Microsoft to encrypt data to prevent snooping

Microsoft plans to encrypt data flowing through all of its communication, productivity and other services as it seeks to reassure users in the United States and beyond that it will guard their personal information from snooping governments, the company announced Wednesday night.

The encryption initiative, approved by company executives last week, comes as many of the nation’s top technology firms scramble to protect their reputations after months of revelations about how the National Security Agency and its foreign counterparts have siphoned off massive amounts of user information, including emails, video chats, address books and more.

“The goal is clear: We want to be sure that governments use legal processes rather than brute force to access user data,” Brad Smith, Microsoft’s general counsel, said in an interview.

Smith said that concern at the company surged in October, when The Washington Post reported, based on documents provided by former NSA contractor Edward Snowden, that the NSA and its British counterpart were tapping into the private communications links of Google and Yahoo as information flowed among those companies’ data centers.

Smith said that report was “like an earthquake sending shock waves through the tech sector” because it made clear that government surveillance was not limited to known legal processes, such as those approved by the Foreign Intelligence Surveillance Court, but was happening by other means as well.

Both Google and Yahoo, which have announced their own major encryption initiatives in recent months, have global networks that resemble Microsoft’s. In addition, documents provided by Snowden to The Post suggested – while not proving – that Microsoft also was a target of the NSA program that collected data moving between centers.

Privacy advocates long have considered Microsoft a laggard in adopting encryption technology and resisting surveillance efforts. The Electronic Frontier Foundation, a civil liberties group based in San Francisco, awards the company a single check mark out of a possible five for its encryption efforts.

Wednesday’s announcement signals a major new corporate commitment to such issues and was accompanied by promises to make the computer coding for Microsoft’s services more transparent and to more vigorously resist data requests from police and intelligence agencies.

Smith said the company also was taking the position that the Foreign Intelligence Surveillance Court, which oversees some NSA intelligence-gathering efforts, does not have jurisdiction to approve the collection of data outside U.S. borders.

The company did not immediately release an estimated cost or a timeline for completing the new encryption efforts. It did, however, promise to implement “best-in-class cryptography” for data flowing between customers and Microsoft and moving between data centers around the world. It also plans to encrypt data that’s in storage. Among the products getting new encryption are, Office 365, SkyDrive and Azure.

The company said the encryption effort will include implementing “perfect forward secrecy,” a way of safeguarding encryption keys, and 2,048-bit key lengths. Both are considered relatively advanced technologies. Data flowing between customers and Microsoft will be encrypted by default, which privacy advocates consider superior to systems that users must personally activate.

“I think it’s a substantial announcement and it’s a substantial undertaking. Encryption is key to privacy on the Internet,” said Greg Nojeim, director of the Project on Freedom, Security and Technology for the Center for Democracy and Technology, a Washington-based advocacy group that receives some industry support.

Encryption technology does not prevent surveillance of a particular target, but it makes it harder to gain access to vast swaths of Internet communications, as NSA has been doing for years. When The Post reported the Microsoft’s plans for encryption last week, NSA officials said that U.S. government surveillance is focused on gathering intelligence against legitimate foreign targets, “not on collecting and exploiting a class of communications or services that would sweep up communications that are not of bona fide foreign intelligence interest to the U.S. government.”

Microsoft also said Wednesday night that it would attempt to reach deals with other technology companies to protect data moving between its services and theirs. Those connections long have been a weak link, allowing for relatively easy surveillance even if the data is encrypted for the rest of its journey across the Internet.

The other elements of Wednesday’s announcement are aimed at government and business customers, not ordinary consumers.

The company said it would make its computer source code available for review by governments worldwide to demonstrate that it does not include “back doors” allowing easy access to user information.

Microsoft also said it would attempt to alert businesses and governments whenever there are legal requests for their data, although it will not do the same for other customers. Smith said that notifying individuals who are targets of government surveillance could undermine investigations.

More in Local News

A Democrat and ex-Republican team up to end two-party politics

Brian Baird and Chris Vance unveil a new organization called Washington Independents.

The beavers weren’t happy, either, about Mill Creek flooding

A tree fell on their dam, sending a rush of water into a neighborhood near Jackson High School.

Stranger offered candy to student walking home from school

The Granite Falls School District is warning families about… Continue reading

Man arrested after stolen car crashes in Everett

The accident occurred in the 100 block of SE Everett Mall Way.

5-vehicle crash in Arlington kills 62-year-old woman

Medics had transported her to the hospital, where she later died.

2 men hospitalized after rollover collision on U.S. 2

Two men were taken to the hospital with minor injuries… Continue reading

Marysville police serve a warrant — across the street from HQ

A man who fled was taken into custody. Police were serving a warrant for alleged drug-related crimes.

If vehicles crash and tumble, rescuers want to be ready

The Puyallup Extrication Team practiced with other fire departments on cars, SUVs and even buses.

Marysville man charged with stabbing wife who sought divorce

Nathan Bradford, 45, found divorce papers while going through the woman’s car.

Most Read