Computer Security: Why Yahoo email surveillance is a big deal
Reuters reported yesterday that Yahoo had actioned a secret dictate by a US security agency to search all it's customers' incoming emails. A small excerpt of Reuters report "... Yahoo in 2007 had fought a FISA demand that it conduct searches on specific email accounts without a court-approved warrant. Details of the case remain sealed, but a partially redacted published opinion showed Yahoo's challenge was unsuccessful. Some Yahoo employees were upset about the decision not to contest the more recent edict and thought the company could have prevailed, the sources said. They were also upset that Mayer and Yahoo General Counsel Ron Bell did not involve the company's security team in the process, instead asking Yahoo's email engineers to write a program to siphon off messages containing the character string the spies sought and store them for remote retrieval, according to the sources. The sources said the program was discovered by Yahoo's security team in May 2015, within weeks of its installation. The security team initially thought hackers had broken in. When Stamos found out that Mayer had authorized the program, he resigned as chief information security officer and told his subordinates that he had been left out of a decision that hurt users' security, the sources said. Due to a programming flaw, he told them hackers could have accessed the stored emails. ..." A program was written to search emails "for character strings". Yahoo facilitated remote retrieval. Yahoo's security team were excluded from the process. Yahoo's security team discovered the program in May 2015. "within weeks of it's installation". Chief Information Security Officer Alex Stamos resigns claiming that he was excluded from a decision that hurts client security. Stamos says that hackers could have accessed the stored emails due to a programming flaw. Why it's a big deal I'm not at all surprised that Stamos was pissed off. His security team would have their systems watching their networks for the slightest hint that anyone was thinking about hacking them. They would be watching which processes were running and be continually confirming the integrity of their programs. And then his boss allowed the government to root (rootkit) his systems. In simple terms, the backdoor (remote retrieval) and it's traffic was hidden, the running process was hidden and file system integrity checking was bypassed to hide the new program. That's serious shit needing changes to the running system. It needs a rootkit to make a system hide all those things and behave as normal while hiding the rootkit itself. It was Stamos's job to prevent some evil hackers from installing rootkits and therefore owning his systems and his boss has gone and installed one behind his back - and it may have been an insecure one at that. There is a problem that the security team can't really know how long they were pwned once the system is controlled by a rootkit. A competent rootkiter would certainly be able to fix the security archive as it was written to hide it's…