Yahoo’s Government Email Scanner Was Actually a Secret Hacking Tool
X-posted from Good Reads: http://www.democraticunderground.com/1016168160
https://motherboard.vice.com/read/yahoo-government-email-scanner-was-actually-a-secret-hacking-tool
The spy tool that the US government ordered Yahoo to install on its systems last year at the behest of the NSA or the FBI was a poorly designed and buggy piece of malware, according to two sources closely familiar with the matter
Last year, the US government served Yahoo with a secret order, asking the company to search within its users emails for some targeted information, as first reported by Reuters this week. Its still unclear what was the information sought, but The New York Times, citing an anonymous official source, later reported that the government was looking for a specific digital signature of a communications method used by a state-sponsored, foreign terrorist organization. ...
...But two sources familiar with the matter told Motherboard that this description is wrong, and that the tool was actually more like a rootkit, a powerful type of malware that lives deep inside an infected system and gives hackers essentially unfettered access. The rootkit-like tool was found by Yahoos internal security testing team during one of their checkups, according to a source.
They assumed it was a rootkit installed by hackers, an ex-Yahoo employee, who requested anonymity to discuss sensitive issues, told Motherboard. If it was just a slight modification to the spam and child pornography filters, the security team wouldn't have noticed and freaked out.
Tl;dr version: The Feds demand Yahoo management install rootkit (my guess is to look for posts using steganography), Yahoo management obliges- but does not tell Yahoo corporate security.
Yahoo security finds poorly-written malware, tells management. Management says
"National security letter, STFU or do time". Head of security resigns as a result.
Presumably someone at Yahoo remains pissed off, leaks details to Motherboard.
(or if your are of conspiratorial bent, malware was/is actually good and reports of
it being poorly written are attempts to make NSA look more inept than they
really are...)