9 ms·
It's just good housekeeping at this point. Attacks never get worse, and there have been structural problems with SHA-1 for a long time. Plus, it does make sense
by subjoriented 8y ago
It's just good housekeeping at this point. Attacks never get worse, and there have been structural problems with SHA-1 for a long time. Plus, it does make sense for a company like Microsoft with a large user base to protect against malicious insiders. While I was there, employees in the Patch Tuesday program had been approached about backdooring updates. I don't think creating a colliding update would necessarily be the vector for such a thing (and removing SHA-1 doesn't necessarily protect against it) but overall its just a good idea.
- JoshTriplett 8y ago> While I was there, employees in the Patch Tuesday program had been approached about backdooring updates. What was the general policy about working with law enforcement to prosecute such attempts, to the extent they were traceable?
- subjoriented 8y agoMicrosoft had a large amount of policy, and it could be that there were some policy that applied, but if there was some it didn't permeate the culture and daily routine in the trenches there (from my personal and limited experience). Both backdoor requests I became privy to while there (2.5 years, circa 2011-2014) came from a certain US TLA, were law enforcement would have been an awkward step, though it seems reasonable to me that there were more requests, including from other organizations, but I was never made aware of those. There were some foreign spies caught in MSRC in the same timeframe. More of an extradite than a prosecute type situation, though.
- foobandit 8y agoThat's significant information, is this something you should be speaking about publicly?
- tiff_seattle 8y agoMaybe this guy? https://www.theatlantic.com/international/archive/2010/07/who-was-the-12th-russian-spy-at-microsoft/344876/ https://www.theatlantic.com/international/archive/2010/07/wh...
- nolok 8y agoIf you're working at a tech company, especially one the size of Microsoft, the only possible answer to that is "tell your boss, and cc whatever privacy / legal /... Head officer too". If Jonny Law goes after you for that the company will cover you, because while they might be OK to take the company decision to cooperate, they can absolutely not have random rogue employees doing that. Since the threat of law is what may make those employees comply, they need to make is as little threatening as possible, thus full legal support.
- jhayward 8y agoI would modify this to omit your "boss". If you think you are being approached to commit IP theft or a crime use a voice phone to call the chief legal officer's office and ask to immediately speak to a corporate attorney. Relate the incident to them and follow their instructions. Speak to no one else first. The reason to omit all others is that at this point you don't know several things: is there an already existing investigation that you are now part of? Is your boss or anyone you work with implicated or suspected in it? And so on. The only other thing you may wish to consider is if you want to discuss it with your personal attorney first. If you think you may have some legal exposure (it is very difficult to know, as a lay person, wether you do or not) you may want expert advice before informing the company. In any case proceed quickly, do not delay in informing the company unless so advised by your attorney.