Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

friendly_iconoclast

(15,333 posts)
Fri Oct 7, 2016, 07:01 PM Oct 2016

Yahoo’s Government Email Scanner Was Actually a Secret Hacking Tool

https://motherboard.vice.com/read/yahoo-government-email-scanner-was-actually-a-secret-hacking-tool

The spy tool that the US government ordered Yahoo to install on its systems last year at the behest of the NSA or the FBI was a “poorly designed” and “buggy” piece of malware, according to two sources closely familiar with the matter

Last year, the US government served Yahoo with a secret order, asking the company to search within its users’ emails for some targeted information, as first reported by Reuters this week. It’s still unclear what was the information sought, but The New York Times, citing an anonymous official source, later reported that the government was looking for a specific digital “signature” of a “communications method used by a state-sponsored, foreign terrorist organization.” ...

...But two sources familiar with the matter told Motherboard that this description is wrong, and that the tool was actually more like a “rootkit,” a powerful type of malware that lives deep inside an infected system and gives hackers essentially unfettered access. The rootkit-like tool was found by Yahoo’s internal security testing team during one of their checkups, according to a source.

“They assumed it was a rootkit installed by hackers,” an ex-Yahoo employee, who requested anonymity to discuss sensitive issues, told Motherboard. “If it was just a slight modification to the spam and child pornography filters, the security team wouldn't have noticed and freaked out.”



Tl;dr version: The Feds demand Yahoo management install rootkit (my guess is to look for posts using steganography), Yahoo management obliges- but does not tell Yahoo corporate security.

Yahoo security finds poorly-written malware, tells management. Management says
"National security letter, STFU or do time". Head of security resigns as a result.

Presumably someone at Yahoo remains pissed off, leaks details to Motherboard.
(or if your are of conspiratorial bent, malware was/is actually good and reports of
it being poorly written are attempts to make NSA look more inept than they
really are...)

Latest Discussions»Issue Forums»Editorials & Other Articles»Yahoo’s Government Email ...