8 ms·
Microsoft sniffed blogger's Hotmail account to trace leak
The company's legal department determined that it had the right to go through a private email account, citing a leak of proprietary Microsoft code
- mglauco 13y ago"The company's legal department determined that it had the right to go through a private email account, citing a leak of proprietary Microsoft code." Judicial Mandate: Necessary or Superfluous?
- res0nat0r 13y agoI'd say investigating corporate trade secret leaks with substantial evidence pointing to an MS owned Hotmail account, to which the leaker agreed could be accessed by MS personnel would be deemed necessary.
- nikster 13y agoI don't think the reason is relevant at all. Just because XY says there's probable cause doesn't make it so. That's why we have the judiciary system. Microsoft has no legal authority to make that call.
- res0nat0r 13y agoThey do...it is in the TOS you agree to when you signup to use Hotmail.
- rossjudson 13y agoAt the time of the search, was he a Microsoft employee? At first glance, it appears that he was. This is Microsoft ordering a search of the email of one of its own employees, on its own servers. Yes, there may be a distinction between private and company emails. But it seems like the lines are somewhat blurry, here.
- chris_mahan 13y agoHotmail is a service offered to the public, and the person was accessing it as such. The hotmail account was his personal email account, not his company-provided email account. Imagine if Ford motors said: Oh, we can look into the Ford cars that Ford employees have bought with their own money and drive to weekend outings with their families, because we made and service the cars. I don't think this will fly very far.
- mcintyre1994 13y agoActually they checked the blogger's account, so it's more like Ford saying they can look into any Ford car if they think an employee is hiding something in it. Of course in this analogy all Ford buyers claim to agree to that so who really knows.
- anigbrowl 13y agoHotmail is a service offered to the public by a private entity, subject to certain terms and conditions - one of which is that the private entity (Microsoft) is allowed to put its own interests ahead of those of the user when those interests are threatened. Should webmail and similar services be regulated so as to put the interests of consumers ahead of service providers? Perhaps, and in many ways this is the approach taken by European regulators in many industries. On the other hand, it has been argued that the rather onerous data protection regulations in the EU are partly to blame for the lesser competitiveness of European firms in that marketplace, by imposing overly burdensome regulatory regimes on entrepreneurs and thus making the barriers to marketplace entry far higher than in the US.
- c_c_c 13y agoMicrosoft didn't search their employee's email. They searched the blogger's email, the one who wrote about and published screen shots of Windows 8. This is how they found that their employee had leaked the info; they saw his email with the blogger.
- dmix 13y agoI'm sure his lawyers will pick this apart and the judge/jury will determine its legality.
- ntakasaki 13y agoI can't even fathom how it can be illegal. Those are Microsoft owned servers. Once your data is in someone else's cloud, you have no recourse. That's why it's better to have your business files under your own control with OpenOffice or even MS Office instead of Google Apps or Office Online. If MS patched Office to upload your local files to MS servers, you would have a very strong case against them for "stealing" your files. If you upload them to OneDrive/Google Drive, not so much. In a similar incident, a Google employee accessed personal information, but Google was never penalized for it. http://gawker.com/5637234/gcreep-google-engineer-stalked-teens-spied-on-chats http://gawker.com/5637234/gcreep-google-engineer-stalked-tee... As usual, Stallman was right when he called cloud computing "careless computing" and a trap. http://www.theguardian.com/technology/blog/2010/dec/14/chrome-os-richard-stallman-warning http://www.theguardian.com/technology/blog/2010/dec/14/chrom...
- scarmig 13y agoYou do have recourse, and it certainly can be illegal. Just because corporations have a Russia-in-Crimea style boots-on-the-ground advantage when it comes to the cloud doesn't mean you have to throw up your hands and give up when someone violates your rights.
- cookiecaper 13y agoWhat's the basis for this assertion? The privacy policies seem to have clauses that allow this type of access. The user wilfully enters an agreement to utilize Microsoft's email servers and that agreement explicitly allows this. Even if it didn't, I don't know of any body of law that would say "the text you're uploading to another person's server can't be read by the server's owners", but I'm not a lawyer. Telecomms are different because their infrastructure is a means of conveyance, not a destination, so they need to file the paperwork to tap the comms between the source and the destination. But in this case, there is no unannounced party in the transaction. If we assume there are no external legal modifiers, it seems pretty straightforward that the server owners should be able to search their own disks for any reason. The entire premise of free modern email is that the provider will be automatically parsing the text of your emails, composing a profile of your behavior and interests from that text, and attempting to sell you products based on that profile. Wouldn't that be illegal if it's not legal to search your own disks? How come you can agree to ToS and privacy policies that allow that but not policies that say "we can also look at it if we suspect that you're trying to screw us over"?
- 300bps 13y agoBefore anyone else comments that hasn't read the full article, here is the very end: Legally, Microsoft appears to be protected by its privacy policies. The policy for Outlook.com, formerly Hotmail, states that, "We may access information about you, including the content of your communications...to protect the rights or property of Microsoft." This is the agreement that every user agreed to when they signed up for Hotmail or Outlook. It's not carte blanche for Microsoft to go through your email, but it seems to allow them to do it for a very particular purpose.
- 6cxs2hd6 13y agoI did not see similar language in Google's ToS or Privacy Policy: https://mail.google.com/mail/help/intl/en/terms.html https://mail.google.com/mail/help/intl/en/terms.html However I read very quickly so please correct me if I'm wrong.
- nivla 13y agoThis bit maybe? We will share personal information with companies, organizations or individuals outside of Google if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to: ... protect against harm to the rights, property or safety of Google ,our users or the public as required or permitted by law. [1] http://www.google.com/intl/en/policies/privacy/ http://www.google.com/intl/en/policies/privacy/
- apercu 13y agoIt's difficult to fault a company for parsing its own servers to stop corporate espionage against itself.
- waps 13y agoIt isn't. Especially not when they did this first : http://www.ibtimes.com/microsoft-rips-email-snooping-google-outlook-any-more-private-gmail-1094118 http://www.ibtimes.com/microsoft-rips-email-snooping-google-...
- jasonlotito 13y ago"The policy for Outlook.com, formerly Hotmail, states that, "We may access information about you, including the content of your communications...to protect the rights or property of Microsoft.""
- nikster 13y agoSure, but a policy doesn't change the law. If laws were broken - and I am hoping there were in accessing private communications of one of their users - then the policy is irrelevant.
- ABS 13y agoexisting thread: https://news.ycombinator.com/item?id=7434584 https://news.ycombinator.com/item?id=7434584
- deleted 13y ago[deleted]
- nullc 13y agoGMail Man! Oh wait.
- higherpurpose 13y agoThis is not the first time Microsoft had actual employees look through their users' personal accounts. At least Google only mines the data algorithmically, but this is way worse. http://wmpoweruser.com/watch-what-you-store-on-skydriveyou-may-lose-your-microsoft-life/ http://wmpoweruser.com/watch-what-you-store-on-skydriveyou-m... This is why I think Microsoft's "privacy attack ads" against Google are done in really poor taste - not necessarily because some or most of them aren't true, but because I know the company doing those ads is just as bad or worse for the very same thing they're accusing Google of. I can't support that.
- ntakasaki 13y agoHow do you figure actual employees were trawling through emails in that incident? Here's Google nailing someone for child porn. http://sacramento.cbslocal.com/2013/11/21/googles-role-in-woodland-child-pornography-arrest-raises-privacy-concerns/ http://sacramento.cbslocal.com/2013/11/21/googles-role-in-wo... AFAIK almost all online storage services use automatic scanners to screen out items violating the ToS. >At least Google only mines the data algorithmically, but this is way worse. Really? How do you even know if the Google CEO read your Gmail today? What recourse do you have? None. http://gawker.com/5637234/gcreep-google-engineer-stalked-teens-spied-on-chats http://gawker.com/5637234/gcreep-google-engineer-stalked-tee...
- meowface 13y ago>Really? How do you even know if the Google CEO read your Gmail today? What recourse do you have? None. This is simply a risk you take with any company you become a customer of. You are willingly give that company certain power over you. Rogue employees will always be able to do things that are harmful. There are many cases of rogue employees working for Comcast and AT&T who will look up someone's IP address and find their full name and address, and harass them or spread that information. Most of the time, some number of employees need access to information like that, and eventually one of them will end up going rogue or becoming mentally unstable.
- chaostheory 13y agoThis is just on an official level. Years ago, an overseas Hotmail support employee confided that if needed they will snoop in a friend's gf's email account if asked as a favor. Hopefully they instituted controls to halt this behavior since then.
- batoure 13y agoSo you might have to make some logical leaps to get to this one with me but. Would you be willing to pay to have a email address provided my the US Postal Service? Based on a reading of the law correspondence "delivered" by the postal service would be federally protected. Maybe its time for the mail service to go digital.
- jdreaver 13y agoAnd then the NSA would have an easier time reading our email. No thanks.
- batoure 13y agothey seem to be having a pretty easy time right now... there are no laws protecting you where google is concerned but there are many protecting you where the post office is concerned.
- teraflop 13y agoWhy would it be easier for the NSA to monitor the USPS than to monitor a private company?
- jdreaver 13y agoBecause they are both branches of the government. The USPS has no incentive to tell taxpayers the NSA is spying on them. At least with a private company there is a profit motive, and they could lose customers over bad press.
- mindslight 13y ago> with a private company there is a profit motive, and they could lose customers over bad press Which means that companies are only going to want to hide, downplay, and pretend to prevent such spying. This sounds familiar..
- 13y ago
- talklittle 13y agoOff topic: The name Office of Legal Compliance immediately made me think of 1984's Ministry naming. Similarly to how the Ministry of Truth's job is to spread propaganda and falsify history in the novel, this Office of Legal Compliance department's job is to ask themselves, "How far can we push the envelope toward being illegal, but still remain within legal boundaries?" Essentially their job is dealing with things that border on being illegal. Determining how far you can get to illegality, while remaining technically inside legality. For the first time the notion of "newspeak" in real life has clicked for me. I'd never grokked the idea from the novel, other than as some fear mongering fantasy that Orwell invented for the sake of compelling irony. But now I see, names actually make sense, from a certain angle. They weren't purely ironic devices. For the record, I'm NOT comparing Microsoft to Big Brother. Just funny to draw that parallel in naming choices.
- character 13y ago(from regular Microsoft employee perspective): this article does make them seem like that. Usually, in my interactions with Legal Compliance, they make sure everything we do is 100% legal, and prevent us from even coming close to the border of legality. They assume that we programmers don't think about complicated legal matters, so they go over a lot of the projects we work on and make us adhere to very strict privacy compliance that most of our competitors breeze over.
- talklittle 13y agoThanks for chiming in. I'm sure that's how legal departments work in most companies, and I didn't mean to suggest otherwise. Yes, just in this case TFA is talking about an isolated situation where my comment happens to be pertinent.
- corin_ 13y agoI have no experience with Microsoft, but my experiences with equivalent legal departments in other big tech. companies matches his view - they play it safe to the point of being insanely anal about it. These guys aren't there to make sure the company can do as much as possible, they're there to make sure there's no way anything can go wrong legally, and given its their asses on the line if they take too big a risk, they'll always stray way away from the edge.
- mindslight 13y agoWhy would you ever think they wouldn't? One of the many reasons that webmail is for jokers.
- andybak 13y agoHow is this related to webmail? That's just a choice regarding email clients. The matter of privacy and access are related to who has access to your email server.
- mindslight 13y ago"Webmail" generally implies that a large company owns and administers the server, and messages are stored on it indefinitely - in other words, completely out of your control and subject to the inherent corruption that centralization brings. Remember back in the day when you wouldn't take someone with a @hotmail or @yahoo address seriously? We shouldn't have stopped just because the domain changed to @gmail.
- benguild 13y agoOther email providers do this as well.
- nikster 13y agoI hope he can sue them and win. What Microsoft should have done is obvious: Get the case before a judge and get a search warrant. Use the search warrant to access the communications. Just because you own the email servers doesn't mean you get to play judge and jury.
- kvb 13y agoOn what grounds? IANAL (and I am a Microsoft employee), but this makes no sense to me. As far as I know, warrants are for government agencies, not companies. And assuming a civil case where they were demanding that the provider turn over the emails, wouldn't their conversation with the judge go something like this? Microsoft: “Judge, we demand that Microsoft turn over these emails.” Judge: “???” (that is, can you even procedurally attempt to force discovery against yourself?) Not to mention that the EULA seems to pretty clearly cover exactly this scenario.
- itsdrewmiller 13y agoWhile the EULA may "clearly cover exactly this scenario" do you think it would be as easy to extract the information if it was a google or apple trade secret? I kind of think MS would go to the mat for user privacy in that circumstance.
- kvb 13y agoWell, as I tried to allude to, in those cases Apple or Google would file a motion to compel Microsoft to disclose the info. Is it even possible under the rules of civil procedure for Microsoft to file a motion to compel itself to disclose something? Again, I'm not a lawyer, but my understanding is that a judge isn't going to hear the argument if there's no case, even if Microsoft did want the same level of scrutiny.
- pionar 13y agoYeah, the general rule is that you can't sue yourself, since you can't collect any damages.
- nikster 13y agoI think in the end we just need an entirely different infrastructure for all this stuff. Email should never be stored on servers unencrypted. I have used PGP/GPG but it's not good enough. It fails the mom test (as in my mom couldn't use it, and by extension, it's not ready for the mass market). If you designed a system from the ground up to be secure, you could do much better.
- ChrisGaudreau 13y agoWould you rather have Google mine your emails to display ads without human involvement, or would you rather Microsoft personally read your emails? Don't get scroogled.
- Fasebook 13y agoExcellent cover story. They really pulled out all the tops.
- jis 13y agoI remember looking into Microsoft's Healthvault product a few years ago. I was astonished to find this: "Microsoft may access and/or disclose your personal information if we believe such action is necessary to: (a) comply with the law or respond to legal process served on Microsoft; or (b) protect the rights or property of Microsoft (including the enforcement of our agreements)." Note clause (b). I thought it was a little off that they can examine your health records to protect their rights and property. But it looks like they are not afraid to use it! This ditty is still there. In fact if you go to the home page for Health Vault, it says: "It's your HealthVault account You decide who can see, use, add, and share info, and which health apps have access to it. HealthVault won't provide your health information to any other app or service without your permission." So as advertised it looks like you get to decide. You have to read pretty far down in their privacy policy before you find the clause I first mentioned. Now of course there are cases where your private information may be used without your permission, but most people would assume that requires some form of legal process... but not for Microsoft.
- aiiane 13y agoScroogled!
- EGreg 13y agoWhat did they smell in there?
- zaroth 13y agoThe way I understand it, this is a story about a reporter who had their personal email hacked in order to uncover the identity of a protected source.
- bainsfather 13y agoThat is correct. From the Microsoft statement: "As part of the investigation, we took the step of a limited review of this third party's Microsoft operated accounts. While Microsoft's terms of service make clear our permission for this type of review, this happens only in the most exceptional circumstances. We apply a rigorous process before reviewing such content. In this case, there was a thorough review by a legal team separate from the investigating team and strong evidence of a criminal act that met a standard comparable to that required to obtain a legal order to search other sites." One might rephrase it as: 'The TOS allow us to read your data. We will choose to do so if it is sufficiently important to us. We can make this decision unilaterally.'
- Aoyagi 13y agoSlightly OT: I see a lot of people here talking about EULAs. What about EULAs and Europan law, EU or national? I don't think they're compatible.
- mikevm 13y agoFor those wondering, this is probably the guy behind the wzor.net site: http://www.computerworld.com/s/article/9247091/Windows_leak_site_Wzor_goes_dark_a_day_after_feds_arrest_Microsoft_mole http://www.computerworld.com/s/article/9247091/Windows_leak_...
- jgalt212 13y agoIf someone stole from me, and I knew how to find the thief, regardless, of the legality of the methods, I'd probably do it.