Feeds

Microsoft: C'mon, you can trust us... look at our gov spook-busting plans

We'll challenge NSA-shielding gag orders, thunders Redmond's top legal eagle

Next gen security for virtualised datacentres

Microsoft has detailed a three-pronged plan to encrypt customer data, improve transparency and fight harder in the courts not to have to hand over your data. The new plan is designed to restore customer trust after revelations of government snooping.

Microsoft has been stung into action by in the wake of documents leaked by former National Security Agency sysadmin Edward Snowden that the NSA and GCHQ had tapped into cables and intercepted sensitive network traffic running between its data centres.

According to the leaks, Microsoft's Hotmail, Windows Live Messenger and Passport services were scanned by software called Monkey Puzzle, cooked up by hacker squads at GCHQ, as reported in a recent Washington Post piece.

The leak came a month after leaks emerged that alleged the NSA was tapping Google and Yahoo!'s data centre interlinks. Two Google engineers then ripped into the NSA's Project MUSCULAR, posting sweary posts on Google + denouncing the so-called tactic. Brad Smith, Microsoft's general counsel, described similar allegations in rather more measured term as "disturbing" and a potentially constitutional breach, if verified.

A foreign affair...

The NSA's controversial PRISM web surveillance programme slurped internet communications and stored data of the customers of Microsoft, Google and Yahoo!, among others – although all of the firms protested they would only give up customer data after an order from the secret United States Foreign Intelligence Surveillance Court.

Nevertheless, PRISM has already made it harder for Microsoft to sell its cloud-based services outside the US and the latest revelations have made a tricky situation even worse.

Microsoft has already said it would strengthen encryption. A blog post by Smith on Wednesday outlines the details and a timescale for the rollout of improved security for the first time.

Microsoft is following Twitter's lead and adopting Perfect Forward Secrecy* and 2048-bit key lengths to strengthen encryption of customer data. In addition, data centre links will be encrypted and customer content moving between users and Microsoft will be encrypted by default.

"All of this will be in place by the end of 2014, and much of it is effective immediately," Smith promised.

We'll challenge gag orders and notify customers

Smith also talked about reinforcing legal protections. "We are committed to notifying business and government customers if we receive legal orders related to their data," he explained. "Where a gag order attempts to prohibit us from doing this, we will challenge it in court."

This sounds like Microsoft will be more proactive about legally contesting surveillance orders rather than a new policy as such.

Finally the software giant wants to be more transparent. It is extending access to its long-standing program that allows government customers to review its source code by promising to build centres in Europe, the Americas and Asia.

Bootnote

*Perfect Forward Secrecy is important because unless it's deployed sophisticated attackers could extract passwords and data from stored copies of previous encrypted sessions. Twitter's announcement when it adopted Forward Secrecy provides a useful primer for those interested in learning how the technology offers increased privacy.

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Best practices for enterprise data
Discussing how technology providers have innovated in order to solve new challenges, creating a new framework for enterprise data.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?