Obama administration demands Web firms turn over user account passwords

“The U.S. government has demanded that major Internet companies divulge users’ stored passwords, according to two industry sources familiar with these orders, which represent an escalation in surveillance techniques that has not previously been disclosed,” Declan McCullagh reports for CNET. “If the government is able to determine a person’s password, which is typically stored in encrypted form, the credential could be used to log in to an account to peruse confidential correspondence or even impersonate the user. Obtaining it also would aid in deciphering encrypted devices in situations where passwords are reused.”

“Some of the government orders demand not only a user’s password but also the encryption algorithm and the so-called salt, according to a person familiar with the requests. A salt is a random string of letters or numbers used to make it more difficult to reverse the encryption process and determine the original password. Other orders demand the secret question codes often associated with user accounts,” McCullagh reports.

Microsoft, Google, and Yahoo would not say whether they had received such requests, but broadly denied handing over passwords. McCullagh reports, “Apple, Facebook, AOL, Verizon, AT&T, Time Warner Cable, and Comcast did not respond to queries about whether they have received requests for users’ passwords and how they would respond to them.”

McCullagh reports, “Even if the National Security Agency or the FBI successfully obtains an encrypted password, salt, and details about the algorithm used, unearthing a user’s original password is hardly guaranteed. The odds of success depend in large part on two factors: the type of algorithm and the complexity of the password… Whether the National Security Agency or FBI has the legal authority to demand that an Internet company divulge a hashed password, salt, and algorithm remains murky. ‘This is one of those unanswered legal questions: Is there any circumstance under which they could get password information?’ said Jennifer Granick, director of civil liberties at Stanford University’s Center for Internet and Society. ‘I don’t know.’ …’If you can figure out someone’s password, you have the ability to reuse the account,’ which raises significant privacy concerns, said Seth Schoen, a senior staff technologist at the Electronic Frontier Foundation.”

Read more in the full article here.

[Thanks to MacDailyNews readers too numerous to mention individually for the heads up.]

Related articles:
Obama administration scrambles to shut down imminent U.S. House vote to defund NSA spying – July 24, 2013
Obama administration demands master encryption keys from firms in order to conduct electronic surveillance against Internet users – July 24, 2013
Apple, Google, dozens of others push Obama administration to disclose U.S. surveillance requests – July 19, 2013
Secret court agrees to allow Yahoo to reveal its fight against U.S. government PRISM requests – July 16, 2013
How Microsoft handed U.S. NSA, FBI, CIA access to users’ encrypted video, audio, and text communications – July 11, 2013
DuckDuckGo search engine surges 33% in wake of PRISM scandal – June 20, 2013
Yahoo: Since December 2012, we have received up to 13,000 U.S. gov’t requests for customer data – June 18, 2013
Apple: Since December 2012, we have received U.S. gov’t requests for customer data for up to 10,000 accounts – June 17, 2013
Nine companies, including Apple, tied to PRISM, Obama to be smacked with class-action lawsuit – June 12, 2013
U.S. lawmakers urge review of ‘Prism’ domestic spying, Patriot Act – June 10, 2013
PRISM: Do Apple, Google, Facebook have an ethical obligation not to spy on users? – June 8, 2013
Plausible deniability: The strange and unbelievable similarities in the Apple, Google, and Facebook PRISM denials – June 7, 2013
Google’s Larry Page on government eavesdropping: ‘We had not heard of a program called PRISM until yesterday’ – June 7, 2013
Seecrypt app lets iPhone, Android users keep voice calls, text messages away from carriers, government eyes and ears – June 7, 2013
Obama administration defends PRISM data-collection as legal anti-terrorism tool – June 7, 2013
Facebook, Google, Yahoo join Apple in sort-of denying PRISM involvement – June 7, 2013
Report: Intelligence program gives U.S. government direct access to customer data on Apple servers; Apple denies – June 6, 2013

93 Comments

  1. Democracy my ASS!

    1st House representatives fail and are brainwashed on voting to defund NSA surveillance on citizens on 2013 Wed July 24…

    2nd, now, Feds/WhiteHouse demands all our personal passwords are revealed to them?! WTF?!!!

    anything else the gov. wants?
    as if between all their Departments & IRS, do not have their legs in between our pussies & pricks, in our beds, in every part of our body & all our holes.
    at what point do we use our democratic rights to stop this alien & unfriendly invasion?!!!?

    how much longer can we be raped and spit on by the joke that is democratic freedom?! what f’g freedom?

    the usa was never endangered or attacked or invaded!! why the necessity for surveillance/spying?!
    Vietnam never endangered us.
    Granada for god’s sake?!
    Kuwait-Afghanistan-Iraq-Iran-N Korea: too far and harmless to USA. WOMD?!
    maybe we should look at the main cause of all our Wars: the syphoning of our hard-earned tax dollars & kids’s lives into Israel which has not benefitted us but controlled our budget & policies, spied on us themselves, and who if not defended by us, is no loss to us, as we’re not affected nor should be, by this part of the middle world.

    the biggest irony is that would our gov. act free, democratic, fair, were we really independent, mature, intelligent, strong inside/out, only thereafter would we be respected worldwide. the irony is the less we spy on our own citizens, the stronger the people’s respect for our gov., the less our gov. has to fear us. when will our stupid gov. learn from history, from other countries, even from our own 1920s Prohibition Era, that once you forbid & control people, they find leaks to go against you, but once you respect total freedom, you kill the need for rebellion naturally, easily, cheaply.

    if you do not spy on people, tax them less, encourage small business & inventiveness, if you do not play the role of the police state or 1984 Orwellians, if you trust people, if the gov. does it’s original real job, to only support the people, not itself or corporations, if you truly protect the people and have no other controlling role as gov., THEN there is peace, prosperity. but never the way you handle it now – you’re not only opening cans of worms but digging your own grave and causing our young nation to reach Roman/Greek-like Decadence already.

    just like Music/Film industry who screwed themselves and still do despite the way Steve Jobs showed them on how to respect consumers so they do not have to fear piracy: the gov. is self-destructing! Stop Fear. Start Trust.

  2. I’m keen on the dear information anyone source in your content articles. I’m going to bookmark your site and view once again in this article routinely. I am just modestly sure I might be well informed a great deal of innovative things suitable the following! Good luck for one more!

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.