Microsoft Admits Its Datacenters Are Wide Open To NSA Attacks

from the uh,-guys... dept

"We have strict controls in place to protect the security of our data centers, and we have not given access to our data centers to the NSA or to any other government agency."

Dorothee Belz, EMEA VP for Legal and Corporate Affairs made the remark when answering a question from Claude Moraes, MEP during a meeting at the European Parliament on Monday.



"Generally, what I can say today is server-to-server transportation is generally not encrypted," she said. "This is why we are currently reviewing our security system."

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community. Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis. While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team

When the NSA news started breaking this past summer, it was noted that Google quickly realized where the NSA might be hacking in, and rushed to encrypt the links that connect their data centers. While some may criticize this, it's easy to see why companies never bothered to encrypt these links. They'renetworks, with no direct access to the outside world. The threat likelihood was quite low... unless you're a giant government spying operation. That said, once it was revealed that, indeed, this is how the NSA hacks in, no company has an excuse for not encrypting such links. Some Google engineers stated a direct "fuck you" to the NSA, as they were making sure that those links were encrypted (they claimed the job was done, though Google officially has said it's an ongoing process, suggesting they may still be finishing up).Unfortunately, it's not clear that other companies are following suit. When asked about this right after the infiltration was revealed, Yahoo gave a non-committal answer Yeah, but that doesn't say they encrypt the links between data centers, or even that they're planning to do so. Since then, Yahoo has basically said nothing as far as I can tell. Over in Europe, however, Microsoft has now admitted that it still is not encrypting those links , and is only now investigating the idea.Sure, it's not something that can be done overnight, but large internet companies who use multiple data centers now need to assume thatof their data is compromised if they're not encrypting the links. Whether or not it's done yet, these companies have a responsibility to get that process started as soon as possible. Hell, they all probably should have started doing this as soon as the news broke that Google was rushing to do this, since it was pretty clear they'd figured out what was going on.It's especially ironic that Microsoft is now admitting that it's not encrypting the data leaks, because the company has been on a rampage trying to present itself as protecting users privacy and that Google is a privacy nightmare . But, given these admissions, Microsoft has now basically said that its made all of your data available to the US government and it's still thinking about what to do about it, while Google has been rushing to protect its users privacy.

Filed Under: datacenters, encryption, infiltration, nsa, nsa surveillance, surveillance

Companies: google, microsoft, yahoo