Slashdot Mirror


Leaked Memo Says Apple Provides Backdoor To Governments

Voline writes "In a tweet early this morning, cybersecurity researcher Christopher Soghoian pointed to an internal memo of India's Military Intelligence that has been liberated by hackers and posted on the Net. The memo suggests that, "in exchange for the Indian market presence" mobile device manufacturers, including RIM, Nokia, and Apple (collectively defined in the document as "RINOA") have agreed to provide backdoor access on their devices. The Indian government then "utilized backdoors provided by RINOA" to intercept internal emails of the U.S.-China Economic and Security Review Commission, a U.S. government body with a mandate to monitor, investigate and report to Congress on 'the national security implications of the bilateral trade and economic relationship' between the U.S. and China. Manan Kakkar, an Indian blogger for ZDNet, has also picked up the story and writes that it may be the fruits of an earlier hack of Symantec. If Apple is providing governments with a backdoor to iOS, can we assume that they have also done so with Mac OS X?"

152 of 582 comments (clear)

  1. How Not to be Seen by alphatel · · Score: 5, Insightful

    The next time you text "i hacked my xbox!" to your friend, expect federal prison for life.

    It's all a big setup. The Patriot Act lets them investigate anything, anywhere, without a warrant. Now they are on your devices. Now any terrorist loses his rights as an American. The next war is at civil. No wonder the troops are coming back home.

    --
    When the foot seeks the place of the head, the line is crossed. Know your place. Keep your place. Be a shoe.
    1. Re:How Not to be Seen by fred911 · · Score: 5, Insightful

      PGP... it's way past time. Clinton was trying to mandate forced escrow keys for strong encryption years ago, first warning. Now, you can't place your trust in anyone but yourself to protect your privacy.

      --
      09 F9 11 02 9D 74 E3 5B - D8 41 56 C5 63 56 88 C0 45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
    2. Re:How Not to be Seen by loufoque · · Score: 4, Funny

      The next time you text "i hacked my xbox!" to your friend, expect federal prison for life.

      Hacking stuff you own is perfectly legal.

    3. Re:How Not to be Seen by Anonymous Coward · · Score: 5, Funny

      You must be new around here..

    4. Re:How Not to be Seen by amiga3D · · Score: 4, Insightful

      What does legality have to do with it?

    5. Re:How Not to be Seen by loufoque · · Score: 2, Funny

      You only get thrown into federal prison for doing illegal things.

    6. Re:How Not to be Seen by Dunbal · · Score: 5, Insightful

      PGP... it's way past time.

      Yeah that will work if they are reading your keystrokes.

      --
      Seven puppies were harmed during the making of this post.
    7. Re:How Not to be Seen by Anonymous Coward · · Score: 5, Insightful

      Everyone has done something illegal. They might not know it and it might not have been immoral. As long as you can monitor everything they do you can find a reason to send them to jail if they start to express 'undesirable' opinions.

    8. Re:How Not to be Seen by swalve · · Score: 5, Funny

      There will be a decoder ring to encode keystrokes.

    9. Re:How Not to be Seen by Anonymous Coward · · Score: 4, Funny

      You only get thrown into federal prison for doing illegal things.

      But innocent people have nothing to hide!

    10. Re:How Not to be Seen by Anonymous Coward · · Score: 4, Informative

      You only get thrown into federal prison for doing illegal things, in america, if your outside america you get drugs, stuck in nappies and an orange jumpsuit, abducted, flown to a foreign state know for torture, held and tortured then released in another country on the side of the road. all for having a name as come as Smith in the arab world. https://en.wikipedia.org/wiki/Khalid_El-Masri

      And that was a citizen of a member of nato.

    11. Re:How Not to be Seen by indytx · · Score: 4, Informative

      Hacking stuff you own is perfectly legal.

      It is until the government makes it illegal. The number of federal crimes has ballooned from around 3,000 in the 1980s to an estimated 4,500 today. wsj.com The Feds seem to make all kinds of things illegal today, so I wouldn't hang my hat on whether it's illegal or not. Where would one even look? Have you ever seen the United States Code? It's a nightmare. New bills that come up for a vote that amend an existing statute, for instance to add a crime to an existing statute, don't republish the whole statute, the bill shows the changes to the statute, and they show that they add a sub-paragraph here or remove a word there. It's really very difficult to figure out what's going on, even for our legislators.

      --
      Make love, not reality television.
    12. Re:How Not to be Seen by filthpickle · · Score: 2, Informative

      that was always my thought....maybe the NSA can decode a file encrypted with a good pgp key.....maybe they can't.....but there are easier ways to get whats in it anyway.

    13. Re:How Not to be Seen by Anonymous Coward · · Score: 5, Interesting

      Everyone has done something illegal. They might not know it and it might not have been immoral. As long as you can monitor everything they do you can find a reason to send them to jail if they start to express 'undesirable' opinions.

      I can be more specific. All programmers violate patent law every time they code, whether they release their code or not.

      question:
      How is it we've accepted a set of laws that guarantee we'll be lawbreakers subject to enormous civil fines and seizure and what can we do?

      answer: publicly funded elections.

      puzzler: explain the answer

    14. Re:How Not to be Seen by jotaass · · Score: 5, Funny

      Obligatory: http://xkcd.com/538/

    15. Re:How Not to be Seen by mcgrew · · Score: 3

      Oh, yeah? You get thrown in prison for being convicted of a felony whether you committed the crime or not.

    16. Re:How Not to be Seen by sapphire+wyvern · · Score: 5, Insightful

      Sounds like you need a US Code Repository, with bills published as changesets, but retaining the ability to pull a complete version of the legal framework that is actually in use.

    17. Re:How Not to be Seen by HAKdragon · · Score: 4, Funny

      Don't forget to drink your Ovaltine.

      --
      "Our opponent is an alien starship packed with atomic bombs. We have a protractor."
    18. Re:How Not to be Seen by dargaud · · Score: 4, Informative

      Sounds like you need a US Code Repository, with bills published as changesets, but retaining the ability to pull a complete version of the legal framework that is actually in use.

      I really wonder why this hasn't been done years ago. Some svn+wiki could be hacked easily, with the whole changelog, the name of the senators/governors who voted on it and links to law cases that applied it.

      --
      Non-Linux Penguins ?
    19. Re:How Not to be Seen by joocemann · · Score: 4, Informative

      In this case, Apple was aiding and abetting foreign intelligence services collecting against the US. Thats illegal.

    20. Re:How Not to be Seen by mosb1000 · · Score: 5, Interesting

      Question: We've given way too much power to the government and we are about to be trapped in a dystopian police state. What can we do to stop it before tos too late?

      Answer: Give the government control over campaign finance as well.

      Puzzler: Why do I have a bad feeling about this?

    21. Re:How Not to be Seen by Nemyst · · Score: 2

      Obviously you need to carry your own portable Enigma machine and pass text through that first before typing it in your mobile phone.

    22. Re:How Not to be Seen by Wootery · · Score: 4, Insightful

      Valid point: there's a Real Life workaround for crypto: force.

      But it's still quite a big win: if they can't watch you without threatening you, they can't watch you without telling you.

    23. Re:How Not to be Seen by Stiletto · · Score: 3, Interesting

      I don't like either, but while we still have elections, I'd rather have government power than corporate power. At least with the government you can vote them out. You can't vote a company out of existence.

    24. Re:How Not to be Seen by swillden · · Score: 2
      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    25. Re:How Not to be Seen by hairyfeet · · Score: 4, Interesting

      I have to wonder how "ahead of the game" the average law enforcement is when it comes to crypto simply because talking to a friend in the state crime lab (he keeps trying to hire me but...damn i don't think i could handle that shit 5 days a week) I have learned that even internet criminals are like most criminals and just very very very very...dumb. I mean stupid on whole never before seen levels of dipshit, just ignorant like you wouldn't believe. I had to cook up a batch file for my buddy last year because all his tools are based on NTFS and he couldn't recall off the top of his head the old DOS commands and they had found a braintrust still using Win98SE! Sure enough Mr Dipshit had hidden enough CP on his drive to get himself 300 years by dropping it in a subfolder in the Windows folder. no crypto, hell not even a password protected zip file, just dropped in a damned folder.

      So while I'm sure the NSA and Interpol have some chops simply because they have to deal with foreign powers and spies I have to wonder if the rest simply are up on their game because the "cyber criminals" they have to deal with are about as smart as the dipshit we had rob a bank last year while wearing his workshirt with his name and the name of the company in bold letters right on the front. Hell the lettering was big enough they could just read the shirt right off the security cam and sure enough Mr braintrust showed up for work the very next day and was shocked! Shocked I tell you! That they had managed to catch his brilliant ass.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    26. Re:How Not to be Seen by lostthoughts54 · · Score: 2

      but that would give way to much info to the common man. Our Gov would never allow this kind of power to rest with its citizens.

    27. Re:How Not to be Seen by Doc+Ruby · · Score: 2

      While I tend to agree with you, we don't have evidence of the US government having a backdoor to your devices. This story is about the Indian government, and how India is spying on the US government. It's the US government getting spied on, which is not exactly the opposite of the US government spying on Americans with device backdoors, but it's closer to the opposite than it is to what you said.

      I expect that if "RINOA" gave it to India, that it gave it to the US, too. But until I see evidence of it, it's just an "educated suspicion".

      As an American I'm upset enough about Apple, an American corp, along with a Canadian and a Finnish corp, giving India the means by which to spy on my government. I can also get outraged about my government spying on me, but I need some actual evidence before I prioritize that.

      --

      --
      make install -not war

    28. Re:How Not to be Seen by mosb1000 · · Score: 4, Insightful

      If the government is corrupt, why would that corruption not extend to campaign finance reform?

    29. Re:How Not to be Seen by hacksoncode · · Score: 3, Informative

      Just one point. Violating "patent law" isn't a criminal offense, it's a civil tort (IANAL, but deal with patents a lot). The government can't come get you and throw you in jail for that one (to any greater degree than they can, of course, do it without any reason whatsoever).

    30. Re:How Not to be Seen by ohnocitizen · · Score: 4, Insightful

      Question: We've given way too much power to corporations and the government, and are about to be trapped in a fascist police state (where corporate and state power join... see SOPA et al for references). What can we do to welcome it with open arms?

      Answer: Fight among ourselves, either choosing the corporate side (because in the libertarian fantasy world where govts have no regulatory power, bullies do step in and do what they want), or the government side (where the government has a police state to smash immigration, protests, etc).

      Better Answer: Let's unite over what really matters: A system of government where votes count, money doesn't buy elections or politicians, and "we the people" actually do run the country. That means campaign finance reform. It means overturning Citizens United. It means getting rid of the electoral college. It means dumping primaries and instituting instant run-off voting. So we end up with a single national popular vote, with instant-run-off, no states getting to go first, and no vast sums of money polluting the discourse and purchasing politicians. That is what we fight for.

    31. Re:How Not to be Seen by CheerfulMacFanboy · · Score: 3, Insightful

      You only get thrown into federal prison for doing illegal things, in america, if your outside america you get drugs, stuck in nappies and an orange jumpsuit, abducted, flown to a foreign state know for torture, held and tortured then released in another country on the side of the road. all for having a name as come as Smith in the arab world. https://en.wikipedia.org/wiki/Khalid_El-Masri

      And that was a citizen of a member of nato.

      You forgot to mention "get detained and interrogated months after you have been identified as not being the guy they are after.".

      --
      Fandroids hate facts.
    32. Re:How Not to be Seen by vux984 · · Score: 3, Informative

      Just one point. Violating "patent law" isn't a criminal offense

      Perhaps not; its worse, it makes me suspect you are a terrorist.

      And that's way better than a criminal offense... as a criminal you still have rights... as terrorist suspect... you don't.

      Aha... I saw you roll your eyes at this post... and then I felt a bit queasy... so you are cleary a witch too...

    33. Re:How Not to be Seen by toadlife · · Score: 3, Interesting

      I saw a forensic expert that works for local law enforcement give a presentation for a local community college "intro to computers" class awhile back. 90% of what he told them was bullshit. He told them, that once they saved a file to their hard drive there was no way they could really delete it and that he could always recover it. He went on and on, belaboring the point that there was no way anyone could ever hide anything from him. I was working on a computer in the class, getting it ready for an upcoming engineering class in the same room, and didn't want to start anything so I just shut up, but I mentioned to the instructor and the class members later that the guy was full of shit.

      It kind of disheartening that a moron like that qualifies as an expert witness for law enforcement.

      --
      I don't always use unix-like operating systems; but when I do, I prefer FreeBSD.
    34. Re:How Not to be Seen by hairyfeet · · Score: 3, Interesting

      That is why i'm glad my buddy actually has a brain. he'll be the first to tell you he won't be getting past any crypto that won't fall to a rainbow hash or brute force dictionary attack and that with a modern drive you wipe with zeroes that shit is gone friend. just to be safe i do a DoD 3 on all drives that pass through the shop but that is just because i have a box sitting in the corner for drive wiping and a DoD 3 really doesn't add much time over a random wipe and part of the reason why many businesses and schools are willing to donate machines to me to refurb for the poor is i tell them "Any drive that you leave in will be getting wiped to DoD specs" which gives them piece of mind.

      And he is damned good in court, I've watched the man work and he is cool as ice, I just don't think i could do that shit. i know the state pays him to see a shrink weekly so he can "data dump" as he calls it but seeing raped kids pics and vids all damned day? man I do NOT want that damned job! In the consumer retail biz i make it a point not to snoop people's drives so i don't have to see any nasty shit, the worst i've had to deal with was some gal that wanted me to back up her erotic pics of herself before I wiped the drive. I swear that gal had dildos big enough you could mount them on a gun rack! But I don't think I could do like he does and sit there all calm while sitting across from some guy I KNOW raped his kid because i saw the pics. not enough brain bleach in the world, i don't care how good the benefits are!

      --
      ACs don't waste your time replying, your posts are never seen by me.
    35. Re:How Not to be Seen by jackbird · · Score: 2

      What are you talking about? All the information needed is public record. Totally doable as an open source project.

    36. Re:How Not to be Seen by dances+with+elks · · Score: 2

      But if everyone could understand the Law you wouldn't need as many lawers.

      --
      Will wash cars for karma
    37. Re:How Not to be Seen by L4t3r4lu5 · · Score: 3, Interesting

      Pfff. Amateur hour.

      In the UK, you get shot six times in the face for wearing a jacket in summer.

      --
      Finally had enough. Come see us over at https://soylentnews.org/
    38. Re:How Not to be Seen by Anonymous Coward · · Score: 2, Insightful

      The upside to that is he gets the satisfaction of putting that fucker away. The man that raped my 8-year-old daughter got out after two years because of good behavior, and now I have to decide between my little girl having a dad or knocking on his door, shooting him in his face, and then sitting down on his porch and calling the cops. It's been a year since he got out, and I still think about it every day. Fuck, every hour.

    39. Re:How Not to be Seen by jahudabudy · · Score: 2

      ) I have learned that even internet criminals are like most criminals and just very very very very...dumb.

      Just a slight correction, most criminals that get caught are very dumb. There is no way to definitively say anything about those that are not caught, although the obvious conclusion is that they are smarter or luckier than those that are.

      --
      ...sometimes, in order to hurt someone very badly, you have to tell that person terrible lies. - PA
  2. ... well that's one reason open source is superior by Karmashock · · Score: 5, Insightful

    I'm not a huge open source guru. I have nothing against it and I use open source software all the time. But I'm not a zealot on the subject. Still... this is unacceptable. If I buy a bit of software from apple or microsoft, it has to be understood that I control the security. I bought the OS. I bought the machine. I own that license. if they're going behind my back to sell my security to a third party... then I consider that a breach of contract and I'm really not amused.

    If this is valid... and it hasn't been confirmed yet... then anyone that signed that agreement is untrustworthy.

    Nothing else to say on the matter.

    --
    I've decided to stop wasting my time responding to AC trolls/sockpuppets... so if you want a response from me... login.
  3. Probably not just Apple by Tangential · · Score: 5, Insightful

    Is there any reason to believe that governments wouldn't put pressure on all OS vendors, telecom providers, etc that wanted to sell into their countries to do something like that? I'd be very surprised if very many cellphones so in the USA don't have a way in for the Feds.

    At the same time, if you are concerned about the possibility of backdoors, it's awfully easy to bury one in deep in some standard hardware component that user space processes and most of the OS don't normally interract with. Since most of our cellphones and PCs (and GPSs and media boxes and cameras and ...) originate in China, what are the odds that they are not all compromised?

    --
    Suppose you were an idiot. And suppose you were a member of congress. But then I repeat myself. -- Mark Twain
    1. Re:Probably not just Apple by SuricouRaven · · Score: 5, Insightful

      I doubt many cellphones in the USA have backdoors for the government. Why would they need to, when the FBI, CIA and NSA all have access to direct fiber taps into the network backbone and presumably have been given the keys to go along with it? Backdoors in phones might be detected, but just getting the carriers to cooperate in permitting decryption and monitoring of network traffic is much safer - plus it lets them intercept the traffic of travelers who bring a phone purchased outside the US too.

    2. Re:Probably not just Apple by geoskd · · Score: 4, Insightful

      It would be very hard indeed to check the code that has been burned into a chip and is running some spy software, unless you could pull apart an Iphone 4s and analyze the whole circuitry and firmware for the back-doors code. I am not sure how difficult that would be, surely more than just a logic probe and some spare time.

      Putting in a "hardware" backdoor of that nature would be exceptionally difficult. You would have to know all kinds of things about the whole system, not just the chip your company is responsible for. That was why Stuxnet was such a big deal. Putting a backdoor into a piece of equipment is easy. Putting it to use in anything more complex than a toaster oven will be very difficult and require massive knowledge of the total system. Hell, even for all its sophistication, Stuxnet still failed to go unnoticed. There are just too many ways that it fails, and causes someone to go see why their system is behaving odd. All it takes is one person at the device manufacturer to start digging into a consistent equipment failure, and soon the light is revealed. You basically need a bunch of spies on the ground at the device designer to tell you what chip sets they're using, what interconnects, what OS, what extra software... It would be far easier to just put a sleeper on the ground to put your backdoor in the software.

      -=Geoskd

      --
      I wish I had a good sig, but all the good ones are copyrighted
    3. Re:Probably not just Apple by Sponge+Bath · · Score: 2

      The NSA never sleeps.

      They know who's naughty and nice. I leave them cookies and milk so I don't get coal in my stocking.

    4. Re:Probably not just Apple by garaged · · Score: 3, Insightful

      It is a convenience for when carrier wont give real time access or cant do it, also not everythin passes thru carrier, and people can be tracked better when offline but phone still powered up

      --
      I'm positive, don't belive me look at my karma
    5. Re:Probably not just Apple by laffer1 · · Score: 2

      Yes, but they may want backdoors in phones so that when we travel outside of the US, they can still intercept our calls.

    6. Re:Probably not just Apple by Mr.+Underbridge · · Score: 2

      Is there any reason to believe that governments wouldn't put pressure on all OS vendors, telecom providers, etc that wanted to sell into their countries to do something like that? I'd be very surprised if very many cellphones so in the USA don't have a way in for the Feds.

      The interesting bit is when they sell to one government while providing backdoors to another. I imagine the US gov is none too pleased if, while overseas, their employees are being surveilled by a US company (Apple) who provides the information to another government. RIM and Nokia are a bit of a different matter I suppose.

      If I were the US government, I would require any potential telecom vendor to sign an affidavit that the devices sold have no backdoor for non-US governments, even when used in foreign countries. I would require that affadavit to be signed by an official who is a US citizen residing in the US and that violating it would be subject to civil and criminal penalties.

    7. Re:Probably not just Apple by Niten · · Score: 3, Interesting

      For Android phones with the Market app installed, an explicit backdoor isn't even necessary. Application installation is performed by the user requesting something from the Market, and the Market subsequently "pushing" the application to the device by sending an install command through Google's XMPP-based notification service. The installation itself does not require any interaction from the user. This is why, for example, you can install an app on your phone from the Android Market web site.

      Well guess what, this means that Google, or anyone who can leverage control over them, doesn't need a backdoor already on your phone. The government could just use the Market's normal installation mechanisms to install SpyOnStuff.apk over the air on an as-needed basis.

    8. Re:Probably not just Apple by jimicus · · Score: 2

      There's something called "lawful intercept" built right into the GSM specs. No idea how far that extends to data transfer.

  4. Awesome headline. by Anonymous Coward · · Score: 5, Insightful

    How RIM, Nokia and Apple becomes just Apple is beyond me. Magic?

    1. Re:Awesome headline. by deniable · · Score: 4, Informative

      Nobody cares about RIM and Americans don't care about Nokia.

    2. Re:Awesome headline. by paimin · · Score: 3, Insightful

      Not only that, it's "mobile device makers, including RIM, Nokia, and Apple". Who else? I smell Android fanboy.

      --
      Facebook is the new AOL
    3. Re:Awesome headline. by whisper_jeff · · Score: 5, Insightful

      Apple generates page-views. RIM and Nokia do not.

    4. Re:Awesome headline. by Lord_Jeremy · · Score: 4, Insightful

      Isn't it also awesome how the Indian government turns into "governments."

    5. Re:Awesome headline. by AmiMoJo · · Score: 4, Insightful

      TFA was just badly worded. The leaked document makes it clear that it was just RIM, Nokia and Apple, or RINOA as they are abbreviated to. The backdoor would probably need to be at the OS level so it stands to reason that only companies which make mobile OSs are on the list, and Google is not there (nor is Microsoft).

      I think Google got burned by their experience in China which turned out to be an impossible situation for them. It seems unlikely they would then jump into bed with India and give them what they refused the Chinese.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  5. Only open source can be secure by Jazari · · Score: 3, Insightful

    The only way to be reasonably sure of security is by using open source encryption (TrueCrypt, PGP). If you're only using a "black box" system to protect your information, you should expect that governments (and crime syndicates who can bribe individual government employees) will have access to your information.

    What's surprising is that anyone with secrets worth protecting doesn't already know this, or hasn't already hired someone competent enough to tell them this.

    1. Re:Only open source can be secure by OneMadMuppet · · Score: 5, Insightful

      No. As soon as you decrypt anything to use/view it on a compromised system then that data is compromised, as is any other data using the same key. Anyone with secrets worth protecting shouldn't be storing them on a phone or accessing them from an insecure device.

    2. Re:Only open source can be secure by Gaygirlie · · Score: 2

      The only way to be reasonably sure of security is by using open source encryption (TrueCrypt, PGP). If you're only using a "black box" system to protect your information, you should expect that governments (and crime syndicates who can bribe individual government employees) will have access to your information.

      That would hardly be useful if your typing is recorded or someone has access to your device; they can already read everything there then. PGP et. al. are only useful during transit, not on either endpoint. If the endpoint is compromised then the content is already known.

      What's surprising is that anyone with secrets worth protecting doesn't already know this, or hasn't already hired someone competent enough to tell them this.

      Similarly to how you place way too much trust in such? As I said, PGP et. al. do not protect you at all if any of the endpoints is compromised, something that is clearly evident in the case of this article: all the endpoints are compromised already.

  6. News from a twit. by slasho81 · · Score: 5, Insightful

    This smells of bullshit. Now a tweet and a few images are considered legit news? Couldn't just one journalist or blogger pick up the phone and get the "RINOA" comment on the matter? Or is it just easier to post conspiracy-laden speculation ending with a giant question mark?

    1. Re:News from a twit. by cong06 · · Score: 3, Funny

      This isn't news. This is slashdot.

    2. Re:News from a twit. by Dunbal · · Score: 4, Funny

      Now a tweet and a few images are considered legit news?

      You're right. We're completely missing the celebrity angle here. What does Lady Gaga think about all this? /sarcasm

      --
      Seven puppies were harmed during the making of this post.
    3. Re:News from a twit. by Stultsinator · · Score: 2

      Well, if that information is classified then not only would the company spokesperson risk firing, he'd also be committing a federal crime for disclosing that information. The journalist himself would face similar pressure, and the number of bloggers and journalists who'd be willing to go to jail to protect a source can be counted on one hand.

  7. Re:... well that's one reason open source is super by Anonymous Coward · · Score: 3, Insightful

    Unless you've personally verified every single line of code in the OS, you're not really better off. You've just hoping that others have verified every single line of code, and unless you've verified that they're all trustworthy, you're just hoping that's true, too.

    ...and in case anyone's thinking this is an astroturf troll, I use Linux, not Windows or Mac. I've exclusively used Linux for 11 years now.

  8. Re:... well that's one reason open source is super by Yvanhoe · · Score: 5, Insightful

    You know, your argumented and reasonable stance on this problem is what led many "open source zealots" like me into their present situation. In a functional legal environment you could use proprietary software and assume that such a breach of confidence would have so serious consequences for the companies involved that no one would dare to take the risk to put a backdoor in their software or to even make it possible. This is not however the case, this affair is one of many (CarrierIQ, Echelon, illegal-later-legalized wiretapping, Bluecoat, Amesys, etc...) and the only cure seems to use open source everywhere a backdoor could exist. And that means, mostly, everywhere.

    Anyway, I like how you present it : "I'm not an open source zealot, I'm merely an opponent to secret backdoors"

    --
    The Wise adapts himself to the world. The Fool adapts the world to himself. Therefore, all progress depends on the Fool.
  9. Re:... well that's one reason open source is super by Kikuchi · · Score: 3, Insightful

    If I buy a bit of software from apple or microsoft, it has to be understood that I control the security. I bought the OS. I bought the machine. I own that license.

    HaHaHaHaHa, HoHoHoHoHo, HaHa, Hoooo....

    Eh, turn your keyboard around, gullible is written under it.

    --
    There's no scientific consensus that life is important.
  10. Re:... well that's one reason open source is super by Opportunist · · Score: 2

    Huh? How has a government or large corporation been wronged?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  11. Re:Manan Kakkar could be less of an idiot by geoskd · · Score: 4, Insightful

    "If Apple is providing governments with a backdoor to iOS, can we assume that they have also done so with Mac OS X?."

    Such an uninformed idiot to not have noticed, how serious the issue but rather wants to gain publicity by making this, big against Apple.

    Ridiculous

    This is not at all unfair to single out apple in this. It has been apparent for some time that M$ would sell their users security to the highest bidder. Nokia and Rim don't make desktop software, so that leaves apple providing a backdoor on one platform as perfectly viable evidence that they would do this on their other major platform, especially since the two share a significant codebase. The revelation here isn't that only apple would do this, its that apple would do this, and risk their brand at all. All the other players had a bad reputation to start. The big question is: What has google done?

    -=Geoskd

    --
    I wish I had a good sig, but all the good ones are copyrighted
  12. Re:Manan Kakkar could be less of an idiot by Anonymous Coward · · Score: 2, Insightful

    Nice fanboi response. It has really become a religion.

  13. Re:Manan Kakkar could be less of an idiot by fastest+fascist · · Score: 5, Insightful

    But how uninformed do you have to be to blame Kakkar for something he didn't write?

  14. Re:... well that's one reason open source is super by Opportunist · · Score: 5, Insightful

    Well, you're slightly better off. Unless you expect a global conspiracy where every person who ever read the code and would talk about it has been bought or silenced.

    The key is that it's heaps harder to slip a backdoor into OSS simply because far more people can (and do) examine it. The chance that someone finds it and reports it is simply by some margin higher.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  15. Seriously, guys by muecksteiner · · Score: 4, Insightful

    How can anyone be so naive to assume that any system that is commercially produced in large numbers these days does *not* have in-built backdoors for the alphabet soup agencies? Living under a rock much, are we?

    Same goes for Google, Facebook and all the rest. If you, even for one second, assume that the three letter agencies do not have permanent liaison staff at the HQs of these companies, and are not free to browse the data accumulated by these companies at will (including specially built data mining apps that cater for their needs, and their needs alone), you are seriously deluded.

    Sorry to put it this bluntly, but reality can be a bit harsh at times.

    The only real question is what to do about this status quo, and whether it is both possible, or realistic, to ever change it. All things considering, our society is arguably (still) the most free society on the planet. "They" are listening to everything, which is most definitely not the way it should be. But then, "they" have also not been hugely disruptive of discourse within society so far - mainly, I would wager, because "they" are mostly fairly normal citizens who work for the *** agencies. In particular, "they" are not a pampered, segregated elite of any sort, e.g. like the IT minions of the investment banking crooks^H^H^H^H^H^Hcrowd, or the secret service bastards of the former communist countries (who enjoyed considerable privileges beyond what normal citizens ever got). Rather, due to the never-too-stellar payment schemes of government services, the people in charge of all this are, by and large, fairly normal people. Most of them, at least. To quite some degree, I would wager that we can fairly safely count on that sort of people not being all too willing to cooperate in the creation of an actively evil 1984-ish state (as opposed to the passively listening one we have at the moment).

    This is not to say that these developments are in any way positive. Nor is it to say that we should just roll over, and stop fighting developments like that. No way. We need to sharpen our instincts for (as it were) "digital freedom" much, much more. But as a part of this, we also need to be realistic about the status quo. Which is currently... odd: theoretically fairly evil, but in practice, apparently still fairly manageable.

    Just my 0.2$

    A.

    1. Re:Seriously, guys by muecksteiner · · Score: 2

      How can anyone be so naive to assume that any system that is commercially produced in large numbers these days does *not* have in-built backdoors for the alphabet soup agencies? Living under a rock much, are we?

      Because of the huge lawsuit that will follow once it backfires.

      Which of course is only a valid objection if said backdoors are reliably traceable to the perpetrators. But if one of the *** agencies orders a company X to place such a backdoor in a product, you can bet that every last bit of discussion about this activity is an official secret, removed from public scrutiny for at least several decades. Good luck with "proving" anything in this regard, even in court.

      And without any proof, good luck with having this publicly backfire on the *** agencies in any measurable way. It's not like these chaps are so stupid to put encryption keys that actually start with "NSA_" in shipping OS releases anymore.

    2. Re:Seriously, guys by muecksteiner · · Score: 4, Interesting

      The Stasi is a very interesting example. That deserves a closer look, to dispel any notions that any of the current *** outfits is remotely comparable.

      First, the Stasi might not have been all that well paid in monetary terms. But the sum total of what a full Stasi employee in good standing had access to (by local standards very nice holiday opportunities for the family, better housing, sometimes even a car, and whatnot) arguably pretty much made them a separate class within the East German state. Not as well off as the actual party apparatchiks, but far ahead of any normal citizen. In a communist society, money couldn't buy you all that much anyway, so one has to look at the broader picture to assess how "well off" someone was in that sort of society.

      Second, the Stasi was never the same thing as the regular police of East Germany. They were always a separate entity that was tasked with things such as (counter-)espionage both at home and abroad (by all means, including dirty ones), and the silencing of political dissenters (again by all means deemed necessary) - but never with regular policing as such. This distinction, and in particular their refreshing openness about "any means necessary for the job" being acceptable, is, at least in my opinion, an important point to note. The Stasi never had any pretensions about being an organisation that deemed itself entirely above the law. They were the "sword and shield of the party" (that was actually their official motto) - and to them, no moral or legal standards applied, except their own.

      Which is a *huge* difference from even a very corrupt U.S. police department, or the bad parts of, say, an alphabet soup agency. Nowhere in the U.S. will you find members of the intelligence community who are openly contemptuous of the rule of law. Corrupt and evil things unfortunately do happen in law enforcement circles, but they are never an *accepted part of the organisation's official culture* like they were with the Stasi.

      And by extension, there is also a third point that follows from what I just said. The Stasi was an organisation which actively recruited persons who were, well, fairly "special" in that they felt right at home in that sort of environment. The only really valid criticism of the (otherwise fantastic) film "The Lives of Others" that I have head so far is that someone like the protagonist (a Stasi officer who develops second thoughts about his "work") would never have been recruited in the first place, because the Stasi was very good at avoiding anyone who might be liable to start asking questions later. During the entire existence of the DDR, there were practically no defections worth mentioning of anyone within the Stasi. Which is a pretty impressive track record, given the huge size of that organisation.

      This has implications for the existing U.S. intelligence services insofar as running an outfit like the Stasi apparently required active psychological monitoring to seed out dissenters, in order to build up the very special cadre of people you need for such a psychopathic organisation. For instance, the Stasi reputedly had an extremely anti-intellectual "work culture", which, amongst many other things, helped to get rid of anyone who was likely to think too much on his own.

      The existing U.S. intelligence services are all *not* built on such psychopathic foundations. Recruitment happens pretty much from the general population (pending security clearance, and all that, but still), so the personnel base of the *** agencies is nowhere near the kind of pathological personality mix you would need to run a Stasi. Or, even more importantly, to transform an existing *** agency into a Stasi. Even with the more or less scary developments of the past few years, this should give some consolation to those of you who worry where all this will lead to. Something like the Stasi does not happen easily, and not overnight. And it does *not* grow out of the institutions of a normal society. The *** agencies might not all be very nice and cuddly, but fortunately, there is a world of difference still.

  16. Treason or not? by Saphati · · Score: 3, Interesting

    If a person were to help another government gain access to confidential data, it would be called treason. If APPLE or Nokia does it, it is OK? Can someone please explain that?

  17. Who'd have thought? by Arancaytar · · Score: 4, Interesting

    The shiny backdoors the US government was so keen on to spy on its own citizens are also used by foreign governments to spy on the US government. Maybe security and privacy is worth something after all.

  18. Not a surprise, but the issue is more complicated by gweihir · · Score: 5, Insightful

    And face it, the worst is not the possible surveillance by the ones that originally placed this. These people did invest significantly to place and hide the backdoor. They will use information gained from it only sparingly, to protect the source. After all, if they are caught possessing information that they can only have gotten this way, the backdoor becomes worthless.

    IMO the real problem is if the backdoor can be used by others that do not have to protect their investment or respect laws (however flimsy). For an example of surveillance software made by people without much of a clue about security, look to the German "Bundestrojaner", recently analyzed by the CCC. Severe flaws include no authentication or encryption on data transfer, a hard-coded AES key that seems to be the same in all instances used for command transfer (still no authentication), and data-transfer via a foreign server (which is likely illegal). In addition, these cretins are of course not liable if somebody uses their backdoor and likely will not even notice.

    Same old story: For a few temporary small benefits, people are willing to accept enormous potential damage. That is my personal definition of evil.

    On the protection side: Use reputed open-source. There is at least some chance that somebody will notice a backdoor and that the person will not be easy to silence. And once somebody has found such a problem, anybody can verify it. Not so with closed-source. There it would be a lot more difficult to find anything, and then to get taken seriously as others cannot easily verify a finding. Some postings here already demonstrate that problem. In addition, use restrictive firewall settings and encryption. Difficult to do in a mobile setting, I know, so as a last measure, do not trust any device not under your own system-administration. In particular, do not trust any mobile phone or similar system. You may also want to add markers to any document you do put on potentially backdoored devices, so you can identify the source. This last step also helps against insiders leaking data.

    Of course, if your secrets are transient and not worth risking the backdoor for (even fore a 3rd party user of said backdoor), then you are probably reasonably secure. This should apply to most people for private use.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  19. It's all just "Lawful Interception" . . . by PolygamousRanchKid+ · · Score: 4, Informative

    Nothing new here: http://en.wikipedia.org/wiki/Lawful_interception

    You may not like that, but that's the way it is. Communications providers can be forced to provide back doors for "legal spying" by governments. All governments know this, and use other methods to protect "sensitive" communications. Any other stuff is, well, who cares?

    --
    Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
  20. Re:... well that's one reason open source is super by MadKeithV · · Score: 4, Informative

    Unless you've personally verified every single line of code in the OS, you're not really better off.

    Even if you do, you're not sure. Your compiler may be compromised. See: Reflections on trusting trust.

  21. Re:The original dump by Dupple · · Score: 3, Informative
    --
    Watch those corners
  22. Re:... well that's one reason open source is super by rawler · · Score: 4, Informative

    I bought the OS. I bought the machine.

    Technically, while you bought the hardware, you did not buy the OS.

    With the machine, you've got the right to do whatever you please with. (Modify, lease ...) Not so with the OS you believe you purchased.

    Typically with proprietary software, you only buy a license to use it as-is, and you are not even entitled to study how it works, or even look for backdoors.

    IMHO, this is the major problem with proprietary software, and an outrage that such agreements have any legal stance in a free-market society.

  23. Re:Manan Kakkar could be less of an idiot by amiga3D · · Score: 4, Interesting

    I think we can safely assume any closed operating system is backdoored. If I was a foriegn government I'd never use an operating system that I couldn't compile from source myself. I think this is one reason that MS was let off from the Fedreal Lawsuit so easily, so they could aid in surveillance. It makes sense, if I was in their shoes I'd do the same.

  24. "Liberated"? by cbraescu1 · · Score: 3, Insightful

    an internal memo of India's Military Intelligence that has been liberated by hackers

    Let's set the record straight: that memo was stolen.

    --
    Catalin Braescu
    Ofaly.com
  25. Re:... well that's one reason open source is super by amiga3D · · Score: 2

    This is borderline FUD. Yes it's possible to poison the code but with a proprietary closed system it's damn near certain you're backdoored. If for nothing else than for the company who sells the software to keep tabs on it. It's in their best interests not to sell you out because loss of credibility means loss of revenue but if the stakes are high enough they can be persuaded. For this reason it's not a problem for the average Joe usually but if you have anything you want kept secure and the stakes are high you'd be a fool to rely on your proprietary OS being secure. Risk management rules apply.

  26. Re:... well that's one reason open source is super by amiga3D · · Score: 2

    IF I was involved in anything where security was paramount. I mean here life or death basically. I'd certainly need to be sure of all my code and that would mean analyzing and compiling code. As for my own, individual security I feel more comfortable with a linux distro. It might be backdoored but I'm absolutely certain that Windows is compromised and I'm almost as sure about OS X.

  27. Re:... well that's one reason open source is super by gutnor · · Score: 5, Insightful

    No need for global conspiracy. You don't control what code is used to build your Android handset. The handset maker just tell you what base version they used and you need to trust them. Even on a vanilla Galaxy Nexus that would be trivial to slip a backdoor.

  28. Re:... well that's one reason open source is super by timholman · · Score: 4, Insightful

    Unless you've personally verified every single line of code in the OS, you're not really better off. You're just hoping that others have verified every single line of code, and unless you've verified that they're all trustworthy, you're just hoping that's true, too.

    Exactly. Even the open source community is built on a massive foundation of blind trust, because perhaps one user in a hundred thousand will actually look at the source. Otherwise, no matter if it's open or closed, the average user says, "That looks neat, I'm gonna install that".

    A personal anecdote: my open source theft recovery package for Macs has several thousand users. All of the source (with comments) is bundled with the installer, yet I often get questions from users about what the program does "under the hood", when they could easily learn the answer themselves by reading the source code.

    The overwhelming majority of users seem to like open source because it's free, not because it is theoretically more secure. I might have been collecting private information from the users of my program for the past three years, and I often wonder if a single one of them would have bothered to check the source in all that time.

    The best attack vector for any malware is incredibly simple: bundle it into something useful, and then give it away. You can guarantee that some people will install it (for the same reason they'll pick up and use a "lost" USB memory stick), because it is human nature to want to take advantage of something that is freely given.

  29. Re:... well that's one reason open source is super by Bert64 · · Score: 3, Informative

    Nothing has to be understood, you didn't buy the software you are renting it and the license agreement says so... It also says that you have no comeback against the company providing it. If you didn't like those terms, then you shouldn't have accepted them.

    Companies exist to make profit, its only logical that they would sell you (a small fry) out to a large government willing to pay a lot more money and open up a potentially huge market to them. This is what companies do, welcome to capitalism.

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  30. Re:Manan Kakkar could be less of an idiot by bazorg · · Score: 2

    Nokia and Rim don't make desktop software

    Well they don't make their own operating systems for PCs, but they both provide desktop software that syncs the contents of the PC with the mobile phone. I've used both and once given the admin rights to install and self-update, I really have no means of knowing what else they read from my drives and copy to the mobile phone and /or to a Nokia/RIM server.

    I think it highlights the importance of a common labelling for software in the same way that other consumer products have. In the past I thought it was important to have software labelled for "phones home", "displays adverts", "closed source", now this would require "has government mandated backdoors".

  31. Re:... well that's one reason open source is super by Bert64 · · Score: 3, Insightful

    Even if a backdoor is discovered, there's no guarantee that credibility will be lost... A smart backdoor would look like a bug and could easily be explained away as such... Exploitable security holes are commonplace, who's to say some of them weren't originally designed as backdoors?

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  32. Maybe I'm just naive by jht · · Score: 2

    I think as a practical matter, any spying done on devices outside of RIM would have to be at the cellular carrier level - and that wouldn't require the handset makers to cooperate at all. Blackberries all get routed through RIM's servers, but pretty much every other smartphone is just an Internet node.

    In the same vein, I'd think that if it's on wifi there wouldn't be anything special that a backdoor would get. Maybe I'm just not paranoid enough.

    --
    -- Josh Turiel
    "2. Do not eat iPod Shuffle."
  33. Not anymore (see NDAA) by boorack · · Score: 4, Insightful

    Go read NDAA, shamelessly passed by Senate (both parties) and shamelessly signed by Obama little more than a week ago. It allows for indefinite military detention of people your lovely govt. calls "terrorists" without charges and without recourse to a court of law as they're free to ignore court orders. With NDAA passed, US is now officialy a police state of kind it used to install in some many Latin countries in the past. You can kiss your freedoms goodbye as your constitution now has been teared down along with all its amendments.

    I doubt US millitary will use it to full extent at first as it would be a major PR disaster, but as time passes and popular anger at corporations/government grows you'll see more and more of people in jail just refusing to do that our corporate overlords want.

    1. Re:Not anymore (see NDAA) by amiga3D · · Score: 3, Insightful

      This is what I so dislike about President Obama. He's not even a good liberal. This is the kind of thing I would Expect from the Bush administration.

    2. Re:Not anymore (see NDAA) by joebagodonuts · · Score: 4, Insightful

      Obama is Dubya V2.0. The folks who thought he was liberal got pwned.

      --
      "Give a woman two glasses of wine and some pad thai, and they'll agree to just about anything." the Sports Guy
    3. Re:Not anymore (see NDAA) by Insightfill · · Score: 3, Interesting

      This is what I so dislike about President Obama. He's not even a good liberal. This is the kind of thing I would Expect from the Bush administration.

      While I don't like all of his decisions, everyone got "pwned" (to quote a sibling post) on this one.

      Since it was packaged in the defense budget, nobody wanted to be seen as 'bad on military' in an election year. So: It ran through House and Senate with a veto-proof majority. Obama could have either taken a stand on this and had it go through anyway (with the headlines in October reading "He hates our troops") or signed it and gotten painted with "He hates our citizens."

      Oddly, the House and Senate, which wrote and passed this POS, seem not to be hit with the same brush.

    4. Re:Not anymore (see NDAA) by cduffy · · Score: 2

      The NDAA, remember, was at its core a military spending bill. Vetoing military spending bills tends to be... unpopular. Signing a spending bill with an utterly unconstitutional provision attached, of course, is also unpopular... but generally speaking, ITSATRAP!

      By the way, you're wondering who was responsible for adding these provisions to a spending bill in the first place? That would be McKeon and McCain, both with (R)s next to their names. The buck may stop with POTUS, but the other side has dirty, dirty hands on this one too.

    5. Re:Not anymore (see NDAA) by chrisphotonic · · Score: 2

      ""President Obama signed the National Defense Authorization Act (NDAA) today, allowing indefinite detention to be codified into law." -ACLU's website

      Jon Steward talks about how horrible this is. It didn't pass...at first." http://www.thedailyshow.com/watch/wed-december-7-2011/arrested-development"

      http://slashdot.org/submission/1898482/infinite-us-citizen-detention--now-law

      Unfortunately, it didn't get enough votes to make the front page. I wish more people were focused on freedom, as well as technology here, but more and more people are waking up quickly now. It's hard not to be aware of it, when our government throws something in our face almost every week.

      I think its important to remember that there are 500-1000 congressmen and senators, while the US population is 307,006,550. The people really do have the power take control of their government-if they wake up.

    6. Re:Not anymore (see NDAA) by Roskolnikov · · Score: 2

      I fear its worse than " you'll see more and more of people in jail "

      with no paper trail the only people who will know are those 'detained' and those who notice them gone (complain loudly enough and you'll get to see them, come right this way....) NDAA and Patriot (security letters) are going to streamline justice in a way that most will regret, the only safe spot (if there is such a thing) might be a seat in the house or congress..... for some reason the laws passed don't seem to apply there.

      --
      Unix, an obscure operating system developed by bored researchers in an attempt to get a better game playing experience.
    7. Re:Not anymore (see NDAA) by Donkey_Hotey · · Score: 2

      According to his voting record and platform, he absolutely was a liberal. There was no reason to believe he'd be in favor of a bill like the NDAA at time we voted for him.

      That's right -- there was no way that anyone could see it coming at all.

      --
      (There is supposed to be a Sarcmark® here, but my $1.99 check hasn't cleared, yet...)
    8. Re:Not anymore (see NDAA) by artor3 · · Score: 5, Insightful

      Please, please, PLEASE stop spreading this lie. We can't run a country based on false information.

      The NDAA is a military spending bill. It gets passed every year. For several years it has allowed the military to detain members of Al Qaeda, and no one had a problem with this. In the latest version, this was expanded to cover members of other terrorists organizations, but it still states that it cannot be applied to United States citizens or immigrants.

      I know that doom and gloom is fun. It gets the blood pumping, and being outraged squirts some feel good chemicals into your brain. But stop spreading lies, and go read the damn thing. Claiming that the US is now a police state is the sort of lie I'd expect from Glen Beck; no different from claiming that the government subsidizing people meeting with their doctor to learn about Do Not Resuscitate orders is equivalent to the Holocaust.

    9. Re:Not anymore (see NDAA) by budgenator · · Score: 4, Informative

      Obama is Dubya V2.0. The folks who thought he was liberal got pwned.

      The folks who thought Dubya was conservative got pwned too. Obama wants to sell us out to big government, Dubya was sold us out to big bussiness, somebody else is just as eager to sell up out to big religion; the only thing that stays the same is we get sold out to something big.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
    10. Re:Not anymore (see NDAA) by artor3 · · Score: 4, Informative

      So let's see, in the past three years we've gotten:

      *Health care extended to millions of people who wouldn't otherwise have it
      *Honesty about how much the War on Terror is costing by putting it in the budget, rather than hiding it as Bush did
      *Laws stopping credit card companies from abusing their customers through short notice due date changes and excessive default rates
      *Limitations on outrageous fees charged to retailers by the card companies
      *A Network Neutrality law (albeit not on mobile networks, but there are good technical reasons why wireless networks can't be as unfettered as wired ones)
      *An end to the stop loss program wherein soldiers were forced to stay beyond what they signed up for
      *Fixes to the abortion that was No Child Left Behind (e.g. funding it, helping low scoring school instead of punishing them, etc.)
      *The Ledbetter Law, pushing back against a conservative SCOTUS ruling that made it virtually impossible for women and minorities to sue over pay discrimination
      *An end to torture and extraordinary rendition
      *An end to DADT, and no support for DOMA (he can't end it unilaterally, but he's refusing to defend it in court)
      *A new START treaty to reduce the number of nukes in the world

      Had it not been for Republican filibusters, we also would have gotten:
      *EFCA, helping to fight back against the corporate driven destruction of unions
      *Cap & Trade, a free market solution to global warming
      *Public option health care, allowing people to buy health insurance direct from the government rather than a for-profit company
      *The DREAM act, allowing illegal immigrants a path to citizenship through college or military service

      That's just what's coming to mind right now. I'm sure there's a bunch of small stuff I've forgotten. Now, how many of those things would be supported by the GOP? Maybe the New START treaty, but I doubt it, and certainly none of the others.

      Claiming that Obama is "Dubya 2.0" makes for a nice sound bite, but it is blatantly false. This whole myopic claim that Republicans and Democrats are the same is just an excuse for the lazy who don't want to be bothered trying to make a difference in the world, and prefer to just shrug off the whole system while hoping for a magic solution that will never come.

    11. Re:Not anymore (see NDAA) by BetterSense · · Score: 2

      Don't blame me; I voted for Ron Paul in 2008...still the only real progressive in Washington.

    12. Re:Not anymore (see NDAA) by Guy+Harris · · Score: 3, Informative

      Please, please, PLEASE stop spreading this lie. We can't run a country based on false information.

      The NDAA is a military spending bill. It gets passed every year. For several years it has allowed the military to detain members of Al Qaeda, and no one had a problem with this. In the latest version, this was expanded to cover members of other terrorists organizations, but it still states that it cannot be applied to United States citizens or immigrants.

      What Section 1021, subsection (e), of H.R. 1540 as enrolled says is

      Authorities- Nothing in this section shall be construed to affect existing law or authorities relating to the detention of United States citizens, lawful resident aliens of the United States, or any other persons who are captured or arrested in the United States.

      which doesn't explicitly say it cannot be applied to US citizens etc.. The question is what "existing law or authorities" say. Senator Carl Levin quoted the Supreme Court as saying "There is no bar to this nation's holding one of its own citizens as an enemy combatant.", which comes from the O'Connor/Rehnquist/Kennedy/Breyer opinion in Hamdi v. Rumsfeld. On the other hand, they also say "It is a clearly established principle of the law of war that detention may last no longer than active hostilities.", but if active hostilities continue until we've defeated "those nations, organizations, or persons he determines planned, authorized, committed, or aided the terrorist attacks that occurred on September 11, 2001, or harbored such organizations or persons", who knows when they'll cease.

    13. Re:Not anymore (see NDAA) by shutdown+-p+now · · Score: 3, Informative

      According to Wikipedia, the text of the bill allows to detain anyone "who was part of or substantially supported al-Qaeda, the Taliban, or associated forces that are engaged in hostilities against the United States or its coalition partners ... without trial, until the end of the hostilities". That's pretty damn broad, especially the part without trial - it essentially leaves the definition of "substantially supporting" at the discretion of the executive.

      Furthermore, there was to be a specific amendment to the wording this year that would clearly spell out that the above is not ever applicable to U.S. citizens. That amendment got thrown out. The wording as it stands is ambiguous on whether it permits indefinite detaining without trial of U.S. citizens or not; what matters is that Obama administration has already explicitly stated that they believe it to be permitted, so that's how they are going to operate. That is a police state, indeed, even if it will not apply in practice to most American citizens.

  34. Re:... well that's one reason open source is super by TeknoHog · · Score: 4, Insightful

    The key is that it's heaps harder to slip a backdoor into OSS simply because far more people can (and do) examine it. The chance that someone finds it and reports it is simply by some margin higher.

    My thoughts exactly. If you think about this as a developer who wants to implement a backdoor, open source is much more risky for you. You'll have to be clever in order to hide it in plain sight, and there is still a good chance someone will find it. In contrast, when the software is closed, you can write the simplest possible backdoor, and not worry about being seen.

    --
    Escher was the first MC and Giger invented the HR department.
  35. Re:Manan Kakkar could be less of an idiot by Goaway · · Score: 2

    Please, you are on Slashdot, we don't need facts when accusing Microsoft of evil!

  36. Re:... well that's one reason open source is super by sjwaste · · Score: 2

    A personal anecdote: my open source theft recovery package for Macs has several thousand users. All of the source (with comments) is bundled with the installer, yet I often get questions from users about what the program does "under the hood", when they could easily learn the answer themselves by reading the source code.

    I was with you until you said "easily" figure out what was going on under the hood by reading the source. Easy for you? Yes, you wrote it. Easy for me? In most cases, unless it's a really ridiculous source tree. Easy for the average user? You're giving the average person on the internet too much credit! :)

  37. Re:... well that's one reason open source is super by Bert64 · · Score: 5, Insightful

    While most people cannot, or will not read the source code... It only takes one of them to read it and find a backdoor, and then tell the world.

    If your really paranoid, you can read the code yourself or find someone you trust to do it for you. Personally i'd much rather trust a friend, or someone who is working explicitly *for me* than a company which has the primary goal of making profit at any expense.

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!
  38. Re:... well that's one reason open source is super by Karmashock · · Score: 3, Insightful

    To everyone that's telling "oh you didn't buy it, you licensed it!" or "But you clicked OK on the EULA!" or any variation on that theme. I'm pretty confident I could effortlessly sue the silly pants off any company that did this to me... especially if I could show damages in court. What jury is going to sit there and say "oh, he clicked OK on the EULA..." From a legal standpoint, EULAs are almost worthless against consumers and I even question how effective they are against corporations. There are different legal standards here. A big corporation for example has a legal obligation to actually read everything to the last line and appreciate what all the various legal terms mean. One person that has no special legal knowledge can't be reasonably expected to sign such things.

    The basis of legal contracts is that BOTH sides know, understand, and agree to the contract. If it can be demonstrated that either side could not be expected to reasonably know, understand, or agree to everything in a contract then the contract is invalid.

    For example, if a blind man signs a 500 pages legal contract it's almost certainly invalid. To make such a contract valid there would have be documentation that made it clear throughout that the man read or understood the contract. That might mean having a notary read it and occasionally inital segments of the contract to signify that given portions had been communicated. Or it might mean giving the man a copy of the contract in braille or something.

    The problem with EULAs is that no one reads them and worse no one can really be expected to read them. How many EULAs do you see in a day? I see about three on average and I think I've only read about two of them... and that was because I was bored.

    EULAs mostly exist not to restrain consumers because they can't reasonably be applied to them. They exist to restrain other corporations who also use the software. Because other corporations don't have this protection. It's one of the big differences legally between small and large organizations. Small groups generally are given a lot of legal slack. Big companies have to make a point of dotting every i and crossing every t. They have to read all these EULAs. And while I bet they don't even do it, they would have a much harder time making the same legal argument in court that they simply don't have the reasonable expectation of reading or understanding such documents.

    If Microsoft or Google did something that meant thousands of credit card numbers were stolen. Something where you could show damages. There is no EULA that would defend them. They'd get their silly pants sued off if it could be demonstrated that it was their fault.

    Now if it was an issue of malware or something then they can probably successfully argue that end users have a responsibility to secure their systems and MS or Google didn't steal the numbers in any case or intentionally make them available. However, if MS and google intentionally used backdoors to get such information or sold the keys to those back doors to a third party that then used them to get the information. THEN those companies would be screwed sideways.

    If the twentieth paragraph in the EULA says "oh by the way, we reserve the right to let third parties pilfer your data at will" it wouldn't stand in court.

    --
    I've decided to stop wasting my time responding to AC trolls/sockpuppets... so if you want a response from me... login.
  39. joshua by Joe_Dragon · · Score: 2

    No password needed (But you need to find the hidden port / number to get to the right login screen)

  40. Re:Manan Kakkar could be less of an idiot by ShadowRangerRIT · · Score: 4, Interesting

    And because they're guilty of one type of bad act, they're guilty of all types of bad acts? Like when I shoplifted last week, got caught, and am now on death row for murder, because being guilty of shoplifting makes me guilty of all other crimes.

    Let me know when you find the article that says MS sold access to their phones and operating systems to open up a lucrative market. Anti-trust is bad, but it's not remotely related to selling backdoors for market access.

    --
    $_ = "wftedskaebjgdpjgidbsmnjgcdwatb"; tr/a-z/oh, turtleneck Phrase Jar!/; print
  41. China? by Fuzzums · · Score: 2

    So, if "America" backdoors products they sell in India...

    --
    Privacy is terrorism.
  42. Re:... well that's one reason open source is super by HungryHobo · · Score: 2

    I dunno. Back in college I used to write code which did a task and also had some form of back door. I'd then challenge my friends to find it.

    rarely could they find it even in reasonably minor applications or scripts.of course better coders would be better at finding them but better coders would also be better at hiding them.

  43. Manning v. Apple? by Bob9113 · · Score: 3, Interesting

    Bradley Manning provided access to U.S. government secrets to everyone, because (or ostensibly because) the U.S. government was not duly informing the United States Citizens of the military's actions in their name.

    Apple(*) provided access to U.S. government secrets to a foreign national government, because they wanted that foreign national government to give them quid pro quo access to a lucrative market.

    Seems pretty clear Apple will be facing more severe charges than Bradley Manning, right? ... Or, at least, it's going to be in the same ballpark, right? ... Well, OK, at least, same kind of national debate, where questions of treason get raised, right? ... No? ... OK, then, well, umm, WTF?!?

    * Note: RIM and Nokia are foreign -- an interesting angle to consider, but not as similar to Manning as Apple.

  44. Haven't you guys ever seen a spy show before? by flibbidyfloo · · Score: 3, Funny

    Why do you think it's so easy for spies to steal your cell phone data? You see it on shows like Chuck and 24 all the time! Spies all have a magical device that plugs into any cell phone and downloads all the data in exactly as long as it takes for the phone's owner to almost get back from the bathroom, giving them just enough time to put it back where it belongs.

    How could they do that if Apple (i.e. every evil phone maker) wasn't providing them with a back door?

    That's why I always carry a dummy phone with decoy data on it while my bluetooth headset is secretly connected to my real phone, which is hidden in my shoe!

  45. They are all the same party by Colin+Smith · · Score: 4, Insightful

    Bush, Obama, Romney.

    It no longer matters who you vote for, they are all owned.
     

    --
    Deleted
    1. Re:They are all the same party by Loosifur · · Score: 4, Insightful

      My wife always asks me why I "throw away my vote" by voting for a third party. I ask her why she bothers to vote at all *unless* it's for a third party. Otherwise it's just picking between different flavors of vanilla.

      --
      This unbiased moderation brought to you by the Porcine Aviation Group!
  46. theres no federal law for classified informatiion by decora · · Score: 2

    being leaked for iphones. there is a specific law about classified information being leaked for certain types of cryptographic information, but then only if its leaked to certain people.

    the espionage act uses the phrase 'national defense information' not 'classified information'... because its a narrower concept.

    but mostly, because presidents and congressmen leak classified information ALL the time to backup themselves in political fights. thats why so many news stories have the phrase "unnamed sources" or "those familiar with the matter" or "officials say that". thats pretty much all examples of someone leaking classified information.

    so whenever a bill comes to congress saying 'leaking classified info is illegal', a bunch of them shit their pants because they themselves leaked it in order to make themselves look good / hurt their opponents.

  47. Re:Manan Kakkar could be less of an idiot by Alrescha · · Score: 3, Informative

    "I think we can safely assume any closed operating system is backdoored."

    http://opensource.apple.com/

    A.

    --
    ...bringing you cynical quips since 1998
  48. Re:... well that's one reason open source is super by betterunixthanunix · · Score: 2

    That is why we install the OS ourselves.

    --
    Palm trees and 8
  49. the taxpayers own memos created by by decora · · Score: 3, Insightful

    the government. how can it be considered stealing?

  50. ok. ok. i guess you MIGHT have a Conspiracy case by decora · · Score: 4, Informative

    the two situations are not exactly the same. Manning is accused of giving information about the national defense to other parties. it would be very hard to argue that apple did that. they just gave instructions to India about how to backdoor their phones.

    now the more accurate analogy would not be Bradley Manning, it would be the 'Cambridge Associates' who went under Grand Jury investigation in 2011 regarding their alleged assistance to Wikileaks (and are still under investigation). They are charged with Conspiracy to Commit Espionage. 18 USC 793 g.

    now, the other law i think applies here would be the Computer Fraud and Abuse Act. why? the Espionage Act only applies to 'national defense information'. but the Computer Fraud and Abuse Act has its own sort of 'mini-espionage-act' inside of it... that applies to not just national defense information, but also "foreign relations" information. This is the only reason Manning could be sued on so many counts of violating the CFAA, for example the Reyjkavic 13 memo about Icelandic Bank Fraud - thats under the CFAA.

    what you have here against Apple, could, theoretically, be Conspiracy to violate the Computer Fraud and Abuse Act, section (1) I believe is the Computer Espionage section.

    --

    another analogy would be George Hotz + FailOverflow, who published information about how to jailbreak the playstation 3. They were sued by Sony - but that was in civil court, not in criminal court. the DOJ never went after Hotz.

  51. Re:Just stop trusting closed source software by bytesex · · Score: 2

    Hardware would have to be awfully clever to /predict/ the software that I'm running on it, and which of the data that it uses, is useful for corrupting or siphoning off.

    --
    Religion is what happens when nature strikes and groupthink goes wrong.
  52. interesting methodology by way2trivial · · Score: 2

    so google settled at 500 million with the government over the books scanning.. and 500 million with the FTC over drug ads..

    so right there, I've proven definitively that google is at least half as evil as microsoft in your terms?

    --
    every day http://en.wikipedia.org/wiki/Special:Random
  53. Re:Manan Kakkar could be less of an idiot by xTantrum · · Score: 3, Interesting

    I think it highlights the importance of a common labelling for software in the same way that other consumer products have. In the past I thought it was important to have software labelled for "phones home", "displays adverts", "closed source", now this would require "has government mandated backdoors".

    Yes, but you're still trusting the goverment to do this and the point that should be seen here is we can no longer depend on elected officials to look out for the people. All this simply reaffirms is what Richard Stallman has been preaching for awhile now. It is up to the people to educate themselves and take the proper precautions. Of course the 99% won't and cannot and thus this is the reason we will soon see an event like Arab Spring spreading to the west. Sounds a bit crazy but the revolution will be here...soon.

    --
    $action = empty(PHP) ? backToC() : unset(PHP) ; "when the concrete cases are understood, the abstractions are readily
  54. Android is open source by YA_Python_dev · · Score: 2

    The big question is: What has google done?

    IMHO certainly it has not installed the backdoor, but if you wanna be sure I suggest to buy a compatible phone, wipe everything on it, recompile and install Android from source avoiding any proprietary program. We probably agree that's very unlikely that any backdoor would be present in any free/open source program, much less one with such high visibility.

    Yes, some Google apps are proprietary (Market, Maps, Videos...), you may want to use open source alternatives if you really don't trust Google.

    The latest version (4.0, Ice Cream Sandwich) of the Android source code is available at: http://source.android.com/

    Disclaimer: I speak only for myself and not anyone else. IANARE.

    --
    There's a hidden treasure in Python 3.x: __prepare__()
  55. BES still secure by Anonymous Coward · · Score: 3, Informative

    I think this apply to BlackBerry devices connected with BIS only. For BES devices (you have own mail server with blackberry software on it) it's still secure. Remember some goverments to ban BlackBerry devices - obviously it means they can not have backdoor for BES devices.

  56. Re:Manan Kakkar could be less of an idiot by jcarr · · Score: 2

    > Google was already exposed last year by Chinese hackers.

    Yes! We are all very thankful to those hackers for exposing the secret agreements between Google and the Government that provide access to various email accounts. It is an important fundamental right as citizens to be aware of the workings of our governments. When these governments are corrupted by corporate influence there is no turning back. That is why, I hope all of us will do the right thing now. For the sake of our internet, and our way of life, I suggest we get the rest of us after them. In peace and freedom from fear, and in true health, through the purity and essence of our natural fluids.

  57. Reality check by joh · · Score: 3, Insightful

    There was a time when efficient encryption was considered a weapon and could not be exported from the US. This was given up later.

    Looking back this was just logical. The point is that controlling what code is being exported is very hard and anyway coming up with good encryption is not that hard anyway. But once you have devices everywhere that can use end-to-end encryption of communications very easily and cheaply, everyone can use that and encrypted communication is basically out of control.

    The only halfway practical way to deal with this is: Just allow all of this but make sure that you get access to the devices at a point BEFORE any encryption takes place (and after decryption).

    I don't like the very idea, but on the other hand I really can't imagine any state or government to accept safe encryption in communications being the norm with no way to listen in. Democracy or not, but ubiquitous encrypted communication for everyone (including criminals, terrorists, whoever) is something that is impossible to accept for any government that sees controlling and policing as part of the job description.

  58. Re:Not a surprise, but the issue is more complicat by Nemyst · · Score: 2

    You don't even need to go so far. My high school had a special program where students would purchase and own a laptop and use it in class. It was required for the program and the laptop truly was YOURS. They had extensive warranty programs and tech support for the students, but you still owned the laptop and would do so even if you were to leave the school at any point.

    What I discovered mere months after getting the laptop was that the school's tech support had created a hidden Windows account (named "backdoor", how original) which had administrative rights and the same password for every laptop in the entire school. Five minutes of L0pht (not even illegal since I was applying it on my own property) gave me administrative access to hundreds of laptops.

    I never actually spoke about it a whole lot outside of a few friends, but I think this highlights how people who have no clue about security can cause possible trainwrecks. Imagine if a malicious person had access to such information? That's hundreds of laptops used daily by minors that could be spied on.

  59. Re:... well that's one reason open source is super by sjames · · Score: 2

    If it's a concern, root the thing and install a self-compiled OS.

  60. They are all the same party: Said Nader by cmholm · · Score: 4, Insightful

    Did I forget to wind my watch, or is it 2000 all over again? Picking between different flavors of vanilla, and a few trillion dollars, a few thousand lives, some wonderful Federal legislation, zero wage growth, zero oversight of the financial markets...

    The problem is that to create real political change requires a hell of a lot more personal commitment than checking an alternative box every few years, or posting about Nader/Paul/Bo, etc.

    --
    Luke, help me take this mask off ... Just for once, let me butterfly kiss you with my own eyes.
  61. Re:... well that's one reason open source is super by metrometro · · Score: 2

    This is a fallacy based on the idea that something is either completely secure or completely not secure. We don't live in that binary. We make security trade offs all the time, and measures which increase the time, cost and complexity of interception or attack are a good thing, even if they are not by themselves complete solutions.

  62. Re:... well that's one reason open source is super by Filip22012005 · · Score: 2

    With a self-compiled compiler.

    --
    When the policeman of the tie, rule you violate, hello punishment of the kitty?
  63. Re:... well that's one reason open source is super by Karmashock · · Score: 2

    Look at what you quoted. I am aware that I just own a license. However, any court worth it's salt will look poorly on a corporation that interprets that as meaning it can insert spy code into my systems and undermine my security intentionally.

    The issue here will be showing actual damages to a court.

    If you bring this to court and can show material damage of some kind that is quantified. Then you could gut them like a fish.

    I know many in the corporate world view EULAs as fostian bargains that everyone that uses their products are stupid enough to sign. These EULAs are actually enforcable between corporations however you'll have a very hard time holding small businesses or consumers to them because it would be very very very easy to argue that they can not REASONABLY be expected to read and understand such agreements. The term "reasonable" is very important in contract law.

    If it can be shown that either party in a contract could not have been reasonably expected to understand something or read it then it won't be enforcable. For that reason EULAs aren't particularly effective against consumers especially as it regards little hidden details. They can of course be expected to know that they're not support to pirate software. But they are likely not being made aware of the foreture of rights or other little things they might try to sneak into the contract.

    Being sneaky with a contract works between big corporations. They can trick each other because they are expected to read and understand everything. However, individuals and small operations are given special protection. Generally anything that goes over our heads or is even a little slippery tends to not do well in court.

    And if you add a jury trial to it... they're screwed.

    The legal system has a lot of problems but it's more sensible then you give it credit.

    --
    I've decided to stop wasting my time responding to AC trolls/sockpuppets... so if you want a response from me... login.
  64. Obama is OK in my book. by t0qer · · Score: 5, Interesting

    2 weeks after my wife and I bought our house in 2001, I was laid off. After 3 months of searching 9/11 happened, and the shit really hit the fan. Silicon Valley for a time looked like a ghost town. Moving trucks were moving east (getting the fuck out of dodge so to speak)

    A year later I wound up getting a crappy job at a bar. 10 years later I'm still here, working on my own software that runs certain aspects of the bar (very profitably I might add) When we bought our house in 2001 interest rates were sky high, and the wife and I thought our futures in tech were pretty secured. I think we were at 10% interest. We refinanced twice over the 10 years trying to keep payments down so we could stay in our house.

    In the last 2 years the ARM on our loan got so high we were paying over $1600@mo for the new interest charges alone. We were virtually on the brink of losing our house. Then the "Obama Affordable home" plan was passed. Bank of America didn't make it easy. My wife had to call them every single day for a year. (like calling your AT&T subcontractor when your T1 goes down) At one point they denied us because "We couldn't verify your identity" (one of the loan modders wrote my social security number down wrong)

    Despite what you might think of Obama.. He's just doing the best he can. He's no Bill Clinton, but having to clean up after GWB can't be easy. He stopped the banks from bending over hardworking people. Osama was killed during his term. Troops are withdrawing from Iraq.

    1. Re:Obama is OK in my book. by Suddenly_Dead · · Score: 2, Insightful

      Despite what you might think of Obama.. He's just doing the best he can.

      Bullfuckingshit. He signed NDAA and is likely going to sign SOPA and PIPA. That's not the "best he can". He got you a house, but the condition is that you and your countrymen can now be jailed indefinitely at his whim. Or, from what he's said, executed even on American soil. Hooray?

    2. Re:Obama is OK in my book. by t0qer · · Score: 3, Informative

      So you got to keep your house that you obviously can't afford

      We could afford it at the time. We bought an "as is" house with numerous problems because it was the cheapest one on the market in an area we wanted to be in. We figured we'd just keep working, and fixing the problems as we saved our money along.

      We didn't buy a house with 0 down either. My wife and I both cashed in stock options (that we had earned and vested at .coms) and had a $50k downpayment on a $500k house. So how dare you discredit the hard work we did getting to that point.

      Why did you refinance repeatedly?

      After 2001-9/11 it wasn't just the banks screwing people over. The counties lost a ton of funding (again, went to Iraq) Everyone's property taxes got raised sky high (we're at about $7k@year)

      Let's face it man, with every city in the bay area suffering a deficit, from San Jose to Vallejo (who went bankrupt) everyone, everywhere lost funding. Inflation really hit hard. Gas prices skyrocketed.

      Guys like countrywide home loans really set up a lot of hardworking folks to fail. We were with countrywide in the beginning.

      How can you look yourself in the mirror now that you've taken such obvious charity from the rest of us?

        I'm not the only one in this boat. I am the 99%.

    3. Re:Obama is OK in my book. by CodeBuster · · Score: 2, Interesting

      So how dare you discredit the hard work we did getting to that point.

      Your missing the point here. You took a risk with an investment that, had it paid off, would have accrued entirely to yourselves. The fact that it didn't pay off isn't my problem. Why should us taxpayers, who prudently decided NOT to make foolish bets in the housing market, be forced to make you whole? Investors, like you, must NOT be bailed out from the downside of risks that they willingly took . Otherwise, it's not really an investment but charity and the rest of us cannot afford to be that generous. The GP is right. You made a bet on the housing market and you lost. You should take your losses and move on. Why should the rest of us bail your ass out? We didn't share in the potential rewards of a successful real estate investment so why should we share in the loss or is this just another case of privatized profits and socialized loses?

      After 2001-9/11 it wasn't just the banks screwing people over.

      You weren't the only ones who had a rough go of it last decade. Many of us decided not to buy overpriced homes or moved back to live with family elsewhere in the country to save money and live within our now reduced means. You'll get no sympathy from me for your underwater mortgage.

      Guys like countrywide home loans really set up a lot of hardworking folks to fail. We were with countrywide in the beginning.

      Nobody put a gun to your head and forced you to sign the papers. What about the rest of us who cut back and endured hardships and deprivations to save money and live within our means? You want to live in society and be treated like an adult while at the same time blaming your foolish financial decisions on bankers in nice suits who saw you coming? The fool and his money are soon parted or would be if the rest of us weren't being forced to bail your ass out.

      I'm not the only one in this boat. I am the 99%.

      No, your part of the 5-10% of foolish first time "home buyers" who should never have received a loan in the first place . You didn't honestly believe that the banks would loan a peon like you $400,000+ unless the government was turning around and immediately buying the mortgage from them did you? Not a chance.

    4. Re:Obama is OK in my book. by rainer_d · · Score: 2

      Other countries's banks go for a 20% down-payment - because they calculate that in the event that you go bankrupt, they can sell the property for 80% of its original value very fast and still break even.
      A 90% financing in the midst of a bubble is no good idea - unless you are basically unifireable from your job (like a civil servant in Germany, with automatic yearly rises and all)

      --
      Windows 2000 - from the guys who brought us edlin
    5. Re:Obama is OK in my book. by scot4875 · · Score: 2

      Why should us taxpayers, who prudently decided NOT to make foolish bets in the housing market, be forced to make you whole? Investors, like you, must NOT be bailed out from the downside of risks that they willingly took.

      Well then you'll be happy with the outcome, because we ABSOLUTELY DID NOT bail out homeowners. Checked foreclosure data lately? Seen all the neighborhoods that are scheduled for fucking demolition because the owners all had to move out (read: their investment failed, they lost everything they put into it) and there's nobody that can afford to move back in?

      We get it, you're angry. Maybe you should direct that at the people who not only caused the problem but also profited greatly from the problem they caused.

      Ignorant, finger pointing, victim blaming assholes like you really make me sick.

      --Jeremy

      --
      Jesus was a liberal
  65. Exactly. Revolution by Colin+Smith · · Score: 3, Insightful

    The problem is that to create real political change requires a hell of a lot more personal commitment than checking an alternative box every few years, or posting about Nader/Paul/Bo, etc.

    Spot on. The political systems have degenerated to the point that revolution is required to make real changes.
     

    --
    Deleted
    1. Re:Exactly. Revolution by catmistake · · Score: 2

      The political systems have degenerated to the point that revolution is required to make real changes.

      I'm not ready to toss our Constitution just yet. I think our Founders were BRILLIANT, and the U.S. Constitution one of the greatest works of Mankind. The individuals in government may be corrupt, but I don't see that document becoming corrupted (although interpretations certainly are, e.g.s habeas corpus destroyed by PATRIOT ACT, 2nd Amendment destroyed by weak conservative court by the 2003 DC gun law case, and there are other forces chipping away at the enumerted individual rights of citizens).

      Revolution would not help us now, President Jefferson's wishes notwithstanding. What we need is competant investigation, exposure, full disclosure, and justice handed out to those nannystate powermonger moneyhoarders that are defiling the pure vision of the Founders. The Founders never intended things such as allowing multinational corporations to influence Presidential/Congressional elections and the votes of individual lawmakers for the financial benefit of the multinational corporations at the financial expense of the hardworking taxpaying American citizen. Shift the government back into the vision of the Founders, and we won't need a revolution. The Constitution itself equips us with the power to do this.

  66. Re:... well that's one reason open source is super by Keybounce · · Score: 5, Interesting

    A smart backdoor would look like a bug and could easily be explained away as such...

    Tee hee. A while ago, one of the hacker sites had a competition to see who could hide a "backdoor" -- the idea was to take an image in a script compatible form (all the numbers were in text, rather than in binaries), black out a certain region (think redaction), and still have some way to have the redacted area be recoverable when the right inputs were given.

    The catch? The code would be given a peer review, so you had to come up with something that would pass most attempts at oversight.

    A lot of people tried to hide stuff in "error detection" routines.

    The winning code had no bugs of any kind. It did perfect redaction of the specified area. No flaws, no errors, nothing to be spotted in code review.

    Except for one oddball usage of fetching and writing individual characters -- getc() and putc(). The author explained that as an attempt to make sure that no matter what was in the input data, no matter how messed up the graphics were in an attempt to break the code, it would not have any overruns, no undefined behavior, etc.

    Result? The "black" would be written out as "0", "00", or "000", depending on the light level of the source. For all three color channels.

    Absolutely unnoticeable when viewed on a viewer. There was no hidden alpha channel, no slight alternation between black-0 and black-1, etc.

    Yet you could still recover readable text, almost perfect pictures, etc.

    Security hole back door? Very doable.

  67. Re:... well that's one reason open source is super by sjames · · Score: 2

    If you're THAT paranoid, yes. Build a compiler just good enough to faithfully compile a compiler just good enough to compile a stage 1 Gnu compiler, etc...

    If it's just the particular carrier you're paranoid of (like the person I replied to), using a compiler they haven't touched is sufficient.

    If the paranoia runs even deeper, then it's impossible to prove that I don't work for THEM, so you should do the opposite of my advice and run the carrier's official release. They'll never expect that.....

    Unless of course, that's what I want you to think they think you thing they think...

    Fnord.

  68. XSecure by Doc+Ruby · · Score: 4, Interesting

    Hm, I wonder if a smart keyboard ran its own OS, like Android, running an X client over a network to the main PC's X server, if that would secure the aggregated workstation better against keyloggers and other similar devices. Not trusting the local buses, which seem harder to secure. An Optimus keyboard might have the HW to run the OS and X client. A monitor that's just an OS and X server over a gigabit ethernet to the main PC might complete the picture. And maybe the whole thing would then run even faster.

    Or maybe that all just kicks the can a little down the road, to where a keylogger or other spyware just infests the "app host" PC at the core.

    --

    --
    make install -not war

  69. Re:... well that's one reason open source is super by grcumb · · Score: 3, Interesting

    The Linux kernel is 14 million lines of code alone, when I type in a password I'm guessing between the kernel, xorg and the browser at least double that. Even if only a tiny bit of the code paths are touched, what's to say there's not a trigger set up somewhere to peek at some buffers?

    Let's say you're walking in a city of 14 million people. You stop at an ATM and enter your PIN. What's to say that one of those 14 million isn't watching, hoping to steal your PIN and then your money?

    When you're wandering around in a city full of strangers, there are real security concerns, some of them supported statistically by the sheer impossibility of being able to trust every member of a given community. But even given those limitations, you can still maintain a decent level of confidence simply by keeping tabs on who's watching you.

    But you've got other fish to fry when the bank itself says, 'You don't need to know about what security measures we've put into place. Just trust us.'

    FOSS is not a cure-all, and making something open source doesn't magically make it secure or even trustworthy. The only benefit is that it makes it possible to verify. Which is more than can be said for proprietary software.

    --
    Crumb's Corollary: Never bring a knife to a bun fight.
  70. Re:... well that's one reason open source is super by 0ld_d0g · · Score: 2

    there's hundred of people from various places writing and eyeballing source and commits. those people have no incentive to get backdoors in, and if there's a blacksheep, it's going to be very tricky to insert rogue code

    Then please explain the reason why security bugs are found in OSS software. A backdoor is simply a security bug.

  71. You could either assume they did or didn't by Guy+Harris · · Score: 2

    "If Apple is providing governments with a backdoor to iOS, can we assume that they have also done so with Mac OS X?"

    You could, or you could, for example, assume that, because OS X isn't a mobile phone OS, they weren't asked for those sorts of backdoors and didn't provide them. Or you could assume that they've provided both sets of backdoors, independently. I.e., the "if ... then" is somewhat bogus there.

    One might be better advised to ask about backdoors in any OS, especially not-completely-open-source OSes, regardless of which particular vendor they came from. As noted elsewhere, the title of the /. article could be changed to "Leaked Memo Says That RIM Provides Backdoor To Governments" or "Leaked Memo Says That Nokia Provides Backdoor To Governments" without loss of generality. It could also be changed to "...Provides Backdoor To Indian Government", as the memo says nothing about other governments; the Indian government apparently required that to allow "Indian market presence", which is not to say that other governments do not impose similar requirements.

    What's special about RIM, Nokia, and Apple, I have no idea.

  72. Re:Thanks, Apple by Guy+Harris · · Score: 2

    More proof that Apple "caring" about users is complete bullshit. They only care about their bottom line. This is why they have so many user-unfriendly policies.

    Boycott Apple.

    ...in favor about companies that care more about their users than their bottom line. Any suggestions for companies of that sort?

  73. Re:Treason Charges? by Guy+Harris · · Score: 2

    I highly doubt this is true. Not one of these companies would want to be a part of a government looking in on another government's information.

    You're presuming that they were told that the purpose of this was to be a part of a government looking in on another government's information, or that, even if they were told or could guess it, they weren't in a position of plausible deniability.

    I'm pretty sure that they would be good contenders for treason charges if this was true,

    Good luck charging Canadian and Finnish companies with treason against the US (unless you're referring to their US subsidiaries).

    That being said, if it's going across wires and isn't encrypted, you shouldn't really expect it to be considered safe information.

    Exactly. The question is whether the backdoors mentioned in the memo allow tapping of information before it gets encrypted, e.g. a way to intercept ("lawfully" or otherwise) $PROTOCOL-over-SSL traffic.