of general mistrust towards the company. Might not help them much, as the search history combined with the IP-address logs of all the G+ buttons is already a pretty encompassing profile, but nonetheless they exist and constitute a non-negligible fraction of the populace over here.


Not just G+ buttons either. How many websites these days _arent_ running Google Analytics?


For me, all of them. Thanks to Ghostery.


Ghostery is just another form of an analytics platform. I hope you realize that.


They still realease a lot of Open Source software, support open source projects (Google summer of code) and publish somewhat sensible standards like SPDY. The last time Microsoft published a standard it used lobby power to push it through ISO fast track. It's horribly bloated and it was quite obvious that they only wanted to avoid to seem unsustanable as data format provider. If Google turns evil, we have a big mess, but in the end we have also won much. Microsoft does not have much to show except for market opression and closed down products. They are still very, very far away from each other.


What surprises me is that for example Apple and Google don't simply ignore the gag orders, and just release what and how much they have handed over.

Google/Apple are not going to get shut down over this. They can afford lawsuits and penalties. So why not take a stand? Are they really that timid? Or is what they would reveal actually so grim they just sit by and hope they're somehow going to escape this?

This is the time to put cost/benefit analysis aside and take a stand. Show the world what kind of company you are. So far, its all whimps and pushovers.


It's easy to suggest that someone else should go to prison.


While I would not bet money on it, it might be possible that the NSA has dirt on these companies, or on their high-ranking employees, keeping them from taking a stand.


http://www.newyorker.com/online/blogs/johncassidy/2013/06/go...

"Google Lawsuit Challenges N.S.A. Domestic-Spying Apparatus"

the first hit on google for "google nsa lawsuit"


This lawsuit was filed after NSA was found with its hand in the cookie jar. I think devindotcom means, why were these tech companies not fighting this years ago. I guess you cannot fault Eric Schmidt, because he has been dropping lines like these [1] for years.

  We know where you are. We know where you’ve been.
  We can more or less know what you’re thinking about

  Just remember when you post something, the computers
  remember forever
[1] http://www.stateofsearch.com/top-15-of-eric-schmidts-remarka...


> the first hit on google for "google nsa lawsuit"

[emphasis mine]

...and for you!

[filter bubble anyone?!]


Are you implying that he's living in a google bubble? I just searched with multiple search engines, with different browsers, and even with different IPs and they all returned a link to the same effect. Different sources (prweb on most), but still the same story.



Wow, almost all of the results of 'google nsa lawsuit' on bing are negative against google.

http://www.bing.com/search?q=google+nsa+lawsuit

1) Maryland Attorney Mike Slocumb Comments on Google Privacy Class Action Lawsuit and NSA Surveillance Case (negative)

2) Google surveillance far surpasses the NSA, author says - CBS News (negative)

3) EPIC files FOIA request over reported Google, NSA partnership ... (negative)

4) ACLU sues Obama administration over NSA surveillance (neutral - not even really about Google, just prism)

5) Lawsuit Could Find Out If Google Working For NSA? For a long… (negative)

6) Conservative activist files lawsuit over NSA surveillance | PCWorld (neutral)

7) Maryland Attorney Mike Slocumb Comments on Google Privacy… (negative)

8) Lawsuit filed over NSA phone spying program - Computerworld (neutral - not even really about Google, just prism)


And almost none of the results of 'google nsa lawsuit' on google are negative about google: http://www.google.com/search?q=google+nsa+lawsuit

Everything is a filter bubble.


Move along and keep on shopping. Nothing to see here.


This information was brought to you by the Ministry of Truth division, MegaCorp-M. Have a fun, happy day, Consumer. And remember: relax, and don't think too much!


Oh, come on.

Developers only need to build some APIs - those APIs can be multi-purpose. They don't need to know that one such purpose is NSA spying - you can come up with dozens of other reasons for wanting a "back door".

The actual interface that's used for responding to legally binding orders or subpoenas and that uses the APIs in question can be built by people on NSA's payroll.

Besides executives, the only people slightly aware of what's going on will be some people from the legal department. And they'll get presented with an interface in which they have to double-check (in bulk) the validity of received orders.


As far as I understand from the other press coverage the current procedure is that people in MS legal department don't even have to "check" that specific orders exist, it's something that the API user is supposed to do on their side. The procedure specifically allows API requests and monitoring immediately and providing the orders in some-week time or if the order doesn't come "destroying" the obtained data that aren't metadata. Metadata can always remain because they are considered "public" in the current up-to-recently secret law interpretations. And for non-US-citizen-or-not-on-US-soil data the orders are never needed.


Give me 12 (a dozen) reasons to break the encryption and security of your users that could be acceptable to a non brain dead engineer and exclude surveillance and government snooping?


You're missing the fact that if a middleman does the encryption or has access to the decryption key, then encryption is already broken.

A service provider is the middleman in this case and encryption only serves the purpose of you making sure that communications are with this service provider and not with another middleman.

"Breaking the encryption" is not accurate. They don't need to break anything as your data is in plain text on their servers.


> "Breaking the encryption" is not accurate. They don't need to break anything as your data is in plain text on their servers.

While this is true, I don't think it was his point. His point, I believe, was that the software should protect the data, and the engineer should not install or create APIs that allow someone to circumvent the security and privacy of the user — for any reason. He was replying to someone saying that higher ups could lie about the reason or need for such an API; his reply was saying that even the lie should be so obviously privacy-breaking as to be unacceptable. (Hence, he asked for examples.)

That said: legitimate law enforcement requests, i.e., warrants, would be an acceptable reason to me to implement such an API. That said, it should be auditable, so that you can verify it isn't being abused.


It's possible companies run an NSA module on their servers and let backdoor hacks happen based on an understanding the NSA will get pissed if they investigate.

This provides full PRISM access and allows for deniability of direct access.

Oh what's that? There is an NSA module most big companies run on their servers? Right, it's called SE Linux. The question that remains how do you build a backdoor that cannot easily be spotted in the source code. Maybe a weakness in a random number generator used for encryption. Oh what's that? The NSA does that too?

On Backdoor in encryption standard: http://www.wired.com/politics/security/commentary/securityma...

On SE Linux: http://www.businessweek.com/articles/2013-07-03/security-enh...


It can't have been less than a couple dozen at least. And none of them raised the issue or let someone know, a journalist for instance, or publicly raised the question?

This speaks about the lowest level of ethics. Many things are more important than the shareholders Once I was working for the tax agency of my country and they wanted to hide tax information for specific politicians (that obviously were involved in corruption cases). I loudly spoke against the project and was ready to speak about it to the press. The project was cancelled at the end.


It's interesting to contrast our current attitude with Microsoft/Skype with similar news 1 year ago: https://news.ycombinator.com/item?id=4254925

Oh how times change.


I remember this, has it really been a year? Man, time flies. It is indeed interesting how far the attitudes have shifted.


Honest question: how does that article contradict that statement? Everyone is bouncing off the walls about this but I honestly can't see where the story is. Microsoft + others enable NSA to access customer data when presented with court order. You can agree or not agree but is it really a shock?


I'm probably overly sensitive to this, being a "non-US person", but I'm constantly reading "with a court order" as "either with a court order, or with a 51% suspicion that one of the two parties to the communication is not a US citizen - in which case we can do what we like"


Providing integration to make access easier is part of a voluntary NSA program (Twitter has said they refused to participate).


Well that quote may be a technically accurate statement. They don't "provide" data directly to the NSA with out a secret FISA order. But, the new leak article seems to suggest that they weaken their cryptography, perhaps turn over private keys, re-architect their topology, and adjust their technology to allow the NSA to trivially easily intercept/get the data of every single Microsoft technology user.

A little bird told me that Microsoft was the most "helpful" out of all the big tech companies. If this new article is accurate, I hope that statement also was. I'm rather pro-US/NSA. But, even I find this new leak very disturbing if it's accurate and true.

Being realistic, I bet all the other big American tech companies are doing similar things. For example, my thinking is still that FB gives law enforcement a "god view" of all information and communications (even if it is in a round about way, like Microsoft allegedly does).


This latest release does not contradict that. They provide user data for accounts under surveillance in real time. To place an account under surveillance, the government needs a valid court order for that account.

This document just says that surveillance was broken for chats when they did the outlook.com upgrade, but that has since been fixed.


Word games; notice the use of the term "voluntary".

This also provides some answers to http://www.skypeopenletter.com/.


What's sad that I'm neither surprised nor shocked about Microsoft doing this. If we hear the same about Facebook or Apple I'm not likely to be surprised either. If/when we hear the level of Google's involvement, that will be very interesting, because although a lot of people suspect that Google invades people's privacy, we've never really had any concrete proof or examples of it.


Scroogled!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: