Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Here is a recent article discussing the DEA doing this: https://www.washingtonpost.com/news/powerpost/wp/2016/09/30/...

$600k to a particular airline employee, $1 million for a single parcel worker (this was over a few years).

Also there is the various NSA efforts to insert people into the encryption standards process, as well as use cooperative sources within companies to insert vulnerabilities in the commercial encryption systems:

http://www.nytimes.com/interactive/2013/09/05/us/documents-r...

Also the FBI/Yahoo email program was apparently done by just the CEO, a lawyer, and a few members of the email team. The security team wasn't informed, nor the board.

https://www.theguardian.com/technology/2016/oct/04/yahoo-sec...



The DEA program is pretty shocking and a great example, thanks for sharing!

The second one sounds more like an interdiction program, where vulnerabilities are inserted into the devices (this is a thing that was in the Snowden documents). The document gives no details. The highlights on the side are from an NYT journalist, not source material.

I disagree that the last example is an example of that. It's still unclear what the scanning was doing.


The Yahoo thing is a huge deal. Email providers do interception all of the time and have strong procedural controls.

The idea that people could bypass those processes and controls is a tremendous liability that no board would ever approve.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: