Slashdot Mirror


Apple, Google, Microsoft: We Have No Government Email Scanning Program Like Yahoo's (vocativ.com)

Apple, Google and Microsoft -- three of the largest technology companies in the U.S. -- have each said they don't scan all incoming messages for the U.S. government, which is exactly what Yahoo does. According to Reuters, Yahoo secretly built a custom software program last year to search all of its customers' incoming emails for specific information provided by U.S. intelligence officials. The company complied with a classified U.S. government directive, scanning hundreds of millions of Yahoo Mail accounts at the behest of the National Security Agency or FBI. Vocativ reports: In a statement, a Microsoft spokesperson told Vocativ that "We have never engaged in the secret scanning of email traffic like what has been reported today about Yahoo." While Apple declined to give a statement on the record, a representative for the company did, in response to Vocativ's question, refer to CEO Tim Cook's official letter on consumer privacy, which reads in part: "I want to be absolutely clear that we have never worked with any government agency from any country to create a backdoor in any of our products or services. We have also never allowed access to our servers. And we never will." The fact that both the companies declined further statement means it's not yet known if the NSA or FBI approached them to request they build a program like Yahoo's. Meanwhile, a spokesperson from Alphabet's Google issued a statement to CNBC: "We've never received such a request, but if we did, our response would be simple: 'no way.'" [The spokesperson later clarified that the company has not received a "directive" or "order" to that effect, either, according to The Intercept.] But the question is whether or not you believe them. With Yahoo's case, only a handful of employees knew about the program. The same could be true with Apple, Google, Microsoft or any other large tech company. Edward Snowden tweeted not too long after Reuters' report surfaced: "Heads up: Any major email service not clearly, categorically denying this tomorrow -- without careful phrasing -- is as guilty as Yahoo."

139 comments

  1. Of course they do! by dohzer · · Score: 3, Funny

    Everyone knows they read all your emails.
    That's why I've gone off shore.
    - jamesd@qq.com

    1. Re:Of course they do! by Anonymous Coward · · Score: 0

      @qq.com ...

      Not much of an improvement

    2. Re:Of course they do! by Anonymous Coward · · Score: 0

      I'm hoping it's sarcasm. And I'm double-hoping it will be moded +5 Funny instead of +5 Insightful.

    3. Re:Of course they do! by Joce640k · · Score: 1

      "We have never engaged in the secret scanning of email traffic like what has been reported today about Yahoo. I want to be absolutely clear that we have never worked with any government agency from any country to create a backdoor in any of our products or services. We have also never allowed access to our servers. And we never will."

      ie. Your system is so insecure that the government didn't need your help to get in.

      --
      No sig today...
    4. Re:Of course they do! by tsqr · · Score: 1

      "We have never engaged in the secret scanning of email traffic like what has been reported today about Yahoo. I want to be absolutely clear that we have never worked with any government agency from any country to create a backdoor in any of our products or services. We have also never allowed access to our servers. And we never will."

      ie. Your system is so insecure that the government didn't need your help to get in.

      With regard to the Apple statement, please refer to Snowden's comment about careful phrasing.

    5. Re:Of course they do! by Anonymous Coward · · Score: 0

      Congratulations, now the NSA can just read your email at will since it's foreign communication.

    6. Re:Of course they do! by Anonymous Coward · · Score: 0

      With regard to the Apple statement, please refer to Snowden's comment about careful phrasing.

      This. This. So very much this.

      We have never engaged in the secret scanning of email traffic like what has been reported today about Yahoo.

      This is correct. They engaged in the secret scanning of email traffic in a different manner than Yahoo. See? Not like Yahoo.

      I want to be absolutely clear that we have never worked with any government agency from any country to create a backdoor in any of our products or services.

      Again correct. They created backdoors on their own without the government working with them.

      We have also never allowed access to our servers. And we never will."

      Correct again. They don't *allow* access to their servers. Why, those government hackers are just too good!

    7. Re:Of course they do! by Anonymous Coward · · Score: 0

      But ours is totally unlike Yahoo's. Completely and utterly unlike theirs. It's so unlike theirs that we don't even...

      What? Of course, there are some similarities. For instance, we actually do scan all emails, for your protection. Yes, we do OCR them if necessary. We also send them to the same place. But other than that, our program is totally unlike Yahoo's.

    8. Re:Of course they do! by fbobraga · · Score: 1

      It's written in the Bible, on Isaias 69:171

  2. If they are under a gag order by Anonymous Coward · · Score: 1

    This is exactly what they would have to say, legally speaking

    1. Re:If they are under a gag order by Anonymous Coward · · Score: 0

      Gag orders can't force you to lie.

    2. Re:If they are under a gag order by ShanghaiBill · · Score: 2, Insightful

      This is exactly what they would have to say, legally speaking

      No. Gag orders prevent you from telling the truth. They cannot, legally, require you to lie.

    3. Re:If they are under a gag order by Anonymous Coward · · Score: 0

      This is exactly what they would have to say, legally speaking

      No. Gag orders prevent you from telling the truth. They cannot, legally, require you to lie.

      They don't need to. Any company that does not respond in kind will be assumed to be guilty and consequently lose users. Therefore, whether a company is sharing data with the government or not they will claim they are not. This is the only financially-sound response.

    4. Re:If they are under a gag order by Anonymous Coward · · Score: 0

      Who cares at this point what is legal anymore? If the Govt wants to punish you and force you to lie. How will you stop them? Throw your billion dollar company into the trash for principals?

    5. Re:If they are under a gag order by Anonymous Coward · · Score: 0

      Gag orders prevent you from telling the truth. They cannot, legally, require you to lie.

      Right, the problem is, it's very easy to deny something without lying about it. Consider Microsoft's statement: "We have never engaged in the secret scanning of email traffic like what has been reported today about Yahoo." While it sounds like a denial on its face, it's not.

      Microsoft didn't deny secretly scanning emails for the government, they denied doing it the way Yahoo was doing it. Their statement leaves wide open the possibility they may be doing so in a manner that is not like what was reported today about Yahoo. For example, maybe Microsoft is only scanning emails originating from APNIC and AFRINIC IP ranges. Maybe Microsoft is providing NSA a direct feed of all incoming email, instead of writing their own software to do it like Yahoo did. In either case, the statement they issued would still be factually correct. It's not a lie. It doesn't mean they aren't secretly scanning emails.

      Always look for the weasel words.

    6. Re: If they are under a gag order by Anonymous Coward · · Score: 0

      Just like APL.

      It's not a back door. It's not access to their servers if a copy is made and given via driv, etc.

      They're also known to just bow and not tell anyone they've given up their cloud servers like a whore gives up STDs

    7. Re:If they are under a gag order by Opportunist · · Score: 1, Insightful

      Gag orders cannot, but the market can.

      Let's assume for a moment that they have the same deals running. Not saying anything would result in losing customers because everyone would assume they are under a gag order and thus can't tell you that they're handing over your data. So they lie to you. What's to be lost? Either it doesn't come up. Then they retained you as a customer. Or it gets out that they lied. Then they'll lose you as a customer. Which is exactly what would happen if they didn't lie to you.

      The obviously financially sound strategy is to lie to your customer.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    8. Re:If they are under a gag order by Anonymous Coward · · Score: 0

      Which schools are we talking about? Or did you mean principles?

    9. Re: If they are under a gag order by Anonymous Coward · · Score: 0

      Governments can and do do things that are not legal.

    10. Re:If they are under a gag order by Anonymous Coward · · Score: 0

      He was talking about the money needed to start another business after the government shut down the first one.

  3. stick a fork in 'em by Anonymous Coward · · Score: 0

    Yahoo is done.

    1. Re:stick a fork in 'em by Anonymous Coward · · Score: 0

      Yahoo was done a long time ago. They gave the eulogy when the chick showed up to manage their stake in Alibaba.

    2. Re:stick a fork in 'em by butchersong · · Score: 1

      Eh, I'm not sure the people that will be aware of this story overlap a great deal with yahoo's user base. Besides they have plenty of assets other than "yahoo" -patents and a huge amount of real-estate etc.

  4. Bullshit by Anonymous Coward · · Score: 2, Insightful

    - Anonymous "Coward"

    1. Re:Bullshit by elvesrus · · Score: 1

      Quotes should be around the other word.

    2. Re:Bullshit by fbobraga · · Score: 1

      exacltly

  5. They're right by Anonymous Coward · · Score: 0

    The NSA does it for them.

  6. I call bullshit on MS by UnknownSoldier · · Score: 3, Insightful

    > Microsoft spokesperson told Vocativ that "We have never engaged in the secret scanning of email traffic like what has been reported today about Yahoo."

    Bullshit.

    Proof: Microsoft (R) Online Services Global Criminal Compliance Handbook

    1. Re:I call bullshit on MS by fahrbot-bot · · Score: 2

      > Microsoft spokesperson told Vocativ that "We have never engaged in the secret scanning of email traffic like what has been reported today about Yahoo."

      Bullshit.

      Proof: Microsoft (R) Online Services Global Criminal Compliance Handbook

      Could be true. Key element in MS quote: "like what has been reported ... about Yahoo." Meaning, they scan your emails for *other* reasons, like for marketing and demographic information -- I'm looking at you Google too.

      --
      It must have been something you assimilated. . . .
    2. Re:I call bullshit on MS by ShanghaiBill · · Score: 4, Informative

      Bullshit.

      Proof: Microsoft (R) Online Services Global Criminal Compliance Handbook

      That handbook is about specific information requested through proper legal channels, such as a subpoena, warrant or an NSL. All companies are required to comply with those. It is not about scanning all email for keywords like TFA is describing. Perhaps Microsoft is doing what Yahoo did, but your link is not proof of that.

    3. Re:I call bullshit on MS by TheGratefulNet · · Score: 1

      bad guys are convince us they're the good guys - can and will abuse this.

      because it exists, they'll get (have gotton) around any inconvenient barriers and now, everything is of 'national security, just let us in' level.

      I advocate for ending all law-enforcement and government access to email and online encrypted comms. governments exist for the betterment of their people (that's the idea, even though its never quite followed, in practice). no LE official really can be trusted with power; we're seeing this almost daily, certainly weekly. give authority figures lots of power and they'll abuse it.

      so, I advocate for fully removing all access, even so-called emergencies. you blew you. we tried trusting you, you fucked us and now we have to take the ability away for all things, both good and bad. thanks for fucking this up, guys. it could have worked, but noooooo, you had to go mess things up for everyone.

      that's what I would like to see. removal of all spy powers, all code in core routers, edge routers, switches, gateways, etc - will have the sections removed for the next build cycle (lol..., I can dream, its my dream, dammit.)

      its only a dream. reality is far uglier. routers/etc have 'legal intercept' built and baked right in, and I think that's just wrong. because the ones who have access to that can't be trusted and those above them (on up) - I really wish that feature set was gone, tomorrow. we'd be a step closer to real freedom online and because goverments really hate it when their people are truly free, they will do all they can to keep things the way they are now.

      we can't change what's below tcp and ip. but we can layer new secure virtual networks on top of that. that's what the tech community should be working towards. the layers below - all spooked. fully untrustable. go define new secure layers on top of that mess and then we'll have internet-v2 that we can really trust.

      --

      --
      "It is now safe to switch off your computer."
    4. Re:I call bullshit on MS by msauve · · Score: 1

      But if they document it, it's not secret, is it?

      --
      "National Security is the chief cause of national insecurity." - Celine's First Law
    5. Re:I call bullshit on MS by Anonymous Coward · · Score: 0

      It would be ok to scan it for aggregate marketing data, as long as it is first stripped of any information that can identify specific users. However, any experienced IT admin can tell you that's pretty hard to do completely.

    6. Re:I call bullshit on MS by Anonymous Coward · · Score: 0

      your uid is far too low for such poor reading comprehension...

      Your link is a handbook that describes procedures and results for legal account info requests. All major email/service providers do this and there's nothing wrong with following court orders (in fact quite the opposite). This is a far cry from actively scanning all email traffic which is what the Yahoo story is about...

    7. Re: I call bullshit on MS by Anonymous Coward · · Score: 0

      "bad guys are convince us they're the good guys..."

      Someone set up us the bomb?

    8. Re:I call bullshit on MS by Anonymous Coward · · Score: 0

      Check out the Zeronet project at http://zeronet.io ... decentralized and pretty easy to use

    9. Re:I call bullshit on MS by guruevi · · Score: 1

      NSL is not a legal channel and is exactly what Yahoo quotes as following.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    10. Re: I call bullshit on MS by Anonymous Coward · · Score: 0

      What you say!

    11. Re:I call bullshit on MS by bloodhawk · · Score: 1

      maybe I missed it but I could not see anywhere in that document that shows they secretly scan email traffic? It seems to outline the legal process and means to access an account after law enforcement serve a warrant.

    12. Re:I call bullshit on MS by Anonymous Coward · · Score: 0

      If you read that document, its targeted to specific individuals and accounts...based on a production order/warrant.....thats completely legit...what yahoo did was essentially scan millions of email accounts automatically for keywords and send it to nsa and fbi..

    13. Re:I call bullshit on MS by swillden · · Score: 1

      NSL is not a legal channel and is exactly what Yahoo quotes as following.

      NSL is a legal channel, but it's restricted to providing only metadata and only about specific targets. Yahoo cited it, but they've gone well beyond what the statute authorizes.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    14. Re:I call bullshit on MS by guruevi · · Score: 1

      The constitution doesn't agree. The government has to have (a) cause, (b) due process and (c) the right for an open defense in a public court

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    15. Re:I call bullshit on MS by swillden · · Score: 1

      The constitution doesn't agree. The government has to have (a) cause, (b) due process and (c) the right for an open defense in a public court

      That's an argument for challenging the law in court. Until that's done, it's legal. That's how the system works. Granted that in this case it's particularly hard to challenge because it's difficult to prove harm when the harm is hidden behind a veil of national security secrecy, but that doesn't change the fact that it is legal until someone manages to challenge it.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    16. Re:I call bullshit on MS by Anonymous Coward · · Score: 0

      If it is stated in their publications, then it is not "secret" scanning like Yahoo did.

  7. Duh! Well of course not by p51d007 · · Score: 3

    They just copy EVERY email and send it to them!

  8. gag orders by TheGratefulNet · · Score: 4, Interesting

    we can't trust any company, not large and not even small.

    to 'play ball' in today's USA, you have to follow orders. and one of those orders is 'do not admit to following orders'.

    so, all this is just talk. 100% unverifyable talk. maybe its true, but likely - based on what we now know (that we once just assumed but didn't know for sure) - the spooks own the internet and they are not showing any signs of giving it back.

    look at the wordplay and parse it out. WE don't scan emails. ok, maybe the 'we' is not active, but does ANYONE scan them on your network? how about transit networks?

    so many holes to exploit. and again, to stay in business, you can't say no to Pappa. not in the US, at least.

    I don't believe apple, either, when they appeal to 'privacy' and that they don't disclose backdoors to gov orgs. totally unprovable, just 'take tims word for it'. yeah sure. right.

    the only thing you can assume is that every network is bugged and every cpu has backdoors (think: intel ME).

    --

    --
    "It is now safe to switch off your computer."
    1. Re:gag orders by ShanghaiBill · · Score: 3, Insightful

      we can't trust any company, not large and not even small.

      You seem to be implying that small companies are generally more trustworthy. That is nonsense. Big companies have a lot more to lose by betraying the public's trust, and they have more legal oversight. When small companies cheat and betray, it doesn't make the headlines.

    2. Re:gag orders by Anonymous Coward · · Score: 1

      You seem to be implying that small companies are generally more trustworthy.

      Not the original poster, but yes and no. Part of the "trustworthy" comes from the notion that the government is designed around acting with other large organizations. So, it targets the larger organizations to capture most of the traffic, attack most the problem. etc And the media, like /., respond by also seeking out the big players because their involvement would have the widest detectable impact. Hence, smaller companies are seen as possibly useful because they might "slip through the cracks" and be ignored.

      The other part is that smaller businesses often are personally owned and the owner might have a personal stake in not complying with an order they view as unlawful.

      That is nonsense. Big companies have a lot more to lose by betraying the public's trust,...

      Which is the reverse. Big companies have a lot more financial buffer to suffer any "betray[al of] the public's trust". Look at Apple and "The Fappening"? Look at Microsoft and well, look at Microsoft. Seriously, big companies betray the public's trust all the time. Small companies that manage that often close shop because they can't weather even relatively minor fluctuations that persist for months.

      ... and they have more legal oversight.

      Which goes to the above above "smaller businesses ... not complying with an order they view as unlawful" precisely because they don't have the "legal oversight" of their own team of lawyers who basically say "just do whatever the government says, or they'll harass us over any little technical violation of the law" and in turn the "legal oversight" of a government who basically thinks whatever it does is de facto legal, damn the Constitution, and so pushes its rules on an organization no matter how unlawful it is.

      I mean, seriously, look at this very case!

      When small companies cheat and betray, it doesn't make the headlines.

      Again, yes and no. Small companies cheating and betraying makes the local news. It's not something that makes national headlines because the business isn't national. And I'd definitely agree that the number (if not the percentages) of small businesses that cheat, betray, and get away with it without repercussions is likely greater than big businesses. But then that's the nature of the count of small businesses. And as I already stated, the repercussions on big businesses are often minor. Even stuff big enough leading to a recession basically lands no one in jail or paying a fine or anything.

    3. Re:gag orders by reboot246 · · Score: 1

      Are you through With your Nonsensical rambling, Pappa?

    4. Re:gag orders by Anonymous Coward · · Score: 0

      I think you just provided a good summary of the Unabomber's manifesto. Not that I have complete trust in either corporate entities or my fellow man, but with zero trust in each other, we'd all be living in our own little cabins in the woods.

    5. Re:gag orders by tlhIngan · · Score: 2

      Big companies have a lot more financial buffer to suffer any "betray[al of] the public's trust". Look at Apple and "The Fappening"?

      Nothing happened with that. Because it was not Apple's fault.. There was no hack of Apple or iTunes.

      The Fappening was traced to basically a hacked account - either reused credentials, or someone used a really weak password.

      Neither of which Apple could really protect against without making it completely unusable for everyone else.

      In fact, it appears most iTunes/iCloud/Apple hacks are reused passwords from all the other breaches that happen - there's no systemic breach of Apple.

    6. Re:gag orders by Anonymous Coward · · Score: 0

      Nothing happened with that. Because it was not Apple's fault..

      And that's an incredibly naive statement. At the time of the hack(s) there was not enough information to know that it was not Apple's fault. After the fact, most people were (and probably still are) unaware of the fact that Apple was not to blame. So simply arguing that Apple wasn't actually responsible doesn't mean anything if people don't trust that Apple wasn't responsible. More to the point, how many celebrities abandoned Apple at any point during the fiasco?

      Same thing holds with Apple, Google, and Microsoft over the various reports of NSA, FBI, etc warrantless (or otherwise unconstitutionally broad) spying? At this point, most people presume (1) the US government is going to spy on you and (2) large companies (and small) are going to be hacked. So, there's little point to really give much of a shit until it actually, personally effects you. The whole "trust" thing long ago is rather meaningless in this context.

  9. There's your "careful phrasing" by dark_requiem · · Score: 4, Insightful

    I want to be absolutely clear that we have never worked with any government agency from any country to create a backdoor in any of our products or services. We have also never allowed access to our servers. And we never will.

    Yeah, that's reassuring. Except, what's being described here falls under neither of those categories. It's not a backdoor, and it doesn't require providing access to Apple's servers. So, Apple is blithely sidestepping the issue with careful phrasing, denying only activities about which they were not asked, while artfully ignoring those about which they were.

    1. Re:There's your "careful phrasing" by Anonymous Coward · · Score: 1

      The truth is bad for business. It doesn't matter how many geeks call them out on their lies, the majority believe, so business rolls along, and we all get scanned.

      There is no changing this. We will *never* have the privacy we once had. It is gone for good. Expect even more government intrusion...it will seep in just as steadily as all forms of tech seep in to our lives. THERE IS NO ESCAPE, there is only adaptation.

    2. Re:There's your "careful phrasing" by AHuxley · · Score: 1

      So from the PRISM, decryption, plain text access days we are back to very careful words again.
      Does that depend on what scanning legally is? On what "email traffic" on some part of the network is this decade?
      Some national security related requests are more legal than others?
      If the gov knows to ask in a different way to the right staff it would never be self discovered?
      Is that big new gov server really a per device or per service backdoor or trapdoor?

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:There's your "careful phrasing" by ShanghaiBill · · Score: 1

      So, Apple is blithely sidestepping the issue with careful phrasing, denying only activities about which they were not asked, while artfully ignoring those about which they were.

      Indeed. If Apple is not scanning all the emails, they really need to issue a clear categorical denial immediately. Otherwise, Apple's statement should be taken as an admission of guilt. If you use Apple's email client, you should assume the NSA and FBI are reading everything you write.

    4. Re:There's your "careful phrasing" by YrWrstNtmr · · Score: 1

      If you use Apple's email client, you should assume the NSA and FBI are reading everything you write.

      "If you use....email, you should assume..."

    5. Re:There's your "careful phrasing" by Anonymous Coward · · Score: 0

      It's pretty likely they haven't scanned icloud email accounts either, although I agree that isn't covered by their "no government access to our servers" denial. Does Apple even own the icloud servers, or could they technically call them someone's else's servers and achieve positive deniability? Nevertheless, Apple's business model at least partially depends on them at least trying to keep customer's data secure, so they shouldn't even think of cooperating with information collection, the harm caused by it leaking out they they did it far exceeds any benefit to the company from cooperating with the spooks.

    6. Re:There's your "careful phrasing" by Anonymous Coward · · Score: 0

      "... have also never allowed access to our servers. ..."

      Yeah, but did you allow access to a plaintext tap to the network leading *to* or *from* your servers?

      Careful phrasing indeed.

    7. Re:There's your "careful phrasing" by guruevi · · Score: 1

      You mean Apple's e-mail service. The e-mail client doing something nefarious like forwarding e-mails to the NSA would be quite noticeable. The solution, as always, is to decentralize and do your own e-mail service. It's not that hard.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    8. Re:There's your "careful phrasing" by Anonymous Coward · · Score: 0

      Typical B.S. This isn't about backdoors. It's about scanning and harvesting emails for keywords and other shit and then storing it for later use.
      Google, Microsoft, and Apple all do it behind your backs.

      Privacy from your government is no longer enough. We now need privacy from the private companies that fuck with our emails.

    9. Re:There's your "careful phrasing" by Anonymous Coward · · Score: 0

      Suppose some company does issue such a clear, categorical denial immediately. Would there be any consequences if it were untrue?

  10. Re:U.S.A. by TheGratefulNet · · Score: 4, Interesting

    its worse than that. all major pipes to and from ANYWHERE are going thru US owned routers, core and otherwise.

    no one is 'safe' anymore. once the spooks decided to own the network, with their money their power and their 'thou shalt not disclose under pain of prison' bullshit, there's no way to know; but its highly probable that every single transcontinental link is 'managed' and tappable.

    this is why its a world problem. its not at all limited to the US.

    --

    --
    "It is now safe to switch off your computer."
  11. Of Course by 31415926535897 · · Score: 1

    I believe them, mostly because they realize the value of the data, and they don't want competition on the spying.

  12. Marissa Mayer again by Anonymous Coward · · Score: 0

    "According to two of the former employees, Yahoo Chief Executive Marissa Mayer's decision to obey the directive roiled some senior executives and led to the June 2015 departure of Chief Information Security Officer Alex Stamos, who now holds the top security job at Facebook Inc."

    "Yahoo is a law abiding company, and complies with the laws of the United States," the company said in a brief statement in response to Reuters questions about the demand. Yahoo declined any further comment.

    A Marissa Mayer decision again.

    1. Re:Marissa Mayer again by butchersong · · Score: 2

      A Marissa Mayer decision again.
      Yep. She's cute and intelligent but Yahoo hid the "wiretap" from Alex Stamos (the freaking Chief Information Security Officer) and he and his team only discovered it later which seems to have been the reason he left. Apparently Yahoo (Marissa) did this secretly to avoid any in house conflict. I'd say she isn't CEO material but it isn't like the majority of CEOs in the country set the bar all that high.

  13. scanning program by Anonymous Coward · · Score: 0

    Let's be clear about this.

    They most certainly DO have a scanning program, it's just not "like Yahoo's".

    1. Re:scanning program by Anonymous Coward · · Score: 0

      Right. "No email scanning program like Yahoo's" But we wish we did...

  14. Something wrong with your right eye? by Stonent1 · · Score: 2

    It looks like it's twitching almost like a wink, when you say that.

  15. Re:U.S.A. by ShanghaiBill · · Score: 3, Informative

    its worse than that. all major pipes to and from ANYWHERE are going thru US owned routers, core and otherwise.

    That is why any data in transit should be encrypted. "They" can still do traffic analysis, and see who is talking to whom, but that can be ameliorated by using proxies and sending dummy traffic.

  16. PRISM by SumDog · · Score: 4, Informative

    Did everyone forget about PRISM? I feel like everyone forgot about PRISM.

    The PRISM leak states that every one of this big companies, MS, Google, Facebook, have dedicated software hooks for searching any record, anytime.

    Or is Edward Snowden is limited hangout, and everything he said coming straight from the CIA?

    1. Re:PRISM by nnull · · Score: 1

      People have a short memory.

    2. Re:PRISM by freeze128 · · Score: 4, Informative

      I remember PRISM. I also remember that when its existence was leaked, Google specifically went out of their way to ENCRYPT traffic between their data centers to prevent the PRISM from capturing any useful data. Before the leak, Google was unaware that any data capture was going on.

      PRISM wasn't a Google initiative, it was an NSA initiative.

    3. Re:PRISM by Anonymous Coward · · Score: 0

      Or is Edward Snowden is limited hangout, and everything he said coming straight from the CIA?

      Probably limited hangout, no? Do you think snowdog is still a CIA asset? I've really been thinking he could be more and more lately.

    4. Re:PRISM by xession · · Score: 1

      Sure it was an NSA initiative. That doesn't mean Google wasn't just posturing when they "went out of their way to encrypt traffic". Encrypting doesn't really do anything if you are already complying with the NSA with other tools. Lets consider an alternative - Google began encrypting their intranet traffic because they became concerned hackers could reveal this compliance easily prior to the encryption.

    5. Re:PRISM by Anonymous Coward · · Score: 0

      https://prism-break.org/

  17. Apple avoids answering the question by Anonymous Coward · · Score: 0

    Apple never said that they haven't scanned E-Mails for any government. They carefully worded it to avoid answering, just as Google and Microsoft. As them to answer yes or no to the question.

    They can't.

  18. Could just be a lie. by Gravis+Zero · · Score: 1

    Publicly traded companies like these are required by law to do what is best for it's shareholders. Since they are not bound by law to tell the truth, they could simply be lying because not lying could hurt them financially.

    --
    Anons need not reply. Questions end with a question mark.
    1. Re:Could just be a lie. by donaldm · · Score: 1

      Publicly traded companies like these are required by law to do what is best for it's shareholders. Since they are not bound by law to tell the truth, they could simply be lying because not lying could hurt them financially.

      You are quite right, lying cannot hurt you financially but being caught lying can.

      The problem you have is many people adopt the attitude of "I have nothing to hide". Sad really, I guess George Orwell was only out by about 40 years.

      --
      There ain't no such thing as proprietary standards only proprietary formats. Standards are by definition open.
    2. Re:Could just be a lie. by Anonymous Coward · · Score: 0

      This is completely false:"Publicly traded companies like these are required by law to do what is best for it's shareholders"

      https://www.washingtonpost.com...

  19. Can't M$ get into your system and add/remove away? by Anonymous Coward · · Score: 0

    Doesn't M$ pwn r00t on all of their Windows installations world-wide?

    Can't they add and remove software at any time?

    Forget e-mail for a moment, we're talking your local computer(s).

    Systems which supposedly host private data.

  20. In 5 years by Anonymous Coward · · Score: 0

    In 5 years time it won't be "Yahoo", it will be "Yeah...who?"

    Yahoo has become poisonous, I would not any service they provide.

  21. HA HA HA by Anonymous Coward · · Score: 0

    Apple, Google, Microsoft: We Have No Government Email Scanning Program Like Yahoo's

    LOL LOL LOL and behold!

  22. ... first cleared by by Anonymous Coward · · Score: 0

    Hm... I had some letters there.

    Believe none of it, and all of it.

    Bin Laden is dancing in his watery grave.

  23. Stick a fork in Yahoo, their done by Anonymous Coward · · Score: 0

    The only asset Yahoo had left was it many email subscribers. Now they've proven they can't even be trusted to provide free email... so what business model is left for them? They should have sold the company a lot quicker, before the value of the company plumetted. Nothing to do but pick pieces of carrion of the dead body of Yahoo now.

  24. Sure, right by AndyKron · · Score: 4, Funny

    Nope, never been approached. Yahoo was the ONLY one. Yup.

  25. We don't do it like Yahoo!... by matbury · · Score: 2

    ...we're much better than them. We've developed our own proprietary systems to streamline and automate the surveillance process and increase our productivity in keeping the American public, and their children, safe... blah... blah... blah...

    Isn't it also Google (Alphabet?) that are vigorously promoting and selling their surveillance systems as a service to repressive regimes around the world?

    1. Re:We don't do it like Yahoo!... by Anonymous Coward · · Score: 0

      While not a fan of Google, I believe you're referring to Cisco

    2. Re:We don't do it like Yahoo!... by fbobraga · · Score: 1

      People adore to use the "but Gloogle too" talk here... While not a big fan, Google is one of the less "evil" (but evil enough to be not trustworthy....) corporations out there

  26. And why is this news? by Anonymous Coward · · Score: 0

    My life won't be any different tomorrow knowing that some computer program scanned my e-mails. Just like it hasn't made a difference since the 90's when the same types of people were complaining.

  27. Do the world a favor, delete ALL Yahoo accounts by Anonymous Coward · · Score: 0

    The intercept gives a nice link to delete your Yahoo account https://theintercept.com/2016/10/04/delete-your-yahoo-account/ .. perhaps some 'gray-hat' hacker could write a bot using those 500M+ compromised Yahoo accounts to do everyone a favor and delete them all.

    1. Re:Do the world a favor, delete ALL Yahoo accounts by fbobraga · · Score: 1

      I still use flickr, you insensitive clod! (but in a disposable account mode: if Yahoo is blown-up, nothing mine of value is lost...)

  28. Good for Yahoo! by hcs_$reboot · · Score: 2

    After this news, Yahoo will have much less accounts that can be hacked.
    More seriously, how come (especially in Japan) so may people keep using Yahoo is a big mistery.

    --
    Slashdot, fix the reply notifications... You won't get away with it...
    1. Re: Good for Yahoo! by Anonymous Coward · · Score: 0

      Because in Japan they are run(?) by softbank. It runs like a different company with different software and infrastructure.

      Yahoo travel (public transit riding planning) is great as is yahoo auction (eBay flopped in Japan)..etc. They also run a big ISP (Yahoo Bb) also really softbank though.

  29. Scanners by Anonymous Coward · · Score: 0

    My Fam has emails with Hotmail/OutLook, Gmail, & Yahoo.
    Every email is either scanned or scanned. (For a $Price).
    I've also has someone go into my email(s). I don't know if they work for the Government or Contracted with the Government.
    Some of my emails get bounced back. I don't know if my ISP also has a scanning service for the Government.
    Some times the email I receive seems like it's from a different person due to the sentence & vocab structure.

  30. Re:U.S.A. by Anonymous Coward · · Score: 0

    its worse than that. all major pipes to and from ANYWHERE are going thru US owned routers, core and otherwise.

    That is why any data in transit should be encrypted. "They" can still do traffic analysis, and see who is talking to whom, but that can be ameliorated by using proxies and sending dummy traffic.

    Routers could add encryption layers muddling things further. Their cost would go up a lot, and the endpoint PCs would be very busy dealing with all the extra overhead and layers..... At any rate, short of that, traffic analysis is as you say pretty easy..

  31. HA hA HA hahaha HAHA hahahahaaaa... by Anonymous Coward · · Score: 0

    ....HAHA HA HAHAHAAAHHHH.....oh my...oh...oh wow...HAHAHAAAHAAAAAA....

  32. We Have No Government Email Scanning Program ... by fatp · · Score: 3, Interesting

    ... like Yahoo's...

    Ours are much more advance and stealthy

  33. Re:Duh! Well of course not by buss_error · · Score: 1

    No need to do that. They scan them in flight (where encrypted tunnels or TLS is not in use).

    --
    Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves.
  34. Technically they don't use the same system. by Anonymous Coward · · Score: 0

    Google and Apple do not use YahooEmailScanner.exe.

  35. "will" is a weasel word by Anonymous Coward · · Score: 0

    And we never will.

    The word "will" is not a binding word, legally. It is a "weasel word" that sits slightly above "might" or "may". The above translates legally as "We do not want to" or "We do not intend to".

    The other interesting thing is that the statement stands on its own (there is no verb, let alone object, immediately after the modal verb), remaining unconnected to any of the previous statements - or any statement whatsoever. IOW, it would be ignored completely in any contractual arrangement or court of law, as it is an unfinished sentence. It's a way of indemnifying themselves against any future class action; leaving the possibility wide open whilst the listener thinks it is a concrete statement about the future. ("Will" doesn't mean future, BTW, it means "intention".)

    The key word to look for in these kinds of statements is: "shall", which is a binding word for known or unknown future events.
    Or, at a long stretch: "going to" which is semi-binding for planned future - it sits above "will" but lower than "shall". "Not going to" means "refuse to".

    Source: me. I translate international contracts between English and Spanish. It has caught me (and my clients) out before.

  36. Not LIKE Yahoo's by Anonymous Coward · · Score: 0

    It is more advanced.

  37. Technology companies? by Anonymous Coward · · Score: 0

    Apple, Google and Microsoft -- three of the largest technology companies in the U.S

    While all three do something with technology on the side, they are primarily software and services companies.

  38. No problem by swd99999999 · · Score: 2

    No one can be held accountable for for naughty things that might have been said in their Yahoo email because their password was compromised.

  39. Two words. by epyT-R · · Score: 1

    Yeah right.

  40. We have no Government Email Scanning Program by Anonymous Coward · · Score: 0

    In respect of the NSA Prism program, you can figure out in general how it works by looking at the NSA slides slides designated "Top Secret" released by The Guardian newspaper and Le Monde, from the material Edward Snowden provided to them. Note: It is these newspapers, together with the Washington Post,that have made these documents public. Edward Snowden, so far as I know, has not made any documents public.
    imho

    1. Every "Prism provider" - NSA designation (P1-Microsoft, P2-Yahoo, P3-Google, P4-Facebook, P5-PalTalk, P6-YouTube [now Google], P7-Skype [now MS], P8-AOL, PA-Apple - maybe others we don't know about), has, directly connected to their company servers and databases, in one or more private locations on their company premises, a "Data Intercept Technology Unit - DITU", property of the US government, controlled and operated by FBI personnel.

    2. Each FBI DITU has a direct connection with the NSA, and CIA, and FBI.

    3. There are two types of situations at the DITU.

    a) "surveillance" the individual Prism provider client is "under surveillance". This means that every action in which they participate, login, e-mail, voice, videoconference, file transfer, image transfer, etc. is automatically provided to the DITU and transferred to NSA (and, optionally, "dual routing", to the CIA and/or FBI) in real time.
    I think it takes a FISA court order to put someone "under surveillance", but I don't know that. Seems to me the statistics about government requests that some of the Prism providers supply are about "surveillance"
    .
    b) "Stored Comms" the NSA analyst sends a request to "poke around" in the information (about anyone "Target") that the Prism provider has in their stored database with an association to the targeted client. (e-mails, web pages, uploads, voice, videos, "friends", etc.). In routing the NSA request to the DITU for "Stored Comms", the NSA request is first filtered through an FBI "Electronic Communications Surveillance Unit - ECSU", which filters out the requests pertaining to individuals (presumably only those not "under surveilllance") known by the FBI to be "US Persons", before the request is sent to the DITU. This is done, presumably, to adhere to the 4th Amendment, though I don't think it does very well. For instance, If I "friend" or send an e-mail to a targeted non -"US person", the NSA would get that...

    Also, the FBI and CIA have direct access to the DITU. If an NSA agent makes a "Stored Comms" request it goes through the ECSU. What about FBI and CIA requests? Can't tell.

    You can look at the slides and see if you agree with my thoughts about this. Incidentally, the Wikipedia site says these slides were released by Edward Snowden, though, of course, Snowden has not released them, to my knowledge, at least.

    So, some Prism providers' statements, to the effect that they provide no information directly to the NSA are technically correct, though such statements seem to me to be deliberately misleading.

    For instance, Tim Cook says in the Charlie Rose interview,
    "There were things written in the press about people having back door access to our servers. None of that is true, zero. We would never allow that to happen, they would have to cart us out in a box before we would do that."

    Look at "PRISM surveillance program" on Wikipedia

    Maybe they don't tell him.

  41. That's not a complete denial by GrokvL · · Score: 2

    To say they don't do it in the same way as Yahoo is not the same as completely denying cooperation. I've never heard a a denial from these companies, for example, that they might feed all information sources to either an on-site or off-site cluster that government entities have access to. I've always watched the wording on statements and they seem to be carefully crafted to not lie, and to only deny very specific suspicions.

    1. Re:That's not a complete denial by Anonymous Coward · · Score: 0

      Such crafted qualified weaselly denials give me the shits - just like politicians.
      Well their share prices will TANK if a careless leak like Yahoo or Snowden releases more. Like 'I did not have sex with that woman' I think Google will have a moment of fame in the next 10 years. Just like all CA authorities doors can be knocked on and issued with gag orders.

      The way to beat this game is a pair of matched crypto dongles, which could be re purposed obsolete IOT things responsible for all those DDOS attacks.(after cutting or lifting the reprogramming pins or attaching a write alarm led to advertise hack attempts). A honeypot router.
      The security of Linux+security mods or OpenBSD and being to run this in an oversized usb stick is near.

      This is why authorities are having a hissy fit over software defined networks that change by the millisecond. Huge market for the first one to release that device.

  42. Snowden is getting senile by Anonymous Coward · · Score: 0

    Edward Snowden tweeted not too long after Reuters' report surfaced: "Heads up: Any major email service not clearly, categorically denying this tomorrow -- without careful phrasing -- is as guilty as Yahoo."

    Snowden of all people should know what a categorical denial in the context of government surveillance is worth.

    He used Lavabit himself exactly because they were not big enough to fail and would close doors rather than betray their customers' rights and privacy to a U.S. government acting outside its constitutional boundaries. And close doors they did eventually.

    Large companies don't have the luxury of closing shop altogether just because the government turned one of their side dishes into a mockery. They are all compromised, and all of them probably have bargained for an individual and particular level of pretense the government is willing to go along with as long as stuff does not get into the open. Of course, this necessitates keeping the people in the know to the bare minimum, and so some company speakers might indeed honestly claim they believe their company not to be involved.

  43. Yeah Yeah Yeah by Anonymous Coward · · Score: 0

    We have n e-mail scanning program like Yahoo. Our program works...

  44. ".. like what has been reported today about Yahoo" by gsslay · · Score: 1

    They could have just said "We have never engaged in the secret scanning of email traffic." Period. End of statement. But they decided to qualify it further. Draw your own conclusions.

  45. Re:U.S.A. by um...+Lucas · · Score: 1

    >but its highly probable that every single transcontinental link is 'managed' and tappable.

    I think that was already disclosed in the 1990's, with AT&T's secret room for the NSA at their facilities, wasn't it?

  46. It's a non-denial denial by wiredog · · Score: 1

    Or at least that's what they call it here in DC.

  47. Encryption is worthless really by Anonymous Coward · · Score: 0

    In this case encryption out side of the server is worthless if the host can simply access all email. Do I think Apple, Microsoft, Google carefully word their response? Absolutely. Because the NSA has always been able to access all information and while the companies may not have helped. It's clear the information is obtainable.
    The only instance is the iPhone when a pass code had to be broken to access the information. I assume any information on a server encrypted or not could be accessed.

  48. Barack Obama: NSA is not rifling through ordinary by Anonymous Coward · · Score: 0

    June 19, 2003. Outrage or Crickets? Well, the media can't be expected to stop doing opposition research on every trivial and imagined slight Trump may have ever made just to cover a lying President that violated all of American's Constitutional Right to Privacy. Don't be sill. What difference, at this point, does it make? MOVE ON. Right? After all, they took down and demonize Squeaky Clean Boy-scout Mitt Romney with the monumental scandal of moving a dog safely in a cage on a car roof - there just isn't time and room to cover tiny stuff like this or selling State Department favors for Clinton Foundation Donations.

  49. I just .cc Obama by ControlsGeek · · Score: 1

    I got a list of all the emails for the U.S. government and tack it on to .cc in all my emails. I don't want anybody in U.S. government to be left out.

  50. Re:U.S.A. by Anonymous Coward · · Score: 0

    Are you referring to 'MaeWest'? that was the west coast aggregate fiber tap. Their was an East coast atlantic fiber run aggregate tap as well, can't recall its name.

  51. Re:U.S.A. by Anonymous Coward · · Score: 0

    It's the Aquinas hub in Area 51. Don't worry though, a man with augmented vision will shut it down in 2052.

  52. Re:U.S.A. by Jayfar · · Score: 1

    Are you referring to 'MaeWest'? that was the west coast aggregate fiber tap. Their was an East coast atlantic fiber run aggregate tap as well, can't recall its name.

    MAE East, Duhr! But those facilities weren't particularly set up to allow government interception.

    https://en.wikipedia.org/wiki/...

  53. Re:U.S.A. by Anonymous Coward · · Score: 1

    Re: Traffic Analysis

    That by itself is extremely useful.

      During WWII there were periods when the Allies were unable to deduce the key(s) used by the Axis in encoding a days message.

    But by careful study of which units were sending to other units and back again, the Allies were able to derive actionable intelligence.

    With the pattern discerning skills of 'Big Data' and 'Machine Learning' the bad guys - and us - likely have no real secrets.

    I just assume that whatever I send, encrypted or not, is going to be read. A post, like this one, is probably hilarious to the NSA which no doubt has abilities we can't even think of.

    Read "The Hut Six Story" by Gordon Welchman to find out what was possible 70 years ago.

  54. Like Yahoo's by Anonymous Coward · · Score: 0

    Yes, Theirs are much better!

  55. Not that hard to get around. by Anonymous Coward · · Score: 0

    Ifou nda as impl er wa yof getti ng ar oundit.

    Ise nd allm y su icidebom bingor der sth isw ay, tomak eitm ore di fficu ltto pi cko utindi vidu alwords.

    Al lah u Ac kba r!! Dea th tothei nfid els!!

    1. Re:Not that hard to get around. by Anonymous Coward · · Score: 0

      A11ahu Ack6ar!! Dea+h +0 +he 1nf1de1Z!!

    2. Re: Not that hard to get around. by Anonymous Coward · · Score: 0

      Interesting. But not difficult. Dictionary words.
      'You a big dummy' - Bender

    3. Re: Not that hard to get around. by fbobraga · · Score: 1

      You don't get it!

  56. uhmm.. Dsniff, Carnivore, etc. by Anonymous Coward · · Score: 0

    Anything you post on the net should be considered public domain. In this post '911 era do you really think we have privacy ? Google searches are all scanned..
    everyting is scanned.. emails, phone calls, etc. I don't care I don't have anything to hide. What do you think IBM's WATSON 's main objective really is ?
    I use the internet for research and such but I can assure you that everything we do on the internet is monitored.

    There are applications that harvest data from applications like Facebook and Google+ Cell Phones.. even if a phones GPS is disabled if it's got a signal it's not too difficult to triangulate an locate the phone.

    If you are on the internet and think you have privacy.. think again.

    If you encrypt communications you are just flagging yourself to be monitored closely.

  57. SPAM Trap by Fnord666 · · Score: 1

    Wait, does this imply that there are people who use yahoo mail as anything other than a spam trap?

    --
    'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
  58. Plausible Deniability by ThatsNotPudding · · Score: 1

    The clueless (and mostly co-opted) Fourth Estate will dutifully parrot the statements from all the various spokespersons and maybe even the CEOs... who intentionally don't know shit.

    The CTOs and their senior staffs on the other hand...

  59. Re:U.S.A. by um...+Lucas · · Score: 1

    Here:

    https://en.wikipedia.org/wiki/...

    (Not sure if both of you posting as A/C are the same person, or if you'll even make it back here. Guess it wasn't the 1990's, but the 2000's, just seemed so long ago, I lost track of time).

  60. No word.. by h8sg8s · · Score: 1

    ..from overpaid Yahoo CEO Marissa Mayer, net worth approximately $300m.

    --
    Organization? You must be joking..
  61. Psychology and business 101 by poofmeisterp · · Score: 1

    The faster competitors team up to answer concerns of those that feed their profit, the more of a lie their answer is.

  62. Bah humbug by thunderclees · · Score: 1

    PRISM showed that they lie.

  63. Re:U.S.A. by lgw · · Score: 1

    its highly probable that every single transcontinental link is 'managed' and tappable.

    Heck, the undersea cables of hostile powers were tapped from the early 70s (presumably friendly powers followed). The US built a special-purpose nuclear submarine, capable of very deep dives and of "installation and maintenance of underwater equipment" just for the purpose of stealthily locating and tapping undersea cables.

    --
    Socialism: a lie told by totalitarians and believed by fools.
  64. Re:U.S.A. by qfman · · Score: 0

    All the companies denying internal programs have NSA taps just outside there server farms that monitor all traffic in and out of there corner of the net.

    --
    They who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety.
  65. Re:U.S.A. by Jayfar · · Score: 1

    Here:

    https://en.wikipedia.org/wiki/...

    Yes, that was NOT MAE West.