Slashdot Mirror


Surveillance Backdoor Enabled Chinese Gmail Attack?

Major Blud writes "CNN is running an opinion piece on their front page from security technologist Bruce Schneier, in which he suggests that 'In order to comply with government search warrants on user data, Google created a backdoor access system into Gmail accounts. This feature is what the Chinese hackers exploited to gain access.' His article is short on sources, and the common belief is that a flaw in IE was the main attack method. Has this come up elsewhere? Schneier continues, 'Whether the eavesdroppers are the good guys or the bad guys, these systems put us all at greater risk. Communications systems that have no inherent eavesdropping capabilities are more secure than systems with those capabilities built in. And it's bad civic hygiene to build technologies that could someday be used to facilitate a police state.'"

2 of 143 comments (clear)

  1. Re:Careful There, Schneier by Anonymous Coward · · Score: 5, Interesting

    "He better be able to back it up."

    He doesn't have to. I'll explain later. In fact, reactionary posts like yours and the /. article is an inhibitor in favor of backdoors like this, instead of being patient and seeing what comes out. You are attacking the holder of the opinion, redirecting focus to the very real case of government backdoors and general population communication abuses, which has been proved, real, and pronounced (see AT&T eavesdropping and others).

    Which is a shitload worse than Schneier mere opinion, even if unsubstantiated (which is worse than uncorroborated) on the matter.

    "I just want to caution everyone that you're reading an opinion piece by a security blogger with no corroborating evidence." ,,,in the story. He may have corroborating evidence, but is smart enough not to put it forward for both his sake, his sources sake, and/or as bait.

    If he had that evidence, he'd be held for obtaining classified information without a due security clearance and prosecuted.

    "I have respect for the man but this certainly shakes that. Any concrete proof of this would be welcomed. The problem is I'm not sure how one would prove it one way or the other since I believe all the source in question is closed source to begin with."

    Very true and you start in on the crux of this matter of releasing source info. However, I think you are looking at this as overly critical of Schneier, instead of looking at the whole picture. He lives in the real world, he has to live with the repercussions to his life, far more than you or I.

    If he releases the info and has a source, Schneier himself gets prosecuted or at least subpoena'd for his source, and if he refuses to reveal it, he gets locked up. His source, at the very least, can be revealed and gets pounded (and people like you won't do a think and can't). And Schneier loses future use of his source. iow, at the very best, he can only suggest his opinion, which is what he is doing.

    If he simply airs the idea out there, knowing it's true, that's fine by me. Maybe it isn't for you, but he's been right far far more often than not so in this case, I think people should look at the bulk of his work instead of just one instance that has yet to play out fully. If he continues to do this repeatedly for other issues, then yes, I'd start to shift in your opinion of the man. But I haven't seem him abuse his reputation. iow, if this is a lapse, it's unfortunate, but Schneier is human, and I doubt it's a lapse of judgment.

    If he doesn't have a source, but has evidence, and isn't sure, he may be airing this out there without corroborating evidence (having no substantial evidence of course), to see what happens. If they go after him, then you have a tell tale sign. If there are code changes, again, tell tale sign. If he gets harrassed or hammered by 3 letter agencies, again, tell tale (and maybe this has already happened).

    If he simply just threw it out there, then, yeah, shame on him, but again, I haven't seen him do this in the past, so I'm very willing to give him the benefit of the doubt, since his contributions, sources, and info in the past has been spot on. His hands may be tied in this case or he's being careful (esp. with a new administration that still has strong ties in the agencies to the prior administration, with a pro-prosecutional bent to it to go after small fries which Schneier would be in the grand scheme of things in the populace).

    Your opinion will likely differ on this, but as you seem well aware of his legacy, I think it's over done to be this critical this early in the game.

  2. Re:Think about it a second by russotto · · Score: 4, Interesting

    That isn't quite how it works. Other than the normal billing logs, the phone companies do NOT log all the data, much less voice logs, without a specific request.

    I don't know about cell. But on land lines, they DO log everything. The switches emit raw call record data. The billing logs are produced from the call record data.