The company's ability (and willingness) to take such an approach became apparent this week. Microsoft admitted in federal court documents that it forced its way into a
blogger's Hotmail account to track down and stop a potentially
catastrophic leak of sensitive software. The company says its decision
is justified.
From the company's point of view, desperate times call for desperate measures.
"In this case, we took extraordinary actions based on the specific
circumstances," said John Frank, one of the company's top lawyers, in a blog post Thursday night.
According to an FBI complaint,
Microsoft in 2012 discovered that an ex-employee had leaked proprietary
software to an anonymous blogger. Fearing that could empower hackers,
Microsoft's lawyers approved emergency "content pulls" of the blogger's
accounts to track it down. Company investigators entered the blogger's
Hotmail account, then pored over emails and instant messages on Windows
Live. The internal investigation led to the arrest on Wednesday of Alex
Kibkalo, a former Microsoft employee based in Lebanon.
Although the move could be perceived as a breach of trust, Microsoft
says it's allowed to make such unilateral decisions. It pointed to its
terms of service: When you use Microsoft communication products, (Outlook, Hotmail, Windows Live) you agree to "this type of review ...
in the most exceptional circumstances," Frank wrote.
Microsoft's legal team thought there was enough evidence suggesting the
blogger would try selling the illegally obtained intellectual property.
In such instances, law enforcement agents would typically seek a
warrant, but Microsoft said it didn't need one. The servers storing the
information are on its own property.
Ginger McCall, a director at the Electronic Privacy Information Center,
said those actions are deeply troubling, because they show "Microsoft
clearly believes that the users' personal data belongs to Microsoft, not
the users themselves."
"This is part of the broader problem
with privacy policies," she said. "There are hidden terms that the users
don't actually know are there. If the terms were out in the open,
people would be horrified by them."
Microsoft recognizes that it's a sensitive topic, especially as the
nation grapples with revelations about the extent of warrantless
surveillance on Americans by their own government -- spying that
Microsoft and other major tech companies have loudly criticized.
That's why Microsoft is instituting a new policy: In the future, it'll
loop in an outside lawyer who's a former federal judge and seek his or
her approval.
In a move that might be deemed ironic, Microsoft
will now add its own internal searches to its biannual transparency
reports on government surveillance.
Source: CNN
Based in the historic downtown area of Plymouth, MA, IES is a web design / hosting, computer / IT support, and marketing consulting firm for small to large business, including government & nonprofits. We also sell & service POS equipment, smart systems, CCTV systems, and custom wifi service. IES operates globally via the latest technology.
Showing posts with label email. Show all posts
Showing posts with label email. Show all posts
Monday, March 24, 2014
Microsoft will break into your Outlook, Hotmail, and instant messenger accounts if it deems necessary.
Labels:
email,
email breach,
email hack,
email privacy,
Hotmail hack,
Internet privacy,
Microsoft,
Microsoft email hack,
Microsoft hack,
online privacy,
Outlook hack,
privacy breach,
security
Friday, January 10, 2014
Gmail and Google+ implement an "email anyone" policy.
A new feature from Google will let you e-mail just about anyone with a
Google+ account, and, in turn, give them the ability to e-mail you.
The feature, announced on the official Gmail blog,
won't give your actual e-mail address to strangers. But when a Gmail
user begins typing in the address box, it will provide suggestions
including people in their Google+ network.
The idea, Google says, is
to make it easier to contact friends and other contacts when you've
forgotten, or never had, their e-mail address. But some early reactions
suggested the new change may make it too easy.
In our opinion, it's just another reason to hate Google+. They have officially turned it into a stalking tool.
Google, clearly anticipating the privacy concerns, notes that users may limit the feature, or opt out of it entirely.
While the default G+
setting will allow anyone on Google+ to contact you, users may limit
that access to people in their Circles on the network, or to nobody at
all.
There are other limits,
too. A user may only e-mail you using the system once if you don't reply
(addressing the stalking concerns, perhaps). And messages from people
who are not in your G+ Circles will go into the "Social" folder, along
with other posts from sites like G+, Facebook and Twitter, instead of
the user's primary inbox.
Google said the feature
will be rolling out to Gmail and Google+ users over the next couple of
days, when they will receive a message with a link to the feature.
Source: Gmail Email Blast
Labels:
email,
email privacy,
G+,
Gmail,
Gmail privacy,
Google,
Google Mail,
Google+,
privacy
Thursday, June 27, 2013
Yahoo raising security concerns for 'recycling" old e-mail addresses.
Yahoo has announced a plan to "recycle" old e-mail addresses, a move meant to free up accounts for folks who want them but that has sparked privacy concerns.
In a blog post, senior vice president Jay Rossiter announced that Yahoo e-mail accounts that have been dormant for more than a year will be reset so that active users can have access to them.
"If you're like me, you want a Yahoo! ID that's short, sweet, and memorable like albert@yahoo.com instead of albert9330399@yahoo.com," he wrote.
The one-year period will officially begin July 15, when users can "claim" a dormant account name. They'll find out in mid-August if they got the account they wanted.
It's clearly an effort by Yahoo, which has been working to redefine and rejuvenate itself under new CEO Marissa Mayer, to re-engage older users and reward active ones. But it has security experts nervous.
Security analyst Graham Cluley doesn't mince words.
"In short: as an idea it sucks, and it shows Yahoo's lack of respect to customers who created accounts with them in years gone by," Cluley wrote Wednesday.
Cluley lists several scenarios where the plan could backfire. They include situations in which a user has another primary e-mail account, but has given their Yahoo address as a backup in case of security situations, lost passwords and the like.
He said the move appears to be "an underhanded way to get people to re-engage with the site" and that people who may not actively use their Yahoo mail, but use it to store old messages and other documents, could lose them without ever realizing it.
Mat Honan of CNN content partner Wired, himself the recent victim of a high-profile hack, called the move "a spectacularly bad idea."
In the wake of such complaints, Yahoo released a followup statement saying it's sure the transition can be made without compromising security.
"We're committed and confident in our ability to do this in a way that's safe, secure and protects our users' data," the company said.
The vast majority of inactive Yahoo IDs don't have a mailbox associated with them, the company said, and any personal data associated with the accounts will be deleted.
During a 30-day deactivation period, bounce-back e-mails will alert senders that the deactivated account no longer exists and Yahoo will unsubscribe those accounts from newsletters, commercial e-mail alerts and the like.
Businesses, financial institutions, social networks and other e-mail providers will be sent notifications about e-mail addresses that have been deactivated.
Source: CNN
Labels:
e-mail,
e-mail privacy,
e-mail security,
email,
email privacy,
email security,
Marissa Mayer,
privacy,
security,
Yahoo,
Yahoo privacy,
Yahoo security
Subscribe to:
Posts (Atom)