US Security Services May 'Have Moles Within Microsoft,' Says Researcher
Barence writes "U.S. government officials could be working under cover at Microsoft to help the country's cyber-espionage programme, according to one leading security expert. According to Mikko Hypponen, chief research officer at security firm F-Secure, the claim is a logical conclusion to a series of recent discoveries and disclosures linking the U.S. government to 2010's Stuxnet attack on Iran and ties between Stuxnet and the recent Flame attack. 'It's plausible that if there is an operation under way and being run by a U.S. intelligence agency it would make perfect sense for them to plant moles inside Microsoft to assist in pulling it off, just as they would in any other undercover operation,' he said. 'It's not certain, but it would be common sense to expect they would do that.'"
... or they just paid/threatened Microsoft. Much simpler and easier.
The US Government has licenses for the Windows source code. Nothing we've seen those virii do have required anything more than that.
What would surprise me, is if the US thinks they're the only one.
dont forget security companies and firms... and yes it does make lots of sense.
I doubt Microsoft would balk at any requests at access. These are, after all, matters of national security, and are therefore paramount over all other concerns. No decent American (ahem) company could refuse.
They THINK there MIGHT be moles inside Microsoft. ("Definitive proof!" says Alex on his radio show.) That's nice. I think their might be moles inside everybody's backyards..... I haven't actually seen any, but let's publish it anyway and scare everyone.
1. Publish some random guy
2. Spin it to make it sound factual "evidence"
3. $profit$
My AC stalker: " I personally agree with your posts most of the time, but that won't keep me from modding you troll"
"Foreign government officials could be working under cover at Microsoft".
Since many/much of the actual development is overseas anyway.
Then obviously they don't really know for sure (so says Betteridge's Law of Headlines).
Now I'm not saying there are moles at Microsoft and Apple, but neither of them have reported back to me either way.
So, what are they hiding?
Let's not beat around the bush! I say Microsoft has known USG agents working on the systems intentionally putting holes in the OS that can then be leveraged for zero-day attacks against other governments. Balmer is in cahoots I say! CAHOOTS!
You don't need a big gun to get the MS source code. It isn't some big fucking secret like all the ./ers seem to think. It isn't GPL, but plenty of institutions have copies. Basically any government that uses Windows does, huge surprise there. Also a lot of research universities. One such university I know that has it is ASU. Then there are copies in the hands of partners for better debugging/integration of their products.
Just because the source isn't on Sourceforge, doesn't mean it is some massive secret. A bit of Google would get you http://www.microsoft.com/en-us/sharedsource/default.aspx which is MS's page on their source sharing.
The question should be, whether these moles will lead to skin cancer, and if Microsoft should limit's exposure to the sun to counter balance them.
Author of TFA dreams up some impossible to falsify idea - offers no supporting evidence of any kind except to say it is plausable.
I love myself a good MS conspiracy and I'm sure there are plenty which actually do exist but lets not reward intellectual laziness.
Just two questions:
1. What do editors of PC Pro get paid to do?
2. What is it doing on slashdot?
Now if you'll excuse me my magic unicorn 'Flame' is hungry and wants a bowl of lucky charms before flying back to the land of lua to meet the angry birds.
...put a worm in apple?
"Government: "Hello there, Microsoft. This here is a really big gun. We want your source code."
Microsoft: "Ummm, okay." "
That's a terrifying abuse of government power! I hope they don't extort source from the Linux community.
"This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
It's "plural", not "plutal". Pedantry Fail. Just a heads up so you don't look like such a clown in the future.
The man who dies rich dies disgraced. -- Andrew Carnegie
Read more about what actually happened. Microsoft was using some keys with md5 hashing that weren't properly set to prohibit their use for code signing and those keys were signed by the Microsoft root. Using a collision attack they created a copy of a signed key and used that to sign their code.
Brief Explanation:
http://blogs.technet.com/b/srd/archive/2012/06/03/microsoft-certification-authority-signing-certificates-added-to-the-untrusted-certificate-store.aspx
Detailed Explanation:
http://blogs.technet.com/b/srd/archive/2012/06/06/more-information-about-the-digital-certificates-used-to-sign-the-flame-malware.aspx
Hotfix MS just published to speed up the revocation process:
http://blogs.technet.com/b/pki/archive/2012/06/12/announcing-the-automated-updater-of-untrustworthy-certificates-and-keys.aspx
http://support.microsoft.com/kb/2677070
Why would hte government bother with moles when it can just read the Microsoft engineers minds from it's spy satellites. It's common sense that they'd be doing this.
by Mike Buddha -- Someday the mountain might get him, but the law never will.
Imagine a government with access to a complex OS source code. Then imagine that they get data on all manner of security holes as they are discovered. Imagine also that this government has access to OS security update certifications. Finally, imagine that this same government has the ability to hack into server DNS tables to route targeted users to their alternative 'security updates'.
The penetration of any software company by undercover government operatives would hardly be surprising, but entirely unnecessary. Microsoft would hardly be alone as a target of such espionage -- every software company would be vulnerable, including OSS. There is also the issue with 'backdoors' hard-wired into computer hardware, including especially telecom systems. IIRC, this became an issue recently with news of backdoors alleged to exist in VLSI circuits manufactured in China. Older news alleged that Israel also puts backdoors into the telecom hardware they sell & ship, including to the USA government.
If virtually every government does such spying, including upon their own citizens, and any number of software & hardware companies do the same with their customers, any cautious user of such technology should be aware of the potential security breaches they expose themselves to every time they connect to the internet, or open their front door for that matter. Redundancy & breadth of security beats security through obscurity any day.
The phrases of the day are, "Trust no one", "Security in depth", and "If it can't be accessed remotely, it's more secure & less vulnerable". At that point, physical security & Tempest-hardening secure your valuable data. The rhetorical question is, "How valuable is your data if you cannot readily access it?" I found it humorous that the USA government recently wanted reporters to write their news stories on government-supplied computers, if only to avoid unwanted data leaks & stop potential whistleblowers in their tracks.
Trust the USA government, or any government, or any corporation with an agenda? Why take that risk unmitigated? And who in Hades would put vulnerable sensitive SCADA systems in close proximity to the Internet except an idiot?
If you are sufficiently concerned about it, then you can inspect the sourcecode of linux and/or remove the parts you don't want...
You can't do that with windows.
If you're a national government, then you certainly have the resources to inspect linux, and you'd be foolish not to inspect the software you use for critical infrastructure.
Even if you can't or won't inspect the linux source, you at least gain some assurance from the fact that many independent people with differing goals are able to see the source. Again, this is something windows simply doesn't provide.
http://spamdecoy.net - free throwaway anonymous email - avoid spam!
Destabilizers! Destabilizers! Destabilizers! Destabilizers!
I deny that I have not avoided attaining the opposite of that which I do not want.