Showing posts with label Skype. Show all posts
Showing posts with label Skype. Show all posts

Thursday, July 11, 2013

Revealed: how Microsoft handed the NSA access to encrypted messages

• Secret files show scale of Silicon Valley co-operation on Prism
• Outlook.com encryption unlocked even before official launch
• Skype worked to enable Prism collection of video calls
• Company says it is legally compelled to comply


Skype logo
Skype worked with intelligence agencies last year to allow Prism to collect video and audio conversations. Photograph: Patrick Sinkel/AP

Microsoft has collaborated closely with US intelligence services to allow users' communications to be intercepted, including helping the National Security Agency to circumvent the company's own encryption, according to top-secret documents obtained by the Guardian.
The files provided by Edward Snowden illustrate the scale of co-operation between Silicon Valley and the intelligence agencies over the last three years. They also shed new light on the workings of the top-secret Prism program, which was disclosed by the Guardian and the Washington Post last month.
The documents show that:
• Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal;
• The agency already had pre-encryption stage access to email on Outlook.com, including Hotmail;
• The company worked with the FBI this year to allow the NSA easier access via Prism to its cloud storage service SkyDrive, which now has more than 250 million users worldwide;
• Microsoft also worked with the FBI's Data Intercept Unit to "understand" potential issues with a feature in Outlook.com that allows users to create email aliases;
• In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;
• Material collected through Prism is routinely shared with the FBI and CIA, with one NSA document describing the program as a "team sport".
The latest NSA revelations further expose the tensions between Silicon Valley and the Obama administration. All the major tech firms are lobbying the government to allow them to disclose more fully the extent and nature of their co-operation with the NSA to meet their customers' privacy concerns. Privately, tech executives are at pains to distance themselves from claims of collaboration and teamwork given by the NSA documents, and insist the process is driven by legal compulsion.
In a statement, Microsoft said: "When we upgrade or update products we aren't absolved from the need to comply with existing or future lawful demands." The company reiterated its argument that it provides customer data "only in response to government demands and we only ever comply with orders for requests about specific accounts or identifiers".
In June, the Guardian revealed that the NSA claimed to have "direct access" through the Prism program to the systems of many major internet companies, including Microsoft, Skype, Apple, Google, Facebook and Yahoo.
Blanket orders from the secret surveillance court allow these communications to be collected without an individual warrant if the NSA operative has a 51% belief that the target is not a US citizen and is not on US soil at the time. Targeting US citizens does require an individual warrant, but the NSA is able to collect Americans' communications without a warrant if the target is a foreign national located overseas.
Since Prism's existence became public, Microsoft and the other companies listed on the NSA documents as providers have denied all knowledge of the program and insisted that the intelligence agencies do not have back doors into their systems.
Microsoft's latest marketing campaign, launched in April, emphasizes its commitment to privacy with the slogan: "Your privacy is our priority."
Similarly, Skype's privacy policy states: "Skype is committed to respecting your privacy and the confidentiality of your personal data, traffic data and communications content."
But internal NSA newsletters, marked top secret, suggest the co-operation between the intelligence community and the companies is deep and ongoing.
The latest documents come from the NSA's Special Source Operations (SSO) division, described by Snowden as the "crown jewel" of the agency. It is responsible for all programs aimed at US communications systems through corporate partnerships such as Prism.
The files show that the NSA became concerned about the interception of encrypted chats on Microsoft's Outlook.com portal from the moment the company began testing the service in July last year.
Within five months, the documents explain, Microsoft and the FBI had come up with a solution that allowed the NSA to circumvent encryption on Outlook.com chats
A newsletter entry dated 26 December 2012 states: "MS [Microsoft], working with the FBI, developed a surveillance capability to deal" with the issue. "These solutions were successfully tested and went live 12 Dec 2012."
Two months later, in February this year, Microsoft officially launched the Outlook.com portal.
Another newsletter entry stated that NSA already had pre-encryption access to Outlook email. "For Prism collection against Hotmail, Live, and Outlook.com emails will be unaffected because Prism collects this data prior to encryption."



Read More  Here


Enhanced by Zemanta

Monday, July 30, 2012

Microsoft denies claims made of “backdoors for government” to Skype. Noting it did recently overhaul its Skype network for Quality, Service and of course Security.


Microsoft-Skype Snooping Accusations Push All the Paranoia Buttons

Hold the phone, Internet, before deciding whether Microsoft has engineered a backdoor to allow Skype wiretaps.

By Robert X. Cringely, Infoworld
Has Microsoft has figured out a way to bug Skype calls? A report published in Slate late last week suggests this might maybe possibly be theoretically true — cue the InterWeb’s full-blown paranoia party.
In a blog post titled “Skype won’t say whether it can eavesdrop on your conversations,” Slate’s Ryan Gallagher determined through dogged questioning that Microsoft will neither confirm nor deny that it has built a backdoor into Skype that would allow the government to wiretap VoIP calls.
From this he naturally concludes that Microsoft really is eavesdropping on our conversations and is trying to keep it a big fat secret:
… when I repeatedly questioned the company on Wednesday whether it could currently facilitate wiretap requests, a clear answer was not forthcoming. Citing “company policy,” Skype PR man Chaim Haas wouldn’t confirm or deny, telling me only that the chat service “co-operates with law enforcement agencies as much as is legally and technically possible.”
Shares of Reynolds Wrap aluminum foil just went up 17 percent on the news.
Gallagher’s other “proof”? In June 2011, one month after Microsoft announced its acquisition of Skype, it received a patent for technology that would allow it to “silently copy communication transmitted via the communication session.”
Sounds scary, don’t it? The problem with that theory is a) Microsoft applied for this “Legal Intercept” patent two years before it acquired Skype, and 2) the patent doesn’t really say much about how the technology would actually work, let alone bust through Skype’s 256-bit AES end-to-end encryption.
Gallagher also relied on a story by another Forbes blogger, Anthony Wing Kosner, which quoted from an ExtremeTech story by Tim Verry about claims made a hacker who goes by the handle Alien Nesby, who says Microsoft added “backdoors for government” to Skype after the acquisition was final.
Nesby made his claim based on a 43-word comment posted three months ago on Hacker News, but he wrote it in FULL CAPS, so you know it must be true.
Microsoft directly denied the claims made in Verry’s post, noting it did recently overhaul its Skype network, but the changes were made to increase quality of service and security, not for spying. But that didn’t stop Forbes blogger Eric Jackson from jumping right on the paranoia pony and riding it to the finish line. In a blog post titled “It’s terrifying and sickening that Microsoft can listen in on all my Skype calls,” Eric proves he has 1) a rather delicate constitution, and b) clearly been taking courses in how to write traffic-magnet blog headlines.
First, let’s acknowledge it might be true that Microsoft has figured out a way to allow authorities to listen to calls made via Skype. That would bring Skype in line with the Communications Assistance for Law Enforcement Act (CALEA), or the same 1994 law that governs wiretaps and was expanded in 2005 to allow access to digital phone networks.
Skype has some 660 million users; do you really think the feds are going to treat it any differently than the cellphone you have in your pocket or the one that might still be plugged into your wall? The notion that Skype will, eventually, conform to CALEA is just a matter of time.
What happens to it from there — if all our calls and chats will then be sucked into the vast data center being constructed in a Utah salt mine by the NSA, for example — is anyone’s guess. Insert your favorite conspiracy theory here. Also: Get me James Cameron, I have a movie script I want to pitch.
Until then, though, we need to take a deep breath and figure out what is actually true about any of this. So far, there ain’t much.
What Microsoft should do is issue a transparency report similar to the ones released recently by Google and Twitter, detailing the many requests it receives for user data from various and sundry government authorities. It should also officially publish the guidelines authorities must follow in order to request information, as well as what types of data are available and how long they are retained. That document [PDF] was made available via a leak to Cryptome.org and is now four years old; I’d like a fresh copy, please.
That would be one way to dispel the notion that Microsoft is the evil bogeyman — at least, more evil than all the other bogeymen. But it won’t make for a very sexy headline.
Is Microsoft Skype-spying on us? Doff your tin foil hats below or beam your thoughts to me via cringe@infoworld.com.
This article, “Microsoft-Skype snooping accusations push all the paranoia buttons,” was originally published at InfoWorld.com. Follow the crazy twists and turns of the tech industry with Robert X. Cringely’s Notes from the Field blog, and subscribe to Cringely’s Notes from the Underground newsletter.
For more IT analysis and commentary on emerging technologies, visit InfoWorld.com. Story copyright © 2011 InfoWorld Media Group. All rights reserved.